top of page
SHIELD button

Attack Mitigation Service (AMS) Lite
Service Specific Terms & Conditions

Master Terms and Condition

These Terms and Conditions are also subject to the Fortis Master Terms and Conditions.

 

1. Scope of Service

1.1 AMS Lite is a vulnerability assessment and readiness service designed to support organisations in identifying, prioritising and reducing vulnerabilities within their IT environment.

1.2 The Service provides vulnerability scanning, reporting and remediation guidance intended to improve visibility of security vulnerabilities across agreed in-scope systems and infrastructure.

1.3 AMS Lite is a point-in-time assessment and advisory service. The Service is provided to assist the Customer in improving cyber security posture and does not guarantee regulatory compliance, certification success, the absence of security vulnerabilities or protection from cyber attack.

1.4 AMS Lite may be purchased as a standalone service or in conjunction with Fortis Cyber Cyber Essentials and/or Cyber Essentials Plus services.

2. Service Eligibility

2.1 The Service is intended for organisations seeking to identify and manage vulnerabilities within their IT environment.

 

2.2 The Customer must provide Fortis Cyber with all information reasonably required to deliver the Service, including:

  • Endpoint quantities;

  • Server quantities;

  • Network ranges;

  • Cloud services in scope;

  • Administrative access where required;

  • Technical points of contact; and

  • Any other information necessary to perform the agreed assessments.

 

2.3 Delays in providing required information, access, approvals or permissions may impact delivery timescales and Fortis Cyber shall not be responsible for any resulting delays.

 

3. Scanning Methodology

3.1 AMS Lite includes vulnerability scanning, analysis and reporting using industry-recognised scanning tools, threat intelligence sources and assessor expertise.

3.2 The scanning approach utilised will be determined by Fortis Cyber based upon the size and nature of the Customer environment.

3.3 For environments containing fewer than fifty (50) endpoints, Fortis Cyber will normally deploy and utilise Tenable Agent-based vulnerability scanning technology.

3.4 For environments containing fifty (50) or more endpoints, Fortis Cyber will normally utilise a Nessus Network Scanner deployment.

3.5 Fortis Cyber reserves the right to recommend an alternative scanning methodology where technical, operational, architectural or security considerations make the standard approach unsuitable.

3.6 Where Fortis Cyber determines that the Customer's environment, asset profile, network architecture, security requirements, operational constraints or endpoint volumes require a scanning methodology, deployment model or level of effort different from that originally quoted, Fortis Cyber reserves the right to revise the scope of the Service and provide an updated quotation. Any additional work, licences, scanning infrastructure, professional services effort or alternative tooling requirements shall be subject to Customer approval and may incur additional charges.

3.7 The Customer agrees to cooperate with the deployment, operation and removal of any scanning technology required for delivery of the Service.

3.8 AMS Lite pricing is based upon the endpoint and server quantities declared by the Customer at the time of quotation. Where actual asset quantities exceed declared quantities, or where the environment materially differs from that originally described, Fortis Cyber reserves the right to revise the scope and fees applicable to the Service.

4. Service Deliverables

4.1 Subject to the purchased package, AMS Lite may include:

  • Vulnerability scanning across agreed in-scope systems;

  • Vulnerability identification and analysis;

  • Prioritised risk reporting;

  • Remediation guidance;

  • Validation re-scanning;

  • Executive summary reporting;

  • Trend analysis where applicable; and

  • Up to ten (10) scan cycles during the agreed service period.

Any deliverables not expressly included within the proposal, quotation or statement of work are excluded from the Service.

4.2 Scan Scheduling and Service Delivery

4.2.a AMS Lite is delivered as a scheduled vulnerability scanning service operating within agreed scanning windows and service periods. Vulnerability scans are performed in accordance with a mutually agreed scan schedule established at the commencement of the Service.

4.2.b Scan activities will be conducted in batches during pre-agreed scanning windows. The timing, frequency and cadence of scans shall be determined by Fortis Cyber and agreed with the Customer prior to commencement of the Service.

4.2.c Fortis Cyber may offer different scanning cadences, including weekly, twice-weekly or other agreed schedules, depending upon the purchased service package, Customer requirements and operational considerations.

4.2.d The Customer shall ensure that all agreed in-scope devices, systems and network assets are powered on, accessible and available during scheduled scan windows. Fortis Cyber shall not be responsible for vulnerabilities,

assets or systems that cannot be assessed due to the unavailability of such devices during scheduled scan periods.

4.2.e Where endpoint-based scanning is used, the Customer shall take reasonable steps to ensure that devices remain connected to the Internet and capable of communicating with the approved scanning platform throughout the scheduled scan window.

4.2.f The Customer is responsible for notifying relevant internal stakeholders, including IT operations teams, security operations teams, change management personnel and end users, of agreed scan schedules to avoid unnecessary alerts, investigations or service disruptions resulting from legitimate scanning activity.

4.2.g Fortis Cyber will provide vulnerability reports following completion of each scheduled scan cycle. Report delivery timelines may vary depending on scan scope, asset volumes, vulnerability volumes and Customer responsiveness.

4.2.h Missed scan windows resulting from Customer unavailability, inaccessible assets, scheduling conflicts or Customer-requested postponements may be deemed consumed unless otherwise agreed by Fortis Cyber in writing.

4.2.i Fortis Cyber reserves the right to amend scheduled scanning dates and times where reasonably required for operational, technical, security or resource-planning reasons. Fortis Cyber will provide reasonable notice of any such changes.

5. Customer Responsibilities

The Customer shall:

5.1 Maintain accurate asset inventories of all systems included within the assessment scope.

5.2 Ensure that all relevant devices remain accessible for scheduled scanning activities.

5.3 Obtain all necessary internal approvals and permissions for vulnerability scanning activities.

5.4 Implement remediation actions at its own discretion and responsibility.

5.5 Ensure all software, operating systems and security tooling remain appropriately licensed and supported.

5.6 Maintain suitable backups and business continuity arrangements prior to any scanning activities.

5.7 Notify Fortis Cyber of any safety-critical, fragile, unsupported or operational technology systems requiring exclusion or special handling.

6. Vulnerability Reporting and Remediation

6.1 AMS Lite provides recommendations and guidance only.

6.2 Unless expressly stated within the applicable proposal or statement of work, Fortis Cyber is not responsible for remediation, patch deployment, configuration changes or vulnerability resolution activities.

6.3 The Customer remains solely responsible for all decisions relating to remediation activities and the operation of its systems and infrastructure.

7. Certification and Compliance

7.1 AMS Lite may support readiness for Cyber Essentials Plus assessments and other assurance activities.

7.2 Fortis Cyber makes no guarantee that vulnerabilities identified through AMS Lite represent all vulnerabilities present within the Customer environment.

7.3 Participation in AMS Lite does not guarantee certification, assessment success, regulatory compliance or a first-time pass outcome under any certification scheme.

7.4 Certification decisions remain subject to the applicable certification body, assessment scheme rules and assessor testing methodologies.

8. Service Period

8.1 Unless otherwise agreed, AMS Lite is delivered over a maximum period of three (3) months and consists of a series of scheduled batch vulnerability scans conducted in accordance with an agreed scanning cadence and timetable.

8.2 Scan cycles may be delivered weekly, twice weekly or at another agreed frequency depending upon the purchased service package and operational requirements.

8.3 Any unused scans, reviews or service activities expire at the end of the agreed service period and cannot be carried forward unless otherwise agreed in writing.

9. Limitations

9.1 AMS Lite is not a Managed Detection and Response (MDR), Security Operations Centre (SOC), penetration testing, incident response or continuous vulnerability management service.

9.2 The Service provides vulnerability visibility only at the time assessments are performed and does not constitute continuous monitoring.

9.3 Fortis Cyber shall not be liable for vulnerabilities that arise after scanning activities have been completed.

9.4 AMS Lite does not guarantee the identification of all vulnerabilities, security weaknesses or configuration issues within the Customer environment.

10. Service Dependencies

10.1 AMS Lite relies upon third-party software, scanning engines, threat intelligence feeds and vulnerability databases.

10.2 Fortis Cyber shall not be liable for delays, inaccuracies, limitations or service interruptions resulting from third-party technologies, vulnerability feeds or service providers.

11. Order of Precedence

In the event of any conflict between:

  1. A Statement of Work, Proposal or Order Form;

  2. These AMS Lite Service Specific Terms & Conditions;

  3. Fortis Cyber Cyber Essentials & Cyber Essentials Plus Terms & Conditions (where applicable); and

  4. Fortis Cyber Master Terms & Conditions;

the documents shall take precedence in the order listed above.

bottom of page