Party 1 Full Name of the Entity: Commercial Registration Number: Tax ID: Head Office Address: Name of the Signing Legal Representative: Title of the Representative (Manager/Authorized Signatory): Phone: Email: | Party 2 Full Name (Four names): National ID Number: Nationality: Address: Phone: Email: |
This contract is made between the two parties whose full details are specified in the attached contracting form, referred to herein as "the First Party" (Cybersecurity Service Provider) and "the Second Party" (Client), collectively referred to as "the Parties." In accordance with the provisions of Egyptian Civil Law No. 131 of 1948, Commercial Law No. 17 of 1999, Personal Data Protection Law No. 151 of 2020, Anti-Cyber Crime Law No. 175 of 2018, E-Commerce Law No. 15 of 2022, Central Bank and Banking Law No. 194 of 2020 (for financial institutions), and the laws and regulations protecting critical infrastructure in the Arab Republic of Egypt, this agreement aims to organize the relationship of providing cybersecurity services between the First Party (Cybersecurity Service Provider) and the Second Party (Client), whereby the service provider undertakes to deliver a comprehensive set of security services to protect the systems, networks, data, and applications of the client from cyberattacks, breaches, and cyber threats, including risk assessment, threat monitoring, incident response, vulnerability management, security auditing, and compliance with standards and laws, in exchange for an agreed fee, with the scope of services, service levels, incident reporting procedures, emergency response plans, confidentiality terms, data protection, indemnification, and penalties defined, all within a framework of transparency and commitment to the highest standards of cybersecurity and the governing laws in the Arab Republic of Egypt. The parties hereby agree to the following:
Article (1) Definitions of the Agreement
1- The words and phrases herein - wherever they appear in this agreement - shall have the meanings set forth beside each of them, unless the context requires a different meaning:
2- Agreement: refers to this Cybersecurity Agreement in its entirety, including its terms and annexes, with its preamble considered an integral part thereof.
3- Service Provider: the first party in this agreement, which is the company specialized in providing cybersecurity services, qualified and licensed to practice this activity, and authorized to handle sensitive information and critical systems.
4- Client: the second party in this agreement, which is the natural or legal person that benefits from cybersecurity services, and owns or manages the systems, networks, and data to be protected.
5- Security Services: a set of specialized services for protecting systems, networks, data, and applications from cyberattacks, as specified in Annex (1) of this agreement.
6- Systems: all devices, servers, network devices, storage devices, computers, mobile devices, and any other devices belonging to or managed by the client.
7- Networks: all internal and external networks, wireless networks, communication networks, and any network infrastructure belonging to or managed by the client.
8- Data: all information, files, databases, records, correspondence, content, and any other data belonging to or managed by the client, including personal data, financial data, commercial data, and sensitive data.
9- Security Incident: any event or series of undesirable or unexpected events that pose a threat to the security of systems, networks, or data, or which result in their breach, loss, damage, or unauthorized access.
10- Breach: any unauthorized access to systems, networks, or data, or any violation of security policies, resulting in the disclosure, modification, damage, or loss of information.
11- Threat: any act, event, or circumstance that has the potential to cause harm to systems, networks, data, or operations.
12- Vulnerability: any weakness or flaw in systems, networks, applications, or security measures, that can be exploited by an attacker to execute a cyberattack.
13- Incident Response: the set of procedures and plans implemented to detect, analyze, contain, remediate security incidents, recover systems, and learn from the incident.
14- Risk Assessment: the process of identifying and evaluating risks threatening systems, networks, and data, and determining the necessary actions to mitigate these risks.
15- Vulnerability Management: the process of identifying, evaluating, and remediating security vulnerabilities in systems and applications.
16- Compliance: the client's commitment to the legal, regulatory, and standard requirements related to cybersecurity and data protection.
17- Service Level Agreement (SLA): the performance and quality standards for security services, including incident response times and reporting times, as specified in Annex (2) of this agreement.
18- Term of the Agreement: the duration during which the Service Provider is obliged to provide services, as specified in Article (3) of this agreement.
19- Service Fees: the financial amount that the client is obliged to pay to the Service Provider for the services, as specified in Article (5) of this agreement.
20- Related Parties: includes subsidiaries, parent companies, sister companies, as well as directors, employees, contractors, consultants, agents, and representatives.
Article (2) Subject of the Agreement and Scope of Security Services
1- Firstly: The security services provided:
2- The service provider shall provide the client with the following security services, as detailed in Appendix (1) of this agreement:
3- Risk Assessment:
4- Conduct a comprehensive assessment of the risks threatening the client’s systems, networks, and data.
5- Identify vulnerabilities and potential threats.
6- Provide a detailed report on risks and recommendations for their mitigation.
7- Prioritize remediation based on the level of severity.
8- Threat Monitoring & Incident Response: