Olerin
ServicesAbout
Log inBook a call
Legal

Standard Terms of Service

Beacon Information Security (Pty) Ltd t/a Olerin Cyber

Last updated: September 2026

On this page
1. Definitions2. Structure and precedence3. Acceptance and commencement4. The Services5. Client authorisation6. Simulated phishing and awareness7. Open source and dark web monitoring8. Authenticated review and access9. Findings, escalation and legal obligations10. Managed services, detection and response11. Incident response12. Forensic investigation13. Fractional executive services14. Intrusive testing15. Deliverables and intellectual property16. Fees, expenses and payment17. Client responsibilities18. Third-party products19. Warranties and exclusions20. Limitation of liability21. Indemnity22. Data protection23. Confidentiality24. Term, suspension and termination25. Non-solicitation26. Force majeure27. Dispute resolution28. General

These Terms govern all services provided by Beacon Information Security (Pty) Ltd, trading as Olerin Cyber.

Please read this document before accepting an order

Three parts of this document need particular attention:

  • Clauses 5 to 14 record the authorisation you give Olerin to examine your systems, domains, accounts and information, to send simulated phishing messages to your staff, and to search publicly available and breach data sources for information about your organisation. Olerin relies on that authorisation as its lawful authority to do this work.
  • Clauses 19 and 20 exclude certain warranties and limit the amount Olerin can be required to pay you if something goes wrong.
  • Clause 21 requires you to indemnify Olerin in defined circumstances.
  • Clauses 10 to 14 apply only where the Order includes the service they describe. A clause for a service you have not bought has no effect.
  • Provisions that impose a risk on you, limit Olerin's liability, or require an indemnity are printed in bold. Your attention is specifically drawn to them.

1. Definitions

1.1

In these Terms:

1.1.1

“Activity” means an activity Olerin performs in the course of the Services which involves access to, examination of, or the collection of information about Client Systems, the Client’s domains and accounts, or the Client’s personnel;

1.1.2

“Authorisation” means the authorisation given by the Client in the Service Agreement, together with any Scope Confirmation given under clause 5.13;

1.1.3

“Authorised Representative” means a director, prescribed officer or employee of the Client who is duly authorised to bind the Client and who signs the Authorisation;

1.1.4

“Business Day” means any day other than a Saturday, Sunday or public holiday in the Republic of South Africa;

1.1.5

“Client Systems” means the information systems, networks, devices, cloud tenants, applications, domains, mailboxes and accounts identified in the Authorisation;

1.1.6

“Cybercrimes Act” means the Cybercrimes Act 19 of 2020;

1.1.7

“Deliverable” means a report, register, assessment, plan or other work product Olerin provides under an Order;

1.1.8

“Engagement” means the performance of the Services under a particular Order;

1.1.9

“Intrusive Testing” has the meaning given in clause 14.1;

1.1.10

“Order” means a quotation, proposal, statement of work or service order issued by Olerin and accepted by the Client, and includes the Service Agreement;

1.1.11

“Scope Confirmation” means a written confirmation given under clause 5.13 recording the specifics of an Activity;

1.1.12

“POPIA” means the Protection of Personal Information Act 4 of 2013, and “Personal Information”, “responsible party”, “operator” and “data subject” have the meanings given in POPIA;

1.1.13

“RICA” means the Regulation of Interception of Communications and Provision of Communication-related Information Act 70 of 2002;

1.1.14

“Services” means the services described in an Order;

1.1.15

“Simulated Phishing” means the sending of messages to the Client’s personnel which imitate an attack, and the recording of the recipients’ interaction with those messages;

1.1.16

“Sub-operator” means a third party engaged by Olerin to process Personal Information on the Client’s behalf;

1.1.17

“Third-Party Product” means software, a licence, a subscription, a platform or a data service supplied by a third party, whether procured through Olerin for the Client or used by Olerin to deliver the Services.

1.2

Clause headings are for convenience. The singular includes the plural. A reference to legislation is to that legislation as amended or replaced. No provision will be construed against Olerin solely because Olerin drafted it, save where the law requires otherwise.

2. Structure and precedence

2.1

The agreement between the Parties consists of these Terms, any Regulated Client Addendum attached to the Service Agreement, the Service Agreement, any other applicable Order, and each Scope Confirmation.

2.2

Where there is a conflict, the following order of precedence applies: first, a Scope Confirmation on matters of scope, access and authority; second, any Regulated Client Addendum; third, the Service Agreement; fourth, any other Order; fifth, these Terms.

2.3

Terms contained in a Client purchase order, vendor portal, supplier questionnaire or similar document do not apply unless Olerin agrees to them in writing.

3. Acceptance and commencement

3.1

The Client accepts these Terms by signing an Order, by accepting a quotation electronically, or by instructing Olerin to proceed with the Services, whichever occurs first.

3.2

Acceptance by electronic means constitutes a valid signature for the purposes of the Electronic Communications and Transactions Act 25 of 2002.

3.3

No Activity will begin before the Client has signed the authorisation section of the Service Agreement, and, where clause 5.13 requires it, given a Scope Confirmation. Clause 5.8 applies to urgent engagements. Work that does not involve an Activity, such as scoping discussions, documentation review and planning, may proceed on acceptance of the Order.

4. The Services

4.1

Olerin will perform the Services with reasonable skill and care, using suitably qualified personnel, in a manner consistent with good practice in the information security industry in South Africa.

4.2

Olerin’s services are defensive. Olerin does not conduct penetration testing, exploitation of vulnerabilities, password cracking against live systems, denial of service testing, physical intrusion, or social engineering by telephone or in person, except on the terms in clause 14.

4.3

Olerin may engage a subcontractor to perform part of the Services. Each subcontractor is named in the Order or in the list referred to in clause 22.6. Olerin will notify the Client before a new subcontractor begins work on its engagement, and the Client may object on reasonable grounds. Where it engages a subcontractor, Olerin remains responsible to the Client for that subcontractor’s performance.

4.4

Olerin uses Third-Party Products, including security awareness training platforms and threat intelligence, breach and credential data services, to deliver the Services. A provider of a Third-Party Product is not a subcontractor performing the Services. Olerin performs the analysis and prepares the Deliverables. Clause 18 applies to Third-Party Products.

4.5

Olerin uses artificial intelligence tooling to assist its analysis, drafting and review. Olerin selects tooling that does not use Client information to train its underlying models. Olerin remains responsible for every Deliverable it issues, whether or not AI tooling was used to prepare it, and will review all AI-assisted output before delivery. Olerin does not permit AI tooling to take an action on Client Systems or to make a decision affecting the Client. Clause 22.6 applies to any Personal Information the tooling processes.

4.6

A change to the scope, timing or fees of an Engagement takes effect only when recorded in writing and agreed by both Parties. Where a change affects an Activity, a revised Authorisation is required.

4.7

Dates and durations in an Order are estimates. They assume the Client meets its obligations under clause 17.

4.8

Referred services. Where the Client requires a service that Olerin does not provide, including one requiring a registration or licence Olerin does not hold, Olerin may introduce the Client to a third-party provider. The Client contracts with that provider directly and pays it directly. Olerin does not render the referred service, does not supervise or direct how it is performed, gives no warranty in respect of it, and accepts no liability for the provider’s work, findings or conduct. A referred provider is not a subcontractor and clause 4.3 does not apply to it.

4.9

Olerin will disclose Client information to a referred provider only with the Client’s written consent. Where a Deliverable refers to a referred provider’s findings, Olerin will attribute them to that provider and will not present them as its own work.

4.10

Olerin is not registered with the Private Security Industry Regulatory Authority and does not render a security service as defined in the Private Security Industry Regulation Act 56 of 2001. The Services are information security and cybersecurity services and are not security services for the purposes of that Act.

5. Client authorisation

5.1

The Client authorises Olerin, its personnel and the subcontractors named or notified under clause 4.3 to perform the Activities identified in the Authorisation, on the Client Systems identified in the Authorisation, during the windows stated in it, and for the purpose of delivering the Services.

5.2

The Client warrants that it owns or lawfully controls the Client Systems, domains, mailboxes and accounts identified in the Authorisation, and that it has full authority to give the authorisation in clause 5.1.

5.3

The Client warrants that it has obtained every consent required from a third party for the Activities to be performed lawfully, including from hosting and data centre providers, cloud and software-as-a-service vendors, internet and connectivity providers, managed IT and managed security providers, content management and advertising platform vendors, and building owners or landlords where physical access is involved. Olerin is entitled to rely on this warranty without further enquiry.

5.4

The Client acknowledges that the Authorisation is the lawful authority on which Olerin relies for the purposes of sections 2 to 7 of the Cybercrimes Act and section 86 of the Electronic Communications and Transactions Act 25 of 2002. If the Authorisation is given without the necessary authority, or a consent required under clause 5.3 has not been obtained, clause 21 applies.

5.5

The authorisation section of the Service Agreement must be signed by an Authorised Representative. A representative of the Client’s IT or security service provider may be named as an operational contact, and may agree operational detail and give a Scope Confirmation where the Client has confirmed that provider’s authority to do so in writing, but may not give the authorisation in clause 5.1.

5.6

Olerin will keep a record of the Activities it performs, including the dates, the accounts used and the systems accessed, and will make that record available to the Client on written request.

5.7

The Client may suspend or withdraw the authorisation at any time by notifying the engagement lead named in the Service Agreement, by telephone or email. Olerin will stop the affected Activity as soon as reasonably practicable. Fees for work already performed remain payable and clause 16.6 applies to any postponement.

5.8

Urgent engagements. Where the Client requires urgent assistance, including in response to a suspected security incident, Olerin may act on the verbal or emailed instruction of an Authorised Representative before the Service Agreement or a Scope Confirmation is in place. The instruction must identify what Olerin is authorised to access and what it is authorised to do. The Client will confirm that instruction in writing within two Business Days. Where the instruction was given verbally, Olerin will send the Client its own written record of it on the same day it is given. Olerin may suspend the Services until the Client confirms.

5.9

Olerin will comply with the Client’s reasonable site, safety and access rules where those rules are notified to Olerin in advance.

5.10

Passive activities need no separate authorisation. Where the Order includes an activity that involves no access to Client Systems, no message sent to Client personnel and no intrusive technique, the Order is the Client’s authority for it and nothing further is required. Those activities are open source intelligence collection on the Client, its brands, domains and named personnel; dark web, breach and credential exposure monitoring; and non-intrusive external observation of hosts and services. The Client identifies the domains, brands, hosts and named individuals concerned in its Service Agreement or in writing, and may withdraw or vary that scope at any time under clause 5.7.

5.10.1

Where non-intrusive external observation involves sending traffic to a host, the Client warrants that it owns or lawfully controls that host, and clauses 5.2 and 5.3 apply to it. Olerin will not observe a host the Client has not identified.

5.10.2

Where the activity concerns a named individual, clause 7.6 applies.

5.11

Every Activity outside clause 5.10 requires an Authorisation. That includes any access to a Client System, any use of credentials, Simulated Phishing, and all Intrusive Testing. A standing authorisation under clause 5.10 does not extend to them, however broadly it is worded.

5.12

Standing access authorisation. Where the Services require recurring access to a Client System, the Client may authorise that access in the Service Agreement rather than confirming it for each period of work. A standing access authorisation:

5.12.1

names the tenant, directory or system, the specific roles or permissions assigned, and the individual Olerin personnel who hold them;

5.12.2

is limited to roles that read configuration, posture, logs and telemetry, and expressly excludes content search, electronic discovery, and access to mailbox, file or message content;

5.12.3

is signed by an Authorised Representative, even where the role is assigned by an administrator at the Client’s IT or security provider;

5.12.4

records the roles in the Service Agreement, or in a Scope Confirmation where a role is added after signature;

5.12.5

remains in force for the term of the relevant Order, and is re-confirmed under clause 5.16 and whenever a role, a named individual or the scope of access changes; and

5.12.6

is withdrawn, and the access revoked by the Client, on termination of the relevant Order or on notice under clause 5.7.

5.13

Scope Confirmation. No further confirmation is needed for an Activity that is authorised in the Service Agreement and performed on an asset, system or recipient group listed there. A Scope Confirmation is required only where an Activity involves a domain, system, tenant, account, recipient group or site that the Service Agreement does not identify. It may be given by email from an Authorised Representative, or from an operational contact whose authority the Client has confirmed in writing, and must identify what Olerin may access or do. No separate signed form is required.

5.13.1

A continuous or recurring Activity authorised under clause 5.10 or 5.12 needs no window and no periodic confirmation, beyond the annual re-confirmation in clause 5.16.

5.14

A time-boxed Activity — a simulated phishing campaign, an on-site assessment, or Intrusive Testing — is performed in the period the Parties agree in writing for that Activity.

5.15

A Scope Confirmation forms part of the Authorisation and is subject to the warranties in clauses 5.2 and 5.3 and, where relevant, clauses 6.2, 8.4 and 14.5, as if repeated on the date it is given.

5.16

The Client will re-confirm the authorisation in the Service Agreement in writing at least once every 12 months, and Olerin will request that confirmation. Where the Client does not re-confirm, Olerin may suspend an Activity that relies on it.

5.17

A read-only role is still access. The Client acknowledges that a standing access Authorisation authorises Olerin to access Client Systems, and that clauses 8.1 to 8.5 apply to that access. Olerin will apply least privilege, will use the narrowest role that supports the Services, and will record the roles it holds in the record kept under clause 5.6.

6. Simulated phishing and awareness activities

6.1

Where the Services include Simulated Phishing, Olerin will send messages to the recipients identified in the Authorisation and record their interaction with those messages, including whether a message was opened, whether a link was followed, whether credentials were submitted to a simulated page, whether an attachment was opened, and whether the message was reported.

6.2

The Client warrants that it is the provider of, or is otherwise lawfully entitled to authorise the monitoring of, the communications systems used, and that its employment contracts, acceptable use policy or electronic communications policy permit Simulated Phishing and the monitoring of the resulting interactions, as contemplated in sections 4, 5 and 6 of RICA. The Client is responsible for giving its personnel any notice, and obtaining any consent, that its own policies or applicable law require.

6.3

The Client is the responsible party in respect of the Personal Information of its personnel used for Simulated Phishing. Olerin processes that information as an operator on the Client’s instruction. The Client will provide only the recipient information reasonably needed to run the campaign.

6.4

The Client authorises the configuration and operation of the simulated phishing platform, and the launch of campaigns to the recipient groups it identifies, in the Service Agreement. Individual messages do not require the Client’s prior approval. Olerin selects lure content from the platform’s template library, excluding any content type the Client has recorded as not permitted. The Client accepts responsibility for the content types it has permitted, including where a lure imitates a third party’s brand.

6.5

Olerin reports campaign results in aggregate. Individual results are available to the Client on written request. The Client decides how individual results are used within its organisation and is responsible for that use, including in any performance or disciplinary process.

6.6

The Client is responsible for arranging any allow-listing or filtering exception required with its mail and security providers, and acknowledges that such an exception reduces the effectiveness of its own controls for the duration of the campaign.

6.7

An awareness training platform provided as part of the Services is a Third-Party Product and clause 18 applies to it.

7. Open source intelligence and dark web monitoring

7.1

Where the Services include open source intelligence or dark web monitoring, Olerin collects and analyses information about the Client, its brands, domains, systems and named personnel from publicly accessible sources, and from breach, credential and criminal marketplace data made available through licensed commercial threat intelligence, breach and credential data services. Olerin performs the analysis and reporting.

7.2

Olerin performs this work passively. The Client does not authorise Olerin, and Olerin will not: purchase data from or transact with a threat actor; contribute content, payment or credentials to a criminal forum or marketplace; solicit the commission of an offence; or access any system, account or mailbox using credentials discovered in the course of the work.

7.3

Where credentials are discovered, Olerin reports them without testing whether they remain valid. Testing them would require an access attempt that neither Party is authorised to make.

7.4

Olerin gives no warranty that this work will identify every exposure. Sources are incomplete, delayed and of varying reliability, and much criminal activity is never observable. The absence of a finding is not evidence that no exposure exists.

7.5

Findings may include Personal Information relating to the Client’s personnel, its clients or third parties, and may derive from data that was obtained unlawfully by a third party. Olerin processes that information as an operator for the purpose of reporting it to the Client. The Client is the responsible party in respect of that information and confirms that it has a lawful basis under POPIA to receive it and to act on it.

7.6

Where an Order includes monitoring of exposures relating to a named individual, including a director, executive or their household, the Client warrants that it has that individual’s consent or another lawful basis for the monitoring, and Olerin will report those findings only to the recipients named in the Authorisation for that purpose.

7.7

Olerin uses licensed commercial data services, as a Third-Party Product, to deliver this work. Clause 18 applies.

7.8

Where this work involves Olerin acquiring and holding an access credential, password or similar data as contemplated in section 7 of the Cybercrimes Act, Olerin does so under the lawful authority recorded in clause 5.4, solely for the purpose of reporting the exposure to the Client under this clause, and does not use, disclose or attempt to use that credential for any other purpose. Olerin retains that material only for as long as reasonably necessary for that purpose, and clause 22.8 applies to it to the extent it is Personal Information.

8. Authenticated review and access to Client Systems

8.1

Where the Services include reviewing configuration using credentials, the Client will provide named, individually attributable accounts for the Olerin personnel concerned, with the minimum privileges needed and protected by multi-factor authentication. Olerin will not use shared or generic accounts, and will not use the personal credentials of a Client employee.

8.2

Olerin’s access is for the purpose of reading configuration, settings, logs and telemetry. Olerin will not create, alter or delete data or configuration on Client Systems unless expressly instructed in writing, or unless clause 5.8 applies.

8.3

Examining a production system carries an inherent risk of unexpected behaviour, including service interruption, even where the activity is limited to reading. The Client is responsible for ensuring that current and tested backups exist before an Activity begins, and for its own business continuity arrangements.

8.4

The Client will notify Olerin before an Activity begins of any system that is unsupported, fragile, subject to a third-party maintenance restriction, or operationally sensitive, including operational technology, industrial control systems, medical technology, and any system supporting revenue-generating assets. Olerin will exclude such a system from scope unless the Authorisation records that it is in scope and how it is to be handled.

8.5

Within five Business Days after an Activity ends, the Client will revoke the access it granted, and Olerin will destroy any credential it holds for the Client Systems.

9. Findings, escalation and legal obligations

9.1

Olerin reports findings to the recipients named in the Authorisation.

9.2

Where a finding concerns the conduct or performance of the Client’s own service provider, or of an individual named in the Authorisation as an operational contact, Olerin will report it to the executive sponsor named in the Authorisation, and not only to that provider or contact. The Client will name an executive sponsor who is independent of its IT and security service providers.

9.3

Where Olerin becomes aware during an Engagement of an apparent unauthorised access to, or compromise of, Client Systems or Personal Information, it will notify the Client’s nominated contacts without undue delay so that the Client can consider its own obligations, including under section 22 of POPIA and, where applicable, section 54 of the Cybercrimes Act.

9.4

Olerin may take any step required of it by law, including making a report to an authority where a legal obligation to do so arises, and may suspend the Services where continuing to perform them would require Olerin to act unlawfully. Olerin will inform the Client of any step it takes, unless the law prohibits it from doing so.

9.5

A finding describes what Olerin observed, on the information available to it, during the window recorded in the Authorisation. It is not a statement about the state of the Client Systems at any other time.

9.6

Olerin uses third-party analysis and intelligence services to examine files, addresses, domains, messages and indicators. Olerin will not submit a Client file, message, document, log or other artefact to a service that publishes submissions or makes them available to its other subscribers, unless the Client instructs it in writing. Where analysis of that kind is required, Olerin will use a private or paid submission tier, or an offline method.

10. Managed services, detection and response

10.1

This clause applies where the Order includes continuous monitoring, managed detection and response, or managed security operations.

10.2

The authorisation for these Services is given on a standing basis in the Service Agreement and remains in force until the Services terminate or the Client withdraws it under clause 5.7. The Client will identify the systems, tenants, log sources and accounts in scope, and will give a Scope Confirmation before a source is added.

10.3

Clause 8.2 does not apply to a containment action recorded in the Service Agreement as pre-authorised. The Client may pre-authorise Olerin to take a defined action without further instruction, such as isolating a device, disabling an account, blocking an address or quarantining a message. The Client acknowledges that a containment action may interrupt its operations, including users and systems unaffected by the incident, and that Olerin will take a pre-authorised action where it reasonably believes it is necessary.

10.4

An action that is not pre-authorised requires the instruction of a contact named in the Authorisation. Where Olerin cannot reach a named contact within the time recorded in the Authorisation, it will take no further action and will continue attempting contact.

10.5

Coverage hours, response targets and service levels are as recorded in the Order. Where Olerin fails to meet a service level, the service credit stated in the Order is the Client’s sole remedy for that failure. Where the Order states no credit, no credit is payable.

10.6

Detection depends on the quality, completeness and continuity of the telemetry the Client makes available and on the Client’s own licensing of the underlying platforms. Olerin does not warrant that it will detect every incident. A change the Client makes to its environment, its licensing or its logging configuration may reduce or remove Olerin’s visibility, and Olerin is not liable for a failure to detect that arises from such a change.

10.7

Alert and log data is retained for the period stated in the Order. On termination, and on written request made within 30 days, Olerin will provide the Client with a copy of the alert and case records relating to it in Olerin’s standard format.

10.8

Onboarding is complete when Olerin confirms in writing that monitoring is live. Service levels do not apply before that confirmation.

10.9

Privileged access. Where the Services require Olerin to hold a role that can change configuration, state or access, the Service Agreement or a Scope Confirmation must record each role, the actions it permits, and the individual Olerin personnel who hold it. The Client’s attention is drawn to this clause: privileged access held by a service provider is itself a security risk to the Client, and the controls below exist to manage it.

10.10

Privileged access is subject to the following, which apply in addition to clauses 8.1 to 8.5:

10.10.1

accounts are separate from the account the individual uses for email and general work, and are protected by phishing-resistant multi-factor authentication instead of the multi-factor authentication required under clause 8.1;

10.10.2

where the Client’s licensing supports it, the role is held as eligible rather than permanently active, and is activated per session with a recorded justification;

10.10.3

Olerin will use the narrowest role that supports the Services, and will not hold a role granting global administrative control where a scoped role is sufficient;

10.10.4

every action taken under privileged access is logged, and Olerin will report those actions to the Client at the frequency stated in the Order and on request;

10.10.5

Olerin will not use privileged access for any purpose outside the Services; and

10.10.6

the Client may require Olerin to hold access through a time-bound delegated administration arrangement rather than standing accounts in its tenant, and Olerin will cooperate in establishing one.

10.11

Olerin will not, under privileged access and without the written instruction of a contact named in the Authorisation: delete Client data; disable, reduce or alter audit logging or its retention; change authentication or multi-factor settings on a Client administrator account; alter a Conditional Access policy other than as a pre-authorised containment action; create a new privileged account; or grant access to a person not named in the Authorisation.

10.12

Where an individual named in the Authorisation ceases to work on the Client’s account or leaves Olerin, Olerin will notify the Client and disable that individual’s privileged access on the same Business Day. Clause 8.5 does not apply to privileged access.

10.13

On termination of the Services, Olerin will surrender privileged access immediately and confirm in writing that it holds none, and will provide a reasonable handover of configuration and case records under clause 10.7. The Client is responsible for revoking the access it granted.

10.14

The Client may audit Olerin’s use of privileged access to its environment once in each 12 month period on 30 days’ written notice, at the Client’s cost, and Olerin will provide its access records for that purpose.

11. Incident response

11.1

This clause applies where the Order includes incident response, whether under a retainer or on call-out. Clause 5.8 governs authorisation where a response begins before an Authorisation is signed.

11.2

Before Olerin begins, the Client must notify its cyber insurer if it holds cover. Policies commonly require the insurer’s approval or the use of a panel provider, and a failure to notify may prejudice the Client’s claim and leave Olerin’s fees uninsured. Olerin is not responsible for the consequences of a failure to notify.

11.3

During a response the Client may instruct Olerin to take action that alters or destroys data or configuration, including isolating, reimaging, rebuilding or restoring a system. Olerin will act on the written or recorded verbal instruction of a contact named in the Authorisation. The decision is the Client’s, and the Client is responsible for the availability and integrity of its backups.

11.4

Olerin does not negotiate with a threat actor, communicate with one on the Client’s behalf, facilitate or process an extortion payment, or advise on whether to pay. That decision belongs to the Client alone, taken on its own legal advice, and the Client is responsible for its own sanctions, exchange control and financial crime obligations. Olerin may decline to continue an engagement where a payment is made or contemplated.

11.5

Out-of-hours, weekend and public holiday rates are as recorded in the Order. Where a retainer applies, the Order records the hours included, the rate for hours beyond them, and whether unused hours carry forward.

11.6

Where incidents at more than one client run concurrently, Olerin determines the allocation of its people acting reasonably. A retainer secures a response commitment, not exclusivity.

11.7

An incident report is prepared on the information available during the response and may be superseded as more becomes known.

12. Forensic investigation

12.1

This clause applies where the Order includes forensic investigation, in addition to clause 11 where the two overlap.

12.2

Where an investigation may become relevant to litigation, a disciplinary process or a regulatory enquiry, the Client should consider instructing Olerin through its legal adviser so that the work is capable of attracting legal professional privilege. Where the Client does so, Olerin will contract with and report to that adviser. Olerin does not advise on whether privilege attaches and gives no assurance that a deliverable is privileged.

12.3

Olerin will handle evidence in accordance with recognised forensic practice, will maintain a record of custody for each item it takes into its possession, and will record the acquisition method and integrity values. Olerin is not responsible for the integrity or completeness of evidence before it takes possession of it, or for evidence that the Client or a third party handles, alters or fails to preserve.

12.4

The Client is responsible for issuing a preservation instruction within its own organisation at the earliest opportunity, including the suspension of routine deletion and log rotation.

12.5

Forensic images and evidence copies are retained for the period recorded in the Order, or for 12 months where the Order records none, and are then securely destroyed. The Client may request return or extended retention in writing before that date, at the Client’s cost.

12.6

Preparing an expert report for proceedings, giving evidence, attending a hearing, an arbitration or a process before the CCMA or a court, and responding to a subpoena, fall outside the scope of an investigation. Olerin will provide those services only under a separate written engagement, at its rates applicable at the time.

12.7

Where an investigation concerns the conduct of an individual, clause 9.2 applies. The Client is responsible for the fairness and lawfulness of any process it runs on the findings, including under the Labour Relations Act 66 of 1995.

13. Fractional executive services

13.1

This clause applies where the Order includes a fractional or part-time Chief Information Officer, Chief Technology Officer, Chief Information Security Officer or equivalent role.

13.2

The individual provides advisory and management support as a contractor engaged by Olerin. The individual does not accept, and is not appointed to, the office of director, prescribed officer, information officer or deputy information officer of the Client, and assumes no statutory duty of the Client or of its directors, unless the Parties record that appointment and its terms in a separate written agreement.

13.3

The Client’s board retains all decision-making authority and remains accountable for the Client’s compliance obligations, and will take and record all decisions on matters within the individual’s mandate. The individual advises and executes within the mandate recorded in the Order. Nothing in the arrangement transfers a duty owed by the Client’s directors under section 76 of the Companies Act 71 of 2008, or an obligation of an information officer under POPIA.

13.4

The Order names the individual and records the days or hours committed. Olerin may substitute a person of comparable seniority and experience, and will consult the Client before doing so.

13.5

Unused days do not carry forward beyond the period recorded in the Order unless the Order says they do.

13.6

The individual may hold similar appointments with other clients, including in the same sector. Olerin will manage conflicts and will not disclose one client’s confidential information to another. The Client may name in the Order a competitor to which Olerin will not assign the same individual.

13.7

The Client will give the individual the access, information and standing needed to perform the mandate, including access to the board or its equivalent where the mandate requires it.

14. Intrusive testing

14.1

“Intrusive Testing” means an Activity that attempts to exploit a weakness rather than observe it, including penetration testing, exploitation of a vulnerability, password attacks against live systems, and social engineering by telephone or in person.

14.2

Olerin performs Intrusive Testing only where the Order expressly provides for it, the Client has expressly authorised it, and written rules of engagement signed by an Authorised Representative have been agreed. Where rules of engagement have not been agreed in writing, Olerin will not test, whatever the Order says.

14.3

The rules of engagement will record at least: the targets and the exclusions; the testing window and permitted hours; the techniques permitted and prohibited; how data encountered during testing is to be handled; the circumstances in which testing stops immediately; and a contact for each Party reachable throughout the window.

14.4

Olerin will not, in any event: conduct denial of service or volumetric testing; use a payload that alters, encrypts or deletes data; leave persistence, tooling or an account in place after the window closes; remove personal information or Client data beyond the minimum needed to evidence a finding; or move into a system excluded from scope.

14.5

The Client warrants that it is entitled to authorise testing of each target, that no target is shared infrastructure serving a third party, and that it has complied with the testing policy of each cloud, hosting or platform provider concerned, including any notification or approval that policy requires.

14.6

Intrusive Testing carries a material risk of service interruption, data corruption and unintended effect on connected systems, including systems that are not in scope. The Client accepts that risk, and warrants that current and tested backups exist and that it has a rollback plan for each target.

14.7

Where Olerin discovers an apparent live compromise during testing, it will stop and escalate under clause 9.3 before continuing.

14.8

Testers may encounter personal information. Olerin will access no more than is needed, will not retain it beyond the reporting period, and processes it as operator under clause 22.

15. Deliverables and intellectual property

15.1

In this clause:

15.1.1

“Olerin Background Material” means Olerin’s methodologies, frameworks, control libraries, question sets, maturity models, templates, model policy and procedure wording, scripts, tooling, benchmarks and know-how, whether it existed before an Engagement or was developed during one;

15.1.2

“Governance Deliverable” means a risk register, information asset register, policy, standard, procedure, plan, control matrix, register, board or committee paper, or similar artefact prepared for the Client and populated with the Client’s own information;

15.1.3

“Report” means an assessment, review, investigation or advisory report and the findings, opinions and recommendations in it.

15.2

Olerin retains all intellectual property rights in Olerin Background Material. Nothing in an Engagement transfers those rights.

15.3

On payment of the fees for the relevant Engagement, Olerin assigns to the Client all intellectual property rights in each Governance Deliverable prepared for the Client. The Client may use, amend, adopt, approve, publish within its organisation, and provide the Governance Deliverable to a successor service provider, an auditor or a certification body, without further reference to Olerin.

15.4

Where a Governance Deliverable incorporates Olerin Background Material, Olerin grants the Client a perpetual, irrevocable, worldwide, royalty-free and non-exclusive licence to use, reproduce and modify that material as embedded in the Governance Deliverable, including after termination and including through a third party acting for the Client. The Client may not extract Olerin Background Material for use independently of the Governance Deliverable, and may not supply the Governance Deliverable or a Report to a competitor of Olerin for use in that competitor’s own service delivery.

15.5

The assignment in clause 15.3 does not prevent Olerin from continuing to use its own Background Material, or the skills, techniques and know-how gained during an Engagement, for any other client.

15.6

Olerin retains the intellectual property rights in each Report. On payment of the fees for the relevant Engagement, Olerin grants the Client a perpetual, irrevocable, worldwide, royalty-free and non-exclusive licence to use, copy, retain and disclose the Report for its own business purposes, including as contemplated in clause 15.7, and including through an adviser, auditor or service provider acting for the Client.

15.7

A Report describes the Client’s own environment, and the Client may disclose it to any person it chooses, including its advisers, auditors, insurers, customers, vendors and prospective vendors, a certification or accreditation body, a regulator and a court. The Client will do so on a confidential basis and will make the recipient aware that the Report was prepared for the Client and that clause 15.8 applies. The Client will not publish a Report to the public at large, or use it in marketing material, without Olerin’s prior written consent, which will not be unreasonably withheld. This clause does not restrict a Governance Deliverable, which is the Client’s own document.

15.8

A Report is prepared for the Client, for the scope and purpose recorded in it. Olerin owes no duty of care and accepts no liability to any other person who receives it or relies on it. Where a Governance Deliverable is amended after delivery by the Client or by a third party, Olerin is not responsible for the amended version.

15.9

Olerin may use anonymised and aggregated information derived from an Engagement to develop its services and benchmarks, provided the information cannot reasonably be used to identify the Client, its personnel or its environment.

15.10

Neither Party may name the other as a client or reference, or use the other’s name or logo, without prior written consent.

16. Fees, expenses and payment

16.1

Fees are as set out in the Order and are quoted in South African Rand, excluding value added tax.

16.2

Olerin is not currently a registered value added tax vendor. If Olerin becomes registered, value added tax at the applicable rate will be added to fees invoiced on or after the effective date of registration.

16.3

Invoices are payable within 14 days of the date of invoice, without deduction or set-off.

16.4

Travel, accommodation and disbursements for work performed outside Gauteng are as quoted in the Order, or where not quoted are charged at cost, and are payable on the same terms.

16.5

Overdue amounts bear interest at the rate prescribed from time to time under the Prescribed Rate of Interest Act 55 of 1975, calculated from the due date to the date of payment. Olerin may suspend the Services while an undisputed amount remains overdue, on written notice. Olerin will not suspend active monitoring under a managed service without giving the Client the notice period stated in the Order, or if none is stated, 5 Business Days’ written notice, and will in any event complete any incident response already in progress before suspending.

16.6

Once an on-site or scheduled date is confirmed, postponement or cancellation by the Client on fewer than 10 Business Days’ notice may be charged at 50% of the fees for the affected days, together with any travel or accommodation cost already incurred and not recoverable.

16.7

Fees for recurring Services may be adjusted once in each 12 month period on 30 days’ written notice, by no more than the change in the Consumer Price Index published by Statistics South Africa over the preceding 12 months plus two percentage points, unless the Order provides otherwise.

16.8

The Client must raise a disputed amount in writing, with reasons, within seven days of the date of invoice. Undisputed amounts remain payable on the due date.

16.9

Where an Order records that a fee will be credited against future managed services, the credit applies only if the Client concludes the relevant managed services agreement within six months of the date of the relevant Deliverable and that agreement runs for at least its stated minimum term. If the Client terminates before the end of the minimum term other than for Olerin’s material breach, the credited amount becomes payable.

17. Client responsibilities

17.1

The Client will provide timely access, information, decisions and points of contact as reasonably required, and will name in the Authorisation the people who may give instructions and receive findings.

17.2

Olerin relies on the accuracy and completeness of information the Client provides, including asset inventories, system descriptions and staff lists. Findings and recommendations reflect that information. Olerin does not independently verify it unless the Order says so.

17.3

The Client remains responsible for the security of its own environment, for deciding whether to implement a recommendation, and for its own compliance obligations. Olerin advises; the Client decides.

17.4

Where a delay attributable to the Client prevents Olerin from performing scheduled work, Olerin may charge for standing time at the day rates in the Order, and clause 16.6 may apply.

18. Third-party products

18.1

Where a Third-Party Product is licensed or provisioned to the Client, it is supplied on the vendor’s own licence and service terms, which the Client accepts on activation or first use. Olerin will provide those terms on request.

18.2

Olerin gives no warranty in respect of a Third-Party Product beyond the warranty the vendor gives, and passes through the benefit of the vendor’s warranties to the extent it is permitted to do so.

18.3

Annual licences and subscriptions are non-cancellable and non-refundable once activated, unless the vendor permits otherwise.

18.4

The Client is responsible for the accuracy of the user numbers it provides and for any adjustment the vendor charges as a result.

18.5

Where Olerin uses a Third-Party Product to deliver the Services rather than licensing it to the Client — including the security awareness training platforms, and threat intelligence, breach and credential data services referred to in clauses 4.4 and 7.1 — clauses 18.1, 18.3 and 18.4 do not apply. Olerin’s obligation in that case is to select and use the Third-Party Product with reasonable skill and care. Olerin does not direct or control how such a provider obtains the data it makes available, and does not warrant the accuracy, completeness or availability of data or output a third-party provider supplies.

18.6

Clause 22.6 applies to any Personal Information a Third-Party Product processes, including any transfer outside the Republic of South Africa.

19. Warranties and exclusions

19.1

Olerin warrants that it will perform the Services with reasonable skill and care, using suitably qualified personnel.

19.2

Olerin does not warrant that the Services will prevent, detect or predict every security incident, that Client Systems are or will be free of vulnerabilities, or that the Client will achieve or maintain compliance with any standard, framework or law. Security is a continuing process. No single engagement establishes a permanent state.

19.3

All warranties, representations and terms not expressly stated in these Terms or an Order are excluded to the fullest extent the law allows.

19.4

Nothing in these Terms excludes or limits a right or remedy that cannot lawfully be excluded or limited. Where the Consumer Protection Act 68 of 2008 applies to the Client, nothing in these Terms limits, waives or deprives the Client of a right conferred by that Act, and any provision that would have that effect applies only to the extent the Act permits.

20. Limitation of liability

20.1

The Client’s attention is specifically drawn to this clause. It limits the amount the Client may recover from Olerin, and excludes certain categories of loss entirely. The Client acknowledges that it has read and understood this clause and that the fees for the Services were set on the basis of the limits it contains.

20.2

Neither Party is liable to the other for indirect or consequential loss, loss of profit, loss of revenue, loss of anticipated savings, loss of goodwill, loss of business opportunity, reputational harm, regulatory fines imposed on the other Party, or loss or corruption of data, whether or not the loss was foreseeable.

20.3

Olerin’s total liability arising out of or in connection with an Engagement, whether in contract, in delict or on any other basis, is limited in the aggregate to the fees paid by the Client under the relevant Order in the 12 months preceding the event giving rise to the claim.

20.4

Olerin is not liable for loss arising from: an attack or incident that Olerin was not engaged to prevent or detect; the Client’s decision not to implement a recommendation, or a delay in implementing it; information provided by the Client that was inaccurate or incomplete; the act or omission of a third party, including the Client’s IT or security service provider or a Third-Party Product vendor; a system or activity excluded from the Authorisation; or the Client’s use of a Deliverable for a purpose other than the one recorded in it.

20.5

Nothing in this clause limits liability for fraud, wilful misconduct, gross negligence, death or personal injury, or for any liability that cannot lawfully be limited.

20.6

Subject to clause 19.4, a claim under an Engagement must be instituted within 12 months of the date on which the claiming Party became aware, or ought reasonably to have become aware, of the facts giving rise to it.

20.7

Olerin makes no representation about insurance cover except as recorded in an Order.

21. Indemnity

21.1

The Client indemnifies Olerin and its personnel against any claim, demand, action, loss, fine, penalty, damage or cost, including reasonable legal costs, arising from the following, except to the extent the claim arises from Olerin’s breach of these Terms, negligence or wilful misconduct:

21.1.1

an authorisation or Scope Confirmation which the Client was not entitled to give;

21.1.2

a third-party consent required under clause 5.3 which was not obtained;

21.1.3

a claim by a data subject, a regulator or the Information Regulator arising from the Client’s own failure to meet its obligations as responsible party in respect of information the Client instructed Olerin to process;

21.1.4

a claim by a member of the Client’s personnel arising from Simulated Phishing conducted within the scope authorised in the Authorisation, or from the Client’s use of individual results; or

21.1.5

the Client’s breach of clause 5.2, 5.3, 5.10.1, 6.2, 7.5, 7.6, 8.4, 14.5 or 14.6.

21.2

Olerin will notify the Client in writing without undue delay of a claim to which this indemnity may apply, will not admit liability or settle without the Client’s written consent, and will allow the Client to conduct the defence at the Client’s cost, subject to Olerin’s right to participate through its own advisers.

22. Data protection

22.1

In respect of Personal Information processed in the course of the Services, the Client is the responsible party and Olerin is the operator. These Terms, together with the Authorisation and the Order, constitute the written mandate contemplated in section 20(2) of POPIA.

22.2

Olerin will process Personal Information only with the Client’s knowledge and authorisation, only for the purpose of delivering the Services, and will treat it as confidential as required by section 21(1) of POPIA.

22.3

Olerin will secure the integrity and confidentiality of Personal Information in its possession by taking appropriate, reasonable technical and organisational measures as contemplated in section 19 of POPIA.

22.4

Olerin will notify the Client in writing without undue delay, and in any event within 24 hours of becoming aware, of any unauthorised access to or acquisition of Personal Information processed on the Client’s behalf, with sufficient information to enable the Client to meet its obligations under section 22 of POPIA. The Client is responsible for any notification to data subjects and to the Information Regulator.

22.5

Olerin will assist the Client, at the Client’s cost where the assistance required is substantial, with a data subject request, a request under the Promotion of Access to Information Act 2 of 2000, or a regulatory enquiry, relating to Personal Information Olerin processes on the Client’s behalf.

22.6

Olerin uses Sub-operators and third-party service providers to deliver the Services, including security awareness training platforms, threat intelligence and breach data providers, and cloud productivity, customer relationship management and hosting services. Some of these process Personal Information outside the Republic of South Africa. The Client authorises those transfers on the basis that Olerin has satisfied itself that the recipient is subject to a law, binding corporate rules or a binding agreement which upholds principles for the reasonable processing of Personal Information that are substantially similar to those in POPIA, as contemplated in section 72 of POPIA. A current list of Sub-operators, including the country in which each processes information, is available to the Client on written request.

22.7

Olerin will bind each Sub-operator in writing to obligations no less onerous than those in this clause, and remains responsible to the Client for the Sub-operator’s processing.

22.8

On termination of an Engagement, Olerin will return or delete Personal Information processed on the Client’s behalf, except where it is required to retain a copy by law, or for professional record, audit or insurance purposes, in which case it will retain it for no longer than seven years, subject to the confidentiality obligations in these Terms.

22.9

Olerin will process special personal information, or the personal information of children, only where an Order records that the Services require it, and then only in accordance with sections 26 to 35 of POPIA.

22.10

In respect of the passive activities in clause 5.10 — open source intelligence collection, dark web and breach monitoring, and non-intrusive external observation — Olerin decides what to collect, from which sources, and how to analyse it, and is the responsible party for that collection and analysis. Olerin’s lawful basis for that processing is its legitimate interest, and that of the Client, in identifying exposures affecting the Client, its brands, domains and personnel, weighed against the interests of any data subject concerned. Where that processing involves Personal Information giving rise to a notifiable event, Olerin will notify the Client under clause 9.3 so that the Client, as responsible party for its own section 22 obligations to data subjects and the Information Regulator, can consider its position; Olerin has no independent section 22 notification obligation to a data subject or the Information Regulator in respect of that processing. Clause 22.1 continues to apply, and Olerin remains the operator, in respect of Simulated Phishing recipient data, authenticated review and access to Client Systems, and managed services.

22.11

Olerin maintains its own security controls to protect information it holds in connection with the Services, including multi-factor authentication on its own systems and accounts, encryption of data in transit and at rest, role-based access control limiting access to personnel who need it, and background screening of personnel with access to Client information. These commitments support clause 22.3.

23. Confidentiality

23.1

Where the Parties have concluded a non-disclosure agreement, that agreement governs the treatment of confidential information exchanged in connection with the Services and survives independently of these Terms.

23.2

Where they have not, each Party undertakes to keep the other’s confidential information confidential, to use it only for the purposes of the Services, and to disclose it only to those of its personnel, advisers, insurers and subcontractors who need it and who are bound by equivalent obligations. Information concerning vulnerabilities, control weaknesses or security incidents in the Client’s environment is the Client’s confidential information, regardless of which Party generated it, and the obligation in respect of that information continues indefinitely.

24. Term, suspension and termination

24.1

An Engagement for a defined piece of work ends on delivery of the last Deliverable and payment in full. Recurring Services continue until terminated in accordance with this clause or the Order.

24.2

Either Party may terminate recurring Services on 30 days’ written notice, unless the Order records a minimum term, in which case termination takes effect at the end of that term. Where the Consumer Protection Act 68 of 2008 applies to the Client, the Client may cancel on 20 Business Days’ written notice, subject to a reasonable cancellation penalty as contemplated in section 14 of that Act.

24.3

Either Party may terminate on written notice if the other commits a material breach and fails to remedy it within 10 Business Days of written notice, or is placed in liquidation, business rescue or under an equivalent process.

24.4

Olerin may suspend or terminate an Engagement with immediate effect where continuing would require it to act unlawfully, where the Client withdraws an authorisation needed to perform, or where a confirmation required under clause 5.8 or 5.16 is not provided.

24.5

On termination the Client will pay for the Services performed to the date of termination and for third-party costs Olerin has committed and cannot recover. Each Party will revoke the other’s access to its systems. Clauses which by their nature survive termination continue in force.

25. Non-solicitation

25.1

Neither Party will, for 12 months after the last Engagement, solicit for employment or engagement a person who was directly involved in delivering or receiving the Services. Responding to a public advertisement not directed at that person is excluded.

26. Force majeure

26.1

Neither Party is liable for a failure to perform caused by an event beyond its reasonable control, including natural disaster, war, civil unrest, epidemic, an act of state, an extended failure of national electricity or telecommunications infrastructure, or a widespread failure of a third-party cloud service. The affected Party will notify the other promptly and both will take reasonable steps to limit the effect. This clause does not apply to an obligation to pay money.

27. Dispute resolution

27.1

A Party raising a dispute must do so in writing. The Parties will refer the dispute to a senior representative of each and will attempt to resolve it within 10 Business Days.

27.2

If the dispute remains unresolved after clause 27.1, either Party may refer it to mediation under the rules of the Arbitration Foundation of Southern Africa, by written notice to the other. The mediation is to be completed within 20 Business Days of the referral.

27.3

Mediation is a precondition to both arbitration and litigation. Subject to clause 27.5, neither Party may institute arbitration proceedings or proceedings in a court in respect of a dispute unless the mediation has been concluded without settlement, or 20 Business Days have passed since the referral without the other Party taking part in it.

27.4

Where mediation does not resolve the dispute, it will be referred to arbitration under the rules of the Arbitration Foundation of Southern Africa, before one arbitrator, seated in Johannesburg, conducted in English. The award is final and binding and may be made an order of any court of competent jurisdiction.

27.5

Clause 27.3 does not prevent either Party from approaching a court at any time for urgent interim relief, including an interdict, or Olerin from instituting proceedings for the recovery of an amount which the Client has not disputed in accordance with clause 16.8.

27.6

Where the Consumer Protection Act 68 of 2008 applies to the Client, nothing in this clause limits the Client’s right to refer a matter to the National Consumer Commission, the National Consumer Tribunal, an ombud with jurisdiction, or a court.

28. General

28.1

Olerin chooses 26 7th Avenue, Edenvale, Johannesburg, 1609 as its domicilium citandi et executandi. The Client chooses the address recorded in the Order. A notice delivered by hand is deemed received on delivery. A notice sent by email is deemed received on the first Business Day after successful transmission, provided no delivery failure notice is received. A notice of breach, termination or dispute must be sent by email and by hand or courier.

28.2

These Terms are governed by the law of the Republic of South Africa. The Parties consent to the jurisdiction of the Magistrates’ Court having jurisdiction in terms of section 45 of the Magistrates’ Courts Act 32 of 1944, without prejudice to either Party’s right to institute proceedings in a division of the High Court.

28.3

These Terms, the Service Agreement, any other Order and each Scope Confirmation are the whole agreement between the Parties on their subject matter, and replace any prior representation or understanding. No variation is of any force unless in writing and signed by both Parties.

28.4

Olerin may amend these Terms on 30 days’ written notice, and the amended Terms apply to Orders accepted after the notice period ends. The Terms accepted at the date of an Order continue to govern that Order.

28.5

No indulgence or failure to enforce a right constitutes a waiver of that right. If a provision is invalid or unenforceable, it is severable and the remainder continues in force.

28.6

The Client may not cede or assign its rights or obligations without Olerin’s prior written consent. Olerin may cede its rights and delegate its obligations to a successor in title to the whole or substantially the whole of its business, on written notice.

28.7

Olerin acts as an independent contractor. Nothing in these Terms creates a partnership, joint venture, agency or employment relationship, and Olerin’s personnel remain Olerin’s personnel for all purposes.

28.8

These Terms may be accepted and signed in counterparts and by electronic signature.

28.9

The Party in breach is liable for the other’s costs of enforcement on the attorney and own client scale.

Olerin
Take the free health checkBook a call
Contact
26 7th Ave, Edenvale, Johannesburg, 1609
+27 10 882 2170info@olerincyber.com
Connect
LinkedIn
Facebook
X (Formally Twitter)
Google Business
Instagram
Services
Security Risk AssessmentManaged SecurityAwareness Training
Resources
Free Health CheckFree tools (soon)Insights (soon)
2026 © Beacon Information Security (Pty) Ltd t/a Olerin Cyber. All rights reserved.
Privacy PolicyCookie noticeTerms of UsePAIA Manual