Statement of Work
Vulnerability & Patch Management for SMBs (SOC-as-a-Service Lite)
Prepared by Starks Enterprise — starksenterprise.com · Irving "Gene" Starks Jr. · [email protected] · (980) 355-9706
Purpose & Overview
Starks Enterprise will deploy continuous vulnerability scanning across Client's environment and provide prioritized, plain-language patch guidance on a recurring basis, giving Client SOC-level visibility without an in-house security team.
Scope of Work
Deployment of vulnerability scanning across in-scope endpoints, servers, and cloud assets
Recurring scan cadence configuration (default: weekly)
Risk-prioritized findings report with remediation/patch guidance in plain language
Monthly review call to walk through findings and remediation status
Escalation path for critical/actively-exploited vulnerabilities
Deliverables
Deployed vulnerability scanning solution
Recurring prioritized findings report
Monthly review call summary
Critical-vulnerability escalation procedure
Timeline
| Phase | Activities | Duration |
|---|---|---|
| Phase 1 | Asset inventory & scanner deployment | 1-2 weeks |
| Phase 2 | Initial full scan & baseline report | 1 week |
| Ongoing | Recurring scans, reporting & monthly reviews | Ongoing |
Pricing & Payment Terms
| Item | Timing | Fee |
|---|---|---|
| Deployment & baseline scan (one-time) | Due at kickoff | $3,000 - $6,000 |
| Recurring scanning, reporting & monthly review (per month, up to 100 assets) | Monthly, in advance | $700 - $1,800/mo |
| Additional assets (per 50 assets) | Added to monthly fee | $250/mo |
Invoices are due net 15. Monthly fee begins the month following baseline scan delivery.
Client Responsibilities & Assumptions
Client will provide timely access to relevant systems, personnel, and documentation needed for discovery.
Client will designate a single point of contact for the duration of the engagement.
Cloud infrastructure costs (hosting, compute, storage) are billed separately to Client unless otherwise stated.
All work is performed remotely unless on-site work is explicitly scoped and priced separately.
Pricing assumes a single production environment and a single tenant/client instance unless stated otherwise.
Client will maintain an accurate, current asset inventory and notify Starks Enterprise of significant environment changes.
Out of Scope
Patch implementation/deployment (guidance only, unless separately scoped as managed patching)
Penetration testing (available as a separate engagement)
24/7 SOC monitoring and real-time alerting (available as an upgrade)
Acceptance Criteria
Scanning solution successfully covers all in-scope assets
Baseline report delivered and reviewed with Client
Recurring scan and reporting cadence confirmed operational
Term & Termination
This SOW is effective upon signature by both parties and remains in effect through delivery and acceptance of all deliverables, or until terminated by either party with 30 days' written notice. Fees for work performed and expenses incurred prior to termination are non-refundable. This SOW is governed by, and incorporated into, the Master Services Agreement between Starks Enterprise and Client.