This document is a draft

It has not been reviewed by a qualified legal adviser. It is published so that it can be read and commented on before it takes effect, and it should not be relied on in its current form.

Corrections and comments: legal@cmsinfosec.com

These terms govern your use of the Cyber Made Simple website and platform at cybermadesimple.co.uk. By creating an account or using the service you accept them.

If you are on a paid plan, the terms and conditions also apply and cover subscriptions, payment and cancellation.

Who we are

Cyber Made Simple is operated by CMS InfoSec Ltd, registered in England & Wales. Contact: support@cmsinfosec.com.

Your account

You must be 18 or over to create an account. Where you create one on behalf of an organisation, you confirm you are authorised to bind it, and “you” in these terms means both you and that organisation.

Keep your credentials confidential and tell us promptly at security@cmsinfosec.com if you think someone else has access. You are responsible for what happens under your account, except where it results from our own failure.

Where your plan includes multiple users, the organisation administrator controls who has access and at what role, and can see the content those users create in the organisation’s workspace.

What the service does

Cyber Made Simple helps you understand your cyber risk, act on it, and evidence what you have done. It provides self-assessments, guidance, training, generated documents, checks against publicly visible information, and shareable evidence.

What the service is not

It is not professional advice. Nothing in the platform is legal, regulatory, insurance or accountancy advice. It does not create a client relationship and it is not a substitute for advice from someone qualified to give it on your situation.

It is not an audit, a certification or a penetration test. A completed assessment is your own self-assessment. It is not an independent examination of your business, and no output from it certifies compliance with any standard.

It is not a monitoring or incident response service. Where a plan includes monitoring, it checks the sources it names on the schedule it states. Nobody is watching your systems in real time, and nobody will respond on your behalf if something happens.

It does not connect to your systems. We do not install agents, take administrative access, or integrate with your infrastructure. Every check runs against information you give us or information that is already publicly visible.

The limits of the outputs

Cost estimates are estimates. The bad-day figure is a modelled range built from published UK statistics. It describes what businesses like yours have experienced. It does not predict what will happen to you, and it is not an insurance valuation.

Assessments reflect what you told us. Answer inaccurately and the result is inaccurate. The platform takes your answers at face value because it has no way to verify them.

Generated documents are drafts. Policies, incident response plans and questionnaire answers are starting points produced from your inputs and from general templates. Read them, adapt them to your business, and have them reviewed where the subject matter warrants it. You remain responsible for anything you adopt or send to a third party.

Benchmarks are context, not targets. Peer comparisons describe published data for businesses of a stated sector and size. They are not a standard you are required to meet.

Badges and trust pages evidence what you did here. A badge means specific assessments and actions were completed on this platform on a date. It is not a certification, it is not accredited, and it does not warrant your security to anyone who sees it. Do not present it as more than it is.

Breach data is incomplete. “No breaches found” means nothing was found in the datasets we can query, which are not exhaustive and are not real-time.

Acceptable use

You must not:

  • use the service unlawfully, fraudulently, or to harm anyone;
  • attempt unauthorised access to the service, its infrastructure, or another customer’s data;
  • probe, scan or test the security of the service without our written permission. Write to security@cmsinfosec.com first, and we will usually say yes;
  • run checks against domains, addresses or systems you neither own nor are authorised to assess;
  • use phishing simulation against anyone outside your own organisation, or without a lawful basis for doing so;
  • scrape or systematically extract content, or use the service to build a competing product;
  • resell, sublicense or share access outside the users your plan covers; or
  • upload malicious code, or content that is unlawful or infringes someone else’s rights.

Content and ownership

Yours stays yours. You keep all rights in the data and content you put into the platform. You grant us a licence to host, process and display it as needed to run the service for you, and to keep backups.

Ours stays ours. We keep all rights in the platform, its content, templates, methodologies, the Cyber Made Simple and CMS InfoSec names and logos, and anything we generate for general use rather than for you.

Documents we generate for you are yours to use in your business, including sharing them with your customers, insurers and auditors. You may not repackage or resell them as a product.

We may use pooled, anonymous statistics to improve the product and to publish research. That means data that cannot identify you or your organisation. Our research findings never name a customer.

Availability

We aim to keep the service available, but we do not promise it will be uninterrupted or error-free. We may carry out maintenance, and we will give notice of planned downtime where we reasonably can.

We may change features. Where a change materially reduces what a paid plan includes, the terms and conditions say what happens.

Suspension and termination

You may close your account at any time.

We may suspend or terminate access if you materially breach these terms, if your account is being used unlawfully or to harm someone, if payment fails and stays unpaid, or if we are required to by law. Except where the breach makes it inappropriate, we will tell you first and give you a chance to fix it.

On termination, your right to use the service ends. Data retention afterwards is described in the privacy policy. In short: up to 90 days, then deletion. Export anything you want to keep before you close the account.

Our liability

Nothing here limits or excludes our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited or excluded.

Subject to that:

  • we are not liable for losses caused by a cyber attack, breach or fraud against you. We help you reduce and evidence risk; we do not insure you against it, and no security product can;
  • we are not liable for loss arising from reliance on an estimate, an assessment result, a generated document, a benchmark or a badge, given the limits set out above;
  • we are not liable for the acts or omissions of third parties, including your own suppliers, insurers and certification bodies;
  • for a paid plan, our total liability is limited to the greater of £1,000 and the fees you paid us in the twelve months before the claim;
  • for free use, our total liability is limited to £100; and
  • we are not liable for indirect or consequential loss, or for loss of profit, revenue, business, goodwill, contracts or anticipated savings.

If you are a consumer, none of this affects your statutory rights.

Covering our costs: business users only

If you use the service for the purposes of a business, you will indemnify us against claims and costs arising from your breach of these terms, from your unlawful use of the service, or from your use of the service against systems or people you were not authorised to assess.

This clause does not apply to consumers.

Governing law

These terms are governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

If you are a consumer resident in Scotland or Northern Ireland, you may also bring proceedings in your own jurisdiction, and your home nation’s mandatory consumer protection law continues to apply.

Changes

We may revise these terms. The “Last updated” date at the top of this page moves when the wording does. Where a change is material we will tell account holders, and continued use after it takes effect means you accept it.