This Appendix describes the scope and features of the INTECH 4CS services offered by Intech Hawaii. This Appendix is incorporated by reference into the Services Guide and is subject to all terms and conditions of the Services Guide and the Master Services Agreement ("MSA"). Only the specific services listed in your Quote will be provided; all other services described in this Appendix are available but not included unless expressly added to your Quote. Intech Hawaii reserves the right to update this Appendix from time to time to reflect changes in available services; material changes that negatively impact services already included in your Quote will be communicated to you by email.
INTECH 4CS is our suite of managed IT services organized across four pillars. Only services specifically listed in your Quote will be provided.
INTECH CLIENT STRATEGY
Virtual executive-level IT leadership. Includes:
- IT roadmap and budget planning
- Technology standards and best practices
- Strategic guidance on emerging technologies
- Scheduled strategy and progress meetings
- Technology documentation management
- Asset inventory and workstation tracking
- Vendor agreement reviews (internet, VoIP, print)
- Recommendations for improving technology usage
INTECH CLIENT SERVICE
Remote Support
Remote support during business hours for managed devices and covered software; after-hours for P1/P2 (urgent) issues. Tiered escalation applies. If remote resolution fails, an on-site technician will be dispatched (subject to availability; additional fees may apply — see Minimum Requirements / Exclusions).
Remote Support excludes new hardware/software installations and major structural file/email changes. These are billed separately.
Remote Monitoring, Management & Maintenance
24/7 agent-based monitoring for servers and workstations. Includes:
- Up/down status, agent health, capacity monitoring, and outage alerts
- Disk space inspection and cleanup
- Security updates and patch installation for supported software
- Secure remote access and screen sharing
- Workstation monitoring: failed updates, agent issues, automated reboots
Additional monitoring beyond standard parameters is not included.
Updates and Patching
Remote deployment of security updates, bug fixes, and minor enhancements. Intech Tools and Microsoft Products are patched as standard; all other applications billed at hourly rates. Minor remote installations under 30 minutes are included.
Software updates (minor) are included. Software upgrades (major version changes) are billed separately.
Backup, File Recovery & Monitoring — Server
24/7 monitoring of offsite backup, offsite replication, and client-provided onsite Backup Appliance. Includes troubleshooting, preventive maintenance, firmware/software updates, and problem analysis.
- Security: 256-bit AES encryption in transit and at rest
- Retention (default): Daily cloud backups — 90-day rolling; weekly backups — 1 year; one daily backup on restricted-access NAS
- Recovery: Business hours; subject to technician availability and viable restore points
Backup, File Recovery & Monitoring — Microsoft 365
24/7 monitoring, troubleshooting, and problem analysis for M365 backups. 256-bit AES encryption in transit and at rest.
- Retention (default): Daily off-site backups — rolling yearly basis
- Recovery: Business hours; subject to technician availability and viable restore points
Managed Domain Registrar and DNS
Secure domain registration and DNS hosting. Client retains domain ownership; Intech Hawaii manages all technical aspects.
INTECH CLIENT SERVICE — Optional Add-Ons
Onsite Support
On-site support during business hours; after-hours for P1/P2 emergencies. If not included in your plan, available at hourly rates (1-hour minimum). Limited to existing environment maintenance; new installations billed separately.
Managed Cloud Print
Serverless, centralized cloud print management from a Third-Party Provider. Covers all printers; no print server required.
Managed Remote Workstation Access
Secure, encrypted remote access to Windows and macOS endpoints. Supports remote control, file transfer, and clipboard sharing.
INTECH CYBERSECURITY
Managed Firewall
Managed firewall configured for your bandwidth, remote access, and user needs. Provides: external intrusion blocking, encrypted VPN access, inbound/outbound antivirus scanning, and website content filtering.
Managed Endpoint Antivirus and Malware Protection
AI/ML-driven endpoint protection for laptops, desktops, and servers. Detects unauthorized user/application behavior, blocks suspicious execution before it runs, sandbox-tests suspicious apps, and protects against file-based and fileless attacks (JavaScript, VBScript, PowerShell, macros, etc.).
Managed Email Security and Threat Protection
Multi-layered email protection against phishing, BEC, impersonation, SPAM, and email-borne malware. Includes: friendly-name and display-name spoofing filters, homoglyph/typosquatting domain detection, whaling/CEO-fraud/W-2 fraud protection, and newly-registered domain blocking.
Managed Endpoint Detection and Response (MDR)
24×7 managed threat detection, hunting, and response. Includes: continuous threat hunting, real-time automated and human-guided response, structured alert notifications, on-demand security reports, and 24×7×365 security team access for incident response.
Managed Dark Web Monitoring
Continuous monitoring of dark web sources for Client-supplied credentials. Compromised credentials are reviewed and affected users notified. We do not guarantee detection of all compromised credentials.
Managed End User Security Awareness Training
On-demand multilingual training videos, quizzes, baseline phishing susceptibility testing, and simulated phishing campaigns.
Managed Vulnerability Management
Monthly internal and external vulnerability scans are performed across the managed environment. External scans cover ISP-assigned IP addresses; internal scans cover all systems on the managed network. Findings are prioritized by severity and reported to Client. Patches and remediations that can be deployed automatically through our managed patching tools will be applied as part of this service.
Any vulnerability remediation requiring manual review, configuration changes, vendor coordination, or hands-on work is outside the scope of this service and will be billed separately at our then-current hourly rates.
Managed Persistent Threat Detection
Detection of persistent network footholds and deployment of ransomware canary files as early-warning tripwires.
Managed DNS Filtering
DNS-based blocking of malware, phishing domains, and configurable content categories. Includes real-time threat analysis of DNS requests.
Managed Phishing and Compromise Detection (M365)
Detects BEC indicators and Microsoft 365 login-page phishing attempts.
Managed SaaS Security
SaaS inventory and discovery; identification of high-risk or non-compliant cloud applications.
Security Incident & Event Monitoring — SIEM/SOC
SIEM correlates threat intelligence against network events to detect internal and external threats. An Initial Assessment defines monitoring scope prior to deployment. During the first 30 days, baselines are established and false positives may occur.
SIEM/SOC is a monitoring and alert service only; remediation is billed separately.
INTECH CYBERSECURITY — Optional Add-Ons
Managed Multi-Factor Authentication — Workstation and Server
MFA for on-premises computers and servers; advanced admin policy controls.
Managed Application Control
Zero-trust application execution platform. Establishes approved-application baseline, deploys anti-ransomware policies, enforces granular execution controls, and provides controlled user privilege escalation.
Managed Penetration Testing
Simulated attack testing performed at least annually:
- External: Internet-facing systems, networks, firewalls, devices, and web applications
- Internal: Post-access internal infrastructure and lateral movement risk
- PCI ASV: PCI DSS-compliant combined external/internal testing
See Penetration Testing / Vulnerability Scanning section for additional terms.
INTECH COMPLIANCE SIMPLICITY
Managed Information Security Program
Cyber liability insurance-aligned security program. Includes: named vCISO, annual cyber liability application assistance, formal Information Security Program creation and maintenance, annual Risk Assessments, Disaster Recovery and Incident Response Plans, Business Continuity Plan assistance, and third-party compliance requirements (privacy policies, fund transfer best practices).
Client Responsibility and Attestation
Client is solely responsible for implementing, maintaining, and attesting to its own information security program and for meeting any requirements imposed by its cyber liability insurance carrier, regulators, or contractual counterparties. Intech Hawaii's role is limited to providing program guidance, documentation support, and advisory services as described in this section. Client acknowledges and agrees that Intech Hawaii's provision of the Managed Information Security Program does not constitute legal, insurance, or compliance advice, and does not guarantee that Client will obtain, maintain, or successfully renew cyber liability insurance coverage or satisfy any insurer's underwriting requirements. Any advice or documentation provided by Intech Hawaii is for informational purposes only; Client should consult qualified legal and insurance counsel regarding its specific obligations. Intech Hawaii shall have no liability for Client's failure to obtain or maintain cyber liability insurance, or for any coverage denial, claim dispute, or regulatory action arising from Client's information security posture.
Last Updated: April 7, 2026