IMPORTANT: These Terms govern all access to and use of the 1600 Cyber platform and all engagements for cybersecurity consultancy, solutions, and training services. By accessing the platform or entering into any engagement with 1600 Cyber, you agree to be bound by these Terms. If you are accepting on behalf of a company or other legal entity, you represent that you have authority to bind that entity.
1. Parties, Definitions, and Scope
1.1 The Parties
These Terms and Conditions (“Terms”) govern your access to and use of the 1600 Cyber platform (“Platform”) at www.1600cyber.com and all cybersecurity consultancy, solutions, and training services (collectively, “Services”) provided by 1600 Cyber.
1600 Cyber (“Company”, “we”, “us”, “our”): 1600 Cyber GmbH, incorporated under German law, and 1600 Cyber America, incorporated in the United States, jointly doing business as 1600 Cyber. Registered offices: Rossmarkt 21, 60311 Frankfurt am Main, Germany; and 355 South Grand Avenue, Los Angeles, CA 90071, USA.
Client / Customer (“you”, “your”): Any business entity, organisation, government body, educational institution, or individual (including individual course buyers) who accesses the Platform or engages 1600 Cyber for Services under these Terms.
1.2 Definitions
“Services”: All cybersecurity consultancy, advisory, managed security, ISAO participation, cyber incident response, penetration testing, risk assessment, cybersecurity training, professional certifications (including GCIH and related programmes), digital forensics, and any other professional services provided by 1600 Cyber, whether delivered in person, remotely, or through the Platform.
“Platform”: The 1600 Cyber website at www.1600cyber.com and any associated subdomains, portals, course delivery systems, learning management systems (LMS), client portals, and digital tools through which Services are delivered or accessed.
“1600 Cyber Products”: All products, software tools, threat intelligence reports, training materials, course content, certifications, assessments, frameworks, methodologies, and deliverables created or provided by 1600 Cyber, including all updates and derivative works.
“Statement of Work” or “SOW”: A written document (including electronic purchase orders, engagement letters, or proposals accepted by the Client) specifying the scope, deliverables, timeline, and fees for a specific engagement. Each SOW is incorporated into and governed by these Terms.
“Confidential Information”: Any non-public information disclosed by one party to the other, whether oral, written, or electronic, that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and circumstances of disclosure, including but not limited to security vulnerabilities, assessment findings, client data, and proprietary methodologies.
“Intellectual Property Rights”: All patents, copyrights, trademarks, trade secrets, database rights, design rights, and all other intellectual property rights, whether registered or unregistered, subsisting anywhere in the world.
“Personal Data”: Any information relating to an identified or identifiable natural person, as defined under applicable data protection law including GDPR, UK GDPR, and the CCPA/CPRA.
2. Engagement Model and Statements of Work
2.1 How Engagements Are Formed
An engagement for Services is formed when: (a) 1600 Cyber and the Client execute a signed Statement of Work; (b) the Client accepts a 1600 Cyber proposal or quote in writing (including by email); or (c) the Client places an order through the Platform and 1600 Cyber confirms acceptance. Each engagement is subject to these Terms. In the event of conflict between a SOW and these Terms, the SOW prevails with respect to the specific engagement only.
2.2 Scope of Services
1600 Cyber will provide the Services as described in the applicable SOW. Any request for services outside the agreed scope constitutes a change request and must be agreed in a written change order before 1600 Cyber is obligated to perform additional work. 1600 Cyber reserves the right to decline any change request.
2.3 Client Obligations
The Client shall: (a) provide timely access to systems, personnel, and information reasonably required by 1600 Cyber to perform the Services; (b) ensure that any permissions or authorisations required for 1600 Cyber to perform security testing or assessments are obtained and documented prior to commencement; (c) designate a named point of contact for the engagement; and (d) review and approve deliverables within the timelines specified in the SOW. 1600 Cyber shall not be liable for delays caused by the Client’s failure to fulfil these obligations.
3. Training, Courses, and Certifications
3.1 Course Enrolment and Access
Individual course buyers and corporate training clients may enrol in 1600 Cyber training programmes, including GCIH preparation, cybersecurity fundamentals, AI and cyber awareness, and specialist training, through the Platform or via a SOW. Course access is granted for the period specified at enrolment. Access is personal and non-transferable.
3.2 No Resale of Training Materials — Explicit Prohibition
The resale, redistribution, sublicensing, or commercial exploitation of any 1600 Cyber training materials, course content, assessments, certifications, frameworks, or deliverables is expressly and absolutely prohibited. This prohibition applies to all 1600 Cyber Products regardless of format (digital, printed, recorded, or otherwise) and applies to both B2B clients and individual course buyers. Any attempted resale or unauthorised distribution constitutes a material breach of these Terms and will result in immediate termination of access, pursuit of all available legal remedies, and may constitute an infringement of 1600 Cyber’s Intellectual Property Rights subject to civil and criminal liability.
3.3 Certification and Assessment
Where 1600 Cyber training programmes lead to or prepare participants for professional certifications (such as GCIH), the Client acknowledges that: (a) certification examinations are administered by the relevant certifying body and are subject to that body’s own rules and terms; (b) 1600 Cyber provides preparation training and does not guarantee examination results; and (c) certification fees payable to the certifying body are separate from 1600 Cyber’s training fees unless expressly stated otherwise in a SOW.
3.4 Corporate Training Licences
Where a SOW grants the Client a corporate training licence for multiple participants, such licence is limited to the number of seats specified in the SOW and to the Client’s own employees or contractors. The Client may not grant access to its training licence to third parties, clients, or the general public without 1600 Cyber’s prior written consent.
4. Fees, Payment, and Cancellation
4.1 Fees
Fees for Services are as specified in the applicable SOW or as displayed on the Platform at the time of purchase. All fees are exclusive of applicable taxes (including VAT, GST, and sales tax), which will be added where required by applicable law and are the Client’s responsibility.
4.2 Payment Terms
Unless otherwise specified in a SOW: (a) invoices are due and payable within 30 days of the invoice date; (b) online course purchases are payable in full at the time of enrolment; (c) consultancy and managed service engagements may be invoiced monthly in arrears or according to milestones specified in the SOW. 1600 Cyber reserves the right to charge interest on overdue amounts at the rate of 1.5% per month (or the maximum rate permitted by applicable law, whichever is lower) from the due date until payment is received.
4.3 Cancellation and Refunds
Cancellation of consultancy engagements: the Client may cancel a SOW with 30 days’ written notice. Fees for work performed prior to cancellation are non-refundable. Where 1600 Cyber has committed resources in advance, a cancellation fee of up to 25% of the remaining SOW value may apply.
Cancellation of training enrolments: individual course buyers may request a refund within 14 days of purchase provided they have not accessed more than 20% of the course content. EU consumers have an additional statutory right of withdrawal of 14 days from the date of purchase, which is waived upon accessing digital content. Corporate training cancellations are subject to the terms of the applicable SOW.
5. Intellectual Property
5.1 1600 Cyber Intellectual Property
All Intellectual Property Rights in 1600 Cyber Products, methodologies, frameworks, tools, training materials, course content, software, and Platform content are and shall remain the exclusive property of 1600 Cyber and its licensors. These Terms do not convey any ownership interest or licence beyond the limited right to use the Services for the Client’s internal purposes as described herein.
5.2 Deliverables
Unless a SOW expressly states otherwise in writing, all deliverables produced by 1600 Cyber (including reports, assessments, recommendations, and custom training materials) are licensed to the Client for internal use only. The Client may not publish, distribute, or otherwise disclose deliverables to third parties without 1600 Cyber’s prior written consent. Underlying methodologies, frameworks, and tools used to produce deliverables remain the property of 1600 Cyber.
5.3 Client Data
The Client retains all ownership of its own data, systems, and information provided to 1600 Cyber for the purpose of performing Services. 1600 Cyber shall use Client data solely for the purpose of providing the agreed Services and shall not use Client data for any other purpose without explicit written consent.
5.4 No Resale or Commercial Exploitation
The Client shall not, and shall ensure that its employees, contractors, and affiliates do not: (a) sell, resell, sublicense, rent, lease, or otherwise transfer access to any 1600 Cyber Product or Service to any third party; (b) use any 1600 Cyber Product in connection with developing competing products or services; (c) reproduce, modify, or create derivative works of any 1600 Cyber training material, course, or tool; or (d) publish or disclose benchmarking results involving 1600 Cyber Products without prior written consent.
6. Confidentiality
6.1 Mutual Obligations
Each party agrees to: (a) hold the other party’s Confidential Information in strict confidence; (b) not disclose Confidential Information to any third party without the disclosing party’s prior written consent; and (c) use Confidential Information only for the purpose of performing or receiving the Services. Each party shall restrict disclosure of Confidential Information to its employees, contractors, and advisors who have a need to know and who are bound by confidentiality obligations at least as protective as these Terms.
6.2 Security Assessment Findings
Security assessment findings, penetration testing results, vulnerability reports, and threat intelligence reports are treated as the Client’s Confidential Information of the highest sensitivity. 1600 Cyber shall not disclose such findings to any third party without the Client’s prior written consent, except as required by applicable law or regulatory obligation.
6.3 Exceptions
Confidentiality obligations do not apply to information that: (a) is or becomes publicly available through no breach of these Terms; (b) was already known to the receiving party at the time of disclosure; (c) is independently developed by the receiving party without reference to the Confidential Information; or (d) is required to be disclosed by law, court order, or regulatory authority, provided that the receiving party gives the disclosing party prompt written notice and cooperates in seeking a protective order where possible.
6.4 Duration
Confidentiality obligations under this Section survive termination or expiration of these Terms for a period of five (5) years, and indefinitely with respect to trade secrets.
7. Security Testing and Authorisation
IMPORTANT: Any penetration testing, vulnerability assessment, social engineering exercise, red team engagement, or other active security testing performed by 1600 Cyber requires the Client’s prior written authorisation specifying the systems, IP ranges, and methods in scope. The Client is responsible for obtaining all necessary permissions from system owners, cloud providers, and third parties before authorising testing. 1600 Cyber will not perform testing outside the agreed scope under any circumstances.
The Client represents and warrants that it has the legal authority to authorise all testing described in the SOW and indemnifies 1600 Cyber against any claims arising from the Client’s failure to obtain required permissions.
8. Warranties and Representations
8.1 1600 Cyber Warranties
1600 Cyber warrants that: (a) it will perform Services with reasonable skill and care in accordance with applicable professional standards; (b) it has the right to grant the licences and access described in these Terms; and (c) it will comply with applicable data protection laws in processing any Personal Data provided by the Client.
8.2 Disclaimer
EXCEPT AS EXPRESSLY SET OUT IN SECTION 8.1, ALL SERVICES AND 1600 CYBER PRODUCTS ARE PROVIDED “AS IS” AND “AS AVAILABLE.” 1600 CYBER EXPRESSLY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. 1600 CYBER DOES NOT WARRANT THAT SERVICES WILL IDENTIFY ALL VULNERABILITIES, PREVENT ALL CYBERATTACKS, OR THAT RECOMMENDATIONS WILL RESULT IN A SPECIFIC SECURITY OUTCOME. CYBERSECURITY INVOLVES INHERENT RISKS THAT CANNOT BE ELIMINATED AND 1600 CYBER’S SERVICES REDUCE BUT DO NOT ELIMINATE THOSE RISKS.
9. Limitation of Liability
9.1 Exclusion of Consequential Loss
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY SHALL BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS OPPORTUNITY, OR BUSINESS INTERRUPTION, HOWEVER CAUSED AND UNDER ANY THEORY OF LIABILITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
9.2 Cap on Liability
SUBJECT TO SECTION 9.3, 1600 CYBER’S AGGREGATE LIABILITY TO THE CLIENT FOR ALL CLAIMS ARISING OUT OF OR RELATED TO A SPECIFIC ENGAGEMENT SHALL NOT EXCEED THE TOTAL FEES ACTUALLY PAID BY THE CLIENT TO 1600 CYBER UNDER THE APPLICABLE SOW IN THE TWELVE MONTHS IMMEDIATELY PRECEDING THE CLAIM. FOR INDIVIDUAL COURSE BUYERS, LIABILITY IS CAPPED AT THE COURSE FEES PAID.
9.3 Exceptions to Cap
The liability cap in Section 9.2 does not apply to: (a) death or personal injury caused by 1600 Cyber’s negligence; (b) fraud or fraudulent misrepresentation; (c) wilful misconduct or gross negligence; (d) breach of confidentiality obligations; or (e) any liability that cannot be excluded or limited by applicable law.
10. Indemnification
The Client shall indemnify, defend, and hold harmless 1600 Cyber and its affiliates, officers, directors, employees, contractors, and agents from and against any claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or relating to: (a) the Client’s breach of these Terms or any SOW; (b) the Client’s failure to obtain required authorisations for security testing; (c) the Client’s use of 1600 Cyber deliverables in a manner inconsistent with these Terms; or (d) the Client’s violation of applicable law or the rights of any third party.
11. Data Protection and GDPR Compliance
11.1 Data Processing Roles
Where 1600 Cyber processes Personal Data on behalf of the Client in the course of providing Services (for example, where Client employee data is included in training enrolments or security assessments), 1600 Cyber acts as a data processor and the Client acts as data controller. In such cases, the parties shall enter into a Data Processing Agreement (DPA) in accordance with GDPR Article 28. Where 1600 Cyber processes Personal Data for its own purposes (such as managing the Client relationship), 1600 Cyber acts as data controller and processes such data in accordance with its Privacy Policy at www.1600cyber.com/privacy-policy.
11.2 GDPR Compliance — EU and UK Clients
Both parties shall comply with their respective obligations under the GDPR (Regulation (EU) 2016/679), the UK GDPR, and applicable national implementing legislation with respect to any Personal Data processed in connection with the Services. Where Personal Data is transferred outside the EEA or UK, the parties shall implement appropriate transfer safeguards (including Standard Contractual Clauses where required) prior to such transfer.
11.3 Security of Client Data
1600 Cyber shall implement and maintain appropriate technical and organisational measures to protect Personal Data and Client Confidential Information against unauthorised access, disclosure, alteration, or destruction, consistent with the sensitivity of the data and applicable legal requirements. 1600 Cyber shall notify the Client without undue delay (and in any event within 72 hours) upon becoming aware of any Personal Data breach affecting Client data, and shall cooperate with the Client in meeting its breach notification obligations.
12. Governing Law and Dispute Resolution
12.1 Governing Law
These Terms shall be governed as follows:
- EU / EEA clients: the laws of Germany apply; disputes subject to the exclusive jurisdiction of the courts of Frankfurt am Main, Germany.
- UK clients: the laws of England and Wales apply; disputes subject to the exclusive jurisdiction of the English courts.
- US clients and all other clients: the laws of California, USA apply; disputes subject to the exclusive jurisdiction of the courts of Los Angeles County, California.
12.2 Dispute Resolution
Before initiating formal proceedings, the parties shall attempt in good faith to resolve any dispute through escalation to senior management of both parties within 30 days of written notice of the dispute. If unresolved, disputes shall be referred to binding arbitration as follows: (a) EU/UK: Deutsche Institution für Schiedsgerichtsbarkeit (DIS) rules for EU disputes; London Court of International Arbitration (LCIA) rules for UK disputes; (b) US: American Arbitration Association (AAA) Commercial Arbitration Rules. Nothing in this Section prevents either party from seeking emergency injunctive or interim relief from a court of competent jurisdiction.
12.3 Class Action Waiver — US Clients
For US clients, all disputes must be resolved individually. Neither party may bring or participate in any class action, class arbitration, or representative proceeding.
13. Term, Termination, and Suspension
These Terms take effect when you first access the Platform or enter into an engagement with 1600 Cyber and continue until terminated. Either party may terminate for material breach if the breach is not cured within 30 days of written notice. 1600 Cyber may suspend access to the Platform immediately without notice if: (a) you fail to make payment when due; (b) your use of the Platform creates a security risk; or (c) 1600 Cyber is required to do so by law. On termination, all licences granted to you immediately cease, outstanding fees become immediately due and payable, and each party shall return or destroy the other’s Confidential Information upon request. Sections 5, 6, 8, 9, 10, 11, and 12 survive termination.
14. General Provisions
14.1 Entire Agreement
These Terms, together with any applicable SOW, Data Processing Agreement, and the 1600 Cyber Privacy Policy, constitute the entire agreement between the parties regarding the subject matter and supersede all prior agreements, representations, and understandings. Any pre-printed terms on a Client’s purchase order or procurement document are expressly rejected and shall have no effect.
14.2 Force Majeure
Neither party shall be liable for any failure or delay in performing its obligations to the extent caused by events outside its reasonable control, including acts of God, war, terrorism, pandemic, government action, or failure of third-party infrastructure, provided the affected party gives prompt written notice and uses reasonable efforts to resume performance.
14.3 Severability and Waiver
If any provision is found unlawful or unenforceable, it is severed without affecting the remaining provisions. No waiver of any right or remedy is effective unless in writing.
14.4 Modifications
1600 Cyber reserves the right to update these Terms at any time. Material changes will be notified by email and posted on the Platform with at least 30 days’ advance notice. For existing SOWs, changes take effect on renewal unless the Client provides written objection within 30 days of notice.
14.5 Contact
- Legal enquiries: legal@1600cyber.com
- EU Office: Rossmarkt 21, 60311 Frankfurt am Main, Germany
- US Office: 355 South Grand Avenue, Los Angeles, CA 90071, USA