We are a 15-person software and data analytics agency based in Dubai. We are on the verge of signing a 450,000 AED annual service contract with a large enterprise client based in Abu Dhabi. However, their procurement and compliance departments just handed us a 40-page vendor security agreement. One clause explicitly mandates maintaining a 24/7 active cyber incident response team with a guaranteed response time of under 2 hours in the event of an incident.
Our entire annual IT and infrastructure budget is only around 30,000 AED. Even hiring a single full-time security specialist is completely out of reach at our scale, let alone building an in-house shift team, which would wipe out all the profit from this deal. Meanwhile, their account rep claims this clause is standard corporate procedure and cannot be waived.
How do small vendors like us actually fulfill these kinds of enterprise requirements? Is there a legitimate, accepted way to pass this audit without building a dedicated internal team?