Establishing secure connection…Loading editor…Preparing document…

Business Phishing Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

BUSINESS PHISHING AGREEMENT

Parties

This Business Phishing Agreement (the Agreement) is made and entered into effective as of (Effective Date) between (Client) and (Service Provider).

WHEREAS

WHEREAS, Client seeks to assess and improve employee awareness of phishing and related social engineering threats through controlled simulated phishing campaigns and training; and

WHEREAS, Service Provider is engaged in the business of designing and executing simulated phishing exercises, providing training, reporting, and remediation recommendations and represents that it has the requisite expertise and resources to perform such services in accordance with this Agreement; and

NOW, THEREFORE, in consideration of the mutual covenants and agreements contained herein, the parties agree as follows:

Scope of Work

Service Provider shall perform phishing simulation and related services as set forth below. Deliverables and specific tasks shall include design of phishing templates, controlled distribution to designated recipients, capture and secure storage of engagement metrics, analysis, and a post-campaign report with remediation recommendations.

Payment Terms

In consideration for the services rendered by Service Provider, Client shall pay the fees and expenses set forth below in accordance with the following terms.

Term and Termination

This Agreement shall commence on and shall continue until unless earlier terminated in accordance with this Section.

Either party may terminate this Agreement for convenience upon written notice to the other party given at least days prior to the effective date of termination. Either party may terminate immediately for material breach by the other party that remains uncured for a period of ten (10) business days following written notice of such breach.

Confidentiality

Each party shall hold in strict confidence all Confidential Information disclosed by the other party. "Confidential Information" includes non-public business information, test results, employee data, simulated credential captures, and remediation plans. Confidential Information shall not include information that is (i) publicly available at the time of disclosure; (ii) rightfully received from a third party without a duty of confidentiality; or (iii) independently developed without use of the other party’s Confidential Information.

Service Provider shall implement and maintain reasonable technical and organizational measures to protect Confidential Information. In the event Service Provider is legally compelled to disclose Confidential Information, Service Provider shall provide prompt written notice to Client to allow Client to seek a protective order or other appropriate remedy.

Upon termination or expiration of this Agreement, Service Provider shall, at Client's election, securely return or destroy Client data and provide written certification of destruction within thirty (30) days.

Reporting and Remediation

Service Provider will provide a written campaign report summarizing methodology, engagement metrics, vulnerabilities observed, and prioritized remediation recommendations. Reports shall not include live credential data in a manner that exposes sensitive information; any captured credentials must be redacted or securely destroyed in accordance with the Data Handling and Retention obligations.

Indemnification and Limitation of Liability

Each party shall indemnify, defend and hold harmless the other party from and against any third-party claims arising from the indemnifying party’s gross negligence, willful misconduct, or material breach of this Agreement. EXCEPT FOR LIABILITY ARISING FROM A PARTY’S GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR BREACH OF CONFIDENTIALITY, NEITHER PARTY SHALL BE LIABLE FOR INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL OR PUNITIVE DAMAGES, AND EACH PARTY'S AGGREGATE LIABILITY FOR ANY CLAIM ARISING OUT OF THIS AGREEMENT SHALL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CLIENT TO SERVICE PROVIDER UNDER THIS AGREEMENT DURING THE TWELVE (12) MONTH PERIOD PRECEDING THE EVENT GIVING RISE TO LIABILITY.

Governing Law

This Agreement shall be governed by and construed in accordance with the laws of the state specified below without regard to conflict of law principles.

Entire Agreement

This Agreement, including all exhibits and attachments incorporated herein, constitutes the entire agreement between the parties with respect to the subject matter hereof and supersedes all prior and contemporaneous agreements, understandings, negotiations and discussions, whether oral or written. Any amendment or modification to this Agreement must be in writing and signed by authorized representatives of both parties.

Miscellaneous

If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect. Neither party may assign this Agreement without the prior written consent of the other party, except that Service Provider may assign to an affiliate or successor in interest in connection with a merger or sale of substantially all of its assets.

Client:

By:

Date:

Service Provider:

By:

Date:

Enter text✕

What a Business Phishing Agreement Covers

A Business Phishing Agreement is a written contract that authorizes and governs simulated phishing campaigns performed by internal teams or external vendors. It defines scope, authorized targets, permissible techniques, notice procedures, data collection limits, breach handling, confidentiality, and liability. The agreement also addresses privacy safeguards for any personal data collected during tests and describes reporting, remediation obligations, and permitted record retention. When executed electronically the agreement should meet ESIGN and applicable state UETA/ESRA standards to ensure enforceability for interstate and intrastate transactions.

Why use a formal phishing test agreement

A clear agreement reduces legal and operational risk by documenting consent, scope, and limits; protects sensitive data; sets remediation timelines; and assigns responsibilities for reporting and follow-up in case of accidental data exposure or adverse employee impact.

Why use a formal phishing test agreement

Who typically signs and implements these agreements

Organizations use this agreement when authorizing simulated phishing to ensure legal clarity and operational safety before tests begin.

  • Internal Security/IT teams: Authorize scope, configure campaigns, and handle technical containment and reporting.
  • HR and Compliance teams: Manage employee notice, disciplinary process alignment, and privacy impact assessments.
  • Third-party security vendors: Provide testing services under defined limits and data-handling obligations.

Core components to include in the agreement

A comprehensive Business Phishing Agreement organizes operational, legal, and privacy controls so tests are deliberate, documented, and defensible.

Scope of Testing

Define campaign types, target populations, permitted channels, and exclusions such as executive accounts or regulated data stores to limit unintended impact and legal exposure.

Authorization

Name authorized signers and approval process, including internal approvals, vendor attestations, and any required board or executive sign-off for sensitive programs.

Targeting Rules

Specify targeting limits, explicit opt-outs, and procedures for excluding sensitive groups such as HR, legal, or high-risk operational staff.

Data Handling

Detail what data is collected, retention windows, anonymization standards, encryption, and deletion procedures to protect personal data and PHI.

Reporting & Remediation

Set timelines for delivering results, notification protocols for compromised credentials, and remediation steps for users and systems following findings.

Liability & Indemnity

Allocate risk for accidental outages, third-party claims, or regulatory exposure and include insurance, indemnity, and limitation of liability provisions.

Essential fields to capture in the agreement

Company Legal Name: Enter registered business name
Authorized Signer: Name and title of signer
Contact Information: Phone, email, and address
Test Dates: Start and end dates
Target Groups: Employee cohorts defined
Data Types: Identifiers and PHI flags

How to complete a Business Phishing Agreement

Follow a short, ordered process to prepare, authorize, and record simulated phishing activities so tests begin with documented consent and controls.

  • 01
    Prepare Scope: Draft objectives and exclusions
  • 02
    Get Approvals: Obtain signatures from security, HR, and legal
  • 03
    Configure Test: Set templates, targets, and timing
  • 04
    Record Results: Deliver report and remediate issues

Typical online configuration settings

When configuring the agreement and campaign online, use consistent settings for authentication, notifications, and record storage to preserve an audit trail.

Field Configuration
Notification Method Email template and delivery timing
Authentication Email link, SMS code, or KBA
Audit Trail Enable timestamps and IP logging
Storage Location Encrypted cloud or secure archive

Where to send signed agreements and reports

Signed agreements and campaign records should be routed to centralized owners and retained under the organization’s records policies for compliance and audit.

  • Security Repository: Store master agreement copies
  • HR Records: File consent and notice copies
  • Vendor Portal: Upload executed vendor agreements
  • Legal Archive: Retain signed contract versions

Digital signing and file format notes

Use a secure eSignature workflow and file formats that preserve integrity and an auditable trail when executing this agreement electronically.

  • Accepted Formats: PDF and DOCX preferred
  • Audit Trail: Timestamps, IP, and signer metadata
  • Authentication: Email link, SMS or stronger

Operational timelines and expected processing windows

Establish clear timing for approvals, campaign notice, remediation, and reporting so stakeholders know when actions must occur and results will be delivered.

Approval Window:

Obtain internal approvals 3–10 business days before testing

Notice Period:

Provide 7–14 days internal notice when applicable

Run Window:

Limit campaigns to specified start/end dates

Report Delivery:

Deliver findings within 7 business days post-campaign

Remediation Timeline:

Address critical issues within 48–72 hours

Common mistakes to avoid

  • Failing to document explicit authorization or signer authority, which can expose the organization to legal challenges or internal disputes.
  • Testing without excluding sensitive accounts or systems, risking service disruption or unintentional data exposure to unauthorized personnel.
  • Neglecting privacy controls or anonymization for collected results, which may create regulatory exposure if personal data or PHI are captured.
  • Using weak or inconsistent authentication for results access, causing gaps in the audit trail and difficulty proving attribution.

Potential penalties and compliance risks

Regulatory Fines: Possible fines for data breaches
HIPAA Exposure: PHI mishandling can trigger HIPAA liability
Employment Claims: Disciplinary disputes if processes unclear
Service Disruption: Testing may cause system outages
Reputational Harm: Loss of trust with staff or customers
Contract Breach: Vendor or customer contract violations

Sample eSignature pricing and capability snapshot

Compare common vendor pricing and basic capabilities relevant when selecting an eSignature platform to execute and retain Business Phishing Agreements.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial, no credit card Varies Varies Varies Varies
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No

Frequently asked questions about Business Phishing Agreements

Answers address common legal, operational, and privacy questions to help ensure your agreement is enforceable and aligned with organizational controls.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users