Your sessions expired. But your deployment didn't finish

Why a Miami-based, Palo Alto Networks certified partner rewrote the services clauses that make cybersecurity deployments stall.
By Omar Gonzalez, PS Consultant Manager at Netdata Cybersecurity
The purchase order is signed. The licenses are provisioned. And somewhere in a spreadsheet, a clock starts running.
This is the part of a cybersecurity project nobody puts in the datasheet. A platform gets bought on the strength of its capabilities, and then delivery gets bought as a block of hours — a package of sessions with an expiration date attached. From that moment, two clocks run against each other: the partner’s, which wants the hours consumed, and the customer’s, which wants them saved for when things get hard.
Read the fine print of a typical services agreement
You will usually find two clauses doing the same job in different words:
- Sessions not consumed in the allocated month expire, are forfeited, and do not carry over.
- Working Sessions not consumed during the Term expire, and the provider has no further obligation to provide the Services.
Read individually, each looks like reasonable scheduling hygiene. Read together, they put the delivery risk on the customer, including risk the customer cannot control.
A change-control board pushes a maintenance window. A network team gets pulled onto an incident. Neither is a failure of the security project, and both cost the customer sessions they already paid for.
The rational response is to hoard: schedule less, ask for less, keep the balance in reserve, which is how a platform ends up licensed, half-configured, and quietly under-used.

What we changed
SOver the past year we went back through our own service descriptions and removed the punitive machinery. Three changes, and they are contractual, not goodwill.
- A recommended cadence, not a minimum
Every engagement still establishes a session cadence at kickoff, because momentum is real and a project with no rhythm doesn’t finish. But that cadence is a recommendation calibrated to the customer’s objectives, and it can be realigned by the project manager and consultant as the work reveals itself. - Late cancellations get rescheduled, not forfeited
When a session has to move, both parties work together to reschedule it at the earliest available opportunity. We still ask for advance notice, and we are still explicit that we can’t be held responsible for delays we didn’t cause, but the consequence of a cancellation is a new date, not a lost session. - A no-cost extension to finish committed scope
At the end of the term, remaining sessions are reviewed jointly and a no-cost extension may be agreed so the committed scope gets completed. This clause is what makes the other two mean something, and it only works because “committed scope” is written down precisely enough to be finished. How we get to that level of precision before a quote is even issued is the subject of the companion piece to this article, on our delivery methodology.
Why this is how we’re entering the U.S. market
Netdata Cybersecurity is a Palo Alto Networks certified partner with a delivery practice built across the Americas and a U.S. presence in Miami.
Our differentiation isn’t a claim about the depth of our bench, although the certifications are there and public. It’s that we were willing to change the commercial mechanics of professional services until they stopped working against the outcome.
A methodology is easy to publish. What’s hard is signing a contract that doesn’t punish a customer for having a real environment, with real change control and real competing priorities. That’s the part we rewrote.

Ready to improve your security?
Discover how to protect your investment with our expert support.
