Managed IT
Your entire IT function, run as one accountable service
We take ownership of the day to day: user accounts, devices, software, licences and the small requests that quietly consume a working week. One agreement covers the whole environment, so nothing falls between two vendors and one named engineer stays accountable for it.
What is included
- Employee onboarding and offboarding completed within one business day
- Device provisioning, imaging and lifecycle tracking for laptops, desktops and mobiles
- Licence management with a quarterly review of what you are actually paying for
- Patching and update windows scheduled outside your working hours
- A live asset register and network documentation you can export at any time
- A named lead engineer and a named backup who both know your environment
Network Management
Wired, wireless and remote access that stays predictable
Networks fail slowly before they fail loudly. We watch throughput, saturation and error rates continuously, so degradation is caught as a trend on a chart rather than reported to us as an outage by your staff.
What is included
- Firewall, switch and access point configuration, hardening and firmware management
- Continuous monitoring of uptime, latency, packet loss and bandwidth saturation
- Segmented guest, staff and device networks with documented access rules
- Encrypted remote access for hybrid, travelling and contract staff
- Structured cabling and circuit coordination handled directly with your carrier
- Capacity reporting, so upgrades are planned rather than triggered by a failure
Cloud Management
Microsoft 365, Google Workspace and public cloud, kept tidy
Cloud spend drifts and permissions sprawl, usually without anyone deciding it should. We manage tenancy configuration, identity and cost as an ongoing discipline, and show you the bill line by line every month.
What is included
- Microsoft 365 and Google Workspace tenant administration and hardening
- Identity, single sign-on and conditional access policy management
- Azure and AWS workload management, resource tagging and right-sizing
- Monthly cost review naming the line items that changed and why they changed
- Migration planning and execution with a written rollback position agreed first
- Shared mailbox, file share and permission audits every quarter
Cybersecurity
Layered defence, and a rehearsed plan for the day it matters
Security is a set of habits rather than a product purchase. We run the controls, produce the evidence that they are working, and rehearse the response with your leadership team before anyone needs it.
What is included
- Managed endpoint detection and response on every company device
- Email filtering and domain authentication with SPF, DKIM and DMARC enforced
- Multi-factor authentication applied across every business system, without exception
- Vulnerability scanning with a prioritised, dated remediation plan
- Security awareness training and quarterly phishing simulations for all staff
- A written incident response plan, tested annually with your leadership team
Backup and Disaster Recovery
Backups that are tested, not merely scheduled
An untested backup is a hope. We hold immutable copies away from your production environment, restore from them on a fixed schedule, and give you the measured recovery times in writing rather than the vendor advertised ones.
What is included
- Immutable, off-site backups for servers, endpoints and cloud data
- Documented recovery time and recovery point objectives for every system
- Quarterly test restores, with the measured results sent to you in writing
- Retention that a compromised administrator account cannot delete
- Microsoft 365 and Google Workspace backup, which those platforms do not provide
- A disaster recovery runbook naming who does what, in what order
Monitoring and Helpdesk
Constant eyes on the estate, and a human on every ticket
Most of what we fix, you never hear about. What is left reaches a helpdesk with published response targets, no phone tree, and engineers who can see your documentation before they pick up.
What is included
- Monitoring of servers, endpoints, network hardware and cloud services around the clock
- Automated remediation for the recurring faults that do not need a person
- Helpdesk by phone, email and chat with published response targets per priority
- Every ticket visible to you in a portal, from the moment it opens until it closes
- An escalation path printed in your agreement, up to and including the founders
- A monthly report showing ticket volume, root causes and what we changed to reduce them
Compliance Support
Evidence gathered as you go, not in the week before the audit
We do not sell certifications and we will not claim to grant one. We run the technical controls your framework asks for and keep the evidence current, so an audit or a client questionnaire becomes a retrieval job instead of a project.
What is included
- Control mapping for HIPAA, PCI DSS, SOC 2 and CMMC readiness
- Access reviews, log retention and change records kept continuously audit-ready
- Written policies covering acceptable use, access control and incident response
- Evidence collected throughout the year rather than reconstructed at the deadline
- Support answering client, insurer and prospect security questionnaires
- Direct coordination with your auditor, assessor or compliance counsel
Vendor Management
One number to call, whoever the problem turns out to belong to
When the phone system, the line-of-business application and the internet circuit all point at each other, we take the call and chase it to a resolution. You stop being the middle of that conversation.
What is included
- A single point of contact for carriers, phone systems and software vendors
- We open, chase and close third-party tickets on your behalf
- A renewal calendar, so contracts are reviewed before they quietly auto-renew
- Contract and licence review measured against what your team actually uses
- Vendor performance tracked and reported alongside our own numbers
- Procurement support with quotes compared line by line before you sign
The exclusions
What the monthly rate does not cover.
Every managed services agreement has exclusions. Most providers put them in an appendix. We would rather put them on the services page, because an exclusion discovered at invoice time is the fastest way to lose a client we would like to keep.
- Hardware and third-party licences, which are quoted at cost with our margin shown separately
- Project work such as migrations, office moves and new site builds, quoted before it starts
- Application development and in-house software support, though we will manage the vendor for you
- Anything we have not documented and tested, because supporting an unknown system is a promise we cannot keep
Everything above is quoted in writing and approved by you before any work begins.
Tell us which of these you are missing.
Send us the shape of your environment and we will come back with the services that genuinely apply to it, priced per user, with the exclusions written just as plainly.