How we work

Assess. Plan. Protect. Perform

Four stages, in order. It is the sequence our name is built on and the only sequence that produces a technology environment somebody can be held accountable for.

A team working through a plan on a large wall display
Why an order

You cannot protect what nobody has counted

The most common failure in managed services is starting at stage three. A provider is appointed, agents are deployed, tickets start flowing, and eighteen months later somebody asks a question — how many servers do we have, when does that contract expire, has a restore ever been tested — that nobody can answer.

It is not incompetence. It is a sequence problem. Protection deployed onto an environment nobody has inventoried protects the parts that happened to be visible.

So we start by counting. Every asset, identity, licence, contract and control. It is unglamorous, it takes two weeks, and everything afterwards depends on it.

The four stages

What each stage produces

Every stage ends in a document. If a stage produces nothing you can read, it did not happen.

  1. Assess
    Two weeks, fixed fee

    We inventory every asset, identity, licence, contract and control. We test your backups by restoring from them. We score you against the Essential Eight. We interview the people who use the systems, not only the people who run them.

    You receive: a written position on your environment, an Essential Eight maturity score with the finding behind each result, a risk register, and a prioritised list of what we would fix first. Yours to keep, whether or not you engage us — including if you take it to another provider.

  2. Plan
    Two weeks

    Findings become a costed, sequenced roadmap. Each item carries an effort estimate, a licence cost where one applies, a business impact rating, and the consequence of deferring it. Split into this quarter, this financial year, and what needs a capital decision.

    You receive: a three-year roadmap, an annual budget you can take to a board, and a fixed-price proposal for the services you have chosen — with the services we think you do not need marked as such.

  3. Protect
    Four to twelve weeks

    Transition and uplift, run in parallel with your incumbent so nothing depends on their goodwill. Monitoring and backup are verified on our side before the service desk cuts over. Controls are staged with pilot groups and documented rollbacks.

    You receive: a documented environment, an updated control register, a tested backup and restore position, and a written incident response plan with real names and phone numbers in it.

  4. Perform
    Ongoing

    Steady state. Service desk, monitoring, patching, detection and response, and a reporting rhythm that does not require you to ask. The roadmap is revised each quarter against what actually happened.

    You receive: a monthly service and security report, a quarterly business review with your leadership, and an annual reassessment against the Essential Eight so the score is earned again rather than assumed.

A planning wall of stage cards being worked through
Onboarding

The first ninety days, week by week

Transitions go wrong in predictable places. This is how we sequence it so the risky parts happen while your incumbent is still contracted.

Onboarding timeline by week
When What happens What you do
Weeks 1–2 Discovery and assessment. Read-only access to your environment, asset and identity inventory, backup restore test, Essential Eight scoring, staff interviews. Provide access, introduce us to your key people, and tell us what annoys you most.
Weeks 3–4 Findings presented, roadmap and budget drafted, service agreement finalised, containment authority and escalation contacts agreed. Review the findings, set the target maturity level, sign or walk away.
Weeks 5–6 Tooling deployed in parallel: monitoring agents, EDR, backup. Documentation built. Your incumbent remains live throughout. Give notice to your existing provider at a time of your choosing.
Weeks 7–8 Service desk cutover. Staff communication, portal access, a short how-to-log-a-ticket session, and an on-site presence for the first days. Tell your people. We provide the wording.
Weeks 9–12 Priority remediation from the roadmap: MFA gaps, patching backlog, backup coverage, local administrator rights, and anything rated critical. Approve the change windows and the two or three decisions only you can make.
Day 90 First quarterly business review: what we found, what we fixed, what moved on the maturity score, and what is next. Ninety minutes with your leadership team.

Scroll the table sideways to see every column.

In writing

Six commitments, and how you can hold us to them

Every one of these appears in the agreement. A commitment that only exists on a website is marketing.

  • We report honestly, including when it is our fault. Missed SLA targets, failed restore tests and incidents we could have prevented appear in your monthly report.
  • We tell you what you do not need. Every roadmap includes items marked as deferrable or unnecessary, with reasons.
  • Your data and documentation are yours. Exported on request, in a usable format, at any time — not only at termination.
  • Your tenants and licences stay in your name. We hold delegated access you can revoke yourself in under a minute.
  • Exit assistance is priced before you sign. Documentation handover, admin transfer, agent removal and knowledge transfer, at a rate agreed at the start.
  • Twelve months, then month to month. If we stop earning it, leaving should be a decision rather than a project.
Fit

When we are not the right choice

Being wrong about fit costs both of us more than saying so early.

  • If you want the cheapest quote, there will always be one lower than ours, and it will not include restore testing.
  • If you need hourly break-fix with no ongoing agreement, a smaller local provider will serve you better and cost you less.
  • If you are under 10 seats, the assessment is usually more rigour than you need. We will tell you what to fix and point you somewhere sensible.
  • If you need 24/7 on-site presence or specialised industrial control system expertise, that is a different kind of provider.
  • If the goal is a tick in a box for a tender without changing anything, we are not useful to you.
  • If your leadership will not attend the reviews, the advisory half of this model does not work and you should not pay for it.

Start where everyone starts

Two weeks, a fixed fee, and a written position on your environment. No obligation to go any further.