Managed IT
One price per user, security included
Cyber-first managed IT. One price per user, every inclusion documented, and the security controls that most providers sell as extras switched on from day one. Three tiers on the same IT service: what escalates is how far the security and the governance go.
Most IT is paid for reactively and priced unpredictably
The common model waits for things to break. You call, it gets fixed, the root cause stays, and the same issue returns next month because nobody asked why. Multi-factor authentication, endpoint detection and conditional access are quoted as premium extras when they are the minimum standard for operating at all.
Meanwhile the invoice moves. Hourly add-ons, callout fees, project charges, and a scope vague enough that every disagreement is a negotiation.
None of that is a technology problem. It is a commercial model built around the provider rather than the customer, and it is the thing Cyber365 replaces.
Secure, operate, prove
The IT service is the same in all three tiers. Twenty-four inclusions do not change: the support team, the triage team, monitoring, patching, incident and change management. What the tiers buy is how far the security and the governance go.
-
Core
$130
per user per month
24 inclusions
Cyber-first managed IT. Security from day one rather than as an upsell.
- Security on from day one Multi-factor authentication, endpoint detection, conditional access and automated patching, active from onboarding. Not quoted separately.
- Structured problem management A dedicated triage team resolves at the source, and every major incident gets a root cause. Problems are prevented from recurring rather than patched over.
- 24/7/365 monitoring with real escalation Every endpoint and server watched around the clock, with automated remediation or a human. Nothing waits in a queue for Monday.
- One price per user Every inclusion documented, unlimited tickets in business hours, no callout fees. Servers and network devices are quoted separately so a heavy environment does not distort a light one.
-
Protect
+$60
per protected device per month, on top of Core
35 inclusions
Security stops being something you hope for and becomes something you operate.
Everything in Core, plus
- Endpoint protection upgraded The platform steps up from Huntress to SentinelOne: a managed 24/7 security operations centre, behavioural detection, and autonomous rollback of an endpoint to its pre-attack state if ransomware executes.
- Default-deny execution Application control and ringfencing, so unapproved software does not run and PowerShell and browsers cannot reach what they should not. Your environment is learned first.
- The people, measured Quarterly awareness training with continuous phishing simulation, behaviour risk scoring, and adaptive content aimed at whoever needs it most.
- Microsoft 365 backup with seven-year retention Daily across Exchange, SharePoint, OneDrive and Teams, with file-level recovery tested rather than promised.
- Credential exposure watched Dark web monitoring on your domains, with a forced reset triggered before an exposed password can be used.
-
Fortify
+$110
per protected device per month, on top of Core. Includes Protect
45 inclusions
Core and Protect secure the operation. Fortify is where you can prove it.
Everything in Protect, plus
- Essential Eight ML2 alignment All eight strategies aligned to the letter of the ASD guidelines at Maturity Level 2, with strategy scoring, trend analysis and gap identification as part of delivery.
- Full vulnerability ownership Hourly scanning, risk-based prioritisation, and remediation we carry out. Not a report left on your desk.
- Managed SIEM and XDR Telemetry correlated across the environment with behavioural analytics and 365 days of retention. Every threat investigated and actioned.
- Board-level risk reporting Twice-yearly packs that translate technical risk into business language, with prioritised actions. Written for the boardroom rather than the server room.
- Independent testing and hardening Virtual penetration testing, privileged access management, user application hardening, and Microsoft Secure Score improvement tracked quarterly.
Core is the base, and you add one of Protect or Fortify to it. Not both: Fortify already includes everything in Protect. Core is priced per user. Protect and Fortify are priced per protected device, so the two figures are not directly comparable. A server counts as a protected device. Server and network device management is quoted separately as standard. Cyber365 carries a minimum of twenty billable seats. Quotes below twenty are billed at twenty. Below that size, Cyber365 Flex pairs the same managed baseline with consumable support instead of a fixed inclusion list, and is usually the better fit. No tier is quoted below the list price of the tier beneath it. Onboarding is quoted separately and is not discounted. Twelve-month term with the rate fixed for the term.
What it costs
Enter your user count for the annual and monthly figure on each tier. The inclusion count beside it is the part that matters.
- Core $130 per user per month
- Protect $190 per user per month
- Fortify $240 per user per month
Indicative only, excluding GST. Nothing you type here is sent anywhere or recorded.
Everything in each tier
The complete list, so you can check rather than ask. Every item is included in the per-user price.
Core 24
- Dedicated IT support team
- Dedicated triage team
- 24/7/365 monitoring and alerting
- SLA-backed response times
- Incident and problem management
- Change management
- Endpoint detection and response
- Multi-factor authentication
- Conditional access policies
- Email filtering (Defender)
- OS and application patching
- Infrastructure patch management
- Active Directory management
- Vendor coordination and escalation
- Asset tracking and inventory
- Service desk portal
- Quarterly service reviews
- Device compliance reporting
- Teams calling management
- AV conferencing support
- Backup monitoring
- VPN connectivity support
- ISP liaison and escalation
- Procurement services
Protect adds 11
- Enhanced 24/7 endpoint protection
- Autonomous ransomware rollback
- Security awareness training
- Simulated phishing campaigns
- Microsoft 365 backup (7 year)
- Application control and ringfencing
- Dark web monitoring
- Strategic business reviews
- Alignment engineering
- Behaviour risk scoring
- Default-deny execution policies
Fortify adds 10
- Essential Eight ML2 alignment
- Privileged access management
- Vulnerability management
- SIEM / XDR (365-day retention)
- User application hardening
- Virtual penetration testing
- Secure Score improvement
- Board-level risk packs
- Budget planning and consultation
- Strategic planning and guidance
Full descriptions, inclusions, exclusions and SLA detail are in the Cyber365 Service Schedule, which is the contractual document and is provided with any proposal.
It starts with one click
None of the steps below are technically difficult, and none of them depend on a sophisticated attacker. Every one of them is a control that was either in place or was not.
-
9:47 AM
Your accounts receivable clerk opens an email that looks like it is from your bank. It is not. Credentials harvested in seconds.
-
9:48 AM
The attacker signs in to your Microsoft 365 environment from an unrecognised device. No multi-factor prompt. No conditional access. No alert.
-
10:15 AM
Inbox rules created silently. Mail from your bank, your clients and your leadership team is being forwarded externally. Nobody notices.
-
11:30 AM
SharePoint accessed. Client contracts, financial records, employee data, downloaded in minutes. Still no alerts.
-
3:45 PM
A fraudulent payment instruction is sent from your CFO’s mailbox to accounts. It references a real invoice. $187,000 goes to an offshore account.
-
Day 3
Your IT provider finds the breach. They cannot tell you what was taken, because there are no logs.
-
Day 7
You notify the OAIC. You notify your clients. Your largest account asks for an urgent meeting and their legal team is already on the call.
-
Day 30
The insurance claim is lodged. The insurer asks for evidence of your security controls: multi-factor policies, access logs, patching records. You cannot produce them.
-
Day 180
Still dealing with it. Two key staff cited loss of trust in their exit interviews. Revenue is down 18 per cent. The board wants answers.
Now rewind. With Cyber365 the story ends at 9:47 AM.
Conditional access blocks the sign-in from an unrecognised device. Multi-factor prevents the credential being reused. The phishing email was quarantined before it reached the inbox. And dark web monitoring flagged that clerk's credentials three weeks earlier, from somebody else's breach, so the password had already been reset.
Your Tuesday continues as normal. You never find out it happened.
A composite, not a customer. The sequence is how these unfold and the controls are real; the organisation, the amounts and the dates are illustrative.
How a month runs
Predictable on purpose. The cadence is what stops a managed service becoming a ticket queue with a retainer attached.
-
Continuously
Monitoring and alerting across every endpoint and server, automated patching on schedule, and automated remediation where an alert has a known answer.
-
As things arrive
Tickets triaged by a dedicated team, incidents managed to closure, and major incidents given a root cause so the same fault does not return.
-
Every quarter
A service review with reporting: what happened, what changed, what is outstanding, and what we think you should do next.
-
Twice a year, at Fortify
A board-level risk pack, plus semi-annual application control policy review and continuing Secure Score work.
Security is not an add-on
Multi-factor authentication, endpoint detection and conditional access are not premium features. They are the minimum standard for operating a business, and a model that charges extra for them is a model designed around the provider.
What Fortify puts a number against
-
A risk score below 40
Hourly vulnerability scanning with every Critical and High finding tracked to resolution. It does not hold where unsupported software must stay in the environment, or where devices are rarely online to receive updates.
-
365 days of log retention
Managed SIEM with behavioural analytics across the environment. Long enough to investigate something found late, which is when most things are found.
-
All eight strategies at ML2
Aligned to the letter of the ASD Essential Eight guidelines, with scoring, trend analysis and gap identification maintained as part of delivery rather than assembled before an audit. Worth saying plainly: there is no Essential Eight certificate. It is ASD guidance, not a certifiable standard, so nobody can accredit you against it and any provider offering to make you "ML2 certified" is describing something that does not exist.
-
Quarterly Secure Score progress
Microsoft Secure Score improvement tracked and reported, so the trend is visible rather than the snapshot.
How a change of provider actually goes
The honest version: it is a transition, not a switch. What follows is what the first ninety days look like.
-
Assess before quoting
What you have, what is unsupported, how many servers and network devices, and where the gaps are. The tier follows from that rather than the other way round.
-
Onboard to the baseline
Agents, monitoring, patching and the Core security controls deployed and brought to a known configuration. Where a control learns your environment first, that runs before enforcement.
-
Then run, review and escalate
The cadence starts, the first quarterly review lands, and if you took Fortify the Essential Eight scoring gives you a starting position to be measured from.
Ask what your current model is costing
Not just the invoice. The recurring faults nobody root-caused, the controls quoted as extras, and the evidence you could not produce if someone asked this week.
Talk to us about Cyber365