IT Support

One price per user, security included

Most managed IT is bought as support and priced as a retainer, with security added later as a project or a line item. The result is an environment where the help desk is responsive, the controls that would have stopped the last incident were never quoted, and the invoice moves every month. Managed IT is one price per user with the security baseline included. Multi-factor authentication, endpoint detection, conditional access and patching are on from onboarding, every inclusion is documented, and the three tiers change how far the security and the governance go while the IT service underneath stays the same.

Reactive support has a cost that never appears as a line item

A support model built around tickets measures itself on response and closure. That is reasonable for the individual incident and expensive for the environment, because the condition that raised the ticket is rarely investigated once the ticket is closed. The same fault returns, is closed again, and is paid for again. Security controls sit outside the model altogether. The baseline controls are scoped as additions, so an organisation can be fully supported and still have none of them in place. The commercial side follows the same shape. Hourly work, callout fees and project charges make the monthly figure unpredictable, and a loosely defined scope turns every disagreement about what is included into a negotiation.

  • 30+ years operating Australian IT environments
  • Solutions Partner Microsoft, Modern Work, with specialisations in Teams Calling and Adoption and Change Management
  • 103147 NSW Master Security Licence

None of this is a technology problem. It is the predictable result of an operating model that rewards activity over resolution, and that model is what this service replaces.

Secure, operate, prove

The IT service is the same in all three tiers. Twenty-four inclusions do not change: the support team, the triage team, monitoring, patching, incident and change management. What the tiers buy is how far the security and the governance go.

  1. Core

    $130

    per user per month

    24 inclusions

    The complete IT service and the security baseline in one price, for organisations that want support and the minimum controls without a separate security project attached.

    • Security on from day one Multi-factor authentication, endpoint detection, conditional access and automated patching, active from onboarding and included in the per-user price. These are the controls that materially affect whether a phished credential becomes an incident, and a service that scopes them as options is asking the customer to make a security decision the provider is better placed to make.
    • Structured problem management A dedicated triage team resolves incidents at source, and every major incident is given a root cause and a problem record. Recurring conditions are tracked to closure instead of being closed one ticket at a time.
    • 24/7/365 monitoring with escalation Every endpoint and server is monitored continuously. Alerts with a known remediation are actioned automatically. The rest are escalated, with a severity-one path to an engineer outside business hours, so a fault raised overnight is being worked before the service desk opens.
    • One price per user Every inclusion documented, unlimited tickets in business hours, no callout fees. Servers and network devices are quoted separately so a heavy environment does not distort a light one.
  2. Protect

    +$60

    per protected device per month, on top of Core

    35 inclusions

    Adds managed endpoint response with a vendor-operated 24/7 security operations centre, application control, Microsoft 365 backup and measured user awareness. The controls are run, and their state is reportable.

    Everything in Core, plus

    • Endpoint protection upgraded Endpoint protection moves to a platform with behavioural detection, a vendor-operated 24/7 security operations centre and, on Windows endpoints, automated rollback to a pre-attack state if ransomware executes. At Core this is Huntress. At Protect it is SentinelOne.
    • Default-deny execution Application control and ringfencing, so unapproved software does not run and scripting engines and browsers cannot reach what they should not. The environment is learned before enforcement begins.
    • The people, measured Quarterly awareness training with continuous phishing simulation, behaviour risk scoring, and adaptive content aimed at whoever needs it most.
    • Microsoft 365 backup with seven-year retention Daily across Exchange, SharePoint, OneDrive and Teams, with file-level recovery tested on a schedule.
    • Credential exposure watched Dark web monitoring on your domains, with a forced reset triggered when exposed credentials are identified.
  3. Fortify

    +$110

    per protected device per month, on top of Core. Includes Protect

    45 inclusions

    Core and Protect secure the operation. Fortify is where you can prove it.

    Everything in Protect, plus

    • Essential Eight ML2 alignment All eight strategies aligned to the letter of the ASD guidelines at Maturity Level 2, with strategy scoring, trend analysis and gap identification as part of delivery.
    • Full vulnerability ownership Hourly scanning, risk-based prioritisation, and remediation carried out by Ericom, with each Critical and High finding tracked to resolution.
    • Managed SIEM and XDR Telemetry correlated across the environment with behavioural analytics and 365 days of retention. Detections are investigated and actioned, and the investigation is recorded.
    • Board-level risk reporting Twice-yearly packs that translate technical risk into business language, with prioritised actions. Written for a board, with the actions a board can fund.
    • Independent testing and hardening Virtual penetration testing, privileged access management, user application hardening, and Microsoft Secure Score improvement tracked quarterly.

Core is the base, and you add either Protect or Fortify to it; not both, because Fortify already includes Protect. Core is priced per user. Protect and Fortify are priced per protected device, so the two figures are not directly comparable. A server counts as a protected device. Server and network device management is quoted separately as standard. Managed IT carries a minimum of twenty billable seats, and quotes below twenty are billed at twenty. Below that size, Managed IT Flex pairs the same managed baseline with consumable support in place of a fixed inclusion list, and is usually the better fit. No tier is quoted below the list price of the tier beneath it. Onboarding is quoted separately and is not discounted. Twelve-month term with the rate fixed for the term.

Everything in each tier

The complete list, so it can be checked against a current agreement. Every item is included in the tier price.

Core 24

  • Dedicated IT support team
  • Dedicated triage team
  • 24/7/365 monitoring and alerting
  • SLA-backed response times
  • Incident and problem management
  • Change management
  • Endpoint detection and response
  • Multi-factor authentication
  • Conditional access policies
  • Email filtering (Defender)
  • OS and application patching
  • Infrastructure patch management
  • Active Directory management
  • Vendor coordination and escalation
  • Asset tracking and inventory
  • Service desk portal
  • Quarterly service reviews
  • Device compliance reporting
  • Teams calling management
  • AV conferencing support
  • Backup monitoring
  • VPN connectivity support
  • ISP liaison and escalation
  • Procurement services

Protect adds 11

  • Managed endpoint protection with 24/7 SOC
  • Autonomous ransomware rollback
  • Security awareness training
  • Simulated phishing campaigns
  • Microsoft 365 backup (7 year)
  • Application control and ringfencing
  • Dark web monitoring
  • Strategic business reviews
  • Alignment engineering
  • Behaviour risk scoring
  • Default-deny execution policies

Fortify adds 10

  • Essential Eight ML2 alignment
  • Privileged access management
  • Vulnerability management
  • SIEM / XDR (365-day retention)
  • User application hardening
  • Virtual penetration testing
  • Secure Score improvement
  • Board-level risk packs
  • Budget planning and consultation
  • Strategic planning and guidance

Full descriptions, inclusions, exclusions and SLA detail are in the Managed IT Service Schedule, which is the contractual document and is provided with any proposal.

It starts with one click

None of the steps below are technically difficult, and none depend on a sophisticated attacker. Each one is a control that was either in place or was not.

  1. 9:47 AM

    An accounts receivable clerk opens an email that appears to come from the bank. It does not. The credentials are harvested in seconds.

  2. 9:48 AM

    The attacker signs in to Microsoft 365 from an unrecognised device. No multi-factor prompt. No conditional access. No alert.

  3. 10:15 AM

    Inbox rules are created silently and mail from the bank, clients and the leadership team is forwarded externally. SharePoint is accessed and contracts, financial records and employee data are downloaded. Nothing flags it.

  4. 3:45 PM

    A payment instruction is sent from the CFO's mailbox to accounts. It references a real invoice. The money goes to an account the attacker controls.

  5. Day 3

    The IT provider finds the breach. They cannot say what was taken, because there are no logs.

  6. Day 30

    The OAIC and the affected clients have been notified. The insurer asks for evidence of the security controls in place at the time: multi-factor policies, access logs, patching records. None can be produced.

Now rewind. With the Core controls in place, the chain has several places to stop.

Conditional access can refuse the sign-in from an unrecognised device. Multi-factor authentication makes a harvested password insufficient on its own. Email filtering gives the phishing message a good chance of never reaching the inbox, and dark web monitoring may have forced a reset weeks earlier, from somebody else's breach. None of these is a guarantee. Each is a point where the sequence is likely to break, and each is in Core.

A composite of real incidents. The organisation and the timings are illustrative; the sequence and the controls are not.

Where Managed IT fits, and where it does not

Scope clarity is part of the service. These are the boundaries worth knowing before a proposal, because they show whether this is the right model for the environment.

What it does

  • Microsoft 365 environments

    The identity, email filtering, conditional access, backup and Secure Score controls in the tiers are Microsoft 365 controls, and the service assumes a Microsoft 365 tenancy.

  • Third-party vendor escalation

    ISP, carrier and software vendor faults are raised, chased and escalated by Ericom. The customer holds one ticket and the vendor conversation is ours.

What it does not do

  • A 24/7 staffed help desk

    The service desk is staffed 7am to 6pm on business days, with unlimited tickets in that window. Monitoring runs around the clock and critical alerts are escalated to an engineer, but a person to call at 2am about a password is not part of the model.

  • A security programme

    Managed IT includes a security baseline and, at Protect and Fortify, operated controls. It is not an assessment or an uplift programme for the whole environment; that is the Cyber Security practice, scoped separately and often run alongside.

  • Essential Eight certification

    Fortify aligns all eight strategies to Maturity Level 2 and scores them. The Essential Eight is ASD guidance, there is no body that certifies against it, and no provider can make an organisation ML2 certified. Alignment, with the evidence to show it, is what Fortify delivers.

  • Servers and network devices in the per-user price

    Quoted separately as standard, so a server-heavy environment does not raise the per-user rate for a light one.

  • Environments under twenty seats

    Managed IT Flex pairs the same managed baseline with consumable support in place of a fixed inclusion list, and is usually the better fit below twenty.

How a month runs

Predictable on purpose. The cadence is what stops a managed service becoming a ticket queue with a retainer attached.

  1. Continuously

    Monitoring and alerting across every endpoint and server, automated patching on schedule, and automated remediation where an alert has a known answer.

  2. As things arrive

    Tickets triaged by a dedicated team, incidents managed to closure, and major incidents given a root cause so the same fault does not return.

  3. Every quarter

    A service review with reporting: what happened, what changed, what is outstanding, and what we think you should do next.

  4. Twice a year, at Fortify

    A board-level risk pack, plus semi-annual application control policy review and continuing Secure Score work.

What Fortify puts a number against

  • A risk score below 40

    Hourly vulnerability scanning with every Critical and High finding tracked to resolution. It does not hold where unsupported software must stay in the environment, or where devices are rarely online to receive updates.

  • 365 days of log retention

    Managed SIEM with behavioural analytics across the environment. Long enough to investigate activity discovered well after the event.

  • All eight strategies aligned to ML2

    Aligned to the letter of the ASD Essential Eight guidelines, with scoring, trend analysis and gap identification maintained as part of delivery and available before an audit asks for it.

  • Quarterly Secure Score progress

    Microsoft Secure Score improvement tracked and reported, so the trend is visible rather than the snapshot.

Common questions

The questions that come up in the first conversation.

What are the support hours?

7am to 6pm on business days for the service desk. Monitoring, automated remediation and severity-one escalation run around the clock.

Is Managed IT the same as your cyber security services?

No. Managed IT is the support service with a security baseline built in and, at the higher tiers, operated security controls. The Cyber Security practice is the assessment and uplift programme for the whole environment. Many organisations run both.

Does Fortify deliver Essential Eight ML2 alignment?

Yes. All eight strategies are aligned to Maturity Level 2 and scored quarterly, with trend and gap reporting. Alignment is the accurate word. The Essential Eight is guidance, so there is nothing to be certified against, and alignment with evidence is what an auditor or insurer can use.

What about the phone system, the network and the cameras?

Managed IT covers the user environment: endpoints, identity, Microsoft 365, and the servers and network devices quoted with it. Voice, contact centre, physical security and site infrastructure are separate Ericom services. Where they share a network or an identity platform, the monitoring and the escalation are joined, so a fault that crosses between them has one owner and one ticket.

How a change of provider actually goes

A change of provider is a transition with three stages, and each stage has a deliverable. This is what the first ninety days look like.

  1. Assess before quoting

    What you have, what is unsupported, how many servers and network devices, and where the gaps are. The tier is chosen from that assessment and quoted after it.

  2. Onboard to the baseline

    Agents, monitoring, patching and the Core security controls deployed and brought to a known configuration. Where a control learns your environment first, that runs before enforcement.

  3. Then run, review and escalate

    The cadence starts, the first quarterly review lands, and if you took Fortify the Essential Eight scoring gives you a starting position to be measured from.

Start with what is not working

Tell us the faults that keep coming back, the controls that were quoted as extras, and the evidence you would struggle to produce if an insurer or auditor asked for it this week. We will come back with where Managed IT fits and what the first ninety days would involve.

Talk to us about Managed IT