What's included

A closer look at what sits inside a Starboard managed plan.

Ten of the controls, tools and rituals that make up our Core, Secure and Assured tiers — what they do, and how they help the business.

Conditional Access policy management interface showing MFA rules and sign-in locations.
01 · Identity Conditional Access

Only the right people, from the right places, with the right proof.

Policies inside Microsoft Entra that decide who can access your Microsoft 365 tenant — checking the user, the device, the location and the sign-in risk before letting them through. MFA on admins, geo-blocking outside Australia, requirement for compliant devices, session controls on unmanaged browsers.

Why it matters: the single biggest cause of Australian SMB compromise is stolen credentials being reused from someone else's laptop in another country. Conditional Access shuts that door quietly, without users noticing.

Core Secure Assured
Cloud backup dashboard showing Microsoft 365 protection status and endpoint backup coverage.
02 · Data Cloud backup — M365 & endpoints

Independent copies of the data Microsoft won't restore for you.

Daily immutable backups of Exchange mailboxes, SharePoint, OneDrive and Teams — held in a separate Australian tenant, retained for 365 days. Endpoint file-level backup available as an add-on for the workstations that hold data outside M365.

Why it matters: Microsoft's own service agreement says "we recommend that you regularly backup your Content and Data" — they don't. If a user deletes a mailbox, ransomware encrypts SharePoint or a departing staff wipes OneDrive, this is the only way you'll get it back.

Core Secure Assured
Patch compliance dashboard showing 94% compliance across 332 endpoints with pending updates.
03 · Operations Patching + monitoring

Everything current, everything watched — quietly, in the background.

Our RMM agent deploys operating-system and third-party application patches to every workstation and server on a rolling weekly cadence, with a reporting console that tells us the moment a device drifts out of compliance. Continuous monitoring of CPU, memory, disk, temperature and service health — with automated alerts to our team before you notice.

Why it matters: unpatched Windows and Chrome are the two entry points most commonly exploited by ransomware in Australia. Patching Applications and Operating Systems are two of the eight ACSC Essential Eight controls — this is how we tick both, without you having to remember.

Core Secure Assured
Annual IT planning review meeting scene with a printed roadmap, laptop and notebook.
04 · Strategy Annual planning review

One hour a year that stops IT being a surprise.

A structured session with your leadership to look 12 months ahead — hardware refresh cycles, licence renewals, headcount changes, compliance milestones, and any project work you're thinking about. You leave with a one-page written plan and a budget forecast to attach to your own.

Why it matters: most SMBs discover IT bills the way they discover potholes — by hitting one. Planning ahead gets you volume pricing, avoids emergency premiums and lets you actually budget properly for the year.

Core Secure Assured
24/7 Security Operations Centre console showing live incident timeline, threat map and MTTR metrics.
05 · Security Bitdefender MDR — 24/7 SOC

A real security team watching your endpoints while you sleep.

Bitdefender's Managed Detection & Response service adds a 24/7 human SOC on top of the EDR agent. Analysts triage every alert, isolate compromised devices, kill malicious processes and call you when it matters — with average time-to-contain measured in minutes, not hours.

Why it matters: ransomware detonates at 2am Sunday, not 2pm Tuesday. Automated EDR alone will flag the alert — you still need someone awake to isolate the device, kick the attacker out and preserve evidence for insurance. That's what the SOC is for.

Core Secure Assured
Email inbox with quarantined phishing messages alongside a DNS filter blocking malicious domains.
06 · Perimeter Email security & DNS filter

Bad email into the bin. Bad domains into the void.

Advanced email filtering that scans every inbound message for phishing, business email compromise, malicious attachments and impersonation of your CEO — with quarantine and end-user release. DNS filtering on every managed device (in the office and remote) that blocks malware, adult, gambling and known-bad domains before the browser can even connect.

Why it matters: the ACSC Cyber Threat Report names phishing and BEC as the two most-reported crime types costing Australian businesses money. Blocking at both the inbox and the DNS layer catches the 98% that scale, and buys time on the rare 2% that get through.

Core Secure Assured
Security awareness training platform showing team-wide phishing simulation results and training module progress.
07 · People Security awareness training

Turn your staff from the weakest link into the last line of defence.

A rolling programme of short (3–5 minute) micro-training modules covering phishing, password hygiene, social engineering, safe file handling and remote-work risks. Monthly simulated phishing campaigns test what they've learned — with results reported back so you can see your click-rate trend down over time.

Why it matters: insurers now check whether you run staff training before they'll quote — and having it in place cuts cyber-insurance premiums by 10–25%. The evidence pack we generate satisfies most underwriter questionnaires without you having to write anything yourself.

Core Secure Assured
Dark web monitoring dashboard showing recent credential exposures and monitored domains.
08 · Intelligence Dark web credential monitoring

We watch the breach dumps so you don't have to.

Continuous monitoring of paste sites, leak forums and credential dumps for any @yourdomain.com.au email address exposed in a third-party breach. When something surfaces you get the alert, the affected user gets a forced password reset, and we check whether the exposed password was in use anywhere else in your tenant.

Why it matters: the average person's password shows up in a breach every 18 months. If the same password is reused for M365, you're compromised the day the dump goes public — usually months before you'd otherwise know. This closes the gap from months to minutes.

Core Secure Assured
Quarterly Business Review presentation showing uptime, tickets, MTTR and security score metrics.
09 · Governance Quarterly Business Review

Four times a year, we sit down and show our working.

A 45–60 minute session covering ticket volumes and resolution times, uptime, security posture (compliance score, patch state, incidents), asset lifecycle, licence spend, and the projects on the horizon. Delivered as a written report plus a live walk-through with your leadership.

Why it matters: most MSP relationships fail not because the tech is broken, but because clients can't see the value. QBRs turn "we pay Starboard $X a month" into "we get Y outcomes for it" — and that's how the conversation about growing the relationship starts.

Core Secure Assured
Essential Eight Maturity Level 1 dashboard showing all eight controls achieved with 100% compliance.
10 · Compliance Essential Eight — ML1 controls

The Australian government's baseline. Configured, evidenced, kept there.

Operational alignment with all eight ACSC Essential Eight controls at Maturity Level 1 — application control, patching, Office macro hardening, user application hardening, admin privilege restriction, patched operating systems, MFA and regular backups. We configure the settings, generate the evidence pack and re-check monthly to make sure nothing drifts.

Why it matters: ML1 is now the entry bar for any Federal or ACT government supplier — and increasingly for insurers, banks and larger private clients. Having it documented and current means you can answer the "are you Essential Eight compliant?" question on procurement forms with an evidenced yes. Assured extends this to ML2.

Core Secure Assured
Want to see how it looks for your business?

Book a walk-through — no pressure, no timeshare pitch.

We'll show you the actual dashboards on our own tenant, walk you through what the reports look like, and answer whatever's still unclear.