The whole plan structure, on one page.
Three tiers. A full inclusion matrix. A published SLA. Essential Eight alignment. Add-ons, exclusions, and commercial terms — all set out so you can decide what fits before we ever get on a call.
Three tiers, one Ad-hoc option.
Per-user, per-month. Minimum 10 users on managed tiers. Ad-hoc has no minimum and no contract. Pricing is shared on request or in the full agreement.
Pay-as-you-go
No contract, no minimum. Small teams that want a trusted number to call when something breaks.
Reactive helpdesk only — no proactive management.
- RMM monitoring available
- Bitdefender EDR available
- Reactive BH helpdesk
- Best-effort response · no SLA
Billed hourly · no QBR · no strategy
Reliable IT operations
Small teams in simple environments. 10–25 users. First step off ad-hoc.
Steady operations with baseline security.
- BH helpdesk unlimited
- Bitdefender EDR
- Conditional Access
- M365 + endpoint cloud backup
- Patching + monitoring
- Annual planning review
Partial E8 ML1 · 12-month term
Modern security stack
Standard Canberra SMB. 20–50 users. Wants a defensible security posture without going full compliance.
Everything in Core, plus a modern security stack + Essential Eight ML1.
- Managed EDR (24/7 SOC)
- Email security & DNS filter
- Security awareness training
- Dark web monitoring
- Quarterly Business Review
- Named primary engineer
- E8 ML1 controls delivered & maintained
15-min P1 response · 2hrs onsite / mo incl.
Essential Eight ML2
Defence supply chain, government-adjacent, compliance-driven. 25+ users. Regulated obligations or panel tender ambitions.
Everything in Secure, plus ML2 operational with evidence pack.
- Application control (zero trust)
- Immutable BCDR (tested DR)
- E8 ML2 evidence pack
- vCISO advisory
- Priority 24/7 SLA on P1
- Unlimited onsite (metro)
- Co-managed option available
ISM-aligned · DISP-ready · audit-ready
Managed tiers include one-off onboarding and a 12-month initial term (24-month option carries a discount). Ad-hoc is billed hourly in 15-minute increments after the first hour. Licensing — Microsoft 365, Google Workspace, Adobe — is quoted separately at the vendor's published Australian rate plus a 10% administration margin.
What sits inside each tier.
The full comparison — service desk, endpoint management, cybersecurity, backup, Microsoft 365, strategy, compliance, and procurement.
← swipe to see all tiers →
| Inclusion | Ad-hoc | Core | Secure | Assured |
|---|---|---|---|---|
| Service desk & support | ||||
| Reactive remote helpdesk (business hours) | ● | ● | ● | ● |
| Unlimited remote helpdesk (fixed fee) | — | ● | ● | ● |
| After-hours emergency support (P1) | — | — | ● | ● |
| 24/7 helpdesk cover | — | ○ | ○ | ● |
| Named primary engineer | — | — | ● | ● |
| Onsite support (Canberra metro) | Hourly | Hourly | 2 hrs/mo | Unlimited |
| Adds, moves, changes (AMC) | Quoted | Quoted | ● | ● |
| Endpoint & infrastructure management | ||||
| 24/7 RMM monitoring & alerting | ● | ● | ● | ● |
| Automated OS & application patching | ● | ● | ● | ● |
| Asset & software inventory | — | ● | ● | ● |
| Hardware lifecycle management | — | ● | ● | ● |
| User onboarding & offboarding (automated) | — | ● | ● | ● |
| Cybersecurity | ||||
| Bitdefender Antivirus & EDR | ● | ● | ● | ● |
| Managed EDR with 24/7 SOC | — | — | ● | ● |
| Multi-factor authentication (Microsoft Entra) | ○ | ● | ● | ● |
| Conditional Access policies | ○ | ○ | ● | ● |
| Email security & anti-phishing | ○ | ● | ● | ● |
| DNS filtering & web protection | — | — | ● | ● |
| Security awareness training (quarterly) | — | — | ● | ● |
| Dark web credential monitoring | — | — | ● | ● |
| Application control / zero-trust allowlisting | — | — | — | ● |
| SIEM / log aggregation (Microsoft Sentinel) | — | — | ○ | ● |
| Backup, resilience & disaster recovery | ||||
| Microsoft 365 backup (mail, OneDrive, SP, Teams) | ○ | ● | ● | ● |
| Endpoint / server / VM cloud backup | — | ○ | ○ | ○ |
| Immutable backup (ransomware-resistant) | — | — | ● | ● |
| Quarterly backup / restore test | — | — | ● | ● |
| Documented DR plan with RTO / RPO | — | ○ | ○ | ● |
| Microsoft 365 & identity | ||||
| Tenant administration & user management | — | ● | ● | ● |
| Licence optimisation & cost review | — | ● | ● | ● |
| Exchange, SharePoint, Teams governance | — | — | ● | ● |
| Purview DLP & sensitivity labelling | — | — | ● | ● |
| Intune device management & baselines | — | — | ● | ● |
| Strategy & governance | ||||
| Annual planning review | — | ● | ● | ● |
| Quarterly Business Review (senior engineer) | — | — | ● | ● |
| vCISO advisory (cybersecurity governance) | — | — | — | ● |
| Documented IT runbook & environment map | — | — | ● | ● |
| Annual budget forecast & roadmap | — | — | ● | ● |
| Compliance & assurance | ||||
| Essential Eight ML1 controls | — | Partial | ● | ● |
| Essential Eight ML2 (operational steady-state) | — | — | — | ● |
| E8 evidence pack (audit / panel tender) | — | — | — | ● |
| ISO 27001 / ISM-aligned operations | — | — | — | ● |
| Annual penetration test coordination | — | ○ | ○ | ● |
| Vendor & procurement management | ||||
| Single point of contact for all IT vendors | — | ● | ● | ● |
| Hardware procurement at discounted rates | — | ● | ● | ● |
| ISP & telco fault logging | — | ● | ● | ● |
| Software licence negotiation | — | — | ● | ● |
A published SLA, with credits if we miss it.
Every ticket is assigned a priority based on business impact. Each priority has a maximum response time and a target resolution time — written down, not implied.
Priority definitions
- P1 — Critical. Complete outage. Whole site or service down. Active security incident. No workaround.
- P2 — High. Major degradation affecting multiple users. Significant business impact. Workaround possible but inefficient.
- P3 — Medium. Partial impact. Single user blocked or feature unavailable. Workaround exists.
- P4 — Low. Single user, low impact. Information-only or cosmetic issue.
- P5 — Request. Standard service request — user creation, password reset, software install, AMC.
Response & resolution
| Priority | Core | Secure | Assured | Target resolution |
|---|---|---|---|---|
| P1 | 30 min | 15 min | 15 min · 24/7 | 4 business hours |
| P2 | 1 hr | 1 hr | 30 min | 8 business hours |
| P3 | 4 hrs | 2 hrs | 2 hrs | 24 business hours |
| P4 | 1 BD | 4 hrs | 4 hrs | 3 business days |
| P5 | 1 BD | 1 BD | 4 hrs | 5 business days |
Business hours: Mon–Fri 8:00am–5:30pm AEST excluding ACT public holidays. Assured P1 applies 24/7. BD = business day.
Service credits — skin in the game
If we miss a P1 or P2 response target during a calendar month, you're entitled to a service credit of 10% of that month's managed fee, capped at 25% per month across multiple breaches. Credits apply to your next invoice. Resolution-target misses caused by client-side dependency, third-party vendor delays, or events outside our control (force majeure, ISP outages, hardware vendor RMA windows) are excluded.
Where each tier sits on the ACSC maturity model.
The Australian Signals Directorate's Essential Eight is the de-facto cybersecurity baseline for Australian organisations — and a common requirement in government supply chain, Defence (DISP), and regulated industries.
Foundational controls
MFA, OS patching, and daily backups are enforced. Application control, application hardening, user privilege restriction, and Office macro controls are not enforced at Core.
Defensible security posture
All ML1 controls delivered and maintained. ML2 roadmap provided in the first QBR. Suitable for SMBs with no current Defence or regulated obligation who want a defensible posture.
Audit-ready with evidence
All eight mitigations implemented, tested, and evidenced. Suitable for DISP-membership SMEs, government panel respondents, and clients with audit obligations.
A formal Essential Eight maturity assessment with documented evidence pack is a separate, fixed-price project engagement — included as standard for new Assured-tier clients at the end of their first 90 days. Reference: cyber.gov.au — Essential Eight Maturity Model.
Plainly: what's not included.
We're explicit about exclusions so there are no surprises at quoting time. The following sit outside every managed tier and are scoped, quoted, and billed separately.
Project work
- Server migrations, M365 tenant migrations, network redesigns
- New site fit-outs, office moves, cabling
- Application implementation projects (new ERP, CRM, accounting system)
- Bespoke automation, integration, or custom development
Hardware & software purchases
- Hardware (laptops, servers, network gear, peripherals) supplied at cost + procurement margin
- Microsoft 365 licences passed through at Microsoft's published Australian rate + 10% administration margin (as your CSP)
- Third-party software licences passed through at vendor rate + margin
Out-of-tier services
- Onsite support beyond included hours (managed metro or regional; ad-hoc metro or regional — hourly rates apply)
- After-hours support outside SLA cover (1.5× standard rate)
- Travel time outside ACT metro area (each way, hourly)
Specific exclusions
- End-of-life operating systems (Windows 7/8/10 post-Oct 2025, Server 2012 and older)
- Unmanaged hardware not on the documented asset register
- Recovery from incidents caused by client-side disabling of security controls
- Personal devices (BYOD) not enrolled in our management
- Telephony / SIP carrier services (handled by your voice provider)
- Physical security, alarm systems, CCTV
Bolt-ons for any managed tier.
Available on any tier. Billed monthly alongside the base subscription unless noted. Full pricing is in the Managed Services Agreement.
Onboarding, contract, and how we bill.
The commercial mechanics of a managed engagement — timeline, term length, renewal, termination, and payment.
Onboarding
One-off fee per user covers assessment, agent deployment, M365 hardening, initial remediation, and handover meetings.
Typically completed in 10–15 business days from signature.
Initial term
12 months from service commencement. 24-month option carries a discount on monthly fees.
Month-to-month or auto-renew available after the initial term — your choice at sign-up.
Pricing review
Annual review on contract anniversary, capped at CPI + 2%.
Mid-term changes only by mutual agreement, 60 days' notice. User count adjusted monthly in arrears.
Termination
Either party may terminate at end of initial term with 60 days' written notice.
Early-termination fee is 50% of remaining monthly fees — it's not a punishment, it covers reserved capacity.
Off-boarding
30-day handover and knowledge transfer at no charge. Full data export, environment docs, and agent removal included.
Client data securely destroyed 90 days post-termination unless a regulatory hold applies.
Payment
Invoiced monthly in advance for fixed fees, in arrears for variable usage. 14-day terms. Direct debit preferred.
Insurance
Professional Indemnity $5M. Public Liability $20M. All staff are AU-based, police-checked, and signed to a confidentiality deed.
Vendor changes
Third-party tooling may evolve — we reserve the right to swap vendors with 60 days' notice, provided the replacement meets or exceeds the same capability.
The platforms we stand behind.
We name the Microsoft platform publicly because our partnership posture is stable. Third-party security and backup vendors may evolve; you'll always know what we've picked.
Microsoft platform (named)
- Microsoft 365 — Business Standard, Premium, or E-series depending on tier
- Microsoft Entra ID — identity, MFA, Conditional Access
- Microsoft Intune — device management, application control, security baselines
- Microsoft Purview — DLP and sensitivity labels (Secure & Assured)
- Microsoft Sentinel — SIEM / log aggregation (Assured; add-on at lower tiers)
Third-party (vendor-flexible)
- Bitdefender Endpoint Security — AV, EDR/MDR, attack surface reduction
- Managed EDR with 24/7 SOC — wrapping Bitdefender for SMB-scale threat hunting
- Email security & anti-phishing — Microsoft Defender for Office 365 or equivalent
- Immutable cloud backup — ransomware-resistant M365 backup + tested restore
- Endpoint & server backup with offsite redundancy
- DNS filtering and web protection
- Security awareness training with quarterly phishing simulations
- Dark web credential monitoring
- Application allowlisting / zero-trust control (Assured)
Request the full Managed Services Agreement.
We'll send you the complete 2026 edition — tiers, matrix, SLA, add-ons, terms, and the pricing table — as a PDF, no strings attached.