Skip to content

Managed IT

Someone has to own the systems the business runs on.

Not the software you sell, the software and hardware you depend on: the network, the Microsoft tenant, the backups, the cameras, the server still humming in the comms cupboard. Most of it works until the day it does not, and the difference between an afternoon and a fortnight is whether anyone had written down how it was put together. We take that on as a monthly agreement.

We do both halves of this, which is the unusual part: the people who run your infrastructure and the people who write software are one team, whoever happens to be the one on site. It means the answer to a workflow that wastes an hour a day is allowed to be a small piece of software rather than a bigger licence, without it becoming somebody else's project first.

What we manage

Five areas, usually taken together.

They are listed separately because they fail separately, but they are one estate and we would rather manage it as one. If you already have a provider for part of it, say so and we will work out where the boundary sits.

01 / network

Networks and Wi-Fi

On-site and remote

The switching, routing and wireless the rest of it depends on, segmented so one compromised device does not have the run of the building.

Most small networks are one flat space where the guest phones, the cameras and the machine holding your accounts can all reach each other. We separate them into VLANs, put a real firewall at the edge, survey the wireless instead of guessing at access point placement, and write the addressing down so the next person does not have to rediscover it.

  • Switching, VLANs and routing
  • Wi-Fi surveys and access points
  • Firewalls, VPN and remote access
  • Internet failover and DNS

02 / microsoft

Microsoft 365 and identity

Usually remote

Tenant, mail, files and accounts run properly: multi-factor everywhere, conditional access, and a joiners and leavers process that actually revokes things.

Identity is the security boundary that matters now, because the account is what an attacker is after rather than the perimeter. We configure Entra ID, enforce multi-factor, set conditional access rules that fit how your people actually work, manage devices through Intune, and review licence allocation, which is usually where a tenant is quietly overspending.

  • Entra ID, MFA and conditional access
  • Exchange Online and mail security
  • SharePoint, OneDrive and Teams
  • Intune device policy and onboarding

03 / backups

Backup and disaster recovery

Usually remote

Copies of everything that matters, one of them offsite and beyond reach of whatever hits the original, and restores that have been tested rather than assumed.

A backup nobody has restored from is not a backup, it is a hope with a schedule. We cover servers, endpoints and the Microsoft 365 tenant, keep an offsite copy that ransomware on your network cannot reach or encrypt, agree in writing how much data you can afford to lose and how long you can afford to be down, then rehearse the restore on a schedule so the first real attempt is not the first attempt.

  • Servers, endpoints and Microsoft 365
  • Offsite and immutable copies
  • Agreed recovery point and recovery time
  • Scheduled restore drills

04 / cameras

Cameras and access control

Mostly on-site

CCTV and door access installed as part of the network rather than bolted alongside it, recording locally, on their own isolated segment.

Cameras and door controllers are network devices with a poor security record, so they go on an isolated VLAN with no path to the internet unless something specific requires it. Footage records to hardware you own. Because these systems record people, who may view footage and how long it is kept are decisions to make deliberately and write down, not defaults to accept from whoever installed the last system.

  • IP cameras, recorders and viewing
  • Door access, intercoms and locks
  • Isolated segment, no open ports
  • Retention and who can view what

05 / onprem

Servers and on-premise infrastructure

On-site and remote

The hardware still sitting in the building: hypervisors, file and application servers, storage and power, monitored and patched on a cadence.

Plenty of businesses still have equipment on site because something genuinely has to be there: a line-of-business application, a large working file store, gear that talks to machinery. We keep it running rather than pretending it should already have moved: virtualisation, storage with redundancy that has been checked, protected power, monitoring that alerts before a disk fills, and patching on a schedule instead of after an incident.

  • Hypervisors and virtual machines
  • File, print and application servers
  • Storage, redundancy and protected power
  • Patching and firmware cadence

What managed means here

The word is used loosely, so here is what you are buying.

Plenty of agreements amount to a phone number and an invoice. These are the four things we think make the difference, and they are the ones to hold any provider to, including us.

An asset register you can actually read

Every device, licence, warranty date and where its credentials live, written down and kept current. It is the first thing we build and the thing most handovers are missing, and it is yours whether or not we are still the ones holding the contract.

Monitoring, so we know before you ring

Alerts on the things that give warning: disks filling, backups failing, certificates expiring, devices dropping offline, power events. Most outages announce themselves for days first, to whoever is watching.

You keep the keys

Administrative accounts are in your name and your tenant, not ours. Nothing is configured in a way that makes leaving us expensive, and if you take it in-house or move to another provider you get the documentation rather than a support ticket.

The same engineers who write software

When the fix is a script, an integration or a small internal tool rather than a setting, that is not an escalation to a different company. It is the part of this we were already doing.

Response times are the part of a managed agreement worth reading, so they belong in the agreement rather than in marketing copy. We set them against what your business actually cannot run without, and we would rather commit to a number we will hit than publish a better-sounding one we will not.

Coverage

As hands-on at your site as the place actually needs.

Some of this only happens in the building: cabling, camera mounting, access points, hardware swaps, and any fault that turns out to be physical. We drive out and do that work. How often we are there depends on the site rather than on a policy, because some places want someone on the floor regularly and others need one visit to set it up and then hardly another.

The rest runs remotely: the Microsoft tenant, identity and device policy, backup monitoring and restore testing, patching, alerts and anything on the software side. We would rather agree the mix with you than publish one and expect your site to fit it, so tell us where you are and how the place runs, and visits get scoped alongside everything else.

Start with what you have.

Tell us roughly how many people, what is on site, and what worries you most about it going down. We will tell you what we would fix first, what can wait, and what it costs a month to keep it that way.