Skip to content

N-200Managed services — layer 02, continued

Data security isn't a project.
You can't install it and leave.

Cabling and cameras get installed once and maintained afterwards. Security has no install phase — it is entirely the ongoing work. Managed service is what layer two looks like as a relationship rather than a job.

N-201Why it never finishes

Everything you secured today changes by Friday.

A patch is released. Someone joins, someone leaves. A laptop goes home and comes back. A vendor is granted access and never has it removed. A backup job starts failing and reports nothing, because the thing that would have told you was the alert nobody configured.

None of that is dramatic and none of it announces itself. It accumulates. The incident, when it comes, is almost never a clever attack — it is an unpatched machine, a credential that should have been revoked, or a restore nobody ever tested.

Which is why security sold as a one-off project is being sold wrong. There is no finished state to hand over.

N-210What is under management

N-211

Endpoints

Every server, desktop, and laptop enrolled, monitored, and patched on a schedule. Operating system and third-party applications both — the browser and the PDF reader are what actually get exploited.

N-212

Users

Email security, multi-factor authentication including the awkward exceptions, phishing simulation with per-user results, and onboarding and offboarding so a leaver's access ends the same day.

N-213

Data

Backup for servers, workstations, and Microsoft 365, with automated verification that a restore actually works and periodic test restores reported to you.

N-214

Network

Switches, firewalls, and wireless monitored and patched, configurations backed up off-box so a dead device is a swap rather than a rebuild from memory.

N-215

Physical devices

NVRs, cameras, door controllers, and intercom panels treated as what they are — networked endpoints with firmware, credentials, and a login page. Patched, segmented, and monitored alongside everything else.

N-216

Evidence

Asset inventory, documentation, and exportable reporting on patch compliance, backup success, and training completion. What an insurer or auditor asks for, ready rather than reconstructed.

N-215The devices nobody manages

Who patches your cameras?

It is a genuine question, and in most buildings the honest answer is nobody. Your IT provider does not touch the security system — they did not install it and cannot log into it. Your alarm company does not patch firmware, because they are not an IT company and were never asked to.

So an NVR sits on the network running whatever firmware shipped with it, often with the default credentials still working, frequently reachable from the internet because someone needed remote viewing. Internet-exposed cameras and recorders are among the most consistently exploited devices there are.

We hold both sides. The same platform that patches your laptops covers the recorder in the closet, and the same segmentation design keeps it from reaching anything it should not.

How we design camera systems →

N-220Three ways to engage

Fully managed

We are the IT department. Helpdesk, patching, backup, security, vendor management, and the physical security systems. Suited to businesses with no internal IT, or one person who is drowning.

Co-managed

You keep your internal IT person and we take the repetitive load — monitoring, patching, backup verification, after-hours cover. They get to work on things specific to your business instead of chasing updates.

Security only

You have IT covered but not security. We run email and user security, backup verification, compliance evidence, and the security devices, and stay out of the rest.

N-230How an engagement runs

  1. 01

    Assess

    We document what is actually there, which routinely differs from the paperwork. Machines nobody knew were still on the domain, backups failing quietly, credentials belonging to people who left. You keep that documentation whether or not you continue with us.

  2. 02

    Stabilise

    Fix what the assessment found before agreeing to monitor it. Taking on an environment and reporting green while known problems sit unresolved helps nobody.

  3. 03

    Onboard

    Everything enrolled on the platform — endpoints, users, backup, network gear, and the security devices. Baselines set, alerting tuned so it means something.

  4. 04

    Operate

    Patching, monitoring, backup verification, and the service desk. Most of this is invisible when it is working, which is the point.

  5. 05

    Review

    Quarterly: what failed, what is ageing, what needs budgeting for, and what changed in your risk. A managed relationship with no review is a subscription.

N-240Response

Written down, not implied.

Response targets are set per site and written into the agreement. A back-office with five staff and a building with tenants do not need the same commitment, and should not pay the same for one.

What is consistent regardless of tier: monitored intrusion alarms are answered around the clock by a central station with dispatch, and you get a named contact rather than a general queue.

QCommon questions

Is managed IT the same as a break-fix support contract?
No. Break-fix means you pay per incident and you find the problem first. Managed means the machines report in, patching happens on a schedule, and the failing drive is replaced during working hours rather than at the worst possible moment.
Do you manage cameras and access control as well as computers?
Yes, and that is unusual. Most MSPs do not install physical security, and most security integrators do not run a monitoring platform, so NVRs and door controllers end up managed by nobody. They are networked devices with firmware and logins, and we treat them that way.
Can you work alongside our existing IT person?
Yes — that is the co-managed model. We take monitoring, patching, backup, and after-hours cover so an internal person can work on things specific to your business.
What platform do you run on?
Kaseya. Monitoring, patching, backup, documentation, user security, and the service desk are one integrated system, so there are no gaps between separate tools for things to fall through.
Will you take over systems another company installed?
Regularly. The engagement starts by documenting and stabilising what is there before agreeing to monitor it.

T-900Next step

Already have systems in, and nobody looking after them?

We take over other providers' work. The assessment documents what is actually installed — which is often not what the paperwork says — and tells you what it would take to bring it under management.