N-200Managed services — layer 02, continued
Data security isn't a project.
You can't install it and leave.
Cabling and cameras get installed once and maintained afterwards. Security has no install phase — it is entirely the ongoing work. Managed service is what layer two looks like as a relationship rather than a job.
N-201Why it never finishes
Everything you secured today changes by Friday.
A patch is released. Someone joins, someone leaves. A laptop goes home and comes back. A vendor is granted access and never has it removed. A backup job starts failing and reports nothing, because the thing that would have told you was the alert nobody configured.
None of that is dramatic and none of it announces itself. It accumulates. The incident, when it comes, is almost never a clever attack — it is an unpatched machine, a credential that should have been revoked, or a restore nobody ever tested.
Which is why security sold as a one-off project is being sold wrong. There is no finished state to hand over.
N-210What is under management
N-211
Endpoints
Every server, desktop, and laptop enrolled, monitored, and patched on a schedule. Operating system and third-party applications both — the browser and the PDF reader are what actually get exploited.
N-212
Users
Email security, multi-factor authentication including the awkward exceptions, phishing simulation with per-user results, and onboarding and offboarding so a leaver's access ends the same day.
N-213
Data
Backup for servers, workstations, and Microsoft 365, with automated verification that a restore actually works and periodic test restores reported to you.
N-214
Network
Switches, firewalls, and wireless monitored and patched, configurations backed up off-box so a dead device is a swap rather than a rebuild from memory.
N-215
Physical devices
NVRs, cameras, door controllers, and intercom panels treated as what they are — networked endpoints with firmware, credentials, and a login page. Patched, segmented, and monitored alongside everything else.
N-216
Evidence
Asset inventory, documentation, and exportable reporting on patch compliance, backup success, and training completion. What an insurer or auditor asks for, ready rather than reconstructed.
N-215The devices nobody manages
Who patches your cameras?
It is a genuine question, and in most buildings the honest answer is nobody. Your IT provider does not touch the security system — they did not install it and cannot log into it. Your alarm company does not patch firmware, because they are not an IT company and were never asked to.
So an NVR sits on the network running whatever firmware shipped with it, often with the default credentials still working, frequently reachable from the internet because someone needed remote viewing. Internet-exposed cameras and recorders are among the most consistently exploited devices there are.
We hold both sides. The same platform that patches your laptops covers the recorder in the closet, and the same segmentation design keeps it from reaching anything it should not.
How we design camera systems →N-220Three ways to engage
Fully managed
We are the IT department. Helpdesk, patching, backup, security, vendor management, and the physical security systems. Suited to businesses with no internal IT, or one person who is drowning.
Co-managed
You keep your internal IT person and we take the repetitive load — monitoring, patching, backup verification, after-hours cover. They get to work on things specific to your business instead of chasing updates.
Security only
You have IT covered but not security. We run email and user security, backup verification, compliance evidence, and the security devices, and stay out of the rest.
N-230How an engagement runs
- 01
Assess
We document what is actually there, which routinely differs from the paperwork. Machines nobody knew were still on the domain, backups failing quietly, credentials belonging to people who left. You keep that documentation whether or not you continue with us.
- 02
Stabilise
Fix what the assessment found before agreeing to monitor it. Taking on an environment and reporting green while known problems sit unresolved helps nobody.
- 03
Onboard
Everything enrolled on the platform — endpoints, users, backup, network gear, and the security devices. Baselines set, alerting tuned so it means something.
- 04
Operate
Patching, monitoring, backup verification, and the service desk. Most of this is invisible when it is working, which is the point.
- 05
Review
Quarterly: what failed, what is ageing, what needs budgeting for, and what changed in your risk. A managed relationship with no review is a subscription.
N-240Response
Written down, not implied.
Response targets are set per site and written into the agreement. A back-office with five staff and a building with tenants do not need the same commitment, and should not pay the same for one.
What is consistent regardless of tier: monitored intrusion alarms are answered around the clock by a central station with dispatch, and you get a named contact rather than a general queue.
QCommon questions
- Is managed IT the same as a break-fix support contract?
- No. Break-fix means you pay per incident and you find the problem first. Managed means the machines report in, patching happens on a schedule, and the failing drive is replaced during working hours rather than at the worst possible moment.
- Do you manage cameras and access control as well as computers?
- Yes, and that is unusual. Most MSPs do not install physical security, and most security integrators do not run a monitoring platform, so NVRs and door controllers end up managed by nobody. They are networked devices with firmware and logins, and we treat them that way.
- Can you work alongside our existing IT person?
- Yes — that is the co-managed model. We take monitoring, patching, backup, and after-hours cover so an internal person can work on things specific to your business.
- What platform do you run on?
- Kaseya. Monitoring, patching, backup, documentation, user security, and the service desk are one integrated system, so there are no gaps between separate tools for things to fall through.
- Will you take over systems another company installed?
- Regularly. The engagement starts by documenting and stabilising what is there before agreeing to monitor it.
T-900Next step
Already have systems in, and nobody looking after them?
We take over other providers' work. The assessment documents what is actually installed — which is often not what the paperwork says — and tells you what it would take to bring it under management.