Recommended Technology Platform

The standard we hold, written down.

Most of what goes wrong in a small business network was predictable, and most of it was predictable years out. This is the platform we recommend, support and manage, set out plainly so you can find your own equipment on it and see where it sits before something breaks rather than after.

It is a standard, not a condition of being a client. Nothing on it is a refusal to help.

How to read this

Most of what you own is in the middle column.

Almost everything a business already owns lands in the middle. That is not a lesser grade of service, it is the same service on equipment somebody else controls the lifecycle of.

Approved

What we would put in ourselves.

Chosen, deployed and managed by us end to end, under current vendor support and configured to our standard. Everything your agreement promises applies here without qualification.

Supported

Yours, and we will look after it.

Equipment or software we did not choose and do not control the lifecycle of, but which is current, licensed and sound. Day to day support is the same. What we cannot do is guarantee a vendor we have no relationship with.

Unsupported

We will still help. It is charged.

Outside the standard, past vendor support, or something we cannot see. We do not refuse to touch it. We work on it at the published hourly rate, with no response commitment, and we will tell you what it would take to bring it back inside.

How long things last

The numbers everybody asks for first.

Equipment Recommended life End of life
Laptops and desktops 3 to 5 years Past 5 years
Servers 5 to 7 years Past 7 years
Firewalls, switches and wifi 5 to 7 years Past 7 years
UPS 3 to 5 years Past 5 years
Cabling 10 to 15 years Past 15 years

End of life does not mean we stop answering the phone. It means the equipment is outside the standard, so the response commitments in your agreement no longer attach to it and the work is charged rather than covered. A machine on this side of the line is also the one most likely to be the reason somebody cannot work.

Two of those behave differently. A UPS usually fails at the battery rather than the unit, so the figure is how long before it stops actually holding a server up, which is a thing you find out during a blackout if nobody has tested it. Cabling rarely fails at all. It simply stops being fast enough for what is now running over it, and because nothing has broken it tends to stay in the wall well past the point it has become the slowest part of the network.

The standard

Nine categories, opened as you need them.

Find the category, find your own setup in one of the three columns. If it is in the third, the fix is usually smaller than it looks.

Workstations and laptops The machines your people actually sit in front of.

Approved

  • Business grade Dell or Lenovo, bought through us or to our specification
  • An operating system the vendor still ships security updates for
  • Monitoring and endpoint protection agents installed and reporting
  • Disk encryption on, and the recovery key held where we can find it

Supported

  • Business grade machines from another manufacturer, in warranty and on a supported operating system
  • Machines between three and five years old with a replacement date against them in the budget

Unsupported

  • Consumer machines bought off a retail shelf
  • Anything past five years without a replacement plan
  • Personal machines used for work, which we cannot patch, protect or wipe
  • An operating system the vendor has stopped patching
Servers The thing everything else in the office depends on.

Approved

  • Business grade server hardware under an active manufacturer support contract
  • A supported operating system, patched on our schedule
  • Backed up daily, with restores tested rather than assumed
  • Monitored around the clock, with alerts coming to us rather than to you

Supported

  • Servers between five and seven years old with a replacement plan and a budget date against them
  • Hardware whose support contract has lapsed but which is otherwise current, while it is being reinstated

Unsupported

  • Anything past seven years, or out of vendor support
  • A server with no current backup
  • A desktop machine doing a server's job
  • Hardware in a cupboard with no ventilation, no UPS or no physical security
Networking Firewall, switching and wifi, which is where most of the exposure is.

Approved

  • Fortinet firewalls, and Ruckus or UniFi for switching and wifi, bought through us and under an active subscription
  • Configured to our standard: segmented, current firmware, central logging, no management interface reachable from the internet
  • Lifecycle managed by us, so firmware and licences do not quietly lapse

Supported

  • Business grade firewalls and switching from another vendor where you hold a current licence and support contract
  • Equipment we troubleshoot and maintain but did not specify, where the vendor will deal with us

Unsupported

  • Consumer routers, or an ISP supplied modem doing the job of a firewall
  • Unmanaged wifi, or a guest network sharing the same wire as the office
  • Port forwards straight to an internal machine, and exposed admin interfaces
  • Expired security subscriptions, which turn a firewall back into a router
Operating systems and software Current, licensed and still getting patches from whoever wrote it.

Approved

  • Versions the vendor still ships security updates for
  • Patching on a schedule rather than whenever somebody gets around to it
  • Licensing matched to what people actually use

Supported

  • Line of business applications on a version the vendor still supports, where that vendor will talk to us on your behalf
  • Software mid upgrade, with a date on the upgrade

Unsupported

  • Anything past its vendor's end of support date, which stops getting security fixes on that date and not before
  • Unlicensed installs
  • Software that requires local administrator rights for ordinary users to run it
Identity and access Who can get in, and what they can reach once they are in.

Approved

  • Microsoft 365 with multi factor authentication on every account, administrators included
  • A named account per person, so a login belongs to somebody
  • Administrative rights held on separate accounts from the ones people read email with
  • A leavers process, so access goes when the person does

Supported

  • An existing directory or identity platform being migrated, with a date on the migration
  • Conditional access or sign in rules you already run, where we can see the console

Unsupported

  • Shared logins, which make an audit trail worthless
  • Accounts without multi factor authentication
  • Permanent local administrator rights for everyday users
  • Former staff accounts left active because nobody told anybody
Security Aligned to the ACSC Essential Eight, which is the Australian benchmark.

Approved

  • Managed endpoint protection deployed and monitored by us
  • Enterprise email filtering and web protection
  • DNS health monitoring and dark web monitoring on your domain
  • Staff security awareness training, because the strongest firewall does not stop a fake invoice

Supported

  • An existing endpoint or filtering product you are contracted to, where we can reach its console and see its alerts

Unsupported

  • Free or consumer antivirus on a business machine
  • A security product whose console we cannot see, which means nobody is watching it
  • A device that has stopped reporting in and has not been chased
Backup and recovery A backup nobody has restored from is a hypothesis, not a backup.

Approved

  • Daily cloud backups of your servers
  • Daily backups of your Microsoft 365 tenancy, which Microsoft does not do for you
  • Copies held separately from the live data, so encrypting your files does not encrypt the copy
  • Restores tested, and the time a restore takes actually measured

Supported

  • An existing backup product with capacity and a current licence, where we can monitor the job results

Unsupported

  • A backup nobody has ever restored from
  • A drive left plugged into the machine it is backing up
  • A file sync tool used as a backup, which replicates a deletion perfectly
  • No backup of Microsoft 365 at all, which is the most common gap we find
Email and collaboration Where the money actually gets stolen from.

Approved

  • Microsoft 365, configured rather than switched on
  • SPF, DKIM and DMARC set correctly, so nobody else can send mail as you
  • SharePoint and OneDrive permissions made deliberate rather than inherited

Supported

  • Another mainstream business mail platform on a current subscription, where the records are correct

Unsupported

  • Mail hosted on a machine in your own office
  • Free consumer mailboxes used for business mail
  • A domain with no SPF or DMARC record
  • Automatic forwarding to a personal address, which is how a mailbox compromise stays invisible
Monitoring and records We cannot look after equipment nobody has told us about.

Approved

  • Our monitoring and patching agent on every workstation and server
  • The device on the asset register with its age, warranty and replacement date
  • Your environment written down rather than remembered

Supported

  • A device we can reach but cannot monitor continuously, for example one that is switched on a few days a month

Unsupported

  • A machine with no agent on it
  • Equipment added to the network without telling us, which is invisible until it breaks or gets used against you
  • Anything at a site we have never been given access to

In practice

A planning tool, not a stick.

01

You get told before, not after

We flag equipment and software approaching end of life while there is still time to budget for it. Nothing on this page should ever arrive as a surprise on the morning something stops.

02

It gets reviewed with you

Ageing equipment, replacement dates and what it will cost are on the agenda at your Technology Business Review, with the asset register in front of both of us. That is where a replacement turns into a budget line rather than an emergency.

What a review covers

03

Buying through us is not compulsory

It is simply how a device arrives already approved, already on the asset register and already carrying the right warranty. Buy elsewhere and we will tell you honestly whether what you have chosen lands in the first column or the second.

04

Nothing here is a refusal

Unsupported means outside the standard, not untouchable. We will work on it, tell you what it would take to bring it back inside, and let you decide whether that is worth doing. Some of it never will be, and we will say so.

Compliance

Where your industry, your insurer or a larger client asks you to meet a standard, the ACSC Essential Eight is the Australian benchmark and it is what this platform is built against. Your own obligations under the Privacy Act 1988 and the Notifiable Data Breaches scheme also depend on the things on this page: an environment that is patched, backed up and access controlled is the difference between an incident and a notifiable one.

Work on unsupported equipment is charged at the published hourly rates. They are on the managed IT page, along with what an agreement covers. All rates in AUD and exclude GST.

Not sure which column you are in?

Most people are not, and it is not obvious from the outside. Bring us what you have and we will tell you plainly what sits inside the standard, what does not, and which of it is actually worth spending money on this year. That is also what a Technology Business Review is for.

Or ring us

1300 025 110 (07) 5638 1255

Monday to Friday, 9am to 5pm

Or send us a message

We get back to you within one business hour, Mon to Fri

Call now Book a call