What 24/7 IT support actually means for an Australian SMB

Nearly every provider advertises it and the phrase covers at least four different arrangements, priced very differently. Here is how to tell which one you are being offered, before you find out at 3am.

Somewhere in the last few years, round-the-clock cover became a default claim among managed IT service providers. It is now on almost every website, including ours, which makes it useless as a differentiator and worth roughly nothing as a purchasing signal unless you interrogate it.

The claim is rarely dishonest. It is just imprecise, and the imprecision is expensive at exactly the moment it matters.

Four things “24/7” can mean

All four exist in the Australian market. All four are sold with the same two characters.

Four delivery models sold as 24/7 support
Model What happens at 3am Realistic response
Rostered onshore team An engineer is awake, at a desk, with your documentation Minutes
Follow-the-sun offshore desk An engineer is awake in another region, with varying access Minutes to triage; longer to act
On-call rotation A phone wakes somebody who then has to get to a laptop 30–90 minutes
Monitoring only An alert is generated and queued for the morning Next business day

Scroll the table sideways to see every column.

None of these is illegitimate. An on-call rotation is a perfectly reasonable model for a twenty-person business, and considerably cheaper than a rostered team. The problem is buying the fourth while believing you bought the first.

Three questions that tell them apart

You can identify which model you are being offered in about ninety seconds.

  1. Rostered or on-call? Is somebody awake and working, or asleep with a phone next to them? Both are defensible. Only one produces a response measured in minutes.
  2. Onshore or offshore? Not a quality judgement — offshore teams are often excellent and genuinely staffed overnight. But it determines what data those people can access, which law governs that access, and what your clients' risk questionnaires will need you to disclose.
  3. Authorised to act, or only to triage? The one that decides outcomes. Can the overnight engineer isolate a compromised machine and disable an account, or must they escalate to someone who can? A team that can only observe is a monitoring service with a phone number.

Get all three answers before you compare monthly figures. A provider whose overnight cover is an on-call rotation is not more expensive than one with a rostered team by coincidence.

What actually happens overnight

It is worth being concrete about why any of this matters, because the case for round-the-clock cover is not that servers fail politely at 2am.

Intrusions run overnight and over long weekends by design. The gap between an attacker getting a valid credential and doing something irreversible is typically hours to days, and they choose the window deliberately: Friday evening before a public holiday is the classic. The Australian time zone helps here and hurts there — much of the criminal activity aimed at Australian organisations is operating in its own business hours while yours are asleep.

What that means practically is that the value of overnight cover is almost entirely in the third question above. Detection at 2am with containment at 8:30am gives an attacker a six-hour uninterrupted run in your environment, and six hours is enough.

The useful test for any provider: what is the longest an attacker could operate in our environment before a human takes action, assuming detection works perfectly? Ask them to answer in hours.

Monitoring is not response, and both get called security

The same imprecision affects the security half of the offer. Three distinct things are routinely sold under one heading.

  • Tooling. An endpoint detection product is deployed and licensed. Alerts exist. Nobody is contractually watching them.
  • Monitoring. Alerts are triaged by someone, and the real ones are escalated to you or to the service desk queue.
  • Detection and response. Alerts are triaged and acted on — containment first, notification second, under a standing authority you signed at onboarding.

Only the third changes what happens overnight. The first two produce a better morning briefing. Ask which one is in the price, and ask for the standing authorisation document — if it exists, they will have a template.

When round-the-clock cover is worth paying for

Honestly, not always. It costs real money because it requires real people, and there are organisations for which the on-call model is the correct trade. A short test.

Buy it if you operate outside business hours
Clinics with evening sessions, multi-site retail and hospitality, logistics running overnight, manufacturing on shifts. If revenue is being earned at 11pm, an eight-hour wait is an outage with a dollar figure attached.
Buy it if you hold data somebody wants
Health records, trust accounts, client confidential material, large volumes of personal information. The exposure is not downtime, it is dwell time — and dwell time is what overnight containment reduces.
Buy it if an insurer or a client requires it
Increasingly they do, and increasingly the questionnaire asks specifically about out-of-hours response rather than accepting “24/7” as an answer. Better to have the arrangement than to describe one.
Think twice if you are a single-site weekday business
A twenty-person consultancy that closes at six and holds nothing unusual may be better served by spending the same money on immutable backups and identity hardening. Those reduce the probability and the consequence; overnight cover reduces the duration.

For most buyers of Australian SMB IT support the honest sequence is: identity, tested backups, then overnight response. A provider who sells you the third before the first two has the order wrong.

How we run it

For completeness, and so you can hold us to the same three questions.

  • Rostered, in Australia. Engineers on shift rather than an on-call phone, with access to your documentation rather than a script.
  • Authorised to contain. A standing authorisation signed at onboarding covering endpoint isolation and account disablement, with notification to you immediately afterwards. Written down, not assumed.
  • Targets in the schedule. P1 — a whole site down, a business-critical system down, or a confirmed security incident — responded to within 15 minutes, with a four-hour resolution target. P2 within an hour. The full table sits on the managed IT page, and we report against it monthly whether or not we hit it.
  • One provider, one report. Service performance and security posture in the same document, so nobody has to reconcile two vendors' accounts of the same night.
  • Priced per user, exclusions named. The boundaries are in the agreement before you sign, not on an invoice afterwards.

We would rather you tested that than took it as read. The three questions at the top of this article work on us as well as on anybody else, and there are four more worth asking.

Questions

How much more does rostered overnight cover cost?

It varies by provider and by how much of the cost is shared across a client base, so a figure here would be misleading. What we would suggest is asking each provider to quote with and without out-of-hours response as a separate line, on the same pricing unit.

That comparison is genuinely useful. It also tends to reveal which providers are carrying the cost of a real roster and which are not.

Is 24/7 support the same as a SOC?

No, though they are often bundled. A service desk answers people; a security operations capability watches systems. An SMB usually needs both, and the useful question is whether they share information — whether the overnight engineer who isolates a machine is the same organisation that has to explain it in your monthly report.

Our detection and response service is built to sit alongside the service desk rather than beside it.

We are a startup with twelve people. Is this relevant yet?

Probably not as your first purchase. At that size, IT services for startups should focus on getting identity, device management and backup right while the environment is still small enough to design properly. Overnight response becomes worth its cost when downtime or dwell time starts carrying a real number.

What is worth doing now is choosing a provider who can add it later without a migration.

Our clinic runs evening sessions. Does that change things?

Yes, and it is the clearest case for extended cover. Practical healthcare IT services need support that spans the actual session times rather than office hours, plus patching windows coordinated with your clinical software vendor so updates never land mid-consultation.

Ask specifically what happens if the practice management system goes down at 7pm on a Thursday. It is a better question than any of the generic ones.

What should be in the agreement, not the brochure?

Four things: the response targets by priority with the out-of-hours position stated; where the overnight staff are located; the standing containment authority; and the named exclusions. If those four are in the schedule, the phrase on the website matters much less.

Why Next Cyber

Rostered, onshore, and allowed to act

On the three questions that separate real round-the-clock cover from a phone number, Next Cyber answers the same way every time. That is why Australian SMBs consolidate onto us.

  • Rostered, not on-call. Engineers on shift with your documentation in front of them, including public holidays.
  • Australian owned and staffed. Sydney, Brisbane and Canberra, with your data held onshore.
  • Authorised to contain. A standing authorisation signed at onboarding covers isolation and account disablement at 3am.
  • Fifteen minutes to P1. A whole site down or a confirmed intrusion, acknowledged in 15 minutes against a four-hour resolution target.
  • One provider, one report. Service desk and security operations in the same document, going to the same meeting.
  • A decade behind it. Australian managed services and vendor-side delivery, not a product with a logo on a slide.

Ask us the three questions

Rostered or on-call, onshore or offshore, authorised or observing. We will answer all three in the first meeting and show you the standing authorisation document.