Managed IT and cyber protection for Australian firms
Most firms buy IT support from one company and security from another, then discover during an incident that neither owns the part in the middle. We built Next Cyber to close that seam, so we will be specific about exactly where it sits and what it costs you.
A typical Australian firm of forty to three hundred people has an IT provider handling the service desk, devices and Microsoft 365, and — added at some point in the last few years, often after an insurance renewal — a separate arrangement for managed security services. On paper that looks like specialisation. In practice it creates a boundary, and boundaries are where incidents live.
The reason firms buy Australian managed IT services and cyber security separately is usually historical rather than deliberate. The incumbent could not offer security, a client's risk questionnaire demanded monitoring, and a second contract was the fastest way to answer it. Nobody sat down and decided that detection and remediation should sit with different companies.
Where the seam actually is
The division is almost never drawn where you would expect. In most arrangements we inherit, it looks like this.
| Activity | Usually owned by | Where it goes wrong |
|---|---|---|
| Detecting suspicious activity | Security vendor | Nothing — this part generally works |
| Deciding whether it is real | Security vendor | Needs environment context the vendor does not hold |
| Containing it | Contested | The vendor often lacks the access; the IT provider lacks the alert |
| Fixing the cause | IT provider | Arrives as a ticket, competing with everything else |
| Confirming it is fixed | Nobody | Each assumes the other closed the loop |
Row three is the expensive one. Cyber security monitoring without the authority and access to contain produces a phone call, and a phone call at 2am to a service desk that opens at 8am produces a six-hour head start for whoever is in your environment.
Four ways the seam fails
1. The alert with nowhere to land
A detection fires on a Saturday. The security vendor triages it, decides it is real, and escalates — by email, to the IT provider's queue. Monday morning it becomes a P2. The detection worked perfectly and bought nothing.
2. The change that broke the coverage
The IT provider migrates a server, rebuilds an endpoint, or onboards a new site. Agents do not get redeployed, log sources go quiet, and the security vendor does not know the estate changed because nobody told them. Coverage gaps of this kind can persist for months and are invisible unless somebody reconciles the two asset lists.
3. The finding nobody funds
The security vendor reports that thirty machines are missing a patch, or that seventeen accounts have standing administrative rights. Remediation is the IT provider's work, and it is not in their scope. The finding is reported again the following month, and the month after. Everyone is doing their job.
4. The incident with two accounts of what happened
After the event, you receive two timelines that do not agree, because each party logged their own portion. Reconstructing what actually occurred becomes a project, at exactly the moment your insurer, your clients and possibly a regulator want a single coherent answer.
What end to end should actually mean
“End to end” is a phrase every provider uses, including us, and it is worth being specific about what it should buy you. Six things.
- One asset list. Monitoring coverage reconciled against the device and identity inventory, monthly, with the exceptions named. If you cannot see a coverage percentage, coverage is an assumption.
- Containment authority in writing. A standing authorisation to isolate a host or disable an account out of hours, held by people who have the access to do it.
- Remediation inside the same scope. A finding becomes work, on a timeline, without a separate quote. Where it genuinely is project work, that boundary is named in the agreement rather than discovered afterwards.
- One report. Service performance and security posture in the same document, going to the same meeting. Two reports get read by two audiences and nobody reconciles them.
- One incident timeline. Detection through containment to root cause and closure, produced by one party who saw all of it.
- One accountable name. When something goes wrong, one person answers for it. This is the part clients tell us they were actually buying.
Underneath that, the technical capabilities are the same eight regardless of who provides them — identity, endpoint detection, patching, email control, privileged access, segmentation, immutable backup and a rehearsed plan. We set them out with the evidence to ask for against each in eight capabilities that decide a ransomware outcome. Consolidating providers does not create ransomware protection on its own. It removes the reason the capabilities do not connect.
What to put in the agreement
If you do consolidate — with us or anyone — these are the clauses worth insisting on. They are the ones that make the promise testable.
- Response targets by priority, with the out-of-hours position stated. Not “24/7 support” as a phrase, but what is rostered, where those people are, and what they are permitted to do at 3am.
- A monitoring coverage commitment, expressed as a percentage of assets with a reconciliation cadence.
- Remediation SLAs for findings, separated by severity, so a critical vulnerability has a clock and not a queue position.
- Restore testing on a named schedule, for named systems, reporting a measured recovery time.
- Named exclusions. Every managed service has them. A provider unwilling to write them down has not removed them.
- Exit terms priced in advance — notice period, exit assistance rate, and exactly what is handed over. Tenants and licences in your name, not the provider's.
The honest case against consolidating
There are two real arguments on the other side and it would be dishonest to skip them.
Independence. A separate security provider marks the IT provider's homework. That is genuinely valuable, and consolidating removes it. Our answer is to keep the independence somewhere else: commission an annual assessment or penetration test from a third party who is not your provider. That preserves the check at a fraction of the cost of running two overlapping contracts, and it produces something you can show a client's risk team.
Concentration. One provider is one point of failure, commercially and operationally. Mitigate it in the contract — documentation kept current and accessible to you, credentials in a vault you can reach, tenants in your name, exit assistance priced — so that leaving is a project rather than a hostage negotiation.
If a provider resists either of those, that is useful information about what you would be signing.
Why this shows up most in professional services
Professional services firms — legal, accounting, financial advice, consulting — sit at an awkward intersection. Client confidentiality is the product. Trust accounts and payment instructions make you a standing target for redirection fraud. Your clients' risk teams audit you, and increasingly send questionnaires that assume you can answer for your whole environment in one voice.
That last point is the practical driver for most of the firms that come to us. A due diligence questionnaire asks one organisation a hundred questions. Answering it from two contracts takes a fortnight, produces inconsistencies, and the inconsistencies are what the risk team notices. We have written more about what we see across the sector.
Questions
Is one provider actually cheaper?
Sometimes, but that is not the argument. Two contracts usually carry overlapping tooling and duplicated onboarding, so there is often some saving — but the real return is in time to containment and in not paying twice for a conversation about whose job something was.
Be suspicious of a consolidation pitch that leads with price. It generally means something has been removed from scope.
Our IT provider has just added a security offering. Is that the same thing?
It depends entirely on whether they built a practice or resold a product. Ask who staffs the monitoring, where those people are, what they are authorised to do without calling you, and to see a redacted incident report they have written.
A provider who has genuinely built the capability will answer quickly and will have an example. One who has added a logo to a slide will describe the technology.
Does this apply to smaller organisations?
More so, in our view. Larger organisations have someone internally who owns the seam between vendors. Australian SMBs generally do not, which means the coordination work either falls to a business owner or does not happen. The gap is the same shape; there is just nobody standing in it.
How long does it take to move to one provider?
For a typical 50 to 250 seat environment, four to six weeks, longer where there are multiple sites or regulated systems. The sequence that works is running in parallel first — documentation, monitoring and backup verified on the new side before the service desk moves — so that nothing depends on the outgoing party's goodwill.
More detail on how we approach transitions is on how we work.
One provider, and no seam to fall through
Next Cyber was built to be the answer to this article: Australia’s premier managed IT and cyber security partner, with the service desk and the security practice under one agreement.
- One asset list. Monitoring coverage reconciled against the device and identity inventory, monthly, with exceptions named.
- Containment authority. Held by the people who have the access to use it, under an authorisation you signed.
- Remediation in scope. Findings get a timeline, not a separate quote.
- One report, one name. Service performance and security posture together, and one person accountable when it goes wrong.
- Built for client risk audits. A single maintained due-diligence response pack, so a tender takes hours rather than a fortnight.
- Independence preserved. We will still tell you to commission your annual test from somebody who is not us.
One provider, one report, one name
Managed IT and security under a single agreement, with containment authority written down and remediation inside the scope. Ask us the hard questions in the first meeting.