How We Work

Assess first, change second, measure throughout

Taking on someone else's IT estate is the riskiest moment in the relationship. This is the sequence we follow so that nothing important is discovered during an emergency.

The Shape Of It

A structured first 90 days

A provider cannot manage what it cannot see, support what it cannot access, or be accountable for systems nobody documented. So the first month is spent understanding your environment rather than changing it. The second turns those findings into fixes, in an order your business can absorb. The third proves the arrangement works and sets the rhythm for everything after.

Phase One · Days 1–30

Discovery, before anything changes

The output is a written picture of what you actually run, and a ranked list of what we inherited.

01

Kickoff and named contacts

A structured start with named people on both sides, so nobody is wondering who to call. Escalation paths and support expectations are agreed in writing before anything else happens.

02

Full asset and network inventory

Hardware, software, licences, user accounts and network topology, catalogued properly. Automated discovery does the collecting; an engineer validates it rather than trusting the tool.

03

Access and credential review

Who can reach what, which admin accounts exist, whether shared logins are in use, and whether your leaver process actually removes access. Inherited credential gaps are the most common serious finding.

04

Backup and recovery validation

We test a restore rather than checking that a job reports success. A backup nobody has restored from is an assumption, not a safeguard.

05

Monitoring in place

Monitoring is deployed early so we are seeing real behaviour before we start changing things — and so the baseline is genuine rather than measured after our own work.

Phase Two · Days 31–60

Findings become fixes

Changes are sequenced so your business can absorb them, rather than compressed into one disruptive month.

01

Risk-ranked remediation

The findings from discovery worked through in order of risk and effort, not in the order they were noticed. You approve the sequence.

02

Security baseline

Patch levels brought current, endpoint protection standardised, multi-factor authentication applied where it is missing. Unpatched systems and compromised credentials are the two most common ways in.

03

Standardised configuration

Machines and services brought onto consistent builds, so support is faster and behaviour is predictable across the estate.

04

Documentation written up

The environment recorded in a form another engineer could pick up cold. This is yours, and you keep it whether or not you stay with us.

05

Your team briefed

Staff shown how to raise a ticket and what to expect back. A support process nobody knows how to use does not get used.

Phase Three · Days 61–90

Into steady state

By the end of the first quarter, IT management should feel planned rather than reactive.

01

Outstanding items closed

Anything parked during phase two is finished or explicitly carried forward with a date, not quietly dropped.

02

Baseline metrics established

Ticket volumes, response times, uptime and open risks recorded, so future reviews compare against something real.

03

First business review

A session with whoever owns the budget: what we found, what we fixed, what it cost, and what we recommend next. Written up, not just discussed.

04

Roadmap agreed

A prioritised plan for the following quarters, with indicative costs, so IT spend stops being a series of surprises.

Afterwards

The ongoing rhythm

Steady state means monitoring and patching running continuously, your team raising tickets through one route, and a business review each quarter covering what happened, what it cost, and what is coming. The roadmap is revisited at each review rather than written once and forgotten.

Prioritisation

How we decide what gets attention first

Tickets are ranked by business impact, not by when they arrived. Anything stopping people working outranks anything inconvenient, and a single user unable to work outranks a cosmetic fault affecting everyone. Specific response targets are written into your agreement rather than published here, because a realistic commitment depends on the size of your estate and the cover you have chosen — and we would rather agree something we can meet than advertise something we cannot.

Common Questions

Questions about the transition

Will there be downtime during onboarding?
Discovery causes none — it is read-only. Remediation work in phase two is scheduled into windows that suit your operation, and anything with a risk of disruption is agreed with you before it happens.
What do you need from us?
Mainly access and a named contact. The most common cause of a slow onboarding is incomplete credentials, so gathering those early makes the biggest difference.
What if you find something serious in week one?
We tell you immediately rather than saving it for a report. Anything actively dangerous gets addressed straight away; everything else goes into the ranked list.
Does the 90 days apply to small jobs too?
No. This is the arc for taking on an environment. A single install or a one-off project follows the same principles — assess, plan in writing, schedule, document — over a much shorter span.

If you are considering moving provider, the discovery phase alone is usually worth having — even if you decide to stay where you are.

Book a Call
No obligation, and no charge for the initial conversation.