Services / 01 · Managed IT
Watched, patched, and provably restorable.
Continuous monitoring, patching on a cadence you can audit, backups tested by actually restoring them, and identity administered instead of left on the defaults it shipped with. No promise that nothing will ever go wrong — a documented account of what is being done so that less does.
What is delivered
The work, itemised — not a page of nouns.
Which of these lands in your agreement depends on scope. All work is billed at $165/hr; the assessment determines what monitoring, patching, backup and remediation your environment needs.
Monitoring & maintenance
- Automated endpoint and network monitoring, running continuously
- Operating-system patching on a defined, documented cadence — Windows, macOS, Linux
- Third-party application patching
- Asset inventory and hardware/software lifecycle tracking
- Live documentation: runbooks, network diagram, credential vault
- A monthly health report you can read without a translator
Security controls
- Managed endpoint detection and response, deployed and tuned
- 24/7 detection-and-response triage delivered by a vendor security operations centre
- Multi-factor authentication and conditional access in Entra, configured and enforced
- Managed password vaulting for the accounts that matter
- Quarterly vulnerability scan with a written remediation plan
- Security awareness training and phishing simulation
Backup & continuity
- Endpoint and Microsoft 365 / Google Workspace backup
- Restore tests run on a schedule and documented — a backup nobody has restored is a hypothesis
- Written RTO and RPO targets agreed with you, not assumed
- Full disaster-recovery restore test with a written report
Support & administration
- Remote helpdesk during the coverage window
- Microsoft 365 / Google Workspace tenant administration
- User onboarding and offboarding, including the offboarding nobody remembers to do
- Vendor liaison: your ISP, your line-of-business software publisher, your copier company
- Quarterly business review and a written twelve-month IT budget
Out of scope
The five things a competitor would let you assume.
Every one of these is either a real limit of the service model or a real limit under California law. You will find them in the agreement too. Finding them here first is the point.
- A 24/7 human helpdesk
- Uptime or response guarantees in marketing copy
- Deep support for your line-of-business application
- Remediation of inherited infrastructure
- Anything that requires a contractor's licence
What we need from you
Five conditions. Without them this is theatre.
- You own your tenants and your domain
- Global administrator on your Microsoft 365 or Google tenant, control of your DNS, and your domain registered in your company's name — not a previous provider's. If any of that is currently held by someone else, recovering it is the first project, and the assessment will say so.
- Hardware that is still in support
- Machines running an operating system the vendor still patches, and network equipment the manufacturer still issues firmware for. Where that is not true today, the assessment prices the replacement rather than pretending monitoring compensates for it.
- A maintenance window and a named decision-maker
- Somewhere in the week that machines can reboot, and one person on your side who can say yes. Patching that can never be applied is not patching.
- Licensing bought in your name
- Microsoft, Google and security subscriptions are purchased under your own account or through The Holm Team at a stated markup — either way they stay yours. Nobody should be able to switch off your email because they lost an argument with their provider.
- A written agreement before access
- Scope, coverage window, response targets, exclusions and data handling get signed before credentials are held. If you handle protected health information, that includes a business associate agreement, because an IT provider with access to ePHI carries direct liability under HITECH.
Next step
A managed agreement starts with an assessment.
The IT Health & Risk Assessment documents your current state and informs the scope of monitoring and remediation. Typically 20–40 hours at $165/hr. Credited against onboarding if you sign within 30 days.