Services / 01 · Managed IT

Watched, patched, and provably restorable.

Continuous monitoring, patching on a cadence you can audit, backups tested by actually restoring them, and identity administered instead of left on the defaults it shipped with. No promise that nothing will ever go wrong — a documented account of what is being done so that less does.

01

What is delivered

The work, itemised — not a page of nouns.

Which of these lands in your agreement depends on scope. All work is billed at $165/hr; the assessment determines what monitoring, patching, backup and remediation your environment needs.

Monitoring & maintenance

  • Automated endpoint and network monitoring, running continuously
  • Operating-system patching on a defined, documented cadence — Windows, macOS, Linux
  • Third-party application patching
  • Asset inventory and hardware/software lifecycle tracking
  • Live documentation: runbooks, network diagram, credential vault
  • A monthly health report you can read without a translator

Security controls

  • Managed endpoint detection and response, deployed and tuned
  • 24/7 detection-and-response triage delivered by a vendor security operations centre
  • Multi-factor authentication and conditional access in Entra, configured and enforced
  • Managed password vaulting for the accounts that matter
  • Quarterly vulnerability scan with a written remediation plan
  • Security awareness training and phishing simulation

Backup & continuity

  • Endpoint and Microsoft 365 / Google Workspace backup
  • Restore tests run on a schedule and documented — a backup nobody has restored is a hypothesis
  • Written RTO and RPO targets agreed with you, not assumed
  • Full disaster-recovery restore test with a written report

Support & administration

  • Remote helpdesk during the coverage window
  • Microsoft 365 / Google Workspace tenant administration
  • User onboarding and offboarding, including the offboarding nobody remembers to do
  • Vendor liaison: your ISP, your line-of-business software publisher, your copier company
  • Quarterly business review and a written twelve-month IT budget

The round-the-clock security triage is purchased from a vendor that staffs a security operations centre. This is vendor-delivered, not an on-call rotation. Being precise about this means you know exactly what you are paying for and what will actually be there when you need it.

02

Out of scope

The five things a competitor would let you assume.

Every one of these is either a real limit of the service model or a real limit under California law. You will find them in the agreement too. Finding them here first is the point.

A 24/7 human helpdesk
Monitoring runs around the clock and vendor security-operations-centre triage runs around the clock. A human answering your call about a jammed printer does not. After-hours support is provided as an emergency line at a higher rate on a best-effort basis, and this is documented in the agreement.
Uptime or response guarantees in marketing copy
Response targets belong in a signed agreement where they are specific, measurable and negotiated against what you are paying. Published SLA numbers on a services page are decoration. Nobody has ever collected on one.
Deep support for your line-of-business application
The platform underneath your application is kept patched and backed up, and vendor liaison is handled on your behalf. Application-level support stays with the publisher, and that is written into the agreement.
Remediation of inherited infrastructure
Onboarding covers deploying monitoring, patching, backup and security onto your environment. It does not cover fixing forty unpatched machines, an end-of-support firewall and a backup that has silently failed since spring. Remediation of legacy infrastructure is a separate project, quoted at standard hourly rates and completed before the managed agreement starts.
Anything that requires a contractor's licence
New cable runs, jacks, patch panels, rack or access-point mounting, and electrical work are licensed trades in California and are not part of managed IT. Specifications are provided and you contract the licensed trade directly.
03

What we need from you

Five conditions. Without them this is theatre.

You own your tenants and your domain
Global administrator on your Microsoft 365 or Google tenant, control of your DNS, and your domain registered in your company's name — not a previous provider's. If any of that is currently held by someone else, recovering it is the first project, and the assessment will say so.
Hardware that is still in support
Machines running an operating system the vendor still patches, and network equipment the manufacturer still issues firmware for. Where that is not true today, the assessment prices the replacement rather than pretending monitoring compensates for it.
A maintenance window and a named decision-maker
Somewhere in the week that machines can reboot, and one person on your side who can say yes. Patching that can never be applied is not patching.
Licensing bought in your name
Microsoft, Google and security subscriptions are purchased under your own account or through The Holm Team at a stated markup — either way they stay yours. Nobody should be able to switch off your email because they lost an argument with their provider.
A written agreement before access
Scope, coverage window, response targets, exclusions and data handling get signed before credentials are held. If you handle protected health information, that includes a business associate agreement, because an IT provider with access to ePHI carries direct liability under HITECH.

Next step

A managed agreement starts with an assessment.

The IT Health & Risk Assessment documents your current state and informs the scope of monitoring and remediation. Typically 20–40 hours at $165/hr. Credited against onboarding if you sign within 30 days.