Your industry isn't listed here. The managed IT barely changes.
Retail, manufacturing, logistics, warehousing, professional services. Plenty of our clients are outside the eight sectors we write pages for. Whether we are a fit comes down to your size, how you want IT run, and whether you will do the security basics. Not your sector.
Outside the named eight
What changes about your managed IT when your sector isn't listed
Almost nothing. New starters get devices that arrive configured and ready to use. Identity and email are standardised on Microsoft 365. Backups are tested on the same schedule for every client, because a backup does not care what you sell. A warehousing operator and a law firm run on the same setup underneath, and that is where most of the work is.
Your sector matters in a narrower set of places than you might expect. A compliance framework you are scored against. A line-of-business application nobody else runs. A security clause a large customer has attached to your contract. Those get scoped per engagement rather than per plan tier, which is why they are not in a price list.
If scoping turns up something a sector specialist would genuinely do better, we will say so and point you at one. That is rare. Most businesses need a provider who does the basics properly, asks questions before selling anything, and says plainly when something is outside their scope.
Frameworks and regulators
The obligations that apply to you whatever your industry
- ASD Essential Eight
- Eight mitigation strategies from the Australian Signals Directorate. Cyber insurers, large corporate customers and government-adjacent contracts now score suppliers against them, whatever the supplier does for a living. We move clients up the maturity levels and produce the evidence at each one.
- Privacy Act 1988 and the Australian Privacy Principles
- Hold personal information and the Australian Privacy Principles apply to you, with formal obligations once you pass the small-business threshold. Tranche 2 is widely expected to remove that exemption for about 100,000 more businesses. Access, correction, breach notification and retention each need machinery underneath them.
- Notifiable Data Breaches scheme
- When a breach is likely to cause serious harm, you have to notify the Office of the Australian Information Commissioner and the people affected. Whether the data left, and what was in it, is a technical question. The deadline is not. Without logs and retention you cannot answer either part credibly.
- Cyber insurance questionnaires
- Insurer questionnaires now read like audit checklists, whatever the policy is worth. Multi-factor authentication coverage, backup testing, patching, offboarding discipline, endpoint detection and response. The questions barely change between insurers or between industries. What changes is whether your systems can answer them with evidence.
- Security clauses in customer contracts
- Tier 1 customers, government-adjacent clients, head contractors and landlords increasingly attach security clauses to commercial contracts. A 30-seat firm with one large customer can face the same evidence demands as a 300-seat firm. The work to satisfy those clauses barely changes with your industry.
Common questions
What businesses outside the named eight ask us first
- We're in retail, manufacturing, logistics, or warehousing. Does that count as 'other'?
- Yes, and we have clients in all of them. The eight named pages mark where we have enough clients to see sector patterns, not the limit of who we work with. A managed-IT engagement looks much the same across those industries. Your line-of-business apps differ. Identity, devices, Microsoft 365, backups and patching do not.
- Our industry has very specific line-of-business software. Can you support it?
- Yes, with a clear boundary. We manage the environment it depends on: the Microsoft 365 tenant, the devices, the network, identity and backups. Where the vendor has a cloud-hosted version, we connect it to your security and identity setup. Where it is on-premises, we host or manage the server. Workflow questions inside the application stay with the vendor, and we know where that line is.
- What size of business do you typically work with?
- 20 to 250 staff is our sweet spot, and most of our clients are around 50. Ten seats is the minimum for a managed-IT engagement. Below ten the per-seat economics do not work for either side, and a smaller-scale arrangement will serve you better. We are happy to point you at one.
- We're between 10 and 20 staff. Are we too small for a proper engagement?
- No. Ten seats is the minimum, and the economics work there. A business that size often gets the most out of a real engagement, because the failure modes are sharpest. One person goes on leave and nothing gets patched. The office manager already has another job. Nobody has ever tested the backup. Most of our long-tenure clients were smaller when they started.
- Our setup is unusual. How long does onboarding take?
- Three months, included in the engagement at no extra charge on our standard three-year term. An unusual setup stretches particular work-streams, a more complicated identity migration or a bigger documentation gap. The overall window holds. We would rather spend the time at the start than find the gap two years in.
- Do you have a list of industries you will not work with?
- We do not actively pitch government departments or agencies. Panel arrangements, procurement rhythm and security-clearance overhead do not suit how we work. Specialists who do that daily will serve you better. Everywhere else there is no published 'no' list. If we cannot do your engagement well, we will decline during scoping and tell you why.
The qualifier
Let's see if we're a fit.
Seven questions, one moment of your time. We'd rather tell you now than three months in.