New plans, a security floor, and the end of pay-by-the-hour.
Three changes to how we work with clients. A security baseline everyone meets, four plans in place of the old lineup, and no hourly work for managed clients.
Jump to section
We’ve made some big calls about how we work with clients from here on. Three of them, and they’re related. Every client now meets a security baseline. We’re collapsing the old plan lineup into four clean tiers. And we’re ending pay-by-the-hour work for managed clients. None of these are unilateral, and our team will walk every client through what it means for their account.
Why we’re tightening, and why now
Twenty years in, we’ve watched the threats change. It used to be someone clicking the wrong link. Now it’s state-backed campaigns that target Australian small and medium businesses every week. The Australian Signals Directorate’s Annual Cyber Threat Report 2023-24 puts one cybercrime incident at an average of AUD 49,615 for an Australian small business. For a medium business, AUD 63,602. IBM’s 2024 Cost of a Data Breach Report puts the global average breach at USD 4.26 million.
We’ve been adding controls in layers as the threats have worsened. DNS filtering, so a browser never reaches a known-bad site. Endpoint detection and response. Identity threat detection. Application control. Password managers. Cybersecurity awareness training. The stack is mature.
The problem isn’t the stack. It’s that we let too many clients pick and choose. Buying security in pieces gives you a number on an invoice, but it doesn’t give you protection. We’ve watched clients tell their insurer they have controls, because we offered them. Then at claim time they find out they declined the parts that mattered. That’s on us. We should have insisted.
So we’re insisting.
There’s an operational reason too. Running legacy and modern plans side by side splits our focus across four different client groups, and we can’t deliver consistent service that way. Simplifying the lineup is partly about you, partly about us. Both of us benefit when our team isn’t context-switching between four operational models.
The minimum every client must meet
To remain a CCP client, you need to be working towards (or already meeting) the items below. We’ll help you get there. Until you do, anything we could have prevented with these controls falls outside our agreement, and we are not liable for it.
- Regular security and operational reviews with your account lead.
- Phish-resistant multi-factor authentication (MFA) on every account that touches business data. Not SMS. Authenticator apps or hardware keys.
- Application control on every endpoint. Only the software you need is allowed to run.
- Vulnerability management with regular review and remediation.
- Cybersecurity awareness training for every staff member, refreshed annually.
- A password manager with single sign-on for your day-to-day apps.
- CCP included in onboarding and offboarding of every staff member, every time.
- Regular staff and device audits so the directory matches reality.
- A maintained incident response plan that someone has actually rehearsed.
- Critical business data backed up, off-site, tested for restore.
- MFA enforced through every software vendor you use, not just Microsoft 365.
This is the same set of controls our agreements already require. It’s not novel. It’s what your insurer, your auditor, and your regulator all expect of you. We’re done pretending that’s optional.
The four new plans
We’re collapsing the old lineup into four tiers. Pick the one that matches your size and your risk.
Managed IT. The new baseline. Inclusive fixed-price helpdesk, monitoring, patching, managed cyber security, Microsoft 365 management, and our regular security and tech reviews. Suits an organisation under 25 staff that doesn’t handle sensitive or personally identifiable information.
+ Compliance. Everything in Managed IT, plus the controls high-risk and high-staff businesses need. Vulnerability scanning, application control, our Technology Success Program, centralised logging, and identity threat detection. The right plan if you’re over 25 staff, in a regulated industry, or handling client data that would hurt to lose.
+ Services. Everything in Managed IT, plus the services many businesses juggle across several vendors. Cloud phone systems, internet services, email signature management, printer management. Choose this if you’re under 25 staff, low-risk, and tired of buying IT in pieces.
Complete. Managed IT, plus + Compliance, plus + Services. Everything in one bill, one accountable team.
The full feature list and per-plan detail is on the plans page.
What we’re retiring
Hourly ad-hoc, retainer, and helpdesk-access plans are ending.
We can’t enforce a security recommendation, action an urgent fix, or respond to an incident in time. Not if we have to wait for a billable-work approval first. The pay-by-the-hour model puts every defensive action on a stopwatch you control. That’s incompatible with how cybersecurity actually works in 2025.
Best-effort, non-committed, liability-exempt ad-hoc support will continue to exist. If you’re on ad-hoc only, you also can’t buy individual licences, services or products from us. No Microsoft licences, no phone services, no internet, nothing. Service level agreements are best-effort only.
Already a customer? Switch to one of the new managed plans by the end of 2025 and you get introductory pricing and lower minimums.
If you’re already a managed client on contract
We’ll honour your existing agreement until renewal. If the new equivalent plan would cost the same or less, we’ll migrate you across automatically within six months. If it would cost more, your plan stays as-is until renewal. You can still upgrade to a new plan early without re-signing.
If you’re a managed client out of contract
Your account manager or tech lead is going to call you. We’ll walk through which new plan fits, what changes, and what it costs. Once we’ve notified you, you have 90 days, or until the end of December 2025 (whichever comes first), to decide. If no decision comes in, your current plan keeps running at a 20% premium on legacy rates from that point. By the end of financial year on 30 June 2026, you need to be on a new plan, or with another provider. We’ll always give you no less than 30 days’ notice before any change to your account takes effect.
Capabilities that used to be add-ons
A few capabilities are now included in the relevant plans instead of being optional add-ons. Managed IT or + Compliance, depending on the item.
Security and tech reviews. A standing meeting with your team’s lead technician. Security reporting, licence and usage review, cost optimisation, risk mitigation. Not a sales call.
Identity threat detection and response. Previously available only to managed clients on bigger plans, now standard. We monitor Microsoft 365 and other platforms for signs that an account has been taken over. Then we respond before it spreads.
Microsoft 365 Intune management. Intune is the Microsoft tool that configures and secures company computers. We design, build, and run your deployment. Consistent device configuration, automatic enrolment for new computers, no more half-day setups when someone joins.
Cloud printer management. No print servers. Staff print from wherever they happen to be working. Built for hybrid teams, cloud-only deployments, and the offshore staff a lot of our clients now rely on.
Application control. Computers run only the software they need. Cuts your exposure to malware that arrives by download, email attachment, or a compromised supplier.
Vulnerability scanning and remediation. We scan your systems against the National Vulnerability Database and the CVE (Common Vulnerabilities and Exposures) list. Between them they track more than 230,000 known vulnerabilities, and we fix the ones that matter to you.
Centralised logging. SIEM-grade collection from firewalls, servers and endpoints into one place. Useful for audit trails. More useful for spotting threat signals before they become incidents.
Technology Success Program. Regular meetings with a dedicated technology success manager, focused on compliance, growth, automation, and where technology can pay back its own cost.
What we’d like you to do
Read this. Our team will be in touch with what specifically applies to your account. If you’d rather move sooner, ring the helpdesk and we’ll start the conversation. You can compare the four new plans side by side on our plans page.
We’ve spent twenty years getting to know our clients. We’re not interested in losing any of them through this transition. There’s a path forward for everyone we want to keep working with.