How we work

What we commit to in writing, how monitoring actually works, and what changes in your first 90 days

Last reviewed: September 2026

Most IT providers describe their service with adjectives. We would rather you could check ours. Everything on this page is specific, measurable, and something you can hold us to. Where we cannot evidence a claim yet, we say so rather than dress it up.

It is also here so you can read it before you talk to us, rather than receiving it at the end of a sales process.

Our commitments

Support hours and how to reach us. Monday to Friday, 08:00 to 18:00 AEST, excluding Victorian public holidays. One phone number, one email address, and a ticket link. Every request becomes a ticket, so nothing relies on someone remembering a conversation.

What we commit to. We commit to a response: a named person acknowledges your issue, tells you who is on it, and starts work. We do not commit to a fixed resolution time, because promising a repair window for an unknown fault is how providers end up breaking their own promises. Work continues until it is resolved or you agree to stop.

P1 Critical
Business stopped, suspected ransomware or breach, or email and phones down for everyone.
Response: 1 hour, by phone. Updates every 2 hours until a workaround is in place.
P2 High
A team or site is blocked, a key system is degraded, or backups have failed.
Response: 4 business hours, with updates daily.
P3 Normal
One person or device affected, a question, a change request, a new starter.
Response: 1 business day.
Out of hours
P1 only, raised through the on-call number we give you in writing when you onboard.
Response: 4 hours. If we cannot be reached, the commitment falls to next business morning at 08:00, with automated alerting continuing either way.

Every ticket records the time received, the time responded, and the time resolved. Your monthly report shows our performance against these targets, including the months we miss.

Patching and maintenance. Security patches are assessed as they are released and applied on a defined cadence: internet-facing and actively exploited issues within 72 hours, everything else within 14 days, with a change window agreed with you for anything disruptive. The monthly report lists what went out and what was deferred, with reasons.

Backup and recovery. Backups run daily and are monitored, with failures raised as P2. A restore is tested quarterly and the test result is included in your report, because an untested backup is not a backup. Retention is 30 days of daily restore points, longer where compliance requires.

Reporting and review. Monthly, a written report covering incidents, patching, backup status, monitoring highlights, and our response performance. Quarterly, a review with a written summary of what changed, what is at risk, and what to plan for. Annually, your IT roadmap and budget, so a refresh does not arrive as a surprise.

Escalation. If anything is not moving, it escalates to the person accountable, and we tell you who that is: the founder, by name, with a direct number. Nobody is asked to chase an account manager who has moved on.

Changes. We do not make unannounced changes to your systems. Material changes are described in plain language, scheduled with you, and reversible, with the rollback stated before we start.

Security incidents. If we suspect an incident we contact you within the P1 window, contain first where needed to protect your business, preserve what is needed for investigation, and tell you what we know and what we do not. We do not wait until an investigation is complete to tell you something is wrong.

Leaving, and what you take with you. Month to month, with no lock-in contract, no exit fee, and no notice period longer than 30 days. On exit you receive the full documentation set within 5 business days, in open formats, plus reasonable assistance handing over to whoever comes next. That assistance is included, not chargeable.

What is not included, so nobody discovers it later: hardware and licences are passed through at cost unless quoted otherwise; major projects are quoted separately; anything outside support hours other than P1 is next business day; and we are not your insurer, your legal adviser, or your compliance auditor.

How monitoring actually works

Agents on your computers, servers and network report continuously. That telemetry is checked automatically, and anything suspicious is compared against current threat intelligence before a human sees it. An alert that matches something criminals are actively using today is treated differently from a first-time oddity, and that difference is decided by intelligence rather than by who happens to be on shift.

When something fires:

  1. The alert is enriched automatically: what it is, where it came from, whether it is already known to be malicious, and what else on your network is affected.
  2. A person looks at it during support hours, starting with that context rather than a raw log line.
  3. Anything material becomes a tracked case, with a record of what was investigated and what was concluded. You can ask for that record.
  4. If it is real, we contact you and use the response commitments above.

Every month you get a written report covering what was monitored, what alerted, what was investigated, what was closed, what we patched, and whether backups succeeded, along with our measured response performance.

What this is not. We do not operate a staffed 24/7 security operations centre: automated monitoring and alerting run continuously, and human triage runs in support hours plus the P1 on-call path. We do not publish an uptime percentage guarantee, because no small provider can honestly underwrite one. Monitoring is not insurance: it reduces the chance and the impact of an incident, and it does not transfer the risk.

Documentation you own

The three things that actually make a business leave an IT provider are billing surprises, support that only appears when something breaks, and an environment nobody has written down. The third is the one that hurts quietly, because when the person who knew your network leaves, you find out how little of it was recorded. So this is a deliverable, not a chore, and it is yours whether you stay with us for ten years or ten weeks.

For every client we maintain:

  • Asset register. Every server, workstation, laptop, network device, cloud service, licence and support contract, with owner, location and renewal date.
  • Credential register. What exists, who owns it, where it is held, and the last rotation date. Passwords live in a managed vault, never in spreadsheets, documents or email.
  • Network and systems diagram. How it all connects, including the internet path, remote access and cloud dependencies.
  • Backup and recovery plan. What is backed up, how often, where copies live, retention, and the date and result of the last tested restore.
  • Change log and incident log. What changed and why, who approved it, and how to reverse it; and for incidents, what happened, what we did, and what we changed afterwards.
  • Onboarding and offboarding runbooks. The tested steps to give a new starter everything they need on day one, and to close access properly when someone leaves.
  • Quarterly review pack. Your current risk list with priorities, what we recommend, and the cost of doing nothing.

You can request any of it at any time, and you receive the complete set within 5 business days on exit, in open formats, with no conditions attached to it.

Your first 90 days

Changing IT providers has a cost, and pretending otherwise would be dishonest. So nothing changes in your environment until three things exist: your environment is documented, the risks are written down with priorities, and you have approved in writing what we can access. That documentation is yours from day one, whatever you decide.

Days 1 to 30, stabilise. The top risks get fixed: unchecked backups, missing multi-factor authentication, unpatched internet-facing systems, departed staff who still have access. We verify your backups by restoring from them, not by reading a log that says they ran. Your ticket path goes live. Weekly check-ins. What deliberately does not change in month one: no migrations, no re-platforming, no changing your line-of-business software, and no removal of any existing tooling.

Days 31 to 60, standardise. Monitoring tuned to your environment so it alerts on what matters. A patch cadence agreed and running in a window that suits your business hours. Onboarding and offboarding runbooks tested with a real starter or leaver. First monthly report issued, including our measured response performance.

Days 61 to 90, improve. A costed roadmap for the year in plain business terms, a quarterly review scheduled, and anything your previous provider did well, kept. We are not going to change things just to look busy.

What we need from you. A named person with authority to approve changes, thirty minutes a week for the first month, and a current contact list for staff and key suppliers.

What we do not claim

Stated deliberately, because you will hear the opposite elsewhere:

  • We do not operate a staffed 24/7 security operations centre.
  • We do not guarantee an uptime percentage.
  • We do not claim ISO 27001 certification. It is in progress.
  • We do not claim dedicated staffing on any plan.
  • We do not claim a track record we cannot show you. Prismera is a new practice, founded in Melbourne in 2026, and what we offer instead is the founder's career, written commitments, and terms that let you leave.

Book a Free Health Check    Ask Us a Question