Recommended Technology Platform

The hardware and software standards we support

What this page is

This page is the standard we support. It is the Recommended Technology Platform referenced by our General Terms and Conditions, and by your Agreement. Those terms define Minimum Standards as the hardware and software requirements published here, so this page is the document that makes them concrete.

It is a living standard. We review it and update it as vendors change their products and as the threats change, and the version that applies to you is the version published on the day you accept our Proposal. We do not move the goalposts on hardware you already own without telling you first, as the last section explains.

Where you already own something that falls short, we do not simply declare it unsupported. We tell you what it is, why it matters, and what it would take to bring it up to standard, usually as a quoted piece of work you can schedule. We also state the consequence of leaving it as it is, which is that our response-time guarantee does not apply to a problem caused by hardware or software that does not meet these standards.

Workstations

We support computers running a current, vendor-supported release of Windows or macOS. In practice that means Windows 11, and the macOS releases Apple still supports with security updates. A computer that has fallen out of vendor support is out of standard, even if it still turns on.

The minimum we set for a workstation:

  • A 64-bit processor from a current generation, with support for hardware virtualisation.
  • At least 16 GB of memory.
  • A solid-state drive (SSD) of at least 256 GB. A machine running from a mechanical hard drive, or with its drive almost full, is below standard.
  • A TPM 2.0 chip present, with Secure Boot enabled.
  • Full-disk encryption turned on and managed, using BitLocker on Windows and FileVault on macOS.
  • A device still inside the manufacturer's support and security-update window.

We register and manage computers that meet this. For anything older, we say so during onboarding, in your asset register and in the health check, rather than discovering it when it fails.

Servers and virtualisation

Servers run a vendor-supported operating system, at a version the vendor still patches. An end-of-life server operating system is out of standard, whether it is physical or virtual.

  • Backups are in place and verified before we make any change to a server.
  • Changes are made in a change window agreed with you, described in plain language, and reversible.
  • The server's role, owner and recovery plan are recorded in your documentation.
  • Virtualisation runs on a mainstream, vendor-supported hypervisor, and cloud workloads run on the platforms named in your Agreement, such as Microsoft Azure.

Network

Your network is business-grade, and supplied by a vendor that still supports it. Consumer routers and unmanaged switches are out of standard, because they cannot be reliably patched, segmented or centrally managed.

  • A business-grade firewall or router, with current vendor support and firmware updates applied.
  • Managed switches, able to separate traffic into segments, such as staff, guest and servers.
  • Wireless access points running a current wireless security standard, with staff and guest networks kept apart.
  • Remote access through a VPN that requires multi-factor authentication. Management interfaces are not exposed to the internet.
  • The internet path, the firewall rules that matter, and the remote access method recorded in your network diagram.

Identity and access

We standardise on Microsoft Entra ID, the identity service included with Microsoft 365, as the platform for accounts and single sign-on. Where you run a different identity platform, we agree in writing what we support in its place.

  • Multi-factor authentication on every account that can reach business data, including email, accounting, remote access and administrator consoles.
  • A managed password vault for shared and administrative credentials. Passwords do not live in spreadsheets, documents or email.
  • Single sign-on used wherever an application supports it, so fewer passwords exist and access is easier to revoke.
  • Administrator rights kept separate from everyday accounts, and granted only where the role needs them.

Endpoint protection and management

Every computer we manage runs managed endpoint protection, which includes antivirus and endpoint detection and response. We do not support a managed computer that runs only a free or consumer antivirus product.

  • Patches and security updates are applied on the cadence stated in our commitments, and monitored.
  • Endpoints report to our monitoring and alerting platform, so we can see device health, patching and suspicious activity.
  • Mobile devices that hold company email, files or applications are enrolled in mobile device management, so they can be encrypted, locked and wiped remotely.
  • For a device to be enrolled and supported, it must be vendor-supported, joined or registered to your identity platform, enrolled in device management, fully encrypted, and have our management agent installed.

Backup and recovery

Backups run daily and are monitored, and a failed backup is raised with you as a High priority issue. Copies are held separately from the system they protect, and protected against ransomware by being immutable or kept offline, so a compromised account cannot delete them.

  • Retention is 30 days of daily restore points, and longer where a compliance obligation requires it.
  • A restore is tested quarterly, and the result is reported to you. If we cannot state the date and result of the last test, the backup is not yet a documented backup.
  • Your backup and recovery plan records what is protected, how often, where the copies live, and when the last restore was tested.

Business applications

We support the applications your business runs on, where the vendor still supports them.

  • Email and collaboration: we standardise on Microsoft 365, including Teams, SharePoint and OneDrive.
  • Accounting and line-of-business applications: we support the platforms in common business use, and we tell you when one of them has reached end of life or lost its vendor support.
  • Licence ownership stays with you. You hold valid licences for everything you run, and you tell us before installing software that is not on the approved list.

We keep an approved software list for your environment. It names what we support directly, and what we help with on a best-effort basis. Adding something outside that list is your decision, and we say plainly whether we can support it before you commit.

Internet and telephony

  • A business-grade internet connection, from a provider that offers a business service commitment, with a fixed address where a service needs one, and upload capacity sized to your cloud use.
  • Where an outage would stop your business, a second connection or a documented plan for how you keep working until service returns.
  • Phone systems run on a supported platform, hosted or on-premise, and integrate with your identity platform where the vendor allows it.
  • Where your internet or telephony is supplied by another provider, you authorise us to work with that provider on your behalf.

What falls outside this list

Some things sit outside this standard. When we find one, we tell you, we quote to bring it up to standard, and we explain the consequence.

  • An end-of-life operating system, on a workstation or a server.
  • Consumer-grade network equipment and unmanaged switches.
  • Unlicensed, pirated or vendor-unsupported software.
  • Hardware outside the manufacturer's support window.
  • Unmanaged personal devices that hold company data.

The consequence is the same in each case: our response-time guarantee does not apply to a problem caused by hardware or software that does not meet these standards. We still help, and we still work the issue, but we have not promised a response time on something we have asked you to replace.

How this list changes

We review this standard at least once a year, and sooner if a vendor ends support for something widely used, or a threat changes what is safe.

  • We tell you in advance when a change affects hardware or software you own.
  • We give you time to plan a replacement, and we quote it in your annual roadmap rather than raising it as an emergency.
  • The version that applies to you is the one published when you accept our Proposal, and the date it took effect is shown on the page.

If you are unsure whether something in your environment meets this standard, ask us. A short conversation is cheaper than finding out during an incident.

prismera.com.au · hello@prismera.com.au · (03) 9123 1929

← Back to home    Contact Us →