Frequently asked

Managed IT, compliance and cyber insurance, answered

These are the questions Australian businesses ask us most. If yours is not here, ask us directly.

About inSUPPORT

What is cyber-insured managed services?

Cyber-insured managed services describe a managed IT model in which day-to-day support, compliance-framework-aligned security controls, remediation, and ongoing control maintenance are coordinated with a cyber insurance pathway through licensed insurance partners. inSUPPORT provides this for Australian businesses. Insurance remains subject to eligibility, insurer assessment and policy terms.

What does inSUPPORT's monthly fee cover?

A flat monthly per-user support fee covers managed IT, the security work and compliance-framework-aligned remediation from your audit, ongoing maintenance, and helpdesk. Cyber insurance, backup and security-awareness training are separate, clearly-quoted line items on your quote.

What size business does inSUPPORT work with?

Australian businesses, typically from around 30 up to 300 users.

Do you support Apple and Mac as well as Windows?

Yes. Our helpdesk supports both Windows and Apple Mac.

About the method

What is the 6 Step Cyber Strength System?

It is inSUPPORT's method for taking a business from first audit to compliant and covered, usually within 30 to 90 days. The six steps are Consult, Audit, Remediate, Comply, Insure and Support, run by one team.

How fast can you get my business aligned?

We onboard a client technically in about 4 hours and complete the agreed remediation program within 30 to 90 days depending on complexity. Security posture scores typically rise from around 30 to 40 percent to about 70 to 75 percent in the first week.

Why is the remediation included instead of quoted separately?

Charging for the audit and then quoting more to fix what it found is how most of the industry works, and it leaves businesses half-protected. We include the remediation in your support fee so the work actually gets done.

Cyber insurance and compliance

Does inSUPPORT provide or underwrite the insurance?

No. inSUPPORT does not hold an Australian Financial Services Licence and does not underwrite insurance. Cyber insurance is arranged through our licensed insurance partners and underwritten by some of the world's most reputable insurers, and cover is subject to the insurer's assessment.

Is inSUPPORT ISO 27001 certified?

inSUPPORT builds and manages environments aligned to ISO 27001, and helps clients achieve ISO 27001 certification, so if you want the accreditation, the groundwork is already done. inSUPPORT describes its own environment as ISO 27001-aligned.

Which compliance frameworks do you work with?

We align environments to the frameworks that apply to your industry: Essential 8 as a baseline, plus CIS Controls, the Cloud Control Matrix, NIST CSF, SMB1001, IRAP and ISO 27001 / SOC 2 where they are in scope.

How inSUPPORT compares

How is inSUPPORT different from a traditional IT managed service provider?

A traditional MSP typically bills the audit, the remediation and the monthly support separately, and treats cyber insurance as someone else's problem. inSUPPORT includes the remediation in your support fee and coordinates your IT, compliance and insurance pathway as one model.

How is inSUPPORT different from a large cybersecurity consultancy?

Large consultancies are built for enterprise budgets and timelines. inSUPPORT brings the same class of security and compliance to Australian SMEs, with a 30 to 90 day path to aligned and covered. The business is run by founder and CEO Kane Nawrocki, with more than 25 years in IT.

Cost and value

How much does managed IT support cost per user in Australia?

Most Australian SMEs pay somewhere between $60 and $150 per user per month depending on coverage hours and what is bundled in. inSUPPORT starts at $68 per user per month for business hours, $100 for extended retail and multi-site coverage, and $135 for round-the-clock support. The remediation your audit finds is included in that fee rather than quoted as a separate project.

Is managed IT cheaper than hiring someone internally?

For most businesses under about 300 users, yes, and not only on salary. One internal person cannot cover 24 hours, cannot be an expert in every platform, and takes their knowledge with them when they leave. A managed team gives you coverage, depth and continuity for less than the fully loaded cost of a single mid-level hire.

What is not included in the monthly fee?

Cyber insurance, backup and security-awareness training are separate line items, clearly quoted, so you can see and choose them. Hardware, software licensing and major project work are also quoted separately. Everything else, including the remediation from your audit, sits inside the monthly support fee.

Do I have to sign a long contract?

Terms are agreed up front and set out in your service agreement. We would rather earn the renewal than trap you in a term, and we will tell you before onboarding exactly what you are committing to.

What does a cyber security audit cost?

For managed clients the Cyber Strength Audit is part of onboarding. For businesses that just want a second opinion it is available as a standalone health check, quoted on the size and complexity of your environment. Book one and we will tell you the number before you commit to anything.

Switching providers

How do we switch IT providers without downtime?

Carefully and in a planned sequence. We document your environment first, agree a cutover plan, then move in stages so nothing critical changes without a fallback. Technical onboarding runs to about four hours of your team's time. Most businesses notice the improvement before they notice the switch.

What happens to our data and accounts if we leave?

They are yours. Your tenancy, your domains, your accounts and your data stay in your name, and we hand over documentation and access on exit. Any provider who makes leaving difficult is telling you something about how they win renewals.

Do you deal with our current provider directly?

Yes, if you want us to. Most handovers go more smoothly when the outgoing provider talks to us rather than to you. We will handle the technical conversation and keep you out of the middle of it.

Will you support the hardware we already have?

Yes, provided the operating system is still supported by the vendor and the device is still under manufacturer warranty. Anything outside that we will flag during the audit, with a replacement plan and a cost, rather than a surprise later.

How long does onboarding take?

Technical onboarding is about four hours. The agreed remediation program completes within 30 to 90 days depending on how the environment looks when we start. Security posture scores typically rise from around 30 to 40 percent to about 70 to 75 percent in the first week.

Compliance frameworks explained

What is the Essential 8?

The Essential 8 is a set of eight mitigation strategies published by the Australian Signals Directorate through the Australian Cyber Security Centre. It covers application control, patching applications, configuring macro settings, hardening user applications, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. It is the baseline most Australian businesses are measured against.

Do Australian businesses have to comply with the Essential 8?

It is mandated for many federal government entities and increasingly expected of their suppliers. For most private businesses it is not law, but it has become the practical benchmark that insurers, enterprise clients and tender processes use to decide whether you are a safe counterparty. In effect, the market enforces it even where legislation does not.

What is an Essential 8 maturity level?

The model describes increasing levels of implementation, from partly aligned through to fully aligned with the intent of each strategy. Which level suits you depends on your industry, your risk and what your clients and insurers expect. We assess where you actually sit before anyone talks about a target.

What is SMB1001?

SMB1001 is an Australian cyber security standard designed specifically for small and medium businesses, structured in tiers so an organisation can demonstrate a credible security posture without the cost of an enterprise certification. It is often the practical middle ground for a business that needs to prove something but is not ready for ISO 27001.

What is the difference between ISO 27001 and SOC 2?

ISO 27001 is an international standard for an information security management system, and is certified by an accredited body. SOC 2 is a US-originated audit report on controls, produced by an accountancy firm and more common when selling into American companies. ISO 27001 tends to matter more for Australian and European buyers.

What is NIST CSF?

The NIST Cybersecurity Framework is a US-developed structure organised around six functions: govern, identify, protect, detect, respond and recover. It is not a certification. It is useful as a way to organise a security program and to talk about it with a board.

Do we need to report a data breach in Australia?

Australia has a Notifiable Data Breaches scheme administered by the Office of the Australian Information Commissioner, and organisations covered by the Privacy Act must notify affected individuals and the OAIC when a breach is likely to result in serious harm. Whether it applies to you and what you must do depends on your circumstances, so take it to the OAIC's guidance or your lawyer. What we do is make sure you can tell quickly what actually happened, which is the part most businesses cannot answer under pressure.

Have the Australian privacy rules changed recently?

Australian privacy law has been under active reform, with changes phasing in that tighten obligations and increase penalties. The direction of travel is clear: more responsibility on organisations to protect personal information and to be able to demonstrate it. We keep environments in a state where that demonstration is possible. For what applies specifically to your business, check the OAIC or take legal advice.

Cyber insurance in practice

What do you get asked to evidence at insurance renewal?

In our experience the questions cluster around multi-factor authentication, backup and tested restoration, patching currency, administrative access control, endpoint protection and security awareness training. We keep that evidence current so renewal is a form-filling exercise rather than a scramble.

We have good security. Do we still need cyber insurance?

That is a risk question for you and your broker, not a technical one, and we will not pretend otherwise. What we can tell you is that good security lowers your likelihood of an incident, and insurance covers what happens if one occurs anyway. They solve different problems, and neither replaces the other.

If you are already in trouble

We think we have been breached. What do we do right now?

Do not turn machines off, because you may destroy the evidence of what happened. Disconnect affected devices from the network, stop using compromised accounts, and get someone technical involved immediately. Then work out scope before you work out blame. If you are not already a client, call us anyway and we will tell you what to do first.

Our cyber insurance is up for renewal and we do not know whether we would actually be covered.

This is the most common reason businesses call us, and there is a way to find out before you sign. A Cyber Strength Audit compares what your policy assumes is in place against what is actually running in your environment. Where those two things have drifted apart is exactly where a claim gets difficult.

A competitor in our industry has been breached and our board is asking questions.

The board usually wants three things: are we exposed the same way, what would it cost us, and what are we doing about it. An audit answers the first two in plain English with an evidence trail you can table, and gives you a costed plan for the third. That is a better board paper than reassurance.

Our IT is run by one person and they are leaving.

This is the moment most businesses discover how much lived in one head. Get the environment documented before the notice period ends, not after. We can run that documentation exercise as part of onboarding and take over without a gap.

We failed a client's security questionnaire. Can you help?

Yes, and it is more common than you would think. Those questionnaires usually fail on evidence rather than on security. You may well have the controls and no documented proof of them. We fix the gaps that are real and produce the evidence for the ones that were only ever a paperwork problem.

I am the CFO and IT has landed on my plate. I do not know what I do not know.

That is a normal place to start and not a failing. You do not need to become technical. You need someone who will translate risk into numbers and decisions, and who will sit in the meeting when the board asks. That is what our virtual CIO service is for.

Day to day

Do you provide 24 hour support?

Our Complete package provides round-the-clock follow-the-sun support. Business and Retail packages cover business hours and extended hours respectively. Whichever level you are on, you get a named contact and an escalation path that does not end in a ticket queue.

Do you support remote and hybrid teams?

Yes. Support is remote-first by design, so it makes no difference whether your people are in an office, at home or travelling. Devices are managed and secured wherever they are.

Do you do penetration testing?

Yes, internal and external penetration tests are part of the onboarding audit rather than an upsell afterwards.

What is a virtual CIO and do we need one?

A virtual CIO gives you technology strategy and someone who can represent IT at board or leadership level without a full-time executive salary. You need one when technology decisions have started to carry real commercial consequences and nobody in the room owns them.

Do you help with Microsoft 365 licensing?

Yes. We take advantage of inSUPPORT's Microsoft Cloud Services accreditation to unlock additional discounts, and we regularly find businesses paying for licence tiers they are not using.

Can you secure Copilot and other AI tools before we roll them out?

Yes, and doing it in that order matters. AI assistants inherit whatever data access the user already has, so a rollout on top of loose permissions will surface things across your business that were never meant to be searchable. We audit data access first, then enable.

Do you work with businesses outside Melbourne?

Yes. We are Melbourne-based and support businesses across Australia, with a follow-the-sun helpdesk across Melbourne, New Zealand, Malaysia and the Philippines.

Still have a question?

If we have not answered it here, ask us directly.

Book a Cyber Strength Audit