A managed IT support fee in Australia covers the running of your environment: the helpdesk your people ring, the monitoring and patching that happens whether or not anyone rings, and the management of the vendors behind your systems. inSUPPORT prices that support component per user per month, Business from $68, Retail at $100 and Complete at $135, with the security remediation an audit finds included in the fee. Cyber insurance, backup and security-awareness training are quoted as separate line items. That is the honest shape of a support fee. It is not always the shape a quote draws for you.
If you are the person who signs the invoices, you have probably lived the other version. A monthly fee goes out, and quotes keep arriving anyway. The security audit produced a report, then a proposal to act on the report. The server needed something, and that was a project. None of it was necessarily dishonest. It is just very hard to explain to a board what a fee buys when the fee keeps having exceptions.
The reality is that a per-user number on its own tells you almost nothing. Two quotes can carry similar rates and describe completely different services, and the cheaper one can cost more once the extras land. What matters is where the boundary sits between the fee and everything else, and whether that boundary is written down. There is no version of this where the work is free. There is only a version where you can see what it costs.
So this article takes the fee apart the way a CFO would want it taken apart: what sits inside the monthly number, what gets quoted separately and why, where security remediation belongs, what the hours tier actually buys, and how to read a quote so you can defend it upward. The prices are the published ones on this site, and the advice on what to put in the contract comes from the Australian Signals Directorate rather than from a sales deck.
TL;DR: What to remember
- ✅ A support fee buys the running of the environment: helpdesk, monitoring, patching and vendor management. Insurance, backup and awareness training are priced on their own here. Bundling them can be perfectly legitimate, so what you insist on is a schedule that itemises what is inside the bundle.
- ✅ Ask where security remediation sits. If the audit is billed and then the fix is billed separately, every gap found is another project to sell, and you are the one buying it twice.
- ✅ The per-user price mostly buys hours of cover. Business from $68 buys weekday business hours, $100 adds Thursday and Friday evenings and Saturday mornings, and $135 buys 24 hours a day.
- ✅ Get the boundary in writing. ASD's advice to any business engaging a provider is to put security expectations and incident notification in the contract, not in the sales conversation.
Contents
- What is actually inside a managed IT support fee?
- What gets quoted separately, and why?
- Where does security remediation sit, and why does it matter?
- What does the hours tier actually buy?
- How do you read a quote so you can defend it to the board?
- Questions finance teams ask about the fee
What is actually inside a managed IT support fee?
Strip away the brochure and a support fee buys four kinds of work. A helpdesk that answers when a user cannot log in, a printer vanishes or an email will not send. Monitoring that watches servers, network gear, cloud services and backup jobs for the alert that arrives before the outage does. Patching and maintenance applied on a schedule rather than when somebody remembers. And vendor management, which means the provider chases your software suppliers and your telco so that you do not have to.
inSUPPORT's IT support pricing page prints what sits inside each tier in exactly those terms: proactive monitoring and security remediation on every tier, vendor management on the Business tier, and a virtual CIO on the Retail and Complete tiers. Beneath the tiers the same page publishes a fuller service inclusions list, covering 24/7 monitoring of critical systems, monthly patch management, operating system health checks, incident and problem management, service level agreements, licensing compliance, line-of-business application support, roadmap planning and disaster recovery planning and testing. Read that list slowly, because it is the boundary. Anything not on it is a conversation.
One item on that list is missing from most support fees, and it is the reason the fee is built the way it is. Security remediation, meaning the fixes an audit turns up, sits inside the support fee rather than coming back as a project quote. It gets its own section below, because it changes how the whole relationship behaves.
The plain test for any provider is the same, and it works on the one you already have. Ask for the inclusions list in writing, then ask which of last year's invoices fell outside it. A provider who runs the account well already has both answers, and one who needs a fortnight to find them has told you how closely the account is being watched.
What gets quoted separately, and why?
Cyber insurance, backup and security-awareness training are separate, clearly quoted line items, and the reason deserves to be said plainly. Each one is a distinct product with its own cost. A fee that claimed to include all three would either be inflated for the businesses that do not want them or quietly thin for the ones that do. Naming them is the honest version, and it is also the version a finance team can actually budget.
Compliant Backup is priced on its own because a tested, point-in-time restore is real infrastructure rather than a tick in a box: built to the Essential 8 backup controls, tested, and with the restore itself verified, because a backup nobody has tested is a hope rather than a plan. The Education add-on runs a phishing platform that tailors simulated attacks to each individual user based on how that person did in the fortnight's online class. The insurance line coordinates cyber insurance through licensed insurance partners; the insurers underwrite it, and cover is subject to the insurer's assessment.
Three more things sit outside most support fees, including this one: hardware, software licensing and major project work. Licensing is the one that surprises finance teams, because it is a per-user cost that arrives whether or not you have a provider at all. Microsoft's own Australian pricing lists Microsoft 365 Business Premium at AU$32.90 per user per month on an annual subscription, before GST, covering identity and access management for up to 300 users. A support quote that appears to swallow that number is either passing it through inside the fee or leaving it out. Either way, ask which. Worth noticing too: Microsoft states its figure before GST, while the support tier prices published on this site do not state a GST position either way, so that is one more thing to confirm on a quote rather than assume.
The reframe that helps most is this. A separately quoted extra is not a hidden cost. A hidden cost is one you did not see coming. A named line item on the quote is the opposite of that, and it is what lets you say yes to backup and no to something else without renegotiating the whole agreement.
Where does security remediation sit, and why does it matter?
In the model most of the industry runs, an audit is a paid piece of work that produces a report, and the report produces a second quote to fix what it found. That is a legitimate way to sell IT. It also means the provider that identifies a gap is rewarded with a second project, and the customer who paid for the audit is now holding a list of problems with a price beside each one.
inSUPPORT priced the remediation inside the support fee instead. The onboarding audit, which includes a security audit, a gap analysis and internal and external penetration testing, produces an agreed remediation plan, and the work on that plan is part of the monthly fee rather than a project invoice. The provider that finds the gap is not paid again to close it. That is checkable on the managed IT services page, which is why it persuades where adjectives would not.
What remediation means in practice is mostly the Australian Signals Directorate's Essential Eight, the eight mitigation strategies ASD names as the most effective of its published set: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. An audit against those controls tends to find administrator access nobody needed, devices nobody manages and accounts that were never closed when people left. Fixing those is the remediation, and it is where most of the first week's work goes.
ASD's guidance for businesses engaging a provider puts the commercial logic in one sentence: the cost of remediation after a compromise far exceeds the cost of upfront implementation. A fee that pays for the upfront work is cheaper than one that waits for the incident. One note on currency, because framework guidance moves. ASD publishes the Essential Eight maturity model alongside the eight strategies and updates it regularly, and in June 2026 it opened a consultation on evolving the Essential Eight into a broader Essentials series, which ran until 12 July 2026. None of the eight controls above changed as a result, and ASD's own position was that organisations already using the Essential Eight could expect strong alignment with their existing controls and investments. The list is accurate at September 2026 and worth checking against the current publication before anyone writes a maturity target into a contract.
What does the hours tier actually buy?
Most of the difference between $68, $100 and $135 is hours. The Business tier covers Monday to Friday, 8:30am to 5:30pm. The Retail tier adds Thursday and Friday evenings to 9:00pm and Saturday mornings from 8:30am to midday. The Complete tier is 24 hours a day, seven days a week. The monitoring, security remediation and patching are the same work at every level; what you are choosing is when a person answers the phone.
The Retail tier exists for a specific reason. inSUPPORT came out of retail IT, where the till, the stock system and the card terminal matter most on Thursday night and Saturday morning, which is exactly when a business-hours helpdesk is shut. If your busiest trading happens at the hours most providers are closed, that tier is the one to price, and the gap between $68 and $100 is the cost of somebody answering at 7pm on a Friday.
Two other things on the pricing page are worth noticing. The Retail and Complete tiers list a virtual CIO, which is strategy-level advice in the room when you are planning, while the Business tier lists vendor management instead. And the pricing FAQ is explicit that an issue arising outside your contracted hours still reaches a 24/7 follow-the-sun helpdesk. Outside your hours is not the same as nobody home, and the difference between the tiers is what you are entitled to rather than whether the lights are on.
The practical onboarding facts, as the company reports them: technical onboarding takes about four hours once the provider has access to the Microsoft environment, and the initial onboarding includes a site visit to document how the business operates, inspect the infrastructure and meet the people who matter. That is the company's own figure rather than an audited one. After onboarding, the fee is the fee, for Australian businesses of roughly 30 to 300 users, run remote-first.
How do you read a quote so you can defend it to the board?
A CFO does not need to understand the technology to judge a managed IT support fee. The quote either answers a short list of plain questions or it does not, and a provider who cannot answer them for the person paying has told you something useful. Work through these six before you sign anything, whether the provider is new or the one you already have.
- The inclusions list, attached to the agreement. Not a summary on a proposal. The actual list of what the fee covers, as a schedule to the contract, so that the boundary survives the salesperson leaving.
- Where the fee stops and a project starts. Who pays when the audit finds something, and which clause says so. This is the single line that decides whether your provider profits from finding problems.
- Every add-on as its own named line. Insurance, backup, awareness training, licensing. One combined number for all of it is not simplicity, it is a decision somebody made on your behalf about what you are buying.
- The licensing question, asked out loud. Passed through inside the fee, billed separately, or not included at all. All three are legitimate and only one of them is what you assumed.
- The hours a human answers, against your own trading hours. The hours on the website are the starting point, not the answer. Ask what happens at your busiest hour, not at eleven on a Tuesday.
- The term and the notice period. Rarely published by anyone, including on this site, so ask for both in writing before you sign. A fee you cannot leave is a different product from a fee you can.
What ASD says to put in the contract
The Australian Signals Directorate's advice for organisations engaging a managed service provider was last updated in 2021, and it is still the clearest short statement of what belongs in the contract. It is not the whole of what ASD publishes: those same pages point readers to the Information Security Manual as the broader framework. But it is short enough to lift straight into a negotiation. State your cyber security expectations upfront. Require the provider to implement cyber security guidance such as the Essential Eight in its own environment. Include cyber security incident notification clauses, so the provider is obliged to tell you when its systems are compromised. And keep a current record of which of your systems the provider can reach, and how.
ASD also publishes five questions to put to the provider itself: are you implementing better practice cyber security, are you securely administering your systems and services, are you monitoring activity on them, are you regularly assessing them, and are you prepared for and able to respond to a cyber security incident. The reason those questions belong in a conversation about money is that a provider holds privileged access to your environment. Their security is part of what your fee is buying, whether or not anybody itemised it.
If you already have a provider
Run the six at renewal, when straight answers are owed, and pair them with the twelve questions to ask your IT provider before you renew, which go wider, into proof and into the day something breaks. If the answers point to a move, how long it takes to change IT providers sets out the four-to-eight-week shape of the job and the three things to settle before you give notice. One awkward answer is not a reason to leave. A pattern of them, on the questions about money, usually is.
Questions finance teams ask about the fee
Is a lower per-user fee actually cheaper?
Only if the boundary is the same, and it usually is not. A managed IT support fee that quotes remediation, after-hours calls and patching projects separately can cost more across a year than a higher fee that does not, because the second invoice is where the difference lives. Compare boundaries before you compare rates, and put last year's out-of-fee spend beside the monthly number. The fee you can forecast is the one whose exceptions are written down.
Do we need someone technical to judge a managed IT quote?
No. Every line can be explained in plain English: what is included, what is quoted separately, who pays when the audit finds something, and what hours a person answers. A provider who cannot explain the fee to the person paying it has answered a bigger question than the one you asked. If you want an independent read before deciding, a Cyber Strength Audit turns the environment into a costed list rather than an opinion.
How long before a new fee settles down?
Technical onboarding takes about four hours once access exists, which is inSUPPORT's own reported figure rather than an audited one, and the agreed remediation programme then runs over a window that depends on what the audit finds and how complex the environment is. Expect the first months to carry that remediation work, which is the point of having it inside the fee. Once the agreed items are closed, the monthly number is the monthly number, with the add-ons you chose sitting beside it as named lines.
Where do we start if we cannot explain our current IT spend?
Pull twelve months of invoices and separate the recurring fee from everything else, then ask your provider for the inclusions list in writing. That comparison alone usually explains the gap. The next step is an independent look at the environment itself: a Cyber Strength Audit documents what is actually configured, ranks the gaps by business impact and returns a costed path to closing them. The number it produces is one you can put in front of a board.
If your monthly fee keeps producing exceptions, the fastest way to find out why is to look at the environment rather than the invoice. A Cyber Strength Audit assesses what is actually configured against the compliance frameworks that apply to your industry, ranks the gaps by business impact and gives you a costed path to closing them, in plain English. Kane Nawrocki has spent more than 25 years in IT, and inSUPPORT has run more than 1,500 cyber audits for Australian businesses of roughly 30 to 300 users. If you go on to managed support, the remediation the audit finds sits inside the fee. Finding the problem and fixing it end up on the same side of the boundary.
Book a Cyber Strength Audit →Sources
- "How to manage your security when engaging a managed service provider", Australian Signals Directorate. The advice to get security into the contract: state expectations upfront, require the provider to implement the Essential Eight, include cyber security incident notification clauses, and keep a current record of which systems the provider can access and how. Also the line that the cost of remediation after a compromise far exceeds the cost of upfront implementation. First published 21 December 2018, last updated 6 October 2021. Read 18 September 2026. cyber.gov.au
- "Questions to ask managed service providers", Australian Signals Directorate. The five questions a customer should put to a provider: implementing better practice cyber security, securely administering systems and services, monitoring activity, regularly assessing them, and being prepared to respond to an incident. First published 24 March 2017, last updated 6 October 2021. Read 18 September 2026. cyber.gov.au
- "Essential Eight explained", Australian Signals Directorate, the web page at the link below rather than the companion PDF. Names the eight mitigation strategies that make up the Essential Eight, which is what security remediation inside a support fee mostly consists of, and records that the supporting maturity model is updated regularly. The page carries First published 01 Feb 2017 and Last updated 27 Nov 2023. Read 18 September 2026. cyber.gov.au
- "Consultation on evolution of Essential Eight", Australian Signals Directorate. ASD's announcement that it was consulting on evolving the Essential Eight into a broader Essentials series grounded in the Information Security Manual, with consultation running until 12 July 2026 and organisations already using the Essential Eight able to expect strong alignment with their existing controls. Published 15 June 2026. Read 18 September 2026. cyber.gov.au
- "Microsoft 365 Business Premium", Microsoft Australia. The published price of AU$32.90 per user per month paid yearly, before GST, covering identity and access management for up to 300 users, used above to show that licensing is a per-user cost separate from a support fee. Read 18 September 2026. microsoft.com
Related Reading
- IT Support Pricing
- Managed IT Services
- Twelve Questions to Ask Your IT Provider Before You Renew
- How Long Does It Take to Change IT Providers?
- The 6 Step Cyber Strength System
About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.
Content reviewed by Probably Genius for accuracy and relevance.
inSUPPORT provides managed IT and cyber security services. It is not an insurer, insurance broker or underwriter and does not hold an Australian Financial Services Licence. Where cyber insurance forms part of a plan, it is arranged through licensed insurance partners and underwritten by the insurer. Cover is subject to the insurer's assessment, the policy terms and the Product Disclosure Statement and Target Market Determination. This article is general information about IT and security practice, not financial product advice, and it does not take account of your objectives, financial situation or needs.
CLICK HERE


