Kane Nawrocki is the founder and CEO of inSUPPORT, a Melbourne-based managed IT and cyber security provider built for Australian businesses of roughly 30 to 300 users. He has spent more than 25 years in IT, the business has served 50 or more companies, and behind it sit 1,500 or more cyber audits and 5,500 or more desktops and users supported. The monthly support fee already includes the security remediation an audit finds, and that decision is his, taken after two decades of watching providers bill the audit and then bill the fix.
If you are reading up on the person behind an IT company, you are usually about to trust that company with something you cannot check yourself. That is fair enough. The industry has no shortage of people who can talk fluently about security, and fewer who have built, broken and repaired the systems they describe.
A fee with the remediation inside it only works if the provider can carry whatever the audit turns up, which is why the model is built for businesses of a certain size and why he is straight about who it does not suit.
What follows is where the 25 years went, the night the business got its name, the mechanism behind pricing remediation into the fee, and the short list of things he will not promise. If you only want the commercial logic, read the third section alongside the support pricing.
TL;DR: What to remember
- ✅ More than 25 years in IT, starting at seventeen building servers in a mate's parents' garage, then mining sites, retail rollouts, the Telstra partner channel and a stint building service-management software.
- ✅ The business got its name in 2022, in a conversation at the Crown in Perth with Matt Condy. Support on its own had become a commodity, so the "in" stands for insured.
- ✅ Two decisions were locked in that night and still define the company: the remediation an audit finds sits inside the support fee, and the cyber insurance pathway is coordinated by the same team that runs the IT, through licensed partners.
- ✅ Support is priced per user per month from $68. Insurance, backup and security-awareness training are separate, clearly quoted line items, and he corrected his own marketing downward to say so.
- ✅ What he will not claim: a certified framework position, an Essential Eight maturity level in public, or any prediction about whether an insurer will pay.
Contents
- Where 25 years in IT actually went
- The night the business got its name
- Why the remediation sits inside the fee
- What he will not promise
- Questions people ask about Kane and the model
Where 25 years in IT actually went
He started at seventeen, building servers in a mate's parents' garage. From there his published account runs through mining-sector IT, where the big vendors paid for his certifications, the Telstra partner channel, data and business-intelligence work for national retailers, and a stint building service-management software. That is not a tidy career. It is the kind of path that puts one person in front of the same problem in a dozen different industries, which is worth considerably more than a tidy one.
The problem kept being the same. Small and medium businesses were being sold security in pieces, and the pieces never added up to actual protection. An audit from one company. A firewall from another. Backups that ran every night and had never once been restored. A policy renewal handled by a broker who had never seen the systems it was written against. Every piece was defensible on its own, and together they left the business exposed.
His summary of the answer is four short sentences, and they are on his own About page: find the best tools, make them work together, automate the process, lock it down. It sounds obvious until you notice how few providers do the second and fourth parts. Making tools talk to each other is unglamorous engineering that nobody sells, and locking things down means taking choices away from people who would rather keep them.
That is also where the standards come from. inSUPPORT holds Microsoft Cloud Services accreditation, and he is vendor-certified across the major security and infrastructure platforms. The longer version of that background is on the site, and the figures on this page match the ones published there.
The night the business got its name
The name arrived in 2022, in a conversation at the Crown in Perth between Kane Nawrocki and Matt Condy, now the company's Technical Experience Manager. The reasoning was blunt. Every IT shop in the country offered support, so support on its own had stopped meaning anything. The business would be inSUPPORT, and the "in" would stand for insured. The whole model was hiding in the name before the model existed.
Two decisions were locked in that night, and they still define the company. First, the security work matters more than the invoice, so the remediation your audit finds is included in your support fee rather than arriving later as a surprise bill. Second, the cyber insurance pathway is arranged and coordinated by the same team that runs your IT, rather than left for you to chase down separately. On that second point the plain words matter, and they are the same words used on every page of the site: the cover is arranged through licensed insurance partners and underwritten by the insurers, cover is subject to the insurer's assessment, and the company holds no Australian Financial Services Licence, which is exactly why the pathway runs through licensed partners rather than through the IT provider.
Two timelines sit close together in that story and careful readers keep merging them, so it is worth separating them. The brand did not start from a blank page. It came out of RIGA, Retail Innovation Group Australasia, a long-standing IT, tech and telco partner that worked predominantly in retail, and around 2020 RIGA became Real Innovation Group and moved into construction, automotive, professional services, agriculture, manufacturing and real estate. That is the parent company's history. The trading brand was named in 2022, and the two are not one story.
The retail heritage did not disappear, which is why there is a support tier built around late-night trading and Saturday mornings, when most helpdesks have long gone home. The trigger for turning the idea into a product was watching the Optus and Medibank breaches land on household names. It made something obvious: the small and medium market needed the same protection the big end of town had suddenly started scrambling for, and nobody was building it for them.
Why the remediation sits inside the fee
Here is the mechanism, because the mechanism is the whole argument. The traditional way to sell security to a smaller business is in three bills: one for the audit, one for the remediation, usually a good deal larger than the first, and a third for ongoing support. Each bill is legitimate on its own. The problem is the incentive underneath. When the audit and the fix are billed separately, every gap the provider finds is a new project for the provider, so the report gets longer, the quote gets bigger, and the business is left holding a folder of findings and a decision about which ones it can afford this year.
Pricing the remediation inside the support fee removes that incentive. The provider that identifies the gap is not rewarded with a second project for closing it, so the audit stops being a sales document and becomes a work order for jobs already paid for. That is checkable in a way adjectives never are. It is written into the published pricing and set out again in the 6 Step Cyber Strength System, and any buyer can ask a competing provider to point at the clause in their own agreement that says the same thing.
The honest version of the price is the version he insisted on. Support is charged per user per month: Business from $68, Retail at $100, and Complete round-the-clock cover at $135. That $68 is the support component only. Cyber insurance, backup and the security-awareness platform are separate, clearly quoted line items, and when earlier marketing described the offer as covering everything, he corrected it downward himself. A founder who edits his own claims to make them smaller is rarer than he should be, and every claim that survives that editing is one a buyer can check.
The Australian Signals Directorate published its own questions for organisations engaging a managed service provider, last updated in October 2021: whether the provider implements the Essential Eight itself, administers its systems securely, monitors activity, regularly assesses its own systems, and is prepared to respond to an incident. That guidance is not the whole of what ASD publishes, and the page itself points on to the Information security manual. Those are still good questions, and they are all about capability. The fee question sits underneath them, because a provider can be perfectly capable and still be structured so that finding your problems earns them money. He settled that one structurally rather than with a promise: the provider who finds the gap is the one who closes it, inside the fee already agreed. Nothing to quote back at him, and nothing to argue about in month three. What the audit itself involves, step by step, is set out in what actually happens in a Cyber Strength Audit.
What he will not promise
Straight talk includes the boundaries, so here they are. inSUPPORT aligns environments to the Essential Eight and to the other compliance frameworks that apply to a client's industry. It does not state a target maturity level in public, because the right level depends on the environment, and it does not describe the Essential Eight as a certificate, because it is not one. ASD's own position is that the Essential Eight is a minimum set of preventative measures, that it will not mitigate all cyber threats, that four maturity levels are defined from Zero to Three, and that there is no requirement for an implementation to be certified by an independent party. The framework references in this article were checked against ASD's published guidance on 18 September 2026.
The same discipline applies to ISO 27001. The company is ISO 27001-aligned and helps clients pursue certification where they want it. It is not certified itself, and it says so. On insurance, nobody there will tell you a claim will be paid, because no IT provider can guarantee an insurer's decision. What the team can do is maintain the environment against the controls a policy assumes, keep the evidence current, and read an existing policy against what is technically in place. The rest belongs to the insurer, and saying otherwise would be a promise about somebody else's money.
He is equally direct about who the model is not for. It is built for businesses of roughly 30 to 300 users that have outgrown break-fix IT, and it standardises environments to a known-good state. The controls are standardised because exceptions create risk, and a business that wants to keep its own stack and direct the work is better served somewhere else. He would rather say that in the first conversation than discover it in month three, which is a commercial position as much as a technical one: the model only works if the environment is actually run the agreed way.
That combination is what a buyer is really evaluating when they ask who runs this company. A long record with receipts on it, a name that is a thesis, a fee structure that removes the industry's worst incentive, and a short list of claims the business refuses to make. He still takes the first conversation himself, which is where any of it can be tested against your own environment.
Questions people ask about Kane and the model
Who is Kane Nawrocki?
Kane Nawrocki is the founder and CEO of inSUPPORT, a Melbourne-based managed IT and cyber security provider working with Australian businesses of roughly 30 to 300 users. He has more than 25 years in IT, from building servers as a teenager to running enterprise security and compliance for Australian businesses, and he is vendor-certified across the major security and infrastructure platforms. The business has served 50 or more companies and has 1,500 or more cyber audits behind it.
What does 25 years in IT actually change about the way the work gets done?
It shows up as opinions rather than options. A provider without that mileage tends to present you with a menu and let you choose; someone who has restored enough broken environments arrives with a standard and explains why it is the standard. The practical difference for a business owner is where the thinking happens. You are not asked to adjudicate technical trade-offs you have no way of judging, and the reasons behind a decision are explained in plain English if you want them.
What actually happens once a business engages inSUPPORT?
It starts with an onboarding audit: a security audit, a gap analysis, and internal and external penetration testing, followed by a conversation about the negotiables, meaning what must change, what can be handled another way, and what stays as it is with the risk written down. An agreed remediation plan comes out of that and is worked through, with the remediation sitting inside the support fee rather than arriving as a separate project. The published timeframe for completing an agreed programme depends on what the audit finds, so ask for it against your own environment rather than a brochure figure.
What is the first step if I want to work with inSUPPORT?
Book a Cyber Strength Audit. It assesses your environment against the compliance frameworks that apply to your industry and against the technical controls a cyber insurer expects to see, and it ends with a plain-English report and a costed remediation path. There is no obligation, and there are two ways to start: book time with a person, or start the audit yourself through the self-service portal. Both are on the audit page.
The record is on the page and on the site: more than 25 years in IT, 50 or more businesses served, 1,500 or more cyber audits, a fee structure printed on the pricing page, and a short list of claims the business will not make. A Cyber Strength Audit is where that gets tested against your own environment, with a plain-English risk picture and a costed remediation path at the end of it. If you go on to managed support, that remediation sits inside the fee rather than arriving as a separate project.
Book a Cyber Strength Audit →Citations
- "Questions to ask managed service providers, Australian Signals Directorate", ASD's own questions for organisations engaging a managed service provider: whether the provider implements the Essential Eight, securely administers its systems and services, monitors activity, regularly assesses its systems, and is prepared for and able to respond to cyber security incidents. The page records its own last update as 06 October 2021 and refers readers on to ASD's Information security manual. Read 18 September 2026. cyber.gov.au
- "Essential Eight maturity model, Australian Signals Directorate", The source of the boundaries stated above: the Essential Eight outlines a minimum set of preventative measures, it will not mitigate all cyber threats, four maturity levels are defined from Maturity Level Zero to Maturity Level Three, and there is no requirement for an organisation to have its implementation certified by an independent party. Read 18 September 2026. cyber.gov.au
- "AFS licensees, Australian Securities and Investments Commission", Confirms that a business carrying on a business of providing financial services must hold an Australian financial services licence, or be authorised as a representative of a licensee, and that providing financial product advice or dealing in a financial product are among the activities that require one. This is why the insurance pathway described above runs through licensed partners. Read 18 September 2026. asic.gov.au
- "Annual Cyber Threat Report 2024-2025, Australian Signals Directorate", Context for the market this model was built for: more than 84,700 cybercrime reports in the year, on average one every six minutes, and an average self-reported cost of cybercrime per report for small business of $56,600, up 14 per cent. Read 18 September 2026. cyber.gov.au
Related Reading
- The 6 Step Cyber Strength System
- Twelve Questions to Ask Your IT Provider Before You Renew
- What Actually Happens in a Cyber Strength Audit
- Cyber Strength Audit
- Managed IT Services
About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.
Content reviewed by Probably Genius for accuracy and relevance.
inSUPPORT provides managed IT and cyber security services. It is not an insurer, insurance broker or underwriter and does not hold an Australian Financial Services Licence. Where cyber insurance forms part of a plan, it is arranged through licensed insurance partners and underwritten by the insurer. Cover is subject to the insurer's assessment, the policy terms and the Product Disclosure Statement and Target Market Determination. This article is general information about IT and security practice, not financial product advice, and it does not take account of your objectives, financial situation or needs.
CLICK HERE


