TSR Solutions Managed IT & security

Which package fits?

Three levels of cover for businesses that want IT run for them, and one for businesses with their own IT team. Every row below is in the data, so what you see is what the contract says.

Foundation

Monitored, patched and backed-up workstations and servers, with a help desk your people can call during business hours.

  • 24×7 monitoring of workstations, servers and the network
  • Unlimited help desk and onsite support during business hours
  • Windows and Windows Server patched on a defined policy
  • Managed backup for servers, with jobs checked and failures chased
  • Microsoft 365 or Google Workspace user and licence administration
  • Endpoint protection and security awareness training for every user

Guardian

Most chosen

Full managed IT with 24×7 detection and response, built on Microsoft 365 Business Premium.

From $175 per user / month

  • 24×7 managed detection and response by a staffed security operations centre, not an alert queue
  • Security and system logs kept off the machine that generated them, so an intruder cannot erase the copy
  • DNS filtering on and off the corporate network to break the tool-download and command-and-control step
  • Defender for Business managed through Intune, already licensed in Business Premium, no extra agent
  • MFA and Conditional Access enforced in Entra ID, with self-service password reset
  • 24×7 workstation monitoring, patching and secure remote support on a defined patch policy

Sentinel

Everything in Guardian, plus vCISO leadership, compliance tooling and the security add-ons included as standard.

  • Everything in Guardian: monitoring, patching, help desk, identity, 24×7 detection and response
  • vCISO leadership that owns the security programme and speaks to your auditor
  • Compliance assessment and management platform with continuous evidence collection
  • Incident response plan, hosted response platform and tabletop exercises
  • Disaster recovery testing twice a year, with results documented
  • Microsoft 365 data loss prevention policies configured and reviewed

Co-Managed Guardian

Guardian's monitoring, security operations and tooling behind your own IT team.

From $110 per user / month

  • 24×7 managed detection and response by a staffed security operations centre
  • Logs kept off the machine that generated them, and DNS filtering on and off the network
  • Patching, configuration enforcement and zero-touch deployment for every endpoint
  • Help desk and onsite support for security, servers and the network, plus a 24×7 on-call engineer
  • Your team keeps user tickets, administrative rights and day-to-day decisions
  • Shared ticket portal, monitoring console and documentation your team can work in

Everything, side by side

Grouped the way we scope it. Rows link to the service page where one exists.

Included Add-on Not included
What's included Foundation Guardian $175 / user / mo Sentinel Co-Managed Guardian $110 / user / mo
Core IT
Ticket portal and reporting Every request is logged and tracked in one portal, with reports on what was fixed and how quickly. Included Included Included
IT asset and lifecycle management Each device is tracked from purchase to retirement, so you know what you own and when it needs replacing. Included Included Included
Workstation management Updates, health monitoring and tuning for every end-user computer. Included Included Included
macOS management Macs get the same updates, security settings and support as Windows machines. Not included Included Included
Linux system management Administration, monitoring and security updates for Linux servers. Not included Included Included
Server management Maintenance, updates and performance monitoring for physical and virtual servers. Included Included Included
Backup management TSR runs and monitors the approved backup solution and chases every failed job. Included Included Included
Network management Switches, firewalls and Wi-Fi monitored around the clock, with issues worked as they appear. Included Included Included
Workstation backup and cloud recovery Automatic backup of end-user computers to the cloud, so a lost laptop does not mean lost work. Not included Included Add-on
Backup and disaster recovery as a service An on-site appliance with offsite replication, so servers can be brought back in hours rather than days. Add-on Included Add-on
Support & Monitoring
Help desk and onsite support (business hours) Unlimited remote and onsite support for your people during business hours. Under Co-Managed Guardian your own team owns user tickets; TSR covers security, servers and the network. Included Included Not included
24×7 monitoring Critical systems watched around the clock, every day of the year. Included Included Included
Windows and Windows Server patching Microsoft security updates tested and applied on a defined patch policy. Included Included Included
Microsoft 365 and Google Workspace administration User accounts, licences and security settings managed for you. Included Included Included
24×7 on-call engineer An engineer to call for emergencies outside business hours. Not included Included Included
Third-party patching and configuration enforcement Software on the approved list is updated automatically and settings are held to your IT policy by job role. Not included Included Included
Proactive remediation and zero-touch deployment Configuration drift is fixed automatically and new software or machines are set up with little user involvement. Not included Included Included
Microsoft 365 advanced monitoring Security monitoring, configuration management and reporting for your Microsoft 365 tenant. Not included Included Included
Security
Endpoint protection Next-generation malware protection on every workstation and server, managed by TSR. Included Included Included
Microsoft 365 and Google Workspace backup Mail, files and Teams or Drive data backed up with one-year retention and point-in-time restore. Add-on Included Included
Security awareness training Short on-demand training, simulated phishing and a report showing who clicked. Included Included Included
Email security Phishing, impersonation and malicious attachments filtered before they reach the inbox. Not included Included Included
Multi-factor authentication MFA and Conditional Access enforced in Entra ID for sign-in, VPN and supported applications. Not included Included Included
Managed detection and response A staffed security operations centre hunts for and responds to threats 24×7, watching what processes do rather than only what files contain. Not included Included Included
Dark web monitoring Alerts when your company's credentials show up in a breach dump. Not included Included Included
Continuous vulnerability scanning Internal and external scans that find unpatched weaknesses before an attacker does. Not included Included Included
Disk encryption and Intune management BitLocker enforced and devices managed through Intune, so a stolen laptop gives up nothing. Not included Included Included
DNS and content filtering Malicious and inappropriate sites blocked at the DNS layer, on and off the office network. Not included Included Included
Zero trust application control Only approved applications run; everything else is blocked by default. Not included Included Add-on
Privileged access management Users work without local admin rights; elevation is granted per application and per request. Add-on Included Add-on
Password vault with breach reporting A company password manager with dark web monitoring and automatic breach alerts. Add-on Included Add-on
SASE (secure access service edge) Secure, identity-aware access to cloud and office resources from anywhere, replacing the traditional VPN. Not included Included Add-on
Custom mobile device management policies Phones and tablets held to your security policy, with app control and remote wipe. Not included Included Add-on
Strategic Leadership
Quarterly business review A quarterly meeting to line IT up with where the business is going. Included Included Included
Annual 123-point IT assessment A yearly audit of your environment against 123 checks, with findings ranked and tracked. Included Included Included
Virtual CIO A named senior engineer who owns your technology roadmap and budget planning. Add-on Included Included
Vendor management TSR deals with your internet, phone, software and hardware vendors so you do not have to. Add-on Included Included
Compliance
SIEM and log management Security and system logs shipped off the machine that generated them, retained centrally and reviewed by analysts. Add-on Included Included
Virtual CISO Security leadership that owns your policies and risk register and speaks to auditors and insurers. Add-on Included Add-on
Incident response platform A written incident response plan, a hosted platform to run it from, and tabletop exercises to practise it. Add-on Included Add-on
Compliance assessment and management platform Controls mapped to your framework, evidence collected continuously and gaps reported. Add-on Included Add-on
Disaster recovery testing Twice a year TSR restores from backup and documents how long it took and what was learned. Add-on Included Add-on
Microsoft 365 data loss prevention Policies that stop sensitive data leaving your tenant by email, Teams or shared links. Not included Included Add-on
Every package: one per-user rate, one invoice line. Quote Foundation Quote Sentinel Quote Co-Managed Guardian

After you sign

The same four workstreams for every package, four to six weeks end to end.

  1. 1.Week 1

    Discovery and scoping

    We learn how your business runs before we touch anything. Engineers document the network, inventory every device and account, review the current backup and security posture, and note any compliance obligations. The device and user counts we agree here are the counts you are billed on.

  2. 2.Weeks 2–3

    Endpoint security cutover

    Defender for Business is onboarded through Intune to the TSR baseline and the detection agent is deployed to every device. Legacy antivirus is removed only after Defender is confirmed active on that machine, and alert routing into TSR is proven with a test detection before we rely on it.

  3. 3.Weeks 3–4

    SIEM and DNS filtering enablement

    We agree which devices and network segments are monitored, then onboard the log sources and verify that logs are leaving each machine. DNS filtering rolls out with an initial category and threat policy that follows laptops off the office network.

  4. 4.Weeks 4–5

    Identity consolidation

    We check the Entra ID baseline for MFA coverage, Conditional Access and self-service password reset, close the gaps, and retire any standalone MFA product once its seats are reconciled to headcount. Inactive licensed accounts are dealt with so you stop paying for people who have left.

Package questions

Can we start on Foundation and move up later?

Yes. Moving between packages is a contract change, not a re-onboarding; the tools stay the same and the extra services are switched on.

What does 'add-on' mean in the matrix?

Available with that package at an additional, quoted cost. 'Included' means it is inside the per-user rate with no separate invoice line.

Do you charge per device or per user?

Per user. A user's workstation and normal devices are covered; servers and network equipment are counted separately during scoping.

Is there a minimum size?

Packages are designed for roughly 20 to 250 users. Smaller and larger businesses are welcome; scoping tells us whether a package or a custom scope fits.

Two questions and we can tell you which column

How many people, and do you have anyone in-house doing IT today. That is usually enough to recommend a package and quote it.