TSR Solutions Managed IT & security

Foundation

Monitored, patched and backed-up workstations and servers, with a help desk your people can call during business hours.

Who it is for

Businesses that need dependable day-to-day IT support and patching and are not yet ready for round-the-clock detection and response.

Foundation keeps the basics running. Every workstation and server is monitored around the clock, Windows is patched on a schedule, your backup is checked, and your people have a help desk to call during business hours. It includes endpoint protection and security awareness training, but not managed detection and response, log retention or the after-hours on-call engineer. It suits a business that wants a dependable IT partner today and a clear path to Guardian when its risk changes.

Inside the rate

  • 24×7 monitoring of workstations, servers and the network
  • Unlimited help desk and onsite support during business hours
  • Windows and Windows Server patched on a defined policy
  • Managed backup for servers, with jobs checked and failures chased
  • Microsoft 365 or Google Workspace user and licence administration
  • Endpoint protection and security awareness training for every user
  • Quarterly business review and an annual 123-point IT assessment
  • Ticket portal with reporting on what was fixed and how fast

What it does not do

  • After-hours support. The 24×7 on-call engineer is a Guardian and Sentinel inclusion; Foundation alerts are worked the next business day.
  • Managed detection and response, SIEM and DNS filtering. Endpoint protection alerts go to the help desk queue, not a staffed security operations centre.
  • macOS and Linux management. Foundation covers Windows workstations and servers.
  • Third-party application patching. Foundation patches Windows and Microsoft server products; other software is patched under Guardian.
  • Project work such as migrations, office moves and new servers, which are scoped and quoted separately.

Services with this package

Included in the rate

Available as add-ons

Pentest

A scoped, human-led attack on your network, web applications and APIs so you find the gaps before someone else does.

Learn more

Web app pentest

An OWASP-based, manual test of your web application or API, with a report your developers can act on within days.

Learn more

vCISO

Security leadership on a monthly retainer for businesses that need a CISO's judgement without a CISO's salary.

Learn more

Compliance assessment

A gap analysis of your policies and controls against HIPAA, PCI DSS, SOC 2, ISO 27001, GDPR or CMMC, with a plan to close what is missing.

Learn more
Assessment

Cyber posture assessment

A one-time review of your technical and operational security that tells you what to fix first and why.

Learn more

Private cloud

Dedicated virtual servers on hardware nobody else shares, sized to your workloads and managed by TSR.

Learn more

Public cloud

Move workloads to the public cloud, or run a mix of cloud and on-premises, with TSR planning the move and managing what follows.

Learn more

Colocation

Rack your own servers in a Tier III data center with redundant power, cooling and carriers, instead of a closet at the office.

Learn more

VoIP

A cloud phone system with auto-attendant, call routing, voicemail-to-email and video meetings, sized to your users and locations.

Learn more

vCIO

A TSR executive who owns your technology roadmap, budget and vendor relationships, for businesses that need a CIO's judgement but not a full-time CIO.

Learn more

AI solutions

Practical AI and automation for your business, from a readiness assessment through a pilot to a system your team actually uses.

Learn more

What happens after you sign

Billing starts when the last workstream closes, not when the contract is signed.

  1. 1.Week 1

    Discovery and scoping

    We learn how your business runs before we touch anything. Engineers document the network, inventory every device and account, review the current backup and security posture, and note any compliance obligations. The device and user counts we agree here are the counts you are billed on.

  2. 2.Weeks 2–3

    Endpoint security cutover

    Defender for Business is onboarded through Intune to the TSR baseline and the detection agent is deployed to every device. Legacy antivirus is removed only after Defender is confirmed active on that machine, and alert routing into TSR is proven with a test detection before we rely on it.

  3. 3.Weeks 3–4

    SIEM and DNS filtering enablement

    We agree which devices and network segments are monitored, then onboard the log sources and verify that logs are leaving each machine. DNS filtering rolls out with an initial category and threat policy that follows laptops off the office network.

  4. 4.Weeks 4–5

    Identity consolidation

    We check the Entra ID baseline for MFA coverage, Conditional Access and self-service password reset, close the gaps, and retire any standalone MFA product once its seats are reconciled to headcount. Inactive licensed accounts are dealt with so you stop paying for people who have left.

Built on

  • MicrosoftMicrosoft 365, Entra ID, Intune and Defender for Business
  • Blackpoint Cyber24×7 managed detection and response
  • NinjaOneEndpoint monitoring, patching and remote support
  • AutoElevatePrivilege management
  • HuduDocumentation and credential vaulting
  • Phin SecuritySecurity awareness training and phishing simulation

Foundation questions

Who does Foundation suit?

A business whose main need is that computers work, updates land and someone answers the phone. If you handle regulated data or have a cyber-insurance questionnaire asking about 24×7 detection, start at Guardian.

What happens if something breaks at night?

Monitoring still runs and the alert is logged. An engineer picks it up at the start of the next business day. If you need an engineer on call around the clock, that is included in Guardian.

Can we move to Guardian later?

Yes. The monitoring, patching and help desk carry over unchanged. Onboarding to Guardian adds detection and response, log retention, DNS filtering and identity hardening on top of what is already in place.

Does Foundation include antivirus?

Yes. Endpoint protection is included and managed by TSR. What Foundation does not include is a 24×7 security operations centre watching what that protection reports.

Request a Foundation quote

User count, locations and whether you have IT staff today is enough for a first number. An engineer replies within one business day.

Prefer to talk? Call 262-292-2000.