Who this is for
When the technology works, nobody thinks about it. When it stops, the office manager loses a morning to it, a job goes out late and the same fault returns soon after. Our managed IT support for small business is a monthly plan that gives your staff someone to ask and gives your systems routine care.
It suits businesses like these:
- A professional services office where the computers are looked after by whoever is least busy.
- A trades business with laptops and phones out on the road, each set up differently by its user.
- A training provider that adds and removes staff and contractors each term and loses track of who still has access.
- A recruitment agency that discovers, on the day it needs them, that its backups stopped some time ago.
What we promise is deliberately modest: we reply within one business day. We do not publish response-time or uptime commitments beyond that, and this is not an emergency service that operates around the clock. If you need that level of cover, tell us on the first call.
The problems it solves
- Faults that are patched up for the day and return because nobody looked for the cause
- Updates that wait until a computer forces them in the middle of a busy morning
- Backups that nobody has checked since they were set up
- New starters who begin without the accounts and access they need
- People who left long ago and still have a working login
- A senior staff member acting as the unofficial help desk
What the monthly plan includes
The exact list is written into your plan. These are the usual parts.
- Help desk: one email address and phone number for staff questions and faults, with every request logged and answered
- Updates and patching for operating systems, applications, web browsers and network devices, on an agreed schedule
- Backups set up, checked and restored as a test, with a record kept of each test
- Monitoring of device health, storage, backups and security alerts
- Onboarding: accounts, licences, a prepared device and the right access for each new starter
- Offboarding: access removed, mailbox and files handed over, licences recovered and devices wiped when someone leaves
- Microsoft 365 or Google Workspace administration: users, groups, shared mailboxes and drives, licences and security settings
- Multi-factor authentication, a password manager and device encryption kept in place
- Printers, wifi and the office network kept working, and the internet provider chased when the fault is theirs
- A current register of devices, software, licences and renewal dates
- A regular plain-English summary of work done and decisions needed
What you hold
These are kept current and are yours at all times.
- A service description: what is covered, what is not and how to ask for help
- Documentation of your environment: a network diagram and a register of devices, software, licences and renewals
- Administrator credentials in a password vault that you own
- The backup schedule and the record of restore tests
- Onboarding and offboarding checklists written for your roles
- A log of every support request and how it was resolved
- A regular summary of requests, changes and recommendations
- A handover pack containing all of the above, so another provider or an in-house hire can take over
Technology we look after and why
Microsoft 365
Microsoft's suite for email, files, meetings and Office applications. We manage users, licences, shared mailboxes and security settings, and switch on the protections your plan already includes before suggesting anything extra.
Google Workspace
Google's suite for email, shared drives, calendars and meetings, administered in the same way.
MFA and SSO
A second proof at sign-in, and one work account for your other systems, so access is added and removed in one place.
Encryption and device management
Laptops and phones are encrypted and enrolled, so a lost device can be locked or wiped. Settings are applied centrally, which replaces setting up each machine by hand.
Cloud backups
Backup copies held on Google Cloud, AWS or Azure, away from the office and away from everyday user accounts.
Monitoring and alerts
Automatic checks on device health, storage space, failed backups and unusual sign-ins. Alerts are reviewed as part of the plan, not watched around the clock.
How we set up and run your support
| Stage | What happens |
|---|---|
| 1. Discovery call | A free conversation about how many people you have, the devices and software they use, which office suite you run and what goes wrong most often. |
| 2. Plan and quote | After a short look at your current set-up, you receive a written plan listing exactly what the monthly plan covers and what it does not, plus a fixed quote for any clean-up needed first. |
| 3. Build and test | We take on your environment in stages: documenting it, bringing devices and accounts under management, then setting up backups and monitoring. Each stage is shown to you, including a backup restored as a test. |
| 4. Launch and train | Staff are told how to ask for help and attend a short session on signing in securely and what to report. Administrator credentials are recorded in a password vault that you control. |
| 5. Ongoing support | The monthly routine begins: requests answered, updates applied, backups checked, joiners and leavers processed, and a summary sent to you. |
Engagement options
| Option | Suits | How it works |
|---|---|---|
| Monthly plan | Day-to-day support and routine care of your systems | A written list of covered services for a monthly fee, sized to your people, devices and systems and adjusted as the business changes. |
| Fixed quote | A defined job, such as the initial clean-up, an office move or setting up a group of new starters | Scope and price are agreed in writing before we start, separately from the monthly plan. |
| Staged pricing | Larger changes, such as moving from an office server to the cloud | The project is split into stages, each quoted and approved on its own. |
Security and how we handle our own access
A support provider holds the keys to your systems, so how we handle them is part of the service.
- Dedicated administrator accounts. At Maturity Level One, ASD's Essential Eight maturity model has privileged users assigned a dedicated privileged user account to be used solely for duties requiring privileged access. Ours are set up that way, with multi-factor authentication, and are never shared.
- Least privilege. We hold the rights the plan requires and no more, and your staff work with standard accounts.
- Where your data is. Email and files stay in your own Microsoft 365 or Google Workspace account. Backups are encrypted and kept in the cloud region you choose.
- Personal information. We open a mailbox or shared drive only to resolve a request you have raised. Where the Privacy Act applies, the duty to protect personal information remains yours, as the OAIC's summary of APP 11 describes.
- Leaving. When a plan ends, our accounts are deleted and the vault credentials are changed.
How support works day to day
Staff send a request by email or phone and it is logged; we reply within one business day. Where we can, we fix the fault over a remote connection, with the person's permission.
Behind the requests, the routine runs to a calendar: updates, backup checks, alert reviews and the register kept current. When a request turns out to be a project, we quote it before doing anything. New enquiries reach us at hello@comingwave.com.au or through the contact page.
Industries it suits
Professional services
Offices where time is billed to clients and nobody senior should be resetting passwords.
Trades and construction
Laptops, tablets and phones spread across utes and sites, kept updated and able to be wiped if lost.
Education and training
Trainer and contractor accounts opened and closed each term, with student records limited to the people who need them.
Recruitment
Consultants who work all day in email and a candidate database, where a locked account stops placements.
What the Essential Eight says about patching and backups
Three of the eight strategies in the Australian Signals Directorate's Essential Eight are everyday managed IT work: patch applications, patch operating systems and regular backups. ASD's Essential Eight maturity model sets out what each involves. At Maturity Level One, for example:
- patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist;
- those for office productivity suites, web browsers and their extensions, email clients, PDF software and security products are applied within two weeks of release;
- those for operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release, and operating systems that are no longer supported by vendors are replaced;
- backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements, and restoration is tested as part of disaster recovery exercises;
- unprivileged user accounts are prevented from modifying and deleting backups.
We use these as the reference when we agree your patching schedule and backup design. They are ASD's benchmarks for you to work towards, not service levels that we promise, and we do not describe a client as having reached a maturity level without an assessment.
ASD also publishes questions to ask managed service providers, noting that such providers often have privileged access to their customers' systems. We encourage you to put them to any provider you are considering, including us.
Managed IT support questions
How quickly will you respond to a support request?
We reply within one business day. That is the only response commitment we publish, and we make no uptime promise. If you need contracted response times, raise it on the first call so we can tell you honestly whether we are the right provider.
Do you support both Microsoft 365 and Google Workspace?
Yes. We administer whichever suite you already use and do not push a change without a reason. If a move from one to the other makes sense, it is handled as a separate, quoted cloud migration project.
What happens when a staff member leaves?
You tell us the date and we work through the offboarding checklist: sign-in blocked, mailbox forwarded, files transferred to their manager, licences recovered, devices wiped and shared passwords changed. Each step is recorded.
Can you work alongside our existing IT person or supplier?
Yes. We agree in writing who does what, so nothing is done twice or missed. Often we handle patching, backups and accounts while your own person handles hands-on tasks in the office.
Do you support Macs, phones and tablets as well as Windows computers?
Yes. Windows and Mac computers, iPhones, iPads and Android devices can all be enrolled, encrypted and kept updated. Tell us about specialist equipment, such as a plotter or a point-of-sale terminal, so the plan states whether it is covered.
What is not covered by the monthly plan?
Projects such as a new office, a migration or a new system are quoted separately. You buy your own hardware and licences, and we advise on what to buy. Faults inside another vendor's product go to that vendor, with our help. For a full review of your set-up, see IT consulting.
Will we be locked in to you?
Your accounts, licences and data stay in your business's name, and the documentation and administrator credentials sit in a vault you own. If you move on, the handover pack lets another provider take over. Security work beyond routine care is described on our cyber security page, and you can ask us for a plan at any time.


