Document summary
This document sets out what's included in our Managed IT Service package.
At a glance, this package covers:
Service Desk support, 08:30–17:00 weekdays, with SLA-backed response and resolution targets
Incident and problem management, including root-cause analysis for recurring issues
24×7 proactive monitoring, alerting and patch management for endpoints and servers
24×7 Managed Detection and Response (MDR), NCSC Early Warning, and active Secure Score management
Secure password management, monthly service reporting, and backup monitoring
A structured onboarding process covering service, security, and project management setup
Our Service Desk is available weekdays 08:30–17:00, delivered by ABL-employed staff at our head office, accessible by email or telephone. Extended coverage hours are available on request.
Tickets are raised in our incident management system and progressed through to resolution, with quality monitoring built in throughout.
Our service desk covers:
The core Microsoft suite of products for endpoints, servers and associated cloud products, plus any systems we supply
Mainstream applications such as anti-virus, Microsoft Office, and remote access tools
Hardware from our preferred vendor list, chosen to keep our team's expertise consistent and deep (list available on request)
Line-of-business applications aren't covered – these need an active support agreement with the software vendor.
Tickets are assigned a priority from 1–4. New tickets emailed in default to priority 3, then reviewed for adjustment.
| Priority level | Definition |
|---|---|
| P1 – Business Critical | Business-critical systems down, majority of users affected, no workaround |
| P2 – High | Systems severely degraded, blocking key day-to-day work |
| P3 – Normal | Non-critical issue, workaround available |
| P4 – Change Request | A requested addition or change – e.g. a new starter, software install, or configuration update |
P1 and P2 incidents must be phoned in – these can't be logged by email.
| Priority level | P1 | P2 | P3 | P4 |
|---|---|---|---|---|
| Target response time | 15 minutes | 1 hour | 2 hours | 8 hours |
| Target resolution | 4 hours | 8 hours | 2 working days | 3 working days |
Reported incidents are reviewed, investigated, escalated where needed, and resolved in a timely manner:
Reporting: customer reports via phone or email
Logging: logged with a unique reference for tracking
Categorisation: assessed for urgency/impact and assigned to an engineer
Investigation: resolved with the customer kept informed throughout
Closure: closed with customer confirmation; knowledge base article updated or created where appropriate
Every ticket has an assigned owner. Our service management team monitors KPIs at both the service and individual-ticket level, with automatic alerts as tickets approach their SLA.
This identifies and fixes the root causes of recurring or significant incidents, reducing future disruption through both reactive and proactive work.
Conducted periodically – typically at a quarterly meeting, or sooner if recurring tickets are identified:
Identification: via incident trends, monitoring, or proactive risk analysis
Logging: logged, referenced, and categorised by impact/urgency
Root cause analysis: structured investigation to find and fix the underlying cause
Resolution: permanent fix implemented, with an interim workaround provided if this takes time
Prevention: ongoing proactive review to reduce future unplanned downtime
Closure: closed once confirmed resolved and documented
We build an understanding of your third-party providers during onboarding, including introductions to key suppliers. This means smoother day-to-day support, and faster progress on issues that span multiple vendors.
Where an issue is multi-supplier – e.g. a performance, reliability or connectivity problem – our team can liaise with the third party on your behalf and manage the process collaboratively. This doesn't replace your existing vendor relationships (e.g. Sage or other line-of-business contracts), which should be maintained separately.
We use Datto RMM for monitoring and device management across all managed endpoints, including servers, with alerts on threshold breaches or status changes.
Standard checks on Windows servers:
Online/offline status, disk space, CPU and RAM usage
Status of critical services (per server type and any bespoke configuration)
Patch compliance and hardware status
Network devices (routers, switches, firewalls) are monitored via SNMP for up/down status, critical links, and hardware changes. Additional monitoring – CCTV, building management, other network-connected assets – can be added on request.
Devices are patched via Datto RMM under our standard policy, unless an alternative is agreed.
Patches are approved where they're a critical, security, definition, or rollup update, or address an actively exploited vulnerability.
Release cycle: deployed to a small "beta" group first; rolled out to remaining devices after 7 days, balancing update speed against the risk of a faulty Microsoft release.
Feature updates (bringing Windows 11 to its latest version) are scheduled and tested with the customer during periodic reviews, given some can affect core functionality.
Requires Microsoft 365 Business Premium or Microsoft Defender for Endpoint Plan 1 (available via our Microsoft partnership); otherwise the free built-in Windows Defender is used.
Devices are onboarded into Defender and given an additional monitoring agent via Datto RMM. Devices outside this platform needing extra configuration may incur a charge.
Devices are monitored 24×7; suspicious signals are reviewed, with our partner's SOC investigating further where needed.
Pre-approved response actions:
Host isolation for high-confidence threats, until resolved
Remediation of High/Critical incidents by the SOC
Remote reboots where required, including servers
Devices can be excluded from active remediation where necessary. All incidents are reported to our service desk for review or further action.
We deploy the NCSC's Early Warning service during onboarding, alerting our service desk to any signals of network compromise. This complements, rather than replaces, active cyber defence.
MyNCSC account creation, and registration of domains/IP addresses
Early Warning configuration and alert routing to our service desk
Ongoing review and investigation of alert data
Secure Score's recommendations, and your score, change over time. We monitor this and deploy tested baselines to improve it where viable – aiming to increase protection as far as sensibly possible, not to chase a perfect 100, which would require disproportionate cost and restriction for most organisations.
Monthly review of score data and new baselines
Vendor recommendations reviewed and applied where appropriate
Customer engagement before applying anything with a cost, risk, or change implication
Progress is tracked over time, with periodic reporting available.
Customers can use MyGlue (IT Glue/Kaseya) for secure, cloud-based password storage, with single sign-on configured via Microsoft Entra ID during onboarding.
An automated service report is provided by default (opt-out on request), covering:
Tickets raised and priorities
SLA performance
Ticket type
Customer satisfaction data
Patch compliance
Read the full Customer Service Report guide
Backup monitoring and remediation
Backup services we supply are monitored for failures, with jobs re-run promptly to minimise the risk of unprotected or outdated data.
The onboarding steps for the core components are listed below:
Service
Ticketing/knowledge-base setup and monthly reporting configuration
Site visits to build knowledge of infrastructure and services, including photographs for future troubleshooting
Standardised device build process, and starters/leavers process agreed with the customer
MyGlue configuration, and secure storage of updated admin passwords
Service Management
Introduction to your Service Delivery Manager and how our services work
Welcome pack, escalation processes, and third-party vendor introductions
NOC (proactive services)
Datto RMM tenant build, agent deployment to servers, and advanced monitoring configuration
Testing and refinement of proactive alerting across network infrastructure and other components
Patch management policy configuration and RMM deployment package creation
Network configuration backups stored in IT Glue; Office 365 and server backups deployed as required
Pilot deployment of Datto RMM with full review, then full rollout to endpoints
ScalePad integration for asset management and warranty reporting
Cyber Security
MDR tenant configuration, with pre-approved remediation actions and escalation processes defined
MDR agent deployment, registration confirmation, and detection/alerting testing
Project Management
Introductory call, Project Initiation Document, and risk log with proposed mitigations
Project plan build-out, and information-sharing handover with the incumbent supplier
Ongoing project management meetings and highlight reports at an agreed frequency
Continual quality/risk management and reporting, through to project closure