Managed IT · Security · Continuity
One flat price. Every device watched, patched, backed up and answered for.
Three plans from $125 a user. Critical issues reach a person in 15 minutes, in writing. Month to month, and the proof arrives on the 10th.
From $125 / user / month · $750 minimum · Month to month

15 min
Critical response, written into the agreement
Same day
Monitoring live from the day you say yes
Unlimited
Remote support for everyone on the plan
By the 10th
Your monthly report, every month
Plans
Three plans. The differences are real.
Most businesses belong in Secured. Essential is for the smaller environment that still needs watching properly. Complete is for when hours of downtime cost more than the difference.
Essential
From $125/user/month
For the smaller environment that still needs watching properly.
- Monitoring and alerting, around the clock
- Operating system and third-party patching
- Unlimited remote support
- Endpoint protection on every device
- Backup monitored, restore-tested quarterly
Secured
From $175/user/month
Where most businesses belong: the security and recovery work done properly.
- Everything in Essential, plus
- Detection and response, alerts triaged
- Multi-factor with conditional access
- Vulnerability scanning, monthly
- Restore tests monthly, and a written recovery plan
- Quarterly technology review
Complete
From $235/user/month
When hours of downtime cost more than the difference.
- Everything in Secured, plus
- 4-hour recovery objectives by default
- Executed failover test, once a year
- Vendor management and renewals
- Operational architecture review
| Item | Essential | Secured | Complete |
|---|---|---|---|
| Infrastructure | |||
| Continuous monitoring and alerting | Included | Included | Included |
| Patch management, operating system and third-party | Included | Included | Included |
| Remote support, unlimited | Included | Included | Included |
| On-site support | Partial | Included | Included |
| Network management | Included | Included | Included |
| Server, cloud and Microsoft 365 administration | Included | Included | Included |
| Security | |||
| Endpoint detection and response | Partial | Included | Included |
| Email security and phishing filtering | Partial | Included | Included |
| Identity, access and multi-factor management | Not in this plan | Included | Included |
| Vulnerability scanning and remediation | Not in this plan | Included | Included |
| Continuity | |||
| Backup, monitored and restore-tested | Partial | Included | Included |
| Disaster recovery plan | Not in this plan | Included | Included |
| Continuity testing, scheduled | Not in this plan | Partial | Included |
| Operations | |||
| Documentation and asset register | Partial | Included | Included |
| Vendor management | Not in this plan | Partial | Included |
| Quarterly technology review | Not in this plan | Included | Included |
| Operational architecture review | Not in this plan | Not in this plan | The bridge into operations work |
What “Partial” means.
So the table can’t be read two ways, every Partial has a written meaning.
| Item | Partial means |
|---|---|
| On-site support (Essential) | Scheduled within three business days rather than prioritized. Travel is billed. |
| Endpoint detection and response (Essential) | Deployed and alerting. Alert triage is best effort in business hours, not continuous. |
| Email security and phishing filtering (Essential) | Standard filtering is on. There is no tuning cycle and no quarantine review. |
| Backup, monitored and restore-tested (Essential) | Monitored daily. A restore is tested quarterly rather than monthly. |
| Documentation and asset register (Essential) | The asset register is maintained. Runbooks are not. |
| Continuity testing (Secured) | A tabletop exercise once a year, rather than an executed failover. |
| Vendor management (Secured) | We contact a vendor when you raise a ticket. We don’t manage the relationship or the renewals. |
What’s included
Four layers, run as one system.
Every layer is designed, installed and run by the same engineers, so a problem never falls into the gap between two vendors. Which plan includes what is in the table above.
- 01InfrastructureNetwork, devices, servers, Microsoft 365
- 02SecurityIdentity, email, endpoint, patching
- 03ContinuityBackup, restore tests, recovery plan
- 04RunHelp desk, monitoring, monthly report
Infrastructure
- Monitoring and alerting, around the clock
- Operating system and third-party patching
- Unlimited remote support, on-site when needed
- Network, server, cloud and Microsoft 365 administration
Security
- Endpoint detection and response
- Email security and phishing filtering
- Identity, access and multi-factor management
- Vulnerability scanning and remediation
Continuity
- Backup, monitored and restore-tested
- A written disaster recovery plan
- Continuity tested on a schedule
- Recovery objectives written into the agreement
Operations
- Documentation to the 3am test
- An asset register that matches the office
- Vendor management and renewals
- Quarterly technology review
Help desk
A person answers. The ticket says what happened.
Unlimited remote support for everyone on the plan. Every request gets a number, a severity and a clock you can see, and it ends with a note that says what was done.
- 01
Ticket raised
By phone, the portal or email. You get the ticket number and the severity straight away.
- 02
A person picks it up
Inside the clock for its severity. The clock stops when someone who can act is working it, not when an automated reply goes out.
- 03
Updates you don’t have to chase
Critical issues every 30 minutes, high every two hours, whether or not there’s progress.
- 04
Fixed, and written down
What broke, what was done and what would stop it happening again, in your ticket history.
The desk covers people, devices, Microsoft 365, printers and line-of-business applications, working with the software vendor where the fix is theirs.

Not a client, and something’s broken?
A managed plan isn’t a condition of getting help. A server that won’t start, email that stopped, three new laptops with nobody to set them up: that’s hourly work, often same-day. You get it fixed first and the conversation second.
Response
Severity is set by what has stopped.
If the business has stopped, it’s critical however it was reported. Anyone can raise a severity at any time. Lowering one needs your recorded agreement.
| Critical (The business has stopped) | 15 min |
|---|---|
| High (A team is blocked) | 1 hour |
| Normal (One person is stopped) | 4 hours |
| Scheduled (Planned work, questions) | Next business day |
Next business day is drawn at the end of the scale.
Written into the managed IT agreement. High, Normal and Scheduled clocks run in business hours. The clock stops when a person who can act is working the issue, not when an automated reply goes out.
| Severity | What it means | First human response |
|---|---|---|
| Critical | The business has stopped | 15 minutes |
| High | A team is blocked | 1 hour |
| Normal | One person is stopped or slowed | 4 hours |
| Scheduled | Planned work and questions | Next business day |
Response times apply to managed clients under their agreement. The clock starts when you tell us by the portal, the support email or the published phone number. The High, Normal and Scheduled clocks run in business hours.
While you’re asleep
The night shift you never have to staff.
Monitoring doesn’t sleep. Patches land in the window you agreed, backups run and get checked, and a failing disk gets flagged before it fails. By morning, every step is in your ticket history.
Illustrative night The kind of work, not a client’s data.
How backup and restore testing work
- Patches stagedfor the window you agreed
- Backups runand checked for errors
- Disk alertflagged before it fails
- Off-site copysent and verified
- Phishing messagequarantined
- Overnight login your ticket history
Security baseline
The same baseline on every environment we manage.
The CIS Controls, Implementation Group 1, are the floor. Secured and Complete go further, and the difference is written down.
| Control | Essential | Secured and Complete |
|---|---|---|
| Multi-factor authentication | Required on all accounts | Required on all accounts, conditional access enforced |
| Endpoint protection | Deployed on every device | Deployed on every device, alerts triaged |
| Local administrator rights | Removed where you permit | Removed, exceptions documented |
| Patching | To the patch standard | To the patch standard |
| Email security | Standard filtering | Advanced filtering, tuned, quarantine reviewed |
| Identity | Documented | Conditional access and risky sign-in review |
| Vulnerability scanning | Not included | Monthly, critical findings fixed within 72 hours |
| Offboarding a departing user | Within one business day | Within four business hours |
| Access review | Once a year | Every quarter |
A client who refuses multi-factor authentication on email is refused the engagement. We can’t be accountable for a system we’re not allowed to protect. Any other exception is recorded in writing, with an owner and a review date.
Backup
Restored and opened, not just checked.
A restore test means data was actually brought back and opened. A green tick in a console is monitoring, not testing.

| Item | Essential | Secured | Complete |
|---|---|---|---|
| Backup monitored | Daily | Daily | Daily |
| Failed job investigated | Next business day | Same business day | Same business day |
| Restore test | Quarterly | Monthly | Monthly |
| Restore test evidence | File, time, who did it | File, time, who did it | File, time, who did it |
| Recovery point objective, default | 24 hours | 24 hours | 4 hours |
| Recovery time objective, default | Best effort | 8 business hours | 4 business hours |
| Disaster recovery plan | Not included | Written, reviewed yearly | Written, reviewed yearly |
| Continuity test | Not included | Tabletop, yearly | Executed failover, yearly |
Recovery objectives are defaults. Yours are set at onboarding and written into your agreement. How backup is run.
Patching
Updates that land, and proof that they did.
Patch compliance is reported to you every month. A device that can’t be patched becomes an exception with an owner, a compensating control and a review date, never a silence.
Firmware and network device updates run quarterly as planned changes. Servers and line-of-business systems are patched in a window you agree, with a restore point taken first.
| Critical (Security patches) | 72 hours |
|---|---|
| High (Security patches) | 7 days |
| Standard (All other updates) | 30 days |
OpsWorq patch standard. Servers and line-of-business systems are patched in a window you agree in writing, with a restore point taken first. A device that can’t be patched becomes a written exception with an owner and a date.
How we communicate
Silence during an incident is what clients remember.
“No progress yet, still working it, next update at 14:30” is a complete and acceptable update. This is what you get, and when.
| Situation | What you get | When |
|---|---|---|
| New inquiry | A reply from a person | Within one business day |
| Ticket raised | The ticket number and severity | Straight away |
| Critical incident | A named person, saying they’re working it | Within 15 minutes |
| Critical incident, ongoing | An update, progress or not | Every 30 minutes |
| High severity, ongoing | An update | Every 2 hours |
| A change that affects you | The window and the back-out plan | Before it starts |
| A missed response commitment | We tell you, before you ask | The same business day |
| Monthly | Your report | By the 10th |
| Quarterly | Your technology review | Within the quarter |
Onboarding
The clock starts the day you say yes.
Monitoring goes live the day you say yes. Your plan is switched on week by week. By day 30, everything is written down, and you get the evidence at every step.
Day 0
Monitoring is live, and proven
A test alert is raised, received and closed, with the timestamp kept in the ticket.
Week by week
Your plan switched on, in order
Each control checked against your plan’s list. A device we can’t reach becomes a finding with an owner and a date.
Day 30
Documented, and handed to you
Assets, accounts, network and runbooks, written to one test: could a stranger restore service at 3am? The baseline report is issued.
A missed day-0 milestone is reported to you the same day, with a new date.
How onboarding and switching workYour price
See what it would cost.
The published floors, turned into your number. It’s a floor, not a quote: yours comes from a 20-minute review of what you run, and it holds after you sign.
Your inputs. An estimate, not a quote. Your number comes from a 20-minute review of what you actually run, and it holds after you sign.
Want it in writing?
We email you exactly what’s on screen. Nothing is held back for the email version.
- Never billed extra. Remote support, monitoring, patching, and everything in your plan.
- Month to month. Thirty days’ notice ends it. About 10% less with a twelve-month commitment.
- Hardware and licenses passed through at a margin stated on the quote.
- Every quote states the plan, the users covered, the monthly fee, what’s billed separately, the term, the notice period and the start date. It’s valid for 30 days.
We don’t take on work we can’t see paying for itself. If we can’t, we’ll tell you.
In your IT lead’s languageThe technical specification, for an IT person, auditor or insurer.
- Remote monitoring and management on every managed device, with alerts routed by severity, not category.
- Patch management for the operating system and third-party software, with maintenance windows agreed in writing and restore points taken first.
- Endpoint detection and response on every device; alert triage continuous (Secured, Complete) or best effort in business hours (Essential).
- Email security policy, identity and access management, conditional access and risky sign-in review.
- Backup and disaster recovery, with restore tests evidenced by ticket and recovery objectives set per client.
- Vulnerability management, scanned monthly (Secured, Complete), with critical findings remediated within 72 hours.
- Documentation to a written standard, and an asset register that matches the office: an unknown device is either an asset nobody is protecting or an intruder.
- The CIS Controls, Implementation Group 1, as the baseline. Exceptions carry an owner, a compensating control and a review date.
- Certifications held by our engineers and technicians: Microsoft MCSE; CompTIA Security+, Network+, A+ and Project+; fiber optic installation and termination; QuickBooks.
Questions
Straight answers about managed IT.
Is there a contract?
What isn’t included?
What happens after hours?
How do we switch from our current provider?
Who owns our data and passwords?
Do you require multi-factor authentication?
How soon can you start?
Is there a minimum company size?
Get started
Talk to an engineer, not a salesperson.
1‑855‑OPSWORQ855‑677‑9677 · Mon–Fri, 8am–5pm ET
If the business has stopped, call. Don’t use the form.
Pick a time for a 20-minute review of what you run, or write to us and a person replies within one business day. Then a written quote with a start date on it.