Growth
Built for organizations adding people, locations, or obligations
What Growth is for
Growth is our most common tier, and the reason is usually the same: the business has reached a size where somebody outside it — a client, an insurer, a regulator, a board — has started asking what your security posture actually is. Answering that requires controls that are configured, evidenced, and reviewed on a cadence.
Operationally this is where identity becomes the centre of gravity. Conditional Access, device compliance, and email security are configured to a defined baseline rather than assembled ad hoc. Patch compliance is reported rather than assumed. Backup testing produces evidence an insurer will accept.
The other shift is cadence. Quarterly business reviews put roadmap checkpoints and budget alignment in front of leadership, so IT investment gets decided rather than absorbed. If you want that strategic layer to go deeper — multi-year planning, board narratives, vendor and licence strategy — Strategic layers on top.
What changes for you
You can answer the security question
When a client questionnaire or insurer renewal lands, the evidence exists already. Retrieval, not a scramble.
IT investment gets decided, not absorbed
Quarterly reviews put the roadmap and the budget in the same conversation, so spending is sequenced against business priorities.
Growth stops breaking things
Adding a location or thirty people becomes a planned change rather than an incident, because standards exist to apply.
What's included
Grouped by what it does for the business, rather than by the tools behind it.
Support and response
- Named escalation paths with documented response expectations for priority and standard queues
- 24/7 monitoring with defined after-hours handoff to on-call engineering
- Onsite included for critical escalations and quarterly planning within the service area
Identity and access
- Conditional Access policies configured to a defined baseline
- Device compliance enforcement so unmanaged devices cannot quietly reach company data
- Privileged account separation and periodic access review
- Email security controls tuned against the impersonation attempts your sector actually receives
Vulnerability and patch management
- Patch compliance reporting — coverage percentages, not assurances
- Vulnerability-driven prioritisation for critical systems
- Remediation backlog ranked by business impact rather than CVSS alone
Resilience
- Backup testing aligned to leadership cadence
- Restore evidence useful for insurers and audit preparation
- Documented recovery expectations per system, agreed with the business
Microsoft 365 governance
- Sharing governance and external collaboration handled deliberately
- Guest lifecycle management so external access expires
- Tenant configuration standards applied and monitored for drift
Leadership cadence
- Quarterly business reviews with roadmap checkpoints and budget alignment
- Posture reporting leadership can read without translation
Deliverables flex with how fast you are growing—not a fixed menu you outgrow in a year.
What Growth does not include
Worth knowing before a call rather than after one.
- Not a compliance attestation. We deliver and document controls; your auditors and counsel own certification.
- Multi-year roadmaps, board narratives and vendor strategy sit in Strategic, layered on top.
- Enhanced SLAs with executive escalation and CAB-style change discipline start at Business.
- Major projects — migrations, office moves, cabling — are scoped as separate SOWs.
Questions about Growth
- Because it is where external scrutiny starts. Somewhere between twenty-five and seventy-five people, most businesses acquire a client, insurer or regulator who wants evidence rather than assurances. Growth is the first tier that produces that evidence as a by-product of normal operations.
- No, and be wary of anyone who says otherwise. Frameworks are certified by auditors, not by your MSP. What Growth does is implement and document the operational controls those frameworks assess, so your compliance lead is assembling evidence rather than creating it.
- Monitoring runs continuously and out-of-hours alerts hand off to on-call engineering under a defined path. It is not a fully staffed overnight service desk — if you need one, say so during discovery and we will scope it honestly rather than imply we already have it.
- Yes. Strategic is a retainer that layers onto any managed tier. Growth plus Strategic is a common combination for a leadership team that wants roadmap depth without mid-market SLAs.
- Handled badly, very. We stage it — report-only mode first to see what would break, then a pilot group, then phased enforcement with a documented break-glass path. Nobody should discover a new access policy by being locked out on a Monday.
Why is Growth the tier most Houston SMBs land on?
Does Growth make us compliant with anything?
What does 24/7 actually mean here?
Can we add vCIO strategy without moving to Business?
How disruptive is enforcing Conditional Access?
Not quite right?
Compare all packages →Is Growth the right fit?
Twenty minutes with an ECS engineer, and an honest answer either way. If a different tier suits you better, we will say so.