MSPs sell tiers. We sell one plan.
Bronze looks cheap until you discover MFA, EDR, monitoring, and training were never in the pack. That is the MSP playbook. Quote low. Upsell security later. Leave Secure Score rotting.
Our One Plan is the opposite. One commercial plan. Support included. Required security stack included. Security Uplift included. Microsoft 365 Business Premium is the floor. EDR, ITDR, SIEM, SAT, ESPM, and ISPM required for all clients. If you want a thin tier, another MSP will take you. We would rather stay excellent for the ones who mean it.
Under the hood sits the Stride IT Security Standard and the Continual Security Uplift Program: a named method with Baseline, Stabilise, Uplift, Mark, and Continual. The Standard is achievable, documented, and renewable. Not a government certificate. Not theatre.
WHAT IS IN. WHAT IS OUT.
In One Plan
- ✓ Day-to-day IT support during business hours, remote and on-site when needed
- ✓ Microsoft 365 Business Premium as the licence floor, finished not half-configured
- ✓ Required stack for every client: EDR, ITDR, SIEM, SAT, ESPM, and ISPM
- ✓ Continual Security Uplift against the Stride IT Security Standard
- ✓ Secure Score tracking, quarterly reviews, and a path to the Stride Uplift Mark
- ✓ Monitoring and response with humans on the alerts, not a dashboard left unread
Not in the monthly plan
- × Major projects: migrations, large rollouts, new sites, and scoped change work
- × Bronze or silver tiers that strip security out so it can be sold back later
- × Break-fix billing and ticket queues that reward chaos
- × Optional security add-ons for clients who will not run the required stack
Projects get a clear scope and a fixed quote. That keeps the monthly plan about running and uplifting your estate, not absorbing every build under a fake “unlimited” promise.
Client filter
We only take clients who will run Our One Plan.
If this list makes you uncomfortable, good. Another MSP will take your money. We would rather stay excellent for the ones who mean it.
You will fit if
- You will run Microsoft 365 Business Premium (or higher) as the floor, not a wishlist.
- You will run EDR, ITDR, SIEM, SAT, ESPM, and ISPM as required stack, not optional extras.
- You will support Continual Security Uplift inside Our One Plan: controls finish, Secure Score moves, QBRs happen.
- You want outcomes priced in, not a surprise invoice every time something breaks.
- You will refresh devices or infrastructure when the Standard says they cannot keep up.
- You want one plan with a named method and a mark you can show, not bronze–silver–gold theatre.
We will decline if
- You want the cheapest MSP who just keeps the lights on.
- You refuse Business Premium and will not upgrade as part of uplift.
- You refuse EDR, ITDR, SIEM, SAT, ESPM, or ISPM for your environment.
- You want break-fix billing, ticket queues, and security left alone.
- You want fear theatre and a checkbox PDF, not a rising Secure Score.
- You want us to babysit consumer routers, ancient PCs, and hope.
- You shop MSPs like commodities and treat security as optional décor.
We turn work away. That is not a marketing line. It is how we keep the Standard real for the clients who stay. Our One Plan is an application, not a shopping cart. We may say no.
Required security stack
Included in One Plan for every client. Not optional extras on a higher tier.
EDR
Endpoint Detection and Response
Managed endpoint detection with 24/7 human response, not antivirus left on its own.
ITDR
Identity Threat Detection and Response
Catch compromised accounts, impossible travel, and privilege abuse before they own your tenant.
SIEM
Security Information and Event Management
Correlated logs and managed detection so signals become action, not a dashboard nobody opens.
SAT
Security Awareness Training
Phishing simulations and short drills for every user. Required habit building, not fear posters.
ESPM
External Security Posture Management
See what attackers see: domains, email authentication, and internet-facing exposure.
ISPM
Identity Security Posture Management
Find MFA gaps, over-privileged accounts, and risky identity configs before attackers do.
Stride IT Security Standard
The controls One Plan is measured against. Microsoft 365 Business Premium is the floor. Humans on the alerts.
01
Microsoft Secure Score: up, not decorative
We baseline your Secure Score, pick the high-impact wins first, and report the trend every quarter. If the number is not moving, we are not done.
Proof you can see. Not a slide saying aligned.
02
Phishing-resistant MFA
Conditional Access with phishing-resistant methods (passkeys, FIDO2, Windows Hello for Business) so a stolen password and a text code are not enough.
Your users should not be the softest door in the building.
03
Conditional Access and legacy-auth kill switch
Entra ID policies that block ancient protocols, enforce compliant devices, and stop any device, any time access from becoming an open invitation.
Attackers love what your MSP never switched off.
04
Defender for Office 365: email that fights back
Safe Links, Safe Attachments, and anti-phishing policies tuned for Business Premium so the inbox is a filter, not a welcome mat.
Most breaches still start with something that looks legit.
05
EDR: Endpoint Detection and Response (required)
Managed Endpoint Detection and Response with 24/7 human investigation and containment, alongside Microsoft Defender for Business. Required for all clients. Agents that only scan are not enough.
If nobody is watching the alerts, you do not have protection. You have hope.
06
Intune device compliance
Encryption, patch baselines, compliance policies, and Conditional Access that locks out non-compliant machines before they touch your data. Hardware has to be able to meet the bar. If it cannot, we schedule a refresh instead of pretending.
Security controls need machines that can run them. That is fairness, not snobbery.
07
Identity and admin hardening
Privileged accounts locked down, break-glass accounted for, guest access controlled, and admin sprawl cleaned up. Pairs with ISPM posture checks.
One over-privileged mailbox can undo a year of good intentions.
08
SAT: Security Awareness Training (required)
Security Awareness Training with phishing simulations and short drills for every user. Required for all clients. Habits that raise the human firewall without death-by-PowerPoint fear theatre.
Training that changes behaviour beats posters that collect dust.
09
ITDR: Identity Threat Detection and Response (required)
Identity Threat Detection and Response watches for compromised accounts, impossible travel, and privilege abuse. Required for all clients. Identity is the new perimeter; we treat it that way.
A stolen password should not own your business.
10
SIEM and managed detection (required)
Security Information and Event Management plus human triage of endpoint, identity, and Microsoft 365 signals. Required for all clients. Escalate what matters and close the loop so signals become action.
A SIEM without response is a screensaver.
11
ESPM: External Security Posture Management (required)
Continuous outside-in view of domains, email authentication, and internet-facing exposure. Required for all clients. Fix what attackers can already see.
You cannot defend what you do not know is public.
12
ISPM: Identity Security Posture Management (required)
Ongoing identity hygiene: MFA gaps, over-privileged accounts, risky consents, and Conditional Access drift. Required for all clients. Harden before attackers probe.
Posture is how you shrink the blast radius before the incident.
13
Backup and recovery proof
M365 and critical data protected, restores tested, recovery times documented, because a backup you have never restored is a bedtime story.
Ransomware does not care that the invoice said backup included.
14
Data loss guardrails
Sensitivity labels and DLP patterns where Business Premium supports them so customer data does not wander into the wrong share or inbox.
Clients trust you with their secrets. Act like it.
15
Quarterly uplift reviews
QBRs with Secure Score trend, open risks, and the next uplift batch: continual improvement, not a one-off project that dies at go-live.
Security that stops improving starts decaying.
The Stride Uplift Mark
The Stride Uplift Mark indicates a signed client self-assessment that they adhere to Stride IT Security Standard recommendations under the Continual Security Uplift Program. It is not an ACSC, DISP, Microsoft, or government certification.
Show your clients you take security seriously. With a mark that means you met a named standard and keep meeting it, not that you bought another scare campaign.
Client website example
Uplift Mark popup
Same example badge on this site. Clients who earn the Stride Uplift Mark get their own proof page and badge. With the disclaimer baked in.
The Stride Uplift Mark indicates a signed client self-assessment that they adhere to Stride IT Security Standard recommendations under the Continual Security Uplift Program. It is not an ACSC, DISP, Microsoft, or government certification.
How uplift runs inside the plan
One Plan is not “set and forget”. The Continual Security Uplift Program is the operating rhythm: five named phases with deliverables you can read.
1. Baseline
Honest picture of where you stand, Secure Score and all.
M365/environment audit, Secure Score baseline, Stride IT Security Standard gap map, tailored uplift plan and schedule.
2. Stabilise
Stop the bleeding. Fix what breaks trust today.
Critical patches, phishing-resistant MFA path, Defender onboarding, backup verification, help desk SLAs live.
3. Uplift
Lift each control against the Stride IT Security Standard.
Conditional Access, Intune compliance, email protection, SOC triage, user drills, Secure Score lift.
4. Mark
Earn the Stride Uplift Mark: signed self-assessment and public proof.
Signed self-assessment against the Standard, mark badge for your site, public proof page linked from the badge.
5. Continual
Keep lifting. Security that stops improving starts decaying.
QBRs, Secure Score trend, roadmap updates, mark renewal criteria tracked.
Photo: LinkedIn Sales Solutions / Unsplash
How to use the mark
- Display on your website footer or security page using artwork provided by Stride IT.
- Include in proposals alongside your Secure Score trend and Standard narrative.
- Always pair with context: Stride IT Security Standard met, not ACSC or Microsoft certification.
- Do not alter colours or imply government endorsement.
FREQUENTLY ASKED QUESTIONS
What is Our One Plan?
It is Stride IT's single managed offering. Day-to-day support, Microsoft 365 Business Premium as the floor, the required security stack (EDR, ITDR, SIEM, SAT, ESPM, ISPM), and Continual Security Uplift against the Stride IT Security Standard. No bronze, silver, or gold tiers. Projects are scoped and priced separately.
Why no tiers like other MSPs?
Tier menus usually strip security out of the cheap package so it can be sold back later. That is part of why MSPs suck. Our One Plan keeps the security floor inside the plan. If you want a thin tier without the stack, we decline. Another provider will take that work.
What is the Continual Security Uplift Program?
It is the method inside Our One Plan: Baseline, Stabilise, Uplift, Mark, and Continual. We lift your environment against the Stride IT Security Standard using Microsoft 365 Business Premium as the minimum stack, and we keep lifting after go-live.
What is the Stride IT Security Standard?
It is Stride IT's security baseline for clients on Microsoft 365 Business Premium or higher: Secure Score lift, phishing-resistant MFA, Conditional Access, Defender, Intune, and the required stack of EDR, ITDR, SIEM, SAT, ESPM, and ISPM, plus backup proof and quarterly reviews. That stack is required for every client. Informed by Microsoft guidance and selected frameworks, not an official certification.
What is not included in Our One Plan?
Major projects: migrations, large rollouts, new websites, and other scoped change work. Those are quoted separately so the monthly plan stays about running and uplifting your estate, not absorbing every build.
Are EDR, ITDR, SIEM, SAT, ESPM, and ISPM required?
Yes. They are part of Our One Plan for every client. See the Required Security Stack pages for detail. If you will not run them, we decline.
Will you take clients who skip the Security Uplift?
No. We decline on purpose. Ticket-only, break-fix, or “keep it cheap and hope” engagements undermine the Stride IT Security Standard. If you will not support Our One Plan minimum, we say no early so we can stay excellent for the clients who will.
What about older laptops and PCs?
Devices need to be fit for the Standard. Able to patch, encrypt, and enrol in Intune so Defender and Conditional Access actually work. If hardware is holding the uplift back, we do not shame anyone. We put a practical refresh plan on the roadmap and sequence it with the rest of the uplift.
How do we start?
Apply for Our One Plan. We run a Baseline Review to capture Secure Score, confirm Business Premium readiness and One Plan fit, check device and infrastructure fitness for the Standard, and give you a tailored uplift plan and schedule. It is an application. We may decline if you will not support the minimum.
The Stride Uplift Mark™ is a Stride IT program mark. It indicates that a client has completed a signed self-assessment affirming they adhere to Stride IT Security Standard recommendations under our Continual Security Uplift Program, and that Stride IT has recorded that attestation at the stated review date. The Standard is informed by Microsoft 365 Business Premium capabilities, Microsoft Secure Score guidance, and selected industry frameworks (including ACSC Essential 8 concepts). It is not an Australian Cyber Security Centre certification, not a Microsoft endorsement, not a DISP approval, and not a guarantee of security or regulatory compliance. Proof for each issuer is published on this site and linked from the badge.