Retained IT and security management

Ongoing scheduled review, maintenance planning and advisory support under a retainer, so security and infrastructure work continues after a project ends.

Isometric diagram of a recurring scheduled review cycle around an environment, catching configuration drift and privileged access changes and reporting to leadership.
How retained it and security management work is framed: scope, evidence and a safe way back.

What we review

  • Scheduled review cycle: Agreed periodic review of configuration, access, patching posture and recent change.
  • Drift detection: What has changed since the last review, whether it was intended, and who made it.
  • Access review: Who holds privileged access now, whether it is still warranted, and what to remove.
  • Change advisory: A technical read on planned changes before they reach production.
  • Remediation tracking: Progress against previously agreed findings, so open items do not quietly lapse.
  • Documentation upkeep: Keeping architecture and operating documents current as the environment changes.
  • Risk reporting: A periodic written position on current risk, suitable for leadership or a board.
  • Escalation path: An agreed route to reach us during business hours, with agreed response expectations.

Deliverables

  • Periodic review report: What changed, what drifted, what needs attention, in priority order.
  • Open findings tracker: Live status of agreed remediation work, so nothing is silently dropped.
  • Change advisory notes: Written positions on proposed changes, with risks and rollback considerations.
  • Current-state documentation: Architecture and operating documents kept current rather than written once.
  • Risk summary for leadership: A plain-language periodic position on where risk sits.
  • Access review record: Evidence of who held privileged access, what was reviewed, and what was removed.

Engagement boundaries

  • This is scheduled advisory and review work during Canadian business hours. It is not a 24/7 monitored service.
  • HAI Consulting does not provide a staffed security operations centre, round-the-clock monitoring, or an on-call rota.
  • This is not a helpdesk. End-user support, device provisioning and day-to-day ticket handling are not included.
  • Incident response during an active breach is separate work, subject to availability, and should not be assumed under a retainer.
  • No guaranteed response time outside agreed business hours is offered, because that capacity is not staffed.
  • Detection depends on the logging and tooling you have; a review cycle is not continuous monitoring.
  • Retained review reduces drift and surfaces risk earlier. It does not prevent incidents or guarantee uptime.
  • Changes are implemented through your change process with your approval, not unilaterally.
  • The retainer covers the scope agreed in writing; work outside it is quoted separately rather than absorbed.
  • This engagement does not certify compliance with any framework or standard.

Questions before the work starts

Is this a managed service with 24/7 monitoring?

No, and it is important to be direct about that. This is scheduled review and advisory work during business hours. HAI Consulting does not operate a staffed 24/7 security operations centre or an on-call rota. If you need round-the-clock monitored detection and response, you need a provider with that staffing, and we will say so rather than sell you something else.

What response times apply?

Response expectations are agreed in writing at the start and apply during Canadian business hours. No out-of-hours guarantee is offered, because that capacity is not staffed. An agreement that promises what cannot be delivered is worse than no agreement.

Does this include helpdesk support?

No. End-user support, password resets, device provisioning and ticket handling are not part of this work. This is senior technical review and advisory support for infrastructure and security decisions.

What happens if we have a security incident?

Contact us and we will help where we can, but incident response during an active breach is separate work and subject to availability. It should not be assumed as part of a retainer. Organizations that need guaranteed incident response should retain a provider who offers it explicitly.

Can we start with a project and move to a retainer?

That is the usual path. An assessment or design engagement establishes the baseline and the findings; a retainer then supports working through them and keeping the environment from drifting. Neither requires the other.

How is this priced?

By agreed scope and cadence, set out in writing before work starts. There is no published price list, because the right cadence for a ten-person business differs from a two-hundred-person one.

The platforms this work covers

Retained review covers the platforms in your agreed scope, revisited on a schedule so drift is caught early.

  • Microsoft 365 and Entra ID
  • Microsoft Azure
  • Amazon Web Services
  • Cisco
  • Palo Alto Networks
  • Check Point
  • Fortinet FortiGate
  • F5
  • Cloudflare
  • On-premises and colocation data centre

Audits available

  • Periodic configuration drift review: what changed since the last cycle, whether it was intended, and who changed it.
  • Privileged access review: who holds administrative access now, whether it is still warranted, and what to remove.
  • Change advisory review: a technical read on proposed changes before they reach production.

Need a second set of eyes on a security or infrastructure decision?

Describe the environment, the risk and the outcome you need.

Contact HAI Consulting →