NumataOne™

One framework.
Six categories.
Governed as one.

NumataOne™ is the strategy enablement framework behind every engagement we run, from Core through to Enterprise. It turns strategy, cyber, data, operations, modern work and AI into a single managed capability, governed on one lifecycle and reported on one cadence.

Kind
Operating model
Runs on
Every tier, Core to Enterprise
Cadence
Quarterly executive review
Numata strategists reviewing a client programme around a boardroom table

Estates drift when responsibility is split across vendors, projects and tickets. NumataOne™ puts it back under one partner.

Why a framework
The management cycle

A cycle that repeats, not a project that ends.

The same cycle applies whether we are stabilising an estate, mobilising a portfolio company through DayOne+, or standing up a Managed AI capability. It closes on itself, so each quarter starts from evidence rather than from memory.

  1. Assess

    Baseline the current state across strategy, risk, operations and data.

  2. Prioritise

    Focus on the moves that carry the most business weight.

  3. Roadmap

    Sequence a phased plan tied to outcomes, not activity.

  4. Execute

    Deliver with named accountability and a single service model.

  5. Govern

    Manage risk, policy and performance against evidence.

  6. Measure

    Report against a scorecard the operating board recognises.

The six categories

Each category is a full practice. Under NumataOne™ they are governed together.

A decision on cyber lands cleanly in operations, and a bet on AI is grounded in data and identity. Categories are never bought in isolation: each engagement draws on whichever the roadmap calls for, at the depth the tier supports, and reports back through the same scorecard.

  • IT Strategy, Risk & Compliance

    Direction, governance and evidence. The operating model that lets the rest of the framework run.

  • Cyber Resilience

    Defence-in-depth, 24/7 detection and response, aligned to Cyber Essentials, NIS2 and NCSC guidance.

  • Data Protection

    Backup, continuity and recovery. Data protected by design, evidenced under UK GDPR and DPA 2018.

  • IT Operations

    Reliable, secure daily delivery. Service desk, endpoint, network and vendor management under one roof.

  • Modern Work Enablement

    Microsoft 365, cloud and identity, tuned for how people actually work across HQ, hybrid and frontline.

  • AI & Data Enablement

    Managed AI, governed responsibly. Use cases delivered through the AI Studio with human-in-the-loop controls.

Where you already have internal capability in a category, we govern around it rather than duplicate it, and the evidence still lands in one place.

Service tiers

Tiers that scale. One framework underneath.

NumataOne™ is not a tier you buy. What changes between tiers is the breadth of services, the depth of strategic engagement and the response posture. Managed AI Services are an optional add-on at every level.

  • Foundation

    Core

    Stabilise the fundamentals: service desk, devices, backup and a managed SOC baseline.

  • Growth

    Standard

    Add governance and resilience: MDR, GRC services and vulnerability management.

  • Scale

    Premium

    Modernise the operating model: cloud, Microsoft 365 and Copilot, data and analytics.

  • Transform

    Enterprise

    Governed as one: named Business Technology Strategist, AI governance, investment readiness.

How it stays honest

The rules that keep the framework honest.

  • One accountable partner

    Six categories, one service model, one roadmap. No vendor triangulation when something breaks.

  • Governed, not improvised

    Every engagement runs against the same lifecycle, with policy, evidence and reporting from day one.

  • Outcomes over activity

    We report against a business scorecard, not a ticket queue. The operating board and store leader both recognise the numbers.

  • Regulated by design

    Aligned to Cyber Essentials, ISO 27001, NIS2, UK GDPR and, where relevant, PCI DSS and DOS 7 for public sector.

Outcomes

Outcomes the operating board actually reads.

Every engagement reports against the outcome it was funded to deliver, with the evidence behind it.

The framework

A working system with numbers attached.

AssessPrioritiseDeliverMeasureImprove01ELEVATEStrategy, Risk &Compliance02SECURECybersecurity03PROTECTResilience &Continuity04OPERATEIT Operations05EMPOWERModern Work06INNOVATEAI & DataNumataOneStrategy enablementFramework
  • One methodology, six categories

    Every engagement scoped and governed through the same framework, whatever the industry.

  • Regulated by design

    Controls, evidence and reporting aligned to the standards your auditors, regulators and boards expect.

  • Service that runs to a scorecard

    Uptime, MTTR, cyber posture, cost-to-serve and value delivered, reviewed every quarter.

  • Independent of hyperscaler and vendor

    Recommendations follow the business case, not a partner tier. Where useful, we say so.

Proof

Run end to end through NumataOne™.

Sunlight through architectural louvers casting geometric shadows
Case study
Featured case study

Operational resilience, delivered under one governance model.

Read the case study

A mid-market client stabilised its estate, uplifted cyber controls and stood up a governed AI capability inside twelve months, run end to end through NumataOne™. Reporting moved from a ticket log to a quarterly business scorecard.

FAQs

NumataOne™, answered.

What is NumataOne™?

NumataOne™ is the strategy enablement framework behind our services, not a package you buy. It combines a management lifecycle, assess, prioritise, roadmap, execute, govern and measure, with six connected service categories. Every engagement, whether Core, Standard, Premium or Enterprise, is scoped and run through it.

How do the service tiers relate to NumataOne™?

Core, Standard, Premium and Enterprise all run on the same NumataOne™ framework. The tier sets the breadth of services, the depth of strategic engagement and the response posture. Managed AI Services are an optional add-on at every tier, so AI adoption is never gated behind an upgrade you do not need.

Why a framework rather than individual services?

Because standalone services drift. A framework keeps strategy, risk, operations, data, modern work and AI aligned to the same roadmap and reporting cadence. It is the difference between technology as a collection of projects and technology as a managed capability.

Who is NumataOne™ designed for?

Ambitious mid-market and SME organisations, and the private equity portfolios that back them. It suits businesses where technology carries real risk and real value, and where the operating board needs a clear line of sight from decision to outcome.

How is NumataOne™ different from a traditional MSP contract?

A traditional MSP contract answers tickets. NumataOne™ runs a strategy enablement framework: it names the risks that matter, tracks the roadmap, evidences governance and reports value. The service desk is part of it, not the whole thing.

How long does it take to see results?

The first 90 days deliver a baseline assessment, a prioritised roadmap and stabilisation of the most exposed operational and cyber controls. Strategic outcomes then land against the roadmap on a quarterly cadence.

How does NumataOne™ work alongside our existing team?

It augments, it does not replace. Where you have an internal IT lead, CIO or CISO, NumataOne™ gives them the framework, capacity and evidence to run at a higher level. Where you do not, we act as the accountable function.

Start with a Business
Technology Assessment.

Two conversations and a working session. You leave with a baseline, a prioritised roadmap and the two or three moves that will most reduce risk and release value in the next 90 days.