A defensible baseline, running to a standard.
Most executive teams inherit an operating environment they cannot easily describe. Stabilise and Protect closes that gap: a documented baseline, accountable support, and the essential controls that let the rest of the strategy proceed.
Document
A written baseline of identity, endpoints, data and support the business can point to.
Operate
Support, patching and protection run by a named team to a defined standard.
Respond
Incidents handled to a rehearsed playbook, with escalation paths named in advance.

Named team
A Business Technology Strategist accountable for the environment, not a ticket queue.
24/7/365
Monitoring and response coverage across every hub we operate from.
One playbook
Incidents follow a documented, rehearsed sequence rather than individual heroics.
90 days
From first baseline to the first executive review of what changed.
Instability is rarely one big failure. It is a hundred small things nobody owns.
No written baseline
Nobody can describe what is running, who owns it, or what happens when it stops.
Key-person dependency
One person holds the passwords, the history and the workarounds. Leave dates become risk dates.
Support without a standard
Tickets get answered eventually. There is no service level, no trend and no root-cause work.
Improvised incident response
When something breaks, the response is invented on the call. Nobody knows who decides what.
The standard the outcome is held to.
The executive team can point to a written baseline. Support is answered by a named team on a defined standard. Identity, endpoints, backup and email protection are managed, not monitored. Nothing important depends on a single person.
- A single accountable owner for day-to-day IT operations.
- Identity, endpoint, backup and support running to defined service levels.
- A documented technology baseline the executive team can point to.
- Incidents handled to a known playbook, not to individual heroics.
A rehearsed sequence, not a bespoke project.
Baseline
Document identity, endpoints, data, network and support as they actually run.
Stabilise
Close the gaps that cause repeat incidents and single points of failure.
Protect
Managed identity, endpoint, email and backup controls to a defined standard.
Rehearse
Incident playbooks written, escalation paths named, response tested.
Review
Quarterly review against the Business Maturity Rating with the leadership team.
Coverage scales with the NumataOne service tier.
Each tier includes everything in the one before it.
Core
Named support to defined service levels, managed identity and endpoint protection, and a documented baseline.
Standard
Adds patch and vulnerability management, email protection and a written incident response playbook.
Premium
Adds 24/7 monitored detection and response, named escalation paths and quarterly executive review.
Enterprise
Adds rehearsed incident scenarios, root-cause reporting and evidence prepared for audit or diligence.
What leadership can review, and when.
- Baseline register and control coverage report.
- Support and incident metrics against service levels.
- Change log with executive sign-off trail.
- Incident records with root cause and actions taken.
Stability is not the absence of incidents. It is knowing, in advance, who answers, what they do, and when the business gets its answer.
Questions leadership teams ask.
What does a technology baseline actually include?
A written record of identity and access, endpoints, servers and cloud services, data locations, network, licensing, support arrangements and the controls protecting each. It names an owner for every item, so nothing important depends on memory.
How is incident response different from support?
Support resolves requests against a service level. Incident response is the rehearsed sequence used when something material breaks: who is notified, who decides, how the business is kept informed, and how the event is recorded and reviewed afterwards.
How quickly can an inherited environment be stabilised?
The baseline and the first wave of stabilisation work typically complete inside the first 90 days, with protection deployed alongside it. Repeat-incident causes are usually cleared in the quarter that follows.
Do we have to replace our existing tools?
Not by default. We assess what is in place, keep what meets the standard, and consolidate only where duplication is creating cost or gaps. The baseline decides the change, not a product preference.
Who is accountable once we are live?
A named Business Technology Strategist owns the environment and the review cadence, supported by the managed operations team. Escalation paths are documented before an incident, not during one.
