The True Cost of Downtime: What an Hour Offline Really Costs

The honest answer to “what does an hour offline cost us?” is: more than you think, and you can work it out in ten minutes. Take the staff who can’t work, multiply by their loaded hourly cost and the hours lost, then add the revenue you didn’t earn and the cost of putting things right. That number is usually a nasty surprise.

Most owners have never run that sum. They have a vague sense that downtime is bad, but no figure to weigh against the cost of preventing it. That gap is exactly why “we’ll fix it when it breaks” feels cheaper than it is. Here’s how to calculate the real cost of downtime for your business, what people leave out, and why a proactive approach almost always wins on the numbers.

The simple formula

You don’t need a consultant or a spreadsheet model to get a defensible figure. Four buckets cover most of it.

  • Lost productivity = staff affected x loaded hourly cost x hours down. The people who are sitting idle, or working at half pace, while the system they need is unavailable.
  • Lost revenue = sales, billable hours or transactions you couldn’t process during the outage and won’t recover later. Not every business has this; a retailer with the till down clearly does.
  • Recovery costs = the after-hours engineering, overtime, expedited hardware, and the catch-up work once you’re back. This is the bit that keeps running after the lights come back on.
  • Intangibles = reputation damage, missed deadlines, SLA penalties you owe your own clients, and the goodwill you spend apologising. Hard to price exactly, real all the same.

Add the four together and you have your cost per hour of downtime. The first bucket is the one everyone can calculate, so start there.

Getting “loaded hourly cost” right

A common mistake is to use the raw wage. The figure you want is the loaded cost — salary plus superannuation, payroll tax, leave loading, and overheads like the desk, the laptop and the software licence that person needs to do their job. As a rough rule, loaded cost runs about 1.25 to 1.4 times base salary. Someone on $90,000 isn’t costing you $43 an hour when they’re idle; they’re closer to $55 to $60 once you load it properly. Use the loaded figure or you’ll undercount every time.

A worked example

Let me put real numbers to it. This is a deliberately hypothetical scenario, not a real client and not a statistic — but the assumptions are the kind we see in Melbourne SMEs every week. You should swap in your own figures.

Picture a 30-person professional services firm in Camberwell. Their line-of-business application and shared files go down for half a day — four working hours — because a server failed and there was no quick failover. Assumptions:

  • 25 of the 30 staff are completely blocked; the other five can do offline admin.
  • Average loaded hourly cost across the affected staff: $60.
  • The firm bills time, and roughly $8,000 of billable work for that morning simply can’t be done and largely can’t be clawed back.
  • Recovery: an after-hours engineer, a replacement part couriered in, and overtime to catch up — call it $3,500.
Cost bucketCalculationAmount
Lost productivity25 staff x $60 x 4 hours$6,000
Lost revenueUnrecoverable billable work$8,000
Recovery costsAfter-hours labour, part, overtime$3,500
IntangiblesTwo client deadlines slipped; one annoyed clientNot priced, but real
Total (measurable)$17,500

That’s $17,500 for half a day, before you count the intangibles. Spread the same event across a few times a year and you’re well into five figures of avoidable loss. Run those four lines for your own business with your own headcount and rates — the exercise takes ten minutes and the result tends to change how people think about their IT budget.

The hidden costs people forget

The formula above captures the obvious losses. The ones that quietly inflate the real figure are easy to miss.

  • The ramp-back-up tax. Productivity doesn’t snap back to 100% the moment systems return. People spend the next hour re-doing lost work, re-establishing context and clearing the backlog. Add 25 to 50 per cent to your productivity figure for this.
  • Cascading effects. If your phone system, payment terminal or booking platform depends on the same internet link or server, one failure takes out several functions at once. The blast radius is usually wider than the thing that broke.
  • SLA penalties you owe. If you have your own service-level commitments to clients, an outage can trigger credits or penalties. A logistics firm that misses a delivery window doesn’t just lose that job’s margin.
  • Morale and overtime. Staff who lose half a day’s work then stay back to catch up don’t forget it. Chronic instability is a genuine factor in people leaving.
  • Reputation. A retailer whose card terminal is down on a Saturday, or a clinic that can’t access patient records, loses trust as well as revenue. You can’t invoice for that, but you pay for it.

Why “fix it when it breaks” is a false economy

Break-fix — paying an hourly rate to fix things only once they fail — looks cheaper on a quiet month because you’re not paying for anything. The problem is what it does to both the frequency and the duration of downtime, which are the two levers that actually drive your cost.

Under break-fix, nobody is watching your systems. A failing disk, a backup that quietly stopped running three weeks ago, a firewall firmware bug — these get discovered when they cause an outage, not before. And when something does break, you’re at the back of the queue: the provider has to be called, has to understand an environment they don’t monitor, has to source parts cold. Your four-hour outage in the example above could easily have been an eight-hour one if the first two hours were spent just working out what failed.

The false economy is comparing the monthly fee of managed IT against zero, when the honest comparison is against the downtime you’ll eat without it. One avoided half-day outage a year often covers the difference.

How proactive managed IT cuts the bill

Good managed IT attacks downtime on two fronts: it makes outages less frequent, and it makes the ones that do happen shorter. Both reduce the hours in your formula.

Monitoring catches problems before they’re outages

Continuous monitoring means a failing drive, a service that’s stopped, or a backup job that didn’t complete raises an alert while it’s still a maintenance task, not an emergency. Most of the outages we prevent are ones the client never knew were coming. That’s the whole point — the cheapest downtime is the kind that never happens.

Redundancy removes single points of failure

A second internet service, a failover server, a clustered firewall — redundancy means one component failing doesn’t stop the business. It costs money, so you apply it where the downtime cost justifies it, which is exactly the calculation above. A business that knows an hour offline costs $4,000 can make a rational call on a $200/month redundant link.

Backups and a tested DR plan shorten recovery

When something does take systems down, the difference between a two-hour recovery and a two-day one is whether your backups work and whether you’ve ever actually tested restoring from them. An untested backup is a guess. We restore from backups on a schedule precisely so the day we need them isn’t the day we find out they were corrupt. A real backup and disaster recovery setup — with a documented, rehearsed DR plan — is what turns a catastrophe into an inconvenience. We go deeper on this in our guide to backup and disaster recovery for Melbourne businesses.

Tying downtime tolerance to RTO and RPO

Once you know what an hour costs, two numbers turn that into a design target. Your recovery time objective (RTO) is how long you can be down before the damage is unacceptable. Your recovery point objective (RPO) is how much data — measured in time — you can afford to lose. A business losing $4,000 an hour can’t tolerate a 24-hour RTO; the maths makes that obvious.

These aren’t abstract IT acronyms — they’re the bridge between your downtime cost and the money you should spend preventing it. Tight RTO and RPO targets cost more to deliver because they need redundancy and faster backups; loose ones are cheaper but expose you to bigger losses. The right answer falls out of the numbers you just calculated. Our explainer on RTO versus RPO walks through how to set them sensibly for each system.

TechAssist is a Melbourne-based MSP, founded in 2014, with 13 Australian-employed engineers and no offshore helpdesk. We run per-user fixed monthly pricing with no hourly billing for in-scope work, and we target sub-15-minute response on critical issues from our 24/7 NOC in Tecoma — because on a P1, every minute is a line in the downtime sum above. If you’d like help working out what an hour offline genuinely costs your business and designing around it, get in touch and we’ll run the numbers with you.

Frequently asked questions

How do I calculate the cost of downtime for my business?

Add four buckets: lost productivity (staff affected x loaded hourly cost x hours down), lost revenue you can’t recover, recovery costs like after-hours engineering and overtime, and intangibles such as reputation and SLA penalties. Sum them for a cost per hour, then multiply by a realistic outage length. Use loaded staff cost — salary plus on-costs and overheads — not the raw wage.

What is loaded hourly cost?

It’s the true cost of an employee per hour, including superannuation, payroll tax, leave entitlements and overheads like their equipment and software, not just their base wage. It usually works out to roughly 1.25 to 1.4 times base salary. Using the loaded figure stops you undercounting your productivity losses.

Is managed IT actually cheaper than break-fix?

Over a realistic period, usually yes — because break-fix ignores the cost of downtime it fails to prevent. Managed IT reduces both how often outages happen and how long they last through monitoring, redundancy and tested backups. One avoided half-day outage a year commonly covers the difference in fees.

How do RTO and RPO relate to downtime cost?

Your downtime cost tells you how much an outage hurts; RTO and RPO turn that into design targets. RTO is how long you can be down, RPO is how much data you can lose. A high hourly cost demands tighter targets, which justify spending on redundancy and faster backups. The numbers should drive the design, not the other way round.

What are the hidden costs of downtime?

The ones people miss include the ramp-back-up time after systems return, cascading effects when one failure takes out several functions, penalties under your own client SLAs, staff morale and overtime, and reputation damage with customers. These often add as much again to the obvious productivity and revenue losses.

For most Australian SMEs in 2026 the honest answer to laptops vs desktops comes down to one question: does the person need to work in more than one place? If yes, buy a business-grade laptop and a dock. If they sit at the same desk every day and never move, a desktop gives you more performance per dollar and a longer life. The nuance is in the edge cases.

The old reasons to buy desktops — far cheaper, far faster, easier to fix — have softened. Laptops have closed the gap on performance, and hybrid work has made portability a default expectation rather than a perk. But desktops haven’t disappeared, and for some roles they’re still the right call. Below is a plain comparison and a role-by-role view, with the Windows 11 and Copilot+ angle that’s now part of every refresh conversation.

The quick comparison

FactorBusiness laptopBusiness desktop
MobilityBuilt for it — works at the desk, at home, on siteNone; tied to one location
Performance per dollarGood, but you pay a premium for the same gruntStronger — more CPU, GPU and RAM for the money
UpgradeabilityLimited; often only RAM/SSD, sometimes solderedOpen case — RAM, storage, GPU, PSU all swappable
RepairabilityScreen, keyboard and battery are real cost itemsMost parts replaceable cheaply and quickly
Lifespan3–4 years typical before battery and wear bite4–6 years; easy to extend with a part or two
Dual monitorsVia dock — clean once set upNative; multiple ports out of the box
Security riskHigher — gets lost or stolen; encryption essentialLower physical risk; stays on premises
Total cost of ownershipHigher hardware + dock, but enables hybrid workLower hardware, but no flexibility value
Best fitField, sales, exec, hybrid, hot-deskingFixed workstations, CAD, finance, heavy compute

Prices and configurations shift constantly, so treat that as a framework, not a quote. The hardware sticker is rarely the deciding number anyway — total cost of ownership over four years, including support, downtime and the value of flexibility, is what actually matters.

Mobility and hybrid work

This is the factor that’s reshaped the decision. A few years ago most Melbourne SMEs ran desktops in the office and that was that. Now hybrid is the default for professional services, and a person who can’t pick up their machine and work from home, a client site or the train is a productivity gap waiting to happen. For sales, field and management roles, a laptop isn’t a luxury — it’s the job.

The catch is that buying laptops “because everyone’s hybrid now” without thinking it through wastes money on people who never actually leave their desk. Be honest about who moves and who doesn’t. A reception or warehouse terminal that lives in one spot for five years doesn’t need a portable battery you’ll be replacing in year three.

Performance per dollar and the power users

For the same spend, a desktop still gives you more — more cores, faster GPU, more RAM, and the thermal headroom to sustain it under load. That matters enormously for a narrow band of roles: CAD and 3D work, engineering simulation, video editing, large data sets, anything that pegs a processor for hours. Cram that workload into a thin laptop and it throttles, runs hot and ages fast.

An engineering or architecture practice in Hawthorn running AutoCAD and Revit is a clear desktop case — or at minimum a mobile workstation, which is a different (and pricier) animal to a standard ultrabook. For the bulk of office work, though — Microsoft 365, browsers, video calls, line-of-business apps — a mid-range business laptop has more than enough grunt, and the performance gap is invisible day to day. Don’t pay for desktop horsepower a spreadsheet user will never touch.

Repairability, upgradeability and lifespan

Desktops win cleanly here, and it’s a real cost lever over time. A desktop is a serviceable box: when the storage fills up or the RAM gets tight, you open it and add more. A failed power supply is a cheap, quick swap. That’s why a well-specced desktop comfortably runs four to six years, and you can stretch it further with a single part.

Laptops are tighter. Better business models still let you upgrade RAM and SSD, but many consumer machines solder the RAM, and a cracked screen, worn battery or failed keyboard is a genuine repair bill — sometimes close to the cost of replacement. Plan on three to four years for laptops as a working assumption, and build that shorter cycle into your budgeting rather than being surprised by it.

Docking and dual monitors

The classic objection to laptops — “but my team needs two big screens” — stopped being valid years ago. A decent USB-C or Thunderbolt dock turns a laptop into a full desktop setup in one cable: dual monitors, keyboard, mouse, wired network and power. Staff get the desktop experience at their desk and full portability when they walk away.

Two practical notes. First, standardise on one or two dock models across the fleet — mismatched docks are a quiet, recurring source of support tickets. Second, check the laptop actually drives the displays you want at the resolution and refresh you want; not every USB-C port carries enough bandwidth for two 4K screens. Get that right at purchase and dual-monitor laptop setups are genuinely seamless.

Security: laptops get lost

This is the factor people underrate. A desktop bolted under a desk in your office is, physically, fairly safe. A laptop rides in cars, sits in cafes and gets left on trains. Every portable device is a data-loss event waiting to happen if it isn’t protected, and under the OAIC’s Notifiable Data Breaches scheme, a lost laptop holding client data can be a reportable breach.

The non-negotiable is full-disk encryption — BitLocker on Windows, managed centrally so recovery keys are escrowed and you can prove the device was encrypted if it goes missing. Pair that with a business-grade machine that has a TPM 2.0 chip (which Windows 11 requires anyway), conditional access so a stolen device can’t simply sign in, and remote wipe through Intune. We cover the access side in our guide to conditional access policies in Microsoft 365, and encryption is a baseline control under the Essential Eight. A lost encrypted laptop is an annoyance; a lost unencrypted one is a notifiable breach and a very bad week.

The Windows 11 baseline and Copilot+ PCs

Windows 10 reached end of support in October 2025, so every machine you buy now should be Windows 11 and meet its hardware floor: a supported 64-bit CPU, 4GB+ RAM (realistically 16GB for business use), UEFI with Secure Boot, and TPM 2.0. Any business-grade device from the last few years clears that bar; the trap is cheap consumer stock that quietly doesn’t.

The newer wrinkle is Copilot+ PCs — machines with a neural processing unit (NPU) rated at 40+ TOPS that run certain AI features locally rather than in the cloud. They’re genuinely more efficient and have excellent battery life, but for most SMEs in 2026 the on-device AI features are a nice-to-have, not a reason to pay a premium or rush a refresh. Buy one if it fits the budget and the role; don’t let the marketing drive the whole fleet decision. If you’re weighing the AI productivity case more broadly, our Microsoft 365 support team can give you a straight read on what’s worth paying for.

Business-grade vs consumer kit

This matters more than the laptop-versus-desktop question for most buyers. Consumer machines from a retail shelf look like a bargain until you account for what’s missing: shorter warranties, no next-business-day on-site option, no fleet manageability, weaker build quality, and bundled junkware. Business lines — think the commercial ranges from the major vendors — give you longer warranties, TPM and firmware-level security features, driver stability, and machines you can enrol and manage centrally.

For a managed fleet, manageability is the quiet killer feature. Business devices support zero-touch provisioning through Windows Autopilot, so a new starter’s machine ships, gets unboxed, connects to wifi and configures itself with the right apps and policies — no engineer building it by hand. Consumer kit fights that process every step. The slightly higher upfront cost pays for itself the first time you onboard someone without a site visit.

Buy, lease or Device-as-a-Service

Buying outright is simplest: you own the asset, depreciate it, and there’s no contract. The downside is a lumpy capital cost every refresh cycle and the temptation to run machines years past their use-by date to avoid spending again. That’s how you end up with a fleet of slow, out-of-warranty laptops dragging productivity down.

Leasing or Device-as-a-Service (DaaS) spreads the cost into a predictable monthly figure and usually bundles refresh, warranty and sometimes provisioning into one line. For a growing business that values predictable opex and an automatic refresh cycle, that’s attractive — it forces the hardware discipline that buyers often skip. The trade-off is you’ll pay a little more over the full term, and you don’t own anything at the end. There’s no universally right answer; it depends on your cash flow and how disciplined you are about refreshes on your own.

Standardise the fleet

Whatever you buy, buy few models, not many. A fleet of three standard configurations — say a standard laptop, a power-user laptop and a desktop workstation — is dramatically cheaper to support than fifteen one-off machines bought ad hoc over the years. Standardisation means one set of drivers to test, spare parts that interchange, predictable imaging, and a swap-out that takes minutes instead of a half-day rebuild.

A professional services firm in Camberwell we work with had exactly that problem: every staff member had picked their own machine over five years, so no two were alike and every fault was a fresh investigation. We moved them to two laptop SKUs and one desktop for their finance team, all enrolled through Autopilot and encrypted with BitLocker. Support time dropped, onboarding went from a day to an hour, and their refresh budgeting finally became predictable. The cost saving wasn’t in the hardware — it was in everything around it. That fleet-management discipline is core to how our managed IT services work.

Frequently asked questions

Are desktops still worth buying in 2026?

Yes, for the right roles. Fixed workstations that never move, finance teams on multiple large monitors, and power users running CAD, video or heavy compute all get more performance per dollar and a longer, cheaper-to-maintain life from a desktop. For mobile or hybrid roles, a laptop with a dock is the better call.

How long should a business laptop last?

Plan on three to four years. The battery, hinges and keyboard wear with use, and after four years repair costs and slowdowns usually outweigh keeping the machine. Desktops stretch to four to six years and can be extended with a cheap RAM or SSD upgrade. Build those cycles into your budget rather than running kit until it dies.

Do we really need business-grade machines instead of cheaper consumer ones?

For a managed business fleet, yes. Business lines give you longer warranties, next-business-day on-site options, TPM and firmware security, driver stability, and central manageability through tools like Intune and Autopilot. Consumer machines look cheaper upfront but cost more in support, downtime and shorter usable life.

What’s the most important security control for laptops?

Full-disk encryption — BitLocker, managed centrally so recovery keys are stored safely. A lost or stolen laptop with client data can be a notifiable breach under the OAIC scheme; if it’s encrypted and you can prove it, the exposure is far lower. Pair encryption with conditional access and remote wipe.

Should we lease or buy our hardware?

Buying suits businesses with the capital and the discipline to refresh on schedule. Leasing or Device-as-a-Service suits those who prefer predictable monthly opex and want refresh, warranty and provisioning bundled in. You pay slightly more over the term but avoid lumpy costs and the temptation to run machines too long.

Getting the decision right

The 2026 rule is simple: match the machine to the role, not to a blanket policy. Map who actually moves, who needs raw compute, and who sits in one place all day, then standardise on a small set of business-grade configurations and manage them properly — encrypted, enrolled and on a sensible refresh cycle. That’s where the real savings live, well beyond the sticker price.

TechAssist is a Melbourne-based MSP founded in 2014, with 13 Australian-employed engineers and same-business-day on-site support across the metro — which means we can hand-deliver, swap or fix a machine fast when hardware does fail. If you want a straight recommendation on what to buy for which roles, or a managed fleet that runs itself, get in touch or take a look at our pricing and SLA. No upsell to gear you don’t need.

Software licence compliance means you hold a valid, paid licence for every copy of every program your business runs. A vendor “true-up” or audit is when Microsoft, Adobe, Autodesk or another publisher checks whether what you’ve deployed matches what you’ve bought. Get it wrong and the bill arrives at list price.

What a true-up and an audit actually are

The two terms get used interchangeably, but they’re not the same thing. A true-up is the reconciliation built into a volume licensing agreement. If you signed a Microsoft Enterprise Agreement or similar, you committed to a baseline number of licences and agreed to “true up” annually for anything extra you deployed during the year. It’s routine accounting: you report the additional seats, you pay for them, the agreement rolls on. Where it bites is when nobody has tracked the additions and the annual reconciliation surfaces twelve months of unlicensed growth at once.

An audit is the adversarial version. The vendor, or a third party acting for them, exercises the audit clause in your licensing contract and asks you to prove compliance. They’ll count installs against entitlements and present you with a “compliance gap”. A right to audit is written into almost every software agreement you’ve ever clicked through. Microsoft, Adobe and Autodesk all do it, and so do Oracle, SAP and IBM, who are notoriously aggressive about it.

Why vendors audit

Because it pays. Software is one of the few products where the customer self-reports how much they’re using, and self-reporting drifts. In any business of reasonable size, deployment creeps past entitlement as staff are added, machines are reimaged and VMs are spun up. An audit converts that drift into revenue, usually at full list price with no discount.

The triggers are predictable: a sharp drop in renewal spend, a merger or acquisition, switching away from a vendor’s product, a jump in headcount, or simply the random rotation a publisher runs through its mid-market customers. Subscription licensing has made it easier still: when your software phones home, the vendor already knows who’s using what before they send a letter.

How SMEs end up non-compliant

Almost no one sets out to pirate software. Non-compliance is nearly always sloppiness, not theft, and it accumulates quietly. These are the patterns we see most across Melbourne SMEs.

  • Over-deployment. You bought 40 Microsoft 365 licences, you’ve grown to 52 staff, and the extra dozen are using the platform on borrowed credentials or seats that were never purchased. The headcount moved; the licence count didn’t.
  • Wrong licence type for the use. Running software licensed for development on a live production server, or using education and not-for-profit pricing in a commercial entity that no longer qualifies.
  • Mixing Business and Enterprise plans. Microsoft 365 Business plans (Basic, Standard, Premium) are capped at 300 seats. Plenty of growing firms blow past 300 users still stacking Business licences, when they should have moved to Enterprise (E3/E5) plans.
  • Client Access Licences (CALs). On-premises Windows Server and SQL Server still need a CAL for every user or device that connects. CALs are the most commonly under-counted licence in Australian SMEs, because the server “just works” whether or not the paperwork exists.
  • Unlicensed virtual machines. Spinning up a new VM from a template often clones a Windows Server or SQL install without anyone buying the licence to cover it.
  • Shared accounts. Three people on reception sharing one Adobe Acrobat or Microsoft 365 login. Named-user subscriptions are licensed per person, not per desk, and sharing breaches the terms even though it feels economical.

The real cost of getting it wrong

When a true-up or audit finds a gap, you don’t buy the shortfall at the keen price your reseller would normally quote. You typically pay back-charges for the period you were under-licensed, the licences at full list price, and in audit scenarios potentially penalties or the vendor’s audit costs on top. There’s no negotiating leverage, because you’ve been caught short and the clock is running.

The other cost is the rushed purchase. Faced with a deadline, businesses buy whatever the vendor puts in front of them, at list, often more than they need. A manufacturer in Dandenong we work with discovered during a routine Autodesk reconciliation that several engineering machines were running design software well beyond the seats they’d paid for. The catch-up purchase, under time pressure and at list, cost several times what an orderly renewal would have. The licences were genuinely needed; the panic premium wasn’t.

How to stay compliant

Compliance isn’t a once-a-year scramble. It’s an ongoing discipline, and most of it is unglamorous record-keeping that pays for itself the first time a letter lands.

Maintain a licence register

The foundation is knowing what you own. A licence register is a single, maintained record of every software product you’ve bought: publisher, product and edition, licence type (subscription or perpetual), quantity, purchase date and proof of purchase, and any agreement number. Most SMEs don’t have one, which is exactly why audits hurt. When you can produce entitlement evidence on demand, an audit becomes an afternoon’s work instead of a crisis. This sits inside broader IT asset management, the same discipline that tracks your hardware, warranties and end-of-life dates.

Reconcile assigned versus purchased seats

For Microsoft 365, the Microsoft 365 admin centre tells you exactly how many licences you’ve purchased against how many are assigned. Under Billing > Licences, you see each product, the seats you’re paying for and the seats in use. Reconciling this regularly catches both problems at once: seats assigned beyond what you’ve bought (a compliance gap) and seats you’re paying for that nobody uses (wasted spend). Do it monthly and neither surprise builds up.

Right-size unused licences

This is where compliance work actually saves money. The same register that protects you in an audit usually reveals seats you’re paying for and not using: the staff member who left three months ago whose Microsoft 365 and Adobe licences are still billing, the premium plan assigned to someone who needs the basic one, the perpetual product everyone forgot they retired. Reclaiming those licences, or cancelling them at renewal, frequently funds the cost of the housekeeping. Compliance and cost control are the same job done properly.

Understand subscription versus perpetual

The two licensing models carry different risks, and most environments are now a mix of both.

SubscriptionPerpetual
What you’re paying forThe right to use the software for a set term (monthly/annual)The right to use a specific version indefinitely, bought once
ExamplesMicrosoft 365, Adobe Creative Cloud, Autodesk subscriptionsOlder Office perpetual, on-prem Windows/SQL Server, legacy Acrobat
Compliance riskOver-assigning seats; the vendor can see live usageRunning more installs or versions than the licence allows; CALs untracked
If you stop payingThe software stops workingYou keep using the version you own, but get no updates or support

Autodesk and Adobe have moved almost entirely to subscription. Microsoft offers both, and a typical Melbourne SME runs Microsoft 365 subscriptions alongside perpetual on-premises Windows Server and its CALs. Knowing which model each product sits under tells you where your audit exposure actually lies.

SaaS sprawl makes this harder

Licence compliance used to mean counting installs on machines you owned. Now most software is bought as a subscription, often on a corporate card by whoever needed it, and the result is SaaS sprawl: dozens of overlapping tools, nobody sure who’s paying for what, and licences quietly renewing for people who left. A law firm in Hawthorn we onboarded was running three separate PDF and e-signature subscriptions across different teams, none fully used. You can’t licence-manage software you don’t know you have. The fix is the same register and the same reconciliation, applied to every subscription.

What to do if you receive an audit or true-up notice

Don’t panic, and don’t ignore it. The worst outcomes come from businesses that either go quiet, hoping it’ll pass, or that rush to admit a gap before they’ve established whether one exists.

  1. Read the agreement first. Find the audit or verification clause being relied on, and check what it actually entitles the vendor to: notice periods, scope and how data is gathered.
  2. Reconcile your own position before you respond. Run the numbers internally, deployments against entitlements, so you walk in knowing where you stand rather than learning it from the vendor. Your licence register is your evidence; don’t volunteer deployment data you haven’t verified.
  3. Bring in your licensing partner. Your reseller or MSP has dealt with these before and can challenge an over-stated gap, identify licences you already hold that the vendor missed, and negotiate the commercial close rather than accepting the first number.
  4. Treat the deadline as real but not immovable. Reasonable engagement buys time. A measured response almost always lands better than a fire-sale purchase.

Where the MSP and CSP partner fit

Most SMEs don’t buy Microsoft licences direct; they buy through a Cloud Solution Provider (CSP), and that’s usually their MSP. A good CSP partner does more than process the order. They right-size your seats at every renewal, flag when you’ve crossed a threshold like the 300-seat Business cap, keep the licence register current, and stand beside you if an audit ever lands. As a Melbourne MSP founded in 2014 with 13 Australian-employed engineers, TechAssist runs licence reconciliation as part of ongoing Microsoft 365 management, not as a billable scramble when the renewal looms. If you’ve never been sure your setup is right-sized, our Microsoft 365 support covers exactly this housekeeping.

Frequently asked questions

How often do software vendors actually audit small businesses?

Less often than large enterprises, but it does happen, and subscription products are effectively audited continuously because usage data flows back to the vendor automatically. For Microsoft 365 and similar SaaS, the bigger risk isn’t a formal audit but the annual true-up or renewal where over-assigned seats get reconciled at once. Perpetual on-premises software (Windows Server, SQL Server, older Office and Adobe) is where traditional formal audits are still most likely.

What’s the difference between a true-up and a fine?

A true-up is the routine process of paying for extra licences you deployed during the year under a volume agreement, no penalty, just the cost of the seats. A fine or penalty comes from an audit that finds you running software with no valid licence at all, where you may pay back-charges, list-price licences and potentially the vendor’s costs. The first is housekeeping; the second is what good housekeeping prevents.

Do we still need CALs if we’re moving to the cloud?

If you still run any on-premises Windows Server or SQL Server, yes, those CALs remain a live obligation regardless of how much else has moved to the cloud. Once a workload is fully migrated to a cloud service like Microsoft 365 or Azure, the CAL requirement for that service usually falls away, because the licensing is built into the subscription. The trap is a hybrid setup where the old server still runs and everyone assumes the cloud move dealt with the licensing. It didn’t.

Getting ahead of it

Software licence compliance is far cheaper to maintain than to fix under audit pressure. A current licence register, a monthly reconciliation in the Microsoft 365 admin centre, and a CSP partner who right-sizes at renewal will keep you compliant and usually trim your spend. If you’re not confident what you own versus what you’re running, that’s worth sorting before a true-up letter forces the issue. Get in touch with our team and we’ll audit your licensing before a vendor does.

SaaS sprawl is the uncontrolled spread of software-as-a-service subscriptions across a business — the dozens of cloud apps staff sign up for that nobody centrally tracks, approves or pays for through one channel. Most Melbourne SMEs we audit are running 30 to 60 of them, and the finance team can account for fewer than half.

The problem is rarely one big bill. It is a hundred small ones, plus a security exposure nobody is watching. This post explains how sprawl happens, what it actually costs you, and how to run a proper audit — using the tools you already own in Microsoft 365 — so you can see every app, kill the duplicates and put a gate on the front door.

What SaaS sprawl is and how it happens

SaaS sprawl is what you get when buying software becomes frictionless. A decade ago, new software meant a purchase order, an install and an IT ticket. Now any staff member with a corporate card and an email address can have a new tool running before lunch. That convenience is genuinely useful — and it is exactly why the count gets out of hand.

It accumulates through a few predictable channels:

  • Departments self-provisioning. Marketing signs up for Canva, a scheduling tool and three analytics platforms. Sales buys its own CRM add-ons. Each decision is reasonable in isolation; nobody sees the total.
  • Individuals on cards. One person expenses a $15-a-month transcription app, another a PDF editor, another a project board. They are small enough to slip through expense approval without a second look.
  • Free trials that convert. A trial gets set up for a one-off task, the card is entered to “unlock the export”, and twelve months later it is still billing because nobody cancelled it.
  • Duplicate tools. Three teams solve the same problem three different ways — you end up paying for two file-sharing platforms, two e-signature tools and a video conferencing app you already get free with Microsoft 365.

None of this is anyone behaving badly. It is the natural drift of a business where buying software is easier than asking permission.

What it actually costs you

The wasted subscription spend is the obvious cost, and it is real — paying twice for the same capability, paying for seats that left with departed staff, paying for trials that quietly converted. But the spend is usually the smallest part of the bill.

Security risk from unmanaged apps

Every app a staff member connects to your data is a door into it. When someone signs in to a third-party tool “with Microsoft” or “with Google”, they often grant that app standing permission to read mail, files or contacts — an OAuth grant that persists long after they have forgotten the app exists. You cannot defend what you cannot see, and an unmanaged app sitting on a live token to your SharePoint is exactly the kind of thing the Australian Cyber Security Centre (ACSC) warns about in its cloud guidance.

Orphaned accounts and offboarding gaps

This is the one that bites hardest. When a staff member leaves, you disable their Microsoft 365 account — but if they signed up directly to a dozen other tools with their work email and a separate password, those accounts keep working. A former employee can still log in to the marketing platform, the file-sharing app or the customer database weeks after their last day, because that login never touched your central identity. Offboarding is only as complete as your app inventory, and most inventories do not exist.

Data scattered everywhere

Sprawl means your business data ends up spread across systems you do not control and cannot search. Customer details in a trial CRM, contracts in a personal e-signature account, project files in someone’s individual cloud drive. When you need to respond to a privacy request, prove what data you hold, or recover after an incident, you cannot — because you do not know where it all is. Under the Notifiable Data Breaches scheme, “we did not know that app held customer data” is not a defence the Office of the Australian Information Commissioner (OAIC) will accept.

How to run a SaaS audit

You do not need a fancy SaaS-management platform to start. Four sources, cross-referenced, will surface almost everything.

1. Expense and card review

Pull twelve months of card statements and accounts-payable records and flag every recurring software charge. Look specifically for small monthly amounts, USD billing, and anything from a name you do not recognise. Twelve months matters because annual subscriptions only show up once. This is the fastest way to find spend nobody approved.

2. Entra ID enterprise apps and OAuth grants

This is the technical heart of the audit and the bit most businesses skip. In the Microsoft Entra admin centre, the Enterprise applications blade lists every third-party app that has been granted access to your tenant — every “sign in with Microsoft” connection your staff have ever made. Each one shows the permissions it holds and who consented. You will almost certainly find apps nobody can name, with read access to mail or files, that should have been revoked long ago. If you want the wider context on how this identity layer works, we have written a full piece on Microsoft 365 support in Melbourne.

3. Browser and SSO sign-in logs

Entra ID sign-in logs show which applications staff are authenticating to and how often. Cross-reference that against your enterprise apps list. If your business uses a single sign-on portal, its activity log is gold — it tells you what people actually use versus what they signed up for and abandoned. Low or zero usage is your cancellation shortlist.

4. Build a simple inventory

Put it all in one spreadsheet: app name, owner, what data it touches, monthly cost, billing channel, who has access, and whether it uses SSO. That single document is more than most SMEs have ever had, and it becomes the working register for everything that follows.

Rationalising what you find

An audit that produces a list and no decisions is just paperwork. The point is to cut. A construction firm in Box Hill we work with came out of this exercise running 41 SaaS tools; we got them to 23, and roughly $1,900 a month in spend disappeared along the way — before counting the risk we closed off.

Three moves do most of the work:

  • Consolidate onto Microsoft 365 where it already does the job. If you pay for Microsoft 365, you are already paying for video meetings (Teams), file sharing (SharePoint and OneDrive), forms, basic e-signature, task boards and a great deal more. A surprising share of the third-party tools we find are duplicating capability the business already owns. Killing those is free money.
  • Kill the duplicates. Where two tools do the same thing, pick one, migrate, and cancel the other. Two e-signature platforms is one too many.
  • Enforce SSO on what survives. Every retained app that can sit behind Entra ID single sign-on should. That gives you one place to grant access, one place to cut it when someone leaves, and one set of credentials staff are not reinventing weakly across a dozen logins.

Ongoing governance and a procurement gate

Sprawl regrows the moment you stop watching. The fix is not a one-off purge but a light, durable process.

Put a procurement gate on new software: any new SaaS tool gets a quick sign-off that checks whether the business already owns something equivalent, what data the tool will touch, and whether it supports SSO. This does not need to be bureaucratic — a two-minute conversation and a line in the inventory is enough. The aim is simply that no app enters the business completely unseen.

Then review the inventory quarterly: what is unused, what is duplicated, what is up for renewal, and which OAuth grants in Entra ID can be revoked. This is the sort of standing discipline a virtual CIO brings to a business that has no internal IT leadership — turning a chaotic app estate into a managed one.

The security angle: OAuth consent and Conditional Access

Two Microsoft 365 controls do most of the heavy lifting on the security side of sprawl.

App consent settings. By default, many tenants let any user grant a third-party app access to their own data. Tightening this so that risky permissions require admin approval stops the next unvetted app from quietly attaching itself to your tenant. It is a single configuration change with a large payoff, and it is one of the first things we set on a managed tenant.

Conditional Access. Policies that require a managed device or block legacy authentication shrink the ways a leaked credential or rogue app can be abused. Identity is the perimeter now, and Conditional Access is where you enforce it — we cover the detail in our guide to Conditional Access policies in Microsoft 365. Together with tightened app consent, these controls mean sprawl stops being a free-for-all and starts being something you govern.

TechAssist is a Melbourne-based MSP, founded in 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. SaaS rationalisation and Entra ID hardening are standard work for our managed clients — and because we bill per user at a fixed monthly rate, this kind of clean-up is in scope rather than a surprise project invoice.

Frequently asked questions

How many SaaS apps does a typical small business actually use?

More than they think. Across Melbourne SMEs we audit, 30 to 60 distinct cloud applications is common, and the finance team can usually account for fewer than half because so many are bought on individual cards and through free trials that converted.

Can I find shadow apps without buying special software?

Yes. The Entra ID enterprise applications list and sign-in logs, cross-referenced against twelve months of card and accounts-payable records, will surface the overwhelming majority. Dedicated SaaS-management platforms add automation and continuous discovery, but you can run a thorough first audit with the tools you already own.

What is the single biggest risk from SaaS sprawl?

Offboarding gaps. When staff sign up to tools directly with a separate password, disabling their Microsoft 365 account does not close those accounts. A departed employee retaining access to a customer database or file-sharing app weeks after leaving is the exposure we see most, and it is invisible without an inventory.

How do I stop sprawl coming back after an audit?

A procurement gate plus a quarterly review. New tools get a quick sign-off that checks for existing capability and SSO support; every quarter you re-check the inventory for unused, duplicated and renewing apps and revoke stale OAuth grants in Entra ID. The process is light, but it has to be standing.

Talk to us about your app estate

If you have no idea how many SaaS tools your business is running — or what they can see — that is the normal starting point, not an embarrassing one. Our managed IT services team can run the audit, rationalise the estate onto Microsoft 365 where it makes sense, and put governance around what is left. Get in touch and we will tell you plainly what we find.

The right to disconnect lets employees refuse to monitor, read or respond to work contact outside their working hours unless that refusal is unreasonable. It is Fair Work law, not an IT rule. But the email, Teams and mobile settings your MSP controls are what turn a policy on paper into something that actually holds.

What the right to disconnect actually says

The right to disconnect was added to the Fair Work Act and took effect on 26 August 2024 for medium and larger employers. For small business employers (fewer than 15 employees), it commenced a year later, on 26 August 2025. So as of now, it applies across the board.

The substance is narrow but important. An employee may refuse to monitor, read or respond to contact (or attempted contact) from their employer outside their working hours, unless the refusal is unreasonable. The same applies to contact from a third party — a client, a supplier — if it relates to their work. Whether a refusal is unreasonable depends on factors the legislation spells out: the reason for the contact, how it is made and how disruptive it is, whether the employee is compensated for being available, the employee’s role and level of responsibility, and their personal circumstances including family or caring responsibilities.

Note what it does not say. It is not a ban on after-hours contact. An employer can still send a message at 9pm. What changes is that the employee is generally entitled not to engage with it until they are back on the clock, and they cannot be punished for that. Disputes are meant to be worked out at the workplace first, and if that fails, the Fair Work Commission can deal with them.

This is workplace-relations law, and the genuinely hard questions — what counts as “working hours” for a salaried manager, how an on-call allowance is structured, what your enterprise agreement or award says — are HR and legal questions. Get advice on those. What we deal with as a Melbourne MSP is the layer underneath: the systems that decide whether a notification lands on someone’s phone at all, and whether your roster and monitoring arrangements line up with what you have told staff.

The IT controls that make a policy real

A right to disconnect policy that says “please don’t email after hours” and changes nothing in Microsoft 365 is theatre. Staff still hear the buzz, still feel the pull, and the more conscientious ones still answer. The controls below are the ones that actually shift behaviour, and most of them are already sitting in your tenant waiting to be turned on.

Quiet hours and scheduled send in Outlook and Teams

Microsoft Teams has a built-in quiet hours and quiet days feature in the mobile app, so notifications are silenced outside the hours a user sets. The catch is that it is per-user and opt-in by default — most people never find it. The fix is to make it part of standard onboarding and to actually show people where the setting lives, rather than burying it in a policy PDF.

On the sending side, Outlook’s scheduled send (Delay Delivery) lets a manager who genuinely does their thinking at 10pm queue the email to land at 8am. That one habit removes most of the after-hours pressure without anyone having to ignore anything. We usually pair it with a short signature line on out-of-hours senders — something like “I work flexible hours; I don’t expect a reply outside yours” — which the Fair Work Ombudsman’s own guidance points to as good practice.

If you want notifications properly switched off rather than left to each person, that is configurable through Microsoft 365 administration and device policy. This is part of the day-to-day work in any managed Microsoft 365 environment, and it is the kind of thing worth getting right once across the whole organisation rather than user by user.

Mobile device management and conditional access

The real after-hours leak is the phone. Work email and Teams on a personal mobile means contact follows people into the lounge room. Mobile device management (through Microsoft Intune) and conditional access policies give you proper levers here.

You can enforce app protection so work data stays inside managed apps, and you can use conditional access to shape when and how people connect. For specific roles — not everyone — you can even restrict access to corporate apps to particular hours or locations, so that someone who is genuinely off the roster is not technically able to be pulled back in. Used carefully, this turns a written rule into an enforced boundary. Used clumsily, it locks out the on-call engineer at 2am, so it has to be designed around your actual roster rather than applied with a blunt instrument.

A professional services firm in Hawthorn we work with had the opposite problem to most: their junior staff were answering partner emails at all hours because the Teams app pinged their personal phones and nobody had told them they didn’t have to. The remedy was not a stern memo. It was switching most of the team to managed app access with notifications off outside business hours, leaving a small after-hours group properly resourced, and writing the policy to match what the systems now did.

On-call rosters and the compensation question

The right to disconnect bites hardest where there is no clear on-call arrangement. If you expect certain people to be reachable after hours, that should be a defined roster with an allowance or overtime attached — not a vague cultural expectation that everyone is always on. The legislation explicitly weighs whether the employee is compensated for being available when judging if a refusal is unreasonable.

From the IT side, that means your access controls and notification rules should mirror the roster. The on-call person this week gets the alerts and the access; everyone else doesn’t. We run our own 24/7 NOC out of Tecoma on exactly this model, with a defined roster and the tooling configured so the engineers who are off are genuinely off. The technology and the employment arrangement have to agree with each other, or one of them is lying.

Monitoring, alerts and overtime creep

System monitoring is where this gets subtle. Automated alerts from a server, a backup job or a security tool are not “the employer contacting you” in the Fair Work sense — they are machines. But if a human is expected to act on those alerts after hours, that expectation is exactly what the right to disconnect is about, and it should be rostered and paid like any other on-call duty.

The practical move is to route after-hours monitoring to whoever is actually on call, not to a whole team’s inboxes. Alert fatigue and silent unpaid overtime usually come from the same root cause: everyone gets every alert, so everyone feels vaguely responsible at all hours. Tightening alert routing is both better security operations and a cleaner employment boundary. This is core to how a managed security operations capability should be run regardless of the legislation.

Writing a policy your systems can back up

The order of operations matters. Plenty of businesses write the policy first, then discover their systems don’t support it. Do it the other way around: decide what the systems will enforce, then write a policy that describes that reality.

A workable right to disconnect policy generally covers:

  • Working hours by role — what they are, and who, if anyone, is on a defined after-hours roster.
  • Contact expectations — that staff are not expected to respond outside their hours, and won’t be penalised for not doing so.
  • The genuine exceptions — emergencies, the on-call roster, and how those people are compensated.
  • The tools — quiet hours, scheduled send, managed notifications — and that the business has configured them, not just recommended them.
  • How to raise a concern — the internal process before anything goes near the Fair Work Commission.

The wording and the workplace-relations judgement calls belong with your HR adviser or employment lawyer. The Fair Work Ombudsman publishes plain-English guidance on the right to disconnect that is a sensible starting point for that conversation. Our job is the other half: making sure the tenant settings, device policies and alerting genuinely do what the document claims. When we take on a new client we treat this as part of the broader managed IT baseline, alongside the security and identity controls that touch the same systems.

Frequently asked questions

Does the right to disconnect ban after-hours emails?

No. Employers can still send messages outside working hours. What the law changes is that employees are generally entitled not to monitor or respond to them until they are back at work, and they can’t be disadvantaged for that — unless their refusal is unreasonable in the circumstances. Scheduled send is the easy way to avoid the issue entirely.

Does it apply to my small business?

Yes. The right to disconnect commenced on 26 August 2024 for employers with 15 or more employees and on 26 August 2025 for small business employers under 15 staff. Both dates have now passed, so it applies regardless of size.

Can IT settings actually enforce this?

To a large degree, yes. Quiet hours in Teams, managed-app notifications through Intune, and conditional access policies can stop most after-hours pings reaching staff who aren’t on call. They can’t make legal judgements about what’s reasonable, but they remove the temptation and the pressure that cause the problem in the first place.

What about our on-call engineers and after-hours support?

Genuine on-call work is fine — it just needs to be a defined roster with proper compensation, and your access and alert routing should match it so only the on-call person is pinged. The law specifically considers whether someone is paid for being available when deciding if declining contact is reasonable.

Is this a security or a compliance issue?

It is primarily a workplace-relations issue, so the policy and any disputes are HR and legal territory. But the controls that make it work — identity, device management, conditional access, alert routing — are the same ones that underpin your security posture, which is why it tends to land on the IT plate.

Where TechAssist fits

We’re a Melbourne MSP, founded in 2014, with 13 Australian-employed engineers — no offshore call centre — and we run this kind of configuration work across professional services, construction, manufacturing and healthcare clients every week. The right to disconnect is one of those rules where the legal text is short but the implementation lives entirely in settings most businesses have never opened.

If you want your Microsoft 365 tenant, mobile device policies and after-hours alerting set up so they actually back the policy you’re putting in writing, get in touch. We’ll handle the IT half; pair it with your HR adviser for the rest.

Azure costs for Melbourne SMEs grow 30 to 50% a year without anyone noticing. Enterprise FinOps assumes a $5 million cloud spend; this is the SME version, sized for the $50k to $500k reality. Eight quick wins, governance guardrails that stick, and the three traps that catch almost every business.

Why SME Azure spend creeps

It is rarely one decision. A pilot tenant becomes a production tenant. A test virtual machine becomes a forgotten orphan with a 1 TB premium SSD attached. Defender for Cloud gets enabled on a free trial, ends up on the Standard tier across every subscription, and nobody can find the off switch by the time the invoice arrives. The dev environment that was ‘just for two weeks’ is still running 18 months later because no one wants to be the person who turned it off.

We see the same pattern across our managed clients. A business signs up for Azure at $3,000 a month. Two years later it is $11,000 a month, the workloads have not materially expanded, and the CFO is asking the right question for the first time. By then the answer is harder than it would have been at $4,000.

FinOps as a published discipline (the FinOps Foundation maintains the framework, Microsoft has published its own opinionated version) assumes you have a cloud platform team, a financial analyst, and an executive sponsor. For a 60-staff Melbourne business with a quarter-million-dollar Azure footprint, that is overkill. The lite version below takes the parts of FinOps that apply at SME scale and ignores the rest. We have run this with clients across professional services in the CBD, manufacturers out around Dandenong, and not-for-profits across the eastern suburbs as part of our Melbourne cloud services work.

What ‘normal’ SME Azure spend looks like

Some benchmarks from our managed book, useful as sanity checks on whether your number is in the right zone.

Workload profileTypical monthly Azure spendSpend per user per month
30-staff professional services, M365-heavy, light IaaS$2,500 – $4,500$80 – $150
60-staff hybrid, file server + 4 to 6 LOB VMs in Azure$5,500 – $9,500$90 – $160
100-staff with line-of-business SQL workloads in Azure$11,000 – $19,000$110 – $190
120-staff manufacturer with ERP, AVD, and DR replication$18,000 – $28,000$150 – $230

If your number is materially above the band for your profile, there is almost certainly waste. If your number is materially below, either you are doing something genuinely clever or you have under-provisioned somewhere that will cause a production incident later.

The eight quick wins

Most SMEs can take 20 to 35% off their Azure bill in a fortnight of focused work, without changing anything about what the business does. The targets in order of effort-to-saving ratio:

1. Rightsize the virtual machines

The Azure Advisor and the Azure Migrate tools both flag VMs running well below their provisioned capacity. The reality is most SMEs have two or three D8s_v5 instances that were sized off a panicked guess at the start of a migration and have been running at 8% CPU ever since. Moving them down two or three sizes typically saves 60 to 75% of the per-VM cost. Validate with seven days of metrics first; do not just take Advisor’s word for it.

One client of ours – a 55-staff engineering consultancy in South Melbourne – was running their file server VM as a D16s_v5 because the original migration consultant ‘matched the on-prem CPU count.’ Seven days of metrics showed 4% average CPU. Rightsizing to a D2s_v5 saved $720 a month with zero user-visible impact.

2. Kill the orphaned disks

Every time someone deletes a VM through the portal, the OS disk and any data disks survive unless deletion was explicitly chosen. Over a few years, an SME tenant will accumulate 20 to 60 orphaned managed disks, often premium SSDs at $0.15 per GB-month. A 1 TB orphaned premium disk is $150 a month for storing absolutely nothing useful.

Run a quick KQL query in Azure Resource Graph to find disks where ManagedBy is empty. Validate that none of them are being held intentionally (some teams keep a disk for a few months as a ‘soft delete’ before truly removing it), then delete the rest. Easy win, usually $400 to $1,200 a month.

3. Reserved instances or savings plans for the steady-state workloads

Anything that runs 24/7 in steady state – production servers, domain controllers, a SQL VM, a file server – is paying full pay-as-you-go pricing by default. A one-year Reserved Instance is roughly 30% cheaper; three years is closer to 50%. The Azure Savings Plan for compute is more flexible (it covers any VM family in any region for the commitment amount) but a slightly lower discount.

The decision rule we use: if the workload is going to run for at least the next 12 months as-is, take the one-year reservation. If it might move, resize, or change family within that window, take the savings plan. Three-year commitments only for genuinely static workloads.

4. Auto-shutdown for dev and test

Dev and test VMs do not need to run on weeknights or weekends. A standard Azure Automation runbook or the built-in Azure DevTest Labs auto-shutdown can cut a non-production VM bill by 65 to 75%. The cost is two hours of configuration and a 30-second wake-up delay when someone needs the box at 7am Monday. We have yet to meet a dev team that genuinely objected once the saving was shown.

5. Azure Hybrid Benefit

If you have Windows Server or SQL Server licences with active Software Assurance, the Azure Hybrid Benefit lets you bring those licences to Azure VMs and stop paying the per-hour Windows or SQL surcharge. The saving on a Windows Server VM is typically 40%; on a SQL VM it can be 60 to 75%. Almost every SME with Software Assurance is leaving this on the table because nobody enabled the toggle at deployment.

Check your existing fleet through Cost Management. Filter by ‘Windows’ or ‘SQL Server’ as a meter category. Anything not marked as Azure Hybrid Benefit is overpaying.

6. Archive cold storage

Storage account blobs default to the Hot tier. Anything older than 30 days that you have not touched should be in Cool ($0.0152 per GB-month versus $0.0184 for Hot) or, for compliance archives, the Archive tier ($0.00099 per GB-month). Lifecycle policies on the storage account do this automatically.

For a healthcare client of ours in Box Hill with a 14 TB compliance archive, moving the long-tail blobs from Hot to Archive saved about $230 a month. A small number per month but a clean, automated saving that compounds as the archive grows.

7. Kill unused public IPs

A standard static public IP is roughly $4.50 a month. Trivial individually, but most SMEs have 15 to 40 of them, half of which are unattached from their original VM or load balancer. Run an Azure Resource Graph query for public IPs with no associated resource, validate, delete.

8. Review egress

Outbound data transfer (egress) from Azure to the internet is roughly $0.087 per GB after the first 100 GB free per month. Backup tools that pull data out of Azure, a misconfigured replication target that goes through public endpoints rather than peering, a video conferencing recording archive that streams out to a local NAS – all of these can quietly produce $400 to $1,500 a month in egress charges that nobody knows about.

The fix is usually a routing change (route the traffic through a private endpoint or service endpoint) or a topology change (move the target into Azure rather than pulling the data out). The win is identifying the source first; Cost Management broken down by Meter Subcategory shows you where the egress lives.

The governance guardrails that actually stick

Quick wins are easy. Stopping the spend from creeping back up over the next 12 months is the hard part. The lightweight controls we recommend for SMEs – the parts of the textbook that work at this scale:

Subscription-level budgets and alerts

One budget per subscription, set to the monthly run rate plus 15%, with alerts at 80%, 100%, and 120%. The alerts should go to a real person (the CFO and the IT lead), not a shared mailbox. The 80% alert is the one that catches the problem before it becomes a quarterly variance discussion.

Do not bother with budgets at the resource group level for an SME; the maintenance overhead is not worth the precision. The subscription is the right granularity.

Tagging that the team will actually do

Enterprise FinOps documents will tell you to enforce 14 mandatory tags. The team will rebel. For SME purposes, three tags are enough: Environment (Prod / Dev / Test), CostCentre (or Department), and Owner (a person, not a generic mailbox). Enforce them with Azure Policy at subscription creation time so any new resource without the three tags is blocked.

Three tags get used. Fourteen tags get ignored, and then nothing gets used.

Quarterly cost review

One hour every three months. The IT lead and the CFO sit down with Cost Management, look at the trend, look at the top ten cost drivers, look at the variance against budget, and decide whether to act. That is the entire process. The output is a one-page note for the leadership team and a list of remediation actions for the next quarter.

This is the rhythm we run with our managed clients. It is also the rhythm where most of the savings actually surface, because it forces someone to look at the data on a cadence that catches problems while they are small.

The three traps

Three patterns catch almost every SME on Azure. Worth understanding them before they catch you.

Trap 1: Lift-and-shift over-provisioning

The most expensive single mistake we see. A business migrates 12 servers from VMware to Azure and tells the migration partner to ‘match the existing VM sizes.’ The existing on-premises VMs were sized for peak load that occurs maybe twice a year, on hardware that was bought five years ago. The Azure VMs run hot for two hours a quarter and idle the other 99% of the time, but are billed at peak capacity every hour. Add up across 12 VMs and you are paying three times what the workload needs.

The fix is to size for Azure metrics, not on-prem habits. Migrate first, then watch the metrics for two to four weeks, then rightsize aggressively. We have done this exercise often enough now that we build the rightsizing step into the migration plan from the start. If the migration partner does not include a post-migration optimisation phase, that is a warning sign.

Trap 2: The dev environment that became production

A developer or contractor spins up a dev environment to test a workload. The business comes to rely on it. Three years later it is processing real production data on a ‘temporary’ subscription with no monitoring, no backup, no DR, and no reserved instances. It is also costing twice what it should because no one ever optimised it.

The fix is governance at the subscription creation step. No new subscription without a documented owner and an explicit lifecycle (this is a permanent prod subscription, or this is a 90-day project subscription with an automatic shutdown date). Cleaning up after the fact is harder than preventing it.

Trap 3: Defender for Cloud tier sprawl

Defender for Cloud is genuinely good, and the Standard tier offerings (Defender for Servers, Defender for SQL, Defender for Storage, Defender for Containers, Defender for App Service, and so on) protect real attack surfaces. The trap is that they bill per resource and the tiers are enabled per subscription. Click the wrong toggle and you have Defender for Servers Plan 2 running on every VM across every subscription for $24 each per month.

We have seen SMEs paying $4,000 a month for Defender coverage when their actual security need would be served by $800 of targeted enablement. The fix is to choose the plans deliberately, enable per subscription, and review quarterly. Defender for Servers Plan 2 on the workloads that need it; off everywhere else. Defender for Storage on accounts with sensitive data; off on the public assets bucket. The protections matter; the indiscriminate enablement does not.

For the security-side conversation about what to leave on, our Melbourne cyber security services page outlines the decisions we apply on the managed side. Cost and security are the same conversation in Azure; you cannot optimise one without involving the other.

What the FinOps tooling landscape looks like for SMEs

The third-party FinOps tools (CloudHealth, Cloudability, Apptio Cloudability, Flexera) are excellent but enterprise-priced. For an SME at $50k to $500k annual Azure spend, the native Azure tooling is enough:

ToolWhat it doesSME relevance
Cost Management + BillingCost analysis, budgets, alerts, exportsEssential. Use weekly.
Azure AdvisorRightsizing, reserved instance, idle resource recommendationsEssential. Review monthly.
Azure Resource GraphKQL queries across resources, perfect for orphan huntsUseful. Quarterly.
Microsoft Cost Management Power BI appPre-built dashboards over Cost Management exportsNice to have for the CFO.
Microsoft FinOps Toolkit (open source)Bicep templates, KQL queries, automation runbooksUseful if you have someone technical to deploy it.

If your spend grows past $1 million a year, the third-party tools become defensible. Below that, the native tooling is fine and the discipline matters more than the platform.

A small-business worked example

A 65-staff manufacturing business in Bayswater came to us in late 2025 with an Azure bill of $14,800 per month and a CFO who could not get a straight answer about why. Two weeks of focused work:

  • Rightsized seven over-provisioned VMs, saving $2,100 per month
  • Deleted 23 orphaned premium disks, saving $1,400 per month
  • Applied Azure Hybrid Benefit to 12 Windows VMs (they had Software Assurance through their CSP and no one had enabled the toggle), saving $1,800 per month
  • Switched the steady-state production workloads to one-year savings plans, saving $1,200 per month
  • Set up auto-shutdown on the dev and test environments, saving $600 per month
  • Identified and re-routed an egress problem through a private endpoint, saving $400 per month
  • Trimmed Defender for Cloud tier coverage to the workloads that actually needed Plan 2, saving $700 per month

Total monthly saving: $8,200, or about 55% of the original bill. The new run rate of $6,600 per month is a defensible number for the workload, with no production impact and no reduction in security posture (in fact a more deliberate one). Subscription budgets, three-tag enforcement, and quarterly review cadence are now in place. The job took us about 70 hours across two engineers from our 13-strong Melbourne team and was delivered alongside the regular per-user fixed monthly managed IT engagement.

FinOps and the broader cloud strategy

Cost optimisation is one strand of a wider conversation about whether the cloud architecture is right for the business. Sometimes the answer to a high bill is to optimise; sometimes it is to redesign. A 24/7 SQL workload that processes a fixed batch overnight may be better suited to Azure SQL serverless or even a scheduled VM. A file server that nobody touches for three months at a time might belong in Azure Files cool tier with a small AVD presence on demand. These are not quick wins; they are architecture changes. But once the quick wins are taken, the conversation moves to design.

For Melbourne SMEs that want a second opinion on whether the architecture is right before committing to another year of the existing spend, we run cloud architecture reviews as a discrete piece of work, separate from ongoing managed services. They are useful at the 12-month mark of any non-trivial Azure deployment. Reach us through the contact page if that is the conversation you need.

Frequently Asked Questions

Should we move away from Azure to save money?

Almost never the right answer for a workload that is already in Azure. Egress fees on a full re-platform are punishing, the operational disruption is real, and the cost difference between Azure, AWS and GCP for SME-typical workloads is usually under 15% once both are properly optimised. Optimise what you have before considering a move. The exception is a workload that genuinely fits a different platform’s primitives better (a heavy GCP BigQuery analytics workload, for example).

How often should we revisit our reserved instance commitments?

At the renewal point and at any major workload change. The Azure Savings Plan is more flexible than the older Reserved Instances because it does not lock you to a VM family; if your workloads shift, the savings plan keeps applying. We typically recommend a mix: reservations for the most stable workloads (domain controllers, file servers, the SQL VM that has run unchanged for three years), savings plans for the rest.

What does FinOps mean for our cloud backup and DR spend?

Backup storage tends to live outside the day-to-day cost conversation and grows quietly. Same principles apply: tier the storage (most backup data can live in cool or archive after 30 days), review retention against actual recovery needs, and watch the egress when you do a restore. Our companion piece on backup and disaster recovery for Melbourne businesses goes deeper on the design decisions.

Do we need a dedicated FinOps person?

Not at SME scale. The work is two to four hours a month for an experienced engineer plus a quarterly review with the CFO. We run it as part of the managed engagement for clients on our per-user fixed monthly pricing model. Hiring a dedicated FinOps person is a sensible move at around $2 to $3 million annual cloud spend, not before.

Will the optimisation work introduce risk to production?

It can if it is done carelessly. The discipline is: validate against metrics before any resize, take a backup before any storage change, do the work in a maintenance window, and have a rollback path. We have done hundreds of these exercises with our MSP Melbourne clients without a production incident, but the process matters. A weekend cowboy resize of a production SQL VM is how you cause an incident.

What is the role of the CFO in cloud cost management?

The CFO owns the budget and the variance conversation; the IT lead and the MSP own the technical optimisation. The quarterly review is the meeting where those two functions talk to each other. Most SME cost creep we see comes from a lack of that conversation rather than from any technical failure.

Network segmentation gets explained as a zero-trust enterprise project with microsegmentation and identity-aware proxies. That framing scares SMEs off, which is a shame. A 30-person Melbourne business can segment its network usefully in a weekend with a UniFi stack and four VLANs. The hard part is sequencing the work so each step reduces real risk.

This guide is the practical version. We will walk through the minimum-viable segmentation that actually reduces lateral movement risk for an Australian SME, the priority order (guest Wi-Fi first, because it is the cheapest win and stops half the dumb risks), where SMEs over-engineer and waste budget, a sample VLAN and firewall rule pack you can adapt, and the trap of segmenting your network without doing the identity work alongside it.

TechAssist has been deploying these stacks for Melbourne SMEs since we were founded in 2014. Our cybersecurity services Melbourne team treats segmentation as one of the highest-leverage controls available to a small business. It is not the most exciting work, but it is the work that means a phished receptionist credential does not become a domain-wide ransomware incident.

What Network Segmentation Actually Is

Segmentation is the practice of dividing your network into separate zones so that a device or user in one zone cannot freely communicate with devices in another zone. Each zone is governed by firewall rules that say what traffic is permitted between it and other zones.

The simplest example: your guest Wi-Fi should not be able to talk to your office laptops. Your office laptops should not be able to talk to your CCTV cameras. Your CCTV cameras should not be able to talk to your phone system. Your phone system should not be able to talk to anything except the SIP provider. If you implement those four rules, you have already done most of the segmentation work that meaningfully reduces risk.

The reason segmentation matters is lateral movement. Modern ransomware does not just encrypt the machine it lands on. It enumerates the local network, finds open shares, weak credentials, and unpatched services on other devices, and spreads. A flat network gives the attacker the entire estate. A segmented network gives them one VLAN.

This is not zero trust, despite what some vendors will tell you. It is the perimeter approach with internal perimeters added. Zero trust is the next step beyond segmentation, where every connection is authenticated and authorised regardless of zone. Read our zero trust security model explained guide for that broader picture. For most SMEs, getting segmentation right is the prerequisite, and the right place to stop for now.

The Minimum Four VLANs for a Melbourne SME

If you run a 15-to-100-person business and you want a segmentation design that actually reduces risk without becoming a multi-month project, run four VLANs. We deploy this exact pattern several times a quarter across our client base.

VLANPurposeDevicesTypical IP range
10 – CorporateStaff workstations, servers, file sharesLaptops, desktops, NAS, on-prem servers, Office 365-connected devices10.10.10.0/24
20 – GuestVisitor internet onlyVisitor phones, contractor laptops, guest tablets10.10.20.0/24
30 – IoT and AVSmart devices, AV gear, CCTV, printersPrinters, cameras, smart TVs, AV controllers, Sonos, smart whiteboards10.10.30.0/24
40 – VoiceSIP phones and gatewaysDesk phones, IP-PBX, SIP gateways10.10.40.0/24

Four VLANs sound trivial. The reason it is enough for most SMEs is that each one represents a meaningfully different risk profile. Guest devices are unmanaged and untrusted. IoT devices are notoriously badly patched and run weird firmware. Voice devices have their own QoS needs and should not be exposed to general office traffic. Corporate is the only zone where managed, patched, and authenticated devices live.

If you have a meaningfully different workload, like a manufacturing floor with PLCs, an OT environment, or a clinical environment with medical devices, add a fifth VLAN for that. Do not collapse it into the IoT VLAN. The blast radius if it gets compromised is too different.

Priority Order: Guest WiFi First

The single highest-leverage step you can take is splitting guest Wi-Fi from corporate Wi-Fi. It is cheap, it is fast, and it removes the most common dumb risk: a visitor’s compromised phone or a contractor’s malware-laden laptop pivoting onto your file server because they got the office Wi-Fi password.

The order we deploy in for a typical Melbourne SME segmentation engagement is as follows.

Week one. Guest Wi-Fi on its own VLAN with a captive portal, time-limited credentials, and a firewall rule that permits internet egress only. No access to internal subnets. This alone removes about 40 percent of the lateral movement risk for a typical SME.

Week two. Voice VLAN. Move the SIP phones onto their own VLAN, lock egress to your SIP provider’s IP range only, and prioritise QoS. This stops a compromised phone from talking to anything except the SIP provider and improves call quality at the same time.

Week three. IoT and AV VLAN. Move printers, cameras, smart TVs, AV gear, and any other unmanaged device onto its own VLAN. Permit only the management traffic the corporate VLAN needs (Bonjour and mDNS reflection for AirPrint, print server traffic, RTSP for camera viewing). Block everything else.

Week four. Corporate VLAN cleanup. Remove anything that should not be on the corporate VLAN, audit static IPs, document the segmentation in a network diagram, and set up monitoring alerts for inter-VLAN traffic that violates the rule set.

That is a four-week project for a typical 30-person Melbourne SME. Most of the cost is engineering time, not hardware. If you are already on UniFi, the hardware is essentially free, and the labour is roughly fifteen to twenty engineer-hours including documentation.

Where SMEs Over-Engineer

Segmentation has a way of attracting over-engineering. Here is what to skip if you are a 30-to-100-person business.

Microsegmentation. This is the practice of giving each workload or application its own segment with policies down to the application port level. It is the right answer for large enterprises with data centres and dozens of regulated workloads. It is not the right answer for a 40-person Melbourne law firm with one practice management system. Microsegmentation tooling costs more than the entire SME’s segmentation budget and adds operational complexity that the IT team cannot maintain.

Per-application firewalls. The pattern where each application has its own next-generation firewall with deep packet inspection rules. Same logic as above. It belongs to the enterprise data centre, not the SME network. For SMEs, a single perimeter firewall with sensible inter-VLAN rules covers the same risk at a fraction of the cost.

Identity-aware proxies for every internal application. Good idea in theory. In practice, deploying ZTNA across every internal app for a 30-person business takes three to six months of integration work, costs tens of thousands in licensing, and leaves the team frustrated. Start with corporate, guest, IoT, and voice segmentation. Then layer identity-aware access onto the two or three highest-value internal applications. Do not try to do all of it at once.

Dedicated SIEM and SOAR. SMEs that try to deploy a SIEM and incident orchestration platform alongside segmentation usually end up with both half-deployed. Use Microsoft Defender for Business or your MSP’s monitoring stack until you genuinely outgrow it. Our managed IT services Melbourne programme includes 24/7 NOC monitoring out of our Tecoma office, which covers what a small SIEM does for a fraction of the cost.

Sample VLAN and Firewall Rule Pack

Here is a sample rule pack that we deploy as a starting point on UniFi, pfSense, or Meraki gear. Adapt the IP ranges to your environment. The rules are written as “from-to: permit/deny.”

SourceDestinationPortsActionReason
Guest VLANAny internal VLANAnyDenyGuests must not touch internal anything.
Guest VLANInternet80, 443, 53PermitWeb and DNS only. No SMB, no RDP, no SMTP.
IoT VLANCorporate VLANAnyDenyIoT devices initiate nothing into corporate.
Corporate VLANIoT VLANPrint, RTSP, mDNSPermitPrint to printers, view cameras, AirPrint.
IoT VLANInternet443, NTPPermitVendor cloud and time sync. Block everything else.
Voice VLANSIP provider IPs5060, RTP rangePermitSIP signalling and media to the provider only.
Voice VLANAny other VLANAnyDenyPhones do not talk to laptops or printers.
Corporate VLANInternetAnyPermit with filteringStandard egress with DNS filtering and TLS inspection.
Corporate VLANVoice VLANHTTPS to PBXPermitAdmin access to PBX from corporate only.
Any VLANManagement VLANAnyDeny except adminNetwork gear management is admin-only.

The thing to notice about this rule pack is how restrictive it is by default. Most SMEs run flat networks where everything can talk to everything. That is the disease. The cure is “deny by default” between VLANs and explicit permits only for the traffic you actually need. If you do not know whether a traffic flow is needed, it is not needed. Add it back if something breaks.

One detail that catches people out: print discovery. Modern printers use mDNS and Bonjour for discovery, which is broadcast-based and does not cross VLAN boundaries by default. You need either an mDNS reflector (UniFi calls it mDNS, Meraki calls it Bonjour Forwarding) configured between corporate and IoT VLANs, or you fix the printers in DNS with static A records and add them as IP-based printers. Both work. We usually prefer the static DNS approach because it is more deterministic.

The Trap: Segmenting Without Identity

This is the trap that costs SMEs more than any other in segmentation projects. You spend a weekend deploying four VLANs, you write a clean rule pack, you feel great, and then a phished user credential turns out to be a domain admin because identity hygiene was never done. The attacker authenticates as a privileged user, traverses your VLAN rules using legitimate credentials, and segmentation buys you nothing.

Segmentation is necessary but not sufficient. You also need identity hygiene. The minimum identity work to do alongside segmentation is as follows.

One. No standing domain admin. Domain admin rights are granted just-in-time, ideally through Privileged Identity Management in Entra ID, or at minimum through a separate dedicated admin account that requires MFA and is not used for email or browsing.

Two. MFA on everything. Not just email. RDP gateways, VPN, the firewall admin interface, the switch management interface, the wireless controller, the file server admin. If a credential gives access to something, that access requires MFA.

Three. Conditional access policies on Entra ID. At a minimum, require MFA for all users, block legacy authentication protocols, and require a compliant device for access to admin roles and high-value applications. This is included in Microsoft 365 Business Premium and is one of the highest-leverage controls available.

Four. Local admin password randomisation. Every Windows endpoint should have a unique, randomised local administrator password managed via LAPS or its modern equivalent in Intune. A consistent local admin password is one of the fastest paths to lateral movement, and most SMEs still have it.

Five. Application control allowlisting on at least the corporate VLAN endpoints. This is the hardest of the Essential Eight to deploy well, but it is also one of the most effective. See our deep dive on application control for the practical playbook.

Without those identity controls, segmentation is theatre. With them, segmentation becomes a meaningful second line of defence.

A Melbourne Example: 38-Person Architecture Practice in Richmond

A 38-person architecture practice in Richmond engaged us in early 2025 after a near-miss incident. A user clicked a phishing link, entered credentials into a fake Microsoft login page, and an attacker logged into their mailbox. The mailbox had access to a shared SharePoint library with five years of client documents, and the attacker started downloading files before MFA challenges (delayed by a policy gap) interrupted them.

The post-incident review showed three problems. First, no conditional access policy requiring MFA on every sign-in. Second, no device compliance check, so the attacker authenticated from an unmanaged device with no resistance. Third, flat network with no segmentation, so if the attacker had pivoted from email to internal systems, nothing would have stopped them.

We deployed in three phases. Phase one was identity hardening: conditional access, device compliance, MFA enforcement, LAPS on the Windows fleet. Phase two was segmentation, exactly the four-VLAN pattern above, with the addition of a fifth VLAN for the Revit project file server because it is high-value and warrants its own zone. Phase three was monitoring: alerting on inter-VLAN traffic that violated rules, alerts on impossible-travel sign-ins, and alerts on download volume anomalies in SharePoint.

Total project cost: just under $34,000 across three months. Total engineer time: 58 hours. Hardware: $4,800 of UniFi gear that replaced a single flat-network router and a consumer-grade access point. They have had zero security incidents in the eighteen months since.

The most important detail: the segmentation work would have been worthless without the identity work that came first. We do not deploy VLANs as a standalone project anymore. Segmentation comes packaged with identity hardening, or it does not come at all.

Hardware Choices: UniFi, Meraki Go, or Meraki Proper

Three tiers cover almost all Melbourne SME deployments. Each has trade-offs.

UniFi from Ubiquiti is the SME favourite for good reason. Hardware is one-time-cost, no recurring licences, the controller is good, and the gear is genuinely capable of handling four-to-six VLANs and the rule pack above. The trade-off is that you (or your MSP) own the operational lift. If the controller falls over, no vendor support phone number rescues you. We deploy UniFi for clients with an MSP relationship in place, because the MSP carries the operational responsibility.

Meraki Go is the entry-level cloud-managed option from Cisco. It is easy to set up, has a clean phone app, and is a good fit for businesses under 20 staff who want minimal operational complexity. The trade-off is feature ceiling. Once you want VLAN-aware DHCP scopes, more than basic firewall rules, or advanced visibility, you hit the ceiling. We tend to deploy Meraki Go for businesses we do not co-manage.

Meraki proper (the full Cisco Meraki dashboard) is the right answer for SMEs with serious compliance ambitions or with multi-site setups. The licensing cost is real (typically $80-$200 per device per year), but the cloud management, deep visibility, and reliability are excellent. We deploy this for clients in regulated sectors and for clients with three or more sites where central management saves enough engineer time to pay for itself.

None of these is the wrong answer. The right answer depends on whether you have an MSP, your compliance trajectory, and how much operational lift you want to carry yourself. Our MSP Melbourne team scopes the hardware decision as part of the segmentation engagement so the gear matches the operating model.

Monitoring: How You Know Segmentation Is Working

Deploying segmentation and not monitoring it is half the job. You need to know when a rule is being violated, when a device is in the wrong VLAN, and when traffic patterns indicate something abnormal.

The minimum monitoring set for an SME deployment:

Alert on denied inter-VLAN traffic above a threshold. A few denied packets are normal background noise. A sustained pattern of denied traffic from one IoT device trying to talk to a corporate file share is a signal worth investigating.

Alert on new devices in any VLAN. Especially the corporate VLAN. If an unknown MAC address suddenly appears, you want to know.

Alert on devices moving between VLANs. This should almost never happen during normal operations. If a device hops from IoT to corporate, something is misconfigured or, worse, someone is poking at the network.

Alert on rule changes. The firewall rule pack is now a security control. Changes to it should be logged, ideally reviewed, and definitely not made silently.

Our 24/7 NOC out of Tecoma handles this monitoring for our managed clients. We respond to P1 incidents in under 15 minutes and are on-site across Melbourne metro within the same business day when something needs hands on gear. For clients running their own ops with our co-managed IT support model, we share the monitoring with the internal team and escalate when thresholds are crossed.

How This Fits With Essential Eight and ISO 27001

Segmentation is not explicitly an Essential Eight strategy, but it is referenced under several of them and is foundational to a Maturity Level Two posture. Restricting administrative privileges, restricting Microsoft Office macros, and application control all become more enforceable when segmentation has limited the blast radius of any single compromised endpoint.

For ISO 27001, segmentation falls under Annex A.13 (Communications Security) and contributes evidence for several other controls. We do not certify clients (we are ISO 27001 capable, not a certifying body), but we have helped a number of Melbourne SMEs pass certification audits, and segmentation always shows up positively in the auditor’s review.

For Privacy Act obligations, segmentation reduces the population of data potentially affected in a breach, which can change the calculus on notifiable data breach decisions. See our Privacy Act for SMBs guide for the data handling context.

What This Costs for a Typical Melbourne SME

The all-in cost for a 30-to-50-person SME segmentation engagement, including identity hardening and ongoing monitoring, breaks down roughly as follows.

Line itemCost (AUD)Notes
Network hardware (UniFi)$5,000 – $8,000Gateway, switches, access points for one site.
Segmentation engineering$6,000 – $9,00040-60 hours including documentation.
Identity hardening (CA policies, MFA, LAPS)$4,000 – $6,000One-off, assumes Microsoft 365 Business Premium in place.
Documentation and handover$1,500Network diagrams, rule pack, runbook.
Ongoing monitoring (per user per month)From per-user fixed monthly pricingPart of TechAssist managed service.

Total project cost typically lands between 20 and 30 thousand dollars depending on existing hardware, site complexity, and how much identity work is needed alongside the segmentation. The ongoing monitoring sits inside our per-user fixed monthly managed service pricing, so there is no surprise on the operational side.

Compared to the cost of a single ransomware incident (we covered this in another article and the realistic number for an SME is between $150,000 and $400,000 including downtime and customer churn), the segmentation project pays for itself if it prevents one incident. The maths is usually obvious in the boardroom.

Frequently Asked Questions

Can I do segmentation myself with a consumer router?

No. Consumer routers do not support meaningful VLAN tagging, and the firewall capabilities are not granular enough to write the kind of rule pack that makes segmentation worth doing. You need at minimum a small-business gateway like a UniFi Cloud Gateway, a Meraki Go GX, or an equivalent. The hardware costs less than a couple of staff laptops, so the price is not the obstacle.

Will segmentation slow down my network?

On modern gear, no. The gateway processes inter-VLAN routing at line rate, and the firewall rules add microseconds of latency, not milliseconds. The only place we see performance issues is when an SME tries to deploy deep packet inspection and TLS interception on undersized hardware. If you size the gateway correctly for your throughput, segmentation is invisible to users.

Do I need separate physical switches for each VLAN?

No. VLANs are logical, not physical. One managed switch handles all four VLANs at once, tagging traffic on the uplink to the gateway. The only reason to use physically separate switches is for an OT or industrial environment with very strict isolation requirements, and that is not most SMEs.

What about working from home: do segmentation rules apply on the VPN?

This is the part that gets missed. If your remote workers VPN in and land in the corporate VLAN by default, your segmentation has a hole. The fix is either a separate VPN VLAN with its own rule set, or, better, moving away from VPN entirely and using Entra ID conditional access with device compliance checks for application access. The latter is the modern approach and avoids the VPN-as-trust-domain problem entirely.

How often should the rule pack be reviewed?

Quarterly at minimum, and after any significant change to the application stack. We review rule packs as part of our managed client quarterly business reviews, and we use those reviews to remove rules that are no longer needed (which is more common than adding new ones).

What if a vendor needs access to one of my internal systems?

Vendor access should land in a dedicated vendor-access zone with explicit rules to the specific systems they need. Do not give vendors guest Wi-Fi credentials and ask them to VPN. Do not give them corporate Wi-Fi access. A dedicated zone with explicit permissions, ideally with MFA and time-bound credentials, is the right pattern.

How do I get started?

The honest first step is an assessment. We will look at your existing network, your endpoint fleet, your identity setup, and your compliance trajectory, and we will give you a sequenced plan. We do this for Melbourne clients regularly out of both our Tecoma office and our 575 Bourke St CBD office. Reach the team via the contact page and we will sort out a discovery session.

Most SME IT is unconsciously designed for the median 35 to 45-year-old user. That median user does not exist alone in the modern workplace, where four generations work alongside each other with very different expectations of technology. This is a Sunday read about designing IT that serves all your staff, not just the comfortable middle.

The four-generation reality

Walk into a typical Melbourne SME today and you will find a 22-year-old graduate, a 38-year-old manager, a 52-year-old senior operator, and a 64-year-old founder or long-tenured staff member all working in the same office. They use the same Microsoft 365 tenant, the same Wi-Fi, and the same helpdesk. They have completely different mental models of how technology is supposed to work, and most SME IT environments accidentally privilege one of those mental models over the others.

Since founding TechAssist in 2014, we have onboarded hundreds of SMEs and watched the generational mix shift through every one of them. The pattern in 2026 looks like this:

GenerationBirth years2026 age rangeTypical share of SME workforce
Gen Z1997-201214-2920-30%
Millennial1981-199630-4540-50%
Gen X1965-198046-6120-30%
Boomer1946-196462-805-15%

For a 60-staff Brunswick design agency we manage, the split is roughly 28% Gen Z, 52% Millennial, 16% Gen X, and 4% Boomer (the founder and one long-tenured operations director). For a 90-staff manufacturing business in Bayswater, the same split is 8% Gen Z, 31% Millennial, 44% Gen X, and 17% Boomer. Same Microsoft 365 tenant, completely different IT delivery requirements.

What each generation actually expects

These are generalisations, and individuals vary wildly within every group. They are still useful generalisations because the average matters when you are designing a helpdesk channel mix or a default permission set.

Gen Z

Gen Z grew up with iPads, Discord, TikTok, and friction-free consumer tech. Their reference point for ‘good software’ is whatever app they used last on their phone. Their expectations:

  • Chat-first communication; phone calls feel intrusive
  • Self-service everything; if there is a form, they will not fill it in
  • Search-driven discovery rather than menu navigation
  • Zero tolerance for slow interfaces or multi-step authentication friction
  • Limited muscle memory for keyboard shortcuts or file system organisation
  • Strong assumption that anything they need will be Googleable or YouTube-able

What this means in practice: Gen Z staff bounce off old-fashioned ticket portals, do not read documentation, and will quietly use a personal Notion or a personal ChatGPT account rather than ask IT for help. The risk is shadow IT and data leakage, not refusal to use tools.

Millennial

The bulk of most SME workforces. Grew up with the internet as it commercialised, formed their work habits with email and Slack, and have generally adapted to whatever tech their workplace put in front of them. Their expectations:

  • Self-serve when possible, but happy to raise a ticket when needed
  • Comfortable with both chat and email; tolerant of phone if the situation calls for it
  • Strong adoption of new tools when the value is clear
  • Reasonable security hygiene if it has been trained
  • Power users of collaboration tools (Teams, SharePoint, project management)

Most SME IT is implicitly designed for this group. They are easy. They are also the group most likely to get over-prioritised because they make up the largest share of the helpdesk inbound.

Gen X

Gen X formed their work habits in the late 1990s and early 2000s, in the transition from paper to digital. They are often the most productive group with established workflows, and they are often the silent shadow IT contributors because they have been carrying habits from old systems forward for two decades. Their expectations:

  • Get the job done; do not care about new shiny tools unless they obviously help
  • Email-first, with chat as a tolerated overlay
  • Strong file system mental model; may struggle with SharePoint’s metadata-first approach
  • Quietly use personal Dropbox, Evernote, or other tools they brought with them from a previous job
  • Will phone the helpdesk if email is taking too long

The shadow IT pattern in this generation is the biggest hidden risk in most SMEs. It is rarely malicious. It is almost always ‘I have been doing it this way since 2008 and nobody told me to stop’.

Boomer

Often the founder, often a director, often the most experienced person in the room with the strongest informal authority. Their expectations:

  • Phone or in-person support, preferably from someone they know by name
  • Email as the dominant communication channel
  • Reluctance to adopt new tools without strong evidence of value
  • Trust-based rather than process-based interaction with IT
  • Will phone the helpdesk for a captcha that has stumped them, and will be frustrated if the helpdesk does not pick up immediately

The Boomer cohort is often the smallest by headcount and the largest by IT influence per person. A board member who cannot get into Teams before a meeting will create more helpdesk pressure in five minutes than 20 Millennials in a week.

Helpdesk channel design for a four-generation workplace

The default modern helpdesk is a ticket portal plus a chat channel, optimised for self-service. This works for Gen Z (chat) and Millennials (either) but actively fails Gen X and Boomers, who often prefer phone or walk-up. The solution is not to abandon chat; it is to offer all four channels with deliberate routing.

ChannelBest forSLA expectationWatch for
Chat (Teams or web)Gen Z, Millennials, quick questionsFirst response under 2 minutesConversation sprawl; need clear closure
Email or ticket portalMillennials, Gen X, non-urgent issuesFirst response under 30 minutesEmail gets buried; ticket portal feels formal
PhoneGen X (urgent), Boomers, P1 issuesPick up under 30 secondsRequires a real human; voicemail is failure
Walk-up or on-siteBoomers, complex hardware issues, executivesSame business day for Melbourne metroRequires actual on-site presence

Running all four channels properly is expensive if you do it yourself with a small internal team. It is one of the practical reasons SMEs move to an MSP arrangement. Our 13 Australian engineers cover all four channels from our 24/7 NOC in Tecoma and our 575 Bourke Street CBD office, with a contractual sub-15-minute P1 response and same-business-day on-site response across Melbourne metro. That coverage model is hard to replicate with internal staff under about 8 IT FTEs, which is well beyond most SMEs.

Training that does not condescend

The single fastest way to lose generational goodwill in IT training is to pitch every session at the lowest common denominator. A 24-year-old Gen Z staff member sitting through ‘how to attach a file to an email’ becomes a future shadow IT user because they have learned that IT is not where help comes from. A 64-year-old Boomer thrown into a fast-paced ‘we will assume you know Slack’ onboarding becomes a future helpdesk regular because they did not catch up.

Tiered training

The model that works in SMEs is tiered training with self-selection. Offer three tiers of every major training session: foundational (assumes no prior knowledge), standard (assumes baseline comfort with the tool category), and advanced (assumes daily use, focuses on power features). Let staff self-select.

Almost everyone correctly self-assesses. The exception is a small subset of Gen X and Boomer staff who under-select out of pride and then struggle. The fix is a gentle 1:1 follow-up two weeks later: “How is the new system going? Is there anything you would like a walkthrough on?”

Avoid the metaphor trap

Training that leans on ‘this is like an old filing cabinet’ or ‘this is like sending a letter’ lands badly with Gen Z, who have never used either. Training that uses TikTok metaphors lands badly with Boomers, who have never used TikTok. The safest training language is concrete and operational: “Click here, then here, this is what happens, this is how to undo it.” Skip the metaphors entirely.

Documentation that respects time

Documentation needs to exist in two forms: searchable short-form (Notion pages, SharePoint articles, KB entries) for Gen Z and Millennials, and printable PDF or single-page reference sheets for Gen X and Boomers who learn by reading offline. The same content, different formats. The cost of producing both is modest. The cost of having only one is a generation that does not engage with documentation.

Default-deny vs default-allow assumptions

Modern security thinking, and the zero trust security model in particular, is default-deny. Nothing works unless it has been explicitly allowed. This is the right approach from a security perspective. It is also the approach that generates the most generational friction.

Gen Z and Millennials, raised on consumer apps that just work, find default-deny baffling: “Why can I not just install this thing? It is free.” Gen X and Boomers, raised on workplaces where IT controlled everything, find default-deny familiar but resent the friction when they are trying to do their actual job.

The path through this is not to compromise on default-deny. It is to invest in the user experience around it.

  • Make exception requests easy. A two-click ‘request this app’ button beats a five-field ticket form every time.
  • Publish a list of pre-approved tools clearly visible to staff. Most exception requests are for tools that would have been approved if the staff member had known.
  • Communicate decisions back. “Your request for Tool X was approved/denied because Y” closes the loop and trains future requests.
  • Treat the catalogue of approved tools as living. Add to it monthly. Staff who see the catalogue growing will treat exception requests as legitimate, not as a fight.

This is the practical application layer of application control, which is the hardest Essential Eight strategy to implement well. It is also the area where generational expectations matter most, because Gen Z will go around the control if the friction is too high.

The ‘tech buddy’ pairing model

One of the highest-leverage interventions we have seen in SMEs is the formal tech buddy model. Every new starter is paired with a tenured staff member from a different generation as their day-to-day go-to for small tech questions. The tech buddy is not IT; they are someone who already knows how the business uses the tools.

Why it works

  • Reduces helpdesk inbound for small questions (estimated 12-25% reduction in our deployments)
  • Creates cross-generational relationships in a way that other onboarding rarely does
  • Surfaces shadow IT habits early, before they become entrenched
  • Distributes IT literacy across the workforce instead of concentrating it

How to set it up

Pair new Gen Z starters with a Millennial or Gen X buddy who can model how the business actually uses tools. Pair new Boomer or Gen X starters with a Millennial buddy who can explain the modern collaboration patterns. The asymmetry is deliberate. The cross-generational pairing is where the learning happens.

For a Richmond marketing agency we manage, the introduction of the tech buddy model coincided with a 19% reduction in ‘how do I do X’ helpdesk tickets in the following quarter. The remaining tickets were genuinely harder problems that needed an engineer rather than a peer.

Specific design choices that help

Authentication friction

MFA is non-negotiable for any modern SME. The friction of MFA falls most heavily on Boomers, who are most likely to forget to bring their phone, lose their authenticator, or be confused by a passwordless prompt. Mitigations:

  • Use Microsoft Authenticator passwordless or Windows Hello for Business as the default, not SMS codes
  • Set up FIDO2 security keys (Yubikey) for users who repeatedly struggle with mobile MFA
  • Conditional access policies that reduce MFA prompts on managed devices within the trusted network
  • A clear and well-staffed account recovery process for the inevitable ‘I have lost my phone’ moment

Communication channels

Do not collapse all internal communication to Slack or Teams chat. The over-collapse of channels privileges Gen Z and disadvantages everyone else. Keep email viable for substantive communication, keep Teams or Slack for quick coordination, and keep phone open for urgent or sensitive conversations. Generational comfort follows the channel.

Device choice

Gen Z and many Millennials prefer Apple hardware for personal use and increasingly for work. Gen X and Boomers are typically Windows-fluent and find macOS unfamiliar. Standardising on Windows for cost and management reasons is the right call for most SMEs (and aligns with our endpoint policy recommendations), but be explicit about it and explain why. Treating Mac requests as unreasonable rather than as a legitimate preference creates a generational rift.

The Boomer founder problem

Worth a section of its own because it is so common in Melbourne SMEs. The founder, often Boomer or older Gen X, has built the business over 20 to 40 years. They use technology pragmatically but have not personally driven a tech refresh in five years. They are often the bottleneck for any decision about new tools, and they often have the strongest informal control over IT spend.

Two failure modes:

  1. The ‘just make it work like the old one’ instruction. Migrations and modernisations get blocked because the founder cannot accept that new tools will not exactly replicate the old ones. Solution: explicit acknowledgement that the new tool is different, paired with a clear demonstration of what gets better. Avoid ‘training’ the founder; offer to sit with them for an hour and walk through the actual workflows they use.
  2. The ‘I do not need that’ veto. Security investments and modernisations get blocked because the founder personally does not feel the pain. Solution: frame the conversation in terms of business risk rather than personal benefit. The Privacy Act compliance work and the Essential Eight investments protect the business; they are not optional convenience features.

For a Mount Waverley accounting firm we work with, the founder (mid-60s) had been blocking a move from a self-hosted file server to OneDrive and SharePoint for three years. The breakthrough came not from another training session but from a one-hour walk-through where one of our senior engineers sat with him and showed him how his existing daily file workflow would work in the new environment. The migration completed within two months. The block had been about uncertainty, not opposition.

What this means for IT strategy

Designing IT for a multi-generational workplace is not about generational stereotyping. It is about acknowledging that the median user does not exist on their own and that a one-size-fits-all approach excludes more people than it includes. The practical implications:

  • Run multiple support channels in parallel and route deliberately
  • Invest in documentation in multiple formats
  • Treat default-deny security as a UX problem to be solved, not a posture to be defended
  • Pair new starters with cross-generational tech buddies
  • Resist the temptation to over-collapse communication channels
  • Make founder onboarding to new tools a personal walk-through, not a training session

This is the kind of operational design work that sits inside a properly run Melbourne MSP relationship. A good MSP brings the channel mix, the documentation discipline, and the engineering depth to make all of this work. A bad MSP gives you a ticket portal and expects everyone to use it.

If you want to talk through what this looks like for your specific generational mix and business model, get in touch. Every SME is a different blend, and the right IT delivery model depends on the actual blend you have.

Frequently Asked Questions

Are these generational patterns really that consistent?

On the average, yes. On the individual, no. We work with 64-year-old Gen X-borderline staff who out-skill 24-year-old Gen Z staff on technical fluency, and vice versa. The point is not to assume; the point is to design for the variance. If your IT delivery model only works for one generational profile, you are excluding the others.

Should we have generation-specific training tracks?

Skill-specific, yes. Generation-specific, no. Self-selecting tiered training is more dignified and more accurate than tracking people by age. Generation matters as a design input, not as a sorting category.

How do we handle Gen Z staff who refuse to use email?

You will lose this battle if you frame it as compliance. You will win it if you frame it as professional necessity. Most clients, vendors, and regulators still operate on email. Gen Z will use email for those interactions if you explain why and accept that internal communication can happen elsewhere. The compromise is appropriate.

Is the tech buddy model just unpaid IT support?

It is informal peer support, not unpaid IT support. The tech buddy answers small questions (where do I find the project template, how do I share this externally) that would otherwise become helpdesk tickets. They do not troubleshoot hardware failures or security incidents. Make the boundary clear and recognise the buddy’s time in their performance review.

How does multi-generational design intersect with security?

It intersects most heavily in the authentication and access control layers. The same MFA policy that is invisible to a Gen Z user creates daily friction for a Boomer who keeps misplacing their phone. The same default-deny posture that protects the business creates shadow IT pressure in Gen Z. Good security design accounts for both, not just one. This is why our cybersecurity practice spends as much time on user experience as on policy.

What is the single highest-leverage change we could make this quarter?

Introduce or strengthen the tech buddy model for new starters. It is cheap, it builds relationships, and it surfaces shadow IT patterns before they entrench. Most SMEs see meaningful reductions in helpdesk inbound within a quarter, and the cultural benefits outlast the operational ones.

The ‘just one more year’ laptop is the most expensive computer in your business. Once you account for warranty cost, ticket volume, productivity drag, and the security exposure of out-of-support hardware, the five-year-old machine in accounts is costing more than a new one would. Real numbers and a clean decision tree follow.

The honest TCO of a business laptop

Most SMEs assess endpoint refresh by looking at the purchase price. That is the wrong number. The right number is total cost of ownership across the working life of the device, which for a business laptop includes hardware acquisition, extended warranty, helpdesk tickets attributable to the device, productivity loss from slowness or failure, and the security risk premium of running unsupported software.

We have been tracking this data across our managed endpoint base since founding TechAssist in 2014, and the pattern is consistent. A Dell Latitude 5450 or Lenovo ThinkPad T14 purchased today at around $2,200 with a 3-year ProSupport or Premier warranty will deliver, on average:

  • Year 1: 0.8 tickets per device, mostly setup and configuration issues
  • Year 2: 1.4 tickets per device, mostly software and minor performance issues
  • Year 3: 2.1 tickets per device, with the first hardware failures appearing
  • Year 4: 3.6 tickets per device, often a battery or SSD swap, plus rising ‘this thing is slow’ complaints
  • Year 5: 5.8 tickets per device, mostly performance complaints and software compatibility issues

At an average internal cost of $85 per ticket (including the user’s time, not just the helpdesk’s), a year-5 device is costing about $493 in support, plus the productivity hit from a user who is fighting their machine instead of doing their job. That productivity hit is the largest hidden cost, and it is what most SMEs miss when they decide to extend an endpoint refresh cycle.

Windows 11 changes the calculation

Until 2024, the SME endpoint refresh debate was mostly a productivity and support cost conversation. From October 2025, when Windows 10 reached end of support, the conversation became a hard security question. Microsoft will not issue free security patches for Windows 10 after that date. Extended Security Updates (ESU) for SMEs are available but priced to discourage them: USD $61 per device for year one, doubling each year for up to three years, on top of your existing licence costs.

The Windows 11 hardware requirement is the bigger issue. TPM 2.0, Secure Boot, and a compatible CPU are required. Most laptops sold before mid-2018 cannot run Windows 11 at all. Many laptops sold between 2018 and 2020 can technically run it but lag on performance. If you have devices in your fleet older than five years, the choice is no longer ‘replace or repair’, it is ‘replace, pay ESU, or accept the risk of unpatched endpoints’.

For Essential Eight alignment, running out-of-support operating systems fails the Patch Operating Systems control immediately. If you have any aspiration toward cybersecurity maturity or working with clients who require it, this is non-negotiable.

The replace-vs-repair decision tree

For every device in your fleet, the decision tree is:

  1. Is the device Windows 11 compatible? If no, replace. The exceptions are devices that will be repurposed for a non-Windows use case (signage, kiosks, dedicated Linux workstations).
  2. Is the device under warranty? If yes, repair through warranty for hardware failures. If no, move to step 3.
  3. Is the device older than 4 years? If yes, replace rather than repair almost any hardware failure.
  4. What is the failure? Battery and SSD swaps are usually repair-economic up to year 4. Motherboard, screen, or keyboard failures past warranty are almost always replace-economic.
  5. Is the user a heavy use case? Developers, designers, video editors, and finance staff running large models tend to outgrow consumer-grade machines faster. For these users, lean toward earlier replacement.

The single most important question is the first one. Windows 11 compatibility is binary. There is no halfway. A device that cannot run Windows 11 is on borrowed time and every month of extension increases your security exposure.

The 3-year vs 4-year cycle debate

For years, the standard SME refresh cycle was 4 years, often stretched to 5. The recent move by most progressive MSPs has been toward 3 years, and the reasoning is worth understanding.

The case for a 3-year cycle

  • Manufacturer warranties typically cover 3 years out of the box (extending to 4 or 5 adds noticeable cost)
  • Tickets jump significantly from year 3 to year 4 (1.4 to 3.6 in our data)
  • Resale value at 3 years is meaningfully higher than at 4, especially for ThinkPad and Latitude business lines
  • Battery degradation past 36 months affects user productivity even when the device is technically working
  • Operating system and software requirements creep upward; a 3-year-old device is current, a 5-year-old device is fighting Teams

The case for a 4-year cycle

  • Higher capital cost per year averaged out, but lower total spend if devices truly are healthy at year 4
  • Light-use users (front-of-house, occasional office users) often genuinely do not need a refresh at year 3
  • Lease structures often align to 36 or 48 month terms; 48 spreads the cost more

Our recommendation

Run a 3-year cycle for heavy users and a 4-year cycle for light users, with the cohort defined explicitly during procurement, not retrospectively. Mixed cycles within a fleet are fine as long as the policy is documented and the lifecycle dates are tracked.

Lease vs buy in a high-AUD or volatile-AUD environment

The AUD has been volatile against the USD through 2025 and into 2026, and hardware pricing reflects it. Dell, Lenovo, and HP price in USD and adjust Australian list prices on a delayed basis. For an SME refreshing 30+ endpoints, the lease vs buy decision needs revisiting.

FactorBuy outrightLease (DOA, equipment finance)Hardware-as-a-Service (HaaS)
Year-1 cash impactFull capital outlayMonthly paymentMonthly payment, often bundled with support
Tax treatmentDepreciation over effective lifeOperating lease often fully deductibleOperating expense, fully deductible
Refresh disciplineOften deferred past optimal cycleEnforced at lease endEnforced at refresh date
Asset disposalBusiness problemReturned to financierManaged by provider
Best fitCash-rich, low staff growthPredictable growth, capex-averseFast growth, low IT bandwidth

The instant asset writeoff has changed several times over the last few years and remains a moving target through the 2026 federal budget cycle. As at writing, the current rules support certain small business write-offs, but the thresholds and the eligible business turnover bands change frequently. Talk to your accountant before committing to an EOFY hardware purchase based on a write-off assumption.

For a Box Hill accounting firm we work with, 28 staff, the move from a buy-and-stretch model (5-year average device age) to a leased 3-year cycle through a major financier reduced their year-on-year IT support cost by 22% and removed the year-4 productivity drag entirely. The lease cost was higher in nominal monthly terms than the depreciation on the previous model, but the total cost was lower once support and productivity were included.

The ‘one device class, one image’ policy

One of the highest-leverage decisions an SME can make about endpoints has nothing to do with the refresh cycle. It is the decision to standardise on one device class with one operating system image.

What standardisation actually means

One business laptop SKU for everybody who needs a laptop (with a workstation-class SKU for the heavy users who genuinely need it). One desktop SKU for fixed-desk roles. One Windows 11 image, one set of pre-installed applications, one configuration baseline managed through Intune or your MDM of choice.

Why it matters

  • Bulk pricing improves significantly when you buy 10 of one SKU instead of 2 each of five SKUs
  • Spares and loaners are interchangeable, so a broken device can be swapped in 15 minutes
  • Driver and firmware management becomes a single workflow instead of five
  • Support tickets resolve faster because the helpdesk has seen this exact configuration a hundred times
  • Security baselines are testable across the entire fleet

For a Port Melbourne logistics company we manage, the move from a mixed fleet (Dell, Lenovo, HP, a few MacBooks) to a single Lenovo ThinkPad SKU with one image reduced their endpoint ticket volume by 31% in the first year of the new policy. Not because the hardware was better, but because the standardisation killed an entire class of compatibility and driver problems.

Standardisation is also what enables sub-15-minute P1 response. When a director’s laptop dies on the way to a board meeting, our team can dispatch an identically configured loaner from our Tecoma or 575 Bourke Street CBD office, and a same-business-day on-site swap is achievable across Melbourne metro. None of that works if the fleet is heterogeneous.

The EOFY tax timing question

The Australian financial year boundary at 30 June makes endpoint refresh a tax-timing question every year. Should you bring forward purchases to claim depreciation or instant asset write-offs in the current FY? Should you defer to spread cost?

The current state of instant asset write-off

The instant asset write-off has been a moving target since the original $20,000 limit was raised, extended, contracted, and reset multiple times through COVID-era stimulus and subsequent budgets. As at the 2025-26 financial year, the threshold and eligibility rules sit at a different level than they did during the peak stimulus period. Do not rely on this post for current numbers; check with your accountant in the month you are planning to purchase.

The strategic question

Tax timing should be a tiebreaker, not a driver. If you genuinely need to refresh devices, the right time is when the devices need refreshing. Bringing forward a purchase by two months to capture a write-off can be smart. Deferring a needed refresh by six months to align with FY26 is almost never smart, because the support cost and productivity drag of the extra six months exceeds the tax benefit.

Bulk timing

For businesses on a 3-year cycle, batching refreshes once a year (typically May or June, into the new FY) is administratively cleaner than rolling refreshes throughout the year. Procurement is a single negotiation, deployment is a single project, and the depreciation schedule is clean. The downside is that a year-1 cohort all ages out together, but in practice the cohort approach also makes succession planning easier.

What to do with the old devices

Endpoint refresh is not finished until the old devices are properly disposed. Three options, with very different risk profiles.

Resale

Through a refurbisher or platform like Grays. Requires certified data destruction before transfer. Acceptable for devices in good condition with no sensitive role history. Capture the resale value against the new device cost.

Donation

To schools, charities, or community programs. Still requires certified data destruction. Generates goodwill and sometimes a tax deduction. The administrative overhead is non-trivial.

Certified destruction

For devices that held sensitive data, devices that failed, or devices with no resale value. Use a certified e-waste processor with a documented chain of custody. For businesses pursuing ISO 27001 capability or aligned to the Essential Eight, this is the only defensible disposal path for devices that handled regulated data.

For healthcare and legal practices in particular, the data on a returned laptop is the same data that triggered the Privacy Act compliance work. Treat disposal as a data security event, not an asset disposal event. Our healthcare IT practice and legal IT practice both build certified destruction into the refresh workflow as standard.

Putting it all together

A working endpoint refresh policy for a typical Melbourne SME looks like this:

  • 3-year cycle for knowledge workers, 4-year cycle for light users, documented at procurement
  • One device class (e.g. Lenovo ThinkPad T-series or Dell Latitude 5000-series) for all standard knowledge workers
  • One workstation-class SKU (e.g. ThinkPad P-series or Latitude 7000-series) for heavy users
  • Windows 11 Pro, one image, managed through Intune
  • 3-year manufacturer warranty (ProSupport or Premier) bundled at purchase
  • Annual batch refresh, typically May or June
  • Lease structure for businesses with predictable growth or capex sensitivity
  • Certified destruction or platform resale at end of life, with documented chain of custody

This is the kind of policy that lives inside a managed IT services arrangement with per-user fixed monthly pricing, because the MSP carries the refresh planning, the procurement leverage, and the deployment execution. For businesses that prefer to keep procurement in-house, the policy still works; you just need to run it yourselves.

Frequently Asked Questions

How do we handle devices for staff who travel constantly?

Heavy travellers are heavy users by definition; their devices take more wear, drop damage, and battery cycles. Move travellers to the 3-year cohort regardless of seniority, and consider upgrading to a workstation-class device with a longer battery and a heavier-duty chassis. The TCO maths almost always favours the more expensive device for users who live out of a bag.

What about Macs?

Macs have a different lifecycle pattern. Hardware tends to last longer (battery and SSD are the main issues), but macOS support tails off after about 7 years and Apple does not offer extended security updates the way Microsoft does. For Mac-using teams, a 4-year refresh cycle is realistic, and the resale value at 4 years is typically strong enough to materially offset the next purchase.

Are refurbished devices a viable option?

For light-use roles, yes. Certified refurbished business-class devices from a reputable refurbisher with warranty can be a sensible choice for 5% to 15% of a typical fleet, particularly for casual users or temporary staff. We do not recommend refurbs for knowledge workers, finance, or any role that lives on the device 8 hours a day.

What is the policy on bring-your-own-device?

BYOD has security and support cost implications that almost always exceed the savings. For staff who genuinely need it (contractors, casual freelancers, board members), use a managed app model on personal devices with Intune App Protection or similar. For employees, issue a managed device. The exception is mobile phones, where BYOD with corporate app containerisation is the more common pattern.

How does this fit with the rest of our IT strategy?

Endpoint refresh policy is one of the foundational decisions that sits underneath cybersecurity, productivity, and IT support cost. A coherent policy makes everything else easier. An incoherent policy or no policy makes everything else harder. If you are evaluating an MSP, ask them what their default endpoint policy looks like and how they enforce it. The answer tells you a lot about how they run their other operations.

Can we just keep extending the warranty?

Most major manufacturers will extend warranty by 1 or 2 years past the original 3-year term, but the cost ramps quickly and the warranty does not cover battery, productivity, or the security exposure of older hardware. For most SMEs, extending warranty past year 4 is more expensive than refreshing the device. If you want a deeper conversation about the right policy for your business, get in touch; this is the kind of question we work through with clients in onboarding.

If you cannot tell us in 30 seconds how many SaaS subscriptions your business pays for, you have SaaS sprawl. For a typical sub-$10M Australian SME, 5% to 12% of recurring SaaS spend is duplicated, unused, or forgotten. This post walks through a four-step audit you can finish before EOFY.

Why SaaS sprawl is a financial problem, not just an IT one

This is a deliberately financial post. We have a separate piece coming on Shadow IT, which covers the security angle. The audit process below is the one we run when a CFO calls us in May or June and says some version of: “I think we are paying for too much software and I do not really know what we have.” That conversation has happened more times this year than in the previous three combined, and EOFY is the moment to fix it because every subscription you cancel before 30 June reduces your run-rate cost for FY27.

SaaS sprawl is not a security incident, it is a slow leak. It happens because individual product subscriptions are small enough to fall under the discretionary spend threshold of most managers ($50 to $200 a month on a credit card), and big enough collectively to fund another two staff members. For a Hawthorn-based professional services firm we audited recently with 48 staff and around $7.5M revenue, the SaaS bill came to $186,000 a year. After audit, we cut it to $142,000 without removing any meaningful capability. That is one and a half graduate salaries, sitting in software nobody used.

Since founding TechAssist in 2014, we have run this exercise inside our managed IT engagements and as standalone projects. The methodology has stabilised into a four-step process that works for any SME with bookkeeping in Xero or MYOB and an executive willing to make some decisions.

Step 1: Extract the spend data

The first step sounds easy and is usually the hardest. You need a clean, single-source list of every recurring software charge the business has paid for in the last 12 months. Not what the IT register says you have. What the bank account and the credit card statements prove you have.

Pulling data from Xero

For Xero-based businesses, the export workflow is:

  1. Go to Accounting, Reports, Account Transactions
  2. Set the date range to the last 13 months (you want one full year plus the current month for renewal visibility)
  3. Filter by the expense accounts you typically book software to: usually ‘Software Subscriptions’, ‘IT Expenses’, ‘Computer Software’, ‘Cloud Services’, and sometimes ‘Marketing’ for tools that snuck in via that team
  4. Export as CSV

You also need the credit card transaction export, separately, because half the rogue subscriptions are on staff cards and never get coded to a software account. Pull the last 13 months of card statements and grep for any merchant name that looks like a SaaS vendor.

Pulling data from MYOB

For MYOB Business or AccountRight users, the workflow is similar: Reports, Accounts, Find Transactions, filter by account, export to Excel. The chart of accounts in MYOB tends to be messier than Xero in our experience, so you will want to also pull the All Journals report for the period and search the description column for known SaaS vendor names.

The Microsoft 365 admin centre and Google Workspace

Do not forget the platform you are already on. Microsoft 365 and Google Workspace both have a billing section showing all subscriptions, seat counts, and the per-seat price. Pull that as a separate dataset. You will use it later when you check seat utilisation against headcount.

At the end of step 1, you should have a single spreadsheet with columns for: vendor name, total annual spend, monthly spend (if recurring), billing frequency, payment method, charge account, and a blank column for ‘function’ which we fill in next.

Step 2: Deduplicate by function

This is where the audit gets interesting. Most SMEs do not think they have duplicate tools. Almost all of them do. The trick is to categorise every tool by the job it does, and then look for jobs being done twice.

Use a six-category matrix:

CategoryTypical toolsCommon duplication pattern
Collaboration and project managementAsana, Trello, ClickUp, Monday, Notion, JiraTwo or three of these running in parallel across teams
CommunicationsSlack, Teams, Discord, Zoom, Webex, Google MeetTeams paid for as part of M365 plus Slack paid for separately
Development and engineeringGitHub, GitLab, Bitbucket, Jira, Linear, SentryMultiple issue trackers; multiple monitoring tools
Finance and back-officeXero, MYOB, Hubdoc, Dext, DocuSign, Adobe SignTwo e-sign tools; receipt capture tool nobody uses
Marketing and salesHubSpot, Mailchimp, ActiveCampaign, Salesforce, PipedriveMultiple CRMs from different sales eras; multiple email platforms
Niche and line-of-businessIndustry-specific tools (practice management, CAD, EHR)Less duplication, more ‘paid but unused’

For each line in your spreadsheet from step 1, assign a category. Then sort by category and look for duplicates within each category. The patterns we find most often:

  • Three project management tools, because each department picked their own and never standardised
  • Two e-signature platforms (DocuSign for legal, Adobe Sign because it came in Acrobat Pro)
  • Paid Zoom Pro alongside Teams Phone, when nobody actually needs Zoom anymore
  • An old CRM still being paid for after the team migrated to a new one 18 months ago
  • Multiple file-sharing tools (Dropbox, OneDrive, Google Drive, Box) because different teams brought in different ones
  • Two password managers, one of which has six active users out of 40 seats paid

The team in our audit example that kept paying for Trello two years after moving to ClickUp is not an exaggeration. The Trello bill was $18 a user per month for 12 seats, $2,592 a year, billed to the credit card of a manager who left in 2024. Nobody had thought to cancel it because nobody had thought about it at all.

Step 3: Map each tool to a business owner

For every line in your now-deduplicated list, you need a named human who owns the decision to keep, kill, or consolidate. This is the step that breaks the audit at most SMEs, because nobody wants to own a tool nobody uses, and nobody wants to admit they signed up for the thing in the first place.

The ownership conversation

Run this as a structured exercise, not an email thread. Get the leadership team in a room with the spreadsheet on a screen. For each line, the question is: “Who is the business owner of this tool?” If nobody puts their hand up, that is the strongest possible signal that the tool should be killed.

Owners need two responsibilities clearly stated:

  • They authorise the spend
  • They are accountable for whether the business gets value from the tool

For tools that survive ownership assignment, you also want a documented use case (“we use Asana for client project tracking across the consulting team, 18 users”) and a renewal date.

Seat utilisation check

For every tool the business is keeping, pull the actual seat utilisation in the last 30 days. Most SaaS vendors have a ‘last active’ or ‘last login’ field in the admin console. Compare paid seats to actively used seats.

A South Melbourne creative agency we audited had 38 Adobe Creative Cloud licences for 24 people. The previous office manager had set up seats for every staff member because Adobe ran a promotion in 2022. Of the 38 seats, 19 had been used in the prior 90 days. Cutting back to 25 seats (24 plus one buffer) saved $11,800 a year. They had been paying $880 a month for unused creative software for 18 months.

Step 4: Kill, consolidate, keep

The final step is the decision. Every tool in your spreadsheet ends up in one of three buckets.

Kill

Tools with no owner, no use case, or zero seat utilisation. Cancel them before the next renewal. For tools billed monthly, the cancellation is easy. For tools on annual contracts, mark the renewal date in the calendar and set a reminder for 60 days prior.

Watch for cancellation friction. Some SaaS vendors require you to call a sales rep to cancel, especially on enterprise tiers. Budget time for this. Some require 30 or 60 days notice. Read the terms before you assume you can cancel today.

Consolidate

Two tools doing the same job, both with active users. The owner of each tool needs to pick one and migrate. Set a realistic migration timeline (usually 60 to 90 days for a project management tool migration; longer for a CRM) and a hard cancellation date for the loser.

Migration is the step where consolidation projects die. Account for the cost: someone needs to actually do the work, and the loser tool needs to stay paid until the migration completes. Build that into the savings calculation.

Keep

Tools with a clear owner, an active use case, and reasonable seat utilisation. For these, the audit work is rightsizing the seat count and aligning the billing frequency. Annual billing is usually 10% to 20% cheaper than monthly. If you are confident in the keep decision, switch to annual at renewal.

Typical wins for a sub-$10M SME

For Australian SMEs in the $2M to $10M revenue band, we consistently see SaaS audit savings of 5% to 12% of total SaaS spend. The mix typically breaks down like this:

Saving sourceTypical share of total savingExample annual saving (mid-sized SME)
Fully unused tools (kill)35-45%$8,000-$15,000
Duplicate tools (consolidate)25-35%$6,000-$12,000
Over-provisioned seats (rightsizing)20-30%$5,000-$10,000
Monthly to annual billing switch5-10%$1,500-$4,000

For a Cremorne software business we worked with (32 staff, $4.8M revenue, $94,000 annual SaaS spend pre-audit), the savings broke down as $11,200 from killing unused tools, $9,800 from consolidating overlapping tools, $6,400 from rightsizing seats, and $2,100 from billing switches. Total $29,500 a year, 31% reduction. The audit itself took about 14 hours of staff time across three weeks.

The Excel template

The template we use internally has six tabs. You can build your own in an afternoon:

  1. Raw data: CSV exports from Xero or MYOB, pasted as-is, one tab per source
  2. Consolidated list: deduplicated by vendor, with annual spend, monthly spend, billing frequency, category, owner, use case, and decision (kill/consolidate/keep) columns
  3. Seat utilisation: for each kept tool, the paid seats vs active seats vs target seats
  4. Renewal calendar: all renewal dates in date order, colour-coded by criticality
  5. Savings tracker: per-decision annualised saving, with a running total
  6. Action log: what we cancelled, when, what we consolidated, and the realisation date for each saving

The most important tab is the action log. Audits are easy. Execution is hard. Without a tracked action log, half the decisions never get implemented and the savings never land.

Common mistakes during SaaS audits

Not including microservices and add-ons

Many tools are sold as the base product plus per-feature add-ons. HubSpot, Salesforce, Microsoft 365, Adobe Creative Cloud, all have premium add-ons that are often turned on by accident or for a one-off campaign and never turned off. Audit add-ons separately, not just the base product.

Ignoring the implicit licence inside another product

This is the biggest miss. If you are paying for Microsoft 365 Business Premium at $33 per user per month, you already have Teams (voice optional), SharePoint, OneDrive, Exchange, Intune, Defender for Office 365, Azure AD Premium P1, and Power Automate Free. If you are also paying for Slack, Dropbox, a separate identity provider, or a third-party MDM, you are paying twice. Map the included entitlements of your platform tier before assessing the standalone tools.

Forgetting personal credit card subscriptions

If staff expense SaaS through reimbursement, those subscriptions never hit the company card. They live in the expense system. Pull a year of expense claims and search for any vendor name that smells like software.

Treating it as a one-off

SaaS sprawl is a continuous problem. Without a recurring process, you will be back where you started in 18 months. Build a quarterly mini-audit into the finance calendar: every quarter, pull new SaaS charges, check ownership and use case, and add to the central register. This is the kind of governance that comes naturally inside a managed IT services arrangement with per-user fixed monthly pricing, because the MSP has a vested interest in keeping the SaaS register clean.

How this connects to your broader IT environment

A clean SaaS register is a precondition for several other things you probably need to do this year. It feeds directly into your cybersecurity posture, because every SaaS tool is an authentication surface and a data exfiltration risk. It feeds into your Privacy Act compliance, because the 2024 reforms require you to know where personal information lives, and ‘in some SaaS tool nobody can remember the name of’ is no longer acceptable. It also feeds your cloud services strategy, because a deduplicated tool stack is much easier to integrate and govern.

For Essential Eight alignment specifically, the audit is the foundation of the User Application Hardening control. You cannot harden applications you do not know exist.

When to bring in external help

You can run the audit yourself if you have a financially literate operations manager with a few spare hours each week and an executive willing to make decisions. If you do not, or if you suspect the audit will surface uncomfortable conversations about who signed up for what, an external party makes the process faster and less politically charged.

TechAssist runs SaaS audits as a standalone engagement or as part of broader managed IT onboarding. Our team of 13 Australian engineers includes the people who actually know which Microsoft 365 entitlements overlap with which standalone tools, which matters because most of the consolidation savings hide in that overlap. We run audits out of both our Tecoma office and our 575 Bourke Street CBD office, so we can do the workshop in person wherever your team is. If you want to start a conversation, the EOFY window is the right time.

Frequently Asked Questions

How long does a typical SaaS audit take?

For a 30 to 80-staff SME, plan on 12 to 20 hours of work spread over three weeks. The data extraction is the longest single task. The decisions can be made in two or three workshops if leadership is willing to commit time.

Can we just use a SaaS management platform like Vendr or Zylo?

Those tools are excellent for businesses with 200+ staff and SaaS bills over $500,000. For sub-$10M SMEs, the licence cost of the management tool is often higher than the savings it surfaces. Excel and a focused three-week project produce 90% of the result at 10% of the cost.

Should we cancel everything that has zero use, or migrate users first?

Confirm zero use across at least 90 days before cancelling, and notify the listed billing contact (not just the technical contact) before pulling the plug. Some tools are ‘used’ only at month-end or quarter-end and look dormant at other times. A 90-day window catches most of these.

What about free SaaS tools, do they matter for the audit?

From a cost perspective, no. From a security and governance perspective, very much yes. Free tools are where the data leaks happen. That conversation belongs in the Shadow IT review, not the financial audit.

Do we need to involve our MSP in the audit?

If you have one, yes. Your MSP often holds the admin credentials to half the tools you are auditing, knows the seat utilisation in real time, and can execute the cancellations on your behalf. If you run a co-managed IT arrangement, this is the kind of work that should already be part of your quarterly review with the MSP.

When is the right time of year to run the audit?

April or May, to bank the FY27 savings before 30 June. Cancellations made in May reduce your run-rate for FY27 and improve your EBITDA position before EOFY. Audits run in September or October are still valuable, but you have given up a year of savings.

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon — just a clear-eyed look at where you stand and what's possible.