The honest answer to “what does an hour offline cost us?” is: more than you think, and you can work it out in ten minutes. Take the staff who can’t work, multiply by their loaded hourly cost and the hours lost, then add the revenue you didn’t earn and the cost of putting things right. That number is usually a nasty surprise.
Most owners have never run that sum. They have a vague sense that downtime is bad, but no figure to weigh against the cost of preventing it. That gap is exactly why “we’ll fix it when it breaks” feels cheaper than it is. Here’s how to calculate the real cost of downtime for your business, what people leave out, and why a proactive approach almost always wins on the numbers.
The simple formula
You don’t need a consultant or a spreadsheet model to get a defensible figure. Four buckets cover most of it.
- Lost productivity = staff affected x loaded hourly cost x hours down. The people who are sitting idle, or working at half pace, while the system they need is unavailable.
- Lost revenue = sales, billable hours or transactions you couldn’t process during the outage and won’t recover later. Not every business has this; a retailer with the till down clearly does.
- Recovery costs = the after-hours engineering, overtime, expedited hardware, and the catch-up work once you’re back. This is the bit that keeps running after the lights come back on.
- Intangibles = reputation damage, missed deadlines, SLA penalties you owe your own clients, and the goodwill you spend apologising. Hard to price exactly, real all the same.
Add the four together and you have your cost per hour of downtime. The first bucket is the one everyone can calculate, so start there.
Getting “loaded hourly cost” right
A common mistake is to use the raw wage. The figure you want is the loaded cost — salary plus superannuation, payroll tax, leave loading, and overheads like the desk, the laptop and the software licence that person needs to do their job. As a rough rule, loaded cost runs about 1.25 to 1.4 times base salary. Someone on $90,000 isn’t costing you $43 an hour when they’re idle; they’re closer to $55 to $60 once you load it properly. Use the loaded figure or you’ll undercount every time.
A worked example
Let me put real numbers to it. This is a deliberately hypothetical scenario, not a real client and not a statistic — but the assumptions are the kind we see in Melbourne SMEs every week. You should swap in your own figures.
Picture a 30-person professional services firm in Camberwell. Their line-of-business application and shared files go down for half a day — four working hours — because a server failed and there was no quick failover. Assumptions:
- 25 of the 30 staff are completely blocked; the other five can do offline admin.
- Average loaded hourly cost across the affected staff: $60.
- The firm bills time, and roughly $8,000 of billable work for that morning simply can’t be done and largely can’t be clawed back.
- Recovery: an after-hours engineer, a replacement part couriered in, and overtime to catch up — call it $3,500.
| Cost bucket | Calculation | Amount |
|---|
| Lost productivity | 25 staff x $60 x 4 hours | $6,000 |
| Lost revenue | Unrecoverable billable work | $8,000 |
| Recovery costs | After-hours labour, part, overtime | $3,500 |
| Intangibles | Two client deadlines slipped; one annoyed client | Not priced, but real |
| Total (measurable) | | $17,500 |
That’s $17,500 for half a day, before you count the intangibles. Spread the same event across a few times a year and you’re well into five figures of avoidable loss. Run those four lines for your own business with your own headcount and rates — the exercise takes ten minutes and the result tends to change how people think about their IT budget.
The hidden costs people forget
The formula above captures the obvious losses. The ones that quietly inflate the real figure are easy to miss.
- The ramp-back-up tax. Productivity doesn’t snap back to 100% the moment systems return. People spend the next hour re-doing lost work, re-establishing context and clearing the backlog. Add 25 to 50 per cent to your productivity figure for this.
- Cascading effects. If your phone system, payment terminal or booking platform depends on the same internet link or server, one failure takes out several functions at once. The blast radius is usually wider than the thing that broke.
- SLA penalties you owe. If you have your own service-level commitments to clients, an outage can trigger credits or penalties. A logistics firm that misses a delivery window doesn’t just lose that job’s margin.
- Morale and overtime. Staff who lose half a day’s work then stay back to catch up don’t forget it. Chronic instability is a genuine factor in people leaving.
- Reputation. A retailer whose card terminal is down on a Saturday, or a clinic that can’t access patient records, loses trust as well as revenue. You can’t invoice for that, but you pay for it.
Why “fix it when it breaks” is a false economy
Break-fix — paying an hourly rate to fix things only once they fail — looks cheaper on a quiet month because you’re not paying for anything. The problem is what it does to both the frequency and the duration of downtime, which are the two levers that actually drive your cost.
Under break-fix, nobody is watching your systems. A failing disk, a backup that quietly stopped running three weeks ago, a firewall firmware bug — these get discovered when they cause an outage, not before. And when something does break, you’re at the back of the queue: the provider has to be called, has to understand an environment they don’t monitor, has to source parts cold. Your four-hour outage in the example above could easily have been an eight-hour one if the first two hours were spent just working out what failed.
The false economy is comparing the monthly fee of managed IT against zero, when the honest comparison is against the downtime you’ll eat without it. One avoided half-day outage a year often covers the difference.
How proactive managed IT cuts the bill
Good managed IT attacks downtime on two fronts: it makes outages less frequent, and it makes the ones that do happen shorter. Both reduce the hours in your formula.
Monitoring catches problems before they’re outages
Continuous monitoring means a failing drive, a service that’s stopped, or a backup job that didn’t complete raises an alert while it’s still a maintenance task, not an emergency. Most of the outages we prevent are ones the client never knew were coming. That’s the whole point — the cheapest downtime is the kind that never happens.
Redundancy removes single points of failure
A second internet service, a failover server, a clustered firewall — redundancy means one component failing doesn’t stop the business. It costs money, so you apply it where the downtime cost justifies it, which is exactly the calculation above. A business that knows an hour offline costs $4,000 can make a rational call on a $200/month redundant link.
Backups and a tested DR plan shorten recovery
When something does take systems down, the difference between a two-hour recovery and a two-day one is whether your backups work and whether you’ve ever actually tested restoring from them. An untested backup is a guess. We restore from backups on a schedule precisely so the day we need them isn’t the day we find out they were corrupt. A real backup and disaster recovery setup — with a documented, rehearsed DR plan — is what turns a catastrophe into an inconvenience. We go deeper on this in our guide to backup and disaster recovery for Melbourne businesses.
Tying downtime tolerance to RTO and RPO
Once you know what an hour costs, two numbers turn that into a design target. Your recovery time objective (RTO) is how long you can be down before the damage is unacceptable. Your recovery point objective (RPO) is how much data — measured in time — you can afford to lose. A business losing $4,000 an hour can’t tolerate a 24-hour RTO; the maths makes that obvious.
These aren’t abstract IT acronyms — they’re the bridge between your downtime cost and the money you should spend preventing it. Tight RTO and RPO targets cost more to deliver because they need redundancy and faster backups; loose ones are cheaper but expose you to bigger losses. The right answer falls out of the numbers you just calculated. Our explainer on RTO versus RPO walks through how to set them sensibly for each system.
TechAssist is a Melbourne-based MSP, founded in 2014, with 13 Australian-employed engineers and no offshore helpdesk. We run per-user fixed monthly pricing with no hourly billing for in-scope work, and we target sub-15-minute response on critical issues from our 24/7 NOC in Tecoma — because on a P1, every minute is a line in the downtime sum above. If you’d like help working out what an hour offline genuinely costs your business and designing around it, get in touch and we’ll run the numbers with you.
Frequently asked questions
How do I calculate the cost of downtime for my business?
Add four buckets: lost productivity (staff affected x loaded hourly cost x hours down), lost revenue you can’t recover, recovery costs like after-hours engineering and overtime, and intangibles such as reputation and SLA penalties. Sum them for a cost per hour, then multiply by a realistic outage length. Use loaded staff cost — salary plus on-costs and overheads — not the raw wage.
What is loaded hourly cost?
It’s the true cost of an employee per hour, including superannuation, payroll tax, leave entitlements and overheads like their equipment and software, not just their base wage. It usually works out to roughly 1.25 to 1.4 times base salary. Using the loaded figure stops you undercounting your productivity losses.
Is managed IT actually cheaper than break-fix?
Over a realistic period, usually yes — because break-fix ignores the cost of downtime it fails to prevent. Managed IT reduces both how often outages happen and how long they last through monitoring, redundancy and tested backups. One avoided half-day outage a year commonly covers the difference in fees.
How do RTO and RPO relate to downtime cost?
Your downtime cost tells you how much an outage hurts; RTO and RPO turn that into design targets. RTO is how long you can be down, RPO is how much data you can lose. A high hourly cost demands tighter targets, which justify spending on redundancy and faster backups. The numbers should drive the design, not the other way round.
What are the hidden costs of downtime?
The ones people miss include the ramp-back-up time after systems return, cascading effects when one failure takes out several functions, penalties under your own client SLAs, staff morale and overtime, and reputation damage with customers. These often add as much again to the obvious productivity and revenue losses.
For most Australian SMEs in 2026 the honest answer to laptops vs desktops comes down to one question: does the person need to work in more than one place? If yes, buy a business-grade laptop and a dock. If they sit at the same desk every day and never move, a desktop gives you more performance per dollar and a longer life. The nuance is in the edge cases.
The old reasons to buy desktops — far cheaper, far faster, easier to fix — have softened. Laptops have closed the gap on performance, and hybrid work has made portability a default expectation rather than a perk. But desktops haven’t disappeared, and for some roles they’re still the right call. Below is a plain comparison and a role-by-role view, with the Windows 11 and Copilot+ angle that’s now part of every refresh conversation.
The quick comparison
| Factor | Business laptop | Business desktop |
|---|
| Mobility | Built for it — works at the desk, at home, on site | None; tied to one location |
| Performance per dollar | Good, but you pay a premium for the same grunt | Stronger — more CPU, GPU and RAM for the money |
| Upgradeability | Limited; often only RAM/SSD, sometimes soldered | Open case — RAM, storage, GPU, PSU all swappable |
| Repairability | Screen, keyboard and battery are real cost items | Most parts replaceable cheaply and quickly |
| Lifespan | 3–4 years typical before battery and wear bite | 4–6 years; easy to extend with a part or two |
| Dual monitors | Via dock — clean once set up | Native; multiple ports out of the box |
| Security risk | Higher — gets lost or stolen; encryption essential | Lower physical risk; stays on premises |
| Total cost of ownership | Higher hardware + dock, but enables hybrid work | Lower hardware, but no flexibility value |
| Best fit | Field, sales, exec, hybrid, hot-desking | Fixed workstations, CAD, finance, heavy compute |
Prices and configurations shift constantly, so treat that as a framework, not a quote. The hardware sticker is rarely the deciding number anyway — total cost of ownership over four years, including support, downtime and the value of flexibility, is what actually matters.
Mobility and hybrid work
This is the factor that’s reshaped the decision. A few years ago most Melbourne SMEs ran desktops in the office and that was that. Now hybrid is the default for professional services, and a person who can’t pick up their machine and work from home, a client site or the train is a productivity gap waiting to happen. For sales, field and management roles, a laptop isn’t a luxury — it’s the job.
The catch is that buying laptops “because everyone’s hybrid now” without thinking it through wastes money on people who never actually leave their desk. Be honest about who moves and who doesn’t. A reception or warehouse terminal that lives in one spot for five years doesn’t need a portable battery you’ll be replacing in year three.
Performance per dollar and the power users
For the same spend, a desktop still gives you more — more cores, faster GPU, more RAM, and the thermal headroom to sustain it under load. That matters enormously for a narrow band of roles: CAD and 3D work, engineering simulation, video editing, large data sets, anything that pegs a processor for hours. Cram that workload into a thin laptop and it throttles, runs hot and ages fast.
An engineering or architecture practice in Hawthorn running AutoCAD and Revit is a clear desktop case — or at minimum a mobile workstation, which is a different (and pricier) animal to a standard ultrabook. For the bulk of office work, though — Microsoft 365, browsers, video calls, line-of-business apps — a mid-range business laptop has more than enough grunt, and the performance gap is invisible day to day. Don’t pay for desktop horsepower a spreadsheet user will never touch.
Repairability, upgradeability and lifespan
Desktops win cleanly here, and it’s a real cost lever over time. A desktop is a serviceable box: when the storage fills up or the RAM gets tight, you open it and add more. A failed power supply is a cheap, quick swap. That’s why a well-specced desktop comfortably runs four to six years, and you can stretch it further with a single part.
Laptops are tighter. Better business models still let you upgrade RAM and SSD, but many consumer machines solder the RAM, and a cracked screen, worn battery or failed keyboard is a genuine repair bill — sometimes close to the cost of replacement. Plan on three to four years for laptops as a working assumption, and build that shorter cycle into your budgeting rather than being surprised by it.
Docking and dual monitors
The classic objection to laptops — “but my team needs two big screens” — stopped being valid years ago. A decent USB-C or Thunderbolt dock turns a laptop into a full desktop setup in one cable: dual monitors, keyboard, mouse, wired network and power. Staff get the desktop experience at their desk and full portability when they walk away.
Two practical notes. First, standardise on one or two dock models across the fleet — mismatched docks are a quiet, recurring source of support tickets. Second, check the laptop actually drives the displays you want at the resolution and refresh you want; not every USB-C port carries enough bandwidth for two 4K screens. Get that right at purchase and dual-monitor laptop setups are genuinely seamless.
Security: laptops get lost
This is the factor people underrate. A desktop bolted under a desk in your office is, physically, fairly safe. A laptop rides in cars, sits in cafes and gets left on trains. Every portable device is a data-loss event waiting to happen if it isn’t protected, and under the OAIC’s Notifiable Data Breaches scheme, a lost laptop holding client data can be a reportable breach.
The non-negotiable is full-disk encryption — BitLocker on Windows, managed centrally so recovery keys are escrowed and you can prove the device was encrypted if it goes missing. Pair that with a business-grade machine that has a TPM 2.0 chip (which Windows 11 requires anyway), conditional access so a stolen device can’t simply sign in, and remote wipe through Intune. We cover the access side in our guide to conditional access policies in Microsoft 365, and encryption is a baseline control under the Essential Eight. A lost encrypted laptop is an annoyance; a lost unencrypted one is a notifiable breach and a very bad week.
The Windows 11 baseline and Copilot+ PCs
Windows 10 reached end of support in October 2025, so every machine you buy now should be Windows 11 and meet its hardware floor: a supported 64-bit CPU, 4GB+ RAM (realistically 16GB for business use), UEFI with Secure Boot, and TPM 2.0. Any business-grade device from the last few years clears that bar; the trap is cheap consumer stock that quietly doesn’t.
The newer wrinkle is Copilot+ PCs — machines with a neural processing unit (NPU) rated at 40+ TOPS that run certain AI features locally rather than in the cloud. They’re genuinely more efficient and have excellent battery life, but for most SMEs in 2026 the on-device AI features are a nice-to-have, not a reason to pay a premium or rush a refresh. Buy one if it fits the budget and the role; don’t let the marketing drive the whole fleet decision. If you’re weighing the AI productivity case more broadly, our Microsoft 365 support team can give you a straight read on what’s worth paying for.
Business-grade vs consumer kit
This matters more than the laptop-versus-desktop question for most buyers. Consumer machines from a retail shelf look like a bargain until you account for what’s missing: shorter warranties, no next-business-day on-site option, no fleet manageability, weaker build quality, and bundled junkware. Business lines — think the commercial ranges from the major vendors — give you longer warranties, TPM and firmware-level security features, driver stability, and machines you can enrol and manage centrally.
For a managed fleet, manageability is the quiet killer feature. Business devices support zero-touch provisioning through Windows Autopilot, so a new starter’s machine ships, gets unboxed, connects to wifi and configures itself with the right apps and policies — no engineer building it by hand. Consumer kit fights that process every step. The slightly higher upfront cost pays for itself the first time you onboard someone without a site visit.
Buy, lease or Device-as-a-Service
Buying outright is simplest: you own the asset, depreciate it, and there’s no contract. The downside is a lumpy capital cost every refresh cycle and the temptation to run machines years past their use-by date to avoid spending again. That’s how you end up with a fleet of slow, out-of-warranty laptops dragging productivity down.
Leasing or Device-as-a-Service (DaaS) spreads the cost into a predictable monthly figure and usually bundles refresh, warranty and sometimes provisioning into one line. For a growing business that values predictable opex and an automatic refresh cycle, that’s attractive — it forces the hardware discipline that buyers often skip. The trade-off is you’ll pay a little more over the full term, and you don’t own anything at the end. There’s no universally right answer; it depends on your cash flow and how disciplined you are about refreshes on your own.
Standardise the fleet
Whatever you buy, buy few models, not many. A fleet of three standard configurations — say a standard laptop, a power-user laptop and a desktop workstation — is dramatically cheaper to support than fifteen one-off machines bought ad hoc over the years. Standardisation means one set of drivers to test, spare parts that interchange, predictable imaging, and a swap-out that takes minutes instead of a half-day rebuild.
A professional services firm in Camberwell we work with had exactly that problem: every staff member had picked their own machine over five years, so no two were alike and every fault was a fresh investigation. We moved them to two laptop SKUs and one desktop for their finance team, all enrolled through Autopilot and encrypted with BitLocker. Support time dropped, onboarding went from a day to an hour, and their refresh budgeting finally became predictable. The cost saving wasn’t in the hardware — it was in everything around it. That fleet-management discipline is core to how our managed IT services work.
Frequently asked questions
Are desktops still worth buying in 2026?
Yes, for the right roles. Fixed workstations that never move, finance teams on multiple large monitors, and power users running CAD, video or heavy compute all get more performance per dollar and a longer, cheaper-to-maintain life from a desktop. For mobile or hybrid roles, a laptop with a dock is the better call.
How long should a business laptop last?
Plan on three to four years. The battery, hinges and keyboard wear with use, and after four years repair costs and slowdowns usually outweigh keeping the machine. Desktops stretch to four to six years and can be extended with a cheap RAM or SSD upgrade. Build those cycles into your budget rather than running kit until it dies.
Do we really need business-grade machines instead of cheaper consumer ones?
For a managed business fleet, yes. Business lines give you longer warranties, next-business-day on-site options, TPM and firmware security, driver stability, and central manageability through tools like Intune and Autopilot. Consumer machines look cheaper upfront but cost more in support, downtime and shorter usable life.
What’s the most important security control for laptops?
Full-disk encryption — BitLocker, managed centrally so recovery keys are stored safely. A lost or stolen laptop with client data can be a notifiable breach under the OAIC scheme; if it’s encrypted and you can prove it, the exposure is far lower. Pair encryption with conditional access and remote wipe.
Should we lease or buy our hardware?
Buying suits businesses with the capital and the discipline to refresh on schedule. Leasing or Device-as-a-Service suits those who prefer predictable monthly opex and want refresh, warranty and provisioning bundled in. You pay slightly more over the term but avoid lumpy costs and the temptation to run machines too long.
Getting the decision right
The 2026 rule is simple: match the machine to the role, not to a blanket policy. Map who actually moves, who needs raw compute, and who sits in one place all day, then standardise on a small set of business-grade configurations and manage them properly — encrypted, enrolled and on a sensible refresh cycle. That’s where the real savings live, well beyond the sticker price.
TechAssist is a Melbourne-based MSP founded in 2014, with 13 Australian-employed engineers and same-business-day on-site support across the metro — which means we can hand-deliver, swap or fix a machine fast when hardware does fail. If you want a straight recommendation on what to buy for which roles, or a managed fleet that runs itself, get in touch or take a look at our pricing and SLA. No upsell to gear you don’t need.
Software licence compliance means you hold a valid, paid licence for every copy of every program your business runs. A vendor “true-up” or audit is when Microsoft, Adobe, Autodesk or another publisher checks whether what you’ve deployed matches what you’ve bought. Get it wrong and the bill arrives at list price.
What a true-up and an audit actually are
The two terms get used interchangeably, but they’re not the same thing. A true-up is the reconciliation built into a volume licensing agreement. If you signed a Microsoft Enterprise Agreement or similar, you committed to a baseline number of licences and agreed to “true up” annually for anything extra you deployed during the year. It’s routine accounting: you report the additional seats, you pay for them, the agreement rolls on. Where it bites is when nobody has tracked the additions and the annual reconciliation surfaces twelve months of unlicensed growth at once.
An audit is the adversarial version. The vendor, or a third party acting for them, exercises the audit clause in your licensing contract and asks you to prove compliance. They’ll count installs against entitlements and present you with a “compliance gap”. A right to audit is written into almost every software agreement you’ve ever clicked through. Microsoft, Adobe and Autodesk all do it, and so do Oracle, SAP and IBM, who are notoriously aggressive about it.
Why vendors audit
Because it pays. Software is one of the few products where the customer self-reports how much they’re using, and self-reporting drifts. In any business of reasonable size, deployment creeps past entitlement as staff are added, machines are reimaged and VMs are spun up. An audit converts that drift into revenue, usually at full list price with no discount.
The triggers are predictable: a sharp drop in renewal spend, a merger or acquisition, switching away from a vendor’s product, a jump in headcount, or simply the random rotation a publisher runs through its mid-market customers. Subscription licensing has made it easier still: when your software phones home, the vendor already knows who’s using what before they send a letter.
How SMEs end up non-compliant
Almost no one sets out to pirate software. Non-compliance is nearly always sloppiness, not theft, and it accumulates quietly. These are the patterns we see most across Melbourne SMEs.
- Over-deployment. You bought 40 Microsoft 365 licences, you’ve grown to 52 staff, and the extra dozen are using the platform on borrowed credentials or seats that were never purchased. The headcount moved; the licence count didn’t.
- Wrong licence type for the use. Running software licensed for development on a live production server, or using education and not-for-profit pricing in a commercial entity that no longer qualifies.
- Mixing Business and Enterprise plans. Microsoft 365 Business plans (Basic, Standard, Premium) are capped at 300 seats. Plenty of growing firms blow past 300 users still stacking Business licences, when they should have moved to Enterprise (E3/E5) plans.
- Client Access Licences (CALs). On-premises Windows Server and SQL Server still need a CAL for every user or device that connects. CALs are the most commonly under-counted licence in Australian SMEs, because the server “just works” whether or not the paperwork exists.
- Unlicensed virtual machines. Spinning up a new VM from a template often clones a Windows Server or SQL install without anyone buying the licence to cover it.
- Shared accounts. Three people on reception sharing one Adobe Acrobat or Microsoft 365 login. Named-user subscriptions are licensed per person, not per desk, and sharing breaches the terms even though it feels economical.
The real cost of getting it wrong
When a true-up or audit finds a gap, you don’t buy the shortfall at the keen price your reseller would normally quote. You typically pay back-charges for the period you were under-licensed, the licences at full list price, and in audit scenarios potentially penalties or the vendor’s audit costs on top. There’s no negotiating leverage, because you’ve been caught short and the clock is running.
The other cost is the rushed purchase. Faced with a deadline, businesses buy whatever the vendor puts in front of them, at list, often more than they need. A manufacturer in Dandenong we work with discovered during a routine Autodesk reconciliation that several engineering machines were running design software well beyond the seats they’d paid for. The catch-up purchase, under time pressure and at list, cost several times what an orderly renewal would have. The licences were genuinely needed; the panic premium wasn’t.
How to stay compliant
Compliance isn’t a once-a-year scramble. It’s an ongoing discipline, and most of it is unglamorous record-keeping that pays for itself the first time a letter lands.
Maintain a licence register
The foundation is knowing what you own. A licence register is a single, maintained record of every software product you’ve bought: publisher, product and edition, licence type (subscription or perpetual), quantity, purchase date and proof of purchase, and any agreement number. Most SMEs don’t have one, which is exactly why audits hurt. When you can produce entitlement evidence on demand, an audit becomes an afternoon’s work instead of a crisis. This sits inside broader IT asset management, the same discipline that tracks your hardware, warranties and end-of-life dates.
Reconcile assigned versus purchased seats
For Microsoft 365, the Microsoft 365 admin centre tells you exactly how many licences you’ve purchased against how many are assigned. Under Billing > Licences, you see each product, the seats you’re paying for and the seats in use. Reconciling this regularly catches both problems at once: seats assigned beyond what you’ve bought (a compliance gap) and seats you’re paying for that nobody uses (wasted spend). Do it monthly and neither surprise builds up.
Right-size unused licences
This is where compliance work actually saves money. The same register that protects you in an audit usually reveals seats you’re paying for and not using: the staff member who left three months ago whose Microsoft 365 and Adobe licences are still billing, the premium plan assigned to someone who needs the basic one, the perpetual product everyone forgot they retired. Reclaiming those licences, or cancelling them at renewal, frequently funds the cost of the housekeeping. Compliance and cost control are the same job done properly.
Understand subscription versus perpetual
The two licensing models carry different risks, and most environments are now a mix of both.
| Subscription | Perpetual |
|---|
| What you’re paying for | The right to use the software for a set term (monthly/annual) | The right to use a specific version indefinitely, bought once |
| Examples | Microsoft 365, Adobe Creative Cloud, Autodesk subscriptions | Older Office perpetual, on-prem Windows/SQL Server, legacy Acrobat |
| Compliance risk | Over-assigning seats; the vendor can see live usage | Running more installs or versions than the licence allows; CALs untracked |
| If you stop paying | The software stops working | You keep using the version you own, but get no updates or support |
Autodesk and Adobe have moved almost entirely to subscription. Microsoft offers both, and a typical Melbourne SME runs Microsoft 365 subscriptions alongside perpetual on-premises Windows Server and its CALs. Knowing which model each product sits under tells you where your audit exposure actually lies.
SaaS sprawl makes this harder
Licence compliance used to mean counting installs on machines you owned. Now most software is bought as a subscription, often on a corporate card by whoever needed it, and the result is SaaS sprawl: dozens of overlapping tools, nobody sure who’s paying for what, and licences quietly renewing for people who left. A law firm in Hawthorn we onboarded was running three separate PDF and e-signature subscriptions across different teams, none fully used. You can’t licence-manage software you don’t know you have. The fix is the same register and the same reconciliation, applied to every subscription.
What to do if you receive an audit or true-up notice
Don’t panic, and don’t ignore it. The worst outcomes come from businesses that either go quiet, hoping it’ll pass, or that rush to admit a gap before they’ve established whether one exists.
- Read the agreement first. Find the audit or verification clause being relied on, and check what it actually entitles the vendor to: notice periods, scope and how data is gathered.
- Reconcile your own position before you respond. Run the numbers internally, deployments against entitlements, so you walk in knowing where you stand rather than learning it from the vendor. Your licence register is your evidence; don’t volunteer deployment data you haven’t verified.
- Bring in your licensing partner. Your reseller or MSP has dealt with these before and can challenge an over-stated gap, identify licences you already hold that the vendor missed, and negotiate the commercial close rather than accepting the first number.
- Treat the deadline as real but not immovable. Reasonable engagement buys time. A measured response almost always lands better than a fire-sale purchase.
Where the MSP and CSP partner fit
Most SMEs don’t buy Microsoft licences direct; they buy through a Cloud Solution Provider (CSP), and that’s usually their MSP. A good CSP partner does more than process the order. They right-size your seats at every renewal, flag when you’ve crossed a threshold like the 300-seat Business cap, keep the licence register current, and stand beside you if an audit ever lands. As a Melbourne MSP founded in 2014 with 13 Australian-employed engineers, TechAssist runs licence reconciliation as part of ongoing Microsoft 365 management, not as a billable scramble when the renewal looms. If you’ve never been sure your setup is right-sized, our Microsoft 365 support covers exactly this housekeeping.
Frequently asked questions
How often do software vendors actually audit small businesses?
Less often than large enterprises, but it does happen, and subscription products are effectively audited continuously because usage data flows back to the vendor automatically. For Microsoft 365 and similar SaaS, the bigger risk isn’t a formal audit but the annual true-up or renewal where over-assigned seats get reconciled at once. Perpetual on-premises software (Windows Server, SQL Server, older Office and Adobe) is where traditional formal audits are still most likely.
What’s the difference between a true-up and a fine?
A true-up is the routine process of paying for extra licences you deployed during the year under a volume agreement, no penalty, just the cost of the seats. A fine or penalty comes from an audit that finds you running software with no valid licence at all, where you may pay back-charges, list-price licences and potentially the vendor’s costs. The first is housekeeping; the second is what good housekeeping prevents.
Do we still need CALs if we’re moving to the cloud?
If you still run any on-premises Windows Server or SQL Server, yes, those CALs remain a live obligation regardless of how much else has moved to the cloud. Once a workload is fully migrated to a cloud service like Microsoft 365 or Azure, the CAL requirement for that service usually falls away, because the licensing is built into the subscription. The trap is a hybrid setup where the old server still runs and everyone assumes the cloud move dealt with the licensing. It didn’t.
Getting ahead of it
Software licence compliance is far cheaper to maintain than to fix under audit pressure. A current licence register, a monthly reconciliation in the Microsoft 365 admin centre, and a CSP partner who right-sizes at renewal will keep you compliant and usually trim your spend. If you’re not confident what you own versus what you’re running, that’s worth sorting before a true-up letter forces the issue. Get in touch with our team and we’ll audit your licensing before a vendor does.
SaaS sprawl is the uncontrolled spread of software-as-a-service subscriptions across a business — the dozens of cloud apps staff sign up for that nobody centrally tracks, approves or pays for through one channel. Most Melbourne SMEs we audit are running 30 to 60 of them, and the finance team can account for fewer than half.
The problem is rarely one big bill. It is a hundred small ones, plus a security exposure nobody is watching. This post explains how sprawl happens, what it actually costs you, and how to run a proper audit — using the tools you already own in Microsoft 365 — so you can see every app, kill the duplicates and put a gate on the front door.
What SaaS sprawl is and how it happens
SaaS sprawl is what you get when buying software becomes frictionless. A decade ago, new software meant a purchase order, an install and an IT ticket. Now any staff member with a corporate card and an email address can have a new tool running before lunch. That convenience is genuinely useful — and it is exactly why the count gets out of hand.
It accumulates through a few predictable channels:
- Departments self-provisioning. Marketing signs up for Canva, a scheduling tool and three analytics platforms. Sales buys its own CRM add-ons. Each decision is reasonable in isolation; nobody sees the total.
- Individuals on cards. One person expenses a $15-a-month transcription app, another a PDF editor, another a project board. They are small enough to slip through expense approval without a second look.
- Free trials that convert. A trial gets set up for a one-off task, the card is entered to “unlock the export”, and twelve months later it is still billing because nobody cancelled it.
- Duplicate tools. Three teams solve the same problem three different ways — you end up paying for two file-sharing platforms, two e-signature tools and a video conferencing app you already get free with Microsoft 365.
None of this is anyone behaving badly. It is the natural drift of a business where buying software is easier than asking permission.
What it actually costs you
The wasted subscription spend is the obvious cost, and it is real — paying twice for the same capability, paying for seats that left with departed staff, paying for trials that quietly converted. But the spend is usually the smallest part of the bill.
Security risk from unmanaged apps
Every app a staff member connects to your data is a door into it. When someone signs in to a third-party tool “with Microsoft” or “with Google”, they often grant that app standing permission to read mail, files or contacts — an OAuth grant that persists long after they have forgotten the app exists. You cannot defend what you cannot see, and an unmanaged app sitting on a live token to your SharePoint is exactly the kind of thing the Australian Cyber Security Centre (ACSC) warns about in its cloud guidance.
Orphaned accounts and offboarding gaps
This is the one that bites hardest. When a staff member leaves, you disable their Microsoft 365 account — but if they signed up directly to a dozen other tools with their work email and a separate password, those accounts keep working. A former employee can still log in to the marketing platform, the file-sharing app or the customer database weeks after their last day, because that login never touched your central identity. Offboarding is only as complete as your app inventory, and most inventories do not exist.
Data scattered everywhere
Sprawl means your business data ends up spread across systems you do not control and cannot search. Customer details in a trial CRM, contracts in a personal e-signature account, project files in someone’s individual cloud drive. When you need to respond to a privacy request, prove what data you hold, or recover after an incident, you cannot — because you do not know where it all is. Under the Notifiable Data Breaches scheme, “we did not know that app held customer data” is not a defence the Office of the Australian Information Commissioner (OAIC) will accept.
How to run a SaaS audit
You do not need a fancy SaaS-management platform to start. Four sources, cross-referenced, will surface almost everything.
1. Expense and card review
Pull twelve months of card statements and accounts-payable records and flag every recurring software charge. Look specifically for small monthly amounts, USD billing, and anything from a name you do not recognise. Twelve months matters because annual subscriptions only show up once. This is the fastest way to find spend nobody approved.
2. Entra ID enterprise apps and OAuth grants
This is the technical heart of the audit and the bit most businesses skip. In the Microsoft Entra admin centre, the Enterprise applications blade lists every third-party app that has been granted access to your tenant — every “sign in with Microsoft” connection your staff have ever made. Each one shows the permissions it holds and who consented. You will almost certainly find apps nobody can name, with read access to mail or files, that should have been revoked long ago. If you want the wider context on how this identity layer works, we have written a full piece on Microsoft 365 support in Melbourne.
3. Browser and SSO sign-in logs
Entra ID sign-in logs show which applications staff are authenticating to and how often. Cross-reference that against your enterprise apps list. If your business uses a single sign-on portal, its activity log is gold — it tells you what people actually use versus what they signed up for and abandoned. Low or zero usage is your cancellation shortlist.
4. Build a simple inventory
Put it all in one spreadsheet: app name, owner, what data it touches, monthly cost, billing channel, who has access, and whether it uses SSO. That single document is more than most SMEs have ever had, and it becomes the working register for everything that follows.
Rationalising what you find
An audit that produces a list and no decisions is just paperwork. The point is to cut. A construction firm in Box Hill we work with came out of this exercise running 41 SaaS tools; we got them to 23, and roughly $1,900 a month in spend disappeared along the way — before counting the risk we closed off.
Three moves do most of the work:
- Consolidate onto Microsoft 365 where it already does the job. If you pay for Microsoft 365, you are already paying for video meetings (Teams), file sharing (SharePoint and OneDrive), forms, basic e-signature, task boards and a great deal more. A surprising share of the third-party tools we find are duplicating capability the business already owns. Killing those is free money.
- Kill the duplicates. Where two tools do the same thing, pick one, migrate, and cancel the other. Two e-signature platforms is one too many.
- Enforce SSO on what survives. Every retained app that can sit behind Entra ID single sign-on should. That gives you one place to grant access, one place to cut it when someone leaves, and one set of credentials staff are not reinventing weakly across a dozen logins.
Ongoing governance and a procurement gate
Sprawl regrows the moment you stop watching. The fix is not a one-off purge but a light, durable process.
Put a procurement gate on new software: any new SaaS tool gets a quick sign-off that checks whether the business already owns something equivalent, what data the tool will touch, and whether it supports SSO. This does not need to be bureaucratic — a two-minute conversation and a line in the inventory is enough. The aim is simply that no app enters the business completely unseen.
Then review the inventory quarterly: what is unused, what is duplicated, what is up for renewal, and which OAuth grants in Entra ID can be revoked. This is the sort of standing discipline a virtual CIO brings to a business that has no internal IT leadership — turning a chaotic app estate into a managed one.
The security angle: OAuth consent and Conditional Access
Two Microsoft 365 controls do most of the heavy lifting on the security side of sprawl.
App consent settings. By default, many tenants let any user grant a third-party app access to their own data. Tightening this so that risky permissions require admin approval stops the next unvetted app from quietly attaching itself to your tenant. It is a single configuration change with a large payoff, and it is one of the first things we set on a managed tenant.
Conditional Access. Policies that require a managed device or block legacy authentication shrink the ways a leaked credential or rogue app can be abused. Identity is the perimeter now, and Conditional Access is where you enforce it — we cover the detail in our guide to Conditional Access policies in Microsoft 365. Together with tightened app consent, these controls mean sprawl stops being a free-for-all and starts being something you govern.
TechAssist is a Melbourne-based MSP, founded in 2014, with thirteen Australian-employed engineers and a 24/7 NOC in Tecoma. SaaS rationalisation and Entra ID hardening are standard work for our managed clients — and because we bill per user at a fixed monthly rate, this kind of clean-up is in scope rather than a surprise project invoice.
Frequently asked questions
How many SaaS apps does a typical small business actually use?
More than they think. Across Melbourne SMEs we audit, 30 to 60 distinct cloud applications is common, and the finance team can usually account for fewer than half because so many are bought on individual cards and through free trials that converted.
Can I find shadow apps without buying special software?
Yes. The Entra ID enterprise applications list and sign-in logs, cross-referenced against twelve months of card and accounts-payable records, will surface the overwhelming majority. Dedicated SaaS-management platforms add automation and continuous discovery, but you can run a thorough first audit with the tools you already own.
What is the single biggest risk from SaaS sprawl?
Offboarding gaps. When staff sign up to tools directly with a separate password, disabling their Microsoft 365 account does not close those accounts. A departed employee retaining access to a customer database or file-sharing app weeks after leaving is the exposure we see most, and it is invisible without an inventory.
How do I stop sprawl coming back after an audit?
A procurement gate plus a quarterly review. New tools get a quick sign-off that checks for existing capability and SSO support; every quarter you re-check the inventory for unused, duplicated and renewing apps and revoke stale OAuth grants in Entra ID. The process is light, but it has to be standing.
Talk to us about your app estate
If you have no idea how many SaaS tools your business is running — or what they can see — that is the normal starting point, not an embarrassing one. Our managed IT services team can run the audit, rationalise the estate onto Microsoft 365 where it makes sense, and put governance around what is left. Get in touch and we will tell you plainly what we find.
The right to disconnect lets employees refuse to monitor, read or respond to work contact outside their working hours unless that refusal is unreasonable. It is Fair Work law, not an IT rule. But the email, Teams and mobile settings your MSP controls are what turn a policy on paper into something that actually holds.
What the right to disconnect actually says
The right to disconnect was added to the Fair Work Act and took effect on 26 August 2024 for medium and larger employers. For small business employers (fewer than 15 employees), it commenced a year later, on 26 August 2025. So as of now, it applies across the board.
The substance is narrow but important. An employee may refuse to monitor, read or respond to contact (or attempted contact) from their employer outside their working hours, unless the refusal is unreasonable. The same applies to contact from a third party — a client, a supplier — if it relates to their work. Whether a refusal is unreasonable depends on factors the legislation spells out: the reason for the contact, how it is made and how disruptive it is, whether the employee is compensated for being available, the employee’s role and level of responsibility, and their personal circumstances including family or caring responsibilities.
Note what it does not say. It is not a ban on after-hours contact. An employer can still send a message at 9pm. What changes is that the employee is generally entitled not to engage with it until they are back on the clock, and they cannot be punished for that. Disputes are meant to be worked out at the workplace first, and if that fails, the Fair Work Commission can deal with them.
This is workplace-relations law, and the genuinely hard questions — what counts as “working hours” for a salaried manager, how an on-call allowance is structured, what your enterprise agreement or award says — are HR and legal questions. Get advice on those. What we deal with as a Melbourne MSP is the layer underneath: the systems that decide whether a notification lands on someone’s phone at all, and whether your roster and monitoring arrangements line up with what you have told staff.
The IT controls that make a policy real
A right to disconnect policy that says “please don’t email after hours” and changes nothing in Microsoft 365 is theatre. Staff still hear the buzz, still feel the pull, and the more conscientious ones still answer. The controls below are the ones that actually shift behaviour, and most of them are already sitting in your tenant waiting to be turned on.
Quiet hours and scheduled send in Outlook and Teams
Microsoft Teams has a built-in quiet hours and quiet days feature in the mobile app, so notifications are silenced outside the hours a user sets. The catch is that it is per-user and opt-in by default — most people never find it. The fix is to make it part of standard onboarding and to actually show people where the setting lives, rather than burying it in a policy PDF.
On the sending side, Outlook’s scheduled send (Delay Delivery) lets a manager who genuinely does their thinking at 10pm queue the email to land at 8am. That one habit removes most of the after-hours pressure without anyone having to ignore anything. We usually pair it with a short signature line on out-of-hours senders — something like “I work flexible hours; I don’t expect a reply outside yours” — which the Fair Work Ombudsman’s own guidance points to as good practice.
If you want notifications properly switched off rather than left to each person, that is configurable through Microsoft 365 administration and device policy. This is part of the day-to-day work in any managed Microsoft 365 environment, and it is the kind of thing worth getting right once across the whole organisation rather than user by user.
Mobile device management and conditional access
The real after-hours leak is the phone. Work email and Teams on a personal mobile means contact follows people into the lounge room. Mobile device management (through Microsoft Intune) and conditional access policies give you proper levers here.
You can enforce app protection so work data stays inside managed apps, and you can use conditional access to shape when and how people connect. For specific roles — not everyone — you can even restrict access to corporate apps to particular hours or locations, so that someone who is genuinely off the roster is not technically able to be pulled back in. Used carefully, this turns a written rule into an enforced boundary. Used clumsily, it locks out the on-call engineer at 2am, so it has to be designed around your actual roster rather than applied with a blunt instrument.
A professional services firm in Hawthorn we work with had the opposite problem to most: their junior staff were answering partner emails at all hours because the Teams app pinged their personal phones and nobody had told them they didn’t have to. The remedy was not a stern memo. It was switching most of the team to managed app access with notifications off outside business hours, leaving a small after-hours group properly resourced, and writing the policy to match what the systems now did.
On-call rosters and the compensation question
The right to disconnect bites hardest where there is no clear on-call arrangement. If you expect certain people to be reachable after hours, that should be a defined roster with an allowance or overtime attached — not a vague cultural expectation that everyone is always on. The legislation explicitly weighs whether the employee is compensated for being available when judging if a refusal is unreasonable.
From the IT side, that means your access controls and notification rules should mirror the roster. The on-call person this week gets the alerts and the access; everyone else doesn’t. We run our own 24/7 NOC out of Tecoma on exactly this model, with a defined roster and the tooling configured so the engineers who are off are genuinely off. The technology and the employment arrangement have to agree with each other, or one of them is lying.
Monitoring, alerts and overtime creep
System monitoring is where this gets subtle. Automated alerts from a server, a backup job or a security tool are not “the employer contacting you” in the Fair Work sense — they are machines. But if a human is expected to act on those alerts after hours, that expectation is exactly what the right to disconnect is about, and it should be rostered and paid like any other on-call duty.
The practical move is to route after-hours monitoring to whoever is actually on call, not to a whole team’s inboxes. Alert fatigue and silent unpaid overtime usually come from the same root cause: everyone gets every alert, so everyone feels vaguely responsible at all hours. Tightening alert routing is both better security operations and a cleaner employment boundary. This is core to how a managed security operations capability should be run regardless of the legislation.
Writing a policy your systems can back up
The order of operations matters. Plenty of businesses write the policy first, then discover their systems don’t support it. Do it the other way around: decide what the systems will enforce, then write a policy that describes that reality.
A workable right to disconnect policy generally covers:
- Working hours by role — what they are, and who, if anyone, is on a defined after-hours roster.
- Contact expectations — that staff are not expected to respond outside their hours, and won’t be penalised for not doing so.
- The genuine exceptions — emergencies, the on-call roster, and how those people are compensated.
- The tools — quiet hours, scheduled send, managed notifications — and that the business has configured them, not just recommended them.
- How to raise a concern — the internal process before anything goes near the Fair Work Commission.
The wording and the workplace-relations judgement calls belong with your HR adviser or employment lawyer. The Fair Work Ombudsman publishes plain-English guidance on the right to disconnect that is a sensible starting point for that conversation. Our job is the other half: making sure the tenant settings, device policies and alerting genuinely do what the document claims. When we take on a new client we treat this as part of the broader managed IT baseline, alongside the security and identity controls that touch the same systems.
Frequently asked questions
Does the right to disconnect ban after-hours emails?
No. Employers can still send messages outside working hours. What the law changes is that employees are generally entitled not to monitor or respond to them until they are back at work, and they can’t be disadvantaged for that — unless their refusal is unreasonable in the circumstances. Scheduled send is the easy way to avoid the issue entirely.
Does it apply to my small business?
Yes. The right to disconnect commenced on 26 August 2024 for employers with 15 or more employees and on 26 August 2025 for small business employers under 15 staff. Both dates have now passed, so it applies regardless of size.
Can IT settings actually enforce this?
To a large degree, yes. Quiet hours in Teams, managed-app notifications through Intune, and conditional access policies can stop most after-hours pings reaching staff who aren’t on call. They can’t make legal judgements about what’s reasonable, but they remove the temptation and the pressure that cause the problem in the first place.
What about our on-call engineers and after-hours support?
Genuine on-call work is fine — it just needs to be a defined roster with proper compensation, and your access and alert routing should match it so only the on-call person is pinged. The law specifically considers whether someone is paid for being available when deciding if declining contact is reasonable.
Is this a security or a compliance issue?
It is primarily a workplace-relations issue, so the policy and any disputes are HR and legal territory. But the controls that make it work — identity, device management, conditional access, alert routing — are the same ones that underpin your security posture, which is why it tends to land on the IT plate.
Where TechAssist fits
We’re a Melbourne MSP, founded in 2014, with 13 Australian-employed engineers — no offshore call centre — and we run this kind of configuration work across professional services, construction, manufacturing and healthcare clients every week. The right to disconnect is one of those rules where the legal text is short but the implementation lives entirely in settings most businesses have never opened.
If you want your Microsoft 365 tenant, mobile device policies and after-hours alerting set up so they actually back the policy you’re putting in writing, get in touch. We’ll handle the IT half; pair it with your HR adviser for the rest.
Azure costs for Melbourne SMEs grow 30 to 50% a year without anyone noticing. Enterprise FinOps assumes a $5 million cloud spend; this is the SME version, sized for the $50k to $500k reality. Eight quick wins, governance guardrails that stick, and the three traps that catch almost every business.
Why SME Azure spend creeps
It is rarely one decision. A pilot tenant becomes a production tenant. A test virtual machine becomes a forgotten orphan with a 1 TB premium SSD attached. Defender for Cloud gets enabled on a free trial, ends up on the Standard tier across every subscription, and nobody can find the off switch by the time the invoice arrives. The dev environment that was ‘just for two weeks’ is still running 18 months later because no one wants to be the person who turned it off.
We see the same pattern across our managed clients. A business signs up for Azure at $3,000 a month. Two years later it is $11,000 a month, the workloads have not materially expanded, and the CFO is asking the right question for the first time. By then the answer is harder than it would have been at $4,000.
FinOps as a published discipline (the FinOps Foundation maintains the framework, Microsoft has published its own opinionated version) assumes you have a cloud platform team, a financial analyst, and an executive sponsor. For a 60-staff Melbourne business with a quarter-million-dollar Azure footprint, that is overkill. The lite version below takes the parts of FinOps that apply at SME scale and ignores the rest. We have run this with clients across professional services in the CBD, manufacturers out around Dandenong, and not-for-profits across the eastern suburbs as part of our Melbourne cloud services work.
What ‘normal’ SME Azure spend looks like
Some benchmarks from our managed book, useful as sanity checks on whether your number is in the right zone.
| Workload profile | Typical monthly Azure spend | Spend per user per month |
|---|
| 30-staff professional services, M365-heavy, light IaaS | $2,500 – $4,500 | $80 – $150 |
| 60-staff hybrid, file server + 4 to 6 LOB VMs in Azure | $5,500 – $9,500 | $90 – $160 |
| 100-staff with line-of-business SQL workloads in Azure | $11,000 – $19,000 | $110 – $190 |
| 120-staff manufacturer with ERP, AVD, and DR replication | $18,000 – $28,000 | $150 – $230 |
If your number is materially above the band for your profile, there is almost certainly waste. If your number is materially below, either you are doing something genuinely clever or you have under-provisioned somewhere that will cause a production incident later.
The eight quick wins
Most SMEs can take 20 to 35% off their Azure bill in a fortnight of focused work, without changing anything about what the business does. The targets in order of effort-to-saving ratio:
1. Rightsize the virtual machines
The Azure Advisor and the Azure Migrate tools both flag VMs running well below their provisioned capacity. The reality is most SMEs have two or three D8s_v5 instances that were sized off a panicked guess at the start of a migration and have been running at 8% CPU ever since. Moving them down two or three sizes typically saves 60 to 75% of the per-VM cost. Validate with seven days of metrics first; do not just take Advisor’s word for it.
One client of ours – a 55-staff engineering consultancy in South Melbourne – was running their file server VM as a D16s_v5 because the original migration consultant ‘matched the on-prem CPU count.’ Seven days of metrics showed 4% average CPU. Rightsizing to a D2s_v5 saved $720 a month with zero user-visible impact.
2. Kill the orphaned disks
Every time someone deletes a VM through the portal, the OS disk and any data disks survive unless deletion was explicitly chosen. Over a few years, an SME tenant will accumulate 20 to 60 orphaned managed disks, often premium SSDs at $0.15 per GB-month. A 1 TB orphaned premium disk is $150 a month for storing absolutely nothing useful.
Run a quick KQL query in Azure Resource Graph to find disks where ManagedBy is empty. Validate that none of them are being held intentionally (some teams keep a disk for a few months as a ‘soft delete’ before truly removing it), then delete the rest. Easy win, usually $400 to $1,200 a month.
3. Reserved instances or savings plans for the steady-state workloads
Anything that runs 24/7 in steady state – production servers, domain controllers, a SQL VM, a file server – is paying full pay-as-you-go pricing by default. A one-year Reserved Instance is roughly 30% cheaper; three years is closer to 50%. The Azure Savings Plan for compute is more flexible (it covers any VM family in any region for the commitment amount) but a slightly lower discount.
The decision rule we use: if the workload is going to run for at least the next 12 months as-is, take the one-year reservation. If it might move, resize, or change family within that window, take the savings plan. Three-year commitments only for genuinely static workloads.
4. Auto-shutdown for dev and test
Dev and test VMs do not need to run on weeknights or weekends. A standard Azure Automation runbook or the built-in Azure DevTest Labs auto-shutdown can cut a non-production VM bill by 65 to 75%. The cost is two hours of configuration and a 30-second wake-up delay when someone needs the box at 7am Monday. We have yet to meet a dev team that genuinely objected once the saving was shown.
5. Azure Hybrid Benefit
If you have Windows Server or SQL Server licences with active Software Assurance, the Azure Hybrid Benefit lets you bring those licences to Azure VMs and stop paying the per-hour Windows or SQL surcharge. The saving on a Windows Server VM is typically 40%; on a SQL VM it can be 60 to 75%. Almost every SME with Software Assurance is leaving this on the table because nobody enabled the toggle at deployment.
Check your existing fleet through Cost Management. Filter by ‘Windows’ or ‘SQL Server’ as a meter category. Anything not marked as Azure Hybrid Benefit is overpaying.
6. Archive cold storage
Storage account blobs default to the Hot tier. Anything older than 30 days that you have not touched should be in Cool ($0.0152 per GB-month versus $0.0184 for Hot) or, for compliance archives, the Archive tier ($0.00099 per GB-month). Lifecycle policies on the storage account do this automatically.
For a healthcare client of ours in Box Hill with a 14 TB compliance archive, moving the long-tail blobs from Hot to Archive saved about $230 a month. A small number per month but a clean, automated saving that compounds as the archive grows.
7. Kill unused public IPs
A standard static public IP is roughly $4.50 a month. Trivial individually, but most SMEs have 15 to 40 of them, half of which are unattached from their original VM or load balancer. Run an Azure Resource Graph query for public IPs with no associated resource, validate, delete.
8. Review egress
Outbound data transfer (egress) from Azure to the internet is roughly $0.087 per GB after the first 100 GB free per month. Backup tools that pull data out of Azure, a misconfigured replication target that goes through public endpoints rather than peering, a video conferencing recording archive that streams out to a local NAS – all of these can quietly produce $400 to $1,500 a month in egress charges that nobody knows about.
The fix is usually a routing change (route the traffic through a private endpoint or service endpoint) or a topology change (move the target into Azure rather than pulling the data out). The win is identifying the source first; Cost Management broken down by Meter Subcategory shows you where the egress lives.
The governance guardrails that actually stick
Quick wins are easy. Stopping the spend from creeping back up over the next 12 months is the hard part. The lightweight controls we recommend for SMEs – the parts of the textbook that work at this scale:
Subscription-level budgets and alerts
One budget per subscription, set to the monthly run rate plus 15%, with alerts at 80%, 100%, and 120%. The alerts should go to a real person (the CFO and the IT lead), not a shared mailbox. The 80% alert is the one that catches the problem before it becomes a quarterly variance discussion.
Do not bother with budgets at the resource group level for an SME; the maintenance overhead is not worth the precision. The subscription is the right granularity.
Tagging that the team will actually do
Enterprise FinOps documents will tell you to enforce 14 mandatory tags. The team will rebel. For SME purposes, three tags are enough: Environment (Prod / Dev / Test), CostCentre (or Department), and Owner (a person, not a generic mailbox). Enforce them with Azure Policy at subscription creation time so any new resource without the three tags is blocked.
Three tags get used. Fourteen tags get ignored, and then nothing gets used.
Quarterly cost review
One hour every three months. The IT lead and the CFO sit down with Cost Management, look at the trend, look at the top ten cost drivers, look at the variance against budget, and decide whether to act. That is the entire process. The output is a one-page note for the leadership team and a list of remediation actions for the next quarter.
This is the rhythm we run with our managed clients. It is also the rhythm where most of the savings actually surface, because it forces someone to look at the data on a cadence that catches problems while they are small.
The three traps
Three patterns catch almost every SME on Azure. Worth understanding them before they catch you.
Trap 1: Lift-and-shift over-provisioning
The most expensive single mistake we see. A business migrates 12 servers from VMware to Azure and tells the migration partner to ‘match the existing VM sizes.’ The existing on-premises VMs were sized for peak load that occurs maybe twice a year, on hardware that was bought five years ago. The Azure VMs run hot for two hours a quarter and idle the other 99% of the time, but are billed at peak capacity every hour. Add up across 12 VMs and you are paying three times what the workload needs.
The fix is to size for Azure metrics, not on-prem habits. Migrate first, then watch the metrics for two to four weeks, then rightsize aggressively. We have done this exercise often enough now that we build the rightsizing step into the migration plan from the start. If the migration partner does not include a post-migration optimisation phase, that is a warning sign.
Trap 2: The dev environment that became production
A developer or contractor spins up a dev environment to test a workload. The business comes to rely on it. Three years later it is processing real production data on a ‘temporary’ subscription with no monitoring, no backup, no DR, and no reserved instances. It is also costing twice what it should because no one ever optimised it.
The fix is governance at the subscription creation step. No new subscription without a documented owner and an explicit lifecycle (this is a permanent prod subscription, or this is a 90-day project subscription with an automatic shutdown date). Cleaning up after the fact is harder than preventing it.
Trap 3: Defender for Cloud tier sprawl
Defender for Cloud is genuinely good, and the Standard tier offerings (Defender for Servers, Defender for SQL, Defender for Storage, Defender for Containers, Defender for App Service, and so on) protect real attack surfaces. The trap is that they bill per resource and the tiers are enabled per subscription. Click the wrong toggle and you have Defender for Servers Plan 2 running on every VM across every subscription for $24 each per month.
We have seen SMEs paying $4,000 a month for Defender coverage when their actual security need would be served by $800 of targeted enablement. The fix is to choose the plans deliberately, enable per subscription, and review quarterly. Defender for Servers Plan 2 on the workloads that need it; off everywhere else. Defender for Storage on accounts with sensitive data; off on the public assets bucket. The protections matter; the indiscriminate enablement does not.
For the security-side conversation about what to leave on, our Melbourne cyber security services page outlines the decisions we apply on the managed side. Cost and security are the same conversation in Azure; you cannot optimise one without involving the other.
What the FinOps tooling landscape looks like for SMEs
The third-party FinOps tools (CloudHealth, Cloudability, Apptio Cloudability, Flexera) are excellent but enterprise-priced. For an SME at $50k to $500k annual Azure spend, the native Azure tooling is enough:
| Tool | What it does | SME relevance |
|---|
| Cost Management + Billing | Cost analysis, budgets, alerts, exports | Essential. Use weekly. |
| Azure Advisor | Rightsizing, reserved instance, idle resource recommendations | Essential. Review monthly. |
| Azure Resource Graph | KQL queries across resources, perfect for orphan hunts | Useful. Quarterly. |
| Microsoft Cost Management Power BI app | Pre-built dashboards over Cost Management exports | Nice to have for the CFO. |
| Microsoft FinOps Toolkit (open source) | Bicep templates, KQL queries, automation runbooks | Useful if you have someone technical to deploy it. |
If your spend grows past $1 million a year, the third-party tools become defensible. Below that, the native tooling is fine and the discipline matters more than the platform.
A small-business worked example
A 65-staff manufacturing business in Bayswater came to us in late 2025 with an Azure bill of $14,800 per month and a CFO who could not get a straight answer about why. Two weeks of focused work:
- Rightsized seven over-provisioned VMs, saving $2,100 per month
- Deleted 23 orphaned premium disks, saving $1,400 per month
- Applied Azure Hybrid Benefit to 12 Windows VMs (they had Software Assurance through their CSP and no one had enabled the toggle), saving $1,800 per month
- Switched the steady-state production workloads to one-year savings plans, saving $1,200 per month
- Set up auto-shutdown on the dev and test environments, saving $600 per month
- Identified and re-routed an egress problem through a private endpoint, saving $400 per month
- Trimmed Defender for Cloud tier coverage to the workloads that actually needed Plan 2, saving $700 per month
Total monthly saving: $8,200, or about 55% of the original bill. The new run rate of $6,600 per month is a defensible number for the workload, with no production impact and no reduction in security posture (in fact a more deliberate one). Subscription budgets, three-tag enforcement, and quarterly review cadence are now in place. The job took us about 70 hours across two engineers from our 13-strong Melbourne team and was delivered alongside the regular per-user fixed monthly managed IT engagement.
FinOps and the broader cloud strategy
Cost optimisation is one strand of a wider conversation about whether the cloud architecture is right for the business. Sometimes the answer to a high bill is to optimise; sometimes it is to redesign. A 24/7 SQL workload that processes a fixed batch overnight may be better suited to Azure SQL serverless or even a scheduled VM. A file server that nobody touches for three months at a time might belong in Azure Files cool tier with a small AVD presence on demand. These are not quick wins; they are architecture changes. But once the quick wins are taken, the conversation moves to design.
For Melbourne SMEs that want a second opinion on whether the architecture is right before committing to another year of the existing spend, we run cloud architecture reviews as a discrete piece of work, separate from ongoing managed services. They are useful at the 12-month mark of any non-trivial Azure deployment. Reach us through the contact page if that is the conversation you need.
Frequently Asked Questions
Should we move away from Azure to save money?
Almost never the right answer for a workload that is already in Azure. Egress fees on a full re-platform are punishing, the operational disruption is real, and the cost difference between Azure, AWS and GCP for SME-typical workloads is usually under 15% once both are properly optimised. Optimise what you have before considering a move. The exception is a workload that genuinely fits a different platform’s primitives better (a heavy GCP BigQuery analytics workload, for example).
How often should we revisit our reserved instance commitments?
At the renewal point and at any major workload change. The Azure Savings Plan is more flexible than the older Reserved Instances because it does not lock you to a VM family; if your workloads shift, the savings plan keeps applying. We typically recommend a mix: reservations for the most stable workloads (domain controllers, file servers, the SQL VM that has run unchanged for three years), savings plans for the rest.
What does FinOps mean for our cloud backup and DR spend?
Backup storage tends to live outside the day-to-day cost conversation and grows quietly. Same principles apply: tier the storage (most backup data can live in cool or archive after 30 days), review retention against actual recovery needs, and watch the egress when you do a restore. Our companion piece on backup and disaster recovery for Melbourne businesses goes deeper on the design decisions.
Do we need a dedicated FinOps person?
Not at SME scale. The work is two to four hours a month for an experienced engineer plus a quarterly review with the CFO. We run it as part of the managed engagement for clients on our per-user fixed monthly pricing model. Hiring a dedicated FinOps person is a sensible move at around $2 to $3 million annual cloud spend, not before.
Will the optimisation work introduce risk to production?
It can if it is done carelessly. The discipline is: validate against metrics before any resize, take a backup before any storage change, do the work in a maintenance window, and have a rollback path. We have done hundreds of these exercises with our MSP Melbourne clients without a production incident, but the process matters. A weekend cowboy resize of a production SQL VM is how you cause an incident.
What is the role of the CFO in cloud cost management?
The CFO owns the budget and the variance conversation; the IT lead and the MSP own the technical optimisation. The quarterly review is the meeting where those two functions talk to each other. Most SME cost creep we see comes from a lack of that conversation rather than from any technical failure.
Network segmentation gets explained as a zero-trust enterprise project with microsegmentation and identity-aware proxies. That framing scares SMEs off, which is a shame. A 30-person Melbourne business can segment its network usefully in a weekend with a UniFi stack and four VLANs. The hard part is sequencing the work so each step reduces real risk.
This guide is the practical version. We will walk through the minimum-viable segmentation that actually reduces lateral movement risk for an Australian SME, the priority order (guest Wi-Fi first, because it is the cheapest win and stops half the dumb risks), where SMEs over-engineer and waste budget, a sample VLAN and firewall rule pack you can adapt, and the trap of segmenting your network without doing the identity work alongside it.
TechAssist has been deploying these stacks for Melbourne SMEs since we were founded in 2014. Our cybersecurity services Melbourne team treats segmentation as one of the highest-leverage controls available to a small business. It is not the most exciting work, but it is the work that means a phished receptionist credential does not become a domain-wide ransomware incident.
What Network Segmentation Actually Is
Segmentation is the practice of dividing your network into separate zones so that a device or user in one zone cannot freely communicate with devices in another zone. Each zone is governed by firewall rules that say what traffic is permitted between it and other zones.
The simplest example: your guest Wi-Fi should not be able to talk to your office laptops. Your office laptops should not be able to talk to your CCTV cameras. Your CCTV cameras should not be able to talk to your phone system. Your phone system should not be able to talk to anything except the SIP provider. If you implement those four rules, you have already done most of the segmentation work that meaningfully reduces risk.
The reason segmentation matters is lateral movement. Modern ransomware does not just encrypt the machine it lands on. It enumerates the local network, finds open shares, weak credentials, and unpatched services on other devices, and spreads. A flat network gives the attacker the entire estate. A segmented network gives them one VLAN.
This is not zero trust, despite what some vendors will tell you. It is the perimeter approach with internal perimeters added. Zero trust is the next step beyond segmentation, where every connection is authenticated and authorised regardless of zone. Read our zero trust security model explained guide for that broader picture. For most SMEs, getting segmentation right is the prerequisite, and the right place to stop for now.
The Minimum Four VLANs for a Melbourne SME
If you run a 15-to-100-person business and you want a segmentation design that actually reduces risk without becoming a multi-month project, run four VLANs. We deploy this exact pattern several times a quarter across our client base.
| VLAN | Purpose | Devices | Typical IP range |
|---|
| 10 – Corporate | Staff workstations, servers, file shares | Laptops, desktops, NAS, on-prem servers, Office 365-connected devices | 10.10.10.0/24 |
| 20 – Guest | Visitor internet only | Visitor phones, contractor laptops, guest tablets | 10.10.20.0/24 |
| 30 – IoT and AV | Smart devices, AV gear, CCTV, printers | Printers, cameras, smart TVs, AV controllers, Sonos, smart whiteboards | 10.10.30.0/24 |
| 40 – Voice | SIP phones and gateways | Desk phones, IP-PBX, SIP gateways | 10.10.40.0/24 |
Four VLANs sound trivial. The reason it is enough for most SMEs is that each one represents a meaningfully different risk profile. Guest devices are unmanaged and untrusted. IoT devices are notoriously badly patched and run weird firmware. Voice devices have their own QoS needs and should not be exposed to general office traffic. Corporate is the only zone where managed, patched, and authenticated devices live.
If you have a meaningfully different workload, like a manufacturing floor with PLCs, an OT environment, or a clinical environment with medical devices, add a fifth VLAN for that. Do not collapse it into the IoT VLAN. The blast radius if it gets compromised is too different.
Priority Order: Guest WiFi First
The single highest-leverage step you can take is splitting guest Wi-Fi from corporate Wi-Fi. It is cheap, it is fast, and it removes the most common dumb risk: a visitor’s compromised phone or a contractor’s malware-laden laptop pivoting onto your file server because they got the office Wi-Fi password.
The order we deploy in for a typical Melbourne SME segmentation engagement is as follows.
Week one. Guest Wi-Fi on its own VLAN with a captive portal, time-limited credentials, and a firewall rule that permits internet egress only. No access to internal subnets. This alone removes about 40 percent of the lateral movement risk for a typical SME.
Week two. Voice VLAN. Move the SIP phones onto their own VLAN, lock egress to your SIP provider’s IP range only, and prioritise QoS. This stops a compromised phone from talking to anything except the SIP provider and improves call quality at the same time.
Week three. IoT and AV VLAN. Move printers, cameras, smart TVs, AV gear, and any other unmanaged device onto its own VLAN. Permit only the management traffic the corporate VLAN needs (Bonjour and mDNS reflection for AirPrint, print server traffic, RTSP for camera viewing). Block everything else.
Week four. Corporate VLAN cleanup. Remove anything that should not be on the corporate VLAN, audit static IPs, document the segmentation in a network diagram, and set up monitoring alerts for inter-VLAN traffic that violates the rule set.
That is a four-week project for a typical 30-person Melbourne SME. Most of the cost is engineering time, not hardware. If you are already on UniFi, the hardware is essentially free, and the labour is roughly fifteen to twenty engineer-hours including documentation.
Where SMEs Over-Engineer
Segmentation has a way of attracting over-engineering. Here is what to skip if you are a 30-to-100-person business.
Microsegmentation. This is the practice of giving each workload or application its own segment with policies down to the application port level. It is the right answer for large enterprises with data centres and dozens of regulated workloads. It is not the right answer for a 40-person Melbourne law firm with one practice management system. Microsegmentation tooling costs more than the entire SME’s segmentation budget and adds operational complexity that the IT team cannot maintain.
Per-application firewalls. The pattern where each application has its own next-generation firewall with deep packet inspection rules. Same logic as above. It belongs to the enterprise data centre, not the SME network. For SMEs, a single perimeter firewall with sensible inter-VLAN rules covers the same risk at a fraction of the cost.
Identity-aware proxies for every internal application. Good idea in theory. In practice, deploying ZTNA across every internal app for a 30-person business takes three to six months of integration work, costs tens of thousands in licensing, and leaves the team frustrated. Start with corporate, guest, IoT, and voice segmentation. Then layer identity-aware access onto the two or three highest-value internal applications. Do not try to do all of it at once.
Dedicated SIEM and SOAR. SMEs that try to deploy a SIEM and incident orchestration platform alongside segmentation usually end up with both half-deployed. Use Microsoft Defender for Business or your MSP’s monitoring stack until you genuinely outgrow it. Our managed IT services Melbourne programme includes 24/7 NOC monitoring out of our Tecoma office, which covers what a small SIEM does for a fraction of the cost.
Sample VLAN and Firewall Rule Pack
Here is a sample rule pack that we deploy as a starting point on UniFi, pfSense, or Meraki gear. Adapt the IP ranges to your environment. The rules are written as “from-to: permit/deny.”
| Source | Destination | Ports | Action | Reason |
|---|
| Guest VLAN | Any internal VLAN | Any | Deny | Guests must not touch internal anything. |
| Guest VLAN | Internet | 80, 443, 53 | Permit | Web and DNS only. No SMB, no RDP, no SMTP. |
| IoT VLAN | Corporate VLAN | Any | Deny | IoT devices initiate nothing into corporate. |
| Corporate VLAN | IoT VLAN | Print, RTSP, mDNS | Permit | Print to printers, view cameras, AirPrint. |
| IoT VLAN | Internet | 443, NTP | Permit | Vendor cloud and time sync. Block everything else. |
| Voice VLAN | SIP provider IPs | 5060, RTP range | Permit | SIP signalling and media to the provider only. |
| Voice VLAN | Any other VLAN | Any | Deny | Phones do not talk to laptops or printers. |
| Corporate VLAN | Internet | Any | Permit with filtering | Standard egress with DNS filtering and TLS inspection. |
| Corporate VLAN | Voice VLAN | HTTPS to PBX | Permit | Admin access to PBX from corporate only. |
| Any VLAN | Management VLAN | Any | Deny except admin | Network gear management is admin-only. |
The thing to notice about this rule pack is how restrictive it is by default. Most SMEs run flat networks where everything can talk to everything. That is the disease. The cure is “deny by default” between VLANs and explicit permits only for the traffic you actually need. If you do not know whether a traffic flow is needed, it is not needed. Add it back if something breaks.
One detail that catches people out: print discovery. Modern printers use mDNS and Bonjour for discovery, which is broadcast-based and does not cross VLAN boundaries by default. You need either an mDNS reflector (UniFi calls it mDNS, Meraki calls it Bonjour Forwarding) configured between corporate and IoT VLANs, or you fix the printers in DNS with static A records and add them as IP-based printers. Both work. We usually prefer the static DNS approach because it is more deterministic.
The Trap: Segmenting Without Identity
This is the trap that costs SMEs more than any other in segmentation projects. You spend a weekend deploying four VLANs, you write a clean rule pack, you feel great, and then a phished user credential turns out to be a domain admin because identity hygiene was never done. The attacker authenticates as a privileged user, traverses your VLAN rules using legitimate credentials, and segmentation buys you nothing.
Segmentation is necessary but not sufficient. You also need identity hygiene. The minimum identity work to do alongside segmentation is as follows.
One. No standing domain admin. Domain admin rights are granted just-in-time, ideally through Privileged Identity Management in Entra ID, or at minimum through a separate dedicated admin account that requires MFA and is not used for email or browsing.
Two. MFA on everything. Not just email. RDP gateways, VPN, the firewall admin interface, the switch management interface, the wireless controller, the file server admin. If a credential gives access to something, that access requires MFA.
Three. Conditional access policies on Entra ID. At a minimum, require MFA for all users, block legacy authentication protocols, and require a compliant device for access to admin roles and high-value applications. This is included in Microsoft 365 Business Premium and is one of the highest-leverage controls available.
Four. Local admin password randomisation. Every Windows endpoint should have a unique, randomised local administrator password managed via LAPS or its modern equivalent in Intune. A consistent local admin password is one of the fastest paths to lateral movement, and most SMEs still have it.
Five. Application control allowlisting on at least the corporate VLAN endpoints. This is the hardest of the Essential Eight to deploy well, but it is also one of the most effective. See our deep dive on application control for the practical playbook.
Without those identity controls, segmentation is theatre. With them, segmentation becomes a meaningful second line of defence.
A Melbourne Example: 38-Person Architecture Practice in Richmond
A 38-person architecture practice in Richmond engaged us in early 2025 after a near-miss incident. A user clicked a phishing link, entered credentials into a fake Microsoft login page, and an attacker logged into their mailbox. The mailbox had access to a shared SharePoint library with five years of client documents, and the attacker started downloading files before MFA challenges (delayed by a policy gap) interrupted them.
The post-incident review showed three problems. First, no conditional access policy requiring MFA on every sign-in. Second, no device compliance check, so the attacker authenticated from an unmanaged device with no resistance. Third, flat network with no segmentation, so if the attacker had pivoted from email to internal systems, nothing would have stopped them.
We deployed in three phases. Phase one was identity hardening: conditional access, device compliance, MFA enforcement, LAPS on the Windows fleet. Phase two was segmentation, exactly the four-VLAN pattern above, with the addition of a fifth VLAN for the Revit project file server because it is high-value and warrants its own zone. Phase three was monitoring: alerting on inter-VLAN traffic that violated rules, alerts on impossible-travel sign-ins, and alerts on download volume anomalies in SharePoint.
Total project cost: just under $34,000 across three months. Total engineer time: 58 hours. Hardware: $4,800 of UniFi gear that replaced a single flat-network router and a consumer-grade access point. They have had zero security incidents in the eighteen months since.
The most important detail: the segmentation work would have been worthless without the identity work that came first. We do not deploy VLANs as a standalone project anymore. Segmentation comes packaged with identity hardening, or it does not come at all.
Hardware Choices: UniFi, Meraki Go, or Meraki Proper
Three tiers cover almost all Melbourne SME deployments. Each has trade-offs.
UniFi from Ubiquiti is the SME favourite for good reason. Hardware is one-time-cost, no recurring licences, the controller is good, and the gear is genuinely capable of handling four-to-six VLANs and the rule pack above. The trade-off is that you (or your MSP) own the operational lift. If the controller falls over, no vendor support phone number rescues you. We deploy UniFi for clients with an MSP relationship in place, because the MSP carries the operational responsibility.
Meraki Go is the entry-level cloud-managed option from Cisco. It is easy to set up, has a clean phone app, and is a good fit for businesses under 20 staff who want minimal operational complexity. The trade-off is feature ceiling. Once you want VLAN-aware DHCP scopes, more than basic firewall rules, or advanced visibility, you hit the ceiling. We tend to deploy Meraki Go for businesses we do not co-manage.
Meraki proper (the full Cisco Meraki dashboard) is the right answer for SMEs with serious compliance ambitions or with multi-site setups. The licensing cost is real (typically $80-$200 per device per year), but the cloud management, deep visibility, and reliability are excellent. We deploy this for clients in regulated sectors and for clients with three or more sites where central management saves enough engineer time to pay for itself.
None of these is the wrong answer. The right answer depends on whether you have an MSP, your compliance trajectory, and how much operational lift you want to carry yourself. Our MSP Melbourne team scopes the hardware decision as part of the segmentation engagement so the gear matches the operating model.
Monitoring: How You Know Segmentation Is Working
Deploying segmentation and not monitoring it is half the job. You need to know when a rule is being violated, when a device is in the wrong VLAN, and when traffic patterns indicate something abnormal.
The minimum monitoring set for an SME deployment:
Alert on denied inter-VLAN traffic above a threshold. A few denied packets are normal background noise. A sustained pattern of denied traffic from one IoT device trying to talk to a corporate file share is a signal worth investigating.
Alert on new devices in any VLAN. Especially the corporate VLAN. If an unknown MAC address suddenly appears, you want to know.
Alert on devices moving between VLANs. This should almost never happen during normal operations. If a device hops from IoT to corporate, something is misconfigured or, worse, someone is poking at the network.
Alert on rule changes. The firewall rule pack is now a security control. Changes to it should be logged, ideally reviewed, and definitely not made silently.
Our 24/7 NOC out of Tecoma handles this monitoring for our managed clients. We respond to P1 incidents in under 15 minutes and are on-site across Melbourne metro within the same business day when something needs hands on gear. For clients running their own ops with our co-managed IT support model, we share the monitoring with the internal team and escalate when thresholds are crossed.
How This Fits With Essential Eight and ISO 27001
Segmentation is not explicitly an Essential Eight strategy, but it is referenced under several of them and is foundational to a Maturity Level Two posture. Restricting administrative privileges, restricting Microsoft Office macros, and application control all become more enforceable when segmentation has limited the blast radius of any single compromised endpoint.
For ISO 27001, segmentation falls under Annex A.13 (Communications Security) and contributes evidence for several other controls. We do not certify clients (we are ISO 27001 capable, not a certifying body), but we have helped a number of Melbourne SMEs pass certification audits, and segmentation always shows up positively in the auditor’s review.
For Privacy Act obligations, segmentation reduces the population of data potentially affected in a breach, which can change the calculus on notifiable data breach decisions. See our Privacy Act for SMBs guide for the data handling context.
What This Costs for a Typical Melbourne SME
The all-in cost for a 30-to-50-person SME segmentation engagement, including identity hardening and ongoing monitoring, breaks down roughly as follows.
| Line item | Cost (AUD) | Notes |
|---|
| Network hardware (UniFi) | $5,000 – $8,000 | Gateway, switches, access points for one site. |
| Segmentation engineering | $6,000 – $9,000 | 40-60 hours including documentation. |
| Identity hardening (CA policies, MFA, LAPS) | $4,000 – $6,000 | One-off, assumes Microsoft 365 Business Premium in place. |
| Documentation and handover | $1,500 | Network diagrams, rule pack, runbook. |
| Ongoing monitoring (per user per month) | From per-user fixed monthly pricing | Part of TechAssist managed service. |
Total project cost typically lands between 20 and 30 thousand dollars depending on existing hardware, site complexity, and how much identity work is needed alongside the segmentation. The ongoing monitoring sits inside our per-user fixed monthly managed service pricing, so there is no surprise on the operational side.
Compared to the cost of a single ransomware incident (we covered this in another article and the realistic number for an SME is between $150,000 and $400,000 including downtime and customer churn), the segmentation project pays for itself if it prevents one incident. The maths is usually obvious in the boardroom.
Frequently Asked Questions
Can I do segmentation myself with a consumer router?
No. Consumer routers do not support meaningful VLAN tagging, and the firewall capabilities are not granular enough to write the kind of rule pack that makes segmentation worth doing. You need at minimum a small-business gateway like a UniFi Cloud Gateway, a Meraki Go GX, or an equivalent. The hardware costs less than a couple of staff laptops, so the price is not the obstacle.
Will segmentation slow down my network?
On modern gear, no. The gateway processes inter-VLAN routing at line rate, and the firewall rules add microseconds of latency, not milliseconds. The only place we see performance issues is when an SME tries to deploy deep packet inspection and TLS interception on undersized hardware. If you size the gateway correctly for your throughput, segmentation is invisible to users.
Do I need separate physical switches for each VLAN?
No. VLANs are logical, not physical. One managed switch handles all four VLANs at once, tagging traffic on the uplink to the gateway. The only reason to use physically separate switches is for an OT or industrial environment with very strict isolation requirements, and that is not most SMEs.
What about working from home: do segmentation rules apply on the VPN?
This is the part that gets missed. If your remote workers VPN in and land in the corporate VLAN by default, your segmentation has a hole. The fix is either a separate VPN VLAN with its own rule set, or, better, moving away from VPN entirely and using Entra ID conditional access with device compliance checks for application access. The latter is the modern approach and avoids the VPN-as-trust-domain problem entirely.
How often should the rule pack be reviewed?
Quarterly at minimum, and after any significant change to the application stack. We review rule packs as part of our managed client quarterly business reviews, and we use those reviews to remove rules that are no longer needed (which is more common than adding new ones).
What if a vendor needs access to one of my internal systems?
Vendor access should land in a dedicated vendor-access zone with explicit rules to the specific systems they need. Do not give vendors guest Wi-Fi credentials and ask them to VPN. Do not give them corporate Wi-Fi access. A dedicated zone with explicit permissions, ideally with MFA and time-bound credentials, is the right pattern.
How do I get started?
The honest first step is an assessment. We will look at your existing network, your endpoint fleet, your identity setup, and your compliance trajectory, and we will give you a sequenced plan. We do this for Melbourne clients regularly out of both our Tecoma office and our 575 Bourke St CBD office. Reach the team via the contact page and we will sort out a discovery session.