The service catalog: what's in – and what's not.
A flat rate is only worth as much as the clarity about what it covers. That's why both are stated here: the scope of our managed services – and its limits. Both named openly, so you know where you stand.
Eight modules, one contract
- L-01
Monitoring & operations
- Included
- Continuous 24/7 monitoring of all managed systems, assessment of alerts, remote fault resolution, a monthly report on incidents and maintenance.
- Not included
- Projects and rebuilds (separate quote); systems outside the agreed scope of support.
- Response
- Automated fault detection around the clock; handling according to the contractually agreed urgency.
- Billing
- Within the monthly flat rate.
- L-02
Patch & update management
- Included
- Scheduled security and maintenance updates for operating systems and infrastructure firmware within agreed maintenance windows; prioritized handling of actively exploited vulnerabilities.
- Not included
- Major release upgrades and migrations (project); third-party application software, unless agreed.
- Response
- Critical security vulnerabilities are brought forward after a risk assessment – even outside the regular schedule.
- Billing
- Within the monthly flat rate.
- L-03
Backup & restore testing
- Included
- Veeam-based daily backup with an immutable copy to our own geo-redundant backup targets, daily success monitoring, regular documented restore tests, individual restores in day-to-day operation; optionally including Microsoft 365 backup.
- Not included
- Full recovery after a major incident or security breach (emergency service billed by effort, procedure governed by the emergency plan).
- Response
- Failed backups are usually addressed on the same business day; restore tests follow a fixed plan with a log.
- Billing
- Within the monthly flat rate.
- L-04
Firewall & network operations
- Included
- Rule-set maintenance in ongoing operation, configuration backups, firmware levels, changes within the agreed scope, review of remote-maintenance access.
- Not included
- Network redesigns, new sites and segmentation projects (separate quote).
- Response
- Change requests usually answered on the same business day; implementation after coordination within the maintenance window.
- Billing
- Within the monthly flat rate.
- L-05
Workplace support
- Included
- User support on business days, central device management, onboarding of new employees, orderly offboarding including revocation of access.
- Not included
- Hardware procurement costs (passed on transparently); training and courses (a separate module in the Training & Change solution area).
- Response
- Requests usually answered on the same business day; prioritization by operational impact.
- Billing
- Within the monthly flat rate, tiered by number of workplaces.
- L-06
Compliance support
- Included
- Ongoing evidence management (patch levels, backup logs, change history), reports for customer audits and insurers, answering security questionnaires based on the managed environment.
- Not included
- Certification and TISAX assessments themselves (performed by accredited or authorized bodies); building an ISMS (consulting project).
- Response
- Audit dates and questionnaire deadlines are planned together – in good time rather than reactively.
- Billing
- Within the flat rate or as a delimited consulting module, depending on scope.
- L-07
Procurement & licenses
- Included
- Specification and quotation via our vendor partnerships (Microsoft, Juniper, Cisco, HPE, F5, Fortinet), preconfiguration and rollout into monitoring, license inventory management, end-of-life planning.
- Not included
- Public price lists or shop orders (procurement runs on a quotation basis); vendors outside the partner programs are sourced through established trade partners.
- Response
- Quotation requests usually answered on the same business day; delivery times depend on vendor and market and are communicated transparently.
- Billing
- Project- or quotation-based; license subscriptions monthly; ongoing operation of the procured components via modules L-01 to L-04.
- L-08
External information security officer (ISB)
- Included
- The role of the external information security officer: ongoing ISMS management, regular management reports to executive leadership, steering of awareness measures, preparation for and support during audits, maintenance of reporting processes.
- Not included
- The responsibility of executive leadership itself (not legally delegable); certification audits (accredited bodies). A deliberately limited number of parallel mandates.
- Response
- Fixed regular meetings and reports; security-relevant events are handled with priority via the agreed reporting channels.
- Billing
- Monthly flat rate per mandate, depending on company size and rule set.
So what does it cost?
One flat rate per month – depending on the number of systems, the modules chosen and the criticality of your environment. We don't quote shop-window prices that don't hold up later: after a stock-take, you receive a quote with exactly one figure in it. That figure then applies – with no unplanned additional costs in normal operation.
Anything outside the agreed operation – projects, rebuilds, emergency responses after a major incident – is quoted beforehand, never billed afterward.