AI is changing how Australian business works. The ones who do it properly will compound the advantage.

What $1,850/month actually buys

Mid-sized Australian accounting firm · 12 users · FY26.

A 12-month operating record from a real Evisent client — a mid-sized accounting practice with an affiliated financial advisory arm under an external AFSL. 117 tickets — all resolved — an always-on security stack across 23 endpoints, 1,176 vulnerabilities tracked, 125 patch cycles deployed, 4 Quarterly Business Reviews, and a sustained licensee compliance program for the financial advisory practice. This is what shows up when the helpdesk queue is quiet — and what the per-user managed services fee actually funds.

EVISENT // OPERATING RECORD ACTIVE CLIENT
Accounting Practice · 12 users
FY26 · JUN 2025 – MAY 2026

  • 100% Tickets resolved
  • 117 Tickets / 12 mo
  • 1,176 Vulnerabilities tracked
  • 125 Patch cycles
  • 23 ENDPOINTS · 4 QBRs · 8.5h SCHEDULED ADVISORY · LICENSEE COMPLIANCE PROGRAM

The ticket queue is the visible part. Most of the work isn't in the queue.

117 tickets across 12 months sounds light for a 12-person firm — and that's the point. The ticket count is a function of what doesn't get raised: endpoints that don't get compromised, patches that don't get missed, identities that don't get phished, mail rules that don't sneak in. Every ticket raised in FY26 has been resolved. At the moment the annual report was cut, 116 had closed and 1 remained in progress (since closed). We don't carry tickets. The four cards below cover what landed in the queue. The two sections after that cover what didn't.

Tickets · 76% incident

  • 89 incidents
  • 13 software requests
  • 7 leavers
  • 6 new starters
  • 4 alerts

The mix you'd expect from a well-run small practice. The biggest single bucket is incident response. Only one ticket all year originated from a user-raised vulnerability — the rest of the vulnerability surface is handled in the always-on stack, below.

Lifecycle

  • 13 onboarding and offboarding events handled cleanly.

Provisioning of accounts, devices, M365 licences and security policies — and the reverse on the way out. Identity, access and data don't drift in a firm running this process. No abandoned accounts. No unprovisioned starters waiting on access.

Patching tempo

  • 125 patch cycles. Every Wednesday morning. All endpoints.

Windows and third-party application updates deployed, monitored and reported across all 23 endpoints, on a defined schedule. Current state at year-end: zero missing critical updates, zero missing standard updates on sampled endpoints.

Threats stopped quietly

  • 1,176 vulnerabilities tracked. 1 critical CVE escalated.

Continuous vulnerability scanning across the endpoint fleet. One critical CVE (CVE-2025-55182, React Server Components) was escalated via the licensee in 2025 and remediated as a tracked piece of work. The absence of incidents is the system working.

The always-on managed services stack.

The per-user managed services fee funds an integrated security and operations stack that runs continuously across every device and user account — not just helpdesk response. At $181.50/user/month ex GST, that works out to roughly $6 per user per day for round-the-clock coverage. The eight components below are active 24/7 whether or not a ticket is raised.

  • Managed Endpoint Detection & Response
    24/7 threat detection on every endpoint, backed by a Security Operations Centre that triages, contains and remediates incidents on Evisent's behalf. Active threat hunting — not passive AV signatures.

  • Application allowlisting / control
    Zero-trust application execution policy. Only approved software runs; ransomware, droppers and living-off-the-land attacks are blocked by default.

  • Automated patch management
    OS and third-party application updates deployed, monitored and reported across all devices.

  • DNS-layer protection
    Outbound DNS filtering blocks access to malicious, phishing and command-and-control domains.

  • Microsoft 365 & Intune configuration management
    Ongoing tuning of conditional access, device compliance, sign-in risk policies.

  • Vulnerability management & patching
    Continuous scanning across monitored endpoints with automated weekly patch deployment.

  • Backup verification
    Daily monitoring of Microsoft 365 and endpoint backups.

  • Email threat protection
    Microsoft Defender for Office 365 active across protected mailboxes.

$42,866 ex GST across 12 months. Itemised, not bundled.

Evisent's bills separate the service fee from Microsoft licensing from hardware-at-cost. Every line item is visible; nothing is hidden inside an all-in number.

12-month spend breakdown · ex GST

  • $27,225 Evisent managed services (12 × $181.50/user/mo avg)
  • $7,435 Microsoft licensing (via our CSP)
  • $6,795 Hardware (at cost + handling)
  • $1,411 Other (Azure, WatchGuard, consulting)

This is what an MSP fee actually pays for. Not a phone number.

Most small accounting and advisory firms can name the helpdesk number their MSP gives them. Very few can name the eight things in the security stack, or the patch cadence, or the vulnerability count, or the licensee evidence they'd need on day one of an AFSL audit. You should know exactly what you're paying for, and it should hold up under audit.

  • 100% of tickets resolved. 117 raised across 12 months; all closed.
  • 23 endpoints monitored 24/7 with EDR, application allowlisting, DNS-layer protection and managed M365/Intune configuration.
  • 1,176 vulnerabilities tracked, 125 patch cycles deployed, zero missing critical updates at year-end.
  • 4 Quarterly Business Reviews + 8.5h scheduled advisory + a live cyber awareness training session.
  • Licensee compliance program delivered end-to-end: multi-stage audit response.
  • Itemised billing: service fee, Microsoft licensing, hardware-at-cost and other broken out separately on every invoice.