Managed IT Cybersecurity Microsoft 365 & Azure Infrastructure & Cloud Who We Help Manufacturing & Engineering Legal Firms Accountancy & Finance Professional Services Healthcare & Social Care Charities & Membership Areas we cover Sheffield Rotherham Barnsley Doncaster Chesterfield How We Work Onboarding About NorthCTO Contact Book a consultation
Onboarding

Secure by onboarding. No upfront project fee.

Most providers treat onboarding as a chargeable project and security as a later upsell. We do the opposite. Every new client is brought up to a secure, resilient, Cyber Essentials-ready standard as part of joining — with the cost built into your monthly service, not billed as a shock upfront.

What “secure by onboarding” means

You start secure. Not eventually — from the start.

Joining NorthMSP isn’t a slow handover that leaves the risky bits for later. We bring your environment up to a known-good, defensible baseline as part of onboarding — the same foundation every client gets.

Multi-factor authentication

Enforced across all users, with legacy authentication blocked — the single biggest reduction in account-takeover risk.

Conditional access

Policy-based access that blocks risky sign-ins without getting in your team’s way.

Microsoft 365 hardened to the CIS benchmark

Your tenant configured to a recognised, defensible standard — then kept from drifting.

Endpoint protection & patching

EDR on every device and managed patching, so machines are defended and kept current automatically.

Tested, isolated backup

Recovery you’ve actually proven, so an incident is recoverable rather than terminal.

Cyber Essentials certification

Remediation and certification rolled into your service — not left as a someday job, and not billed as a separate project.

The onboarding journey

From handover to certified, step by step.

A clear, low-disruption path that fixes the foundations and the security in the right order — with no surprise invoices along the way.

1

Assess

We start with a structured review of your infrastructure, Microsoft 365 tenant, security posture, backups and risks. This also scopes exactly what “secure” means for your environment, so nothing is open-ended.

Technical discoveryRisk & gap reportScoped baseline
2

Stabilise

We fix the foundations first — identity, backup, patching, monitoring and documentation — clearing the critical risks that leave you exposed. This is where most of the value lands early.

FoundationsDocumentationQuick risk wins
3

Secure

We bring the environment up to the secure baseline — MFA, conditional access, endpoint protection and a CIS-aligned Microsoft 365 configuration — so you’re defended by design.

CIS-aligned hardeningEndpoint securityTested recovery
4

Certify

We close the remaining gaps and take you through Cyber Essentials — included in your service, giving you something clients, insurers and regulators recognise.

Cyber EssentialsInsurer-readyIncluded in service
5

Embed & support

With stable, secure, certified foundations in place, we support the environment long term — monitoring, reviews and senior guidance — and keep the baseline from drifting.

Ongoing supportService reviewsDrift control
The commercial model

No upfront fee. Here’s the honest version.

The upfront onboarding fee is the most-hated, most-negotiated line item in our industry. We’ve removed it — not by skipping the work, but by funding the remediation and certification ourselves and recovering the cost gradually through your monthly service. In return, we ask for a minimum term. Certification assumes your in-scope systems can be brought up to standard — if legacy or third-party kit gets in the way, we’ll tell you early rather than spring it on you. That’s the deal, stated plainly.

No separate upfront onboarding charge — the cost is amortised into your monthly fee
Remediation is scoped by the onboarding assessment, so it’s defined, not open-ended
Cyber Essentials remediation and certification included — not billed as a separate project
Hardware, licensing, third-party services and larger transformation projects are scoped and quoted separately
Typically a 24-month minimum term, then rolling month to month
One standard, two depths

Every client gets Secure. Regulated clients step up to Assured.

The baseline you’re brought up to during onboarding is our Secure tier. If you answer to a compliance regime — NHS secure email, payment handling, ISO 27001 or an insurer’s requirements — Assured adds the gap analysis, evidence and accreditation support on top.

Related guidance

Before you move, read these.

Useful context if you are changing provider, reviewing Cyber Essentials or trying to understand what a secure baseline should include.

Provider change

How to Change IT Provider Without Losing Control

A practical handover guide covering admin access, ownership, documentation and stabilisation.

Read the guide ->
Compliance

Cyber Essentials Is Not the Finish Line

Why certification matters, but the operating standard behind it matters more.

Read the guide ->
Microsoft 365

Microsoft 365 Security Baseline for SMEs

The identity, admin, app consent and mail controls that sit at the heart of secure onboarding.

Read the guide ->
Let’s talk

Start secure. Stay supported.

If you’re tired of being quoted a fat onboarding fee to fix problems you didn’t cause, let’s have a straight conversation about joining — what we’d secure first, and how the no-upfront-fee model works for you.