Case study · Perth metro

A Perth-metro legal & accounting SMB, with the right SOC reading the environment.

Anonymised engagement. Industry, location and headcount band shared with permission; the firm name, partner names and client list are not. Read the detail for the challenge that brought the firm to a Perth-only firm, the work we did in the first 90 days, and what changed in the year that followed.

Engagement snapshot

Industry

Legal & accounting SMB

Location

Perth metro (CBD, Osborne Park, Fremantle)

Headcount band

25–40 staff

Active engagement. Anonymised at the firm’s request — confidentiality is the product for a legal practice, and the posture delta speaks for itself.

Challenge

A ticketed-only model that opened one ticket per week and closed none of the underlying risk.

The practice ran on an interstate MSP whose contract was structured around tickets, not outcomes. Tickets opened on Monday sat open until Wednesday. Tickets opened on Friday sat open until the following Tuesday. After-hours reach went to a queue that sometimes returned the call by Wednesday of the following week — a problem when a partner needed a file or a dictation stream recovered at 9pm on a Friday.

On the security side, there was no SOC, no EDR coverage on the partner-track laptops, and no patching cadence. The practice had picked up one confirmed credential-stuffing incident in the quarter before the engagement started, and the team lead described the posture as “finger’s crossed, mainly”.

The internal threshold for action was a partner-driven one, not a ticketing one: confidentiality expectations from clients (legal work in particular), after-hours access patterns (accounting deadlines), and an operating footprint that had grown from one CBD suite to three metro sites without a corresponding investment in IT.

What Katalyst did

A Perth-staffed pairing — a named SOC analyst + a visit-share on-site engineer.

We replaced the per-ticket support model with a managed IT pairing: a rostering share of our SOC reading the environment 24/7 from Perth AWST, and a named on-site engineer carrying one of the three metro sites on a published visit cadence. The partner track ran on EDR with managed detection plus a written runbook for credential-stuffing style attempts; the practice plan covered patching, M365 hardening and a monthly posture check written into the engagement rather than the brochure.

Tickets stopped being the unit of work. The Perth analyst owns the environment end-to-end, so a partner who reports a problem at 9pm gets the same engineer who has been reading their environment all evening — not the next ticket in a different timezone. The on-site engineer carries a defined visit slot at the CBD site and a published road cadence for the Osborne Park and Fremantle branches; on-site is reserved for work that genuinely benefits from being physically present, not the default.

The data-exit runbook was written down at week two rather than at the end of the engagement — same export format, same credential rotation, same access revocation, same written confirmation of log retention deletion. The partners kept the runbook. The point of writing it down was that it was no longer subject to how anyone felt on a given Monday.

Outcome

From one security incident per quarter to none over the following 12 months — and a partner-side service standard the practice could actually quote.

Across the 12 months after handover, the practice recorded zero confirmed security incidents — down from the credential-stuffing incident and two near-misses in the quarter before. Patching cadence moved from “whenever we get to it” to a measured weekly pass with a named owner and a weekly report the partners read. EDR coverage on the partner-track laptops went from zero to 100% in the first month, with detection tuned for partner-track usage rather than office-worker defaults.

Ticket SLA, which had been the practice’s primary frustration, moved from a two-day median to a same-business-day acknowledgement and a 4-hour median resolution during the AWST window. After-hours reach, which had been the secondary frustration, stopped returning a callback as a measure of success — the partner on the call was the engineer who had been reading their environment all evening.

Most measurably: the partners stopped describing their IT setup as a thing they worried about and started describing it as a thing they could quote to clients. The engagement does not advertise itself as a reference, in line with the firm’s confidentiality posture — but the FY-by-FY posture delta, measured on the agreed dashboard, is real, and the partners read the dashboard monthly.

Next step

See what the same pairing would look like for your operation.

Same business day, an engineer from our Perth SOC reads your intake and books a 30-minute call. You walk away with a written snapshot of your IT and security posture — even if you never sign with us.

Free assessment. Written snapshot is yours to keep regardless of whether you sign.