black header background

Red or REDD Managed Services: What You’re Actually Buying

Posted on September 19, 2026 in Uncategorized

If you typed “red managed services” and landed here, you are probably looking for REDD, a managed technology and cyber security provider with its head office in Toowong, Brisbane, working with businesses across Australia and New Zealand. The second thing you likely want to know is what “managed services” actually includes, because the term gets stretched to cover everything from a help desk phone number to running an entire IT department.

This article sets out what sits inside a typical managed services agreement, what usually sits outside it, and the questions worth asking before you commit to anyone.

What managed services means in practice

A managed service is an ongoing arrangement where an external provider takes responsibility for part or all of your technology, for a recurring fee, against agreed response times. You are not buying hours. You are buying an outcome: the systems work, someone is watching them, and when they break there is a defined path to getting them fixed.

That usually breaks into a few areas:

  • Service desk. Day to day support for staff. Password resets, a laptop that will not connect, a printer that has stopped talking to the network.
  • Monitoring and maintenance. Patching, updates, backups, disk space, certificate expiry. The unglamorous work that stops most outages before anyone notices.
  • Infrastructure and cloud. Servers, Microsoft 365 or Google Workspace tenancies, identity, networking, firewalls.
  • Security. Endpoint protection, monitoring for suspicious activity, access controls, and a response plan for when something gets through.
  • Strategy and planning. Budgeting for hardware refreshes, licence changes, and where the business is heading in two years rather than two weeks.

REDD’s managed technology services sit in this space, with cyber security treated as its own discipline rather than a tick box inside the support contract.

Break/fix, co-managed, or fully managed

Most businesses end up in one of three models. The right one depends on whether you already have internal IT staff and how much risk you can carry.

Break/fix Co-managed Fully managed
Who does the work Provider, when called Your team plus provider Provider
How you pay Per hour or per job Fixed fee for the agreed scope Fixed monthly fee
Best for Very small teams, low dependency on IT An internal IT person or small team needing depth No internal IT, or IT that should be doing higher value work
Response times Usually best efforts Defined for provider scope Defined across the board
Who owns the risk You Shared, and worth writing down clearly Largely the provider, within scope
Main weakness Costs spike exactly when you can least afford them Boundaries get blurry if not documented You need to be sure the scope matches reality

The co-managed trap is worth naming. If nobody writes down who patches the firewall, it does not get patched. Insist that the split is in the agreement, not in someone’s head.

What is usually not included

Read any managed services quote with this in mind: the monthly fee covers the agreed scope, and everything else is a project or a variation. Common exclusions include new site fit outs, office moves, major migrations, hardware and software licensing, third party application support where the vendor holds the contract, and out of hours work outside the agreed window.

None of that is a trick. It just means the number on page one is not the number you will spend in year one. Ask for the likely project work alongside the recurring fee so you can budget the whole thing.

Why cyber security has become the deciding factor

For a long time, managed IT was judged on how fast the phone got answered. That is still true, but it is no longer the thing that will put you out of business. Ransomware, business email compromise and credential theft are the three most common ways Australian businesses lose money to an incident, and the first two rely on people rather than software flaws.

A provider that takes this seriously will talk to you about multi factor authentication on every account, backup that is tested and separated from the live environment, restricted administrator access, and what happens in the first hour of an incident. If the security conversation is only about antivirus, keep asking questions.

The Australian Signals Directorate publishes the Essential Eight as a practical baseline. It is a reasonable common language to use with any provider: ask which of the eight you currently meet, at what maturity level, and what it would take to lift.

What to check before you sign

Response times, in writing. Not “we aim to respond quickly”. Actual hours by priority, and what counts as a priority one.

Who you will actually deal with. Is there a named account contact, and do engineers rotate constantly or do you get people who learn your environment?

Where the data and the admin credentials live. You should own your tenancies, your domains and your licences. If leaving a provider means losing access to your own systems, that is a problem to solve before you start, not after.

Onboarding. The first sixty to ninety days matter more than the rest. Ask what documentation gets produced, what gets remediated straight away, and what gets flagged as a project.

Exit terms. Notice period, offboarding assistance, and handover of documentation. Good providers are relaxed about this question.

References from businesses your size. A provider used to enterprise environments and one used to ten person offices work very differently.

Does location matter?

Less than it used to, and more than vendors admit. Most support is delivered remotely and that is genuinely fine for the bulk of issues. But someone needs to be able to stand in your comms room when a switch dies, and someone should be willing to sit in a room with your leadership team once or twice a year. Ask what on site attendance looks like, what it costs, and how it works if you have sites in more than one state.

REDD is based in Brisbane and works with organisations across Australia and New Zealand, so the practical question for any multi site business is how coverage is arranged outside the head office city. Worth raising early.

FAQ

Is it REDD or Red?

The business name is REDD, with two Ds. Plenty of people search for “red managed services” and mean the same thing. If you want to talk to someone directly, the contact page is the fastest route.

How is managed services priced?

Most providers price per user, per device, or as a fixed fee for an agreed scope. What moves the number is user count, how many servers or sites you run, whether security monitoring is included, and the hours you need covered. Be cautious comparing two quotes on headline price alone. Compare what is inside the scope first, then the number.

Can we keep our internal IT person?

Yes, and often you should. Co-managed arrangements let an internal person stay close to the business and the applications while the provider handles after hours cover, security monitoring and specialist work. The one thing to get right is a written split of responsibilities.

If you want a broader view of where the market is heading before you shortlist anyone, REDD’s rundown on managed IT and security services in Australia is a reasonable starting point.

Reach out!

If anything in this post interests you, or you'd like to have a chat with someone about your technology challenges, we would love to hear from you!