PCO / IT & Managed Services Practice Protection
IT & Managed Services · Practice Protection · South Africa

IT & Managed Services Firm protection when the principal cannot give instructions.

For IT consultancies, MSPs and cloud/service firms where one principal may hold privileged access to many client environments, critical credentials, vendor accounts and incident knowledge.

The practical problem

Trusted people are not the same as tested authority.

PCO looks at what must keep working when the normal decision-maker is unexpectedly unavailable and unable to give instructions — who steps in, what they may do, which systems they can use, what limits apply and what still depends on a professional, provider or formal approval.

Practice structures

The Diagnostic changes with the way the practice is structured.

01 · Structure

Solo consultant

One technical principal holds most client and administrative access.

02 · Structure

Small technical team

A few engineers share client and operating responsibilities.

03 · Structure

Managed-service firm

Multiple technicians, clients, vendors and privileged systems create a wider control environment.

Profession-specific focus

What PCO would examine in a it & managed services practice.

Privileged access
Password vault / MFA
Client tenants
Domain & cloud admin
Incident response
Vendor portals
Change approvals
Billing & SLAs
Questions that matter

The Diagnostic tests the operating reality, not just whether a document exists.

Examples from the IT & Managed Services pathway:

01If the principal is unreachable during a ransomware incident or client outage, who can enter the client tenant without the principal’s MFA device?
02Are domain registrar, cloud-admin, backup, security and password-vault recovery routes held by more than one authorised person?
03Can the team distinguish emergency technical access from authority to approve a client-impacting change or spend?
04Who can contact critical vendors, cyber insurers or client decision-makers with the evidence needed during an incident?
05Which renewals, certificates, domains, licences or client SLAs could fail quietly if they sit only in the principal’s inbox?
Practice Protection Diagnostic fees

Three structures. A defined entry price for each.

The Diagnostic price reflects the amount of work normally created by the profession and structure. Guided Protection Review and Practice Protection Plan fees are scoped only after the Diagnostic.

Solo consultant
R4,500
excl. VAT · standard published scope

Profession-specific Practice Protection Diagnostic for this structure.

Small technical team
R6,500
excl. VAT · standard published scope

Profession-specific Practice Protection Diagnostic for this structure.

Managed-service firm
R9,500
excl. VAT · standard published scope

Profession-specific Practice Protection Diagnostic for this structure.

Standard published scope: one legal entity and an ordinary small-to-medium professional practice. Multi-entity groups, more than 10 professionals, or more than two operating locations / branches are confirmed by PCO before payment.
The full Diagnostic

Twelve protection areas have to work together.

01Decision responsibilityWho normally decides, who can step in, and where decisions must escalate.
02Professional eligibilityRegistration, scope, competence, supervision or other eligibility required for regulated work.
03Client / patient / matter handoverWhat is live, urgent, incomplete or at risk if the principal stops giving instructions.
04Records & information custodyWho may see records, what must stay confidential, and how access is controlled.
05Systems & authenticationNamed-user access, portals, MFA, recovery routes and single-person credential dependencies.
06Money & payment limitsBanking, payroll, suppliers, refunds, client money where relevant, approval limits and backups.
07Contracts, mandates & approvalsWho may instruct, approve, sign, vary, renew or escalate commitments.
08Providers & third partiesBanks, SARS, regulators, laboratories, insurers, vendors and other external dependencies.
09Deadlines & renewalsFilings, court dates, project milestones, licence renewals, audits and client promises.
10Staff & operating coordinationWhat managers and staff may do, where their limits sit, and what cannot be casually delegated.
11Escalation & prohibited actionsWhat must not be done without the principal or required professional/provider approval.
12Evidence, testing & reviewWhat proves the arrangement exists, who accepted the role, and whether access and fallbacks were tested.
How it works

From free indication to a controlled plan.

01Free AssessmentFive profession-specific questions and a mini report.
02Practice Protection DiagnosticPCO tests the full 12-area pathway and produces findings.
03Guided Protection ReviewResponsibilities, limits, evidence and fallbacks are worked through.
04PPP + NEXUSApproved arrangements become a managed Practice Protection Plan.
Important boundary: neither the free assessment nor the Diagnostic verifies that a POA, bank mandate, professional registration, provider permission, system entitlement or other arrangement is legally or operationally effective merely because the client says it exists. PCO identifies and tests the dependency; the relevant adviser, institution, regulator or provider confirms what only they can confirm.
Two useful starting questions

Would the practice know what to do tomorrow?

01If the principal is unreachable during a ransomware incident or client outage, who can enter the client tenant without the principal’s MFA device?
02Are domain registrar, cloud-admin, backup, security and password-vault recovery routes held by more than one authorised person?
Related profession pathways

Explore other professional practices.