This matrix clarifies the division of responsibilities between Superfast IT and the client. It supports transparency, informed decision making and alignment with NCSC guidance.
| Area of responsibility | Superfast IT responsibility | Client responsibility |
|---|---|---|
| General governance and security culture | Provide guidance on best practice, security controls and policy recommendations. | Maintain internal governance, enforce security policies, ensure users follow agreed procedures. |
| User endpoints (workstations, laptops) | Deploy security tools, configure devices securely, monitor health, apply patches, manage antivirus and updates within supported systems. | Ensure devices are used appropriately, report issues promptly and avoid unauthorised changes. Maintain compliance if using non-managed devices. |
| Servers (on-premises / cloud) | Manage, monitor and patch supported servers. Apply security baselines. Maintain backup routines where contracted. | Provide change approvals. Maintain any servers outside contracted scope. Ensure adequate hosting capacity. |
| Network infrastructure (firewalls, switches, Wi-Fi) | Manage supported firewalls, apply updates, enforce access controls and monitor security alerts. | Maintain and secure any unmanaged network devices. Approve configuration changes and maintain physical security of network locations. |
| Identity and access management | Manage Microsoft 365 or other identity platforms within contracted scope. Enforce MFA for administrative accounts. Support user lifecycle processes. | Approve access rights, maintain HR-driven joiner, mover and leaver processes. Ensure users protect their credentials. |
| Administrative and privileged access | Maintain secure administrative accounts, monitor admin actions, enforce MFA and follow least-privilege principles. | Do not share administrative credentials. Notify Superfast IT of role changes. Maintain responsibility for internally held privileged accounts not managed by Superfast IT. |
| Patch and vulnerability management | Apply patches to systems covered under the service. Monitor vulnerabilities and provide remediation recommendations. | Approve patch windows where required and ensure devices are powered on and available. Manage exceptions or delays in patching due to operational needs. |
| Security monitoring and detection | Monitor managed systems for alerts, suspicious activity and vulnerabilities. Respond according to incident procedures. | Report suspicious behaviour, emails or potential breaches promptly. Ensure staff follow safe practices. |
| Backups and disaster recovery | Configure, monitor and test backups where included in the service. Provide restoration support in accordance with SLAs. | Approve backup schedules and retention policies. Notify Superfast IT of critical data locations. Ensure users store data in designated backed-up systems. Carry out regular in-application back-ups where it is recommended by the manufacturer e.g. Sage. |
| Incident response | Lead investigation, containment and recovery of incidents related to managed systems. Provide updates and post-incident reports. | Cooperate with investigations, provide information as required and implement recommended security actions. |
| Software and application management | Support and manage applications specified within the contract. Provide updates where applicable. | Maintain licensing, ensure staff use software appropriately. Manage unsupported legacy applications unless explicitly included. |
| Third-party vendors and integrations | Manage third-party services where contracted and approved. Maintain secure integrations with supported providers. | Manage relationships and contracts with vendors not included in Superfast IT’s services. Notify Superfast IT before introducing new third-party systems. |
| Cloud platforms (Microsoft 365, Azure, etc.) | Apply secure configurations, manage permissions, monitor alerts and enforce security controls for in-scope platforms. | Maintain responsibility for configuration elements outside the contract. Implement organisational policies and compliance rules. |
| Physical security | N/A – outside managed scope except where Superfast IT manages on-site hardware. | Secure premises, prevent unauthorised physical access and protect hardware. |
| Compliance and data protection | Support clients with technical measures, provide evidence for audits where relevant, and maintain secure handling of client data. | Maintain legal responsibility for data controller obligations, policies and staff compliance. |
| Client change control | Implement agreed changes and advise on risk. | Approve changes, communicate business needs and manage change impact internally. |