This matrix clarifies the division of responsibilities between Superfast IT and the client. It supports transparency, informed decision making and alignment with NCSC guidance.

Area of responsibility Superfast IT responsibility Client responsibility
General governance and security culture Provide guidance on best practice, security controls and policy recommendations. Maintain internal governance, enforce security policies, ensure users follow agreed procedures.
User endpoints (workstations, laptops) Deploy security tools, configure devices securely, monitor health, apply patches, manage antivirus and updates within supported systems. Ensure devices are used appropriately, report issues promptly and avoid unauthorised changes. Maintain compliance if using non-managed devices.
Servers (on-premises / cloud) Manage, monitor and patch supported servers. Apply security baselines. Maintain backup routines where contracted. Provide change approvals. Maintain any servers outside contracted scope. Ensure adequate hosting capacity.
Network infrastructure (firewalls, switches, Wi-Fi) Manage supported firewalls, apply updates, enforce access controls and monitor security alerts. Maintain and secure any unmanaged network devices. Approve configuration changes and maintain physical security of network locations.
Identity and access management Manage Microsoft 365 or other identity platforms within contracted scope. Enforce MFA for administrative accounts. Support user lifecycle processes. Approve access rights, maintain HR-driven joiner, mover and leaver processes. Ensure users protect their credentials.
Administrative and privileged access Maintain secure administrative accounts, monitor admin actions, enforce MFA and follow least-privilege principles. Do not share administrative credentials. Notify Superfast IT of role changes. Maintain responsibility for internally held privileged accounts not managed by Superfast IT.
Patch and vulnerability management Apply patches to systems covered under the service. Monitor vulnerabilities and provide remediation recommendations. Approve patch windows where required and ensure devices are powered on and available. Manage exceptions or delays in patching due to operational needs.
Security monitoring and detection Monitor managed systems for alerts, suspicious activity and vulnerabilities. Respond according to incident procedures. Report suspicious behaviour, emails or potential breaches promptly. Ensure staff follow safe practices.
Backups and disaster recovery Configure, monitor and test backups where included in the service. Provide restoration support in accordance with SLAs. Approve backup schedules and retention policies. Notify Superfast IT of critical data locations. Ensure users store data in designated backed-up systems. Carry out regular in-application back-ups where it is recommended by the manufacturer e.g. Sage.
Incident response Lead investigation, containment and recovery of incidents related to managed systems. Provide updates and post-incident reports. Cooperate with investigations, provide information as required and implement recommended security actions.
Software and application management Support and manage applications specified within the contract. Provide updates where applicable. Maintain licensing, ensure staff use software appropriately. Manage unsupported legacy applications unless explicitly included.
Third-party vendors and integrations Manage third-party services where contracted and approved. Maintain secure integrations with supported providers. Manage relationships and contracts with vendors not included in Superfast IT’s services. Notify Superfast IT before introducing new third-party systems.
Cloud platforms (Microsoft 365, Azure, etc.) Apply secure configurations, manage permissions, monitor alerts and enforce security controls for in-scope platforms. Maintain responsibility for configuration elements outside the contract. Implement organisational policies and compliance rules.
Physical security N/A – outside managed scope except where Superfast IT manages on-site hardware. Secure premises, prevent unauthorised physical access and protect hardware.
Compliance and data protection Support clients with technical measures, provide evidence for audits where relevant, and maintain secure handling of client data. Maintain legal responsibility for data controller obligations, policies and staff compliance.
Client change control Implement agreed changes and advise on risk. Approve changes, communicate business needs and manage change impact internally.