Infrastructure overhaul and managed IT support for a Melbourne ecology consultancy
A 25-person ecology consultancy in Melbourne came to us after a poor experience with their previous managed services provider. Services they were paying for had simply never been delivered, infrastructure had been left to age past end of life, and a Windows Server 2012 R2 machine sat exposed to the internet. We rebuilt their infrastructure from the ground up, secured 3TB of data that had never been backed up, and delivered a five-year strategy so the business always knows what’s coming. Just as importantly, we rebuilt their trust in what an IT partner is supposed to be.
The challenge
The business’s relationship with IT was broken. Their previous provider had promised services that were never delivered, and once those failures came to light, trust went with them. There were no proactive technology roadmaps, no known good state, and no clear direction. Leadership had no way of knowing what was actually in place, what was at risk, or what to invest in next.
Underneath the relationship problem sat serious technical debt. A Windows Server 2012 R2 machine, years past end of life, was exposed directly to the internet through RRAS. A legacy terminal server was still in use, but inconsistently.
Server hardware was eight years old, past end of life, and beginning to fail. The UPS protecting it had already failed. The network was a mess, Wi-Fi was unreliable, and 3TB of business data was not backed up anywhere.
Security controls were just as thin. Every user was a local administrator, and there were no device restrictions of any kind. For a business holding years of client project data, the combined risk was significant.
What we did
We started by establishing what was actually there, then rebuilt it properly.
The eight-year-old HP server was replaced with a new Dell R550, and the domain was upgraded from Windows Server 2012 to Server 2022, with Entra ID sync enabling password writeback and single sign-on. The legacy QNAP iSCSI storage was decommissioned. The 3TB of data that had never been backed up was secured, with Veeam Backup & Replication protecting backups to a new 10 gigabit Synology NAS for fast local backup storage.
The network got the same treatment. A Cisco Meraki MX firewall went in at the edge, closing off the exposed RRAS server and providing secure remote access through an SSO SAML VPN with MFA. Three end-of-life switches were replaced with a single 48-port Ubiquiti PoE switch, and new Wi-Fi infrastructure went in with a captive guest portal. The rack also held three dead UPS units that had simply never been taken away when replacements went in over the years. Those went to recycling, and a single 1.5kVA Eaton UPS now protects the equipment.
We introduced Microsoft Intune and Conditional Access to bring both company-owned devices and BYOD under control, replacing the everyone-is-an-admin free-for-all with proper, policy-driven access.
We completed a full scope and comparison of a migration of local data to SharePoint against what the business actually needed. With years of historical data and large ArcGIS map files in the mix, a hybrid approach made more sense: heavy geospatial and historical data stays on fast local storage, while SharePoint handles modern collaboration and opens the door to AI tools.
Finally, we delivered a five-year strategy plan and roadmap, so leadership can see exactly what IT investment is needed, when, and why.
The results
The business’s cybersecurity posture is unrecognisable from where it started. The internet-exposed legacy server is gone, end-of-life hardware is off the network, every device is managed, and remote access now runs through MFA-protected single sign-on, which also made the VPN experience noticeably better for staff.
Operational risk dropped just as sharply. Data that once existed in a single unprotected copy is now properly backed up, hardware is current and under warranty, and the five-year roadmap gives leadership clear markers for future investment at specific intervals rather than surprise failures.
The result they mention most, though, is the relationship. Staff get fast and personal support from people they enjoy dealing with, and leadership has an IT partner they trust.
“We switched from our previous IT managed service provider to Aus Advantage 5 months ago, and we have been extremely impressed with the quality of service and level of professionalism shown by Sean and his team. The staff at Aus Advantage are all friendly, knowledgeable and helpful, and their service portal is easy to navigate. As soon as we signed up with Aus Advantage, our IT setup was comprehensively analysed and promptly upgraded where necessary. All weaknesses in our IT security measures were immediately secured. Multiple other existing IT-related issues were identified and addressed within weeks. We now have the confidence and reassurance that our IT systems and security are in safe and expert hands.”Client, Melbourne ecology consultancy
Questions this project raised
How do you know when it’s time to change IT providers?
The clearest signs are promised services that never materialise, infrastructure quietly ageing past end of life, and no roadmap for what happens next. If you can’t get a straight answer about what’s in place and what it costs to maintain, the relationship is running on hope rather than management. A strategic IT roadmap shouldn’t be a premium extra; it should be the standard, reviewed with you regularly. It’s also normal for your IT needs to outgrow a provider. What suited a five-person startup rarely suits a fifty-person business, and moving to a partner that matches where you’re heading is a sign of growth, not disloyalty.
Is it dangerous to keep running end-of-life servers and software?
Yes. Once hardware or software reaches end of life, security updates stop, so every vulnerability discovered afterwards stays open forever. Attackers actively scan for exactly these systems because they know they can’t be patched. This client had a Windows Server 2012 R2 machine, unsupported since October 2023, exposed directly to the internet, which is about as inviting as it gets. If any part of your environment is past end of life, replacing or isolating it should be a priority, not a someday job.
Should a small business move everything to SharePoint or keep a local server?
It depends on the data. Modern collaboration, live documents, and AI tools like Copilot all work best in the cloud, so SharePoint is the right home for the files your team works in every day. Large or specialised datasets are a different story. Things like the ArcGIS map files in this case study are often faster and cheaper on local storage, and some legacy applications simply aren’t compatible with cloud file platforms. A hybrid approach, with heavy and incompatible data on-prem and everything collaborative in the cloud, frequently beats forcing everything one way.
Why does it matter if staff are local administrators on their computers?
Local admin rights let any program a user runs, including malware, make system-level changes. Removing them is one of the most effective single controls against ransomware. It’s also a core expectation across the major security frameworks: restricting administrative privileges is one of the ACSC Essential Eight strategies, appears in the higher tiers of SMB1001, and falls under privileged access management in ISO 27001.
See how we have helped other businesses
Could your business run like this?
Tell us where your IT is at and we will tell you, plainly, whether we can help. A straight conversation with an onshore engineer, no obligation.