Layer3 Logo

Pricing

How we price

Every organisation's number is different. The method behind it is not. This page publishes what gets counted, what sits inside the monthly fee, what is quoted separately, and what moves the number up or down.

Four

plans, from IT run properly through to security governance you can put in front of a board.

Per user

priced per user per month, excluding GST. Not per ticket, and not per hour.

24 or 36

month terms. Onboarding is discounted 25% at two years and 50% at three.

Small requests

small requests outside your agreement taking less than an hour are not charged; larger work is scoped first.

Layer3 has supported New Zealand organisations since 2005, from offices in Upper Hutt, Wellington and Auckland, under an ISO/IEC 27001-certified information security management system.

No price list

Why there is no rate card here

A published per-seat price is the easiest thing to put on a website and often the least reliable number for comparing providers.

We would rather publish the method than a number that only holds for an organisation we have never met. Three reasons.

01

The same number buys very different things

Two organisations of forty staff can carry completely different risk. One runs current hardware, has no compliance obligation and no insurer asking questions. The other has legacy systems, a customer due-diligence questionnaire and a board that wants evidence. A single per-seat figure hides the only difference that matters.

02

Scope is decided before price, not after

We validate users, devices, sites and systems first, then issue a service schedule and a price against it. A number quoted before that work is a guess, and the corrections all arrive later, as variations.

03

You would be comparing the wrong number

A lower monthly fee with 24/7 detection and response sold as an add-on is not cheaper. It is a different service. The comparison worth making is what is included, not what is advertised, which is why this page lists both.

The basis

What actually gets counted

Managed services are priced per user, per month, excluding GST. Five things set that number.

Users

The count follows your Microsoft 365 users with a company workstation. Frontline users - staff with no company workstation, working in web apps only - are counted separately and cost less. Part-timers and contractors who hold an account are users; a shared account is not a licence to halve the number.

Devices and servers

Workstations and servers carry the security tooling, so they carry licensing. Windows devices must be upgraded or replaced by Microsoft's published end-of-support date, and Apple devices must be registered in Apple Business Manager. An estate of ageing machines costs more to keep secure, and we will say so before you sign.

Sites and network

One office and six offices are not the same service. Firewall, switching and wireless management, secure site-to-site tunnels and static IPs are scoped to the sites you actually run.

The plan you choose

The largest single factor, and the one you control. Manage, Protect, Secure Edge and Sentinel differ in the depth of security coverage, response and governance support you receive, and in how much evidence you can put in front of an insurer, a customer or a board.

Coverage and response

Business hours support is standard on every plan. Whether a human security team is watching your environment at 2am is a plan decision, and it is the clearest line between Manage and everything above it.

What we do not count

Tickets, phone calls and hours. Support is unlimited and SLA-backed on every plan. Charging by the ticket makes asking for help expensive, and we would rather you asked.

The ladder

Four plans, one ladder

Every plan includes the managed IT foundation. Higher plans increase the security coverage, governance and evidence Layer3 provides.

Plan 01

Manage

Essential posture

IT run properly, with a practical security baseline.

Best fit: organisations that need IT run properly and nothing more. Suitable where risk is low and no board or insurer is asking for evidence.

What you get

  • Service desk with unlimited support and clear SLAs
  • Endpoint monitoring, patching and maintenance
  • Microsoft 365 administration and management
  • Next-gen antivirus, endpoint detection and response, and application control
  • Cove 365 backup, domain protection (DMARC), and 30-day searchable security event retention (SIEM)
  • Monthly reporting and a light annual IT review

Recommended

Plan 02

Protect

Advanced posture

Managed IT with genuine prevention, visibility and 24/7 human response.

Best fit: organisations with cyber insurance, customer due-diligence questionnaires or governance expectations. The first plan to add 24/7 human response and the evidence needed for insurance, customer assurance and governance.

Everything in Manage, plus

  • Managed detection and response (MXDR) with a 24/7 SOC
  • Five SOAR response playbooks
  • Microsoft 365 security baseline and conditional access
  • Vulnerability monitoring
  • Security awareness training and phishing simulations
  • Annual strategy review, risk review and roadmap

Plan 03

Secure Edge

Zero Trust posture

Secure access and stronger control for hybrid and multi-site work.

Best fit: remote and hybrid teams, several offices, private cloud or legacy applications. Anywhere the old idea of a secure office network no longer describes how your people actually work.

Everything in Protect, plus

  • SASE cloud firewall and secure access policy
  • LAN Zero Trust and Zero Trust network access, replacing VPN
  • Firewall, switching and wireless management as scoped
  • 90-day SIEM retention with unlimited SOAR playbooks
  • One static IP and one secure site-to-site tunnel included
  • Secure access and risk reviews twice per year

Plan 04

Sentinel

Governed posture

High-touch managed IT with mature, evidenced security governance.

Best fit: higher-risk organisations, professional services, regulated environments, and any board that needs to demonstrate continuous security improvement rather than assert it.

Everything in Secure Edge, plus

  • Governance, risk and compliance programme with a formal roadmap
  • One year of searchable security event retention (SIEM)
  • Advanced email protection and managed password security
  • Board-ready reporting on posture, incidents and progress
  • Quarterly vCIO, risk and security review cadence
  • Mobile device security, two static IPs and unlimited tunnels

Final scope is confirmed in the service schedule. Each plan is also available alongside an internal IT team - see co-managed IT and support.

At a glance

How the four plans differ

The capabilities that actually separate one plan from the next. Final scope is confirmed in the service schedule.

Scroll the table sideways to see all four plans.

Capability

Manage

Protect

Secure Edge

Sentinel

Security posture

Essential

Advanced

Zero Trust

Governed

Managed IT support and Microsoft 365

Included

Included

Included

Included

Application control

Included

Included

Included

Included

Backup, archiving and domain protection

Backup and DMARC

Long-term archiving

Long-term archiving

Advanced email security

24/7 managed detection and response (SOC)

Not included

Included

Included

Included

User risk: awareness training and phishing tests

Not included

Included

Included

Full programme

Secure access and Zero Trust (SASE)

Not included

Optional

Included

Included

Vulnerability management

Not included

Continuous monitoring

Continuous monitoring

With remediation planning

Mobile device security

Not included

Not included

Optional

Included

Security event retention (SIEM)

30 days

30 days

90 days

One year

Todyl security platform tier

EDR

Special

Advanced

Complete

Strategy and governance cadence

Light annual review

Annual review

Twice per year

Quarterly vCIO

Security maturity target (SMB1001)

Bronze

Bronze

Silver

Gold

Indicative investment

On request

On request

On request

On request

Delivered with Todyl, ThreatLocker, ConnectSecure, uSecure, PowerDMARC, Cove 365 Backup, Avanan and 1Password. The stack is cumulative by design: each plan carries everything below it.

Inside and outside

What the monthly fee covers

Every provider draws a line between the agreement and the work quoted separately. Here is ours, in writing, before you compare it to anyone else's.

Inside the monthly fee

Included at every plan, for the users and systems named in your service schedule.

  • Service desk and SLAs

    Unlimited, SLA-backed support. Not a monthly allowance of hours, and not per ticket.

  • Monitoring, patching and maintenance

    Endpoints and servers monitored, patched and maintained as a standing service rather than on request.

  • The security stack for your plan

    Every plan includes a defined security baseline. The ladder determines which tools are included and how much monitoring and decision-making Layer3 provides.

  • Microsoft 365 administration

    Identity, devices, policy and day-to-day administration. We manage Microsoft 365; the licences themselves are separate, below.

  • Backup, recovery and domain protection

    Cove 365 backup and DMARC domain protection, with long-term email archiving from Protect upward.

  • Reporting and review cadence

    Reporting on every plan, and a scheduled strategy and risk review whose frequency rises with the plan.

  • SMB1001 alignment

    Alignment to New Zealand's tiered cyber security standard is part of how we deliver managed IT, not a separate project. See SMB1001 certification.

Outside the monthly fee

Quoted separately, so the monthly fee stays a fee for the service rather than an average of everything.

  • Projects and major change

    Migrations, office moves, new sites and system replacements are scoped and quoted before they start.

  • Hardware and software

    Devices, servers and network equipment. Managed network hardware can instead be leased and included - see managed network.

  • Licensing

    Microsoft 365, security and backup licensing is quoted separately from the managed fee and itemised in your proposal. Vendor increases are passed through at cost, not marked up.

  • Onboarding and transition

    A one-off project, quoted up front and discounted by term. Set out in full below.

  • Remediation to standard

    If the environment is not at standard when we arrive, the work to get it there is planned and quoted with you. Burying it in the monthly fee would only hide it.

  • Third parties, freight and cabling

    Line providers, application vendors, freight at cost, and internal wiring and mounting. We can plan and arrange a contractor for cabling; third-party charges remain outside the monthly fee.

The under-an-hour rule

In-scope support is unlimited, with a single request covered for up to four hours. If a small request falls outside the agreement and takes less than an hour, we do not charge for it. Larger or planned work is scoped and quoted before it starts.

Onboarding and terms

What it costs to start

Onboarding is a managed transition project with a plan, milestones and named owners: a dedicated project manager and a senior engineer. It is quoted up front, and your agreement term determines the onboarding discount.

Standard

Quoted up front, before anything moves. Typically about one month's service fee.

Two-year term

25% off your onboarding.

Three-year term

50% off your onboarding.

Switching provider, three-year term

100% off your onboarding, and we waive our own fees for the time left to run on your existing agreement, so you never pay two providers at once. See switching to Layer3.

The term

Agreements run for 24 or 36 months. The longer term carries the larger onboarding discount. Every managed agreement also includes a 90-day exit option if the service is not working for you. Pricing and service levels are subject to verification of final requirements, which is what the scoping stage is for.

What the renewal price accounts for

Three things, and we will show you which is which: cost movement across the term since your last agreement was priced; vendor and licensing increases, passed through at cost rather than marked up; and changes to the tooling inside the plan as security products are added, replaced or retired.

Getting to standard

If the environment is not where it needs to be, we plan that work with you and quote it separately rather than spreading it silently across the monthly fee. You see the gap, the cost of closing it, and the order it happens in.

Price drivers

What moves the number

Two organisations the same size rarely pay the same. These are the reasons, in the order they usually matter.

Moves it up

Legacy infrastructure

Unsupported operating systems, ageing servers and devices past their end-of-support date cost more to secure and more to keep running. They also fail more often, which shows up as support demand.

Moves it up

Insurance and due diligence

Cyber insurers and enterprise customers now ask specific questions. Answering them honestly means 24/7 detection, searchable logging and evidence, which is Protect and above rather than Manage.

Moves it up

Compliance and audit

Regulated work, privacy obligations and audit cycles need a governance programme and board-ready reporting, not just good tooling. That is what pulls an organisation toward Sentinel.

Moves it up

Sites, and how people connect

Several offices, private cloud, legacy applications and genuinely remote work all move protection away from the building and onto the person and the device. That is Secure Edge.

Brings it down

A current, standard environment

Devices in support, identity in one place, no unsupported systems and no undocumented exceptions. This is the single biggest thing an organisation can do to lower its own number, and most of it is decisions rather than spending.

Brings it down

Term length

A longer commitment takes 25% or 50% off onboarding, and 100% if you are moving to us from another provider. It does not buy a cheaper monthly fee; it takes the cost out of starting.

Comparing providers

Six questions worth asking, including of us

Two monthly fees are only comparable once you know what each one contains. These six questions get you there faster than a proposal will.

Question 01

Is 24/7 detection and response included, or is it an add-on?

Ask where the security operations centre is, who staffs it, and whether a human responds at 2am. If it is an add-on, the advertised monthly fee is not the number to compare.

Question 02

How long are security logs kept, and who reads them?

Retention is the difference between knowing what happened and guessing. Ask for the number of days, then ask who actually reviews the alerts and what they are expected to do about one.

Question 03

What sits inside the monthly fee, and what is quoted separately?

Every provider draws the line somewhere. Ask where theirs is, in writing, before comparing two numbers. A fee that covers less is not a lower price.

Question 04

What standard is the service aligned to, and what level are we at?

"Secure" is a feeling. A named level against a published standard is a position you can track, evidence and improve. Ask which standard, which level, and how you move up it.

Question 05

Is the provider itself audited?

You are giving an outside organisation administrative access to everything you run. Ask what standard they are held to, who audits them against it, and how recently.

Question 06

What moves the price at renewal, and by how much?

Ask whether vendor increases are passed through at cost or marked up, what happened at the last two renewals, and how much notice you get before a change takes effect.

Common questions

Questions we get asked about pricing

The seven that come up in almost every first conversation.

Because a per-seat figure would be right for almost nobody. Two organisations of the same size can carry completely different risk, run completely different equipment and face completely different obligations, and a single published number hides all of it. What we publish instead is the method: what gets counted, what sits inside the fee, what is quoted separately, and what moves the number.

Per user, per month, excluding GST. The count follows your Microsoft 365 users with a company workstation. Frontline users - staff with no company workstation, working in web apps only - are counted separately and cost less. Devices and servers still affect the number, because they carry the security tooling and its licensing, but the user is the unit.

No. We manage Microsoft 365; the licences themselves are quoted separately from the managed fee and itemised in your proposal. The same applies to security and backup licensing. Vendor increases are passed through at cost rather than marked up.

Yes, and it is quoted up front before anything moves. Onboarding is a real project - a dedicated project manager, a senior engineer, a shared plan with milestones and named owners - and it is typically about one month’s service fee. A two-year term takes 25% off it and a three-year term takes 50% off. If you are switching from another IT provider on a three-year term, onboarding is 100% off - see switching to Layer3.

Not on Manage, and we would rather say so than imply otherwise. Manage covers operations, not assurance: there is no 24/7 threat response and no formal governance cadence. From Protect upward, managed detection and response with a 24/7 security operations centre is included in the plan, delivered through our long-standing partnership with Todyl. If you carry cyber insurance or report to a board, start at Protect.

24 or 36 months. The term does not buy a cheaper monthly fee; it takes the cost out of starting, through the onboarding discount. Pricing and service levels are subject to verification of final requirements, which is what the scoping stage exists to settle.

Then you are probably looking at co-managed IT rather than a full plan. We take whole functions - the ones that need 24/7 cover, specialist tooling or after-hours attention - and leave the rest with your team. It is priced the same way, against the scope actually handed over. See co-managed IT and support.

Next step

Let us put a number on it

A short conversation is enough to work out which level fits, what your environment needs before it gets there, and roughly what that costs. No obligation, and no proposal until the scope is real.

All pricing is in New Zealand dollars and excludes GST. Plan inclusions are subject to agreed scope, minimum requirements and the final service schedule, and pricing is subject to verification of final requirements. Additional costs may apply for onsite setup at regional locations.

Layer3

Book a discovery call - 30 minutes, no obligation