What DTC Does — Complete Service Catalog
Provided by DTC Inc. | Reviewed Annually | Version 2.0 — September 2026
This document lists everything DTC offers, grouped by what it does for your organization. It is a catalog, not an invoice.
Important: This page shows the full range of what we offer. It does not mean every item is active in your environment. What DTC actively manages for you is defined by your signed Service Agreement and Statement of Work. If you want to know what is switched on today — or what it would take to switch something else on — ask your DTC account team.
How to read this document
| Marker | What it means |
|---|---|
| ✅ Included | Part of every DTC managed services agreement. No separate charge. |
| ⭐ Full Service Suite | Included for clients on the Full Service Suite. Available to add on its own. |
| ➕ Available | Added to your agreement when you want it, or quoted as a project. |
| 🔜 Coming soon | In development. Not yet available to order. |
There are two service levels, and the difference between them is straightforward:
- Managed Services (base) — everything needed to run and defend an organization day to day, including 24/7 monitored detection and response on both your computers and your Microsoft 365 accounts.
- Full Service Suite — the base, plus vulnerability management and the DTC engineers who act on what it finds. This is the level we recommend.
Pricing is not listed here because it depends on the size and shape of your environment. Your account team will quote against your Service Order Form.
🏢 Industries we serve
The service catalog below is the same regardless of what business you are in — the same monitoring, the same security baseline, the same help desk. What changes is which parts matter most, which applications we have to protect, and which regulations you answer to.
Find your row. The catalog that follows is the menu; this table is what we would emphasize for you.
| Industry | What is different about your environment | What we emphasize |
|---|---|---|
| Dental & oral health | Practice management and imaging software with hard version dependencies — Dentrix, Eaglesoft, Open Dental, Curve, SoftDent alongside DEXIS, Carestream, Romexis, Dolphin, i-CAT, Sidexis. Sensors, scanners and CBCT units tied to specific driver versions. Imaging data is large and grows fast. | Patch review before approval — an auto-approved update that breaks imaging closes the schedule. BDR, because downtime is measured in cancelled appointments. HIPAA safeguards. |
| Medical & healthcare | EHR and PACS platforms — Epic, Cerner/Oracle Health, athenahealth, eClinicalWorks, NextGen, Merge, Ambra. Imaging modalities and biomedical devices that often cannot be patched and must be isolated instead. | Network segmentation for medical devices. HIPAA safeguards, encryption, and audit evidence. BDR with tested recovery. |
| Defense contracting (DoD) | Controlled Unclassified Information (CUI) on your network, CMMC obligations flowing down through your contracts, CAC/PIV authentication, and government-furnished equipment. | The technical practices behind CMMC and NIST SP 800-171, GCC High Microsoft tenants where required, managed SIEM with log retention, Zero Trust access, and evidence your assessor and your compliance consultant can rely on. |
| Accounting & financial services | QuickBooks, Sage, NetSuite, Dynamics or SAP holding your clients' financial records. Extreme seasonality — an outage in filing season costs more than the same outage in July. You are also a top target for wire fraud and business email compromise. | Security awareness training and email threat protection, because the attack comes as an email asking for money. Encryption, MDR, and the documentation that supports a written information security plan. |
| Manufacturing, construction & field services | ERP and job costing — Epicor, Infor, Sage, Dynamics 365, JobBOSS² — plus CAD workloads with very large files, and project platforms like Procore, Sage 300 or Buildertrend. Shop-floor machine controllers frequently run operating systems that cannot be patched or replaced. Jobsites and field crews need access from outside the building. | Isolating production equipment from the business network, so an unpatchable controller is not an open door. BDR, because a stopped line has an hourly cost. Application control, and remote access built for the field. |
| Transportation & logistics | Dispatch, ELD and telematics platforms your operation cannot run without. Devices and people are mostly not in the building — they are in vehicles, at terminals, and on customer sites. Connectivity is the single point of failure. | Zero Trust access rather than VPN for roaming users, monitoring that works on devices which are rarely on the office network, redundant connectivity, and MDR that does not depend on a machine coming back to the office. |
| General business & commercial | CRM, payroll, accounting and point-of-sale systems. If you take card payments, PCI-DSS applies to whatever touches that data. | The full base stack, network segmentation to keep card processing out of scope where possible, and awareness training for the whole team. |
Regulatory frameworks we work within
During onboarding we ask which of these apply to you, and we design and document accordingly.
| Framework | Who it applies to | What DTC contributes |
|---|---|---|
| HIPAA | Dental, medical, and anyone handling protected health information | Technical safeguards, encryption, access control, audit logging, and a Business Associate Agreement |
| CMMC (Levels 1–3) / NIST SP 800-171 | DoD contractors and subcontractors handling CUI | Readiness assessment, control implementation, GCC High tenancy where required, and the evidence package an assessor asks for |
| FTC Safeguards Rule / GLBA / IRS Pub. 4557 | Accounting, tax preparation, and financial services firms | MFA, encryption, monitoring, and the technical documentation behind a written information security plan |
| PCI-DSS | Anyone processing credit card payments | Segmentation to reduce what falls in scope, plus the required technical controls |
| State privacy laws (CCPA, VCDPA and similar) | Anyone holding consumer personal information at scale | Data inventory, access control, and breach-response readiness |
If you are a defense contractor, read this twice. An IT provider that touches your CUI falls inside your assessment scope. That means our own controls become part of your compliance story. We plan for that with you at the start rather than letting you discover it during an assessment.
🎧 Support & Service Desk
The part of DTC your team actually talks to.
| Service | What it covers | Level |
|---|---|---|
| Help desk | Unlimited remote support for your staff — phone, email, or portal ticket | ✅ Included |
| Onsite support | Unlimited onsite support during business hours when a problem cannot be solved remotely | ✅ Included |
| After-hours and weekend coverage | Scheduled work and emergency response outside business hours, plus Saturday morning on-call remote coverage | ✅ Included |
| Consulting — DTC T3 engineers | Access to DTC's own senior (T3) engineers for the questions that are not a break/fix ticket: how to approach a change, whether a vendor's recommendation makes sense, how to plan around a system you are outgrowing. Included at a minimum monthly rate. These are our engineers, not a subcontracted help line — the same people who know your environment. | ✅ Included |
| Line-of-business application support | Support for the software your organization actually runs on — practice management and imaging, ERP and job costing, dispatch, accounting, CRM and point-of-sale — including coordinating with the software vendor on your behalf | ✅ Included |
| Specialized equipment troubleshooting | When an imaging unit, scanner, plotter or piece of production equipment stops talking to the computer it depends on, we troubleshoot the connection, the drivers and the workstation, and coordinate with the equipment vendor. Note that this is support, not management — see below for what we monitor and inventory. | ✅ Included |
| DTC Client Portal | Submit and track tickets, review quotes and invoices, approve work, manage payment methods, see your account team | ✅ Included |
| Secure remote console access | MFA- or passkey-protected remote access to your own office computers — for staff and principals working away from the office | ➕ Available |
Hours of operation
| When | Coverage |
|---|---|
| Monday – Friday, 7:30 AM – 5:30 PM | Unlimited remote service. Unlimited onsite support. |
| Monday – Friday, 5:30 PM – 10:00 PM | After hours — scheduled calls or emergencies only. |
| Saturday, 8:00 AM – 1:00 PM | On-call remote service. |
| Sunday and holidays | Closed. Emergency escalation paths remain in place for critical outages. |
Target response times: 4 business hours for hardware and software support, 48 business hours for scheduled maintenance and repair. Actual response varies with business impact — an outage that stops you serving customers comes first.
🏗️ Infrastructure Management
Keeping the computers, servers, and network your organization runs on healthy, current, and monitored.
| Service | What it covers | Level |
|---|---|---|
| Endpoint monitoring & alerting | 24/7 monitoring of workstations and servers — disk health, performance, service failures, offline devices | ✅ Included |
| Patch management | Windows and third-party application patching. Every patch is researched and scored by a DTC engineer before it is approved — nothing auto-approves. | ✅ Included |
| Firmware & driver management | Managed firmware and driver updates on business-class hardware from Dell, Lenovo and HPE, where the manufacturer provides tooling that lets us do it safely and automatically. Not available on white-box or custom-built machines, or on hardware old enough that the manufacturer no longer supports it — there is no reliable way to automate those, and we would rather tell you than pretend. | ✅ Included (supported hardware) |
| Server & virtualization management | Management of your physical servers and the virtual machines running on them — domain controllers, file and data servers, application servers | ✅ Included |
| Hardware & software lifecycle tracking | End-of-life tracking for hardware and operating systems, so replacements are planned rather than urgent | ✅ Included |
| Real-time asset inventory | A live inventory of your computers and servers, plus the network equipment we can actually manage — UniFi devices and your firewall. Always current, not a quarterly snapshot. | ✅ Included |
| Managed firewall | UniFi firewall — policy management, firmware updates, VPN, DNS forwarding, default-deny outbound rules. DTC-leased or client-purchased. | ➕ Required line item |
| Managed switching | UniFi switches — configuration, VLAN segmentation, firmware, monitoring | ➕ Available |
| Managed Wi-Fi | UniFi access points — coverage design, separation of guest and production networks, firmware | ➕ Available |
| Network segmentation | Separating what should not talk to each other — guest Wi-Fi, card processing, medical devices, production and shop-floor equipment, building systems | ➕ Available |
| Site-to-site and remote VPN | Encrypted connections between locations, terminals or jobsites, and for approved remote users | ➕ Available |
| Security cameras | Camera systems, installation and management | ➕ Available |
| Structured cabling | Physical network cabling — new drops, new sites, remediation of existing cabling | ➕ Available |
What is under management — and what is not
This distinction matters, because "you manage our IT" and "you manage every device with a power cord" are different promises. We only make the one we can keep.
| Devices | What that means | |
|---|---|---|
| Monitored, inventoried and managed | Workstations, laptops and servers running Windows or macOS. UniFi network equipment. Your firewall. | Live inventory, health monitoring, patching, alerting, and remote support. These are the devices your agreement is priced on. |
| Supported, but not managed | Imaging units and sensors, panoramic and CBCT units, scanners, plotters, production and shop-floor equipment, and other industry-specific hardware. | We troubleshoot them and work with the vendor when they break. They are not monitored, not inventoried, and not patched by us — the manufacturer does not expose a way for us to do that. |
| Out of scope | Televisions and displays, consumer streaming devices, unmanaged switches, and other equipment with no management interface at all. | There is nothing to manage. If one of these causes a network problem we will help you find it, but it is not a managed device and is not covered. |
If a device matters to your operation and is not on the managed list, tell your account team. Sometimes the answer is to isolate it on its own network segment instead — which protects you from it, and it from everything else.
🔒 Security
Every DTC managed client has 24/7 monitored detection and response before adding anything. It is not an upgrade.
Detection & response — included as standard
| Service | What it covers | Level |
|---|---|---|
| Device MDR (Managed Detection & Response) | A 24/7 staffed security operations center watching your computers and servers. When something malicious happens, analysts isolate the machine in real time — they do not just send an alert. | ✅ Included |
| Cloud MDR | The same 24/7 monitoring applied to your cloud accounts — Microsoft 365, Google Workspace, Duo and Azure sign-ins. This is what watches your identities rather than your machines: impossible logins, mailbox rule changes, unusual file activity, and sign-ins from places your team has never been. A compromised Microsoft 365 account is locked automatically, without waiting for someone to notice. | ✅ Included |
| Managed antivirus | Microsoft Defender, centrally managed and policy-enforced across your fleet | ✅ Included |
| DNS filtering | Blocks connections to known malicious domains at the network level — stops malware reaching its operator even if it runs | ✅ Included |
| Drive encryption | BitLocker enforcement and recovery key escrow, so a lost or stolen laptop is not a reportable data breach. Requires a TPM and a machine that supports it — older hardware without one cannot be encrypted this way, and we will flag those rather than leave you assuming they are covered. | ✅ Included (TPM-capable hardware) |
DTC global security configuration — included as standard
Hardening we apply across every organization we manage. You do not buy up to these.
| Control | What it covers | Level |
|---|---|---|
| Local administrator password management (LAPS) | Every computer gets a unique, automatically rotated local administrator password. One compromised machine does not hand over the rest. | ✅ Included |
| Dormant administrator cleanup | Administrator privilege is automatically removed from any local account that has not signed in for 90 days | ✅ Included |
| Shadow IT detection & enforcement | Unapproved software and services on your network are detected and blocked — including the remote access tools attackers most often abuse | ✅ Included |
| Download execution blocking (AppLocker) | Applications downloaded into browser download folders are blocked from running. This shuts down one of the most common ways ransomware arrives — the staff member who downloads what looks like an invoice or a printer driver. | ✅ Included — releasing 11 September 2026 |
| Fleet-wide vulnerability remediation | When a serious vulnerability lands in software our clients commonly share, we fix it everywhere — proactively, at no additional charge, once we have confirmed the fix is safe for your line-of-business applications | ✅ Included |
Vulnerability management & advisory — Full Service Suite
| Service | What it covers | Level |
|---|---|---|
| Vulnerability management | Internal and external scanning, with findings prioritised against how critical the asset is and whether the vulnerability is actually being exploited in the wild | ⭐ Full Service Suite |
| DTC remediation & consulting | Our engineers review, prioritise and fix what the scans find. This is the part that turns a report into a safer organization — and the reason we do not hand you a list and wish you luck. | ⭐ Full Service Suite |
| Security advisory | Security strategy, compliance guidance, and quarterly reviews with your account team | ⭐ Full Service Suite |
| Application control | Policy-driven control over what software is allowed to run, curated and maintained for you | ⭐ Full Service Suite |
| Cloud posture management | Continuous monitoring of your Microsoft 365 configuration, with alerts when a setting drifts or someone changes a policy | ⭐ Full Service Suite |
| Security posture rating | A maturity score for your organization, benchmarked against a national security framework and tracked over time — useful when a customer or insurer asks how you compare | ⭐ Full Service Suite |
| Attack surface inventory | Every device, account, and application that could be attacked, in one view | ⭐ Full Service Suite |
| Dark web monitoring | Monitoring for your organization's credentials appearing in breach data | ⭐ Full Service Suite |
Additional security services
| Service | What it covers | Level |
|---|---|---|
| Security awareness training | Training modules for your whole team, plus simulated phishing campaigns that identify who needs coaching before a real attack arrives | ➕ Available |
| Email threat protection | Advanced filtering of malicious links and attachments beyond what Microsoft 365 includes natively | ➕ Available |
| Email encryption | Encrypted email for regulated and sensitive correspondence — patient information, client financial records, privileged material, controlled technical data | ➕ Available |
| Zero Trust Network Access | Identity-aware access to specific applications, replacing traditional VPN. Built for people who are rarely in the building. | ➕ Available |
| Managed SIEM & log retention | Security event collection and retention for compliance and audit, with support during an investigation. Frequently the specific control a regulator or contract requires. | ➕ Available |
| Penetration testing | Annual third-party testing of your defences | 🔜 Coming soon |
| Managed password manager | Password management for your whole team, with credential monitoring | 🔜 Coming soon |
🗄️ Backup & Business Continuity
Backup protects your data. Business continuity protects your ability to operate. They are not the same thing, and the difference shows up on the worst day.
| Service | What it covers | Level |
|---|---|---|
| BDR — Backup & Disaster Recovery (recommended) | A DTC-managed appliance on site taking full server snapshots, copied offsite to DTC-managed cloud storage. If your server dies, we run your server on the appliance — you are back on air in about 15 minutes while we deal with the hardware. | ➕ Available |
| Hybrid Cloud Backup | A lower-cost alternative: file-level and system image backup to a local device and to cloud storage. Good for file recovery. It cannot run your server for you, so recovery from a server failure is measured in hours. | ➕ Available |
| Workstation backup | Backup for individual computers that hold data locally — common for CAD, imaging and field laptops | ➕ Available |
| Offsite cloud copy | An isolated second copy of your backups outside your building, so ransomware that reaches your network cannot reach your last resort | Included with BDR or Hybrid Cloud Backup |
| Backup monitoring & restore verification | Daily verification that jobs completed, and periodic test restores — because an untested backup is not a backup | Included with BDR or Hybrid Cloud Backup |
If you have a server, BDR is what we will recommend — every time. That goes double if your work generates large files: imaging studies, CAD assemblies, project archives. Hybrid Cloud Backup is the right answer only for an office with no server dependency at all.
☁️ Cloud & Productivity Platforms
| Service | What it covers | Level |
|---|---|---|
| Microsoft 365 tenant management | User and license administration, multi-factor authentication, conditional access, security defaults, and centrally managed Defender policy. We manage Google Workspace environments the same way — user and group administration, MFA and access policy, and the security settings that matter. Whichever platform you run, managing it is part of your agreement. | ✅ Included |
| Microsoft 365 licensing | DTC supplies and bills your Microsoft licensing, with the right plan chosen for each role rather than one plan for everyone. We add very little on top of what Microsoft charges — you are buying convenience and correct license selection, not a markup. | ➕ Available |
| Google Workspace | For organizations on Google rather than Microsoft. Priced per user, quoted by your account team. | ➕ Available |
| Government and GCC High tenancy | Microsoft 365 Government or GCC High tenants for organizations whose contracts or regulations require them | ➕ Available |
| Hosted infrastructure | Servers and workloads hosted in the cloud instead of your building, where that is the better fit | ➕ Available |
| Business phones (VoIP) | Cloud phone service for your organization | ➕ Available |
| Email and tenant migrations | Moving email, files, or an entire Microsoft or Google tenant — including migrations between the two platforms — quoted as a project | ➕ Available |
Licensing is not included in your managed services agreement. Microsoft 365 and Google Workspace subscriptions are billed separately from the services on this page — they are your software, purchased through us. Managing that platform is included; paying for it is not. We keep our Microsoft pricing close to Microsoft's own so that buying through us costs you little more than buying direct, and saves you the license administration.
📋 Compliance & Advisory
| Service | What it covers | Level |
|---|---|---|
| Onboarding security review | When you join DTC we assess your environment, document what we find, and walk you through the risks and a prioritised plan — so you know your starting position | ✅ Included |
| Network assessment & technology evaluation | A structured review of your infrastructure, repeated periodically, that feeds your technology roadmap and budget | ✅ Included |
| Security advisory & posture reviews | Your account team reviews your technical posture, priorities and spend with you rather than at you, and tells you which technical controls map to the requirements you are under. Reviews are on demand — ask for one when a contract, an insurer, an acquisition or a bad news week makes it useful, rather than waiting for a date on a calendar. | ⭐ Full Service Suite |
| Technical safeguards for HIPAA | Implementing and maintaining the technical controls behind the HIPAA Security Rule — access control, encryption, audit logging, backup — plus a Business Associate Agreement and the evidence that those controls are actually running | ➕ Available |
| Technical controls for CMMC & NIST SP 800-171 | Implementing and evidencing the technical practices in the framework for DoD contractors handling CUI, and giving your assessor and your consultant artifacts they can rely on. This is the work that gets your technology to where the framework requires. | ➕ Available |
| CMMC On-Going Service | For organizations that must stay at CMMC Level 2 or above. Compliance is not a one-time project — controls drift, systems change, people come and go, and evidence has to keep accumulating between assessments. This service maintains the technical controls, collects that evidence continuously, and corrects drift before an assessor finds it. Billed as its own line item, separate from the implementation work that got you there. | ➕ Available |
| Insurer and customer questionnaire support | Answering the technical questions on a cyber insurance application or a customer security questionnaire accurately, and closing the technical gaps that would otherwise void a claim or lose a contract | ➕ Available |
| Technical controls for other frameworks | The same for PCI-DSS, the FTC Safeguards Rule and state privacy law — segmentation, access control, logging, retention, encryption | ➕ Available |
| Working alongside your compliance consultant | Your consultant or auditor owns the framework, the policies and the assessment. We own the technology and provide the evidence. We coordinate with them directly so you are not stuck relaying between two vendors. | ✅ Included |
An honest note on compliance. Many of our services align with national security standards, and they give you real evidence to show an auditor, an insurer, or a prime contractor. But buying services does not by itself make an organization compliant — compliance also depends on your policies, your training, and how your people actually work.
DTC is not a compliance consultancy. We are responsible for the technical half of a framework — the controls that live in software and hardware, and the evidence that they are running. We do not write your policies, build your procedures, run your risk assessment, produce your System Security Plan, or interpret a regulation on your behalf. Those are the work of a qualified compliance consultant or auditor, and we will tell you plainly when you need one rather than improvising.
What that looks like in practice. Your consultant determines the framework requires audit logs retained for a year. We implement it, prove it is working, and hand over the evidence. Your consultant writes the incident response policy. We are the technical team that policy calls at 2 AM. Neither of us can do the other's half, and an organization that buys only one of them is not compliant.
We work with third-party compliance consultants regularly, and we are glad to coordinate directly with yours or to point you toward one. Certification and attestation come from an accredited assessor or auditor — never from your IT provider.
🚧 Projects & Professional Services
Work with a beginning and an end, quoted individually rather than billed monthly.
| Service | What it covers | Level |
|---|---|---|
| Project design, quoting & management | We scope it, quote it, run it, and stay accountable for the result | ➕ Quoted per project |
| Server & network refresh | Replacing aging infrastructure before it fails, with a migration plan that does not stop your operation | ➕ Quoted per project |
| New sites, expansions and relocations | Cabling, network, servers, workstations and phones for a new office, clinic, plant, terminal or branch | ➕ Quoted per project |
| Line-of-business system migrations | Moving between practice management, EHR, ERP or accounting platforms, including data migration and vendor coordination | ➕ Quoted per project |
| Compliance remediation projects | Closing the gaps found in an assessment — segmentation, logging, access control, documentation — as scoped work with a defined finish line | ➕ Quoted per project |
| Hardware procurement | Specifying and supplying workstations, servers, and peripherals that we know work with your software | ➕ Quoted per project |
What DTC does not do
Being clear about this is more useful to you than pretending otherwise.
| Not offered | What happens instead |
|---|---|
| Standalone digital forensics | We support investigations with the logs and evidence we hold, and we will refer you to a dedicated forensics firm when one is needed |
| Ransomware negotiation | DTC does not negotiate with ransomware operators. That decision belongs to you and your cyber insurance carrier, and we will work alongside whoever they appoint. |
| Ransomware recovery as a paid engagement | Recovery is handled through your cyber insurance policy and your incident response coverage — not sold to you as a product at your worst moment |
| Compliance certification or attestation | We provide technical controls and evidence. Certification comes from an accredited assessor or auditor, not from your IT provider. |
| Policy and procedure development | We do not write your HIPAA policies, your CMMC System Security Plan, your written information security program, or your employee procedures. A third-party compliance consultant does that work — we implement and evidence the technical controls those documents call for, and we will coordinate with your consultant directly. |
| Regulatory interpretation & risk assessment | We will not tell you what a regulation requires of your organization, or sign off on your risk assessment. That is professional advice we are not qualified to give, and getting it wrong is expensive for you, not us. |
| Line-of-business software development | We support and integrate the platforms you run. We do not build or modify them — we coordinate with the vendor who does. |
📞 Want to know what is active in your environment, or what it would take to add something here? Contact your DTC account team, email support@dtctoday.com, or submit a request through the DTC Client Portal.