Clinical IT Department · Daryo89 Ltd
Your IT department, run by a clinician-engineer
Microsoft 365, devices, security, backups and DSPT evidence — the whole IT function of a care provider or clinic, managed under a written service level agreement by someone who has worked a shift and built the systems. From five users, from £95 per user per month — priced for a named clinician-engineer and enterprise-grade tooling, not a helpdesk queue — with licences and certification fees passed through at cost.
Includes
Microsoft 365 management, Intune device management, security and compliance, helpdesk and continuity
Price
Essential £95 · Managed £135 · Clinical £185 per user per month; minimum £750 a month; onboarding from £1,500; no VAT is added
Standards
DSPT, Cyber Essentials, UK GDPR, CQC expectations
Delivered by
A named clinician-engineer under a written SLA
- Vendor-neutral, in writing
- AXA professional indemnity
- 5.0 on Google (opens in a new tab)
5.0 on Clutch (opens in a new tab)
Who it is for
Domiciliary and residential care, supported living, clinics, private practices
Care providers and clinics carry the obligations of a hospital with the IT of a small business: staff on the road with phones full of personal data, a Microsoft 365 tenant nobody owns, laptops that were never encrypted, a DSPT submission done in a weekend, and a supplier who fixes what breaks but does not run what should be running. The regulator does not ask whether you have IT support. It asks whether your data is secure — and for the evidence.
The Clinical IT Department is the answer to that question, as a service: we own your IT function, run it to the standard the Data Security and Protection Toolkit and CQC expect, and keep the evidence as we go.
What is included
Four areas, one service, one SLA
Microsoft 365 management
- Identity and access: Entra ID, multi-factor authentication for everyone, conditional access, single sign-on to your care systems
- Email security: Exchange Online Protection, anti-phishing, SPF, DKIM and DMARC set and monitored
- Teams, SharePoint and OneDrive governance: who can share what, with whom, and for how long
- Licences bought once, right-sized quarterly; backup of 365 data independent of Microsoft
- Joiners and leavers: accounts created before day one, removed the day someone leaves, with an audit trail
Device management
- Every laptop, phone and tablet enrolled in Intune — Windows, iOS and Android
- Encryption on, screen lock enforced, updates applied within the window, unsupported devices blocked
- App control: the care apps installed and updated, personal apps kept off work data
- Lost or stolen: remote lock and wipe within the hour, and the log the ICO expects
- An asset register that is actually current — what exists, who has it, when it was patched
Security and compliance
- Microsoft Defender across identities, mail, devices and cloud apps; alerts triaged by a person
- Cyber Essentials readiness and the annual certification with you
- DSPT: the evidence produced as a by-product of the service, the submission prepared each year
- Phishing simulation and short staff training, recorded for your competency records
- Incident response: a written procedure, a named person, and the 72-hour clock managed
Helpdesk and continuity
- A helpdesk your staff can reach by phone, email and Teams, with response times in our SLA
- Backups of everything that matters, tested restores every quarter, a written continuity plan
- Supplier management: care software, telephony, broadband, printers — one point of contact for all of them
- Quarterly review with the registered manager: risks, spend, what changed, what is next
- Everything documented, so nothing depends on one person’s memory — including ours
How it works
Three steps, the first two with fixed dates
Step 1
Audit — week one
We inventory identities, devices, data, suppliers and the gaps against the DSPT and Cyber Essentials. You get a plain report and a fixed onboarding plan.
Step 2
Onboarding — the first month
MFA on, devices enrolled and encrypted, mail protected, backups running, leavers cleared, policies issued. The urgent risks close first; the report says which.
Step 3
Run — every month after
The helpdesk, the patching, the monitoring, the joiners and leavers, the quarterly review, the annual DSPT and Cyber Essentials. Rolling 30-day terms after the first three months.
Pricing
Per user, per month, published
From five users, minimum £750 a month. Onboarding once, at one month’s fee, minimum £1,500. No VAT is added — Daryo89 Ltd is not VAT registered; Microsoft licences and certification fees are passed through at cost.
Essential
Run properly
- Microsoft 365 identity, MFA and mail security
- Intune enrolment and encryption
- Helpdesk in Standard Engineering Hours
- Backups and quarterly restore test
- DSPT evidence pack
£95 per user per month
Book a scoping callManaged
Run and secured
- Everything in Essential
- Defender across mail, devices and cloud apps, alerts triaged
- Phishing simulation and training
- Cyber Essentials with you each year
- Supplier management and the quarterly review
£135 per user per month
Book a scoping callClinical
Run, secured and governed
- Everything in Managed
- Clinical AI Governance Implementation Partner included
- DSPT submission prepared and reviewed with you
- Incident response with the 72-hour clock managed
- Named engineer, extended hours
£185 per user per month
Book a scoping callWhat you pay for
The price, what is passed through, and why it sits where it does
What the price includes, and what is passed through
- The service, the helpdesk, the monitoring, the evidence and the reviews are in the per-user price.
- Microsoft licences (Business Premium is the one that includes Intune and Defender) are bought at Microsoft’s published price and passed through at cost — we take no margin on them.
- Cyber Essentials: the IASME assessment fee (opens in a new tab) is passed through at cost (£320 + VAT for up to nine staff, £440 + VAT for ten to forty-nine); the work to pass is in the Managed and Clinical tiers. Cyber Essentials Plus is quoted separately.
- Hardware at cost, with no mark-up. Out-of-hours and on-site work as our SLA states.
Why the price is at the top of the market
Published UK guides put managed IT in 2026 at about £40 to £150 per user per month, with premium, security-led tiers at £100 to £150 (Tulip Tech (opens in a new tab), Connection Technologies (opens in a new tab)), and buyers handling health data are advised to budget toward the upper bands, because compliance makes the higher tier the standard rather than an add-on (Sentinel SecureTech (opens in a new tab)). Ours sit in the upper band and, for the Clinical tier, above it — deliberately, for two reasons you can check.
- Human commitment. A named clinician-engineer who knows your service answers, not a queue; the founder is on the rota; alerts are triaged by a person; the quarterly review is with the registered manager in the room. Senior time is what a care provider actually buys, and it is what cheaper tiers remove first.
- The equipment and tooling. We run the same stack at five users as at five hundred: Intune and Defender across every identity and device, immutable off-tenant backups with tested restores, 24/7 monitoring, and a device baseline — TPM 2.0, Windows 11 Pro or current iOS/Android, full encryption — below which we will not manage a device. Hardware that meets it is supplied at cost.
A 20-person provider on Managed pays £2,700 a month plus licences; an in-house IT manager for the same headcount costs more than that in salary alone — one published estimate puts a mid-level UK IT manager at £65,000 to £75,000 a year fully loaded (Tulip Tech (opens in a new tab)) — with one person’s memory as the backup plan.
Standards and promises
The standard we work to, and what we will not do
The standard we work to
- Data Security and Protection Toolkit (NHS England) — the ten data security standards, evidenced
- Cyber Essentials and Cyber Essentials Plus
- The UK GDPR and the Data (Use and Access) Act 2025; the ICO’s guidance for health and care
- CQC’s expectations on records, information governance and safe systems
- Where AI tools are in use: DCB0129/DCB0160 clinical safety and the EU AI Act — through our Clinical AI Governance service
What we will not do
- Guess. Every change is planned, tested and written down.
- Lock you in: your tenant, your licences, your documentation, your data — all yours, always.
- Sell you hardware or software we get commission on. We are vendor-neutral and say so in writing.
- Leave the evidence to the last week before a submission.
Questions
What registered managers ask us
We already have someone who ‘does the IT’. Why change?
Most care providers have a person or a local supplier who fixes things. What CQC, the ICO and the DSPT ask for is an IT function that is run: identities managed, devices enrolled and encrypted, backups tested, leavers removed the same day, evidence kept. We give you that function, with a named person, under a written SLA, at a per-user price.
Do we have to move to Microsoft 365?
No, but most of our clients are already on it or on Google Workspace, and Microsoft 365 is where NHSmail-style controls, Intune device management and Defender live. If you are on Google Workspace we manage that; if you are on neither, the first month includes the move.
What about the care software we use — care plans, rostering, eMAR?
We manage the accounts, the devices they run on, the single sign-on and the supplier relationship; the software itself stays with its supplier. Where a supplier’s product uses AI, our Clinical AI Governance work covers the assurance.
Can you help us pass the DSPT?
Yes. The Data Security and Protection Toolkit asks for evidence — policies, MFA, encryption, patching, backups, training, incident logs. Our service produces that evidence as a by-product of running your IT properly, and we prepare the submission with you each year.
Is there a minimum size or term?
From five users, minimum £750 a month. Rolling 30-day terms after a first three months, so you are not locked in; the onboarding month is where most of the work happens.
Who actually answers the phone?
The founder, or the engineer on the rota for your tier — never an offshore desk. Response times are in our Service Level Agreement.
Last updated 29 September 2026 · Daryo89 Ltd, Cambridge
Start with a 30-minute scoping call
Tell us how many people, which systems and which devices. You get a fixed onboarding plan and price within two working days.
DARYO89 LTD · Registered in England and Wales, company number 14758584 · ICO ZB970149 · Registered Trade Mark UK00004255208 · 171 Gladiator Road, Upper Cambourne, Cambridge, CB23 6JZ · Not VAT registered: no VAT is added to any price