The Helios blog
Practical writing on patching, security, automation and the day-to-day of managing IT estates at scale, whether you run them for clients or for your own organisation. From the team building Helios.
An MSP contract always bundled tooling, expertise and accountability, and AI has just changed the middle one. Who genuinely no longer needs an MSP, who absolutely still does, and the test to hold any platform to.
Read the founder note →Exploits land in days while deployment rings add weeks of ritual to guard against a risk that is rare, loud and reversible. Why a ring nobody watches is just a queue, and the faster cadence to run instead.
Read article →Months after someone leaves, one of their accounts logs in. A post-mortem of the most common offboarding failure, traced to its root causes, and a three-pass checklist with a trigger, an owner and proof.
Read article →A failed Windows update is a symptom with about five common causes. How to tell full disks, reboot loops, broken components, stale update servers and absent machines apart, and the right fix for each one.
Read article →Clients leave, and the way you exit is the story they tell for years. An annotated offboarding checklist in four phases: agree the exit, hand over the estate, remove your access completely, and close out with sign-off.
Read article →One person can run IT for a hundred people, but not by heroics. A sustained argument for systems over firefighting, with the five obvious objections, staffing, standards, automation, security and holidays, met head on.
Read article →Realistic lifespans by device class, the health and support signals that matter more than age, the Windows 11 long tail, and the budget maths that make a rolling refresh cheaper than running hardware into the ground.
Read article →A new tenant is configured for adoption, not safety. The ten settings to fix first, from MFA and legacy authentication to forwarding rules and offboarding, and how to stop them drifting back.
Read article →A QBR should prove value, surface decisions and set the next quarter, not read out ticket counts. A 45-minute agenda, the metrics worth showing, and how to prepare one without losing half a day.
Read article →Response is not resolution, and neither means anything undefined. Sensible response targets by priority, the triage matrix that keeps them honest, and the clock mechanics that quietly break SLA reporting.
Read article →Contracts are rarely lost at the sales stage: they are lost in the first 30 days. A practical onboarding checklist covering discovery, agent rollout, baselining patching, protection and backups, and the 30-day review.
Read article →A founder's view on the IT tooling market right now: why the big platforms are built for the biggest buyers, how SME needs genuinely differ from enterprise, and what the AI vibe-coding wave does and doesn't change.
Read the founder note →A successful backup job is not proof you can restore. The silent failure modes that stay green for months, the 3-2-1-1-0 rule, and a tiered restore-testing cadence that fits in a real working week.
Read article →Alert noise is a configuration problem, not a staffing problem. Where RMM noise really comes from, five changes that cut it at the source, and the three numbers that stop it growing back.
Read article →Browsers, PDF readers and conferencing tools are where most breaches start, yet they patch on their own schedules. A practical look at third-party patching at scale, winget's sharp edges, and what real coverage requires.
Read article →