Welcome to Managed-ICT
A strategic IT consulting and implementation firm dedicated to regulated industries, focusing on pre-clinical and clinical-stage biopharmaceuticals, life sciences companies, healthcare (hospitals and clinics), pharmaceutical manufacturers, medical device and diagnostics manufacturers, clinical research organizations, healthcare providers and laboratories, drug distribution and pharmacovigilance organizations, and other organizations that require top-tier security and compliance, including IT, software, and SaaS providers and other supporting providers (e.g., G&A) serving these sectors.
Managed-ICT
— an Overview
Based on 15 years of hands-on experience as a full-service MSP serving regulated industries, we have evolved into a consulting powerhouse, fusing strategic IT advisory with modern IT operations design and deep technical expertise. Our real-world, battle-tested knowledge enables us to design, operate, and scale secure, compliant IT environments in high-stakes pharma and life sciences sectors, including biotechnology, medical devices and diagnostics, clinical research, healthcare providers and laboratories, and pharmacovigilance organizations.
Built for Regulated Environments
We understand the importance of documentation, compliance, and strict control in fields like pre-clinical and clinical-stage biopharmaceuticals, life sciences, healthcare providers and laboratories, medical device and diagnostics manufacturing, clinical research organizations, drug distribution and pharmacovigilance, pharmaceutical manufacturing, and mission-critical SaaS providers supporting these sectors. Our team is well-versed in ISO 27001, FDA/ EMA GxP compliance, ICH, GDPR, EU Annex 11, and SOX (ITGC/ICFR)-ensuring custom solutions aligned with rigorous standards.
Strategic Consulting & Execution
Unlike traditional consultants, we don’t just hand off designs; we’ve operated these environments. From guiding CIO-level strategy to configuring Entra ID or deploying Microsoft Sentinel, we provide consistent advisory and hands-on execution across the entire IT lifecycle.
We draw on extensive experience: our consultants have worked in companies of all sizes & phases, from start-up-phase to successful IPOs.
Service & Project-Based Delivery
Our approach emphasizes clearly scoped engagements, defined project roles, and workshop-style collaboration that elevates internal IT maturity while delivering tangible outcomes. We ensure swift progress on critical milestones. We offer flexible consulting arrangements, from traditional agreements with or without a retainer, to project-based engagements and subscription models designed specifically for SMEs.
Implementation Leadership
Our operational IT roots mean we handle more than just advising. We act as your project lead, solution architect, and partner manager, coordinating with internal IT teams, MSPs, and cloud vendors to ensure seamless, successful implementations.
Pre-Built, Always Tailored
- ISO 27001-compliant policy sets
- Outsourced ITOM frameworks
- Cloud architecture templates & secure configuration baselines (CIS Benchmarks)
- Security monitoring deployments
These resources adapt to your specific environment, ensuring the best possible match for your business needs.
With Managed-ICT, your IT environment becomes modern, manageable, measurable, and compliant. You bring the vision; we bring the blueprint to operationalize it.
About
Who We Are
Managed-ICT draws from over 15 years of experience managing full-service IT across pharma and life sciences regulated organizations. Our beginnings as an MSP evolved into a specialist consulting and implementation firm, enabling us to provide a broad advisory spectrum and hands-on expertise, from governance strategies to cloud-native designs and robust security frameworks.
Our Team
Technology is built into our DNA: We are a cross-functional group of consultants and professionals with extensive backgrounds and deep technical knowledge in managed services, security, project management, and training. When projects require additional or highly specialized resources, we collaborate with a trusted network of partner providers to ensure the right expertise is always on hand.
-
IT Strategy and Security Managers:
Veterans in IT and Security Management. -
MSP Architects:
Mastery of Microsoft 365, Azure, Entra ID, N-able. -
Security & Compliance Experts:
Skilled in ISO 27001, SOC 2, EMA, GDPR, SOX ITGC. -
Finance & ERP Implementation Experts:
Experienced leaders for ERP implementations and SOX ICFR. -
Project Managers & Product Owners:
Biotech, software scale-ups, IT transformations. -
Trainers & Facilitators:
Bridging vision and execution, coaching internal IT teams.
What We Offer
Secure & Scalable IT Strategies
We map out tailored roadmaps for secure, high-performance IT that aligns with your organization's goals.
ISO 27001-Aligned ISMS Documentation
Robust information security management documentation to streamline audits and maintain compliance across regulated sectors.
ITIL-based ITSM Process Templates
Blueprint processes for incident, change, and service management following industry best practices, reducing downtime and improving efficiency.
Full-Stack Microsoft Platform Blueprints
Proven designs for Microsoft 365, Azure, and Entra ID, achieving secure collaboration, scalable infrastructure, and compliance-ready environments.
Outsourced ITOM Architectures & SOPs
Leverage our frameworks for efficient ITOM, including runbooks, policies, and vendor governance.
Automation & Scripting
Streamline repetitive tasks, reduce human error, and accelerate deployment with custom scripts and automated workflows.
We combine strategic insights with proven toolkits to comprehensively modernize your IT. Beyond documentation, we conduct workshops, train your IT staff, and collaborate with providers to implement real, lasting change.
Services
IT Strategy & Governance
Overview:
In regulated environments, governance ensures compliance and accountability. We shape IT strategies rooted in real operational experience, ensuring technology aligns with your business mission.
- CIO-as-a-Service and advisory for startups/growth-phase businesses
- Governance & role definitions and outsourcing models (internal vs. external)
- Information Technology investment planning & vendor selection strategy
- Compliance-driven documentation (ISO 27001, GDPR, FDA/ EMA GxP, SOX)
- IT Strategy decks & board-ready briefs
- Governance charters & review schedules
- Policy frameworks mapped to ISO 27001, GDPR, FDA/ EMA GxP, ICH, SOX
- Annual planning calendars & investment roadmaps
Security & Compliance
Overview:
Protecting business-critical data and meeting regulatory demands ( ISO 27001, SOC 2, EMA, GDPR) requires a comprehensive, streamlined approach. We craft security programs without creating unnecessary overhead.
- Lean ISMS template packs (ISO 27001-aligned/mapped to CIS Critical Security Controls); secure configuration baselines using CIS Benchmarks (e.g., Microsoft 365, Azure, Windows)
- SOX ITGC/ICFR readiness for pre- and post-IPO (access, change, operations) with auditor-ready evidence.
- Pre-IPO readiness and post-IPO SOX 404 sustainment (walkthroughs, testing coordination, evidence).
- CISO-as-a-Service for growing organizations.
- Complete configuration of Microsoft 365 and Security E5.
Cloud Architecture
Overview:
We specialize in secure, compliant, cloud-native designs based on Microsoft Azure, Entra ID, and Microsoft 365 and complemented with trusted, industry-specific cloud-solutions -enabling scalability and simplifying audits for regulated sectors.
- Entra ID design & conditional access policies, and full Security E5 deployments
- Azure subscription & network architecture
- Microsoft 365 configuration (full setup including collaboration & security)
- SaaS integrations (SSO & identity federation)
- Backup, disaster recovery, and monitoring solutions
- Architecture diagrams & security baselines aligned to CIS Benchmarks
- Infrastructure-as-Code templates ( Terraform, ARM, Bicep)
- Full documentation, handover materials, and implementation guidance
ITSM & Operations
Overview:
Efficient day-to-day IT requires strong ITSM foundations. We help design or optimize ITIL-based processes, ticketing, and monitoring structures that adapt to your evolving needs.
- ITOM architecture diagrams (roles, tools, services) and Ops Models
- ITIL workflows for support, incidents, and change management
- Vendor escalation pathways & service ownership models
- RACI charts & documentation standards
- SLAs, KPIs, and reporting templates
We design services and publish clear service catalogs, help select and onboard helpdesk vendors and integrate ticketing across platforms. KPI dashboards ensure real-time visibility, proactive monitoring, and reporting.
Technical Expertise & Implementation
Overview:
Drawing on an MSP heritage, we offer direct technical execution and leadership for mission-critical deployments, where speed, quality, and compliance are paramount.
- Project ownership & end-to-end delivery
- Engineering support (Microsoft 365, Azure, Entra ID, Defender, Sentinel)
- N-Able stack configuration (RMM, patching, backups, automation)
- Automation & scripting (policy deployments, advanced setups)
- Migration & rollout execution
We partner with your in-house IT or external MSPs, leading workshops and implementation sprints. Our co-delivery approach ensures thorough documentation, training, and lasting system stability.
DevOps & Automation
Overview:
Modern IT environments often rely on streamlined DevOps pipelines and intelligent automation. We design and implement CI/CD strategies, containerization, and integrated workflows.
- Continuous Integration/Delivery (CI/CD) with Azure DevOps or GitLab
- IaaS and code-based deployments
- Container orchestration ( Kubernetes, Docker)
- Infrastructure as Code alignment with security policies and frameworks
- Automated testing & environment provisioning
By unifying development and operations practices, we help organizations reduce release cycles, maintain high-quality code, and respond swiftly to business needs. Our automation focus ensures consistency and compliance.
IT Leadership-as-a-Service for SMEs
Outsource IT leadership roles to Managed-ICT with our CIO- & CISO-Services for SMEs in pharma and life sciences industries: Each subscription places an experienced CIO and CISO at your side, driving governance, security, compliance, budgets, vendors, and roadmaps, while remaining technology-independent and able to coordinate with internal teams or any MSP so you can focus on product, science, and growth.
LAUNCH & PREPARE
Stage 1For startups and early-stage companies establishing secure, compliant-ready IT foundations.
- ≈20 FTE, no IT strategy or governance in place; limited IT process and documentation.
- Need a secure cloud baseline and lean policies.
- Founders/teams wear many hats; vendors need coordination.
- Clear decision rights and quarterly governance rhythm.
- Secure-by-default identity & collaboration tenancy, based on technology and achitecure blueprints and best-practices.
- ISO-aligned starter policy set and initial, scenario-based risk register.
- Kick-off governance (quarterly reviews, change control light).
- Identity & access hygiene; baseline Conditional Access.
- Gap snapshot for ISO/GxP/GDPR/ICH; audit roadmap.
BUILD & SCALE
Stage 2For organizations expanding headcount and systems, formalizing compliance and IT operations.
- Hiring quickly; multiple, organically grown SaaS/IaaS environments to standardize.
- Audit/compliance obligations emerging (SOC/ISO/SOX, sponsor due diligence).
- Need consistent ITSM processes and measurable KPIs.
- Monthly governance with control owners and risk treatment tracking.
- Landing zones & identity architecture (PIM, Conditional Access tiers).
- Design of service catalog, SLAs, CAB charter, and KPI definitions; quarterly governance reviews of MSP-produced KPIs.
- ISMS build-out: policy set tailored to risk; register & SoA upkeep.
- Data protection (DLP/retention) and monitoring blueprints (XDR/SIEM).
- MSP/vendor alignment to deliver auditable, repeatable operations.
ASSURE & PROTECT
Stage 3For mature programs operating under continuous scrutiny (e.g., Phase 3 studies, pre-IPO or post-IPO).
- Evidence-rich, inspection-ready security and operations are mandatory.
- Complex vendor ecosystem and formal third-party risk management.
- Board-level oversight and regular compliance reporting needed.
- ISMS operated and maintained; SOX/ITGC readiness; internal audits and audit prep.
- Continuous compliance overview and monthly posture briefs.
- Leadership plans/approves BC/DR scenarios and reviews evidence; MSP executes tests and compiles evidence.
- Remediation governance; release/validation oversight; compliance coordination.
- Vendor risk management and audit/inspection (ISO/GxP/SOX) orchestration.
- Secure operations leadership across identity, endpoint, network, backup/DR.
Always Included in Every Tier: Executive IT leadership with dedicated CIO and CISO expertise, providing platform-agnostic architecture, structured governance, strategic risk management, and compliance oversight tailored to your company’s stage of growth.
Scope: Strategy, policy, architecture, governance, risk, vendor/MSP/SOC oversight. Not included: Service desk, JML execution, patching, monitoring run, or incident response - these are delivered by ManagedOps or your chosen MSP.
IT Operations-as-a-Service for SMBs & SMEs
Blueprint-driven, enterprise-grade IT operations with fixed per-user pricing (up to 5 devices per user). Built on a Microsoft 365 foundation and complemented with our MSP-Tools, with standardized onboarding, proactive monitoring, automated patching, and an 8x5 service desk, pair with Leadership for full strategy-to-operations coverage.
Core
Basic8×5 run of essentials on a secure Microsoft 365 foundation paired with our MSP-stack.
- 8×5 service desk; email + portal intake; P1 ≤4h in hours; JML execution to approved standards; core catalog; tickets logged.
- Intune baseline + compliance; MFA with baseline Conditional Access; admin separation; EOP baseline; spam/quarantine handling as run.
- Automated OS and 3rd-party patch-management; quarterly vulnerability snapshots; endpoint/service-health monitoring; security alerts forwarded; 8×5 triage with tickets; cadence/SLOs set by leadership or your IT owner.
- Logged changes; pre-flight checks; baseline drift flagged; quarterly ops review; ops logs retained; backup oversight not included; no scheduled DR tests.
Core + Secure
AdvancedPriority desk, hardened baselines, governed risk handling, and extended threat protection.
- 8×5 priority desk incl. phone; P1 ≤2h; JML with approvals; expanded catalog; operate role-based request standards.
- Hardened baselines with drift alerts; tiered Conditional Access; PIM; anti-phishing; sharing controls; operate starter DLP. Policies & exceptions governed.
- Automated OS and 3rd-party patch-management with weekly manual checks; monthly scans with owners + target dates; health + security telemetry; same-day playbook triage; coordinated vendor escalations; governed risk acceptance.
- Peer review (CAB-lite); checklists and validation; scheduled drift fixes; monthly ops and security posture report with KPIs; control-evidence; backup mgmt with annual DR test.
Enterprise
CompleteFollow-the-sun operations with evidence-rich continuity and advanced compliance.
- Follow-the-sun desk; paging; P1 ≤1h any time; after-hours cutovers; full catalog with SLAs; pre-approved exception patterns.
- Policy-as-code enforcement; risk-based Conditional Access; just-in-time elevation with approvals; adaptive phishing defenses; org-wide DLP & information protection labels.
- Continuous priority-patching with auto- and manual remediation; continuous scans with SLOs/exceptions tracked; 24×7 telemetry; XDR/EDR operations & incident response; orchestrated escalations; KPIs reviewed with leadership or your IT owner.
- Formal CAB and release execution; enforced desired state; post-change reviews; compliance-grade pack (SLA, RTO/RPO, alert KPIs); audit-ready evidence.
Scope: MSP services run independently or alongside Leadership and are tailored for pharma and life sciences organizations, plus IT, software/SaaS, and other supporting providers serving these sectors.
Fixed-rate, fully remote delivery for regulated SMEs in Switzerland & the EU. Prices exclude VAT and may vary with scope, user count, license editions, and bundled Leadership+MSP discounts.
Methodology & Approach
Our approach blends visionary planning with agile execution and continuous refinement. From day one, we work closely with your team to ensure every strategy is more than just a document - it’s a roadmap to tangible outcomes. By coupling innovative thinking with proven frameworks, we transform high-level objectives into operational reality. Below, we outline the core pillars that drive our collaborative, results-focused methodology.
Greenfield & Legacy Migrations
Whether you’re standing up a secure greenfield tenancy or unwinding brittle, decades-old legacy stacks, we apply a phased, low-risk migration playbook that starts with discovery and dependency mapping, clarifies ownership and change control, and aligns identity, data protection, and compliance requirements from the outset.
For legacy transitions, we plan staged cutovers with clear rollback paths, communication plans, and hypercare to preserve business continuity and minimize downtime. For greenfield, we accelerate day-one productivity with secure-by-default patterns, landing zones, conditional access, device management, and monitoring - so the environment is ready to operate on day one. Throughout, we document decisions, evidence configurations, and train your team so the new platform is supportable, auditable, and scalable.
Workshops & Coaching
We bridge the gaps betwenn technical and non-technical roles:
- Customized training sessions for IT and non-IT roles
- Hands-on knowledge transfer for new systems and processes
- Comprehensive guidance capturing best practices
We believe lasting change comes from empowerment. Our experts coach your staff, building confidence and skills to manage, adopt, and expand capabilities across tools and practices. Through follow-up workshops and check-ins, we help your organization stay current with evolving best practices and technologies, ensuring your investment in people and systems continues to deliver value long after our initial engagement.
Technology & Solutions Ecosystem
We are proudly technology-independent, giving you the confidence that every solution we recommend is driven by your goals, not vendor ties. Our seasoned experts draw on extensive, hands-on experience across a wide range of platforms to implement what truly works, ensuring compliance, efficiency, and long-term success.
We are explicitly not part of any exclusive partner network that binds us to solutions and conditions, and we remain as independent as possible to provide our customers with unbiased expertise.
Below is a selection of suppliers, solution providers, manufacturers, and products that our experts have successfully worked with or applied in projects.
Core IT, Cloud & Security
Business Applications & Analytics
Life Sciences, GxP & Scientific
DevOps & Data Science
All company and product names, and logos within this section are the property of their respective owners and are used here for reference only. Their appearance does not imply endorsement or partnership.
Contact
Let’s connect - whether it’s strategy, compliance, or implementation, our experts are here to help.
Main Office:
Messeplatz 10, 4058 Basel, Switzerland
Distributed team - member of FlexOffice. Meeting spaces available in Basel, Zurich, and Geneva.