The switch and the servers it exists for, under one agreement.
Most maintenance contracts stop at the edge of one vendor's kit. Ours follows the path: the core switch, the servers and hypervisors behind it, the firewall in front, the UPS under all of it, and on a plant, the SCADA and historian servers too. Certificates renewed before they expire, not after the VPN portal or the HMI goes blank. And when it does fail, the person who answers has been to your site.

Why it matters
The contract promises a response and the person who answers has never seen your site. That is the gap this service closes: continuity of the people, not just a ticket queue.
The other gap is coverage that stops at the switch and leaves the servers it exists for uncovered. We cover the path, head-ends included.
What it covers
- The network under everything
- Managed switches and routers, firewalls, out-of-band management, and the UPS and PDUs keeping them up.
- Core IT
- Hypervisor hosts and clusters, storage, domain controllers, DNS and DHCP, file and backup servers.
- Security head-ends
- VMS servers, NVRs and the storage that holds retention; access-control servers, door controllers and panels.
- Control and metering head-ends
- Where a site has them: SCADA and historian servers, HMI and engineering workstations, AMI head-end servers and collectors, and the redundant pairs and failover behind them.
How it runs
Register and baseline
An asset and lifecycle register: model class, firmware, end-of-support date and certificate expiry for everything under the agreement, so nothing ages out silently.
Preventive maintenance
A schedule of health checks (disk, RAID, fans, PSU, UPS battery runtime, temperatures) and firmware and patches qualified against what the application and control vendors support, applied in windows you already have.
Respond by consequence
Severity tiers defined by what the failure does to the business or the process, not by an abstract number, with an escalation path that reaches someone who knows the site.
Report and review
A service report after every visit and a quarterly lifecycle report, so you can see what is ageing before it fails.
A page of what you are handed
ARTA CYBER
Representative deliverable — site and figures redacted.
Lifecycle register — excerpt
| Asset | Class | Firmware / version | End of support | Certificate expiry | Action this quarter |
|---|---|---|---|---|---|
| SW-CORE-A/B | Managed L3 switch pair | 16.12.x | 2028-04 | — | Qualify 17.x in the lab, then upgrade one member at a time in the next window. |
| FW-EDGE | Perimeter firewall pair | 7.2.4 | 2029-09 | VPN portal, next quarter | Renewal booked ahead of expiry. Config backup verified weekly. |
| DC-02 | Domain controller | Windows Server 2016 | 2027-01 | — | Replacement build planned; demote after the new controller replicates. No in-place upgrade. |
| HV-CL1 | Hypervisor cluster, 3 hosts | 8.0 U2 | 2027-10 | — | Check backup agent compatibility before the next update. |
| HIST-01 | Historian server (plant) | 2019 build | 2027-01 | OPC UA, this quarter | Renew in the booked window. A lapsed OPC UA certificate stops collection. |
| UPS-CR1 | Rack UPS | — | battery 2027-06 | — | Runtime tested at load and within spec. Recheck next quarter. |
What you are left holding
- SLA schedule: tiers, coverage, escalation and exclusions (figures set per contract).
- Asset and lifecycle register: model class, firmware, end-of-support date, certificate expiry.
- Preventive maintenance calendar.
- Service report after each visit.
- Quarterly lifecycle report.
- Spares list.
Worked to
- IEC 62443-2-1
Questions we are asked first
Who actually answers when we call?
Someone who has been to your site and knows the estate under the agreement. The register and the service reports mean the person on the phone is not starting from zero, whichever of us picks up.
Will a firmware update break a vendor's supported configuration?
Not without checking first. We qualify every update against the application or control vendor's compatibility list, test it where we can, and apply it in a window you already have, not on our own schedule.
Why is there no response-time number on this page?
Because we will not publish a figure we have not agreed with you. The tiers here are defined by consequence, for example a stopped process or an affected safety system, and the minutes are set in your contract, not on a web page.
Does the agreement cover the servers or just the network?
Both, by design. The point of it is that the switch and the servers it exists for are under one agreement, along with the firewall in front and the UPS beneath them.
Related work
Tell us what is bothering you.
An email is enough to start with. A scoping call is free and there is nothing to commit to, and where we are not the right people we will say so and point you at someone who is.
A first call about one site. No charge, and nothing to commit to.
Our named next step: we come to one site and hand you an assessment you can act on.