Summary
JAFLAC Systems and Services, a growing MSP based on Sydney’s Northern Beaches, was managing multiple security tools across different clients, and looking for a more simplified, scalable approach. After evaluating several alternatives, founder James Frost switched to Guardz in September 2025, consolidating everything into a single platform. The result: per-user costs cut by more than half, real threats caught and contained, and a simpler, more confident conversation with clients about their cybersecurity.
The Challenge
Before adopting Guardz, JAFLAC Systems and Services was running security for its client base across a patchwork of tools including Sophos, N-able and Microsoft Defender. Each product covered a slice of the picture, from filtering to endpoint protection to security awareness training, but none of it was tied together. For a small, growing MSP, that meant separate consoles, separate invoices and no single view of client risk.
James Frost, founder of JAFLAC, was looking for three things: simplification, a stronger overall security strategy for clients, and a better cost structure. It’s part of a broader push at JAFLAC to reduce everything down across the board, consolidating tools wherever possible.
Weighing up the alternatives
James didn’t move to Guardz without first looking around. He considered building on a full Microsoft security stack, evaluated Huntress, and took a fresh look at Sophos, noting that they had altered their offering since he’d last used it. None matched what he was after: a truly integrated platform rather than a set of siloed components. He was also unimpressed by the responsiveness of some competing MDR teams during his evaluation, noting that with one option, the MDR team simply didn’t work at all.
Why Guardz cybersecurity?
Manage Protect recommended the Guardz solution for several reasons. The financial case was straightforward… JAFLAC’s previous combination of tools was costing upwards of $40 per end user, compared with under $15 per user on Guardz once Sophos, the relevant N-able modules and a Microsoft Defender licence were retired. As James put it, it all came into one product, with one oversight and one price.
JAFLAC is currently on the Ultimate plan, with a mix of clients – tradespeople and solo traders through to medium enterprises with more complex security and compliance requirements.
Getting up and running
The early implementation had some friction. James pointed to a lack of documentation, uncertainty about the downstream impact of configuration changes, and manual imports for whitelists and blacklists. Security awareness training could initially only be delivered one course at a time, making it hard to bring new starters up to speed quickly.
James acknowledges that the Guardz platform has improved these areas since. Onboarding a new client now takes 20 to 30 minutes, including a self-install option for end users, and JAFLAC has stopped customising most tenant setups, relying instead on Guardz defaults. Day to day, James values that the platform holds a persistent session rather than logging out every hour, as Sophos previously did, and that switching between clients takes a single drop-down rather than repeated logins.
Handling real incidents
Guardz has already proven itself on real threats. It flagged an unusual sign-in when James logged into a client’s cloud PC remotely, and separately detected and shut down a credential-stuffing attack against a client’s managing director before it could escalate into a full breach. For James, incidents like these give him confidence that he can let the platform do its thing and know his clients are covered.
James also praised the ability to drop into the underlying SentinelOne and Check Point Avanan consoles for finer-grained control, such as creating a process exception to fix a false block on a client’s device, something not possible from the Guardz interface alone.
James acknowledges that the Guardz platform has improved these areas since. Onboarding a new client now takes 20 to 30 minutes, including a self-install option for end users, and JAFLAC has stopped customising most tenant setups, relying instead on Guardz defaults. Day to day, James values that the platform holds a persistent session rather than logging out every hour, as Sophos previously did, and that switching between clients takes a single drop-down rather than repeated logins.
Changing the conversation with clients
Beyond the technical fit, James says Guardz has reshaped how he talks to clients about security. Rather than juggling multiple portals to piece together a picture of a client’s risk, he can pull up a single dashboard, show a client their incident pie chart, and point to specifics such as old passwords found circulating on the dark web.
"As soon as you flick the computer around, show them a pie chart... they go, 'oh yeah, this is great.'"
- James Frost, JAFLAC Systems and Services
That visibility has also changed JAFLAC’s commercial model. Rather than pitching individual vendor products, which meant re-opening the “should we switch security brands” conversation every time, James now sells a flat managed security package, currently around $30 for a base tier or $50 for a bundled offering. Because Guardz sits underneath as infrastructure rather than a named product, JAFLAC can adjust its stack without unsettling clients or re-litigating the sale, and there’s enough margin built in to stay flexible.
The Verdict
James’s overall assessment is strongly positive, even allowing for a few rough edges he’d like Guardz to address. Reporting is the main one: the incident timeline has improved a great deal but there’s still no way to export a polished, customer-ready PDF summary, and he’s not convinced by the platform’s built-in prospecting report.
None of this dampens his recommendation. James’s advice to other MSPs considering consolidation is that the barrier to entry is low, with a full trial achievable within a day.
"You've got top products right down the line there. I really don't see any negatives around it."