IT products & value added services
Complementary products and services that run on any cloud, on premises or hybrid. Several are bundled into our SAP Business One hosting by default, and all of them are available on their own for non SAP environments and other ERPs.
IT products & value added services
Complementary products and services that run on any cloud, on premises or hybrid. Several are bundled into our SAP Business One hosting by default, and all of them are available on their own for non SAP environments and other ERPs.
MFA, Passwords & Advanced Printing
Multi factor authentication and password policy that hold up, plus remote to local printing that just works.
Two unglamorous problems decide whether a hosted environment is actually usable. The first is access: passwords alone stopped being sufficient years ago, and credential theft remains the most common way an attacker gets in through the front door rather than the wall.
Multi factor authentication closes that, backed by password management and system policies that are enforced rather than documented. The point is to make the secure path the easy one, because policies that fight people get worked around, and a written down password is worse than a weak one.
The second problem is printing. Remote sessions and local printers have a long history of not getting along: driver mismatches, queues that vanish, invoices that print in the wrong office. Advanced Printing sends output from the remote session straight to the printer next to the user, without installing that printer's driver on the server.
Scope: Available standalone. Works with any remote or hosted environment.
What's included
- Multi factor authentication: A second verification factor on top of the password, so a stolen credential is not by itself an entry.
- Password management: Centrally managed credentials with rotation and strength policy, replacing the spreadsheet everyone pretends does not exist.
- Secure system policies: Session, lockout and access policies enforced at the platform rather than left to individual discipline.
- Remote to local printing: Print from a remote SAP Business One session directly to the printer beside you, at full quality.
- No driver conflicts: No need to install every user's printer driver on the server, which is where remote printing usually breaks.
- Works with hosted and on premises: Deployable against our hosted environments and against remote setups you already run.
Remote desktop access tool
Secure remote access to SAP Business One through a browser: the capability of RDS, without the licence stack.
Remote access to a Windows application has historically meant one of two things: a Microsoft RDS deployment with its licensing and infrastructure, or Citrix with its cost and its specialists. Both are defensible at enterprise scale. Neither is proportionate for a company that needs forty people to reach SAP Business One from wherever they are.
TSplus publishes applications to a browser. Users open a web portal, authenticate, and work in SAP Business One as though it were local. No client install, no VPN client to troubleshoot, no per device configuration when someone changes laptop.
We deploy it, secure it and manage it: role based permissions so people reach only what they should, SSL encryption on the session, and the same monitoring and support that covers the rest of your environment.
Scope: Available standalone. Publishes SAP Business One or any Windows application.
What's included
- Browser based access: SAP Business One and your other Windows applications published to a web portal, with nothing to install on the client.
- Role based permissions: Users see the applications their role allows and nothing else, managed centrally rather than per machine.
- SSL encrypted sessions: Traffic encrypted end to end, with the portal published securely instead of exposing RDP to the internet.
- No RDS or Citrix licensing: The same practical capability without the licence stack and the specialist administration those platforms assume.
- Works with advanced printing: Pairs with our advanced printing service so a remote session prints to the printer beside the user, without driver conflicts.
- Deployed and managed: Installation, hardening, updates and support handled by us as part of your environment.
CrowdStrike Endpoint Protection
CrowdStrike Falcon, deployed and managed by us. AI driven detection that stops ransomware before it spreads.
Signature based antivirus recognises malware it has seen before. That is a shrinking share of what actually reaches your endpoints, because the profitable attacks are the novel ones and ransomware operators rewrite their payloads faster than signature lists update.
CrowdStrike Falcon works from behaviour instead. It watches what a process does: the sequence of actions that constitutes an attack rather than the file that carries it. That is how it stops variants nobody has catalogued yet. The sensor is light enough that users do not notice it, which matters more than it sounds: heavy agents get disabled.
We deliver it as a managed service. Deployment, policy, tuning and the alerts that follow are ours to run, so the platform's detection capability actually turns into a response rather than a dashboard nobody has time to open.
Scope: Available standalone. Protects any endpoint, SAP or not.
What's included
- Next generation antivirus: Behaviour based prevention that catches novel and fileless attacks, not only malware with a known signature.
- AI driven threat detection: Machine learning models trained on global attack telemetry, flagging the patterns that precede compromise.
- Behavioural analytics: Process level visibility that identifies an attack by what it does, so a repackaged payload is not a new problem.
- Ransomware containment: Encryption behaviour blocked at the point it starts, and the affected host isolated from the network before it spreads.
- Lightweight sensor: A cloud native agent with negligible performance cost. No scan windows, no machines crawling on a Tuesday morning.
- Managed deployment and response: Rollout, policy tuning and alert handling run by our team, so detections reach someone who acts on them.
Cyber Security Advisory Solutions
Monitoring, testing and incident response sized to your risk profile and to the regulations your market actually enforces.
Security work divides cleanly into three questions: what is exposed, who is looking, and what happens when something gets through. Most organisations have partial answers to the first, none to the second, and a plan for the third that has never been read under pressure.
We cover all three. Continuous network monitoring for the second, scheduled vulnerability assessment and penetration testing for the first, and a rehearsed incident response process for the third, scaled to your organisation rather than to an enterprise template you would never staff.
Compliance support runs alongside rather than as a separate exercise. The controls that satisfy an auditor are largely the controls that reduce real risk, and the regulations that apply to you depend on where you operate, which is why our market pages set them out region by region.
Scope: Available standalone. Covers your whole estate, not only what we host.
What's included
- Network monitoring: Continuous visibility of traffic and access patterns, with alerting on the behaviour that precedes an incident.
- Vulnerability assessment: Scheduled scanning across your estate, findings ranked by exploitability and business impact rather than raw CVSS.
- Penetration testing: Directed testing against your live environment, with a report your engineers can act on and your auditor can read.
- Endpoint safeguards: Device level protection, hardening and policy enforcement across the machines your people actually work on.
- Incident response: A defined process, agreed contacts and rehearsed containment steps, decided before the incident, not during it.
- Compliance support: Evidence, controls and documentation mapped to the regulations that apply in the markets you operate in.
Microsoft 365 Solutions
Licensing, configuration and support for Microsoft 365, integrated with the cloud environment your ERP already runs in.
Most companies already have Microsoft 365. Far fewer have it configured well: licences assigned to people who left, SharePoint used as a file dump, Teams sprawl nobody governs, and a tenant whose security defaults were never revisited after the trial.
We take the whole thing: licensing, configuration and ongoing support for Outlook, Teams, SharePoint and the Office suite, and run it as a managed service. That includes right sizing the licence mix, which is usually where the first saving is.
The part that matters if you host with us is the integration. Identity, access and security policy applied once across both your Microsoft 365 tenant and your SAP Business One environment, rather than maintained twice and drifting apart.
Scope: Available standalone. Integrates with your hosted SAP Business One.
What's included
- Licence management: The right licence for each role, assignments kept current, and the mix reviewed rather than renewed on autopilot.
- Tenant configuration: Security defaults, sharing policy and access rules configured deliberately instead of left where the trial put them.
- Outlook and email: Mail, calendars and shared mailboxes set up, migrated where needed, and supported.
- Teams and SharePoint: Structure, permissions and governance so collaboration stays findable as it grows.
- Integration with your cloud: Identity and security policy applied consistently across Microsoft 365 and your hosted SAP Business One environment.
- Ongoing support: The same support line that covers your ERP covers your productivity suite: one number, not two vendors pointing at each other.
Where we deliver
Available across every market we serve, deployed into the cloud region your data has to stay in. Each region below sets out the regulations it answers to.
Compliance is shared between provider and customer. We provide the infrastructure controls, evidence and documentation on our side of that line: residency, encryption, access control, backup, monitoring and incident response. Your obligations as data controller remain yours. This page is general information, not legal advice; confirm your specific obligations with your own counsel.
Additional services
Move to the cloud, the right way.
Let's talk about your SAP environment, your security and your growth plan. Migration with minimal disruption is what we do.
Common questions
Why is multi factor authentication necessary if we have strong passwords?
Because password strength does not help against theft. Phishing, credential stuffing and reused passwords hand an attacker a valid credential, and a second factor is what makes that credential insufficient on its own.
Why does printing from a remote session usually fail?
Because the remote server needs a driver for every printer a user might print to, and those drivers conflict, break on update, or simply are not installed. Advanced Printing removes the server side driver from the equation entirely.
Can users print to any local printer?
Yes. The printer beside the user, at full quality, without an administrator installing anything on the server first.
Does this work with environments you do not host?
Yes. Both the authentication layer and advanced printing can be deployed against remote environments you already run.
How is TSplus different from Microsoft RDS or Citrix?
It delivers the same practical outcome (Windows applications reachable remotely) without RDS client access licensing or Citrix's cost and administrative overhead. For mid sized deployments that is usually a large saving with no functional loss.
Do users need to install anything?
No. Users open a web portal in a browser and authenticate. There is no client to install, no VPN client to configure, and nothing to reconfigure when someone changes machine.
Is it secure enough to expose to the internet?
The portal is published over SSL with role based permissions, and we pair it with multi factor authentication. That is a materially different exposure profile from opening RDP to the internet, which nobody should do.
Can we use it for applications other than SAP Business One?
Yes. TSplus publishes Windows applications generally, so the same portal can carry your other line of business software.
How is CrowdStrike different from traditional antivirus?
Traditional antivirus matches files against known signatures, so it only recognises malware someone has already catalogued. CrowdStrike Falcon identifies attacks by behaviour: what a process is doing. That is how it stops new variants and fileless attacks that have no signature to match.
Will it slow our machines down?
No. The Falcon sensor is cloud native and lightweight, with the analysis happening off the endpoint. There are no scheduled full disk scans, which is where traditional agents cost users their morning.
Do we need CrowdStrike if our SAP Business One is hosted with you?
Hosting secures the server side; endpoints are the other half. Most ransomware arrives through a laptop, so protecting the machines your people actually use is what closes the loop.
Do you manage it, or do we?
We do: deployment, policy, tuning and alert handling. You can retain visibility and your own console access; what you do not have to do is staff someone to watch it.
What does a vulnerability assessment involve?
Scheduled scanning of your systems and network for known weaknesses, followed by a ranked report. We rank by exploitability and business impact rather than raw severity score, because a critical finding on an unreachable host matters less than a moderate one on your perimeter.
How often should we run penetration testing?
Annually as a baseline, and after any significant change to the environment: a migration, a new public facing service, a merger. Several regulatory frameworks in the regions we serve set their own minimum, which we map on the market pages.
What happens if we are breached?
The incident response process runs: containment first, then investigation, then recovery and a written post incident report. Contacts, authority to act and containment steps are agreed with you in advance, because an incident is a poor time to be deciding who can shut down a server.
Do you help with regulatory compliance?
Yes. We provide the evidence, controls and documentation on our side of the boundary, mapped to the regulations that apply where you operate. Compliance is shared between provider and customer, so we are explicit about which half is ours.
Can you take over a Microsoft 365 tenant we already have?
Yes. We audit the tenant as it stands (licences, security configuration, sharing policy), tell you what we would change and why, then take on the running of it.
Will you help us reduce Microsoft 365 licensing cost?
Usually, yes. The common findings are licences still assigned to people who have left and users on a tier above what their role needs. Right sizing the mix is part of taking the tenant on.
How does Microsoft 365 integrate with hosted SAP Business One?
Identity and security policy are applied once across both, so access, authentication and offboarding happen in one place. Practically, that means a departing employee loses ERP and email access in the same action.
Do you migrate email from another provider?
Yes. Mailbox, calendar and shared mailbox migration into Microsoft 365 is part of the service, planned so users keep working through the move.