FAQ

Questions people
actually ask us.

If yours isn't here, ask an engineer directly — no forms-to-nowhere.

What does Do Now actually do?

We're a Singapore IT engineering and cybersecurity partner. That covers ten IT disciplines (cloud, custom software, managed IT, data & AI, networking, digital transformation, DevOps, IoT, backup & continuity, and fractional CIO advisory) and six cybersecurity disciplines (VAPT, 24/7 SOC & MDR, governance & compliance, zero trust, cloud security, and incident response). Most clients use a combination, not a single service — see the full breakdown on our services and cybersecurity pages.

How does pricing work?

There's no generic price list because the work isn't generic — a managed IT retainer for a 20-person office and a 24/7 SOC engagement for a financial institution have nothing in common cost-wise. We scope every engagement after the Discover stage of our process, so you get a number based on your actual systems and risk, not a guess.

How fast can you start?

Discovery calls are typically booked within days of your enquiry. Full engagements start on a timeline that matches the work — a managed IT handover might take one to two weeks to transition cleanly; a security audit can begin almost immediately.

What's your actual SLA for managed IT and SOC clients?

Helpdesk response times are measured in minutes, not hours. Our published median incident response time for SOC clients is 12 minutes, and we target 99.9%+ uptime on core collaboration and monitored infrastructure, with credits if we miss it. Specific SLA terms are set per contract based on the systems covered.

Do you work with businesses outside Singapore?

Our base and SOC operate from Singapore, and most of our clients are Singapore-based or SEA-based businesses with Singapore compliance obligations (PDPA, MAS TRM). We do support regional offices for existing Singapore clients — talk to us about your specific footprint.

Can you help us get PDPA, MAS TRM, ISO 27001 or CSA Cyber Trust compliant?

Yes — this is a core part of our governance & compliance practice. We treat compliance as an engineering requirement with an evidence trail, not a document produced right before an audit. See our governance & compliance page and our guides on PDPA and CSA Cyber Trust in Insights.

We already have an in-house IT person — can you work alongside them?

Regularly. Many clients keep one internal person who owns vendor relationships and day-to-day priorities while we handle specialist work (security, cloud architecture, 24/7 monitoring) that's expensive or impractical to hire for directly.

What happens if we have a security incident outside office hours?

Our SOC monitors 24/7, including public holidays. If something's flagged, our on-call team is engaged immediately — this is the same team that handles planned incident response engagements, not a separate after-hours contractor.

Do you sign NDAs before scoping calls?

Yes, as standard practice for any conversation that touches your systems, architecture or data in detail. Ask when you book your audit call.

No questions match "". Ask an engineer directly →

Still have a question?

Talk to an engineer →