Netmon: One Network Monitoring Platform Built for Modern MSPs

Netmon: One Network Monitoring Platform Built for Modern MSPs

Managing a customer network is no longer as simple as checking whether a server is online. Today’s IT environments include laptops, desktops, servers, printers, cameras, switches, wireless devices, databases and other connected equipment. A device may remain technically “online” while suffering from packet loss, high latency, unstable connectivity or an exposed service that creates unnecessary risk.

Hi, I'm Steve Richards and for 18 years I was an MSP before becoming an MSSP, I finally reached the point where nothing good was changing in the industry, the same big players selling the same solutions with more bolt on's each year.

When I completed my Masters my dissertation revolved around the fact that there were very few vendors who provided really great cybersecurity and IT monitoring tools at a price the smaller business with under 50 employees could afford. The one man band or certainly up to 5 members of staff would struggle to expand without paying a fortune for tools. And for what? Every month we hear of some business that was hacked and they had those tools, but couldn't stop the hackers spending weeks on their systems before being discovered.

For managed service providers (MSPs), identifying these problems early is essential. Customers expect reliable systems, rapid support and clear evidence that their IT investment is delivering value. Netmon, the network monitoring platform from Angstep, is designed to help MSPs bring monitoring, vulnerability awareness, reporting, remote access and ticketing together in one place.

More than an uptime monitor

Traditional monitoring tools often focus primarily on availability. They tell you when a device stops responding, but that is only one part of the picture. A network can be experiencing serious performance problems long before a complete outage occurs.

Netmon monitors real-world network behaviour, including:

* Device availability.
* Latency trends.
* Packet loss.
* Intermittent or “flapping” connectivity.
* Newly discovered devices.
* Vulnerabilities associated with monitored systems.
* Potentially exposed services and ports.

This broader approach allows an MSP to investigate degraded performance before it becomes a customer-reported incident. A workstation that intermittently drops packets, a server with increasing latency or a network device that repeatedly disconnects may all indicate problems that deserve attention.

The aim is straightforward: detect issues while they are still manageable, rather than waiting for the customer to call.

Automatic device discovery

One of Netmon’s key capabilities is automatic discovery of devices on a client’s local network. A lightweight agent installed at the site can identify equipment connected to the LAN, helping create a current picture of the customer’s environment.

This may include:

  • * Workstations and laptops.
  • * File and application servers.
  • * Printers.
  • * Network infrastructure.
  • * Security cameras.
  • * IoT equipment.
  • * Other connected devices.

Maintaining an accurate asset list is difficult when it relies on spreadsheets or occasional manual surveys. Devices are added, replaced and moved over time, while documentation can quickly become outdated.

Automatic discovery provides a more practical starting point. It gives the MSP visibility of what is present and helps highlight changes that may need investigation. An unfamiliar device appearing on the network, for example, may be a legitimate addition—or something that should not be connected at all.

Monitoring that notices degradation

A major advantage of proactive monitoring is the ability to identify gradual or intermittent faults. Complete outages are usually obvious, but degraded services can be more difficult to diagnose.

Users may report that applications are “slow”, video calls keep freezing or access to a shared system is unreliable. Without historical monitoring data, an engineer may have little evidence beyond the user’s description.

Netmon’s availability, latency and packet-loss tracking can provide useful context. Trends can help show whether a problem is isolated to one device, affecting a wider network segment or occurring at particular times of day.

This information can improve troubleshooting and make customer conversations more objective. Instead of simply saying that a network appears unstable, an MSP can identify measurable changes and investigate them systematically.

Built-in vulnerability awareness

Network monitoring and cybersecurity are closely connected. Knowing that a device is online is useful, but knowing whether it may be exposed to a known vulnerability is much more valuable.

Netmon cross-checks discovered devices against recognised vulnerability information, including the national CVE database and a catalogue of actively exploited threats. This can help MSPs prioritise weaknesses that may pose a more immediate risk.

A vulnerability scan may identify software or services associated with known security issues. Netmon is designed to present those findings in a way that supports practical investigation, rather than leaving the engineer with an overwhelming list of technical identifiers.

This distinction matters because not every theoretical vulnerability presents the same level of urgency. A weakness being actively exploited in the wild may deserve faster action than an issue with limited practical exposure. Highlighting known-exploited threats can help direct attention towards risks that require prompt remediation.

Understand exposed services

Open ports and exposed services can be difficult to explain to non-technical customers. Terms such as remote desktop, file sharing and database services may be familiar to an IT professional, but they do not always communicate the business risk clearly.

Netmon focuses on translating technical findings into plain-language information. An exposed service can then be discussed in terms of what it does, why it may matter and what action should be considered.

This is particularly useful when reviewing remote access configurations. Services intended for internal use can become a security concern if they are unnecessarily exposed to the internet or accessible from an inappropriate network location.

By combining monitoring information with service exposure awareness, Netmon can help MSPs move beyond a simple list of open ports. The objective is to make findings easier to understand and easier to act upon.

Detect rogue devices

An unknown device on a customer network could be harmless, such as a recently installed printer or wireless access point. However, it could also indicate poor asset management, unauthorised equipment or a potentially compromised system.

Netmon supports rogue-device detection using baseline learning. By observing the normal network environment over time, the platform can help identify devices that do not match the expected baseline.

This gives MSPs another way to spot changes that might otherwise go unnoticed. A new device can be investigated, documented and approved—or removed if it has no legitimate business purpose.

Baseline monitoring is especially valuable for organisations without a dedicated internal security team. It provides an additional layer of visibility without requiring staff to manually compare network inventories every day.

Ticketing that starts the response

Monitoring only creates value when it leads to action. Netmon includes automatic ticketing, as well as the ability to create manual tickets when an engineer needs to record work or follow up on a finding.

When a device’s performance falls outside expected conditions, Netmon can open a ticket automatically. This means the support process can begin before the customer reports the issue.

For an MSP, that changes the nature of the conversation. Instead of starting with “What seems to be wrong?”, the engineer may be able to begin with “We have detected an issue and are already investigating it.”

Automatic ticketing can also improve consistency. Alerts become part of a defined workflow rather than depending on someone noticing a dashboard notification and remembering to create a support record.

Remote access without another licence

Remote access is a core part of modern IT support. Engineers need to investigate systems, make changes and resolve issues without always travelling to the customer site.

Netmon includes integrated remote access, allowing monitoring and access capabilities to exist within the same platform. Reducing the number of separate tools can simplify administration and make it easier for engineers to move from a detected issue to remediation.

A unified approach can also help control costs. Instead of paying for separate monitoring, scanning and remote-access products, an MSP can evaluate whether one platform meets more of its operational requirements.

The result is not merely fewer applications on an engineer’s computer. It can also mean fewer dashboards to maintain, fewer integrations to troubleshoot and fewer licences to track.

Reports customers can understand

One of the biggest challenges for MSPs is demonstrating the value of work that customers never see. Monitoring, patching, investigation and security checks are important, but they often happen quietly in the background.

Netmon addresses this with one-click, client-facing PDF reports. These reports are designed to present network and security information in plain English, including:

  • * An overall status.
  • * Devices requiring attention.
  • * Recommended actions.
  • * Positive findings where no immediate fix is required.

Avoiding unnecessary CVE terminology and raw port numbers makes the report more accessible to business owners and managers. Customers can see what has been checked, what needs attention and what is already working well.

This can make regular service reviews more productive. Rather than discussing an invisible collection of technical tasks, the MSP can use a clear report to demonstrate ongoing oversight and explain priorities.

Solutions for the SME

Designed for multi-tenant MSP environments

MSPs need to separate customer data while retaining an efficient operational view. Netmon supports multi-tenant management, allowing client organisations and sites to be managed within the same platform.

This is important for providers supporting multiple businesses, particularly those with several offices or locations. Engineers can monitor individual networks while maintaining a broader view of the customer estate.

The platform’s model is intended to consolidate key capabilities around a single agent, dashboard and bill. That can be attractive to providers looking to reduce the complexity of a monitoring stack assembled from multiple point solutions.

A practical starting point

Netmon is available as a free starting option for monitoring up to 20 devices, with no commitment. This gives an MSP an opportunity to test the platform on a smaller network and assess how well it fits existing processes.

For organisations with multiple sites or larger client estates, the higher-level plans provide broader remote access, multi-site management and support for unlimited client organisations. Activation for these plans requires a demonstration, allowing the provider to explore the platform in more detail.

The most important question is not whether an MSP already has monitoring software. It is whether the current collection of tools provides a complete and efficient view of customer networks.

Netmon is built around the idea that monitoring, vulnerability awareness, rogue-device detection, remote access, ticketing and reporting should work together. By bringing these functions into one platform, it aims to help MSPs detect problems earlier, understand risk more clearly and show customers the value of proactive IT support.[angstep.co]

Steve Richards headshot

Bio for Stephen Richards: Born in Colwyn Bay North Wales, Steve's introduction it Computers was at secondary school in 1974. That first year, Machine Code was hand written onto gridded paper and sent to Connah's Quay Technical College where is was copied to punch card and then entered into a mainframe computer. The results printed out were sent back for the following week!

Steve left School in 1976 joining the Royal Air Force to work on RADAR and communications equipment. His last 5 years involved working in an Automatic Test Equipment (ATE) department on the System Management Team and also writing models for Microchips. It was a good job that he had kept up with computers which had become rather a passion by the time he started in ATE.

During that time the main Mainframe we replaced in a £3.9 million upgrade reducing the run time of the biggest ATE program from just under 2 weeks to the time it took for a finger to come off a depressed return key!

Leaving the RAF after 18 years service Steve worked for a Charity (Apex Leicester Project) before returning to electronics at Sonatest in Milton Keynes which after 3 or 4 years led to a Job at Telematica the then development arm of Trafficmaster PLC (Tm). Eventually brought in-house at Tm he worked moved into the IT Support Team with his last project moving email from a Linux Box to Microsoft Echange for the 300 users in the company each of whom typically had 5 email addresses.

In 2006 Steve left to start his own company back in North Wales, Computer Technical Solutions was an MSP and moved to become an MSSP following another of Steve's passions Cybersecurity. Officially retiring in 2025, by May 2026 that overactive mind started thinking about all of the software he had seen not just for MSSPs but also for his clients that was either extremely expensive or that didn't exist with a complete answer to the needs of the SME.

By August 2026 two significant pieces of software have been created. Netmon the Network Monitoring Software and the second release Parkcore aimed at Caravan/Lodge Holiday Parks..... And so it begins!