Skip to main content

Virtual ISP

The build estimate is usually the easy part. Someone prices the hardware, adds an engineer or two, and the number looks survivable. What tends to get missed is everything that only starts once the equipment is racked: the redundancy, the on-call rota, the support center you now have to hire for, and the months of lead time before a single subscriber notices any of it. This walks the full cost model and the decision that follows from it.

Aureon · Contact Center & Virtual ISP

Offering internet service under your own brand means running two businesses at once. There is the network, which is an engineering problem, and there is the subscriber relationship, which is a staffing problem. Build estimates tend to price the first one carefully and the second one as an afterthought, which is roughly backwards, because the phones never stop and the hardware mostly does what it was told.

What "build" actually includes

The Cost Model

Rather than quote figures that would not survive contact with your own vendor quotes, here is the line-item structure. Price each of these against real numbers from your suppliers and your finance team, and the comparison stops being a debate about ambition.

Price these

Core infrastructure

DNS and DNSSEC · DHCP · RADIUS · Redundancy · DNS security and filtering

Three services do the unglamorous work of an ISP. DNS resolves the names subscribers type, DHCP hands out the addresses their equipment needs, and RADIUS authenticates them onto the network and records the session. None of them are exotic. All of them are the sort of thing nobody notices until they stop, at which point every subscriber notices simultaneously. The cost that gets underestimated here is not the primary hardware, it is the second set that exists purely so the first can fail without taking your service with it, plus the DNS security and filtering layer you will want the first time something nasty comes through.

The costs that never make the estimate

Four things reliably get left out, and between them they tend to be larger than the hardware line everyone argued about.

Time to first subscriber

Procurement, racking, configuration, testing, hiring, training. All of it happens before anyone can buy anything from you, and none of it generates revenue. The question worth asking your team is not what the build costs but what the delay costs, because a competitor launching two quarters earlier is taking subscribers you will later have to win back rather than simply acquire.

The on-call rota

Twenty-four hour coverage of infrastructure is not a rounding error on an engineer's salary. It is either a rota that needs enough people to be sustainable, or it is two engineers quietly burning out and eventually leaving with everything they knew about your setup.

Knowledge walking out

A small team running specialised infrastructure is a concentration risk. When the person who configured RADIUS leaves, the documentation is never as good as everyone assumed. Price the documentation discipline, or price the outage.

Brand damage during the learning period

New operations make mistakes. That is normal and survivable in most functions, but subscriber support is the one place where the learning curve is experienced directly by the customer. Early churn is the most expensive kind, because you paid to acquire those subscribers and got nothing back.

The honest framing
Build is not the expensive option because of the hardware. It is expensive because it converts a variable cost into a fixed one, and does so before you know how big the subscriber base will get.

What the white-label side changes

A white-label model inverts the structure. The infrastructure and the support floor already exist and are already staffed, so you are buying access to them rather than building them. Aureon's own Virtual ISP figures put that at zero build-out, with DNS infrastructure handling up to 75,000 queries per second and around-the-clock monitoring behind it. Those are Aureon's service claims rather than independent research, and the same question applies to any vendor: ask what capacity and coverage you are actually buying, in writing.

The trade is control. You are dependent on somebody else's roadmap, their maintenance windows, and their staffing decisions. For most providers that is a good trade, because none of those things were a differentiator anyway. If your network architecture is the product you are selling, it may not be.

How to decide which path fits

The Framework

The decision usually comes down to three things: how certain your growth is, whether the infrastructure is a differentiator, and how much fixed cost your balance sheet wants to carry before the subscribers arrive.

White-label tends to win when

Your subscriber forecast has real uncertainty in it. You want to be selling this quarter rather than next year. Internet service is a way to deepen an existing customer relationship rather than the thing you are famous for. You are entering a new market and would like the option to leave it without stranding capital. Or you simply do not want a 24-hour engineering rota to be one of the things you manage.

Building tends to win when

Volume is high enough and predictable enough that fixed cost beats per-subscriber pricing, and you can say that with numbers rather than optimism. Or the network genuinely is your product, and specific architecture, peering or performance characteristics are what you sell against. Or you already run comparable infrastructure and adding these services is incremental rather than a standing start. Regulatory or contractual terms may also require direct control, which settles it regardless of the arithmetic.

The number that actually decides it

Work out the subscriber count at which your fully loaded build cost per subscriber drops below what a white-label partner would charge you. Fully loaded means everything above, including the on-call rota and the recurring recruiting, not just hardware divided by users. Then compare that number honestly against your forecast.

If the crossover point sits comfortably below where you expect to be in eighteen months, building has a case. If it sits above your forecast, or if you find yourself arguing that the forecast is conservative, you have answered the question. Plenty of providers also start white-label and revisit at renewal, which is the sensible order given that the build option does not expire.

Ask before you model
Get a white-label quote before you build the business case, not after. It is the only way to know where your crossover point actually is, and it costs you a conversation.

Virtual ISP Readiness Checklist

The Checklist

Fifteen questions across the five areas that decide whether adding subscribers grows the business or just grows the overhead. Tick the ones you can answer without going and asking someone, and the score updates as you go. Use it yourself or share it with your team.

0 of 15 answered confidently

Tick what you can answer without checking. The blanks are the gaps.

Infrastructure Capacity

Do you know your DNS query volume at peak, not average?

Capacity planning done on averages fails on the evening everyone streams at once.

What happens if your primary DNS or RADIUS node fails right now?

If the answer involves someone driving somewhere, you have a single point of failure rather than redundancy.

Could you double your subscriber base without new hardware?

Growth that requires a procurement cycle is growth you cannot accept quickly.

Subscriber Onboarding

How long from sign-up to a working connection?

Every day in between is a day the subscriber is paying attention to the wrong thing.

Do you know how many new subscribers leave in the first month?

Early churn is the most expensive kind. You paid to acquire them and got nothing back.

How many support contacts does a typical activation generate?

If activation reliably produces a call, the onboarding process is the problem rather than the subscriber.

Support Coverage

Who answers at 10pm when someone cannot get online?

Connectivity problems do not keep office hours, and evenings are when subscribers actually notice them.

Do you know your abandon rate, and is a callback offered?

A subscriber who gave up waiting has not gone away. They have gone to look at alternatives.

Who carries the pager when infrastructure breaks overnight?

If the honest answer is one or two people indefinitely, that is an attrition risk rather than a rota.

Billing Workflows

Can a subscriber change payment details without reaching an engineer?

Billing questions are the most common contact reason in most subscriber operations, and the least suited to technical staff.

How much of your support volume is billing rather than technical?

Most providers guess low. Measuring it usually reshapes how you staff.

Would adding a thousand subscribers require adding back-office staff?

If subscriber growth and headcount growth are locked together, margin does not improve with scale.

Brand Consistency

Whose company do subscribers hear when they call support?

If it sounds like an outside call center, every interaction is building somebody else's brand.

Are email, chat and phone all presented as you?

One unbranded channel is enough to tell subscribers the operation is outsourced.

Does anyone review what subscribers were actually told?

Recording without review is storage. Somebody has to listen for it to protect the brand.

Frequently asked questions

A virtual ISP is a provider that sells internet service under its own brand while a partner runs the infrastructure and subscriber support behind it. You own the customer relationship, the pricing and the brand. The partner operates the DNS, DHCP and RADIUS services, monitors the network, and answers subscriber calls as your company. It lets a business offer connectivity without building a network operations team or a support center first.

White-label internet service means the infrastructure and support are delivered by a partner but presented entirely as your brand. Subscribers see your name on the bill, hear your company name when they call, and receive branded email and chat. The practical test of a white-label arrangement is whether any subscriber touchpoint reveals the vendor behind it. If one channel is unbranded, the arrangement is only partly white-label.

At minimum you need DNS, DHCP and RADIUS services, each with enough redundancy that a single failure does not take the service down, plus DNS security and filtering. Around that sits monitoring, patching and upgrade processes, an on-call rota for overnight failures, and billing and subscriber management systems. The infrastructure itself is rarely the expensive part. The recurring cost of keeping it running and staffed is what tends to be underestimated.

They handle the three things that must work before a subscriber can use the internet. DNS resolves the domain names people type into the addresses their devices need. DHCP assigns those devices an address on the network automatically. RADIUS authenticates subscribers onto the network and records their sessions for accounting. None of them are visible to a subscriber when working correctly, and all of them are immediately visible to every subscriber at once when they fail.

It depends on subscriber volume and how predictable that volume is, so the useful exercise is finding your crossover point. Work out the subscriber count at which your fully loaded cost per subscriber drops below what a white-label partner would charge. Fully loaded means hardware and redundancy plus engineering salaries, the on-call rota, recurring recruiting and training for support staff, and billing systems, not hardware divided by users. If the crossover sits above your realistic forecast, white-label is cheaper for you.

Building from scratch means procurement, installation, configuration, testing, hiring and training before a single subscriber can be sold to, and every stage of that runs before revenue starts. A white-label launch removes the infrastructure and staffing timeline because both already exist, so the work becomes branding, integration and process rather than construction. When comparing the two options, price the delay as well as the build, since a competitor launching earlier takes subscribers you then have to win back rather than simply acquire.

They should not be able to, and whether they can is a fair thing to test before signing. Agents should answer as your company through branded call queues, with branded email and chat, so no touchpoint reveals a vendor. Ask a prospective partner to demonstrate the full subscriber journey as your brand rather than describing it, and check every channel rather than just the phone. Subscribers who realise support is outsourced tend to attribute problems to the arrangement rather than the issue.

Building makes sense when volume is high and predictable enough that fixed cost beats per-subscriber pricing, and you can demonstrate that with numbers rather than an optimistic forecast. It also makes sense when the network genuinely is your product, meaning specific architecture, peering or performance characteristics are what you sell against, or when you already operate comparable infrastructure so these services are incremental rather than a standing start. Regulatory or contractual requirements for direct control can settle it regardless of cost.

Want to know where your crossover point is?

Get a Virtual ISP walkthrough. We'll go through the checklist with you and give you a number to model against.

Talk About Virtual ISP