Managed IT services is an arrangement where an outside provider takes ongoing responsibility for running and protecting an organization's technology for a recurring fee. Unlike hourly support, the provider is paid to prevent problems as well as fix them, so monitoring, patching, backups, security and planning become continuous work instead of reactions to failures.
This guide is written for owners, operations managers and finance leads at organizations with roughly 10 to 250 people who are deciding whether to hand their IT to a provider, or whether the provider they already have is doing the job. It covers what the service includes, what it normally does not, how it is priced, how to tell when you need it, and what to ask before you sign.
What does a managed IT provider actually do?
A managed service provider (MSP) runs the day-to-day operation of your technology under a standing agreement. The work falls into five groups.
Monitoring and maintenance. Servers, workstations, network equipment and cloud services are watched continuously for failures, full disks, expiring certificates and security events. Operating systems and applications are patched on a schedule, and the results are checked rather than assumed.
Support for your people. A help desk handles the requests staff raise every day: passwords, email, printers, new accounts, software that will not open. This is the part most people see, and it is only a fraction of the work.
Security operations. Endpoint protection, email filtering, multi-factor authentication, firewall management and account hygiene are configured, monitored and kept current. Security is not a separate product bolted on at the end; most of it is ordinary IT administration done carefully. Our cybersecurity services page describes how that work is organized.
Backup and recovery. Data and systems are backed up, and restores are tested. An untested backup is an assumption, not a recovery plan. See backup and disaster recovery.
Planning and vendor management. Hardware refresh cycles, licensing renewals, internet and phone carriers, and line-of-business software vendors are tracked, so renewals and replacements are planned instead of discovered.
A useful way to judge scope is the NIST Cybersecurity Framework 2.0, which organizes security work into six functions: Govern, Identify, Protect, Detect, Respond and Recover (NIST CSF, retrieved 2026-09-29). A provider that only fixes things is working in Respond. A managed provider should be doing meaningful work in every function, including the unglamorous ones: keeping an accurate inventory (Identify) and agreeing on who decides what (Govern).
What is usually not included in a managed IT agreement?
Most disputes with a provider come from scope that was never written down. These items are commonly outside the monthly fee, and a good agreement says so explicitly:
- Projects. Office moves, server replacements, cloud migrations and new site build-outs are normally quoted separately, because their size varies too much to fold into a flat fee.
- Hardware and licenses. The fee covers managing equipment and software, not buying it. Some providers resell both; you should be able to see the cost of each line.
- Line-of-business application support. The provider keeps the systems running, but deep support for specialized software (practice management, ERP, CAD) often stays with that software's vendor, with the MSP coordinating.
- After-hours and on-site time. Whether nights, weekends and site visits are included, capped or billed separately varies widely between providers and between plans.
- Compliance deliverables. Keeping systems secure is part of managed IT. Writing a System Security Plan, preparing for a formal assessment or producing audit evidence is usually separate work. See compliance services.
None of these exclusions is a problem on its own. The problem is finding out about one after you needed it.
How is managed IT priced?
Most providers use one of three structures:
| Model | How the fee is calculated | Works best when |
|---|---|---|
| Per user | A monthly rate for each person supported, covering their devices and accounts | Most staff use similar equipment and cloud services |
| Per device | A rate for each workstation, server and network device under management | Equipment counts matter more than headcount, such as shared workstations or plant-floor systems |
| Tiered or bundled | Defined packages at increasing levels of service and security | You want to compare a small number of clearly defined options |
The structure matters less than what drives the number: how many people and systems are covered, how much of your environment is on-premises versus cloud, how deep the security stack goes, whether a compliance framework applies, what hours are covered, and how often someone needs to be on site. We cover each factor, and how to read a quote against it, in what drives managed IT pricing.
How do you know when you have outgrown ad-hoc IT support?
Many organizations run for years on a part-time contractor, a knowledgeable employee or a computer shop that comes out when something breaks. That can be the right choice for a small office. These are the signs it has stopped being enough:
- The same problems keep coming back. Each fix is real, but nobody owns the cause, so the problem returns.
- Nobody can say what you have. There is no current list of devices, accounts, licenses, admin passwords or who has access to what.
- Patching is somebody's intention rather than a verified fact. Updates happen when someone remembers, and nobody checks whether they succeeded.
- Your backup has never been restored. You believe you have backups, but nobody has recovered a real system from one under time pressure.
- A customer, insurer or contract is asking questions you cannot answer. Security questionnaires, cyber insurance applications and contract clauses increasingly require documented controls.
- One person holds everything. If your IT knowledge lives in one employee or one contractor, their vacation, illness or departure is an outage.
If three or more of these describe you, the cost of continuing as you are is probably already larger than it looks. We compare the two models directly in managed IT vs. break/fix support.
Fully managed, co-managed or break/fix: which model fits?
Break/fix means you call when something fails and pay for the time. It is simple and has no monthly commitment, but nobody is paid to prevent problems, and costs arrive when you can least absorb them.
Fully managed means the provider is your IT department. This suits organizations without internal IT staff.
Co-managed means the provider works alongside an internal IT person or team, taking the work they lack time or specialist skill for: after-hours monitoring, security operations, patching at scale, or project capacity. The internal team keeps ownership. See co-managed IT.
The right answer depends less on company size than on whether you have anyone internal whose job is IT, and how much risk you carry if systems or data are unavailable.
What should you ask a managed IT provider before signing?
Sales conversations tend to focus on features. These questions focus on what happens when things go wrong, and on the risks a provider itself introduces.
Who owns the keys? Administrator credentials, domain registrations, cloud tenants and documentation should be owned by your organization, with the provider given access. Ask how you would get everything back if you left.
How is the provider itself secured? An MSP holds administrative access to all of its clients at once, which makes it a target. CISA and its international partners published joint guidance on exactly this risk (AA22-131A, Protecting Against Cyber Threats to Managed Service Providers and their Customers, retrieved 2026-09-29), and CISA's Cross-Sector Cybersecurity Performance Goals 2.0 include goals addressing managed service provider risk (CISA CPGs, retrieved 2026-09-29). Ask whether the provider uses multi-factor authentication on every tool that can reach your systems, how its remote access is restricted, and how it would tell you if it were breached.
What exactly is in scope? Ask for the scope in writing, including the exclusions in the section above, and how out-of-scope work is quoted and approved.
What happens in the first 90 days? A competent onboarding includes discovery, documentation, credential handover from any previous provider, security baseline fixes, and a written list of risks found. If onboarding is described as "we install our agent," ask what happens next.
How will you know the work is being done? Ask what reporting you receive: patch compliance, backup success and restore tests, security events, open risks. Reports should describe your environment, not the provider's activity volume.
What are the contract terms? Look at term length, renewal, termination notice, and what the provider must hand over when the relationship ends.
Who will you actually talk to? Ask whether you will work with a consistent team that knows your environment, and how escalation works when the first person cannot solve a problem.
Does a local provider matter if most support is remote?
Most managed IT work is remote: monitoring, patching, account administration and most help desk requests never need anyone on site. Physical work still happens, though: network cabling, a failed switch, a new office, a server that will not power on, a site that has lost connectivity entirely.
If you have physical locations, ask how on-site work is dispatched, from where, and how it is billed. A provider with no local presence may subcontract site visits, which is workable but worth knowing in advance. Organizations in the Aiken and Augusta area can see how we handle this on our managed IT services page.
What should you do next?
Write down the six signs above and mark which apply to you. Collect what you know about your environment: number of people, devices, servers, locations, cloud services, and any contract or insurance requirements that mention security. That list is the basis of any accurate quote, from any provider.
If you want a second opinion on your environment or on a proposal you have already received, request an IT and security assessment.
