What is managed IT? Models, inclusions, and who needs it
Managed IT explained for small businesses: the four common support models, what is usually included and excluded, and who does not need it.
Managed IT is an ongoing arrangement where an outside provider takes responsibility for an agreed part of your business technology, such as computers, accounts, email, network, and backups, and looks after it on a regular schedule for a recurring fee. The alternative is paying for help only when something breaks. Whether you need it depends on how much your business relies on its technology and whether anyone currently owns the routine upkeep.
What does “managed” actually mean?
The US Cybersecurity and Infrastructure Security Agency (CISA) and its partner agencies define a managed service provider, or MSP, as a company that “delivers services, such as network, application, infrastructure and security, via ongoing and regular support and active administration”.
The important words are ongoing and regular. A managed arrangement is defined by recurring work: updates get installed on a schedule, backups get checked, accounts get added and removed as staff change, and someone is responsible for noticing problems. A repair visit is a one-time event. Managed IT is a standing responsibility.
It does not mean any particular company size, a specific set of tools, or a guarantee that nothing will break. Those details vary by provider and by agreement, which is why the written scope matters more than the label.
What are the common IT support models?
Most small businesses use one of four models, or a mix of them.
| Model | How you pay | Who owns routine upkeep | Usually fits |
|---|---|---|---|
| Break-fix | By the hour, when something needs fixing | You do | Very small or simple setups with little that needs regular attention |
| Block hours | A prepaid bundle of hours, used as needed | You do, unless you spend hours on it | Businesses with occasional but recurring needs who want a known rate |
| Per-user or per-device managed | A recurring fee per person or per device covered | The provider, for whatever the agreement lists | Offices where downtime is costly and nobody internal owns IT |
| Co-managed | A recurring fee or hours, scoped around an internal person | Shared between your staff and the provider | Businesses with an internal IT person who needs backup, tools, or specialist help |
A fifth category, the one-time project, sits alongside all of these: a new office network, an email migration, or a round of computer replacements, quoted as its own piece of work.
Break-fix
You contact someone when there is a problem and pay for the time it takes. There is no recurring fee. The trade-off is that nobody is paid to prevent problems, so updates, backup checks, and account cleanup only happen if you arrange them.
Block hours
You buy a bundle of hours in advance and draw them down. It works like break-fix with a committed rate, and some businesses use part of the block for scheduled maintenance. Check whether unused hours expire.
Per-user or per-device managed
You pay a recurring amount for each person or each device covered, and the agreement lists what the provider looks after. This is the model most people mean by “managed IT”. Published survey data on what providers charge is in our guide to what managed IT costs.
Co-managed
Your business has someone internal who handles day-to-day requests, and an outside provider covers specific areas: security tools, projects, vacation cover, or problems beyond that person’s experience. The scope is split in writing so both sides know who handles what.
What is typically included?
There is no standard package. These are the items that commonly appear in a managed agreement, and each one should be listed explicitly in yours:
- Support requests. Help for staff when something is not working, remotely or on-site, during agreed hours.
- Operating system and software updates. Installing security fixes on a schedule (often called patch management).
- Account administration. Creating accounts for new hires, removing access when people leave, resetting passwords, and managing licenses in Microsoft 365 or Google Workspace.
- Backup checks. Confirming backups ran and testing that files can be restored.
- Security basics. Endpoint protection (security software on each computer), multi-factor authentication (a second sign-in step beyond the password), and email filtering.
- Network upkeep. Firmware updates and configuration for the firewall, switches, and Wi-Fi access points.
- Vendor coordination. Dealing with your internet provider or software vendors on your behalf.
- Documentation. A current record of devices, accounts, licenses, and how things are set up.
What is usually excluded or billed separately?
Read this part of any proposal closely. Common exclusions include:
- Projects. Migrations, office moves, new servers, and new network installs are normally quoted separately.
- Hardware. Computers, firewalls, and other equipment are purchased separately.
- Software subscriptions. Microsoft 365, Google Workspace, backup storage, and security tool licenses may be billed by the vendor or passed through by the provider.
- Support outside agreed hours. After-hours and weekend help is a separate item where it is offered at all.
- Specialist incident response. Investigating a serious breach often involves specialists and your cyber insurer.
- Line-of-business software. Your practice management, accounting, or point-of-sale vendor supports their own application. An IT provider supports the computers and network it runs on.
- Compliance sign-off. A provider can implement technical safeguards, but formal compliance advice comes from a qualified compliance or legal advisor.
Does outsourcing IT transfer the responsibility?
No. CISA’s guidance for MSP customers states that outsourcing “does not absolve an organization from risk management responsibilities”. In practice this means three things for a small business:
- You own the accounts. Your domain name, your Microsoft 365 or Google Workspace tenant, and your backup account should be registered to the business, with the provider given access.
- Responsibilities are written down. The same CISA document suggests a shared responsibility list covering who applies patches, who maintains hardware, and who trains employees.
- You can see what was done. Ask for regular reporting on updates, backup tests, and open issues.
The FTC’s vendor security guidance adds that vendor access should be limited to what is needed and protected with multi-factor authentication.
Who does not need managed IT?
Plenty of businesses do not, and it is worth being honest about that.
You can likely manage with occasional help if most of these are true:
- You have one to three people, all using cloud apps on reasonably new computers.
- Automatic updates are turned on and you have confirmed they are working.
- Your files live in a cloud service with version history, and you have a second copy somewhere else.
- Multi-factor authentication is on for email and banking.
- A day without a working computer would be inconvenient but not costly.
- You do not hold regulated data such as patient records or payment card details.
If that describes you, a one-time setup review and an hourly contact for the odd problem is usually enough. Our small business IT checklist covers the basics to confirm on your own.
When does it start to make sense?
Managed support tends to earn its cost when several of these apply:
- Staff cannot work when systems are down, and downtime has a clear dollar cost.
- You handle client financial records, health information, or payment data.
- Nobody on staff owns updates, backups, and account changes, so they happen late or not at all.
- You are adding people or locations and want each setup done the same way.
- An insurer, client, or regulator asks security questions you cannot answer.
Our list of signs your business needs IT support includes a short self-assessment if you want something more concrete.
Common mistakes when buying managed IT
- Comparing price without comparing scope. Two quotes with the same monthly total can cover very different work.
- Assuming “monitoring” means someone responds. Software that raises an alert and a person who acts on it are separate things. Ask about both.
- Leaving account ownership with the provider. If the domain or admin accounts are registered to an outside company, changing providers later becomes harder.
- No exit terms. Agree up front how records and access are handed back. Our guide to switching IT providers shows what that handover involves.
Common questions
Is managed IT the same as outsourced IT?
Mostly. Outsourced IT is the broader term for any outside provider handling your technology, including hourly and project work. Managed IT refers specifically to an ongoing arrangement with recurring responsibilities and a recurring fee. Our post on outsourced IT versus an in-house hire compares the options.
Does managed IT include cybersecurity?
It usually includes the basics: updates, endpoint protection, multi-factor authentication, and email filtering. Continuous threat monitoring, penetration testing, and breach investigation are specialist services that are normally separate. Ask for the security items to be listed individually so you know what is and is not covered.
Do I need a long contract?
Not necessarily. Terms vary from month to month up to multi-year agreements. What matters is that the term, renewal, cancellation notice, and handover process are written down before you agree. A one-time project should not require an ongoing plan.
Can I start with a project and decide later?
Yes. A defined project, such as cleaning up accounts or fixing the network, is a practical way to see how a provider works before committing to anything recurring.
How Coastal Growth Co. approaches it
We offer both one-time projects and ongoing support, and we agree the scope and price in writing before any paid work starts. For ongoing arrangements, the proposal names the users, devices, systems, maintenance tasks, and support hours covered, with third-party subscriptions and project work listed separately. You can read how that works on the managed IT and support page and the pricing page, or tell us about your setup and we will suggest a sensible next step.
- managed IT
- IT support models
- break-fix
- small business
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward