Menu

Managed IT support for small business: what to expect from a provider

Comingwave team · 7 minute read · published

A support technician wearing a headset helps a staff member set up a new laptop at an office desk.

Managed IT support for small business means paying a provider an agreed regular fee to look after your computers, accounts, network and security on an ongoing basis, instead of calling someone only when something breaks. A sound provider covers the help desk, updates, backups, monitoring, staff arrivals and departures, and the security basics, and puts all of it in writing. This guide explains what is usually included, how managed support compares with hiring in-house or paying per fix, which questions to ask, and how the Essential Eight fits in.

What managed IT support usually covers

Agreements differ between providers, so treat the list below as a description of what is common, then check each item against the written scope you are offered.

Help desk

A single place for staff to report problems, by phone, email or a ticketing portal, with each request logged and tracked until it is resolved. Good help desks record what was done, so that repeat problems can be spotted and fixed at the cause. Ask which hours are covered and what counts as urgent.

Patching and updates

Patching means installing the fixes that software makers release for security flaws and bugs. A managed service schedules and applies updates to operating systems and common applications across all your devices, and reports on any machine that has fallen behind. This is routine work that is easy to postpone in a busy office and risky to skip.

Backups

Copies of your important data kept separately from the original, with regular checks that they can be restored. The agreement should say what is backed up, how often, where the copies are held, how long they are kept and who tests a restore. Cloud services need attention here as well: confirm whether your email and file storage are included or assumed to be someone else's job.

Monitoring

Software on your devices and network equipment that reports faults and warning signs, such as a disk that is filling up, a backup that failed overnight or a security tool that has been switched off. The value is in someone acting on the alert before staff notice a problem.

Onboarding and offboarding staff

When a person starts, they need a device, accounts, the right access and a short induction on how things are done. When a person leaves, access must be removed promptly, data handed over and licences recovered. A provider should run both from a checklist that you have agreed. Offboarding is a security control as much as an administrative task: an account left active after someone has gone is an open door.

Security basics

Multi-factor authentication (a second proof of identity at sign-in), protection against malicious software, email filtering, sensible administrator rights, device encryption and staff awareness. These should be part of the standard service, not an optional extra discovered after an incident. Businesses with higher risks may add dedicated cyber security services on top.

What is often outside the standard scope

New hardware, software licences, large projects such as an office move or a cloud migration, and support for specialist industry software are commonly quoted separately. None of that is unreasonable, provided it is clear before you sign.

In-house, managed or break-fix

There are three common ways for a small business to get IT support. Break-fix means calling a technician when something fails and paying for that job.

Point of comparisonIn-house IT personManaged IT supportBreak-fix
How you paySalary and employment costsRegular agreed fee, usually based on users or devicesPer job or per hour, when needed
Preventive workYes, if time allowsYes, it is the core of the serviceRarely; work starts after a failure
Coverage when someone is awayA gap unless you have more than one personShared across the provider's teamDepends on the technician's availability
Breadth of skillsOne person's experienceA team with different specialitiesVaries by technician
Knowledge of your businessDeepGood, if documented and reviewedLimited to past jobs
Predictability of costHighHigh for the agreed scopeLow
Typically suitsLarger offices with constant on-site needsBusinesses that rely on IT daily without a full-time role to fillVery small offices with simple, low-risk setups

The options can be combined. Some businesses keep an internal person for day-to-day questions and use a managed provider for monitoring, security and cover. The weak point of break-fix is not the cost of each visit but the work that never happens between visits: updates, backup checks and removing old accounts.

How the Essential Eight relates

The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate (ASD) to help organisations protect themselves against cyber threats. As listed in Essential Eight explained on cyber.gov.au, the strategies are:

  1. patch applications
  2. patch operating systems
  3. multi-factor authentication
  4. restrict administrative privileges
  5. application control
  6. restrict Microsoft Office macros
  7. user application hardening
  8. regular backups

Set that list beside the service list above and the overlap is plain. Patching, multi-factor authentication, control of administrator rights and backups are the daily work of managed IT support. That makes the Essential Eight a useful yardstick: you can ask a provider how its standard service addresses each of the eight, and which ones need extra work.

Three points from ASD's Essential Eight maturity model help keep the conversation honest. First, the model defines four maturity levels, from Maturity Level Zero to Maturity Level Three, and says organisations should pick a target level suited to their environment and reach the same level across all eight strategies before moving higher. Second, ASD describes the Essential Eight as a minimum set of preventative measures and says it will not mitigate all cyber threats. Third, the model states there is no requirement for organisations to have their implementation certified by an independent party, although an assessment may be required by a government directive, a regulator or a contract. Be cautious of any provider who implies that buying their service makes you "Essential Eight certified".

Questions to ask a provider

  • What exactly is in the regular fee, and what is charged separately? Ask for the scope in writing.
  • Which hours is the help desk staffed, and how are urgent problems outside those hours handled?
  • What response and resolution targets do you commit to in the agreement, and how are they measured and reported?
  • How are our backups tested, and when did you last restore a customer's data in a real incident?
  • How does your standard service address each of the Essential Eight strategies?
  • Who holds the administrator passwords and documentation for our systems, and how do we get them if we leave?
  • How do you protect your own access to our systems, including multi-factor authentication for your staff?
  • What happens during onboarding: what will you audit, change and document at the start?
  • What is the notice period, and what help do you give when handing over to another provider?

The answers on ownership matter most. Your business should hold, or be able to obtain at any time, the administrator credentials, licences, domain names and documentation for its own systems.

What you still need to do yourself

A provider cannot make your business decisions for you. Nominate one person as the main contact, tell the provider about new starters and leavers before the day, approve who may access which information, and review the service reports.

It also pays to step back from daily support and look at where your technology is heading: ageing equipment, software reaching end of support, systems that no longer fit how you work. That planning is the role of IT consulting.

Comingwave is an Australian technology company that provides managed IT support to small and medium businesses. If you would like a written scope and quote for your office, send us an enquiry.

Key takeaways

  • Managed IT support is ongoing, preventive care for an agreed fee, not a call-out service.
  • Expect help desk, patching, backups, monitoring, onboarding and offboarding, and security basics in the standard scope.
  • Get the scope, service targets and exclusions in writing before signing.
  • Use the Essential Eight as a yardstick for what the service covers, and be wary of certification claims.
  • Make sure you own your credentials, licences and documentation.

Frequently asked questions

Is managed IT support worth it for a very small business?

It depends on how much the business relies on its systems and data. An office of a few people with cloud email and accounting may need only a light service. If losing access to your systems or losing client data would seriously hurt you, regular patching, tested backups and prompt removal of old accounts are worth paying for.

What is the difference between managed IT support and break-fix?

With break-fix you pay a technician when something fails. With managed support you pay a regular fee and the provider is responsible for keeping systems healthy between failures. Break-fix costs less in quiet periods but leaves preventive work undone.

Does a managed IT provider make us Essential Eight compliant?

Not automatically. A provider can implement and maintain many of the eight strategies for you, such as patching, multi-factor authentication and backups. ASD's maturity model sets out requirements for each maturity level and says there is no requirement for independent certification, so ask for evidence of what has been implemented and to what level.

How do we change IT providers without disruption?

Check the notice period in your current agreement, ask for all administrator credentials and documentation, and have the new provider audit the environment before the old one finishes. Plan for a period of overlap, and change shared passwords once the handover is complete.

Need help with your business technology?

Tell us what you need. We reply within one business day.

Get a free quote