IT & Cloud
What is managed IT support?
Managed IT support is an arrangement in which an external provider takes ongoing responsibility for an organisation's technology — helpdesk, device and server management, patching, monitoring, backup and vendor liaison — for a recurring fee, usually charged per user or per device, under a defined service level agreement.
At a glance
- Also known as
- Managed service provider (MSP) support
- Typical pricing model
- Per user or per device, per month
- Common inclusions
- Helpdesk, patching, monitoring, backup, onboarding
- Alternative models
- Break-fix (pay per incident), in-house IT, co-managed
What is typically included
Scope varies between providers, and the contract matters more than the label. A conventional managed support agreement covers:
- Service desk for end-user issues, by phone, email or portal.
- Proactive monitoring of devices, servers and network hardware.
- Operating system and third-party application patching.
- Backup configuration and restore testing.
- User onboarding and offboarding, including account creation and device provisioning.
- Licence and vendor management, and hardware procurement advice.
- Periodic technology reviews and roadmap planning.
Managed IT versus managed security
The two disciplines overlap but are not the same. Managed IT keeps systems available and users productive. Managed security detects and responds to hostile activity: threat hunting, 24/7 monitoring of security telemetry, incident containment, vulnerability management and certification support.
Many providers deliver both, and many deliver only the first while implying the second. The practical test is whether the contract specifies who monitors security alerts outside working hours, what happens in the first hour of a suspected compromise, and who is accountable for it.
Pricing and contract structure
Per-user pricing is the most common model and typically ranges from roughly £30 to £90 per user per month in the UK SME market, depending on inclusions. Cheaper agreements usually exclude project work, out-of-hours cover, on-site visits or security tooling, which are then billed separately.
Contract length is commonly twelve months, though shorter and rolling terms exist. The items worth scrutinising are response and resolution targets, what counts as a project rather than support, out-of-hours arrangements, and exit terms including data and documentation handover.
Sources
The definitions and figures on this page are drawn from the primary sources below. Where guidance changes, the source takes precedence over our summary of it.
- Small Business Guide: Cyber Security — National Cyber Security Centre
- Cyber Assessment Framework and managed service providers — National Cyber Security Centre
- Cyber Security Breaches Survey — UK Department for Science, Innovation and Technology
FAQ
What is managed IT support — common questions
Direct answers to the questions asked most often about this topic.
How much does managed IT support cost per user?
+
UK SME pricing generally falls between about £30 and £90 per user per month. The spread reflects scope rather than quality alone: at the lower end, agreements typically cover remote helpdesk and basic monitoring, with projects, on-site work, security tooling and out-of-hours cover charged separately. At the higher end, agreements bundle endpoint protection, backup, device management and sometimes security monitoring. Comparing quotes requires normalising scope — a cheaper per-user rate that excludes patching, backup and security tooling is often more expensive once those are added back in.
What is the difference between managed IT support and break-fix?
+
Break-fix means paying for work as incidents occur, typically at an hourly rate with no ongoing fee. It can suit very small organisations with simple, stable environments. The structural weakness is incentive: the provider earns more when things break, and there is no commercial reason to invest in prevention such as patching, monitoring or documentation. Managed support charges a predictable recurring fee, which aligns the provider's interest with keeping systems stable. It also makes budgeting straightforward, since unpredictable incident costs are replaced by a known monthly figure.
Does an SME need managed IT support if it uses Microsoft 365 for everything?
+
Cloud services remove server maintenance but not administration. Someone still has to configure the tenant securely, manage licences, enrol and configure devices, apply Conditional Access and MFA policies, handle joiners and leavers, patch endpoints and third-party software, arrange backup of Microsoft 365 data, and support users when something fails. In very small organisations this often falls informally to whoever is most technical, which creates key-person risk and inconsistent configuration. The question is less whether the work exists and more who is accountable for it.
Can an organisation keep its IT provider and add a separate security provider?
+
Yes, and it is a common arrangement. The IT provider continues to handle support, infrastructure and day-to-day operations, while a specialist handles security monitoring, certification, assessments and incident response. It works when responsibilities are documented explicitly — who patches, who owns firewall rules, who acts on an out-of-hours alert, who leads during an incident — and when both parties have direct communication rather than routing everything through the client. Ambiguity between two providers is a genuine risk, so a written responsibility matrix is worth the effort at the outset.
What should be checked in a managed IT support contract?
+
Look for defined response and resolution targets by severity, and whether they are contractual or aspirational. Confirm what falls outside support and is billed as project work, since that boundary is where unexpected costs arise. Check out-of-hours arrangements and whether they cost extra. Establish who owns licences, domains, backups and documentation, and how they transfer if the relationship ends. Clarify security responsibilities specifically: monitoring, patching cadence, incident response and reporting. Finally, check notice periods and whether the term renews automatically.

