There is rarely a single moment when a business decides it has outgrown reactive IT support. It accumulates. A printer issue becomes a two-day wait. An onboarding takes a week because nobody owns the process. Someone asks how many Microsoft 365 licences the company pays for and three people give three answers. None of these are crises, which is precisely why they persist.
This article is about the decision, not the technology. It is written for owners, finance leaders and operations managers weighing whether to keep buying IT by the hour.
Ten signals you have outgrown break/fix support
- Repeat incidents. The same fault recurs monthly because each engagement fixes the symptom and no one is funded to find the cause.
- Response times that depend on who is free. With no service levels, urgency is negotiated ticket by ticket.
- No IT governance. Nobody can produce a current asset register, an access policy, or a record of who approved the last change.
- Unmanaged devices. Staff laptops that were never enrolled, personal devices holding company data, and machines still running an unsupported build.
- Microsoft 365 configuration drift. Sharing settings loosened for one project and never reverted; guest accounts from a tender two years ago still active.
- Security gaps you only discover during an audit. Or worse, during a cyber insurance renewal questionnaire you cannot honestly complete.
- No visibility of assets and licences. Paying for departed staff, or paying for premium licences that nobody has enabled the features of.
- Backup uncertainty. Backups may be running. Nobody has restored from them recently enough to say so with confidence.
- No strategic planning. Technology decisions are made when something breaks or when a renewal lands, never in advance.
- An internal team stuck on the treadmill. One or two capable people consumed by tickets, with no capacity for the projects that would reduce the tickets.
Two or three of these is normal. Six or more and the cost of the current model is already being paid — just not on an invoice line.
Unpredictable versus predictable expenditure
The honest comparison is not "hourly rate versus monthly fee". It is the total cost of the current model versus the total cost of a managed one.
Reactive spend is lumpy and back-loaded: the invoice is largest in the month something goes badly wrong, which is also the month you lose productivity. It also hides labour that never gets billed — the staff hours spent working around problems, the manager acting as an unpaid IT coordinator, the finance team reconciling licences by hand.
Managed spend is a known per-user or per-device figure, with project work quoted separately. The value is not that it is always cheaper in a good year; it is that the good years and bad years cost roughly the same, and someone else carries the risk of the bad year.
Break/fix versus managed services
| Break/fix | Managed services | |
|---|---|---|
| Commercial incentive | More incidents, more revenue | Fewer incidents, protected margin |
| Response | Best effort | Contracted SLA by severity |
| Security | Reactive, project-based | Continuous monitoring and posture management |
| Documentation | Held by the last engineer | Maintained as a service deliverable |
| Planning | None | Scheduled roadmap and budget cycles |
| Cost profile | Volatile | Predictable, per user or per workload |
What to expect from a modern MSP
A credible provider in 2026 should offer more than a helpdesk with a subscription attached. Expect service levels defined by severity, security operations rather than security products, full lifecycle device management, licence and asset governance, documented change control, and a named person accountable for your account who is not the same person answering the phone.
Expect them to say no occasionally, too. A provider that agrees to every exemption request is not managing risk; it is deferring it to you.
Questions to ask a managed IT provider
Take these to every shortlisted vendor and compare the answers side by side.
1. SLA structure. What are your severity definitions, response and resolution targets, and business hours? What happens when a target is missed?
2. Security monitoring. Who watches detections, during which hours, and what are you authorised to do without contacting us first?
3. Microsoft 365 management. Who owns tenant configuration, conditional access policy, and secure score improvement — and how are changes approved?
4. Endpoint management. How are devices enrolled, patched and retired? What is your compliance target and how is it reported?
5. SOC capability. Is security operations delivered in-house or subcontracted? Which platform, and can we see a sample incident report?
6. Reporting. What arrives monthly without us asking, and does it show trends rather than raw ticket counts?
7. Strategic advisory. Who runs the roadmap and budget conversation, how often, and is it included or billed?
8. Backup and recovery. What is protected, at what frequency and retention, and when was a restore last tested for a client like us?
9. Escalation. What is the path when the first responder cannot resolve it, and at what point does a senior engineer or account lead get involved?
10. Onsite support. Where are your people physically located, what is included, and what triggers a site visit?
If a provider answers the security questions with product names rather than processes, ask again. The distinction is the whole point — the mechanics of how these functions interlock are set out in our article on secure managed IT.
Making the decision
Most organisations that move are not chasing a lower bill. They are buying back attention: the ability to plan a financial year without a technology surprise in it, and to stop having the same conversation about the same laptop. Compare providers on the specifics of the ten questions above, ask for a reference in your sector, and look at our service packages for a sense of how the commercial structure typically works.
