The most useful thing to figure out first isn’t which provider to hire — it’s which pricing model fits how you actually work. A 9-person accounting firm and a 40-person contractor with field tablets have almost nothing in common as IT customers, and the same provider will be a bargain for one and a bad deal for the other.

This walks through the three models, what they really cost, the questions that separate a good provider from a bad one, and the warning signs that should end a conversation. No pitch. The goal is that you can run a decent evaluation yourself.

Three ways to buy IT support

Break-fix, billed hourly

Something breaks, you call, they bill you. Typical rates run $95-175 per hour, often with a one-hour minimum and a premium rate outside business hours.

What’s good about it: you pay only when you need help. For a very small, very simple shop — three people, cloud email, no server, no compliance requirements — this can genuinely be the cheapest option and there’s nothing wrong with choosing it.

What’s bad about it: the incentives are backwards. The provider makes money when things break and makes nothing when your systems run well. Nobody is watching your backups, your patch levels, or your disk health between calls, because nobody is paid to. You also queue behind that provider’s contract clients when something goes wrong, which tends to be exactly when you can least afford to wait.

Block hours

You buy hours in advance — 10, 20, 40 — at a discount, and draw them down. Effective rates land around $85-140, so maybe 15-25% off the hourly rate.

Read the expiration terms carefully. Many blocks expire in 6 or 12 months, unused hours vanish, and you’ve prepaid for nothing. Also ask about rounding — some providers bill in 15-minute increments, others round every ticket up to a full hour, which quietly turns 20 hours into 12.

Better than pure break-fix, mainly because prepaying usually buys you higher priority in the queue. Still doesn’t buy proactive maintenance.

Managed services, flat monthly

A fixed fee per user or per device covering support, monitoring, patching, security tooling, and backup management. Roughly $49-200 per user per month depending on what’s included and whether onsite visits are part of it. Remote-only providers sit at the lower end because they’re not funding trucks and drive time.

The reason this model works better for most businesses is incentive alignment. When the provider gets the same money whether you call twice or twenty times, they have a direct financial reason to keep your systems stable. Preventing an outage is now in their interest rather than against it.

The trade-off: you pay in quiet months. Some owners hate that. The counterargument is that you’re paying for the quiet months.

What that costs on a 15-person business

Real numbers, one year, 15 employees with about 20 devices between laptops and desktops.

ModelQuiet yearNormal yearBad year (one real incident)
Break-fix @ $135/hr$4,000
~30 hrs
$9,500
~70 hrs
$26,000+
plus downtime
Block hours @ $110/hr effective$4,400
some may expire
$7,700$21,000+
Managed @ $89/user/mo$16,020$16,020$16,020
Managed, lean remote-only @ $59/user/mo$10,620$10,620$10,620

Read that table honestly. In a genuinely quiet year, break-fix wins on paper. The managed value proposition isn’t that it’s always cheaper — it’s that it’s predictable, and that the proactive work makes the bad year less likely in the first place.

Also notice what the “bad year” column leaves out: your own lost revenue. Three days of a 15-person team unable to work is far more expensive than the invoice for fixing it.

Per user or per device — which is cheaper for you

This is a five-minute calculation that changes quotes by thousands of dollars, and providers rarely walk you through it.

Per user means one price per person, covering all their devices — laptop, desktop, phone, tablet. Per device means one price per endpoint regardless of who uses it. Servers and network gear are usually priced separately either way.

Count your devices and divide by headcount. If the ratio is above roughly 1.4 devices per person, per-user pricing almost always wins. Below about 1.2, per-device may be cheaper.

Concretely: a 20-person design studio where everyone has a desktop and a laptop is 40 devices. At $65 per device that’s $2,600 a month. At $99 per user it’s $1,980. The per-user quote looks more expensive per unit and is $7,400 cheaper a year.

Flip it: a 12-person warehouse operation with 4 shared terminals is 4 devices. Per-device at $65 is $260 a month. Per-user at $99 is $1,188 — for the same four computers. Per-device is obviously right there.

Ask any provider quoting per-device how they count. Some count phones. Some count printers, firewalls, and network switches. That detail can add 30% to a quote after you’ve signed.

Questions to ask before you sign

Ask these directly. How someone answers matters as much as the answer.

What’s your average response time, and is it in the contract?

Everyone says “fast.” Push for the number and then push for it in writing. A real answer distinguishes response time from resolution time, and defines severity tiers — critical, high, normal — with a different commitment for each.

Then ask the follow-up that actually reveals things: what happens if you miss it? A provider with genuine confidence has a remedy — a service credit, an escalation path. One who’s never thought about it will get vague fast.

Who owns the licenses and the admin credentials?

The single most important question on this list, and the one that causes the most pain later.

Your Microsoft 365 or Google Workspace tenant should be registered to your business, with a Global Administrator account your owner controls. Your domain name should be registered to you, in an account you can log into. Your firewall admin password should exist somewhere you can reach it.

Plenty of providers hold all of this under their own umbrella. Sometimes that’s habit, sometimes it’s deliberate lock-in. Either way, if you can’t independently log into your own tenant and domain registrar, you don’t fully control your business. It’s fine for the provider to hold day-to-day admin. It is not fine for you to have no path to it.

What happens to our data and access if we leave?

Ask before you’re happy, not after you’re unhappy. You want to hear: documented notice period, a written offboarding process, all credentials handed over, all data exported in a standard format, and cooperation with the incoming provider.

Ask specifically about backups. If your backups live in the provider’s tenant, in their storage account, how do you get years of retained data out? Is there a fee? Watch for an offboarding charge buried in the contract — a few hundred dollars for the transition work is defensible; four figures is a hostage fee.

Who does the work — your staff or a subcontractor?

Lots of small providers white-label an offshore NOC or help desk. That’s not automatically bad; some of those teams are excellent and it’s how a small firm affords 24/7 coverage. But you should know, because it affects who has access to your systems, what timezone answers at 2 a.m., and whether the person on the phone has any context about your business.

A provider who answers this straightforwardly is telling you something good. One who dodges it is telling you something too.

Is there an onboarding fee, and what does it buy?

Most managed providers charge one. It’s legitimate work — documenting your environment, deploying monitoring and security agents, auditing accounts, fixing the accumulated mess. Typical range for a small business is $1,500-5,000.

What you want is a scope: what specifically gets done, over what timeline, and what “done” looks like. A flat fee with no deliverables list is a blank check. Some providers waive it on a 12-month commitment, which is a fair trade if the commitment terms are otherwise reasonable.

Three more worth asking

Red flags

Any one of these is worth a hard second look. Two or more, walk.

No references. A required three-year term. Scope described only as “full IT support” with no exclusions listed. Refusal to give you Global Admin access to your own tenant. Vaguely defined “emergency” hours billed at a premium the provider gets to declare. Pricing that only makes sense with a long lock-in. Pressure to sign this week. No written SLA. Won’t tell you what monitoring and security tools they deploy.

Two deserve elaboration.

The three-year contract. For a business under 50 people, this is almost always about the provider’s revenue predictability, not your benefit. Twelve months is standard and fair. Month-to-month after an initial term is better still — it means the provider is choosing to earn the renewal every month rather than relying on a clause.

Vague scope. A good agreement says explicitly what’s not covered. Hardware costs, software licenses, major project work, cabling, vendor management, onsite visits — each should be either in or out, in writing. “Everything IT” always turns out to mean less than you assumed, and you find out mid-crisis.

Included versus extra

Normally included in a managed planNormally billed separately
Unlimited remote help desk during business hoursHardware purchases and the labor to deploy new machines
OS and third-party patch managementSoftware licenses (Microsoft 365, Adobe, line-of-business apps)
Endpoint monitoring and alertingOffice moves, cabling, physical infrastructure
Antivirus / endpoint protection licensing and managementMajor projects — server migration, M365 tenant migration, new office build-out
Backup monitoring and restore assistanceBackup storage costs above an included tier
User onboarding and offboardingOnsite visits, if the provider is remote-first
Microsoft 365 / Google Workspace administrationCompliance audits and formal security assessments
Basic security configuration — MFA, conditional access, email filteringIncident response and forensics after a confirmed breach

There’s no universal standard here — providers draw the line differently and that’s fine. What isn’t fine is a provider who won’t tell you where they draw it.

Why size fit matters more than you’d think

A firm built to serve 200-seat companies is not a scaled-down version of what you need. It’s a different business with different economics.

Their overhead — account managers, a virtual CIO layer, quarterly business reviews, an enterprise ticketing stack — is priced into every seat. On 200 seats that’s a rounding error. On your 12, it’s most of the bill, and you’re paying for governance apparatus you don’t need.

Their ticket priority math also puts your 12 seats near the bottom when their biggest account has a problem the same afternoon. Flip side: a one-person operation supporting 40 businesses is a genuine single point of failure. What happens when they’re on vacation, sick, or handling someone else’s emergency at the same moment as yours?

For most businesses between 5 and 50 people, the sweet spot is a small provider whose typical client looks like you, with at least two or three technicians so there’s real coverage. Ask them directly: how many clients do you have, what’s your average client size, and how many people are on your technical team? Those three numbers tell you most of what you need to know about fit.

Evaluation checklist

Score each provider. Anything you can’t confirm counts as a no.

That last one is more predictive than most of the others combined. A provider who quotes a per-seat number in the first ten minutes without asking what software you run, whether you have compliance obligations, or how your data is currently backed up is selling a package, not solving your problem.

Common questions

How much should a small business budget for IT support?

Managed support for a small business generally runs $50-200 per user per month, with remote-only providers at the lower end and firms including onsite work at the higher end. As a share of revenue, small businesses typically spend 2-5% on IT overall — support, licenses, hardware, and internet combined. If a quote is dramatically below the range, ask precisely what’s excluded; it’s usually monitoring, security tooling, or after-hours coverage.

Is remote-only IT support good enough without anyone onsite?

For most businesses now, yes. Roughly 90-95% of support work — software problems, account issues, email, security configuration, patching, user setup — is done remotely regardless of whether the provider has a local office. What genuinely needs hands is physical hardware failure, cabling, and new equipment installation, and those can be handled with a local contractor or by shipping replacement gear. Remote-only providers usually cost less because they aren’t funding vehicles and travel time. The question to ask isn’t “are you local” but “what’s your plan when something physical breaks.”

When does it make sense to hire someone in-house instead?

Usually somewhere north of 50-75 employees, or earlier if you run complex custom systems that need dedicated attention. A capable IT generalist costs $70,000-95,000 plus benefits, so call it $95,000-125,000 fully loaded — and that’s one person who takes vacations, gets sick, and can’t be expert in networking, security, cloud administration, and desktop support simultaneously. Below that headcount you generally get broader coverage and better redundancy from a provider. Many companies past 60 people run a hybrid: one internal person for day-to-day, a provider for security, infrastructure, and after-hours.

What if we already have a provider and things are just okay?

Start with a conversation rather than a search. Bring specifics — response times you’ve measured, tickets that dragged, things you expected to be covered. Plenty of providers will fix a fixable relationship, and switching has real costs in transition time and lost institutional knowledge. Switch when you see the things that don’t get better with a conversation: no monitoring at all, backups nobody has tested, security work not happening, or a pattern of finding out about problems from your own staff instead of from them.

How long does switching providers actually take?

Two to four weeks for a typical small business, assuming the outgoing provider cooperates. Week one is documentation and credential transfer, week two is deploying the new provider’s monitoring and security agents, and the remainder is cleanup and knowledge transfer. It goes faster when you already control your own tenant, domain, and licenses — which is exactly why that question is worth asking before you sign with anyone. Overlapping both providers for a couple of weeks costs a little extra and is nearly always worth it.

Leave a Reply

Your email address will not be published. Required fields are marked *