Menu

Outsourced IT support, explained properly

What outsourced IT support actually covers, how providers price it, where it goes wrong, and how to tell a good provider from a cheap one.

Faizan Shaikh
Faizan Shaikh · Founder · 8 min read

Outsourced IT support means paying an external provider to run some or all of the technology your business depends on: the helpdesk your staff call, the patching nobody remembers to do, the backups nobody has tested, and the access controls nobody owns.

The reason it is worth considering is rarely cost alone. A single competent internal IT hire is expensive, and one person cannot cover holidays, sickness, out-of-hours incidents, and the breadth of a modern stack. The reason it goes wrong is almost always the same: the scope was never written down clearly enough for either side to know what "supported" meant.

What is actually included

Providers vary enormously, and the word "managed" carries no fixed meaning. What follows is the set of things worth checking line by line before signing anything, because the gaps between providers sit here rather than in the headline price.

Helpdesk

Someone your staff can contact when something breaks. Check the hours, the channels, and crucially whether the response target is time-to-acknowledge or time-to-resolve. Those are very different promises and providers are not always careful about which one they quote.

Endpoint monitoring and patching

Agents on laptops and servers reporting health, and a patch cycle that actually runs. Ask what happens to a device that stops reporting: the unreporting machines are usually the interesting ones, and a provider who cannot tell you how many they currently have is not really monitoring.

Identity and access

Microsoft 365 or Google Workspace administration, MFA enforcement, joiners and leavers. Offboarding is the part most commonly done badly, and it is the part that matters most when someone leaves under a cloud.

Backup and recovery

Not whether backups run, but whether a restore has been tested and how recently. An untested backup is a hypothesis. Ask for the date of the last successful test restore and treat hesitation as an answer.

Documentation

Runbooks, asset inventory, network diagrams, and credentials held somewhere you can access without the provider. This is what determines whether you can leave, which is the single best predictor of whether you will be treated well while you stay.

How providers price it

Three models dominate, and the differences matter more than the headline number.

Common pricing models for outsourced IT support
ModelHow it worksWatch for
Per user, per monthA flat fee per person supported, covering their devices and accounts.Simplest to forecast, and the most common. Check what counts as a "user" and whether shared or service accounts are billed.
Per device, per monthPriced by endpoint and server rather than headcount.Can be cheaper for teams with few devices each; gets expensive fast with kiosks, spare laptops, or test machines.
Block hours / retainerA pool of hours drawn down monthly.Looks cheap and misaligns incentives. The provider profits when you need less help, so proactive work quietly stops. Fine for project work, poor for support.

Where the real cost hides

The monthly fee is the visible number. The costs that surprise people are in the exclusions, and they are worth reading for before signing.

Onboarding is frequently billed separately and can be substantial, because the first month is when a provider discovers what you actually have. Project work (a migration, a new office, a security remediation) usually sits outside the recurring fee. Out-of-hours support is often an uplift rather than an inclusion. And third-party software licences are almost always passed through, sometimes with a margin.

None of that is unreasonable. What is unreasonable is finding out afterwards.

How to tell a good provider from a cheap one

Price differences between providers are usually explained by what they are quietly not doing. A few questions separate them quickly, and the useful signal is how comfortable they are with the question rather than the answer itself.

"When did you last test a restore for a client like us?"

A good provider answers with a date and a process. A weak one talks about backup software. The distinction is the whole point.

"What is your response target, and is that acknowledge or resolve?"

A provider who has not thought carefully about this distinction has not thought carefully about their own operations either.

"What happens to our documentation if we leave?"

Documentation held hostage is a real practice. The answer should be that it is yours and exportable, without hesitation.

"Who specifically will we deal with?"

Small providers should be able to name a person. Larger ones should be able to describe the escalation path. Vagueness here usually means a ticket queue and a rotating cast.

When outsourcing is the wrong answer

It is worth being honest that this does not suit everyone. If your technology is genuinely your product (a software company with its own infrastructure) outsourcing the operation of it usually creates more coordination cost than it removes, and you are better served hiring.

If you have highly unusual or heavily regulated requirements, the overhead of bringing a provider up to speed can exceed the benefit. And if you have fewer than about five staff, a good break-fix arrangement is often more economical than a monthly contract, though you accept slower response and no proactive work.

Common questions

How much does outsourced IT support cost?

Market rates for per-user managed IT in the UK and US typically fall somewhere between roughly $80 and $250 per user per month, and the spread is explained almost entirely by scope rather than by quality. The low end usually means business-hours helpdesk and patching with everything else billed as a project. The high end usually includes 24/7 response, security tooling, a named account lead, and regular strategy reviews. Comparing quotes on the headline per-user number is therefore close to meaningless. You have to normalise them against the same scope first. Ask each provider what is excluded rather than what is included, since the exclusions are where the difference lives. We do not publish a rate card because engagements differ enough that a single number would mislead in both directions, but we will give you a scoped figure in writing before you commit to anything.

Can we outsource only part of our IT?

Yes, and it is a common arrangement. Usually called co-managed IT. The typical split gives the provider the work that benefits from tooling, coverage and repetition: monitoring, patching, backup verification, out-of-hours response. The internal person keeps the work that benefits from context: the bespoke line-of-business application, the relationships, the decisions about what the business actually needs. This works well when the boundary is written down and one side is unambiguously accountable for each area. It works badly when the split is left informal, because monitoring and backup verification are exactly the things that quietly become nobody’s job. If you already have someone internal, co-managed is usually a better starting point than full outsourcing, and it preserves the option to go either direction later.

What happens to our data if we switch providers?

It should come with you, and you should confirm that in writing before you sign rather than when you leave. Specifically: your documentation and runbooks, your asset inventory, administrative credentials for every system, and any backup data held on your behalf. A reasonable contract states an offboarding process with a defined handover period, typically thirty to ninety days, and does not charge punitively for it. Warning signs are documentation kept only in a provider-owned platform you cannot export, administrative accounts registered to the provider rather than to you, and backups stored in the provider’s tenancy with no independent copy. None of these are unusual, and all of them are negotiable at signing and almost impossible to renegotiate at exit.

Services related to this guide

Tell us about your setup

A written review of access control, patch status, backup restore verification, and endpoint coverage, with findings ranked by what would hurt most during an incident.

Request an IT review