Most small businesses don’t decide to get serious about IT. They hit a moment that decides for them: a server dies the week before their busiest stretch of the year, a ransomware email gets clicked, or the one person who understood the network takes another job and takes the passwords with them.
I’ve spent my career in enterprise IT, running a 911 network operation and leading infrastructure teams handling millions of requests per second. The problems I saw at that scale show up at small companies too. Same failure modes, smaller budgets, and a lot less patience for downtime.
The Real Math on an In-House Hire
The instinct is usually to hire someone. Then you run the numbers.
A competent systems administrator is not cheap, and salary is the smallest part of it. Add payroll taxes, benefits, training and certifications to keep them current, and the equipment they need to do the job. Then account for the part nobody plans for: that person takes vacation, gets sick, and eventually leaves. When they do, everything they knew about your environment walks out with them unless it was written down, and it usually wasn’t.
There’s also a utilization problem. Most small operations don’t have forty hours a week of genuine IT work. They have four hours of real work and thirty-six hours of availability, which is a very expensive way to buy peace of mind.
A managed services agreement swaps that for a monthly number you can budget around. It isn’t automatically cheaper in every case, and anyone who promises that without looking at your environment is guessing. What it reliably is, is predictable.
What “Managed” Actually Covers
The term gets used loosely, so it’s worth being specific. A real managed services agreement usually includes some combination of:
- Monitoring and alerting on servers, network gear, and endpoints, so problems surface before a person notices them
- Patch management for operating systems and applications, on a schedule rather than whenever someone remembers
- Backup and recovery, including the part most businesses skip, which is periodically testing that a restore actually works
- Endpoint protection and the administrative work of keeping it deployed everywhere
- Helpdesk access for the day to day questions that otherwise land on whoever is nearest the problem
- Vendor coordination, so when your point of sale vendor blames your network and your network vendor blames the point of sale, someone else owns that argument
Notice how much of that is routine. That’s the point. Most IT failures at small businesses are not exotic. They are a backup that quietly stopped running eight months ago, or a firewall still on factory default credentials.
The Variables Nobody Budgets For
A few things reliably get left out of a standard proposal, and they are worth raising before you sign rather than after.
Replacement hardware takes as long as it takes. If your business is not in a major metro, a failed switch is not a next-morning fix. Delivery timelines stretch, and a “four hour response” in a contract means someone responds in four hours, not that your hardware is replaced in four hours. That distinction is worth pinning down in writing, and it usually means keeping a spare of anything whose failure stops the business.
Coverage hours are not the same as business hours. If your provider operates in a different time zone, their standard support window may end in the middle of your afternoon, and their overnight bench is often thinner than their daytime one. Work out when your operation is actually most exposed, then check whether that window is covered by people or by an answering service.
The specialist bench is smaller than the sales deck implies. Every provider lists expertise in security, cloud, networking, and telephony. Ask how many people actually hold each of those specialties, and what happens when the one who knows your phone platform is booked on another job.
Security Is the Part That Gets Skipped
There’s a persistent idea among smaller companies that they are too small to be a target. They are not. Most attacks are not chosen deliberately. They are automated, they scan broadly, and they take whatever answers.
Customer-facing businesses that take payments are, if anything, more exposed than average, because they handle card data and personal information at volume, often through several systems that were connected to each other by different people over several years. If you take cards, you have PCI obligations whether or not anyone has ever audited you on them.
The uncomfortable part is that a breach usually is not discovered internally. It gets discovered when a customer’s bank calls them, or when a processor flags a pattern. By then it has typically been going on for a while.
What To Ask Before You Sign
If you are evaluating a managed provider, these questions separate the serious ones from the rest:
- What are your actual response and resolution targets, and what happens if you miss them? Get it in writing.
- Who owns the licenses and the documentation? If you leave, do you keep your Microsoft tenant, your domain, your network diagrams, and your admin credentials?
- What does offboarding look like? A provider confident in their work will answer this without getting defensive.
- Who is actually doing the work, and where are they? Not as a gotcha, just so you know what coverage you have at 6pm on a Saturday.
- How do you handle the vendors you don’t control, like the point of sale platform or the scheduling system?
- Are you tied to specific products? A provider who only sells one manufacturer’s gear will find that every problem needs that manufacturer’s gear.
How I Fit In
To be clear about my own role: I don’t run a managed services operation, and I’m not the one patching your servers at 2am. I’m a consultant and a partner with OTG Consulting, which is a consultancy that presents the services of other providers.
What I do is the part that comes before that. I look at what you’re actually running, what it’s costing you, and where the real exposure is. Then I connect you with a provider whose coverage, response times, and specialties genuinely match your operation, and I stay involved afterward as someone reachable who is not the provider. Since I’m not the one delivering the service, I have no reason to steer you toward one provider over another except fit.
Worth a Conversation
If you’re at the point where IT problems are interrupting the actual business more than occasionally, that’s usually the signal. It costs nothing to talk through what you have and what it would take to make it boring again.
Schedule a free consultation and we’ll go through your current setup, what’s actually at risk, and whether a managed partner makes sense for you.