There are businesses that should not buy managed IT, and we will say which. But the hourly model has a structural problem that has nothing to do with the hourly rate.
Break-fix means you call someone when something breaks and pay for their time. Managed IT means you pay a flat monthly fee and they look after everything continuously. The comparison is usually presented by people who sell one of them, so here is a version that admits where each actually wins.
When break-fix is genuinely the right answer
- Under about five people, with everything in cloud services and no server.
- No compliance obligation and no regulated data.
- A business that can lose a day without meaningful cost.
- Someone internally who is genuinely competent and has time.
If that describes you, a managed agreement is probably overspending. We will tell you so during an assessment.
The structural problem with hourly
The issue is not the rate. It is that the incentives point the wrong way.
Under break-fix, a provider earns when things break and earns nothing when they run smoothly. The work that prevents failures — patching, testing restores, reviewing who still has admin rights, turning on multi-factor authentication — is unbillable. It is not that break-fix providers are dishonest; it is that nobody is paid to do the invisible work, so it does not get done.
That is why break-fix environments accumulate the same findings: backups nobody has restored from, machines months behind on updates, and a firewall with rules for a vendor who left two years ago.
Where the money actually goes
| Break-fix | Managed | |
|---|---|---|
| Monthly cost | Nothing until something breaks | Flat and predictable |
| Cost in a bad month | Unbounded, at emergency rates | Unchanged |
| Who pays for prevention | Nobody, so it does not happen | Built into the fee |
| Provider's incentive | Earns more when you have problems | Earns more when you do not |
| Response priority | Whoever called first | Contractual, by severity |
| Budgeting | Impossible | A line item |
The comparison people get wrong
Businesses compare the monthly managed fee against last year's IT invoices and conclude managed is more expensive. That comparison omits the cost of the downtime those invoices represent — the staff who could not work, the appointments cancelled, the day spent rebuilding a machine.
It also omits the tail risk. One ransomware event in a business with untested backups costs more than a decade of managed fees. That is not a scare tactic; it is why insurers now ask specifically about MFA, endpoint detection and tested restores before they will write a policy.
A middle option nobody mentions
Co-managed IT is worth knowing about. You keep whoever you have internally — they know the business, the software and the people — and bring in a provider for after-hours cover, security, and the specialist work one person cannot reasonably cover alone.
For businesses with a capable internal person who is simply stretched too thin, this is often better value than either extreme.
Frequently asked
At what size does managed IT start to make sense?
Commonly around eight to ten staff, earlier if you hold regulated data or cannot tolerate downtime. A five-person practice with HIPAA obligations needs it sooner than a twenty-person firm that could work on paper for a day.
Can we start with just security?
Yes, and it is a sensible entry point. Multi-factor authentication, email authentication and verified backups deliver most of the risk reduction available, and they do not require a full agreement.
Will switching disrupt us?
Onboarding is mostly documentation and deploying monitoring, which happens in the background. The disruptive part is fixing what was already broken, and that is scheduled around you.