In short: Managed IT services means paying a fixed monthly fee for a provider to look after your technology continuously, rather than paying by the hour when something breaks. In Australia it is usually priced per user per month, covers devices, security, backups and a helpdesk, and suits businesses from around five staff upward. The decision that matters is not which provider has the longest feature list — it is whether the agreement makes the provider’s incentives match yours.
What managed IT services actually means
A managed IT provider takes ongoing responsibility for the technology a business runs on, for a fee agreed in advance. That is the whole idea. Everything else is detail.
The word doing the work is ongoing. Under a break-fix arrangement, a provider earns when something goes wrong. Under a managed agreement, they earn the same amount whether your month was quiet or catastrophic — so a quiet month is the profitable one. That single change in incentive is why managed services became the standard model, and it is the thing to check before anything else in a proposal.
In practice a managed arrangement usually covers:
- Monitoring of servers, workstations and network equipment, so faults surface before someone reports them
- Operating system and application patching on a schedule
- Backup configuration, monitoring and test restores
- Security tooling across email, devices and identity
- A helpdesk your staff can contact directly
- Starter and leaver processes when someone joins or leaves
- Licence, warranty and asset tracking
- Coordination with your other vendors — the practice software company, the telco, the accountant’s platform
What that adds up to is not a list of tasks. It is the difference between technology being someone’s job and technology being everyone’s occasional emergency.
The four ways Australian businesses buy IT support
A business that has been trading for a few years has usually been through at least two of these, without ever naming them. Knowing which you are in makes the next decision much easier.
Break-fix
You ring someone when something stops working, and you pay for the time it takes to fix it. Rates typically run by the hour, often with a minimum callout.
It is genuinely the right answer for some businesses — a two-person operation running two laptops and a cloud accounting package does not need a managed agreement. The problems start when the business grows past the point where “we’ll deal with it when it breaks” is a strategy.
The structural issue is the incentive. Your provider’s revenue depends on things going wrong. Nobody sets out to be negligent, but under break-fix nobody is paid to notice that your backup has been failing for three weeks, so nobody does.
Block hours
You buy a block of hours up front, usually at a discount, and draw them down. It feels like a compromise between break-fix and managed, and it is a popular first step.
It also has a specific failure mode worth knowing about: it makes you reluctant to call. When every question costs a slice of a finite pool, staff stop raising small things. Small things become large things. By the time you use the hours, you are spending them on something that could have been a five-minute conversation two months earlier.
Co-managed
You have internal IT — one person, or a small team — and a provider works alongside them. The provider might handle after-hours, security tooling, projects, or the specialist work your internal person cannot cover alone.
This is the most under-used model in Australia, and it suits a specific and common situation: the business that has outgrown having no IT person but cannot justify a full team. It also removes the single-point-of-failure problem, where the entire technology function is one person’s undocumented knowledge and their annual leave is a business risk.
Fully managed
The provider owns the technology function. You have a monthly fee, an agreed scope, and a defined way to raise things.
This is what most people mean by “managed IT services”, and it is what the rest of this guide is mostly about.
What is actually included, and what usually is not
This is where proposals diverge most, and where the differences are hardest to see. Two agreements at similar monthly prices can cover materially different things.
Usually included
- Helpdesk support during business hours
- Monitoring and alerting on the systems under management
- Patching of operating systems and common applications
- Antivirus or endpoint protection licensing and management
- Backup management for the systems in scope
- User account administration — creating, changing and removing accounts
- Basic vendor liaison
Usually charged separately
- Projects. A server replacement, an office move, a migration to a new platform. These are scoped and quoted individually, and it is reasonable that they are — they are not day-to-day support.
- Hardware. The agreement covers managing devices, not buying them.
- Third-party licensing. Microsoft 365, your practice management software, your backup platform. Some providers bundle these into the per-user fee; others pass them through. Neither is wrong, but comparing a bundled quote to an unbundled one without noticing is the most common way businesses misread proposals.
- After-hours work. Unless the agreement specifically says otherwise.
- On-site attendance. Some agreements include a set number of visits; some charge per visit; some include unlimited on-site within a radius. This varies more than any other item.
The items worth asking about explicitly
Ask about these directly, because the answer is often “no” and it is rarely volunteered:
- Are backup restores tested, and how often? Monitoring that a backup job completed is not the same as knowing the data can come back.
- Is documentation maintained, and do you get a copy? If the answer is that documentation lives in the provider’s system and you cannot have it, you are locked in by design.
- Who owns your Microsoft 365 tenant and your domain name? These should be in the business’s name, with the business holding administrative access. A provider who owns your tenant owns your ability to leave.
- What happens to your data if you leave?
That last question is the one that tells you most. A provider who has a clear, unbothered answer has thought about it. A provider who becomes vague has usually built the answer around not being left.
What monitoring actually watches, and what it misses
“24/7 monitoring” appears in nearly every proposal, and it is one of the least examined phrases in the industry. It is worth understanding what it does and does not mean.
What it genuinely catches
Monitoring software sits on your devices and servers and reports back on conditions that reliably predict failure:
- Disk health and free space. A drive reporting errors usually gives warning before it fails outright. Catching that means replacing a disk on a Tuesday afternoon rather than rebuilding a server on a Saturday.
- Backup job outcomes. Whether the job ran, and whether it completed.
- Service availability. Whether the things that should be running are running.
- Patch status. Which machines have fallen behind, and why.
- Antivirus and endpoint agent health. Protection that has stopped reporting is protection you do not have, and it fails silently by definition.
- Certificate and licence expiry, which cause outages that are entirely avoidable and consistently embarrassing.
What it does not catch
This is the part rarely discussed in a sales meeting.
Monitoring watches the systems it has been installed on and configured for. It does not know that your line-of-business application has become unbearably slow for the accounts team, that a process everyone relies on depends on one person’s spreadsheet, or that a shared mailbox is being accessed by someone who left last year.
It also does not, by itself, catch a security incident. Detecting an attacker requires different tooling watching different signals, and treating operational monitoring as security monitoring is a common and consequential confusion.
The question worth asking
The value of monitoring is not the tool. It is what happens when an alert fires.
Ask a provider: what happens to an alert raised at 11pm on a Saturday? Some are genuinely staffed. Some route to an on-call engineer for defined severities only. Some queue it for Monday morning. All three are legitimate positions at different price points — what matters is that you know which one you are buying, rather than assuming the first and paying for the third.
What managed IT costs in Australia, and why per-seat pricing won
Managed IT is normally priced per user per month — sometimes per device, occasionally as a flat fee for the whole business.
Per-user pricing became the norm because it is the only model that tracks the thing that actually drives support effort. Servers are predictable; people are not. A business with one server and forty staff generates far more support load than one with three servers and eight staff. Per-device pricing made sense when the device count was the workload, and stopped making sense once everyone carried a laptop and a phone.
What moves the price
The number that appears in a proposal depends on more than headcount:
- What is in scope. Devices only, or devices plus servers plus network plus mobile?
- Whether licensing is bundled. A quote including Microsoft 365 Business Premium per user looks much higher than one excluding it, for the same service.
- Security depth. A baseline of endpoint protection and multi-factor authentication costs less than managed detection and response with someone reviewing alerts.
- Response commitments. Faster agreed response costs more, because it constrains how the provider staffs.
- On-site expectation. A business that needs someone physically present regularly costs more to serve than one that is comfortable working remotely.
- Your sector. A medical practice with clinical software and privacy obligations carries more support and compliance overhead than a five-person consultancy on cloud tools.
How to compare quotes without being misled
Ask every provider to break the price into three parts: the managed service fee, the third-party licensing, and anything excluded that you should expect to pay for separately.
Do that and the comparison becomes straightforward. Skip it, and you are comparing numbers that measure different things — which is how a business ends up choosing the cheaper provider and then paying more.
The second thing worth asking: what would make this price go up? A provider who says “nothing, ever” is either not thinking about it or is planning to renegotiate later. An honest answer names the triggers — headcount growth, adding a site, taking on a system that needs specialist support.
How to read a managed services proposal
Proposals are written to be persuasive. Reading them well means knowing which parts carry weight.
Scope is the document. Everything else is commentary. If the scope says “workstations and Microsoft 365”, then your server, your firewall and the machine running your practice software are not covered, however comprehensive the covering letter sounds.
Look for what is measured, not what is promised. “Rapid response” means nothing. “Priority 1 issues acknowledged within an agreed timeframe, defined in Schedule 2” means something, because it can be checked.
Check the exclusions carefully. They are usually accurate, and usually the most informative section. A short exclusions list is a warning rather than a selling point — every real agreement excludes something.
Look for the exit. Notice period, what happens to your data, whether documentation is handed over, whether administrative credentials transfer. A twelve-month lock-in with a ninety-day notice period and no data handover clause is a contract designed around your leaving being difficult.
Ask who does the work. Some providers subcontract. That is not automatically a problem, but you should know, and you should know whether the person attending your site has been background-checked if they will be working around sensitive information.
The questions that actually tell you whether a provider is any good
Most sales conversations are a provider describing their strengths. These questions produce more useful answers, because they are hard to answer well without genuine practice behind them.
“When did you last restore a client’s data from backup, and how long did it take?” A provider who does test restores will have a recent, specific answer. A provider who monitors backup jobs and calls that a backup strategy will answer in general terms about their platform.
“Tell me about a time you got something wrong with a client.” Everyone has. The answer reveals whether the culture is to own it or to explain it away. Be wary of a provider who cannot think of one.
“What would you tell me not to spend money on?” A provider whose every answer is to buy something is selling, not advising. There should be things they would talk you out of.
“What does your onboarding look like in the first month?” Vagueness here is the clearest possible warning. A provider who has onboarded businesses properly has a process, and can describe it without preparation.
“If we left in two years, what would that look like?” Watch the reaction as much as the answer.
“Who would we actually deal with?” Some providers assign a consistent team; others route to whoever is free. Both models work, but only if the answer is honest and the documentation is good enough that a new technician is not starting from scratch.
What the first ninety days should look like
The onboarding period tells you more about a provider than the sales process, and it is where most of the value of the arrangement is either created or lost.
Weeks one and two — find out what is actually there. Devices, licences, accounts, backups, network equipment, and the systems the business genuinely depends on. It is common for a business to have never seen this written down, and normal for the audit to find things nobody knew were running.
Expect surprises. Accounts still active for people who left. Software nobody can identify. A backup that has been failing quietly. A server under someone’s desk running something important. This is the normal condition of a business that has been growing faster than its IT.
Weeks two to four — deal with what is dangerous. Not the easy wins; the things that could stop the business. Unsupported systems, backups that have never been restored, accounts that should not exist, missing multi-factor authentication on anything holding money or personal information.
A provider who spends the first month on cosmetic improvements has chosen the work that demonstrates activity over the work that reduces risk.
Month two — establish how things actually run. One way for staff to raise issues. Agreed definitions of what counts as urgent. Documentation written down. Monitoring and patching running properly rather than nominally.
Month three — the first real review. What was found, what changed, what is still outstanding, and what should be planned for. In plain language, in a document that can go to an owner or a board without translation.
If ninety days pass and you have not had a conversation like that, the arrangement has become a helpdesk with a monthly invoice.
Managed IT and your compliance obligations
Several sectors carry obligations that touch technology directly — NDIS providers, healthcare and allied health practices, schools, legal and accounting firms, and businesses working on government-funded contracts.
Two things are worth being clear about.
A managed IT provider does not make you compliant. They provide technology services. Determining what applies to your organisation, and demonstrating that you meet it, remains yours. Any provider implying that engaging them satisfies an obligation is overstating what they can deliver, and you should treat that as information about them.
What a provider can do is make compliance possible to demonstrate. Access controlled and reviewable. Backups tested rather than assumed. Multi-factor authentication on systems holding personal information. Documentation showing what is in place. Leavers offboarded properly and provably. When someone asks you to evidence a control, the evidence exists.
The practical distinction is this: obligations are yours, evidence is something a good provider builds as a by-product of doing the work properly.
Where security frameworks are referenced — the Australian Signals Directorate’s Essential Eight is the common one for Australian businesses — treat them as a structure for the conversation rather than a certification. Alignment to a framework is a description of practice, not an audited outcome, unless someone has actually audited it.
What security should look like inside a managed agreement
Security is the area where proposals differ most and where the differences are hardest for a non-specialist to judge. Two agreements can both say “cyber security included” and mean very different things.
The baseline that should not be optional
These are not premium features. A provider treating them as upsells is telling you their standard build is below what a business should accept:
- Multi-factor authentication on email, remote access and anything holding money or personal information. This single control prevents the most common way small businesses are compromised, which is a password being reused and appearing in someone else’s breach.
- Managed endpoint protection — not the free antivirus that came with the machine, and importantly, protection that someone is actually watching rather than one that quietly stops updating.
- Email filtering, because that is the door most attacks arrive through.
- Patching on a schedule, applied and verified rather than left to each user’s discretion.
- Backups that have been restored from, which is the only version of a backup that exists.
- Offboarding that actually removes access, promptly and provably. Former staff retaining access to email or files is one of the most common findings in an audit of a business that has never had one.
What sits above the baseline
Beyond that, security becomes a genuine decision about spend and risk rather than a default:
- Managed detection and response — someone reviewing alerts and acting on them, rather than alerts arriving in a dashboard nobody opens. This is a meaningful step up in cost and in protection.
- Conditional access policies, restricting where and how accounts can be used.
- Security awareness training for staff, including simulated phishing.
- Formal incident response planning, so a compromise is met with a procedure rather than improvisation.
- Log retention sufficient to investigate an incident after the fact, which many businesses discover they lack at the worst possible moment.
The reasonable approach is to get the baseline unambiguously in place, then decide about the layer above it with a clear view of what each item costs and what it actually addresses. A provider who leads with the advanced tier before the baseline is complete is selling in the wrong order.
The question that cuts through it
Ask a prospective provider: “If we were compromised tomorrow, what would you be able to tell me about what happened?”
The answer reveals whether logging, monitoring and retention are genuinely in place. A provider who can describe how they would reconstruct the timeline has built for it. A provider who talks about their security stack in general terms has not.
Managed IT versus hiring internally
At some point most growing businesses ask whether they should just employ someone. It is a reasonable question and deserves a straight comparison rather than a sales answer.
What an internal hire gives you
Someone whose entire attention is your business. They learn how your people actually work, they are physically present, and they absorb the small requests that never become tickets. For a business with genuinely complex or unusual systems, that depth is difficult for an external provider to match.
What it does not give you
Coverage. One person cannot be available every day of the year. Annual leave, illness and resignation are not edge cases, they are certainties, and each one leaves the business without its technology function.
Breadth. Modern business IT spans networking, identity, cloud platforms, security, backup and half a dozen vendor ecosystems. One person can be genuinely strong across some of that. Nobody is expert across all of it, and the gaps are usually invisible until something in a gap breaks.
Escalation. When an internal person hits something outside their experience, there is no next line. They are researching it in real time while the business waits.
Documentation, usually. Not because internal staff are careless, but because documenting is the task that gets deferred when you are the only person who needs it. The risk surfaces when they leave.
The honest comparison
Weigh the fully loaded cost of employment — salary, superannuation, leave, training, tooling, recruitment — against a managed agreement covering the same scope. Then consider what happens to each option during a two-week absence, and what happens if the person resigns.
For many businesses the answer is not one or the other. A single internal person handling day-to-day needs and knowing the business, supported by a provider for after-hours, security tooling, projects and escalation, gives better coverage than either alone. That is what co-managed exists for, and it is under-used in Australia relative to how well it fits the mid-sized business.
What to sort out before you talk to any provider
The quality of the proposals you receive depends heavily on the quality of the brief. Half an hour of preparation changes what comes back.
Write down what would actually hurt. Not a list of systems — a list of consequences. If email stopped for a day, what happens? If the file server was unavailable for three days? If client data were exposed? Ranking those tells a provider where to focus and tells you which quote addresses your real risk rather than a generic one.
Count your people honestly. Full-time, part-time, casual, contractors who need an account. Per-user pricing depends on this and underestimating it produces a quote you will not receive again at the same price.
List the software the business genuinely cannot operate without. Practice management, ledger software, a scheduling platform, a design suite. This is the list that determines whether a provider can actually support you, and it is the one most likely to be forgotten until after signing.
Find out who owns what. Domain name, Microsoft 365 tenant, website hosting. If the answer is “our last IT guy set it up”, resolve that first — it will otherwise surface at the least convenient moment.
Decide what you want to be different in twelve months. Fewer interruptions, better security posture, an environment that can absorb ten more staff, or simply not being the person who deals with it any more. A provider who knows the goal can be judged against it.
Warning signs worth taking seriously
Some patterns show up reliably in arrangements that end badly.
The provider owns your accounts. Your domain, your Microsoft tenant, your licences held in their name and not yours. Sometimes it is legacy sloppiness rather than intent, but the effect is the same and it should be corrected regardless of the reason.
Nothing is documented, or documentation is refused. If the only record of your environment is in the provider’s system and you cannot obtain a copy, you have a dependency rather than a service.
Every conversation ends in a quote. Advice that always concludes with a purchase is sales with a technical vocabulary.
Backups are reported but never restored. Ask when a restore was last tested. If the answer is unclear, treat the backup as untested — because it is.
Recurring problems are treated as recurring tickets. A well-run arrangement should see the same fault less often over time. If the same issue is being resolved every month, nobody is asking why it happens.
You cannot get a straight answer about leaving. Covered above, and worth repeating, because it is the most reliable single indicator available before you sign.
When managed IT is the wrong answer
It is not the right model for everyone, and a provider willing to say so is worth listening to.
Businesses under about five people running entirely on cloud services with no server, no specialist software and no compliance obligations often do not need one. The monthly fee buys capability the business will not use.
Businesses whose technology is genuinely simple and stable — a handful of laptops, email, and nothing else — may be better served by a good break-fix relationship and a properly configured backup.
Businesses in the middle of deciding something structural — a merger, a move to entirely different software, a change of premises — sometimes benefit from a project engagement first, then a managed agreement once the shape is settled.
Businesses that want someone to blame rather than someone to work with. The model depends on the provider being told about problems early. A relationship where the provider is treated adversarially produces the opposite behaviour and both sides lose.
The honest test: if you cannot articulate what you want to be different in twelve months, an agreement will not supply the answer.
How to change providers without breaking anything
Switching is the part businesses most often get wrong, usually by underestimating how much lives in the outgoing provider’s head.
Before giving notice, establish what you own. Domain name registration. Microsoft 365 tenant ownership and global administrator access. Backup platform accounts. Licence entitlements. If any of these sit in the provider’s name, resolve it before the relationship becomes tense.
Ask for documentation in writing. Network layout, credentials for systems you own, current configuration, anything running on a schedule. A professional provider hands this over. A provider who resists is telling you why you were right to leave.
Overlap the two providers if you can. A short handover period costs a little and prevents the situation where something breaks in week one and neither party is responsible.
Expect the incoming provider to find things. They are looking at the environment with fresh eyes and different standards. Some of what they find will be genuine; some will be the ordinary difference between how two competent providers do things. A provider who describes everything they inherit as a disaster is selling; a provider who separates “this is a real problem” from “this is not how I would have done it” is being straight with you.
Change the credentials. All of them, on the day the relationship ends. This is not personal and any competent provider expects it.
Common questions
How much does managed IT cost for a small business in Australia?
It is normally priced per user per month, and the range is wide because “managed IT” covers very different scopes. What matters more than the number is what the number includes — particularly whether third-party licensing such as Microsoft 365 is bundled or passed through separately. Ask every provider to split the quote into service fee, licensing, and known exclusions, and the comparison becomes possible.
Is managed IT worth it for a business with only ten staff?
Usually, yes, if the business depends on its systems to trade. Ten staff is typically past the point where informal arrangements hold — there is enough hardware, enough accounts and enough turnover that things fall through gaps. The clearer test than headcount is what an outage costs. If a day without email or files would be expensive or damaging, the arrangement pays for itself the first time it prevents one.
What is the difference between managed IT and just having an IT guy?
Coverage and continuity. An individual is excellent until they are on leave, ill, unavailable, or leave the business — and typically holds the knowledge of your environment in their head. A managed provider brings a team, documentation, and monitoring that runs regardless of who is working. The trade-off is that an individual usually knows your business more intimately, which is exactly why co-managed arrangements exist.
Do we have to move everything to the cloud?
No, and be cautious of anyone who says yes without looking at your environment. Some workloads genuinely belong in the cloud, some are cheaper and better on-premises, and some cannot move because the software vendor does not support it. The right answer depends on what you run, what it costs today, and what your internet connection can actually sustain.
What happens if we are not happy with the service?
Read the notice period and the exit terms before you sign, because that is the moment you have leverage. A reasonable agreement has a defined notice period, a clear statement about data and documentation handover, and no attempt to make leaving technically difficult. Providers who are confident in their service do not need contractual barriers to keep clients.
Does a managed IT provider guarantee we will not be hacked?
No, and nobody can. What can be committed to is the work — which controls are applied, what is monitored, how quickly something is escalated, and what happens when an incident occurs. Any provider promising you will not be compromised is telling you something they cannot know, which is itself useful information about them.
How quickly should a provider respond?
That depends on what has happened, and it should be defined in the agreement rather than promised in general terms. What matters is that “urgent” is defined in writing before an incident rather than argued about during one. A stopped production line and a slow printer are not the same problem, and an agreement that treats them identically has not been thought through.
Where to go from here
If you are weighing up whether a managed arrangement makes sense for your business, the useful next step is not a proposal. It is a conversation about what you are running now, what it is costing you in time you do not see, and where the genuine risks sit.
Geeks360 supports businesses across Penrith, Western Sydney and Greater Sydney with managed IT services, cyber security, Microsoft 365, backup and disaster recovery, and business networks. We work most often with NDIS providers, healthcare practices, construction firms, schools, professional services, accounting practices, legal firms and real estate agencies — sectors where technology failing has consequences beyond inconvenience.
If something in this guide does not match what you are seeing in your own business, that is worth a conversation too. The specifics usually matter more than the general case.