Home / Blog / Article

How to choose a managed IT services provider (MSP) in 2026

You've reached the point where "the lad who's good with computers" is no longer enough. The server went down on a Friday evening, nobody answered the phone until Monday, and the backup everyone assumed was working turned out to be three months old. Or, more simply: you've grown from 5 to 40 staff and you need IT that behaves like a department, not an occasional firefighter.

This is where a managed IT services provider (Managed Service Provider, or MSP for short) comes in — a firm that takes over the day-to-day running of your infrastructure for a monthly fee: monitoring, helpdesk, security, backup, patching. It sounds straightforward, but the market is full of providers who promise "complete IT" and deliver a closed ticket five days later.

In this guide I'll show you exactly what to check before you sign: what a real SLA actually means, which questions separate a serious MSP from a mediocre one, how to compare the cost of a retainer with that of an in-house hire, and the warning signs that should make you walk away.

1. What an MSP actually does (and what it doesn't)

The term "managed IT services" is used very loosely, so let's get specific. A serious MSP takes responsibility for the availability and security of your systems proactively — not just when something breaks.

What's normally included in the package

  • 24/7 monitoring — servers, network, workstations, with automatic alerting before the user even notices the problem.
  • Helpdesk and user support — responding to incidents, passwords, printers, email, VPN access. See in detail what a managed IT helpdesk service covers.
  • Patch management — security updates applied in a tested and scheduled way, not left to chance.
  • Backup and disaster recovery — regularly tested copies, with a clear restoration plan.
  • Security — centralised antivirus/EDR, firewall, email filtering, account management.
  • Infrastructure administration — servers, virtualisation, storage and network managed as a single coherent system (see IT infrastructure management).

What is NOT a standard MSP's job

This is where a lot of misunderstandings start. An MSP is not, by default, your software house, nor your digital strategy consultant. Custom application development, large cloud migration projects and compliance audits are usually separate services, billed distinctly — under the umbrella of IT consultancy. An honest provider tells you up front where the retainer ends and the project begins.

📊 Worth remembering

The real difference between an MSP and a "fixer" isn't the price — it's the direction. The fixer reacts to problems; the MSP prevents them. If the offer doesn't include proactive monitoring and monthly reporting, you're actually paying for break-fix in disguise.

2. The SLA: reading the promises beyond the marketing

The SLA (Service Level Agreement) is the document that turns sales promises into contractual obligations. Without a written SLA, "fast support" means absolutely nothing. Here's what it needs to contain and how to read it.

Response time vs resolution time

Watch this distinction carefully — it's the classic trap. Response time is how long it takes for someone to confirm they've received your ticket. Resolution time is how long it takes for the problem to actually be fixed. An MSP can advertise "response within 15 minutes" and still leave you with a downed server for an entire day. Demand clear targets for both.

Prioritisation by severity

A serious SLA classifies incidents and attaches different targets to each class. A typical, healthy structure looks something like this:

SeverityExampleTarget responseTarget resolution
P1 — CriticalServer/ERP down, all users affected15-30 min2-4 hours
P2 — MajorOne department without email or a key application1 hourup to 8 hours
P3 — MinorA single user, no blocking issue4 hours1-2 working days
P4 — RequestNew account, software install1 dayscheduled

The exact values vary depending on the package and how business-critical your operation is — what matters is that the scale exists in the contract, rather than you receiving a single generic promise.

Coverage hours and penalties

  • Coverage: 8×5 (working days) is enough for a typical office; but if you run production, eCommerce or shift work, you need 24/7. Check what's included and what costs extra.
  • Penalties / service credits: an SLA with no consequences for non-compliance is just an intention. Look for credit clauses (a reduction on your invoice) when targets are consistently missed.
  • Exclusions: read what the SLA does NOT cover — often power cuts, internet from another provider, end-of-life hardware.
⚠️ Common trap

"99.9% uptime" sounds impressive, but ask how it's measured and who measures it. 99.9% a month still means around 43 minutes of permitted downtime — and if the MSP monitors its own uptime with no independent report, the figure is just marketing.

3. Ten questions that separate a good MSP from a poor one

Before you sign, ask these questions directly. Evasive answers tell you more than the brochure does.

  1. Who actually answers the phone? A dedicated technician who knows your environment, or a call centre that just opens the ticket?
  2. What monitoring tools do you use and do I get access to the dashboard? Transparency about system health is a sign of maturity.
  3. How do you test backups and how often? An untested backup isn't a backup. Ask for the date of the last real restore.
  4. What's your onboarding procedure? A serious MSP runs an inventory audit and documentation exercise in the first 2-4 weeks.
  5. Do you document the client's infrastructure? If you leave, do you get the documentation? (See below — it's a major red flag.)
  6. What certifications and partnerships do you hold? Microsoft, ISO 27001 compliance, security partners — signs of process, not just improvisation.
  7. How do you handle security incidents? Is there a written response plan, and who coordinates it?
  8. How many clients do you have and what size are they? You want a provider that has managed businesses your size before.
  9. What happens at the end of the contract? Notice period, knowledge transfer, handover of access.
  10. Can I speak to 2-3 reference clients? An MSP with happy clients introduces you without hesitation.

4. MSP retainer vs in-house IT hire — the real maths

The question I hear most often: "Wouldn't it be cheaper to just hire an IT person?" The answer depends on size, but the correct calculation includes far more than gross salary.

The real cost of an in-house IT employee

A competent IT administrator means, on top of net salary, taxes and on-costs, equipment, training, holidays and — crucially — a single person who can't cover 24/7 and who goes on leave. When they're off sick or hand in their notice, you're completely exposed. On top of that, one person is rarely an expert in networking, security, servers, cloud and backup all at once.

What you get from an MSP for the same money

  • A team with complementary skills, not a single generalist.
  • Continuous coverage, with no "key person" risk if someone leaves.
  • Enterprise tooling (monitoring, EDR, backup) already licensed — which you'd pay for separately with an in-house hire.
  • A predictable monthly cost, easy to budget for.
CriterionIn-house IT employeeMSP provider
Coverage hours8×5, one personup to 24/7, a team
Key-person riskHigh (resignation, illness)Eliminated (redundancy)
Skills breadthLimited to one generalistNetwork + security + cloud + backup
Tools / licencesAdditional costIncluded in the retainer
Cost predictabilityVariable (extras, overtime)Fixed monthly retainer
Rapid scalingRequires recruitmentImmediate, contractual

In practice, below roughly 10-15 users an MSP is almost always more cost-effective than a dedicated hire. Above 50-70 users, the hybrid model (one in-house IT person plus an MSP for coverage, security and escalation) often becomes optimal. For an estimate tailored to your size, see our plans and pricing.

💡 Pro tip

Don't just compare the monthly figure. Compare the total cost of unavailability: a day of halted production or a ransomware attack with no tested backup usually costs far more than the retainer difference between two providers.

5. Pricing models: per device, per user, all-in

MSPs bill in a handful of ways. Understanding them helps you compare offers that, at first glance, seem impossible to compare.

  • Per device — a rate for each managed server/workstation/device. Simple to understand, but it can be misleading if you have many users with 3-4 devices each.
  • Per user — a rate per employee, regardless of how many devices they use. Usually the fairest for modern offices (laptop + phone + home).
  • All-inclusive (flat fee) — a fixed retainer that covers everything, including call-outs. Predictable, and it aligns interests: the provider wins when systems run, not when they break.
  • Tiered / blocks of hours — packages with a set number of included hours. Watch what happens when you exceed the block.

The practical recommendation: for most SMEs, a per-user or all-inclusive model offers the best predictability. The "per hour / break-fix" model is tempting and cheap at first, but it aligns interests badly — the provider earns more the more problems you have.

6. Red flags — when to run

After you've seen enough providers, you quickly recognise the toxic patterns. If you spot any of the signals below, treat them as red flags.

  • They won't put an SLA in writing. "We'll look after you, don't worry" is not a contract.
  • They refuse to hand over documentation or access at the end. They hold the client "hostage" through obscurity. An ethical MSP documents everything and hands it over.
  • Backup with no restore testing. If they can't show you when they last did a real restore, the backup only exists on paper.
  • Security as an expensive option, not a standard. In 2026, EDR, MFA and patching aren't extras — they're the baseline.
  • Evasive answers to technical questions. If the salesperson can't bring an engineer to the second meeting, they're selling smoke.
  • Contracts with long lock-ins and a difficult exit. A provider confident in their service won't tie you in for 36 months with no reasonable exit clause.
  • No monthly reporting. If you don't receive reports on tickets, patches, backups and security incidents, you're working on blind trust.
⚠️ The most serious signal

If your current provider can't tell you how many devices you have, which licences you use and where your backups are, they're not managing your infrastructure — they're just patching it up when it squeaks. That's exactly the moment an attack or a failure catches you unprepared.

7. Final checklist before you sign

Before you sign with a managed IT services provider, tick off:

  • ✅ A written SLA, with separate response and resolution targets by severity
  • ✅ Coverage hours suited to your business (8×5 vs 24/7) clearly defined
  • ✅ An onboarding procedure with an inventory audit and documentation
  • ✅ A backup strategy with regular, demonstrable restore testing
  • ✅ Security (EDR, MFA, patching, email filtering) included as standard
  • ✅ Monthly reporting (tickets, uptime, patches, incidents)
  • ✅ A transparent, predictable pricing model with no surprises on overruns
  • ✅ A clear exit clause and knowledge transfer at the end of the contract
  • ✅ 2-3 references from clients of a similar size
  • ✅ A real engineer present in the technical discussions, not just sales
🚀 Final recommendation

Ask for a trial period or an initial IT audit before committing long term. A good MSP will show you, in the first few weeks, exactly what it found misconfigured in your environment — and that tells you more about them than any brochure.

Want IT that works like a department, not an occasional firefighter?

We give you a free IT audit, propose a clear SLA and a retainer suited to your size — 24/7 monitoring, helpdesk, security and tested backup, all predictable on a monthly basis.

Book a call