Elevaire Systems
What's Actually Included in Managed IT Services (And What Isn't)
← Back to Insights
Foundation ITmanaged ITcost optimization

What's Actually Included in Managed IT Services (And What Isn't)

Elevaire Systems·

Most companies sign a managed IT services agreement expecting it to cover, in some general sense, "IT." Then six months in, a new office needs cabling, a compliance questionnaire asks for an incident response plan, or a laptop refresh comes with a surprise invoice, and it becomes clear the contract covers less than the sales conversation implied. The gap isn't usually deception. It's that "managed IT services" describes a category, not a fixed scope, and the specifics vary enough between providers that most buyers never actually compare them line by line.

What's Almost Always in Scope

Despite the variation, a core set of services shows up in nearly every managed IT agreement, because it's the baseline work required to keep an organization's technology running day to day.

Help desk and remote support. Employees submit tickets for password resets, software issues, and general troubleshooting, typically during defined business hours, with a stated response time rather than a resolution time. Those are different commitments, and the distinction matters more than it sounds.

Endpoint monitoring and management. Remote monitoring and management (RMM) software installed on laptops and desktops gives the provider visibility into device health, disk space, and basic performance issues, often catching a failing drive or a stalled backup before the employee notices anything wrong.

Patch management. Operating system and common application updates get pushed on a schedule rather than left to individual employees to install or ignore. This is baseline hygiene, not advanced security, and it's one of the most consistently included items across providers.

Microsoft 365 or Google Workspace administration. User provisioning, basic permission management, and routine configuration of the core productivity platform are standard, though the depth varies: some agreements include license optimization and security configuration review, others only cover account creation and resets.

Basic security baseline. Antivirus or endpoint protection deployment, firewall configuration, and a minimum password policy typically fall inside the core agreement. Active threat hunting, security operations center (SOC) monitoring, and incident response almost never do, which is the single most common gap between what companies think they're buying and what a standard contract actually includes.

What Usually Costs Extra, or Isn't Included at All

The exclusions matter more than the inclusions, because they're the ones that surface at the worst possible time: during an incident, an audit, or a project that was assumed to be covered.

CategoryTypically IncludedTypically Billed Separately
Help desk supportYes, during business hoursAfter-hours or emergency response often costs extra
Patching and updatesYes, for supported OS and softwareUnsupported or legacy systems usually excluded
Device monitoringYes, ongoingNew device procurement and hardware cost
M365 / Workspace adminYes, basic administrationLicense optimization and advanced security config vary
Security baselineYes, antivirus and firewall configIncident response, SOC monitoring, penetration testing
Strategic planningRarelyTechnology roadmap, vendor strategy, compliance consulting
New projectsRarelyOffice moves, cabling, migrations, large rollouts

Two categories deserve particular attention because they're the ones that catch growing companies off guard most often. The first is incident response. A managed IT contract that covers endpoint monitoring and patching is not the same as one that covers what happens after a ransomware alert fires at 11 p.m., and conflating the two is a common and expensive assumption. IBM's Cost of a Data Breach Report, in its most recent breakdown by organization size, put the average breach cost for companies under 500 employees at $3.31 million, a figure driven heavily by how quickly an organization can detect, contain, and respond, not just whether it had antivirus software installed. A support contract with no defined incident response component leaves that entire response function unassigned until the moment it's needed most.

The second is strategic and project work: a technology roadmap, a vendor consolidation effort, or planning for a compliance deadline is a different kind of work than day-to-day support, and most managed IT agreements are structured, reasonably, to exclude it rather than absorb open-ended strategic hours into a fixed monthly fee.

Why the Gap Shows Up at the Worst Possible Time

Nobody reviews the fine print of a managed services agreement until they need something the agreement doesn't cover. That's usually during a security incident, when the difference between "we monitor for issues" and "we have an incident response plan" becomes very real very quickly, or during growth, when a new office, an acquisition, or a headcount jump requires project work that a steady-state support contract was never built to handle.

CISA's guidance for small and mid-sized businesses is direct about the baseline every organization needs regardless of what a support contract covers: an up-to-date inventory of devices and software, prioritized patching for internet-facing systems like VPNs and firewalls, and a plan for what happens when, not if, something goes wrong. A managed IT agreement that only covers routine patching and help desk tickets leaves the incident response and strategic planning pieces as somebody else's job, and "somebody else" is often nobody until the moment it's needed.

A Practical Way to Check Scope Before You Sign

None of this requires specialized expertise to evaluate. It requires asking specific questions before signing rather than after something goes wrong, and comparing answers across providers rather than accepting the first proposal's framing at face value.

  1. Ask for the exclusions list in writing, not just the inclusions. A provider that can produce a clear, specific list of what's excluded is one that has thought through the boundaries. A provider that only talks about what's included and gets vague about exclusions is one where scope will get negotiated after something breaks, on their terms.
  2. Confirm whether response time or resolution time is what's actually guaranteed. "We respond within one hour" and "we resolve within one hour" are very different commitments, and the gap between them is where a lot of frustration with managed IT relationships originates.
  3. Ask specifically about incident response. Is there a documented plan for a ransomware event, a data breach, or a significant outage, and is executing that plan part of the monthly fee or a separate emergency engagement billed at a different rate?
  4. Ask who owns strategic decisions. Someone should be accountable for the technology roadmap, vendor renewals, and budget planning. If the answer is "nobody, that's not part of this contract," that's not a flaw in managed IT services as a model, but it is a gap that needs a plan.
  5. Get hardware and licensing costs itemized separately from support fees. Bundling all-in pricing sounds simpler, but it makes it harder to see what you're actually paying for ongoing support versus one-time or recurring product costs.
  6. Ask what happens during a project, not just steady-state operations. An office move, a system migration, or a compliance push typically falls outside standard managed IT scope. Knowing that in advance, and what it costs when it happens, avoids a surprise mid-project.

Where This Fits at Elevaire

Foundation IT is built around the core scope described above: device management and endpoint monitoring, RMM-based proactive monitoring, Microsoft 365 or Google Workspace administration, security baseline enforcement including patch oversight, and responsive help desk support. What's different is that a quarterly Technology Health Review is part of the engagement rather than an upsell, so the strategic gap most managed IT contracts leave open, who is watching the roadmap, doesn't sit unaddressed by default. Companies that outgrow that scope move into Fractional IT Leadership as an expansion of an existing relationship rather than a vendor change.

That structure matters because the two gaps described above, incident response ownership and strategic direction, are exactly the ones a purely operational support contract isn't built to close. A quarterly review doesn't replace a dedicated incident response plan, but it does mean someone is looking at the environment on a fixed cadence rather than only when a ticket comes in, which is often the difference between catching a developing problem and discovering it after the fact.

Frequently Asked Questions

How much should managed IT services actually cost?

Pricing varies by scope and headcount, but most mid-market agreements are structured as a per-user or per-device monthly fee that covers help desk, monitoring, and patching. The number that matters more than the headline rate is what's excluded: two providers quoting similar per-user pricing can have very different total costs once incident response, projects, and licensing are factored in separately. A proposal that looks meaningfully cheaper than others in a comparison is worth a second look at exactly what it leaves out, not an assumption that it's simply a better deal.

If we already have an internal IT person, does adding managed IT services overlap with what they do?

It shouldn't, if scoped correctly. Managed IT services are well suited to the recurring, time-consuming work, ticket resolution, patching, monitoring, that consumes an internal IT person's day without using their most valuable skills. A good arrangement frees that person to focus on the initiatives specific to your business rather than routine maintenance, rather than duplicating their work.

What's the biggest mistake companies make when evaluating a managed IT proposal?

Comparing only the monthly price without comparing the exclusions list. A lower quote that excludes incident response, after-hours support, and project work is not necessarily cheaper once those costs materialize, and they usually materialize at the least convenient time.

Does managed IT services include cybersecurity?

It includes a security baseline: antivirus or endpoint protection, firewall configuration, and patch management. It typically does not include active threat hunting, SOC monitoring, incident response, or compliance program work like SOC 2 or HIPAA readiness, which usually require a dedicated security engagement layered on top of the baseline.

How do we get started if we're not sure our current provider's scope is adequate?

Request the current contract's exclusions list and compare it against the checklist above: incident response, strategic ownership, project work, and hardware and licensing transparency. A gap in any of those areas is worth a direct conversation with the current provider before assuming a new one is needed.

Is it normal for a managed IT contract to exclude new office setups or equipment rollouts?

Yes. Most agreements are priced around steady-state support for an existing environment, not one-time project work. That's a reasonable structure as long as it's clear upfront, so a new office buildout or a large device refresh doesn't arrive as an unplanned invoice.

About Elevaire Systems

Elevaire Systems provides fractional Chief Information Officer (CIO), Chief Technology Officer (CTO), and Chief Information Security Officer (CISO) leadership, along with infrastructure modernization, intelligent automation, and compliance strategy for growing organizations.

Ready to Put This Into Practice?

Schedule a free consultation and let's talk through what this means for your organization specifically.

Schedule a Free Consultation