Definition
What is a managed service provider (MSP)?
The plain-English definition, what an MSP does day to day, how it differs from an MSSP and from break-fix, and what to ask before you sign.
Talk to usManaged service provider, defined
A managed service provider is a company that takes ongoing responsibility for running part or all of another organization's IT โ monitoring, patching, backups, security, and support โ for a fixed recurring fee under a service-level agreement. The term is almost always shortened to MSP. Three things separate it from every other kind of IT supplier: the work is continuous rather than project-based, the provider is accountable for an outcome rather than for hours worked, and the commercial relationship is a subscription rather than an invoice per incident.
The model exists because most organizations depend completely on technology without wanting to be technology companies. Running IT properly means covering networks, cloud, endpoints, identity, backup, security monitoring, and a help desk at once, around the clock. Staffing all of that internally takes more people than any single discipline's workload justifies, which is why in-house teams end up simultaneously overloaded and under-specialized. An MSP spreads specialists and their tooling across many clients, so each client reaches capability it could never afford to own outright.
What you are actually buying is accountability with evidence behind it. A serious MSP agrees measurable targets up front โ how fast it acknowledges an incident, how fast it resolves each severity, what uptime it commits to โ then reports against them on a fixed cadence. That reporting is the line between an MSP and an outsourced pair of hands. If nobody can show you last month's SLA performance, patch status, and backup tests in writing, you have bought labor, not a managed service.
What a managed service provider actually does
The visible half of the job is reactive. Users raise tickets, alerts fire, something breaks, and the service desk triages by severity and works the issue until it closes. Severity definitions matter more than most buyers expect: a good contract states in plain language what counts as critical โ a site down, a security incident, a blocked payroll run โ and what waits until business hours, so nobody negotiates priority mid-outage.
The half that decides whether the service was worth paying for is proactive, and it is invisible when it works. Patches go on inside agreed maintenance windows. Backups are not merely scheduled but restored on a test schedule, because an untested backup is a hypothesis. Certificates and licenses are renewed before they expire. Cloud spend is reviewed before it becomes a finance problem. Security baselines โ MFA, endpoint protection, privileged-access reviews, log retention โ are checked rather than assumed.
Underneath both halves sits tooling you rarely see but always pay for. MSPs run remote monitoring and management (RMM) agents on managed devices to collect health data and push updates, plus a professional services automation (PSA) platform handling ticketing, SLA timers, asset inventory, and billing. Ask to see both, and ask for the asset register they keep for an existing client. Documentation quality predicts year two better than any sales deck.
MSP, MSSP, break-fix, and in-house: what the labels mean
The most common confusion is between an MSP and an MSSP. A managed security service provider specializes in security operations โ threat detection and monitoring, SIEM, vulnerability management, incident response, and compliance reporting โ rather than general IT operations. An MSP keeps the estate running and applies security hygiene as part of that job; an MSSP watches for adversaries and responds when it finds them. The two overlap at the edges, and many organizations buy both.
Break-fix is the older model an MSP replaced. You call when something breaks, an engineer bills by the hour, and nobody is paid to prevent the next failure โ the supplier's revenue rises when your systems fail, which is a hard incentive to defend. Break-fix still suits genuinely occasional, low-dependency IT. It stops making sense the moment downtime costs real money, because the model contains no mechanism for reducing how often it happens.
In-house is the fourth option and the one most often compared on the wrong axis. The honest comparison is not one salary against a monthly fee; it is the full cost of an internal team โ salaries, benefits, recruitment, training, tooling, and the redundancy genuine out-of-hours coverage requires โ against a contracted fee for the same scope and SLA. Most organizations land on a hybrid: their own people own strategy, and an MSP runs the always-on operational layer underneath.
MSP vs MSSP vs break-fix vs in-house
Managed service provider (MSP)
Scope: day-to-day IT operations โ monitoring, patching, backup, cloud, endpoints, help desk. Paid as a fixed recurring fee under an SLA. Strongest when you depend on technology continuously and want one accountable party. Weakest as a substitute for owning strategy.
Managed security service provider (MSSP)
Scope: security operations โ threat monitoring, SIEM, vulnerability management, incident response, compliance evidence. Also a subscription, usually with 24/7 analyst coverage. Strongest when your risk profile or your regulator demands active detection. It will not patch servers or unblock users unless you buy that too.
Break-fix support
Scope: whatever is broken today, billed by the hour. No SLA, no proactive work, no accountability for prevention. Defensible for occasional, low-dependency IT with a tolerable outage cost. Worst where downtime is expensive, because nothing in the model reduces how often it happens.
In-house IT team
Scope: whatever you hire for. Unbeatable business context and direct control, paid for with salaries, benefits, recruitment, tooling, and the redundancy real 24/7 cover requires. Strongest where technology is your product. Hardest to justify in a small team.
How managed service providers price the work
Four pricing models cover most of the market. Per-user pricing charges a flat fee for each person supported and covers every device that person uses. Per-device pricing charges per managed endpoint โ workstation, server, firewall, switch โ and forecasts better in environments full of shared or unattended hardware. Tiered packages bundle features into levels such as basic, standard, and advanced. ร-la-carte pricing bills each service separately.
The model matters far less than what falls outside it. Ask in writing which work sits inside the recurring fee and which is billed as a project: migrations, new-site build-outs, major version upgrades, security incident response, and after-hours work are the usual exclusions. Ask whether third-party licenses pass through at cost, and what happens to the fee when headcount changes mid-term. A low monthly rate with everything meaningful classed as a project is not a low rate.
Questions to ask before you sign
What exactly is in scope?
Ask for a written list of the systems, sites, and services covered, with the exclusions beside it. Vague scope is where these relationships go wrong.
What are the SLA targets by severity?
Response and resolution times should be stated per severity, with each severity defined in plain language rather than left to the provider's judgment mid-incident.
Who is our named service lead?
You want one accountable person who knows your environment, not a rotating queue. Ask how often they change and who covers their leave.
How do you prove backups work?
Ask for the restore-test schedule and the latest test report. A backup that has never been restored is an assumption, not a recovery plan.
What access will you hold?
Scoped, least-privilege, logged access should be the default. Ask who approves elevation and how often access is reviewed.
What is in the monthly report?
Incidents, SLA performance against target, patch status, backup tests, security events, recommendations. Optional reporting means optional accountability.
Do you hold a security attestation?
Ask whether they hold something like ISO 27001 certification or a SOC 2 Type II report, then ask to see the current document, not a logo.
What is the exit plan?
Documentation handover, notice period, and the format your data comes back in should be in the contract before you sign.
Frequently asked questions
- What does MSP stand for?
- MSP stands for managed service provider: a firm that runs agreed parts of your IT continuously for a fixed recurring fee, under a service-level agreement stating how fast it must respond and what it must keep available. You will also see MSSP โ managed security service provider โ the security-focused version.
- What is the difference between an MSP and an MSSP?
- An MSP keeps your technology running โ monitoring, patching, backups, cloud, endpoints, help desk โ and applies security hygiene as part of that work. An MSSP specializes in security operations: threat detection, SIEM, vulnerability management, and incident response, usually with analysts watching around the clock. Many organizations buy both.
- How much does a managed service provider cost?
- It depends on the pricing model and, far more, on the scope. Providers typically charge per user, per device, in tiered packages, or ร la carte. What matters is total cost including whatever is excluded, so ask which work is billed separately before comparing quotes.
- Is a managed service provider the same as IT outsourcing?
- Managed services is one form of IT outsourcing, but not all outsourcing is managed services. Outsourcing can mean handing over a one-off project with no ongoing commitment. Managed services specifically means a continuing relationship, a defined scope, and an SLA the provider is measured against every month.
- Do we still need an in-house IT person if we hire an MSP?
- Often yes, and usually not for the same work. The most durable arrangement keeps someone internal owning strategy, vendor decisions, and business-specific systems, while the MSP runs the operational layer underneath. Someone on your side still owns priorities and approves change.
- What is an SLA and why does it matter?
- A service-level agreement converts promises into measurable commitments: how quickly incidents are acknowledged and resolved at each severity, what availability is targeted, and how performance is reported. Without one, coverage is a hope. With one, you can tell each month whether you got what you paid for.
- How long are managed services contracts?
- Twelve months is the most common initial term, because onboarding and documenting an environment properly takes effort a very short contract cannot repay. Check the notice period, whether the fee is fixed for the term, and what triggers a mid-term repricing. A long lock-in with no exit clause is a warning sign.
- What happens to our data and access if we leave?
- That should be written in the contract before you sign. A well-run exit hands back documentation, runbooks, configurations, and credentials in a usable format, revokes the provider's access on an agreed date, and includes a transition period. Confident providers write this down without being pushed.
- How can we tell if an MSP is any good before signing?
- Ask for evidence rather than adjectives: a sample monthly report with client details removed, the SLA targets with severity definitions, a restore-test report, and two references you pick from their client list rather than the one they nominate. Providers who cannot produce these have not been doing the work.
- Can an MSP work alongside our existing IT team?
- Yes โ that arrangement is usually called co-managed IT, and it is how most mid-sized organizations use a provider. You split the estate explicitly: which systems the provider owns, which your team owns, who holds which access, and how work crosses the boundary.
Deciding whether you need an MSP?
Tell us what you run and where it hurts. We will say which parts a managed provider should own, which you should keep, and price it plainly.
Get started