What your MSP is doing in the months when nothing breaks

The hardest thing to sell in managed IT is the month where nothing happens. Here is what that month actually costs to produce, and the questions to ask your provider about it.

The hardest thing to sell in managed IT is the month where nothing happens.

A client rings in March, mildly annoyed. “We’ve barely logged a ticket this quarter. What exactly are we paying for?” It is a completely fair question, and the honest answer is uncomfortable: you are paying for the quarter to have been boring. That is the product. But nobody writes a testimonial about an uneventful Tuesday.

So here is what actually happens in the background of a quiet month, written for the person signing the invoice rather than the person reading the dashboard.

Patching, which is duller and riskier than it sounds

Every month a stream of operating system, firmware and application updates lands. Most are harmless. A few will break a line-of-business application that hasn’t been meaningfully updated since 2019, and one or two will close a hole that is already being actively exploited.

The work is not “click update”. It is deciding the order, staging to a test group first, knowing which of your applications is fragile, and holding back the driver update that historically bluescreens a particular model of laptop. When it goes well, nobody notices. When it goes badly, everyone does, which creates a strong incentive for providers to quietly skip it. Ask yours for a patch compliance report. If they can’t produce one in under a day, that tells you something.

Backups, and the far more important part: restores

Backups that have never been restored are not backups. They are a comforting green tick.

I have walked into environments where the nightly job had been reporting success for fourteen months while silently excluding the folder that mattered most, because someone renamed a share and nobody re-checked the selection. The job was healthy. The data was not there.

A real managed service performs test restores on a schedule, documents how long a full recovery actually takes rather than how long the vendor says it takes, and tells you plainly if your recovery time objective is a fantasy. Most small organisations think they can be back up in four hours. Very few have measured it.

Watching the things that fail slowly

Hardware rarely dies suddenly. It degrades, and it tells you it is degrading months in advance if anyone is listening. Disks report reallocated sectors. Switches log CRC errors on a port where someone crimped a cable badly two winters ago. A UPS battery quietly loses the ability to hold load for more than ninety seconds.

None of these generate a ticket. All of them generate an outage eventually, usually at the least convenient possible moment. A good chunk of a quiet month is someone reading alerts that turned out to be nothing, so that the one that isn’t nothing gets caught.

Identity housekeeping

This is the one most organisations underestimate, and it is where the genuine security risk usually sits.

  • Accounts belonging to people who left in February and still have mailbox access in July.
  • The shared “reception” login that six people know the password to.
  • A service account with domain admin rights created for a project that finished three years ago.
  • Multi-factor authentication enabled for everyone except, invariably, the two executives who found it annoying.

Cleaning this up produces nothing visible. Not cleaning it up is how most small-business compromises actually begin. Not through a sophisticated attack, but through a valid credential that should have been disabled months ago.

Documentation, or the difference between a service and a person

Here is a test worth running on your provider. Ask what happens if the engineer who knows your site best is hit by a bus.

If the honest answer involves phrases like “well, Dave set that up,” you do not have a managed service. You have a dependency on Dave. The unglamorous work of writing down where the fibre enters the building, which VLAN the door controllers sit on, and what the alarm panel’s integration actually depends on, is what separates the two.

Documentation is also the thing that decays fastest, because it is the easiest to skip when you are busy. Keeping it current in a quiet month is precisely the point of having a quiet month.

Vendor wrangling on your behalf

Chasing a carrier about a service fault, arguing with a software vendor about a licensing change they announced with three weeks’ notice, checking whether a hardware model is approaching end of support. Every hour spent here is an hour your staff didn’t spend on hold.

What this means when you are choosing a provider

The uncomfortable implication is that the cheapest managed IT contract is usually cheap because the invisible work isn’t being done. You cannot tell the difference in month one. You find out in month nineteen, when a server dies and the restore takes three days instead of three hours.

So ask for the boring evidence: patch compliance reports, the date of the last successful test restore, an offboarding checklist, and documentation you can actually read. A provider doing this work will be glad you asked. A provider who isn’t will change the subject to their new AI-powered dashboard.

Quiet months are expensive to produce. That is exactly why they are worth paying for.


Written by

Matt Rollins is a Melbourne-based technology founder. He runs TechAssist, a managed IT provider serving growing Australian businesses, and is building TeachingBlox, AussieWave Hosting and Self Storage Auctions.

Start a conversation or connect on LinkedIn.