Managed IT services are an ongoing agreement under which a provider operates defined technology functions for a recurring fee or other contracted model. The defining feature is accountable, continuing responsibility—not a particular tool bundle, price, or promise to prevent every incident.
Current as of 2026-08-15
ITECS’s terms define managed IT services as ongoing management, monitoring, and maintenance of customer infrastructure, with scope controlled by the agreement and order forms.
Decision summary
- The contract should state what the provider operates and what the customer retains.
- Break-fix support reacts to individual requests; managed service adds continuing operational duties.
- Security, backup, cloud, projects, and compliance are not automatically included.
- Review access, evidence, service levels, pricing, exclusions, and exit.
Common managed service functions
- Service desk and user support.
- Endpoint, server, network, and cloud monitoring.
- Patch, configuration, asset, and lifecycle management.
- Identity, email, endpoint, firewall, logging, and security operations.
- Backup, recovery, vendor coordination, planning, and reporting.
Managed IT versus break-fix
Break-fix work is typically authorized and billed around a specific incident or task. Managed service assigns recurring responsibilities and a regular operating cadence. A business may use both models, but it should know which work is included, separately billed, or excluded. The agreement should also identify the baseline, onboarding work, projects, emergency authorization, and after-hours handling. Ambiguous categories should be resolved before an incident creates urgency.
Shared responsibility still applies
CISA’s MSP guidance tells customers and providers to address access, monitoring, logging, and contractual responsibilities. A provider cannot make business risk, legal duties, data ownership, or executive decisions disappear.
What a good agreement makes visible
- Covered people, assets, locations, platforms, and hours.
- Service, security, change, incident, and escalation ownership.
- Performance measures and evidence.
- Fees, units, minimums, projects, and exclusions.
- Data, credential, documentation, transition, and deletion terms.
Next step
Mark every technology responsibility as provider-owned, customer-owned, shared with named actions, or out of scope. For an environment-specific baseline, request an ITECS technology and security assessment.
Primary Sources
- ITECS — Terms and service-scope definitions
- CISA — Joint advisory for MSPs and customers
- NIST — CSF 2.0 resources for small business
Review trigger: Review whenever the contract, asset inventory, platforms, risk profile, business hours, or retained IT team changes.
