InsightManaged ITOperating models2026

Managed IT has split into two categories: helpdesk capacity or engineering capability.

Many managed IT providers are still measured by ticket response, patching cadence and user support. Those things still matter, but they are no longer enough for organisations where identity, cloud, cybersecurity, network, backup and recovery now sit inside the same operating model.

A modern managed IT provider should reduce recurring incidents, operate to a defined cyber baseline, involve senior engineers where the risk warrants it, produce recovery evidence, integrate network and security, and give leadership a clear view of what is improving. The question is not whether a provider is good — it is which category they are in, and whether that matches what the business now needs.

Helpdesk capacity / engineering capability / the split
CAPABILITY MEASUREOWNERSECURITYRECOVERY Engineering Capabilityprevents incidentsArchitecture OwnershipIntegrated SecurityTested RecoveryHelpdesk Onlytickets closedWORKWORKWORKWORKWORK THE SPLIT
MeasureTickets closed, or incidents prevented?
EngineersWho owns the architecture?
SecurityOne system, or two arrangements?
RecoveryEvidence, or completion reports?
Start here

Three questions that define what a modern MSP should actually be doing

Three questions cut through the category quickly. The honest answers place a provider on one side or the other of the split this insight describes.

01

Is the model measured by tickets closed, or by incidents prevented?

The answer reveals the operating philosophy more than any other question. A capacity-led model is measured by tickets closed and response-time SLA; a capability-led model is measured by incidents prevented and root causes closed.

SignalMeasurement
02

Are senior engineers involved, or only tier-one operators routing tickets?

The signal is not that every ticket reaches a senior engineer. The signal is that complex, recurring or risk-bearing issues have a defined path to engineering ownership — the architects and incident leads who resolve issues that cannot be fixed by following a runbook.

SignalOwnership
03

Do network and security operate as one system, or as two separate arrangements?

If the answer is "we have a partner who handles security", the model is split. In a capability-led model, network and security are operated as one system rather than two separate arrangements.

SignalIntegration
Two viable models

'Managed IT' covers very different services. The buyer's job is to know which one they have.

Capacity-led (support)
  • Measured by tickets closed and response-time SLA
  • Staffing tier-one operators handle most interactions
  • Security handled separately from the day-to-day model
  • Evidence backup completion reports
Capability-led (engineering)
  • Measured by incidents prevented and root causes closed
  • Staffing senior engineers engaged early where risk warrants
  • Security network and security operated as one system
  • Evidence tested recovery with accepted RTO/RPO
Ticket
Fix
Recurs
Root cause
Closed
Compounds

Reactive support fixes on break. A capability-led model closes recurring incident classes at the root, and the improvement compounds over time.

The category test

Eight questions that change the conversation.

A capable provider answers these concretely, with specifics about your environment. A capacity-led provider tends to pivot to generalities about response time and satisfaction. The pattern is consistent enough that the questions work as a category test.

Question 01 · Which security framework do you operate to?
A real answer"Essential Eight, scored at Maturity Level 1 across these controls, with a documented path to Level 2 by Q3."
Not an answer"We follow best practice."
Question 02 · Who is the senior engineer accountable for our architecture?
A real answerA name, a frequency, and a description of what they actually look at.
Question 03 · How do network and security operate as one system?
The tellIf the answer is "we have a partner who handles security", the model is split.
Question 04 · What is your incident escalation authority?
A real answerWho can disable an account, isolate a host, block mail flow or revoke sessions without a meeting — named and reachable, not abstract.
Question 05 · What does recovery evidence look like for our environment?
A real answerTested restores, sequenced priorities, RTO/RPO accepted by leadership, immutability design.
Not an answerBackup completion reports are not recovery evidence.
Question 06 · How do you measure value: tickets closed, or incidents prevented?
What it revealsThe answer reveals the operating philosophy more than any other question.
Question 07 · What recurring root causes have you closed in the last twelve months?
A real answerSpecific incident classes with measurable reduction — to hand for a capable provider.
Question 08 · What does the operating model look like in twelve months?
A real answerIt describes how prevention work compounds and where maturity moves, if nothing major changes.
The Inlight IT view

Ticket response, patching and user support are baseline functions — not the full value of a modern managed service.

Inlight IT's view is that a support-led provider is not necessarily failing — they may be doing it well. They are simply doing a different thing from what some organisations now need, and confusing the two is what produces the gap. The capability model produces better outcomes per ticket, fewer recurring incidents, and a stack that genuinely improves over time.

Modern managed IT is measured by operating improvement, not ticket volume.

01

Measure incidents prevented, not tickets closed

02

Give risk-bearing issues a path to engineering ownership

03

Operate network and security as one system

04

Ask for recovery evidence, not backup reports

Delivery

Where this is delivered.

Not every organisation needs the heaviest possible managed service — some environments are still well served by a responsive support-led model. The issue is category fit. When the business depends on cloud platforms, cyber-insurance evidence, multi-site networking, regulated data or recovery confidence, the capability-led model is the one that matches.

Managed IT Review

Find out whether your managed IT model is still fit for the environment you now operate.

Review whether your support model still matches your risk, systems and expectations. Scoped to your environment and focused on the operating model, not a generic checklist.

Book a Managed IT Review