Managed IT has split into two categories: helpdesk capacity or engineering capability.
Many managed IT providers are still measured by ticket response, patching cadence and user support. Those things still matter, but they are no longer enough for organisations where identity, cloud, cybersecurity, network, backup and recovery now sit inside the same operating model.
A modern managed IT provider should reduce recurring incidents, operate to a defined cyber baseline, involve senior engineers where the risk warrants it, produce recovery evidence, integrate network and security, and give leadership a clear view of what is improving. The question is not whether a provider is good — it is which category they are in, and whether that matches what the business now needs.
Three questions that define what a modern MSP should actually be doing
Three questions cut through the category quickly. The honest answers place a provider on one side or the other of the split this insight describes.
Is the model measured by tickets closed, or by incidents prevented?
The answer reveals the operating philosophy more than any other question. A capacity-led model is measured by tickets closed and response-time SLA; a capability-led model is measured by incidents prevented and root causes closed.
Are senior engineers involved, or only tier-one operators routing tickets?
The signal is not that every ticket reaches a senior engineer. The signal is that complex, recurring or risk-bearing issues have a defined path to engineering ownership — the architects and incident leads who resolve issues that cannot be fixed by following a runbook.
Do network and security operate as one system, or as two separate arrangements?
If the answer is "we have a partner who handles security", the model is split. In a capability-led model, network and security are operated as one system rather than two separate arrangements.
'Managed IT' covers very different services. The buyer's job is to know which one they have.
- Measured by tickets closed and response-time SLA
- Staffing tier-one operators handle most interactions
- Security handled separately from the day-to-day model
- Evidence backup completion reports
- Measured by incidents prevented and root causes closed
- Staffing senior engineers engaged early where risk warrants
- Security network and security operated as one system
- Evidence tested recovery with accepted RTO/RPO
Reactive support fixes on break. A capability-led model closes recurring incident classes at the root, and the improvement compounds over time.
Eight questions that change the conversation.
A capable provider answers these concretely, with specifics about your environment. A capacity-led provider tends to pivot to generalities about response time and satisfaction. The pattern is consistent enough that the questions work as a category test.
Ticket response, patching and user support are baseline functions — not the full value of a modern managed service.
Inlight IT's view is that a support-led provider is not necessarily failing — they may be doing it well. They are simply doing a different thing from what some organisations now need, and confusing the two is what produces the gap. The capability model produces better outcomes per ticket, fewer recurring incidents, and a stack that genuinely improves over time.
Modern managed IT is measured by operating improvement, not ticket volume.
Measure incidents prevented, not tickets closed
Give risk-bearing issues a path to engineering ownership
Operate network and security as one system
Ask for recovery evidence, not backup reports
Where this is delivered.
Not every organisation needs the heaviest possible managed service — some environments are still well served by a responsive support-led model. The issue is category fit. When the business depends on cloud platforms, cyber-insurance evidence, multi-site networking, regulated data or recovery confidence, the capability-led model is the one that matches.
Find out whether your managed IT model is still fit for the environment you now operate.
Review whether your support model still matches your risk, systems and expectations. Scoped to your environment and focused on the operating model, not a generic checklist.
Book a Managed IT Review