Reactive IT answers the phone. Managed IT removes the reason for the call.
Reactive IT support and managed IT services are different operating models, not two levels of the same product. Reactive IT support responds when something breaks, a user needs help, or a system creates disruption. Managed IT takes broader responsibility for the operating environment: support, monitoring, maintenance, patching, documentation, cybersecurity baseline, vendor ownership and improvement over time.
The monthly cost can look similar at first glance. The environments those two models create over two or three years are not. This guide compares reactive IT support, basic helpdesk support and managed IT services so you can understand which model fits your organisation.
See the models side by sideReactive IT support, basic helpdesk support, break-fix IT and managed IT services; what each model owns; where reactive support breaks down; when basic IT support is enough; when managed IT becomes necessary; and what a Managed IT Review should clarify. For Australian organisations working out whether their current support model still fits the way the business now operates.
Managed IT services and reactive IT support are different operating models, not two tiers of the same service.
Reactive IT support is built around response. A user has a problem. A ticket is raised. A technician investigates. The immediate issue is resolved. The relationship is centred on incidents.
Managed IT is built around ownership. The provider is expected to help operate the environment over time. That includes user support, but it also includes monitoring, patching, Microsoft 365 administration, endpoint management, documentation, vendor coordination, cybersecurity baseline, backup visibility, infrastructure support and improvement planning.
The difference is not just whether support is responsive. The difference is whether the provider is responsible for making the environment more stable, more secure and easier to operate.
The confusion usually starts when reactive IT is packaged as a monthly service.
A reactive arrangement with a larger monthly hour pool is still reactive if the provider is only responding to issues raised by the client. A managed arrangement is different because the provider is accountable for the operating baseline of the environment, not only the quality of the response.
The distinction is not the invoice structure. It is the commitment shape. Reactive IT is accountable for response quality and resolution time on tickets raised. Managed IT is accountable for the controls, cadences, documentation and operating standards that reduce the need for avoidable tickets in the first place.
What each model actually is — and what it owns.
- Also described as break-fix IT, ad hoc IT support, basic IT support, helpdesk-only support or pay-as-you-go IT support
- Perfectly reasonable for simple environments — a small business with a handful of users, low system complexity, limited cybersecurity exposure and no meaningful infrastructure
- The limitation appears when the environment becomes more dependent on technology
- Once Microsoft 365, cloud services, remote access, security tools, vendors, endpoints, backup, infrastructure and user expectations become more important, reactive support can leave too much unmanaged
- User support, monitoring and alerting, patching and maintenance
- Microsoft 365 administration, identity and access support, endpoint management
- Cybersecurity baseline, backup oversight, vendor coordination
- Documentation, infrastructure and network support, reporting and roadmap input, improvement work over time
- A capable provider should be able to explain what is being monitored, maintained and documented, what risks are visible and what improvement work is being prioritised
Managed IT services vs IT support.
The same operating areas, viewed through each model. Switch between the two to see what each one actually commits to.
Responds when issues are raised. Best fit for simple, low-complexity environments.
- Primary model — responds when issues are raised
- Support style — ticket-by-ticket
- Monitoring — limited or not included
- Patching — often ad hoc or issue-driven
- Documentation — often informal or incomplete
- Microsoft 365 — basic administration when requested
- Endpoint management — device-by-device
- Cybersecurity — often separate or reactive
- Backup — checked when needed or when requested
- Vendors — client often coordinates
- Projects — quoted separately when required
- Reporting — activity and ticket updates
Operates and improves the environment over time. Best fit for businesses dependent on stable, secure and supportable IT.
- Primary model — operates and improves the environment over time
- Support style — support plus operating ownership
- Monitoring — usually included within agreed scope
- Patching — managed to an agreed cadence or standard
- Documentation — maintained as part of operating discipline
- Microsoft 365 — administration, identity, access and security posture
- Endpoint management — standards, policy, visibility and lifecycle
- Cybersecurity — baseline security operated as part of the model
- Backup — monitored and reviewed within agreed responsibility
- Vendors — provider helps coordinate technical ownership
- Projects — sequenced into roadmap and improvement work
- Reporting — risk, operational visibility and improvement priorities
The distinction is sharpest at the operating-baseline level.
None by default vs continuous
Reactive: none by default unless separately scoped. Managed: continuous monitoring across agreed endpoints, servers, identity, network or platforms.
On request vs on cadence
Reactive: when the client asks, during incidents or as a project. Managed: managed to a stated cadence or service level, with exceptions documented.
Ticket notes vs operating asset
Reactive: limited, often ticket notes and individual technician memory. Managed: environment documented to a standard another engineer could pick up.
Products vs baseline
Reactive: often sold as separate products or addressed after concern appears. Managed: treated as an operating baseline, with evidence produced over time.
Activity meetings vs operating rhythm
Reactive: none by default, or account meetings focused on activity. Managed: defined review rhythm with documented operational output.
Ticket times vs environment condition
Reactive: ticket response and resolution times. Managed: fewer recurring incidents, remediated root causes and a more defensible operating posture.
Reactive support becomes expensive when the environment becomes operationally important.
Reactive IT can look cheaper because the monthly commitment is lower. But the hidden cost appears when the business becomes more dependent on technology and the support model does not mature with it. The provider can respond to issues, but recurring problems remain. Documentation stays thin. Vendors keep blaming each other. Microsoft 365 configuration drifts. Cybersecurity becomes a set of assumptions. Projects are delayed. Leadership has no clear view of what is improving.
The visible cost is the support fee. The invisible cost is operational friction. A helpdesk-led model can close tickets efficiently while still allowing architectural debt to accumulate. The faster ticket queue is not the same as a more supportable environment.
In a reactive model, repeated incidents can become normal support workload. The same issue is fixed six times because each event is treated as a separate ticket. The ticket may be resolved correctly each time, but the pattern is not treated as evidence that the environment needs to change. Managed IT should treat recurring incidents as a signal: the goal is not faster closure of the same issue; it is to remove the reason the issue keeps appearing.
Reactive providers usually respond to events. They do not necessarily surface conditions. A single domain controller without a secondary is not a ticket until it fails. A firewall rule base that has not been reviewed for years is not a ticket until it creates exposure or blocks a change. A backup configuration last tested two years ago is not a ticket until recovery is needed. These are not support incidents — they are operating conditions. Managed IT should surface those conditions before they become incidents.
The environment functions day to day, but no one is clearly responsible for keeping it documented, patched, monitored, secured and improved.
In reactive environments, documentation is often accumulated in ticket notes, individual memory and old diagrams. That may be enough while the same engineer is available and the environment stays familiar. It becomes a problem when the engineer leaves, the client changes provider, a major incident occurs, or another technician needs to take over. Documentation is not administration — it is what allows the environment to be supported beyond one person's memory. Managed IT should maintain documentation as an operating asset, not reconstruct it during pressure.
MFA, patching, endpoint protection, privileged access, backup coverage and Microsoft 365 security are discussed after a concern appears, not operated as an ongoing baseline. In reactive models, security gaps tend to be handled as separate conversations after the concern surfaces — at insurer renewal, after an incident, or when a client requires evidence. In managed IT, the baseline should be operated continuously rather than reconstructed under pressure.
The client remains stuck between carriers, firewall vendors, software providers, cloud platforms and application suppliers.
In reactive models, larger decisions often appear as separate projects: cloud migration, vendor change, infrastructure refresh, Microsoft 365 restructure, security uplift or network redesign. The issue is that the provider running the project may not have been operating the environment. Decisions made without day-to-day operating context often cost more to unwind than to make correctly in the first place. Managed IT should connect project decisions to the actual condition of the environment.
Infrastructure refresh, Microsoft 365 improvement, backup cleanup, endpoint management and documentation work remain future projects instead of part of operating improvement.
A reactive model can produce useful ticket reporting. But ticket reporting does not tell leadership whether the environment is improving, whether risk is reducing, whether infrastructure is ageing, whether backup is recoverable, whether Microsoft 365 is secure, or whether vendor ownership is clear. The only view of IT becomes the support queue. Managed IT should give leadership a view of the operating environment, not only the volume of issues moving through it.
Managed IT should carry operational accountability, not just support availability.
Managed IT is not valuable because it creates more tickets, more tools or more reporting. It is valuable when it gives the organisation a more stable and supportable operating model. A capable managed IT arrangement should clarify:
- Who owns support
- What is monitored
- How patching is handled
- How Microsoft 365 is administered
- How endpoints are managed
- How cybersecurity baseline is operated
- What backup visibility exists
- How vendors are coordinated
- What documentation is maintained
- How infrastructure issues are escalated
- What risks are visible
- What improvement work is prioritised
If those responsibilities are unclear, the organisation may be paying for managed IT but receiving something closer to reactive support.
Reactive IT can be rational for simple environments. Managed IT becomes more important as the environment becomes harder to operate casually.
Reactive support is not automatically wrong — and managed IT is usually the better fit when the business depends on IT to operate reliably every day. The risk is holding onto reactive support after the environment has outgrown it.
- The business has few users and systems are simple
- There is no meaningful infrastructure
- Microsoft 365 usage is basic
- Cybersecurity exposure is low and downtime has limited impact
- There are few vendors and no internal IT roadmap is required
- Leadership is comfortable accepting more reactive risk
- Microsoft 365 is central to operations; users work across multiple sites or remote locations
- Cybersecurity expectations have increased; the business has cyber insurance, client or compliance requirements
- Infrastructure, backup or networking need clear ownership; vendor issues are consuming internal time
- Repeated support issues are affecting productivity; documentation is incomplete
- Internal IT is stretched; projects are delayed by daily support load
- Leadership wants more visibility and fewer surprises
The monthly fee is the wrong number to compare.
Reactive IT often looks cheaper because the monthly operating fee is lower. That comparison is incomplete. Under a reactive model, monitoring, patching, documentation and security posture are not usually part of the monthly operating baseline — they are paid for later as projects, incident time, remediation, consulting, emergency work or internal productivity loss. Managed IT usually looks more expensive at the monthly fee line because it includes more operating responsibility. The better comparison is the total cost of running the environment over 24 to 36 months.
Reactive: lower — pay-per-use or a limited monthly model. Managed: higher — a fixed monthly fee that covers the operating baseline.
Reactive: higher where recurring issues accumulate hours. Managed: lower where root causes are removed over time.
Reactive: larger and more frequent where remediation is always separate. Managed: smaller where improvement is built into operations.
Reactive: built when needed, often as a project. Managed: maintained as part of the managed service.
Reactive: constructed under renewal, audit or insurer pressure. Managed: produced as a by-product of operating discipline.
Reactive: higher where repeated issues keep affecting staff. Managed: lower where avoidable disruption reduces.
Reactive: ticket dashboards and ad hoc advice. Managed: operational review cadence with documented output.
The comparison that matters is not this month's invoice. It is the cost of running the environment over two or three years, including incident time, project work, security evidence, internal disruption and leadership time. Do not compare only hourly rates, monthly support fees, ticket response times and tool lists. Compare recurring issue volume, documentation quality, security baseline, Microsoft 365 posture, backup visibility, vendor ownership, project delivery, infrastructure lifecycle, leadership visibility and operating improvement over time.
Growth exposes the limits of basic IT support.
Many businesses begin with reactive support because it is simple and practical. That can work for a while. Then the environment changes. More staff are added. Microsoft 365 becomes more complex. Teams need remote access. Security expectations rise. Applications multiply. Vendors increase. Infrastructure ages. Leadership wants reporting. The business needs projects delivered without disrupting support.
The support model that once worked starts to strain. This is where businesses often experience a gap between what they think they are buying and what they are actually receiving. They may believe they have managed IT. In practice, they may have a responsive support provider with limited responsibility for the broader operating environment. A Managed IT Review should clarify that gap.
Reactive and managed are both honest products when sold honestly.
The problem appears when one is sold under the name of the other — most commonly a reactive operation with a monthly subscription attached. The useful test is simple: what does the provider do on a Tuesday when nothing has broken?
A reactive provider does very little on that Tuesday, and that is the correct behaviour for a reactive provider. The model is designed to respond when called. A managed provider uses that Tuesday differently. They monitor, patch, review, document, investigate patterns and surface the conditions that would otherwise become Thursday's incidents. The Tuesday behaviour is the model.
At small scale with low complexity and low exposure, the reactive Tuesday may be the rational choice. At larger scale, where Microsoft 365, cybersecurity, infrastructure, vendors and cloud dependency matter, the managed Tuesday is often the better operating model.
If the provider only responds when something breaks, the business is buying support. If the provider helps reduce what breaks, the business is moving toward managed IT.
Run the Tuesday test on your current arrangement. If you cannot say what your provider did last Tuesday, that answer is the review.
Run it with us →Review whether your current IT support model still fits.
If the comparison is familiar, the next step is not choosing a package. It is reviewing whether the current IT support model still fits the way the organisation now operates. A Managed IT Review helps clarify whether the business needs:
- Basic support
- Managed IT services
- Co-managed IT around an internal team
- Stronger cybersecurity baseline
- Provider change
- Better vendor ownership
- Microsoft 365 and endpoint improvement
- Infrastructure or backup uplift
- A clearer operating rhythm around IT
The goal is not to force every organisation into managed IT. The goal is to understand which operating model fits the environment.
FAQs about managed IT services vs IT support.
What is the difference between managed IT services and IT support?
IT support usually responds to issues when users need help. Managed IT services take broader responsibility for the operating environment, including monitoring, patching, documentation, Microsoft 365 administration, endpoint management, cybersecurity baseline, backup visibility, vendor coordination and improvement work. The main difference is ownership. Basic IT support resolves issues. Managed IT should help the environment become more stable and supportable over time.
Is reactive IT the same as break-fix IT?
Reactive IT and break-fix IT are closely related. Both usually mean support is provided when something breaks, a user needs help or a specific issue is raised. The provider is not necessarily responsible for monitoring, patching, documentation, security baseline or improvement planning unless those services are separately agreed.
Is managed IT always better than basic IT support?
No. Basic IT support can be enough for simple, low-risk environments with few users, limited systems and minimal operational dependency. Managed IT becomes more appropriate when the business depends on Microsoft 365, cloud services, cybersecurity controls, vendors, infrastructure, endpoints, documentation and ongoing improvement.
Why is managed IT more expensive than reactive support?
Managed IT usually costs more because it includes broader responsibility. The provider is expected to support users, monitor systems, maintain documentation, manage patching, support Microsoft 365, coordinate vendors, operate cybersecurity baseline and help improve the environment over time. Reactive support may cost less upfront, but can become more expensive if recurring issues, downtime, security gaps and project delays continue.
How do we know if we are getting managed IT or just reactive support?
Ask what has improved over time. If the provider can show fewer recurring incidents, better documentation, clearer security baseline, stronger backup visibility, improved Microsoft 365 posture, completed lifecycle work and better vendor ownership, the model is probably managed. If the relationship is mostly ticket response, the model may still be reactive even if it is billed monthly.
Can reactive support become managed IT over time?
Yes, but only if the operating model changes. That means adding defined responsibilities for monitoring, patching, documentation, security baseline, vendor coordination, roadmap, Microsoft 365 administration, endpoint management and improvement work. A different monthly fee alone does not make support managed.
What should managed IT services include?
Managed IT services should usually include user support, monitoring, maintenance, patching, Microsoft 365 support, endpoint management, cybersecurity baseline, backup visibility, vendor coordination, documentation, infrastructure support and improvement planning. The exact scope depends on the organisation's size, complexity, internal capability and risk profile.
When should a business move from reactive IT to managed IT?
A business should consider managed IT when IT becomes operationally important enough that waiting for problems is no longer acceptable. Common signs include recurring issues, multi-site complexity, stronger cyber expectations, Microsoft 365 dependency, internal IT pressure, vendor complexity, weak documentation, project delays and leadership wanting better visibility.
Does managed IT include cybersecurity?
A proper managed IT model should include a cybersecurity baseline. That typically includes identity controls, MFA, endpoint visibility, patching, privileged access, Microsoft 365 security posture, backup visibility and escalation. Deeper cybersecurity work, such as MDR, Essential Eight assessment, penetration testing remediation or cyber insurance evidence, may need separate scope.
Can you transition from reactive IT support to managed IT without disruption?
Yes, but the first stage needs to be handled carefully. The first 30 to 90 days are often stabilisation: documenting the environment, validating access, reviewing backup, checking security baseline, identifying recurring issues and surfacing accumulated technical debt. Ticket volume can rise briefly during this phase because the provider is actively finding issues that were previously hidden. That is not necessarily a sign that the transition is failing. It may be the first time the environment has been reviewed as a managed operating model rather than a collection of support tickets.
What is the next step if we are unsure which model fits?
The next step is to review the current environment, support model, recurring issues, security baseline, Microsoft 365 posture, vendor ownership and operational risk. A Managed IT Review helps clarify whether basic support is still enough, whether managed IT is required, or whether another model such as co-managed IT or provider replacement is more appropriate.
Does the support model still fit the way the business now operates?
A Managed IT Review answers it in one structured conversation — whatever the answer turns out to be.
Book a Managed IT Review