Managed IT / Reactive vs Managed IT

Reactive IT answers the phone. Managed IT removes the reason for the call.

Reactive IT support and managed IT services are different operating models, not two levels of the same product. Reactive IT support responds when something breaks, a user needs help, or a system creates disruption. Managed IT takes broader responsibility for the operating environment: support, monitoring, maintenance, patching, documentation, cybersecurity baseline, vendor ownership and improvement over time.

The monthly cost can look similar at first glance. The environments those two models create over two or three years are not. This guide compares reactive IT support, basic helpdesk support and managed IT services so you can understand which model fits your organisation.

See the models side by side
This guide compares

Reactive IT support, basic helpdesk support, break-fix IT and managed IT services; what each model owns; where reactive support breaks down; when basic IT support is enough; when managed IT becomes necessary; and what a Managed IT Review should clarify. For Australian organisations working out whether their current support model still fits the way the business now operates.

Short answer

Managed IT services and reactive IT support are different operating models, not two tiers of the same service.

Reactive IT support is built around response. A user has a problem. A ticket is raised. A technician investigates. The immediate issue is resolved. The relationship is centred on incidents.

Managed IT is built around ownership. The provider is expected to help operate the environment over time. That includes user support, but it also includes monitoring, patching, Microsoft 365 administration, endpoint management, documentation, vendor coordination, cybersecurity baseline, backup visibility, infrastructure support and improvement planning.

The difference is not just whether support is responsive. The difference is whether the provider is responsible for making the environment more stable, more secure and easier to operate.

Basic IT support fixes issues. Managed IT should reduce the number of avoidable issues over time.
Commitment shape

The confusion usually starts when reactive IT is packaged as a monthly service.

A reactive arrangement with a larger monthly hour pool is still reactive if the provider is only responding to issues raised by the client. A managed arrangement is different because the provider is accountable for the operating baseline of the environment, not only the quality of the response.

The distinction is not the invoice structure. It is the commitment shape. Reactive IT is accountable for response quality and resolution time on tickets raised. Managed IT is accountable for the controls, cadences, documentation and operating standards that reduce the need for avoidable tickets in the first place.

Definitions

What each model actually is — and what it owns.

Reactive IT support
A support model where help is provided when something goes wrong
  • Also described as break-fix IT, ad hoc IT support, basic IT support, helpdesk-only support or pay-as-you-go IT support
  • Perfectly reasonable for simple environments — a small business with a handful of users, low system complexity, limited cybersecurity exposure and no meaningful infrastructure
  • The limitation appears when the environment becomes more dependent on technology
  • Once Microsoft 365, cloud services, remote access, security tools, vendors, endpoints, backup, infrastructure and user expectations become more important, reactive support can leave too much unmanaged
Answers the issue in front of it — not necessarily the condition of the environment behind the issue
Managed IT services
A broader operating model with ongoing responsibility for the environment
  • User support, monitoring and alerting, patching and maintenance
  • Microsoft 365 administration, identity and access support, endpoint management
  • Cybersecurity baseline, backup oversight, vendor coordination
  • Documentation, infrastructure and network support, reporting and roadmap input, improvement work over time
  • A capable provider should be able to explain what is being monitored, maintained and documented, what risks are visible and what improvement work is being prioritised
Should not be a helpdesk subscription with a more expensive label
The test is not whether the provider responds. The test is whether the provider is improving the operating standard of the environment.
Side-by-side comparison

Managed IT services vs IT support.

The same operating areas, viewed through each model. Switch between the two to see what each one actually commits to.

Responds when issues are raised. Best fit for simple, low-complexity environments.

  • Primary model — responds when issues are raised
  • Support style — ticket-by-ticket
  • Monitoring — limited or not included
  • Patching — often ad hoc or issue-driven
  • Documentation — often informal or incomplete
  • Microsoft 365 — basic administration when requested
  • Endpoint management — device-by-device
  • Cybersecurity — often separate or reactive
  • Backup — checked when needed or when requested
  • Vendors — client often coordinates
  • Projects — quoted separately when required
  • Reporting — activity and ticket updates

Operates and improves the environment over time. Best fit for businesses dependent on stable, secure and supportable IT.

  • Primary model — operates and improves the environment over time
  • Support style — support plus operating ownership
  • Monitoring — usually included within agreed scope
  • Patching — managed to an agreed cadence or standard
  • Documentation — maintained as part of operating discipline
  • Microsoft 365 — administration, identity, access and security posture
  • Endpoint management — standards, policy, visibility and lifecycle
  • Cybersecurity — baseline security operated as part of the model
  • Backup — monitored and reviewed within agreed responsibility
  • Vendors — provider helps coordinate technical ownership
  • Projects — sequenced into roadmap and improvement work
  • Reporting — risk, operational visibility and improvement priorities
Operating discipline

The distinction is sharpest at the operating-baseline level.

Monitoring

None by default vs continuous

Reactive: none by default unless separately scoped. Managed: continuous monitoring across agreed endpoints, servers, identity, network or platforms.

Patching

On request vs on cadence

Reactive: when the client asks, during incidents or as a project. Managed: managed to a stated cadence or service level, with exceptions documented.

Documentation

Ticket notes vs operating asset

Reactive: limited, often ticket notes and individual technician memory. Managed: environment documented to a standard another engineer could pick up.

Security posture

Products vs baseline

Reactive: often sold as separate products or addressed after concern appears. Managed: treated as an operating baseline, with evidence produced over time.

Review cadence

Activity meetings vs operating rhythm

Reactive: none by default, or account meetings focused on activity. Managed: defined review rhythm with documented operational output.

Success metric

Ticket times vs environment condition

Reactive: ticket response and resolution times. Managed: fewer recurring incidents, remediated root causes and a more defensible operating posture.

Where reactive support fails

Reactive support becomes expensive when the environment becomes operationally important.

Reactive IT can look cheaper because the monthly commitment is lower. But the hidden cost appears when the business becomes more dependent on technology and the support model does not mature with it. The provider can respond to issues, but recurring problems remain. Documentation stays thin. Vendors keep blaming each other. Microsoft 365 configuration drifts. Cybersecurity becomes a set of assumptions. Projects are delayed. Leadership has no clear view of what is improving.

The visible cost is the support fee. The invisible cost is operational friction. A helpdesk-led model can close tickets efficiently while still allowing architectural debt to accumulate. The faster ticket queue is not the same as a more supportable environment.

01
Recurring incidents become workload, not signal

In a reactive model, repeated incidents can become normal support workload. The same issue is fixed six times because each event is treated as a separate ticket. The ticket may be resolved correctly each time, but the pattern is not treated as evidence that the environment needs to change. Managed IT should treat recurring incidents as a signal: the goal is not faster closure of the same issue; it is to remove the reason the issue keeps appearing.

02
Conditions are not tickets until they fail

Reactive providers usually respond to events. They do not necessarily surface conditions. A single domain controller without a secondary is not a ticket until it fails. A firewall rule base that has not been reviewed for years is not a ticket until it creates exposure or blocks a change. A backup configuration last tested two years ago is not a ticket until recovery is needed. These are not support incidents — they are operating conditions. Managed IT should surface those conditions before they become incidents.

03
No one owns the operating standard

The environment functions day to day, but no one is clearly responsible for keeping it documented, patched, monitored, secured and improved.

04
Documentation never exists when it matters

In reactive environments, documentation is often accumulated in ticket notes, individual memory and old diagrams. That may be enough while the same engineer is available and the environment stays familiar. It becomes a problem when the engineer leaves, the client changes provider, a major incident occurs, or another technician needs to take over. Documentation is not administration — it is what allows the environment to be supported beyond one person's memory. Managed IT should maintain documentation as an operating asset, not reconstruct it during pressure.

05
Security becomes reactive

MFA, patching, endpoint protection, privileged access, backup coverage and Microsoft 365 security are discussed after a concern appears, not operated as an ongoing baseline. In reactive models, security gaps tend to be handled as separate conversations after the concern surfaces — at insurer renewal, after an incident, or when a client requires evidence. In managed IT, the baseline should be operated continuously rather than reconstructed under pressure.

06
Vendor coordination stays with the business

The client remains stuck between carriers, firewall vendors, software providers, cloud platforms and application suppliers.

07
Strategic decisions are made without operating context

In reactive models, larger decisions often appear as separate projects: cloud migration, vendor change, infrastructure refresh, Microsoft 365 restructure, security uplift or network redesign. The issue is that the provider running the project may not have been operating the environment. Decisions made without day-to-day operating context often cost more to unwind than to make correctly in the first place. Managed IT should connect project decisions to the actual condition of the environment.

08
Projects keep being deferred

Infrastructure refresh, Microsoft 365 improvement, backup cleanup, endpoint management and documentation work remain future projects instead of part of operating improvement.

09
Leadership cannot get above ticket metrics

A reactive model can produce useful ticket reporting. But ticket reporting does not tell leadership whether the environment is improving, whether risk is reducing, whether infrastructure is ageing, whether backup is recoverable, whether Microsoft 365 is secure, or whether vendor ownership is clear. The only view of IT becomes the support queue. Managed IT should give leadership a view of the operating environment, not only the volume of issues moving through it.

What managed IT should commit to

Managed IT should carry operational accountability, not just support availability.

Managed IT is not valuable because it creates more tickets, more tools or more reporting. It is valuable when it gives the organisation a more stable and supportable operating model. A capable managed IT arrangement should clarify:

  • Who owns support
  • What is monitored
  • How patching is handled
  • How Microsoft 365 is administered
  • How endpoints are managed
  • How cybersecurity baseline is operated
  • What backup visibility exists
  • How vendors are coordinated
  • What documentation is maintained
  • How infrastructure issues are escalated
  • What risks are visible
  • What improvement work is prioritised

If those responsibilities are unclear, the organisation may be paying for managed IT but receiving something closer to reactive support.

Managed IT should be judged by the condition of the environment over time, not only by the responsiveness of the support desk.
When each model fits

Reactive IT can be rational for simple environments. Managed IT becomes more important as the environment becomes harder to operate casually.

Reactive support is not automatically wrong — and managed IT is usually the better fit when the business depends on IT to operate reliably every day. The risk is holding onto reactive support after the environment has outgrown it.

When reactive may be enough
A managed IT model may be more structure than the business needs
  • The business has few users and systems are simple
  • There is no meaningful infrastructure
  • Microsoft 365 usage is basic
  • Cybersecurity exposure is low and downtime has limited impact
  • There are few vendors and no internal IT roadmap is required
  • Leadership is comfortable accepting more reactive risk
Rational at small scale, low complexity, low exposure
When managed IT becomes the better fit
Common triggers that the environment has outgrown reactive support
  • Microsoft 365 is central to operations; users work across multiple sites or remote locations
  • Cybersecurity expectations have increased; the business has cyber insurance, client or compliance requirements
  • Infrastructure, backup or networking need clear ownership; vendor issues are consuming internal time
  • Repeated support issues are affecting productivity; documentation is incomplete
  • Internal IT is stretched; projects are delayed by daily support load
  • Leadership wants more visibility and fewer surprises
At this point the issue is whether the environment is being managed properly, not whether support is responsive
The economics

The monthly fee is the wrong number to compare.

Reactive IT often looks cheaper because the monthly operating fee is lower. That comparison is incomplete. Under a reactive model, monitoring, patching, documentation and security posture are not usually part of the monthly operating baseline — they are paid for later as projects, incident time, remediation, consulting, emergency work or internal productivity loss. Managed IT usually looks more expensive at the monthly fee line because it includes more operating responsibility. The better comparison is the total cost of running the environment over 24 to 36 months.

Monthly operating feeThe number everyone compares first

Reactive: lower — pay-per-use or a limited monthly model. Managed: higher — a fixed monthly fee that covers the operating baseline.

Incident costWhere recurring issues accumulate

Reactive: higher where recurring issues accumulate hours. Managed: lower where root causes are removed over time.

Project spendRemediation as a separate line

Reactive: larger and more frequent where remediation is always separate. Managed: smaller where improvement is built into operations.

DocumentationBuilt under pressure or maintained

Reactive: built when needed, often as a project. Managed: maintained as part of the managed service.

Security evidenceReconstructed or produced

Reactive: constructed under renewal, audit or insurer pressure. Managed: produced as a by-product of operating discipline.

Internal productivity costThe cost that never hits an invoice

Reactive: higher where repeated issues keep affecting staff. Managed: lower where avoidable disruption reduces.

Leadership visibilityDashboards or operating review

Reactive: ticket dashboards and ad hoc advice. Managed: operational review cadence with documented output.

The comparison that matters is not this month's invoice. It is the cost of running the environment over two or three years, including incident time, project work, security evidence, internal disruption and leadership time. Do not compare only hourly rates, monthly support fees, ticket response times and tool lists. Compare recurring issue volume, documentation quality, security baseline, Microsoft 365 posture, backup visibility, vendor ownership, project delivery, infrastructure lifecycle, leadership visibility and operating improvement over time.

The right comparison is not "Which option is cheaper this month?" It is "Which model gives the business a more stable and supportable environment over time?"
Growing organisations

Growth exposes the limits of basic IT support.

Many businesses begin with reactive support because it is simple and practical. That can work for a while. Then the environment changes. More staff are added. Microsoft 365 becomes more complex. Teams need remote access. Security expectations rise. Applications multiply. Vendors increase. Infrastructure ages. Leadership wants reporting. The business needs projects delivered without disrupting support.

The support model that once worked starts to strain. This is where businesses often experience a gap between what they think they are buying and what they are actually receiving. They may believe they have managed IT. In practice, they may have a responsive support provider with limited responsibility for the broader operating environment. A Managed IT Review should clarify that gap.

Inlight IT view

Reactive and managed are both honest products when sold honestly.

The problem appears when one is sold under the name of the other — most commonly a reactive operation with a monthly subscription attached. The useful test is simple: what does the provider do on a Tuesday when nothing has broken?

A reactive provider does very little on that Tuesday, and that is the correct behaviour for a reactive provider. The model is designed to respond when called. A managed provider uses that Tuesday differently. They monitor, patch, review, document, investigate patterns and surface the conditions that would otherwise become Thursday's incidents. The Tuesday behaviour is the model.

At small scale with low complexity and low exposure, the reactive Tuesday may be the rational choice. At larger scale, where Microsoft 365, cybersecurity, infrastructure, vendors and cloud dependency matter, the managed Tuesday is often the better operating model.

If the provider only responds when something breaks, the business is buying support. If the provider helps reduce what breaks, the business is moving toward managed IT.

Try it

Run the Tuesday test on your current arrangement. If you cannot say what your provider did last Tuesday, that answer is the review.

Run it with us →
Next step

Review whether your current IT support model still fits.

If the comparison is familiar, the next step is not choosing a package. It is reviewing whether the current IT support model still fits the way the organisation now operates. A Managed IT Review helps clarify whether the business needs:

  • Basic support
  • Managed IT services
  • Co-managed IT around an internal team
  • Stronger cybersecurity baseline
  • Provider change
  • Better vendor ownership
  • Microsoft 365 and endpoint improvement
  • Infrastructure or backup uplift
  • A clearer operating rhythm around IT

The goal is not to force every organisation into managed IT. The goal is to understand which operating model fits the environment.

Common questions

FAQs about managed IT services vs IT support.

What is the difference between managed IT services and IT support?

IT support usually responds to issues when users need help. Managed IT services take broader responsibility for the operating environment, including monitoring, patching, documentation, Microsoft 365 administration, endpoint management, cybersecurity baseline, backup visibility, vendor coordination and improvement work. The main difference is ownership. Basic IT support resolves issues. Managed IT should help the environment become more stable and supportable over time.

Is reactive IT the same as break-fix IT?

Reactive IT and break-fix IT are closely related. Both usually mean support is provided when something breaks, a user needs help or a specific issue is raised. The provider is not necessarily responsible for monitoring, patching, documentation, security baseline or improvement planning unless those services are separately agreed.

Is managed IT always better than basic IT support?

No. Basic IT support can be enough for simple, low-risk environments with few users, limited systems and minimal operational dependency. Managed IT becomes more appropriate when the business depends on Microsoft 365, cloud services, cybersecurity controls, vendors, infrastructure, endpoints, documentation and ongoing improvement.

Why is managed IT more expensive than reactive support?

Managed IT usually costs more because it includes broader responsibility. The provider is expected to support users, monitor systems, maintain documentation, manage patching, support Microsoft 365, coordinate vendors, operate cybersecurity baseline and help improve the environment over time. Reactive support may cost less upfront, but can become more expensive if recurring issues, downtime, security gaps and project delays continue.

How do we know if we are getting managed IT or just reactive support?

Ask what has improved over time. If the provider can show fewer recurring incidents, better documentation, clearer security baseline, stronger backup visibility, improved Microsoft 365 posture, completed lifecycle work and better vendor ownership, the model is probably managed. If the relationship is mostly ticket response, the model may still be reactive even if it is billed monthly.

Can reactive support become managed IT over time?

Yes, but only if the operating model changes. That means adding defined responsibilities for monitoring, patching, documentation, security baseline, vendor coordination, roadmap, Microsoft 365 administration, endpoint management and improvement work. A different monthly fee alone does not make support managed.

What should managed IT services include?

Managed IT services should usually include user support, monitoring, maintenance, patching, Microsoft 365 support, endpoint management, cybersecurity baseline, backup visibility, vendor coordination, documentation, infrastructure support and improvement planning. The exact scope depends on the organisation's size, complexity, internal capability and risk profile.

When should a business move from reactive IT to managed IT?

A business should consider managed IT when IT becomes operationally important enough that waiting for problems is no longer acceptable. Common signs include recurring issues, multi-site complexity, stronger cyber expectations, Microsoft 365 dependency, internal IT pressure, vendor complexity, weak documentation, project delays and leadership wanting better visibility.

Does managed IT include cybersecurity?

A proper managed IT model should include a cybersecurity baseline. That typically includes identity controls, MFA, endpoint visibility, patching, privileged access, Microsoft 365 security posture, backup visibility and escalation. Deeper cybersecurity work, such as MDR, Essential Eight assessment, penetration testing remediation or cyber insurance evidence, may need separate scope.

Can you transition from reactive IT support to managed IT without disruption?

Yes, but the first stage needs to be handled carefully. The first 30 to 90 days are often stabilisation: documenting the environment, validating access, reviewing backup, checking security baseline, identifying recurring issues and surfacing accumulated technical debt. Ticket volume can rise briefly during this phase because the provider is actively finding issues that were previously hidden. That is not necessarily a sign that the transition is failing. It may be the first time the environment has been reviewed as a managed operating model rather than a collection of support tickets.

What is the next step if we are unsure which model fits?

The next step is to review the current environment, support model, recurring issues, security baseline, Microsoft 365 posture, vendor ownership and operational risk. A Managed IT Review helps clarify whether basic support is still enough, whether managed IT is required, or whether another model such as co-managed IT or provider replacement is more appropriate.

Practical next step

Does the support model still fit the way the business now operates?

A Managed IT Review answers it in one structured conversation — whatever the answer turns out to be.

Book a Managed IT Review