Managed IT Support
Break-fix vs managed IT support: why businesses switch, with a side-by-side cost example
Break-fix IT versus managed IT support compared for UK SMEs: how each is billed, where the hidden costs sit, a worked 20-person cost example and when to switch.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
Break-fix IT means paying an engineer by the hour after something has failed. Managed IT support means paying a fixed monthly fee for monitoring, patching, security and a helpdesk that aim to stop failures happening. Businesses switch because break-fix costs are unpredictable, downtime is uninsured, and nobody is watching security or backups between calls.
Break-fix is how most small businesses start with IT: you know someone, you call them when the server goes down, you pay for the afternoon. It works until the business grows past the point where an afternoon offline is affordable. This article sets out how the two models differ in practice, why firms make the switch, and what a side-by-side year looks like for a typical 20-person business.
The two models in one table
| Break-fix | Managed IT support | |
|---|---|---|
| How you pay | Hourly or per incident, after the fact | Fixed monthly fee, per user or per device |
| When the provider is involved | After something fails | Continuously, through monitoring and scheduled maintenance |
| Patching and updates | Only if you ask | Scheduled and reported |
| Security tooling | Whatever was installed last time | Managed antivirus or EDR, email filtering, MFA enforcement |
| Backups | Your responsibility | Monitored, with periodic restore tests |
| Helpdesk for staff | Ad hoc, often via the owner | Direct, with a ticketing system and priorities |
| Response commitment | None | SLA by priority level |
| Documentation | Rarely | Required, and yours to keep |
| Provider's incentive | More failures, more billable hours | Fewer failures, same fee |
| Budgeting | Unpredictable | Predictable, with planned refreshes |
The last two rows are the ones that matter most. In break-fix, the provider makes money when your systems fail. In a managed contract, the provider makes the same money whether they fail or not, so it is in their interest to prevent failures. That single difference explains most of the others.
Why break-fix looks cheaper than it is
The monthly invoice for break-fix is often zero, which makes it easy to defend at a board meeting. The costs are real, they are just not on that invoice.
Downtime is uninsured. When the file server fails on a Tuesday morning, everyone who needs it stops working until it is fixed. With break-fix, the fix starts when an engineer is free, at their hourly rate, and there is no commitment on how long that takes. The cost of the outage lands on your payroll, not the IT bill. We work through the arithmetic in why unresolved IT issues become expensive.
Nobody is patching. Security updates for Windows, browsers, Office and the firewall are released constantly. Under break-fix, they are applied when someone remembers, which in practice means rarely. The GOV.UK Cyber Security Breaches Survey consistently finds phishing the most common attack on UK businesses, and unpatched software is one of the main ways a phishing click turns into a breach.
Backups are assumed, not checked. The most expensive break-fix calls we see are the ones where the backup "was running" until the day it was needed. Nobody had looked at it for a year.
Emergency pricing. Hardware bought the day a server dies costs more than hardware bought on a planned refresh cycle, and it is configured under pressure by whoever is available.
The owner is the helpdesk. In a break-fix business, staff bring IT problems to the boss because there is nobody else. That time is invisible on the accounts and expensive in reality.
What managed support does between calls
The visible difference is a helpdesk your staff can contact directly. The bigger difference is what happens when nobody has called.
- Monitoring agents on every computer and server flag failing disks, full storage, stopped services and missing updates.
- Windows and third-party patches are tested and applied on a schedule, usually out of hours.
- Endpoint detection and response (EDR) watches for behaviour that antivirus would miss, and is managed centrally.
- Email filtering and multi-factor authentication are enforced across Microsoft 365.
- Backups are checked daily and restore-tested periodically, so the answer to "can we get that file back?" is known in advance.
- Firewall and Wi-Fi firmware is kept current.
- New starters are set up before day one and leavers are disabled the day they go.
- Hardware age and warranty status are tracked so replacements are planned and budgeted.
This is what "proactive" means. It is not a slogan, it is a list of scheduled jobs, each with a record of when it last ran and what it found. That record is also what an insurer or a larger customer asks for when they want evidence that patching, backups and endpoint protection are real rather than intended. Read more about how we run it under proactive monitoring.
Side-by-side: a 20-person business over a year
The figures below are illustrative. The managed column uses our indicative per-device rates (figures reviewed October 2026, confirmed in a written quote). The break-fix column uses assumptions we have stated so you can swap in your own.
The business: 20 staff with a laptop each, one server, one firewall, two network printers, 15 desk phones, Microsoft 365 throughout.
Managed IT support
| Item | Indicative rate | Monthly |
|---|---|---|
| 20 laptops | £17.50 each | £350.00 |
| 1 server | £150.00 | £150.00 |
| 1 router/firewall | £25.00 | £25.00 |
| 2 network printers | £10.00 each | £20.00 |
| 15 desk phones | £16.50 each | £247.50 |
| **Total** | **£792.50 per month, about £9,510 per year** |
That includes monitoring, patching, endpoint security, helpdesk, backup checks, joiners and leavers and reviews. Microsoft 365 licences, hardware and projects are extra in both columns, so they are left out.
Break-fix
Assume a modest year: one server incident, one ransomware scare, a handful of smaller call-outs, and the owner spending time on IT. Assume an engineer rate of £90 per hour and a fully loaded staff cost of £25 per hour. These are round numbers for illustration, not market statistics.
| Event | Assumption | Cost |
|---|---|---|
| Server disk failure, 6 hours down | 8 engineer hours plus 20 staff x 6 hours idle | £720 + £3,000 = £3,720 |
| Phishing compromise, mailbox cleaned, password resets | 6 engineer hours plus 2 staff x half a day | £540 + £200 = £740 |
| 10 smaller call-outs | 2 hours each | £1,800 |
| Owner acting as helpdesk | 2 hours a week at £50 per hour | £5,200 |
| Emergency laptop and server parts bought at short notice | Premium over planned purchase | £600 |
| **Total** | **About £12,060** |
On these assumptions break-fix costs more, and the business still had six hours of downtime, an email compromise, no patching, no monitoring and untested backups. A worse year (a full ransomware event, or a backup that does not restore) would not be measured in thousands.
You can argue every assumption in the second table, and you should, using your own hourly rates and last year's actual incidents. That is the point: the managed column is a known number, the break-fix column is a guess, and the guess is the one with the tail risk.
The triggers that make businesses switch
In our experience the move rarely comes from a spreadsheet. It comes from an event.
- A server or internet failure that stops work for a day and exposes how little anyone knew about the setup.
- A phishing email that compromised a mailbox, followed by the realisation that MFA was never turned on.
- An insurer or a large customer asking for evidence of patching, backups and endpoint protection, and there being none.
- The one person who "did the IT" leaving, with passwords in their head.
- Growth from 8 staff to 20, with joiners waiting days for a laptop and shared drives in chaos.
- Remote and hybrid working, with staff on home networks and personal devices nobody manages.
Mr Plant Hire, a multi-depot plant and tool hire business we have supported for over 15 years, is a useful reference for what managed support looks like when it is mature: site-to-site VPNs between depots, Microsoft 365 and SharePoint, Windows servers, local and cloud backup, EDR and RMM across the estate. Read the Mr Plant Hire case study.
When break-fix is still the right answer
Break-fix is honest and cheap for a business that genuinely fits it: two or three people, laptops only, everything in cloud apps, no regulated data, and a real willingness to lose a day's work now and then. Even then, turn on MFA, buy a backup for Microsoft 365, and keep a provider's number to hand.
The moment you have a server, a shared network, more than about five computers, client data you would be embarrassed to lose, or staff whose time costs more than the monthly fee, the calculation changes. How many computers before you need IT support? goes into the thresholds.
Making the switch without disruption
Moving from break-fix to managed is simpler than moving between two managed providers, because there is usually no contract to exit and little documentation to hand over. The new provider will audit the environment, gather credentials, install monitoring, review backups and security, and brief your staff on how to raise tickets. The changeover typically takes up to 2 days. The first 30 days with a new IT provider describes the process step by step.
What to do next
Run your own numbers. The IT support cost calculator gives an indicative monthly figure for your headcount and equipment using the per-device rates above. Put it next to what last year's outages, call-outs and owner time actually cost, and the decision usually makes itself.

