Business IT projects · Across Québec Request a quoteFrançais

Guide

Managed IT, hourly technician or in-house IT: how to choose

Short answer

Managed IT hands the ongoing management of your IT to an outside firm: monitoring, updates, backups and support, under a service agreement. An hourly technician steps in only when something goes wrong. An in-house team gives you more control, but depends on a few people. The right choice depends on your risks and your needs.

This guide is for information only and is not legal advice.

When a computer won't start, who handles it at your company? Quebec SMBs usually end up with one of three IT support models: hand ongoing management to a managed IT firm, call an hourly technician when needed, or hire IT staff. None of them fits every business. This guide describes each model, its strengths and its limits, then gives you five questions to help you make an informed choice.

The 3 models in one sentence each

Managed IT (managed IT services)

Managed IT means an outside company manages your IT on an ongoing basis, under a written agreement. The Canadian Centre for Cyber Security defines a managed service provider (MSP) as "a company that remotely manages IT infrastructure and user end systems on behalf of a client." According to the MSP Alliance, as cited by the Cyber Centre, MSPs typically have four distinguishing characteristics:

  • they provide some form of network operation centre service and help desk;
  • they remotely monitor and manage all or most of the client's systems;
  • they proactively maintain the systems under management;
  • they use a predictable billing model for regular IT management expenses.

The hourly technician (on call)

An hourly technician comes in when you call, to fix a specific problem or handle a one-off task: a computer that won't boot, a printer to set up, a new hire to equip. You pay for the time spent, with no ongoing service agreement. Between calls, nobody watches your systems unless you have asked for it and planned it.

The in-house IT team

One or more people on your payroll look after IT: helping colleagues, managing accounts, workstations, the network and backups. They know your people and your processes, and they are on site. The Cyber Centre notes that outsourcing IT can help by "eliminating the need to develop and maintain internal IT expertise." The flip side is that an in-house team requires you to build and maintain that expertise yourself.

Proactive or reactive: the real difference

The key difference between these models is not where the person works. It is when they step in.

The reactive model waits for trouble: you call, it gets fixed, and that's it. It works as long as problems are rare, but it leaves out the tasks nobody notices while they are done well: updates, checking backups, reviewing accounts, watching alerts.

The proactive model works continuously to reduce the number and severity of incidents. Proactive maintenance is one of the MSP characteristics cited by the Cyber Centre, and an in-house team can work that way too if it has the time and the mandate.

To decide how much prevention you need, the Cyber Centre recommends that you determine, for each business unit, the acceptable downtime and the acceptable loss of data. Those answers then drive your backup method and schedule. The Cyber Centre gives a simple example: with daily backups, a failure just before the next backup can cost you almost a full day of data.

Whatever model you choose, ask yourself one question: who takes care of these tasks between incidents? If the answer is "nobody," you are running in reactive mode, even if you pay someone for IT.

The 3 models side by side

This table sums up the usual differences. The actual agreement always decides: a technician can do preventive work if you ask, and a managed IT agreement can exclude some services.

CriterionManaged ITHourly technicianIn-house team
How support is deliveredOngoing, under the service agreementOn call, as neededOngoing, during the team's working hours
PreventionProactive maintenance set out in the agreementOnly if you ask for itDepends on available time and priorities
Coverage during absencesRelies on the provider's team, per the agreementDepends on the technician's availabilityMust be planned for vacations, leaves and departures
Range of skillsThe provider's team, within the agreed scopeOne person's skillsThe skills of the people you hire
SecurityGoverned by the agreement: access, logging, incidentsAccess to control on every visitUnder your direct control
Budget predictabilityBilling is usually predictableVaries with breakdownsSalaries, training and tools to plan for
DependencyOn the provider: plan an exit strategyOn a single personOn a few key people

When managed IT is the right fit

Managed IT makes sense when an outage or a security incident would hurt your business and nobody in-house can handle ongoing management. Give it serious thought if:

  • your operations stop when your systems stop;
  • you have many workstations, remote staff or more than one location;
  • you hold personal information or other sensitive data;
  • nobody has the time or the skills to keep up with updates, backups and security;
  • you want recurring IT costs that are more predictable than bills that follow breakdowns.

Managed IT has limits too, and the Cyber Centre spells them out. First, MSPs are attractive targets for cyber criminals because they have access to numerous client systems and a lot of data. Second, a provider serves many customers: in a crisis, your urgent request may sit in their queue if they are busy supporting other organizations with critical issues at the same time. Both are good reasons to insist on a written service level agreement, demonstrated security practices and an exit strategy.

To get a proposal tailored to your environment, you can request a quote for managed IT and IT support. To assess an offer before you sign, see our guide How to choose an IT service provider in Quebec.

When an hourly technician is enough

The on-call model can be enough when your needs are simple and you can live with a disruption until a technician is available. That is often the case if:

  • your team is small and you have few workstations;
  • your tools are mostly cloud services whose vendor runs the infrastructure;
  • you do not keep sensitive data on your own servers;
  • someone in the company can follow a basic maintenance checklist.

The main risk is that things get forgotten. An hourly technician fixes what they are called for. If they are not asked to handle updates or check backups, that work may simply not get done. Write down the maintenance tasks and schedule them with the technician at regular intervals.

Control their access as well. The Cyber Centre says access control should be based on the principle of least privilege, with account reviews when people change jobs or leave. Give the technician a personal account rather than a shared password, and disable it when they no longer work for you.

When to build an in-house team

An in-house team makes sense when the volume and nature of your IT work call for a daily presence, for example when:

  • you have enough requests and projects to keep one person busy full time;
  • you run systems specific to your business that few outsiders know;
  • your work often requires someone on site: shop floors, equipment, many shared workstations;
  • you want direct control over priorities and ways of working.

The limits are mostly about people. A small team depends on a few individuals, so vacations, leaves and departures leave gaps that must be planned for. Skills also have to be kept current across many areas, from security to networking. The Cyber Centre gives one example: managing some security functions yourself, such as encryption keys, requires infrastructure that can be expensive and staff who specialize in it, which is rarely feasible for smaller organizations.

The hybrid model: an internal lead plus managed IT

The models can be combined. In a hybrid model, one person in-house keeps control of decisions and of the relationship with employees, while a managed IT firm handles the ongoing technical work. That person does not need to be a technician. What matters most is that they know the business and have the authority to make decisions.

One way to split the work:

  • In-house: set priorities, approve access requests, onboard new employees, review the provider's reports and act as the main contact.
  • Managed IT: monitoring, updates, backups, user support and, if the contract includes it, security.

This split is in line with the Cyber Centre's guidance. It advises separating the roles and responsibilities of your organization and the provider in your incident response plan, and naming your organization's primary point of contact, including for disaster recovery.

Security and Law 25: your obligations stay the same, whatever the model

Changing your support model does not change your responsibilities. Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, is clear: "Any person carrying on an enterprise is responsible for protecting the personal information held by the person." (s. 3.1)

Here is what the Act provides:

  • Security measures (s. 10): a business must take security measures that are reasonable given the sensitivity of the information, the purposes for which it is used, its quantity and distribution and the medium on which it is stored. This applies to all three models.
  • Staff access (s. 20): authorized employees may access personal information only if it is needed for the performance of their duties. That includes your own IT staff.
  • Written contract with the provider (s. 18.3): if you communicate personal information to a provider because it is necessary to perform their contract, the contract must be in writing and specify the measures the provider takes to protect its confidentiality, to use it only for the contract and not to keep it after the contract expires. The provider must also notify your person in charge of the protection of personal information without delay of any violation or attempted violation.
  • Data outside Quebec (s. 17): if your provider keeps personal information for you outside Quebec, the Act first requires a privacy impact assessment and a written agreement.

The Cyber Centre says the same thing: your organization is the data owner and is legally responsible for data security, and it remains accountable for incident response even if it does not carry out every step itself. Quebec's privacy regulator, the Commission d'accès à l'information, also reminds businesses that when they entrust personal information to a third party for safekeeping, they remain responsible for all of their obligations if a confidentiality incident occurs.

For the details of these obligations, read our guide Law 25: what Quebec SMBs must do on the IT side. If security is at the heart of your needs, see our cybersecurity services as well.

5 questions to assess your situation

Your answers to these five questions will also help you describe your needs to a provider.

  1. How many workstations, users and locations do you have? The more you have, the more routine tasks pile up and the more ongoing management is worth. Several locations also call for a well-managed business network.
  2. Which systems are critical to your operations? Name the ones you cannot serve customers without.
  3. What sensitive data do you hold? The Cyber Centre suggests rating each group of data by the impact a compromise would have on its confidentiality, integrity and availability, using three levels: high, medium or low.
  4. How much downtime can you tolerate? The Cyber Centre talks about maximum tolerable downtime: how long you can be down without significantly impacting your business. Add how much data you can afford to lose.
  5. What skills do you have in-house? Can someone manage accounts, keep up with updates, check backups and respond to an incident? Who covers for that person when they are away?

If your answers describe a simple environment, little sensitive data and a good tolerance for downtime, an hourly technician working from a maintenance checklist may be enough. If your systems are critical, your data sensitive or your in-house skills limited, managed IT or a hybrid model deserves a close look. If the workload keeps a person busy every day, an in-house team, backed by managed IT where needed, may be the way to go.

Frequently asked questions

What is the difference between managed IT and IT support?

IT support means helping users when a problem comes up, for example through a help desk. Managed IT usually includes that, but adds ongoing management: according to the MSP Alliance, as cited by the Canadian Centre for Cyber Security, a managed service provider remotely monitors and manages the client's systems and maintains them proactively.

Does an hourly technician handle updates and backups?

Only if you ask them to. That is how the reactive model works: the technician fixes what they are called for. If you choose this model, write down the maintenance tasks and schedule them with the technician at regular intervals.

Does managed IT include cybersecurity?

It depends on the contract. The Canadian Centre for Cyber Security notes that small and medium businesses may use service providers to remotely manage their IT infrastructure, cyber security and related operations, but the written scope is what counts. Ask that it list the security services included, such as monitoring, access management and incident response.

Can you combine an in-house resource with managed IT?

Yes. A person in-house sets priorities, approves access and acts as the main contact, while the managed IT firm handles monitoring, maintenance and support. The Canadian Centre for Cyber Security recommends clearly separating the roles and responsibilities of your organization and the provider, especially for incident response.

What is a service level agreement (SLA)?

It is the part of the contract that sets the level of service you expect from the provider. According to the Canadian Centre for Cyber Security, it should specify the expected turnaround times, communication media, escalation processes, metrics for assessing performance and penalties for not meeting turnaround times.

Am I still responsible for my data if I outsource my IT?

Yes. According to the Canadian Centre for Cyber Security, your organization is the data owner and is legally responsible for data security. Quebec's Commission d'accès à l'information also reminds businesses that when they entrust personal information to a third party for safekeeping, they remain responsible for their obligations if a confidentiality incident occurs.

Sources

  1. Canadian Centre for Cyber Security, Cyber security considerations for consumers of managed services (ITSM.50.030), sections 1, 1.1, 2.1, 2.4, 2.5, 2.6, 2.7 and 2.9
  2. Canadian Centre for Cyber Security, Small and Medium Organizations: Secure cloud and outsourced IT services
  3. LégisQuébec, Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), sections 3.1, 10, 17, 18.3 and 20
  4. Commission d'accès à l'information du Québec, Incidents de confidentialité et mesures de sécurité (businesses, in French)

Have an IT project in mind?

Describe your project in a few lines: the team will contact you to clarify your needs and send you a quote.

Get a quote