Microsoft-First Managed IT Services
Round-the-clock monitoring and proactive support that keeps your systems, and your people, running.
Your outsourced IT department
In short: We take ongoing responsibility for your estate: monitoring, patching, backup verification and a 24/7 UK service desk, from £40 per user per month. Right for 15 to 250 seats with no in-house IT, or one stretched person. If you already have a capable team and only need the hours they cannot cover, buy out-of-hours cover on its own instead.
Most IT problems aren't dramatic. They're the slow drip of missed patches, unlogged tickets and a device nobody's checked in months, until the day one of them takes the business offline.
The problem
Break-fix IT feels cheaper until the first serious outage: an unpatched server, a failed backup nobody was monitoring, a ransomware hit that spreads because no one was watching. The cost of doing nothing shows up all at once, usually at the worst possible moment.
What we would do
For most UK businesses between 15 and 250 seats with no in-house IT, or one stretched person, a managed contract is the right answer. It moves patching, monitoring, backup verification and out-of-hours cover from things nobody owns to things somebody is paid to own.
- If you already have a capable internal team and only need the hours they cannot cover, buy out-of-hours cover on its own rather than a full contract.
- If you have internal IT and want depth behind them rather than instead of them, co-managed is cheaper and keeps the knowledge in your business.
When we are not the answer: If what you actually want is somebody physically in your building most days handling desk-side requests as they arise, an internal hire will serve you better than we will. We are strong on Microsoft cloud, identity, security and well-run remote support; we are not a body on site.
We look after the day-to-day running of your IT so your team can focus on the business. Proactive monitoring spots issues before they become outages, and our UK-based service desk is on hand whenever you need us.
More on how we deliver managed IT
From a single point of contact to full lifecycle management of your devices and infrastructure, we become the IT department you'd hire if you could, at a fraction of the cost.
Systech is founder-led by Ryan Mangan, a Microsoft MVP for Azure Virtual Desktop and Windows 365, a Chartered Fellow of the BCS (FBCS) and author of Packt's two-edition Mastering Azure Virtual Desktop.
Everything you need, managed for you
What does 'managed' actually cover compared with break-fix?
The difference is who carries the risk of things going wrong. Under break-fix you pay per incident, which means your provider only earns when something has already failed, and the work that prevents failure (patching, monitoring, backup verification, capacity checks, lifecycle planning) has no natural home.
Under a managed agreement the provider is paid a fixed fee to keep the estate healthy, so unglamorous preventative work becomes their cost of doing business rather than a billable extra. That incentive flip is the substance of the model; the tooling and the service desk follow from it.
In practice a managed service usually spans four layers:
- Monitoring and alerting on servers, endpoints and network devices
- A service desk for user-facing issues
- Maintenance on a schedule: patching, updates, backup oversight and configuration hygiene
- Governance: reporting, documentation and periodic review
What varies between providers is where the boundary falls between included work and project work. Migrations, office moves, new site builds and major upgrades are almost always scoped separately, and any provider claiming otherwise is either pricing that risk into your monthly fee or planning to argue about it later.
What actually happens, and how often?
Most managed IT is sold on adjectives. Proactive, responsive, enterprise-grade. None of those are checkable, so here is the rhythm the service actually runs to, which is.
The recurring work, by cadence:
- Daily: infrastructure checks across servers, connectivity, storage and the backup jobs that ran overnight, so a failure is found in the morning rather than when somebody needs the data.
- Continuously: monitoring and alerting, which is the part that does not wait for a working day.
- Continuously, on rings: security patching for operating systems and third-party software, staged by risk profile as described above.
- Weekly: firewall configuration backups, so a failed device or a bad change is a restore rather than a rebuild from memory.
- Quarterly: firmware and infrastructure update cycles for the kit that should not be touched weekly, alongside a review of device and estate health.
- Monthly: service reporting and review, so all of the above is evidenced rather than asserted.
Patching and firmware are deliberately on different clocks, and it is worth understanding why. Security patches for Windows and third-party software cannot wait for a quarter: Cyber Essentials expects critical and high-severity updates inside fourteen days, and that work runs continuously on the ring model above. Firmware for firewalls, switches and infrastructure is the opposite case, where the update itself carries a real risk of taking something down, so it belongs in a planned window with change control around it.
What does proactive monitoring actually detect?
Proactive monitoring catches the class of problems that degrade before they fail.
The genuinely useful signals are trends rather than events:
- Disk consumption climbing toward a threshold
- Backup jobs completing with warnings for three nights running
- A RAID array in a degraded state
- Memory pressure and paging on a server that used to have headroom
- A certificate approaching expiry
- Battery health on a UPS
- Event log patterns that precede a controller failure
- Endpoints that have stopped checking in for updates
None of those are outages yet. All of them become outages if nobody looks.
The value is therefore in what happens to the alert, not in the alert existing. A monitoring platform that emails a shared mailbox nobody reads is theatre. What makes it worth having is a defined owner for each alert type, a triage step that separates noise from signal, and a record of what was done, so that a recurring warning gets fixed at the cause rather than acknowledged every night for six months.
Why do patching rings matter, and what happens without them?
Patching rings exist because the two obvious strategies are both wrong. Patch everything immediately and a bad update takes out the whole estate at once; defer patching until someone has time and you accumulate exactly the exposure that most ransomware relies on.
A ring model splits devices into staged groups (typically a small pilot group of IT and tolerant users, then a broader group, then the rest, then the sensitive machines that need change windows) with a deferral period between each. A problematic update surfaces in the pilot group where the blast radius is small, and everything behind it can be paused.
Two things make or break the model. The first is that rings must be populated by risk profile, not alphabetically: the finance workstation running the practice management client and the theatre PC driving a piece of medical hardware do not belong in the same wave as a general office laptop.
The second is that third-party software needs the same treatment as Windows itself, because browsers, PDF readers, Java runtimes and remote access tools are consistently among the most exploited applications in the estate and are the ones most often left to update themselves, or not.
What should you check before signing any managed IT contract?
Start with the boundary, not the price. Ask precisely what is included and what becomes chargeable project work, because that line is where most disputes live. Then check what 'unlimited support' means in the small print, whether targets are for response or for resolution, what the out-of-hours arrangement genuinely covers versus what triggers an escalation charge, and how many hours of on-site attendance are included if any. A rate card for out-of-scope work should be in the contract from the start rather than produced after you need it.
Then check ownership and exit, which buyers routinely miss. You should own your Microsoft tenant and your domain registration, hold your own break-glass Global Administrator credentials that the provider does not control, and have licences purchased in your name where the agreement allows it.
Ask what happens to documentation, passwords, monitoring agents and configuration at the end of the term, whether offboarding assistance is included or billed, and what security accreditations the provider itself holds. A supplier with administrative control of your identity platform is part of your attack surface, and should be assessed as one.
Co-managed or fully outsourced: which model fits?
Fully outsourced fits when there is no internal IT function, or when the one person you have is spending their week on password resets instead of the work you actually hired them for.
Co-managed fits when you already have internal capability worth keeping and want to extend it rather than replace it: the internal team keeps the business-context work, the applications nobody else understands and the relationships with the rest of the organisation, while the provider supplies the things that are uneconomic to build in-house: out-of-hours cover, enterprise-grade tooling, specialist depth in areas you touch once a year, and holiday and sickness resilience.
Co-managed only works if the split is written down. The common failure is an ambiguous boundary where both parties assume the other is watching backups, patching the servers or reviewing the alert queue, and the answer turns out to be nobody.
Agree which systems belong to which party, who holds which administrative roles, who is first responder for each alert type, where tickets are raised and how they are escalated between teams. Done properly it is the strongest model available to a mid-sized organisation; done vaguely it produces two teams and one gap.
Does it matter whether the service desk is UK-based?
For some organisations it is a preference; for others it is a contractual requirement. If you work in healthcare, in central or local government, in defence or in a regulated supply chain, your own obligations may specify where data is processed and who can access it, and support staff with administrative access are accessing data.
NHS Data Security and Protection Toolkit commitments, public-sector procurement conditions and client security questionnaires all routinely ask where support is delivered from. If you cannot answer, you may not be able to bid.
Beyond compliance, the practical arguments are working hours and shared context. A desk in your own time zone means the person who took the call at nine can still be handling it at four, rather than a handover across shifts on a problem that needed continuity.
What matters most, though, is not geography but whether the same engineers see the same estate often enough to know it: a UK desk with total churn is not better than a well-run offshore one.
Looking for an IT support company near me: does location still matter?
Less than the phrase implies, and not in the way you would expect. Most managed IT work now happens inside your Microsoft tenant rather than in your building, so the engineer fixing a Conditional Access policy or a broken mail flow is doing identical work whether they sit ten miles away or two hundred.
What genuinely changes with distance is the small proportion of work that needs somebody physically present: a failed switch, a network fault nobody can see remotely, an office move.
So the question worth putting to any IT support company is not where its office is, it is what happens when a job needs hands on site, and whether the people answering the phone are the same people who know your estate.
A local address attached to a service desk somewhere else buys you nothing. We are straight about our own geography: our engineers are based in Brough in East Yorkshire, we cover Yorkshire and the Humber on site as a matter of course, and we work with businesses across the rest of the UK remotely.
Where proximity does earn its keep is the first ninety days. Onboarding goes faster when somebody can spend a day walking the estate rather than inferring it from a remote scan, and that is the point at which we would rather be in the room.
What does asset and lifecycle management actually involve?
It starts with an accurate inventory, and most organisations do not have one. A usable asset record covers every device and its owner, purchase and warranty dates, operating system build and support end date, firmware level, encryption status, installed software, and licence entitlements, and it is generated from your management tooling rather than kept in a spreadsheet, because spreadsheets are out of date the day after they are written. Without that record you cannot answer basic questions, such as how many machines will fall out of support before the next Windows end-of-life date.
Lifecycle management is the discipline of acting on the inventory. That means a refresh plan that spreads replacement cost across years instead of concentrating it into one painful capital request; a build standard so new devices arrive configured rather than hand-assembled; and a defined end-of-life route covering secure data destruction, certificates of erasure for anything holding personal data, and WEEE-compliant disposal. Devices out of vendor support are the awkward part, because unsupported hardware and operating systems fail Cyber Essentials and are frequently excluded from cyber insurance.
Managed IT pricing
from£40per user, per month
Included at that price
- Microsoft 365 tenant management and administration
- OS and application patching across every managed device
- Managed endpoint protection
- Monitored, tested backup for Microsoft 365
- 100% UK-based service desk, available 24/7
What takes it higher
- Managed firewall and network monitoring
- EDR/XDR, email security and archiving
- Server and endpoint backup beyond Microsoft 365
- Conditional Access and device compliance rollout
- Microsoft licence and Azure cost management
- Microsoft 365 security posture assessment and hardening
- Copilot readiness
Each of these is subject to quotation. We scope them against your estate and price them individually, so nothing is committed to before we know what it involves.
Priced around your estate, not a standard build
Managed IT is usually priced from a reference build, and the estate is expected to fit it. We work the other way round: we price against what you already run, including the parts that are working perfectly well and do not need replacing. It means the scoping conversation comes before the number, and it means the quote itemises what is actually included, so it can be compared line by line with anyone else's.
Above 50 users, estates vary enough that a single per-user rate stops being meaningful. We scope and quote those directly. Tell us what you run and we'll scope it.
Questions we hear a lot
What does a managed IT service actually include?
Proactive 24/7 monitoring, a UK-based service desk for your users, patch and update management, backup oversight, device and asset lifecycle management, and regular service reviews, all for a fixed monthly fee rather than per-incident charges.
Is managed IT cheaper than hiring an in-house IT team?
For most small and mid-sized UK businesses, yes. You get a whole team's worth of skills, tooling and out-of-hours cover for less than the cost of one or two full-time hires, with no recruitment, holiday or single-point-of-failure risk.
Do you support hybrid and remote workers?
Yes. We manage devices, identity and access wherever your people work, using Microsoft Intune and conditional access so a laptop at home is as controlled and supported as one in the office.
What's the difference between a managed service provider and an IT support company?
An IT support company sells you time, usually reactively and often by the hour or by pre-paid block. A managed service provider sells you an outcome (a working estate) for a fixed fee, and takes on the monitoring, maintenance and reporting that keeps it working. The practical test is whether the provider makes more money when things break. Under a genuine managed agreement they do not, so preventative work is in their interest as well as yours.
If IT is outsourced, do we still need our own IT policies?
Yes. A provider can operate and enforce controls, but they cannot decide on your behalf what your organisation permits: whether staff can use personal devices, what happens to data when someone leaves, who approves administrative access, or how long records are retained. Those are business decisions with legal and regulatory weight, and under UK GDPR you remain the data controller regardless of who administers the systems. Outsourcing changes who operates the controls, not who is accountable for them.
Is putting a monitoring agent on every device a security risk in itself?
It is a real consideration and worth asking about. Remote monitoring and management tooling holds privileged access across an entire estate, which is exactly why attackers have targeted these platforms to reach many organisations at once. The mitigations are specific: multi-factor authentication on every technician account without exception, role-based access so engineers hold only the rights their work requires, restricted and logged use of remote-control and scripting functions, and prompt patching of the tooling itself. Ask a prospective provider how they secure their own platform, and treat a vague answer as the answer.
How should we handle staff joining, moving and leaving?
Treat it as one controlled process rather than three ad hoc requests. Joining should provision identity, licences, group membership and a device from a defined role template, so access is granted by role rather than by copying an existing user: copied accounts are how privilege quietly accumulates. Moving should remove the old role's access as well as adding the new, which is the step most often skipped. Leaving should disable the account immediately, revoke active sessions and tokens rather than only resetting the password, reclaim the device, and deal with the mailbox and OneDrive content before the retention window closes.
How do we tell whether a managed contract is delivering value?
Look past ticket volume, which mostly measures how much is going wrong rather than how well it is handled. More telling metrics are the trend in repeat incidents against the same system, the proportion of tickets resolved at first contact, patch compliance across the estate expressed as a percentage of devices current, backup success and, more importantly, verified restore tests, and the count of devices and applications running out of vendor support. A provider who brings you problems you had not spotted yet is doing the job; one whose reporting only ever shows green is not looking hard enough.
Does managed IT include dealing with our other software vendors?
Usually yes for liaison, and it is worth confirming in writing. Most managed agreements include raising and chasing tickets with third parties on your behalf (your line-of-business application vendor, your connectivity provider, your telephony supplier) because the alternative is your staff sitting in someone else's support queue with an issue they cannot describe technically. What that does not include is responsibility for the third party's product. If your practice management system has a defect, the provider can evidence it, escalate it and work around it, but only the vendor can fix it.
Managed IT is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Hull, Leeds, York, Sheffield, Barnsley and Halifax and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.
What are you actually running?
Forty-five minutes and a written summary: what you are licensed for, what is switched on, where the gaps are, and what we would fix first. You keep it either way.
Prefer to talk now? Call us on +44 (0)1482 770583.
Technology partners
Best-of-breed technology we use to deliver managed IT.
See all technology partners →