We are an IT services company, so you would expect us to argue that every business needs a managed IT provider. We are not going to do that.
Some businesses genuinely are better off looking after their own computers, software and day-to-day problems. We have met plenty of owners and internal staff who are more than capable, who fix things faster than any ticket queue would, and who would get very little value from paying for a helpdesk they would never ring.
If that is you, this article is not an attempt to talk you out of it. It is an honest look at when self-managing works, what it tends to leave exposed, and where we think the line sits.
Why some businesses are better off managing their own IT
These are the reasons we hear, and most of them are good ones.
- You already have the capability. Someone in the business is genuinely good with technology, enjoys it, and would rather sort a problem out than explain it to a stranger.
- Your environment is simple. Cloud-first, no on-premises servers to nurse, a handful of applications, laptops that mostly look after themselves.
- Problems are rare. If something goes wrong once a fortnight, a support contract sits idle most of the time.
- You are faster than any ticket. You know the machine, you know the software, and you fix it in two minutes rather than describing it to someone who has to learn your setup first.
- You keep control of your own machines. You decide what gets installed and when, without a change process or someone else's standard build.
- You know your own software better than a provider will. Specialist or industry-specific applications are often understood best by the people using them daily.
- You are not funding capacity you will not use. A per-user support fee prices in a level of demand you may simply not generate.
- A small team makes the maths harder. At a handful of staff, a full managed service can be a meaningful line item against a problem you are not actually having.
- You would rather spend the money elsewhere. Every dollar has a competing use, and technology has to earn its place like anything else.
None of that is unreasonable. Businesses that self-manage well tend to be well run generally, and the instinct to keep control of something you understand is a sound one.
What self-managing handles well
There is a visible layer to business IT. It is the laptops, the printer, the software that will not open, the person who cannot find a file, the new starter who needs a machine set up. It is immediate, it announces itself, and you know when it is fixed.
If you have a capable person and a simple environment, there is no mystery here. That layer is entirely manageable in-house, and doing it yourself is often quicker than the alternative.
What it quietly leaves exposed
Underneath the visible layer is another one, and it behaves very differently. It does not announce itself, nothing looks broken, and there is no moment where you notice it needs attention.
That layer is your Microsoft 365 tenant, who has access to what, and the security wrapped around both. In our experience it is where the large majority of real incidents actually begin, and it is the part most self-managing businesses have never had reviewed.
The specific gaps we see most often:
- Configuration drift. Microsoft 365 was set up once, probably years ago, and has been changed here and there since. Sharing was loosened for one project and never tightened. Nobody has looked at the whole picture in a long time.
- Identity and access. Multi-factor authentication is on for some people and not others. Accounts have more access than the job needs. This is the single most common route into a small business.
- Old logins. People who left months ago still have accounts, and nobody is certain which ones. Ex-staff access is one of the easiest things to get wrong when offboarding is informal.
- Security that was switched on and never maintained. Defaults are a starting point, not a baseline. Controls need applying, keeping in place, and checking against something, whether that is SMB1001 or the ASD Essential Eight.
- Nobody watching the alerts. Security tools generate signals. If no one is accountable for reading them, the tool is documentation rather than protection.
- Backup that has never been restored. A backup you have not tested is a belief, not a capability.
- No one to call at the worst moment. Not for a jammed printer. For the morning an account is compromised or money has moved on a fake invoice.
The uncomfortable thing about this list is that a business can have every one of these problems and feel completely fine, right up until it is not fine.
The honest test: under control, or just untested?
Self-managing works when the day-to-day genuinely is handled. It goes wrong when a business assumes it is handled because nothing has gone wrong yet. Six questions worth answering honestly:
- When something breaks on someone's laptop, who fixes it, and how long does it actually take?
- How many times a week does that happen, and what is that time worth?
- Who set up your Microsoft 365, and when was it last properly reviewed?
- When someone leaves, who removes their access, and how do you know it was done?
- If a staff member's account were compromised tomorrow morning, what would you do in the first hour?
- When did you last restore something from backup to prove it works?
If the first two answers are comfortable and the last four are not, you have not got a support problem. You have a platform and security problem, and they are different things with different solutions.
You do not have to choose between doing everything and handing over everything
This is usually presented as a binary. Either you manage your own IT entirely, or you sign up for a full managed service with a helpdesk, device management and the fee that comes with it.
There is a middle option, and it is the one we built AgileASSURE for. You keep the day-to-day. We take the layer that does not announce itself.
In practice that means you keep your computers, your software, your installs and your everyday troubleshooting. We manage your Microsoft 365 tenant, identity and user access, joiners and leavers, the security baselines, managed cyber security through AgileSECURE, Microsoft 365 backup, and a simple escalation process gives you a point of contact when something serious happens.
What it deliberately does not include is a live helpdesk, phone support, remote support sessions, software installation help, application troubleshooting or user training. That is not an oversight, it is the whole point. Excluding the support desk is what makes it cost less than a fully managed service.
It is $89 per user per month ex GST, including AgileSECURE. For comparison, the same platform and the same security inside a fully managed arrangement is $129 per user per month with AgileCORE, or $174 with AgileCOMPLETE. You are paying less because you are doing the day-to-day yourself, not because you are getting a lesser platform.
We will still tell you what we actually recommend
For most businesses, a fully managed arrangement is what we would recommend, and we say so on the AgileASSURE page itself. The reason is simple: most of the problems we get called about start on a device or with a person, and those are exactly the parts a self-managed arrangement leaves with you.
But recommending something is not the same as refusing to sell anything else. If you have the day-to-day genuinely under control and what you actually want is a professional standing behind the platform and the security, then that is a sensible way to buy IT, and we would rather provide it properly than watch a capable business run an unmanaged Microsoft 365 tenant because the only options offered were all or nothing.
If you are somewhere in the middle and not sure which side of the line you sit on, that is exactly what a discovery conversation is for. We will tell you plainly, including if the answer is that you do not need us yet.