What is the difference between managed IT support and managed cyber security?
Managed IT support keeps your systems working: the help desk, patching, backups, devices and vendor wrangling. Managed cyber security keeps outsiders from misusing those systems: protective controls, monitoring, detection and response. The two overlap heavily, and for a small business the practical question is not which one to buy, but whether a single provider is accountable for both.
Managed IT support is the operational layer. Someone answers when a screen freezes, applies updates out of hours, manages Microsoft 365 and the network, keeps the printers alive and owns the relationship with your software vendors. Its success measure is uptime and speed: things work, and when they break, they are fixed quickly. It is the half every business already knows it needs, because its absence is loud: phones ring, work stops, someone is cross.
Managed cyber security is the adversarial layer, and the difference in mindset matters. IT support assumes things fail by accident; security assumes someone is trying to make them fail on purpose. It adds application control so unapproved software cannot run, multi-factor authentication so stolen passwords are not enough, restricted admin rights, monitoring by a security operations centre, and detection and response when something slips through. Its success measure is quieter: the incidents that never became your problem. Its absence is silent too, which is exactly the danger; an unmonitored network feels no different until the week it does.
The overlap is where businesses get caught. Patching and backups belong to both worlds, so it is easy for an owner to hear we manage your IT and assume we secure your IT. They are not the same sentence. A provider can be closing tickets brilliantly while nobody watches the logs, no one has tested a restore, and reception still has admin rights. The most useful thing this article can tell you is to stop assuming the second half is included and ask for it in writing, control by control. The Essential Eight is the neutral way to have that conversation, because it names the controls one at a time and sets maturity levels a provider can be held to.
The industry used to treat these as separate purchases, and a few years ago that split made more sense. It has since dissolved at the small-business end, for a simple reason: the same person who patches your systems is best placed to secure them, and during an incident you want one accountable provider, not an IT company and a security company pointing at each other while your files encrypt. The same logic applies after the fact: one provider means one incident timeline, one set of logs, and no gap between vendors for the cause to hide in.
That is the model we run, and why our plans refuse to sell the halves separately. Every tier is managed IT support with a named security maturity built in: Sentinel at $79 per user per month carries the Essential Eight foundations available through Microsoft 365 licensing (deliberately not full Maturity Level 1, and we say so), Fortress at $139 is complete Maturity Level 1, Knox at $179 is Level 2, Titan at $199 is Level 3. We have been doing the IT half since 2006; we are a Microsoft Solutions Partner and an AWS and Azure partner, ISO 27001 aligned, with a 24/7 network and security operations centre behind both halves. Both are also reached through the same service desk, which matters more than it sounds: staff report oddities to people who can actually act on them.
The honest caveats. Separate security providers earn their place in some situations: when a larger organisation wants assurance independent of whoever runs its IT, when a contract demands certified specialists, or for point-in-time work such as penetration testing. And combining the two only works if the combined provider can actually name its security controls; a bundled plan with vague security is the worst of both worlds. Where independent assurance is required, price it separately and knowingly, rather than paying twice for overlapping monitoring nobody reconciles.
If you are not sure which halves you currently have, our free Essential Eight Cyber Security Scorecard will tell you in writing, or call us on 1800 456 567 and ask us the control-by-control question directly.
Find out which halves you currently have.
Ask us the control-by-control question directly, or start with a written baseline you can put in front of any provider, including us.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business