Back to Blog
Managed Services Sep 2026 6 min read

Managed IT Services in 2026: 12 Questions Buyers Actually Ask, Answered

Michael Ross, VP of Operations
BlackHawk Data Team
Pricing models, what is genuinely included, MSP vs MSSP vs co-managed, SLA language that means something, shadow AI governance and the offboarding clause nobody reads.

The managed services market is large enough now — credible 2026 estimates put the global figure in the $431–461 billion range — that the marketing has outrun the substance. Every provider claims 24x7, proactive monitoring and a strategic partnership. The differences are real, but they live in contract language and operating detail rather than in the brochure.

These are the twelve questions buyers search for most, answered directly.

1. How is managed IT priced?

The dominant model is per-user or per-device, per month. It is predictable, easy to benchmark across providers, and scales with the business. Alternatives are tiered flat-fee bundles, all-you-can-eat contracts, and hybrid arrangements with a base fee plus project hours.

What matters more than the model is what sits inside the unit. A $95-per-user quote covering helpdesk, monitoring and patching is not comparable to a $145 quote that includes endpoint detection and response, email security, backup and a defined security program. Normalize the scope before you compare the number.

2. What is typically included — and what is not?

Standard inclusions are helpdesk, remote monitoring and management, patching, device management, basic vendor coordination and reporting.

Commonly excluded, and priced separately: endpoint protection and EDR, email filtering, backup and disaster recovery, security awareness training, projects and migrations, after-hours work, and anything involving OT or industrial systems. Cybersecurity is usually a separate line item — assume it is unless the contract says otherwise in writing.

3. What is the difference between an MSP, an MSSP and a vCISO?

The clean division:

Focus Typical deliverable
MSP Keeps IT running Helpdesk, monitoring, patching, infrastructure operations
MSSP Keeps IT defended SOC monitoring, threat detection, incident response, MDR
vCISO Keeps IT governed Risk posture, framework alignment, board reporting, compliance strategy

Most mid-market organizations need all three functions and buy them from one or two providers. The vCISO role is the fastest-growing of the three — provider adoption of vCISO offerings has climbed steeply, which means quality varies enormously. Ask what the vCISO actually produces each quarter.

4. What is co-managed IT, and when does it make sense?

Co-managed IT is a split where your internal team keeps what it does well and the provider covers the rest — typically after-hours coverage, specialist domains like security or networking, tier-three escalation, or surge capacity during projects.

It fits when you have competent internal IT that is under-resourced rather than under-skilled. It fails when responsibilities are not drawn explicitly: two teams both assuming the other owns patching is worse than either owning it alone. Insist on a written responsibility matrix, by function, before go-live.

5. What security framework does the provider follow?

This is the single most revealing technical question, and the answer should be a named framework — NIST Cybersecurity Framework 2.0, CIS Controls, ISO 27001 — with evidence of how it maps to your controls.

"We follow best practices" means there is no framework. Ask which framework, ask to see how your environment is assessed against it, and ask how often that assessment is repeated.

6. How do they handle patching?

"We automate it" is a bad answer, because automation breaks things. A credible answer describes staged rings — pilot, canary, production — with validation between stages, a defined maintenance window, a rollback path, and exception handling for systems that cannot take a patch on schedule.

Ask for last quarter's patch compliance percentage. If they cannot produce it, they are not measuring it.

7. Do they test backup restoration?

Most providers back up. Far fewer restore. The question is not "do you back us up" but "show me a restoration test report from the last ninety days."

A real answer includes what was restored, how long it took, whether it validated, and what failed. Backups that have never been restored are a compliance artifact, not a recovery capability.

8. What do the SLAs actually guarantee?

Read for three things:

  • Response versus resolution. Most SLAs guarantee response — someone acknowledges the ticket. That is not the same as fixing it. Ask what resolution targets exist and what happens when they are missed.
  • Severity definitions. Who classifies an incident as P1, and by what criteria? If the provider classifies, the SLA is partly self-graded.
  • Remedies. A service credit of one month's fee for a day-long outage is not a remedy, it is an apology with an invoice attached.

9. How do they govern AI use — including shadow AI?

This is the newest question on the list and the one most contracts are silent on. Agreements written before 2025 generally do not mention AI at all, which means nothing governs employees pasting company data into public tools.

Ask: how do you discover AI tools in use across our estate, what is the policy position, what data-loss controls apply to AI endpoints, and do you use AI in delivering our service — and if so, what of our data touches it?

10. Who owns the tools, the data and the documentation?

You should own your data unconditionally. That includes monitoring history, logs, ticket records, network documentation, credentials and configuration backups.

Providers who own the tooling create a dependency that has nothing to do with service quality: leaving means losing your own operational history. Get ownership stated explicitly, and get a copy of the documentation quarterly rather than at termination.

11. What does offboarding look like?

The most revealing question in any MSP evaluation, and the one buyers ask last if at all. Get in writing:

  • Notice period and any early-termination penalty
  • What data is returned, in what format, and how quickly
  • Whether documentation and credentials transfer, and whether there is a fee
  • What transition assistance is included versus billable
  • What happens to licences purchased under their agreements

A provider confident in their service writes a clean exit. One who resists is telling you how the relationship ends.

12. How do I know they are proactive rather than reactive?

The test is the monthly report. If it only counts tickets resolved, the provider is reactive. An alert factory forwards you the emails when something breaks; that is not management.

A proactive report names work performed that no ticket requested: firewall rules optimized, disk capacity extended before it filled, firmware standardized across a switch stack, documentation updated, a recurring fault root-caused and eliminated. Ask for last month's report from a comparable client, redacted. The shape of it tells you everything.

The pattern behind all twelve

Every question above is a variation on one thing: does the provider operate, or do they observe? Monitoring is cheap and every provider has it. Operating means someone owns the outcome, works the problem before you notice it, and can show you what they did.

BlackHawk Data delivers managed services through the OneVision lifecycle with 24x7 NOC and SOC operations across networking, security, datacenter and collaboration. What that looks like in practice: halving support costs across 150 buildings without losing security posture, and acting as the IT department for a global media company across 15 sites. Service tiers and what sits inside each are set out at /solutions/managed-services, the delivery model at /onevision, and if you want a read on your current environment before changing providers, the network health check is the usual first step.