Managed IT Services — Pricing Models, Co-Managed and White-Label

  • Home
  • Managed IT Services — Pricing Models, Co-Managed and White-Label
Managed IT Services — Pricing Models, Co-Managed and White-Label
Managed IT Services — Pricing Models, Co-Managed and White-Label
Managed IT Services — Pricing Models, Co-Managed and White-Label
Managed IT Services — Pricing Models, Co-Managed and White-Label

A buyer’s guide · Operating since 2002

Managed IT servicesWhat the model covers, how the pricing really behaves, and the questions that separate providers

Managed IT means an outside team runs your IT operations for a recurring fee: the service desk, endpoints and patching, identity and email, servers and cloud, backup, network and procurement. You are buying an ongoing outcome rather than hours billed after something has already broken.

This page is written as a buyer’s guide. The section that matters most is the pricing one, because the meter you are billed against decides what you pay in year three far more than the rate you negotiate in year one — and it is the part of the proposal nobody reads twice.

Scope, up front. Managed IT is not managed security. Patching and antivirus are hygiene; detecting an intruder who already holds valid credentials is a different function with different tooling and different people. We run both, and we keep them clearly separated — see managed SOC services and NOC as a Service.
3K+
Projects delivered
1,000+
Enterprises supported
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — operations in scope

Scope

What managed IT actually covers

Eight areas, which between them account for nearly everything an internal IT function does day to day. What varies between providers is depth, not this list.

Service desk

First and second line for the things that stop people working: accounts, access, devices, printing, connectivity, the application that will not open. Ticketed, measured, and answerable to a response target rather than to whoever shouts loudest.

Endpoints and patching

Build, deploy, patch and monitor laptops, desktops and mobile devices. Patch compliance reported rather than assumed — unpatched endpoints are the single most common way a small problem becomes an incident.

Identity and email

User lifecycle from joiner to leaver, mailbox and licence administration, MFA enforcement and conditional access. Offboarding done on the day someone leaves, not in the following month’s tidy-up.

Servers and cloud

On-premises and cloud workloads: capacity, availability, updates and configuration drift, across the hypervisors and cloud tenants you already run.

Backup and recoverability

Backups verified by restoring them. A backup job reporting success is evidence that a job ran, not that your data comes back.

Network and connectivity

Switching, wireless, firewalls and circuits, with the option to fold in continuous monitoring from our operations centre — see NOC as a Service.

Procurement and licensing

Specification, sourcing and lifecycle tracking, with renewal dates surfaced before they lapse rather than after.

Reporting and planning

Ticket trends, recurring root causes, asset age and refresh planning — the material for a budget conversation rather than a monthly activity log.

Money

How managed IT pricing actually works

Six ways the same service gets metered. They are not interchangeable, and the difference between them compounds — two quotes that look comparable at signing can diverge substantially within a couple of years.

Scroll the table sideways →

Model How it is metered What happens as you grow Who it favours
Per user Each person, whatever they carry Tracks headcount. Someone with a laptop, a phone, a tablet and a VM costs exactly what a single-laptop user costs. You, in device-heavy estates. The provider, where most staff carry one machine.
Per device Each endpoint, server, switch and firewall Tracks device count, which has risen faster than headcount for a decade. Almost nobody counts their devices before taking the call, so this is the meter that surprises people at renewal. The provider, in most modern estates.
Tiered / banded Fixed bands — up to 25, up to 50, up to 100 Flat, then a cliff. One extra hire can move you a whole band and add more to the bill than the previous twenty hires did. Whoever chose where the band edges sit, which was not you.
Flat rate“all you can eat” One fee, support described as unlimited Predictable for you, and priced for the provider’s worst case — so a well-run estate quietly subsidises the chaotic ones on the same plan. The provider, unless you are genuinely high-touch. Read the fair-use clause.
Block hours Prepaid or billed by the hour Cheap while nothing breaks. Every hour of your downtime is revenue, so nothing in the commercial structure rewards preventing it. The provider — structurally. This is the only model where their income rises when your systems fail.
Co-managed Priced on the slice you hand over Scales with scope rather than headcount, so hiring does not raise the bill. You, if you already have capable people and only need to fill specific gaps.
050100150People in the business →Monthly cost →Per device~1.9 devices per person, and climbingTieredPer userone extra hirecrosses a bandSame service, same headline rate. The meter decides what you pay in year three.

The chart shows shape, not figures. We have not put numbers on the money axis because we have no sourced benchmark to put there, and an invented one would be worse than none.

The question that settles it

Ask every provider for the projected monthly figure at 1.5× your current size, in writing. It takes them a minute and it exposes more than any other question on the list, because it forces the meter into the open.

Then ask what counts as a user and what counts as a device. Servers, phones, virtual machines, printers, shared kiosks and contractors are all argued about at invoice time, and all of them are cheaper to define now than to dispute later.

What drives our price

  • Number of people, and the device count behind them
  • Servers, virtual machines and cloud tenants in scope
  • Coverage hours: business hours, extended, or around the clock
  • Whether network monitoring and security monitoring are included
  • On-site requirement and location
  • How much of the function you keep in-house

We will quote a specific figure against a specific scope, and we will show you what it becomes as you grow rather than leaving you to find out.

The arithmetic

Why one IT hire cannot cover business hours

The number that decides it

Standard business hours are 2,080 hours a year. A full-time employee, after leave, public holidays, training and sickness, delivers roughly 1,900 productive hours.

So a single hire cannot cover even standard business hours across a year — they are around 180 hours short before a single evening or weekend is considered. Every organisation running on one IT person is carrying uncovered time; most simply have not counted it.

Extend to genuine round-the-clock cover and it is 8,760 hours, or about 4.6 people to keep one seat filled, with no redundancy for two simultaneous problems.

What this actually argues

Not that you should have no internal IT. The people who understand your business are the hardest thing to replace and the easiest thing to lose by outsourcing carelessly.

What it argues is that the coverage problem and the context problem are different problems. Overnight cover, routine patching, monitoring and first-line triage need no business context. Deciding what the business should do next needs nothing but.

Handing over the first so your own people can concentrate on the second is usually a better trade than replacing the function outright.

These are arithmetic on stated assumptions rather than a published benchmark. Change the working week or the leave entitlement to your own terms and the conclusion barely moves.

Engagement shapes

Co-managed, after-hours, or the whole function

Full outsourcing is the least common way these arrangements start, and rarely the best first step.

Co-managed

Your team keeps ownership and business-hours control; we fill defined gaps — second line, a specialism, or capacity during a project. Priced on the slice you hand over, so hiring internally does not raise the bill.

After-hours only

You keep the day, we take nights, weekends and public holidays. The hardest and most expensive hours to staff internally, and the lowest-risk way to evaluate a provider before committing further.

Fully managed

The whole function, from service desk to procurement, with a named team and a published escalation path. Suited to organisations with no internal IT or with one person carrying more than one person can.

Most engagements move between these over time, usually starting narrow. A contract that cannot change shape without renegotiation is worth noticing before you sign it.

For providers

White-label service desk and operations

If you already run a managed service business, overnight and weekend cover is the part that does not scale. Your engineers are worth more on project work than on a 2am password reset, and a night shift is hard to justify per client.

Behind your brand

Client-facing communication and reporting carry your identity. We are not in the room and do not need to be.

Multi-tenant separation

One view for you, hard isolation between your clients. Architectural rather than a permissions setting.

Into your PSA

Tickets arrive in the system your technicians already work in, rather than a console someone has to remember to check.

Complementary hours

Nights, weekends and holidays, filling the gap rather than duplicating cover you already pay for.

Escalation you define

We wake your on-call only against criteria you wrote. Everything else waits for the morning handover.

We do not approach your clients

Not as policy and not as practice. If you need that contractual, say so and it will be.

Straight answers

What buyers get wrong about managed IT

Fact

The meter matters more than the rate

Two providers quoting what sounds like the same price can differ by a wide margin three years later purely because one bills per user and the other per device. Compare the projection at your expected future size, not the headline number on the first page of the proposal.

Ask

“Unlimited” is a scope, not a promise

Every flat-rate agreement has a boundary somewhere: fair-use language, excluded categories, or project work carved out. The boundary is not a trick, but it is the thing to read, and it is never on the first page.

Ask

“24/7 support” may mean an answering service

Ask specifically what happens to a ticket raised at 2am: does an engineer pick it up, or does someone take a message for the morning? Both are sold with the same phrase.

Fact

Block-hour billing pays for failure

It is the only common model where the provider earns more when your systems break. That does not make the people dishonest, but it does mean nothing in the commercial structure rewards them for preventing the next outage.

Fact

Managed IT is not managed security

Patching and antivirus are hygiene. Detecting an intruder who already has valid credentials is a different function, with different tooling and different people watching. Buying the first and assuming you got the second is one of the most common and most expensive misunderstandings in this market.

Ask

“Who owns the tenant?”

If your provider holds ownership of your cloud tenant or your domain registration, your ability to leave is contingent on their co-operation. Ask the question early. A good provider answers it in one sentence.

Onboarding

The first thirty days

Onboarding decides whether the arrangement works. Done badly it produces a provider who is still asking where things are in month four.

Step 1

Discovery and audit

We document what exists: assets, accounts, licences, backups, network and whatever undocumented thing everything depends on. This step routinely finds licences being paid for that nobody uses.

Step 2

Ownership transfer

Tenant ownership, domain registration and admin credentials confirmed as yours, documented, before anything else proceeds.

Step 3

Tooling and baseline

Monitoring and management agents deployed, patch state assessed, backup restores actually tested rather than assumed.

Step 4

Quick wins

The two or three recurring issues generating the most tickets get fixed first. It is the fastest way to prove the arrangement is working.

Step 5

Runbook and escalation

Written with your team: who is called, for what, in what order, and what we may act on unaided.

Step 6

Go-live and review

Formal review at 30 and 90 days against ticket volumes, response times and recurring root causes.

Step two is the one to insist on. Tenant ownership, domain registration and admin credentials should be confirmed as yours at the start of a relationship, when everyone is friendly — not established at the end of one, when they are the only leverage either side has.

Before you sign

Ten questions for any managed IT provider

Use these on us and on everyone else you shortlist. If the answers arrive as adjectives rather than numbers and names, keep looking.

Meter

Which meter am I on, and what does the bill look like at 1.5× our current size?

Ask for the actual figure at a larger size, in writing, before signing. This single question exposes more than any other.

Definitions

What exactly counts as a “user” or a “device”?

Servers, phones, virtual machines, printers, shared kiosks and contractors are all argued about at invoice time. Get the definition in the contract.

Scope

What is genuinely unlimited, and what is billed on top?

“Unlimited support” almost always excludes projects, migrations, on-site visits and after-hours work. Ask which of those you will actually need this year.

The clock

What are the response targets by severity, and are they contractual?

Response is not resolution. Both numbers should exist, and both should be in the agreement rather than the proposal.

Cover

Who answers at 7pm on a Friday, and where do they sit?

Ask for the location and the employer. Subcontracted or answering-service cover outside business hours is common and rarely volunteered.

Security

Is security monitoring included, or is that a separate line?

Most managed IT contracts include antivirus and patching and no actual monitoring. Antivirus is not a security operations centre — see managed SOC services for what that scope really involves.

On site

What happens when someone has to be physically present?

Get the response time, the coverage area and the rate. Remote-first is fine until a switch dies.

Margin

Do you resell hardware and software, and do you disclose the margin?

Resale margin is legitimate. Undisclosed resale margin combined with sole-sourced advice is a conflict of interest, and you are entitled to ask which one you are getting.

Ownership

Who owns the cloud tenant, the domain and the admin credentials?

This is the one that traps people. If the provider holds tenant ownership or the domain registration, leaving becomes a negotiation instead of a decision. Ownership should be yours from day one, in writing.

Exit

What is the offboarding process, and what do we receive?

Documentation, asset inventory, credentials, licence transfers and a handover window. Agree it at contract, when you have leverage, not at notice, when you have none.

Working with us

Why buy this from P J Networks

We have run IT and network operations since 2002, for organisations that kept an internal team and for organisations that had none. That is the experience this page is written from.

Our own engineers

Fifty-plus in-house engineers across service desk, network and security operations. Ask who would actually be on your account and we will tell you.

One provider, three functions

Service desk, network operations and security operations from one team, kept properly separate rather than one desk wearing three hats.

Certified operations

ISO/IEC 27001:2022 certified, with our operations centre inside the certified scope and the scope statement available on request rather than on assertion.

You own your tenancy

Tenant ownership, domain registration and admin credentials are confirmed as yours during onboarding. Leaving us should be a decision, not a negotiation.

3K+
Projects delivered
1,000+
Enterprises supported
50+
In-house NOC & SOC engineers
24+
Years, since 2002
ISO/IEC 27001:2022
Certified — operations in scope

Questions we get asked

Managed IT services, answered

What are managed IT services?

Managed IT services means an outside provider runs some or all of your IT operations for an agreed monthly fee: the service desk, endpoints and patching, identity and email, servers and cloud, backup, network and procurement. The distinguishing feature is the commercial model — you pay a predictable recurring fee for an ongoing outcome rather than paying by the hour after something has already broken.

What is an MSP?

A managed service provider is a company that delivers those services on that recurring model. The term is broad: it covers everything from a two-person shop supporting local small businesses to a large provider running enterprise infrastructure. Because the label is unregulated and self-applied, it tells you almost nothing about scope or depth — which is why the questions further up this page are worth more than the category name.

How much do managed IT services cost?

It depends far less on the headline rate than on which meter you are billed against and what is excluded. Per-user, per-device, tiered, flat-rate and block-hour models behave very differently as an organisation grows, and two quotes that look comparable at signing can diverge substantially within a couple of years. The pricing section above sets out how each behaves. Ask any provider for the projected figure at 1.5 times your current size, in writing.

Is per-user or per-device pricing better?

Neither is inherently better; it depends on your device-to-person ratio. Per-user favours you when people carry several devices each, because the extra hardware is free at the margin. Per-device favours you when most staff have exactly one machine and headcount is growing faster than the estate. Count your actual devices before the conversation — most organisations underestimate, and per-device quotes are built on that.

What is co-managed IT?

Your internal team stays and keeps ownership; the provider fills specific gaps rather than replacing the function. Common splits are after-hours and weekend cover, second-line escalation, a specialism nobody internal has, or simply capacity during a project. It is priced on the slice you hand over, so hiring internally does not increase the bill.

Can we keep our internal IT team?

Yes, and in most co-managed engagements that is the point. The people who know your business are the hardest thing to replace and the easiest thing to lose by outsourcing badly. What is usually worth handing over is the work that does not need business context: overnight cover, routine patching, monitoring and first-line triage.

Do you offer white-label services for other providers?

Yes. We run service desk and operations behind another provider’s brand, multi-tenant with hard separation between their clients, with tickets flowing into their PSA. Most such arrangements cover nights, weekends and holidays rather than duplicating cover the partner already has, and we do not approach their clients.

Can you cover only after hours and weekends?

Yes, and it is one of the most common ways engagements start. It addresses the hours that are hardest and most expensive to staff internally, it does not require restructuring your team, and a quarter of it tells you more about a provider than any reference call.

What is included in the service desk?

First and second line for anything stopping people working: accounts and access, devices, email, printing, connectivity and business applications. Tickets are logged, measured and reported against response targets. What is excluded — typically projects, migrations, on-site visits and out-of-scope applications — belongs in the contract, and you should read that list before the inclusions list.

How is this different from break-fix support?

Break-fix bills for time after something has failed, so the provider’s revenue and your uptime pull in opposite directions. A managed agreement charges a recurring fee for keeping things working, which aligns the incentives — preventing the outage is now in their interest too. The trade is predictability against a higher baseline cost in quiet months.

Is security included?

Basic hygiene is: patching, antivirus, MFA enforcement, backup. Actual security monitoring — detection, investigation and response by analysts watching your environment — is a separate function with separate tooling and separate people, covered under managed SOC services. Treating antivirus and patching as a security operations capability is one of the most common and most expensive assumptions in this market.

Do you handle procurement and licensing?

Yes: specification, sourcing, lifecycle tracking and renewal management, with renewals flagged before they lapse. Where we resell, we will tell you that we are reselling. You are entitled to know whether advice is independent.

How long does onboarding take?

Discovery and tooling deployment typically run two to four weeks depending on estate size and how well documented it is. The service is live well before everything is tidy, because the alternative is leaving you unsupported while we catalogue. Full documentation and the first formal review land around day 30.

What happens to our data and accounts if we leave?

You keep them, because they were always yours — tenant ownership, domain registration and admin credentials are confirmed as yours during onboarding rather than held by us. Offboarding covers documentation, asset inventory, credential handover and licence transfers, and the process is agreed at contract rather than negotiated at notice.

Next step

Tell us your headcount and your device count

We will quote against a written scope, show you what that figure becomes at 1.5× your size, and tell you which parts you would be better off keeping in-house. If a co-managed arrangement serves you better than a full one, we will say so.

sanjay@pjnetworks.com