Managed IT for Small Businesses: What You Actually Need

Most small companies are sold enterprise packages they will never use. Here is the short list of what genuinely matters under fifty people.

4 min readBombardier Tech

Managed IT pricing is usually built for companies with a few hundred staff, then scaled down for everyone else. The result is that small businesses get sold a thinner version of an enterprise package rather than something designed for their actual situation.

Under about fifty people, the risks are different. You probably do not have a compliance department, you almost certainly do not have anyone whose full time job is IT, and one person being unavailable can stop work entirely.

Here is what actually matters at that size.

Identity comes first

Before backups, before monitoring, before anything: who can log into what.

Small companies accumulate accounts fast. A contractor gets access for a project. Someone leaves and their mailbox stays active because it might contain something useful. A shared login exists because setting up individual ones felt like extra work at the time.

Every one of those is a way in, and none of them require a sophisticated attacker.

The fix is unglamorous. Single sign-on where possible, multi-factor authentication everywhere, and a list of who has access to what that somebody actually reviews. This is the highest value work available at small scale and it is consistently skipped in favour of more visible things.

Backups you have restored

Not backups you have configured. Backups you have restored.

The failure mode that catches small companies is not the missing backup. It is the backup that has been running successfully for two years and turns out to be incomplete, or encrypted with a key nobody has, or missing the one system that was added later and never included.

Once a quarter, someone restores something and times it. That number is what your recovery actually looks like, and it is worth knowing before the day you need it.

Patching, on a schedule somebody owns

Most breaches at this scale exploit something that has had a patch available for months.

You do not need a sophisticated vulnerability management programme. You need someone whose job it is to apply updates on a known cadence, and a way to see what has not been updated. That is it.

If nobody owns this, it does not happen, and it will not be obvious that it is not happening. It is also the most obvious candidate for automation at small scale, because the work repeats constantly and involves almost no judgement.

What you probably do not need yet

This is the part that saves money.

A full security operations centre. Under fifty people, the value is low relative to cost. Get the basics right first.

Every compliance certification. Pursue the one a customer is actually asking for. Certifications you chase speculatively are expensive and rarely close deals on their own.

Redundancy for everything. Decide which systems genuinely cannot be down for a day, and make those resilient. For the rest, a clear recovery procedure is usually enough and costs a fraction as much.

24/7 coverage, sometimes. If your business does not run overnight, paying for overnight response may be buying peace of mind rather than risk reduction. Worth asking honestly.

The question to ask a provider

Ask what happens when your one technical contact is on holiday.

Small businesses tend to have a single relationship with a single person at their provider. That works right up until the week it does not. A serious provider will have an answer involving documentation and a second person who already knows your environment. A weaker one will say the word "escalation" and move on.

Where to start

If you are starting from nothing, the order that buys the most protection per pound spent is: identity and access, then a tested backup, then patching on a schedule. Everything else can wait until those three are genuinely solved.

That sequence is also roughly what our managed IT services work covers before anything more advanced gets discussed, and if the access review turns up something worrying, a proper security audit is the next step rather than buying more tools.

Back to all articles

Upgrade your business.

Ready to automate and scale? Tell us about your project and we'll get back to you within 24 hours.

We respond within 24 hours. No spam, ever.