A managed IT service provider (MSP) takes contractual ownership of the systems your business runs on — monitoring, service desk, patching, endpoint security, backup, cloud administration and network management — for a fixed recurring fee against an SLA. This guide explains what an MSP does day to day, how managed support differs from break-fix and co-managed models, and when a South African business is better served by keeping the work in-house.
Key takeaways
- An MSP is defined by outcome ownership, not by activity: you buy monitored systems, resolved tickets within agreed times, tested backups and maintained security controls, rather than hours of effort.
- Break-fix pays a supplier more when your systems fail; a managed retainer pays the same whether or not they do, which is the entire commercial argument for the model.
- Co-managed support keeps your internal IT person and buys the layers they cannot cover alone — after-hours, security monitoring, escalation and project delivery.
- Under POPIA, an MSP administering your mailboxes, file shares or CRM is an operator, and section 21 requires a written agreement covering security safeguards.
- Most South African businesses reach the limits of ad-hoc support between 25 and 50 employees, when leave, after-hours incidents and security can no longer be absorbed by one person.
The short version
A managed IT service provider monitors your systems around the clock, runs the service desk, applies patches, administers endpoint security and backups, manages your cloud tenant and network, and reports performance against an SLA. In South Africa it also carries POPIA operator obligations and, in practice, responsibility for power and connectivity resilience. The alternative models are break-fix, which is reactive, and co-managed, which supplements an internal team.
What an MSP does day to day
Monitoring and alerting
Agents on endpoints, servers and network devices raise alerts on disk pressure, failed services, offline devices, backup failures and security events. The value is not the tooling — it is that somebody is contractually obliged to act on the alert. Ask any prospective provider who watches alerts at 02:00 and what happens next.
Service desk
A single route for users to log issues, with severity triage, defined response and resolution targets, and an escalation path to senior engineers. A functioning service desk is measured by first-time resolution rate and by ticket ageing, not by how friendly the first reply is.
Patching and configuration management
Operating system and third-party patching scheduled, applied and evidenced. Evidence matters: insurers and enterprise clients increasingly ask for patch compliance reporting, and "we patch regularly" does not survive an audit question.
Endpoint security and identity
Endpoint protection deployment and alert triage, multi-factor authentication enforcement, conditional access policy, privileged account control and joiner-mover-leaver processes. Identity is where most breaches now begin, so account lifecycle discipline outperforms most tooling spend.
Backup and recovery
Backups configured, monitored and — critically — restored on a test schedule. A backup that has never been restored is an assumption. Ask for the date of the last successful test restore and the documented recovery time objective.
Cloud and Microsoft 365 administration
Tenant administration, licence assignment, mailbox and SharePoint management, retention configuration and security baseline maintenance across Microsoft 365 or equivalent platforms.
Network, connectivity and resilience
Firewall, switch, Wi-Fi and router management, plus the South African specifics: UPS runtime for network equipment, LTE or secondary-fibre failover, and documented behaviour during load-shedding.
Reporting and governance
Monthly or quarterly reporting on SLA performance, ticket trends, patch compliance, backup success and security posture, feeding an IT roadmap and budget rather than sitting in an inbox.
Break-fix vs managed vs co-managed
| Dimension | Break-fix | Fully managed | Co-managed |
|---|---|---|---|
| Commercial model | Hourly or per incident | Fixed monthly retainer | Fixed retainer for defined layers |
| Incentive | Supplier earns more when systems fail | Supplier earns more when systems stay up | Shared with internal team |
| Monitoring | None or minimal | Continuous, alert-driven | Usually provider-run |
| Best for | Micro businesses, low IT dependency | SMEs with no internal IT | Businesses with one or more internal IT staff |
| Main risk | Unpredictable spend, reactive posture | Paying for scope you do not use | Unclear boundaries between teams |
Co-managed deserves more attention than it gets. It solves the bus-factor problem that comes with a single internal IT employee, keeps institutional knowledge in the business, and costs less than a fully managed contract. Its one failure mode is ambiguity, so the responsibility split must be written down per service, not agreed verbally.
What an MSP does not do
- Replace business decision-making about technology investment — that is a leadership function, covered by CIO-as-a-Service and fractional IT leadership.
- Absorb responsibility for POPIA compliance. You remain the responsible party; the MSP is the operator.
- Develop your line-of-business software, unless engaged separately for it.
- Fix a broken process. Automated monitoring on a badly designed environment produces faster alerts about the same problems.
POPIA and the operator relationship
The moment an MSP administers systems containing personal information, it becomes an operator under the Protection of Personal Information Act. Section 21 requires a written agreement obliging it to maintain appropriate, reasonable technical and organisational security measures and to process data only on your instruction. Your side of the arrangement is a documented breach-notification path to the Information Regulator with defined timeframes. Treat any provider that has never raised operator status as an indicator of governance maturity.
When in-house still wins
Keep it internal when IT is the product, when regulatory or client conditions require staff on payroll, or when your systems are so specialised that generalist support adds latency rather than capability. Even then, most organisations buy something — after-hours cover, security monitoring, escalation — rather than nothing. The realistic question is rarely in-house or outsourced; it is which layers belong where.
How BroadVision helps
BroadVision delivers fully managed and co-managed IT to South African businesses, with SLA-backed Managed IT Services covering service desk, monitoring, security, backup and network operations. Cloud tenant and licensing work sits in Cloud & Software Services, site connectivity and resilience in Connectivity & Infrastructure, and the roadmap and governance layer in Strategic IT Services. For market pricing context, see our guide to managed IT services in South Africa; UK-facing operators should read the UK managed service providers edition.
FAQ
What does a managed IT service provider actually do?
An MSP monitors your systems continuously, runs the service desk, applies and evidences patching, administers endpoint security and identity, manages backups and test restores, administers your Microsoft 365 or cloud tenant, manages the network, and reports performance against an SLA. In South Africa it also typically owns power and connectivity resilience design. The defining feature is contractual ownership of outcomes rather than a supply of hours. BroadVision delivers this scope under Managed IT Services.
What is the difference between break-fix and managed IT support?
Break-fix bills you per incident or per hour, so the supplier earns more when systems fail; a managed retainer is a fixed monthly fee, so the supplier earns more when systems stay up. Break-fix carries no monitoring, no patch cadence and no SLA, which makes spend unpredictable and posture reactive. It remains defensible for micro businesses with low IT dependency. BroadVision uses fixed-fee managed and co-managed models rather than break-fix — see Managed IT Services.
What is co-managed IT support?
Co-managed IT keeps your internal IT staff and buys the layers they cannot cover alone: after-hours support, security monitoring, specialist escalation, cloud administration and project delivery. It costs less than a fully managed contract because first-line support stays in-house, and it removes the single-point-of-failure risk of one internal IT person carrying leave, after-hours incidents and specialist depth. The responsibility split must be documented per service. BroadVision runs co-managed engagements under Managed IT Services.
When should a South African business hire an MSP?
Most businesses reach the limit of ad-hoc support between 25 and 50 employees, when a single person can no longer cover leave, after-hours incidents, patching and security without something slipping. Other triggers are independent of headcount: a client or insurer asking for security evidence, a POPIA obligation you cannot demonstrate, a failed backup discovered during an incident, or a cloud migration nobody internally has run before. BroadVision starts with a scoped assessment rather than an immediate handover — see Strategic IT Services.
Is an MSP responsible for POPIA compliance?
No — you remain the responsible party, and the MSP is an operator processing personal information on your behalf. Section 21 of the Protection of Personal Information Act requires a written agreement obliging the operator to maintain appropriate security safeguards and to process data only on your instruction, with a defined breach-notification path to the Information Regulator. A provider that has never raised operator status is telling you something about its governance maturity. BroadVision signs a POPIA operator agreement as standard under Managed IT Services.
Does an MSP replace an IT manager?
No — an MSP replaces IT operations, not IT leadership. Vendor strategy, budget ownership, prioritisation, risk appetite and board-level reporting are decision-making functions that stay with the business, whether held by an internal IT manager or bought as fractional leadership. Businesses that outsource operations without owning direction end up with well-run systems that do not serve a strategy. BroadVision provides the leadership layer through Strategic IT Services.
