Skip to content

Resource

Flat-rate IT support vs. standards-led IT. They're not the same thing.

The pricing model tells you how you'll be billed. The operating model tells you what actually happens to your environment. Knowing the difference is what determines whether anything changes.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting ·

The models, explained plainly.

Time and materials.

You pay for the time a technician spends on your environment, plus any parts or software. You call when something breaks. They fix it. You get an invoice. Predictable per incident, unpredictable over time. A major incident generates a major bill at the worst possible moment.

Block hours.

A variation on time and materials where you purchase technician time in advance at a discounted rate. When the block runs out, you buy another. The rate is better. The operating model is the same. The provider is still responding to what gets reported. A stable environment is a block that doesn't get used. An unstable one keeps it depleted.

Flat-rate managed IT.

A fixed monthly fee covers a defined scope of services regardless of how many issues arise. The fee doesn't change because a month was busy or quiet. This is where the incentive structure changes. The provider's cost goes up when the environment is unstable and down when it's running well. That alignment is why flat-rate providers have a reason to prevent problems that time and materials providers don't.

Comparing managed IT pricing and delivery models

Why the model matters. And why monthly exists.

IT and security are not static. The environment the business ran on last year is not the environment it's running on today. New staff joined. People left. New applications were adopted. Microsoft pushed updates that changed default settings. Threat actors developed techniques that last year's controls weren't designed to address.

A monthly operating model exists because maintaining a secure, stable environment is ongoing work, not a one-time project. Patches need to be applied on a schedule. Access needs to be reviewed when people leave. Backups need to be tested regularly. Cyber insurance requirements change at renewal. Client security questionnaires ask new questions every year.

A time and materials or block-hour arrangement handles what gets reported. It doesn't handle what's accumulating between reports. An environment managed reactively is falling behind a moving target every month nobody is looking at it.

What flat-rate without standards actually produces.

Flat rate is a pricing model. Standards-led is an operating model. They're different things and conflating them is where buyers get confused.

A flat-rate provider who responds to tickets quickly and keeps things running is better than break-fix. But if the underlying conditions that produce problems aren't being addressed, if nobody is managing the environment against a baseline, reviewing access, testing backups, or maintaining security settings, the environment still accumulates gaps. The billing is more predictable. The outcome isn't necessarily better.

Flat-rate managed IT without a documented standard behind it is reactive support with a monthly invoice instead of an hourly one. The pricing changed. The operating approach didn't.

What standards-led IT actually adds.

A standards-led provider manages the environment against a documented baseline. Every area, identity, endpoints, email, backup, network, Microsoft 365, vendors, is set to a defined standard and reviewed on a schedule. When something falls out of standard it gets corrected. Not closed at the ticket. The underlying condition gets addressed.

The baseline comes from somewhere specific. CIS Controls, the framework we align to, defines the security and operational practices that reduce risk in business environments. The controls aren't invented by the provider. They come from a recognized standard developed by people who have studied what actually prevents incidents. When a provider says they manage to a standard, that standard should have a name, a source, and documentation that can be shown.

This matters beyond security. A business managed to CIS Controls is better positioned for cyber insurance renewals and client security questionnaires because the controls carriers and clients are asking about are the same controls the standard requires. Standards-led IT and insurance readiness are the same conversation.

How to tell which model you're actually in.

Most businesses don't know. The contract says managed IT. The reality may be different.

Can your provider tell you what standard they manage the environment to. And show you the documentation? A standards-led provider has a specific answer. One who doesn't manage to a standard will describe their process in general terms.

What changed in your environment last month? A provider managing to a standard can tell you specifically. Patches applied, access reviewed, backup tests run. A reactive provider can tell you how many tickets were closed.

When was the last backup restore actually tested. Not monitored, tested? A provider managing to a standard has a documented answer with a date.

When the same problem comes back, what happens? A standards-led provider investigates the underlying condition. A reactive provider closes the new ticket.

What changes when the model is right.

The environment gets quieter. Not because problems are suppressed but because the conditions that produce them get addressed. The same tickets stop cycling. Backups get tested rather than assumed. Access gets reviewed when people leave. Security settings get maintained rather than accumulated.

Leadership can describe the environment, what's in place, what it covers, what the plan is when something goes wrong, because someone is accountable for knowing.

The cyber insurance renewal is a documentation exercise instead of a scramble. Client security questionnaires have answers instead of approximations.

If you're not sure which model you're actually in, that's exactly what an IT Environment Review is for.

Schedule an IT Environment Review

Common questions

Questions leadership usually asks first.

What is the difference between break-fix and managed IT?
Break-fix is transactional. Something breaks, you call, they fix it, they invoice. The provider has no incentive to prevent problems and no accountability for the environment between calls. Managed IT is a flat-fee model where the provider is accountable for the environment on an ongoing basis. The incentive structure changes. A provider paid a fixed monthly fee has a reason to prevent problems because fewer issues means lower cost to deliver. Break-fix environments tend to accumulate problems. Managed environments tend to get more stable.
Is flat-rate managed IT the same as standards-led IT?
No. Flat rate is the pricing model. Standards-led is the operating model. A flat-rate provider who closes tickets quickly but doesn't manage the environment against a standard is reactive support with a predictable bill. The pricing changed. The approach didn't. Standards-led IT requires both the pricing model and a documented baseline behind it.
How do I know if my current provider is managing to a standard?
Ask them what standard they manage to and ask to see the documentation. A provider who manages to CIS Controls or another recognized framework can name it and show you how the environment gets measured against it. Ask what changed last month. Ask when the last backup restore was tested. Ask for a current configuration report. If those answers don't exist or take time to produce, the environment isn't being held to a standard.
Why does the operating model matter more than the price?
Because price tells you what you'll pay. The operating model tells you what you'll get. Two providers charging the same monthly fee can produce completely different outcomes depending on whether they're managing the environment to a standard or just responding to what gets reported. A lower fee from a reactive provider may cost more over time in incidents, security gaps, and the accumulated cost of problems that never fully get resolved. See how managed IT pricing actually works for what drives the number itself.
What is an IT Environment Review?
The IT Environment Review is free and takes about 30 minutes by video or phone. We ask a set list of questions about your environment, answer yours, and send you a written summary afterward.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.