Fair question, and one businesses are oddly shy of asking out loud: what exactly is the IT company doing for that monthly invoice? On quiet months, when nothing broke and nobody called, the fee can look like paying for nothing, and the suspicion is worth addressing head on, because the honest answer is either reassuring or damning depending on the provider: the quiet months are the product. Here is what a competent IT support company actually does with its days, including the majority of the work you are not supposed to notice.
The visible work: when your team calls
The part everyone knows: the help desk. Someone’s email will not send, the printer has opinions, a file has vanished, the new starter needs everything setting up. A ticket is raised (or a call answered), an engineer connects remotely, and most issues die within minutes; the stubborn minority get escalated to deeper specialists or an on-site visit. Our help desk service page covers how the triage and priorities work.
Two things distinguish good visible work: speed you can measure (contracted response times per priority, per the SLA disciplines) and pattern-hunting: the third ticket about the same thing should trigger a root-cause fix, not a third workaround. A help desk that only closes tickets is a symptom subscription.
The invisible work: where the fee actually goes
Most of a managed provider’s effort happens whether or not anyone calls, and it divides into five daily disciplines:
Monitoring
Software agents on every machine and server report continuously: disk health, failed services, stalled backups, suspicious sign-ins, expiring certificates. Engineers work the resulting alert queue every morning, fixing failures before opening time. A meaningful share of “the server was about to die” stories end undramatically at this stage, which is precisely the point.
Patching
Security updates for operating systems and applications, tested and rolled out on schedule across the whole estate, closing the holes attackers scan for daily. This unglamorous discipline defeats more real-world attacks than any product, which is why Cyber Essentials audits it with a 14-day stopwatch.
Security operations
Managing the protective stack: endpoint detection alerts triaged, phishing campaigns quarantined when a user reports one, MFA and access policies maintained, staff training campaigns run, and the M365 tenancy’s settings kept hardened rather than drifting.
Backup verification
Not “backups exist” but “backups ran last night, and this month’s test restore worked, in a known time”. The gap between those two sentences is where businesses die; the 3-2-1 discipline only means anything with someone checking daily.
Administration
The connective tissue: starters given accounts and kit on day one, leavers cut off the day they go, licences added and (properly) removed, vendors chased, documentation kept current so the business’s IT knowledge lives somewhere sturdier than one person’s memory.
The periodic work: projects and direction
Beyond the daily rhythm sit the chunks: projects (server migrations, office moves, cloud transitions, phone system replacements) scoped and priced separately from support, and strategy: the periodic review where someone looks a year ahead at your hardware ages, licence spend, security posture and growth plans, so purchases arrive as budget lines rather than emergencies. In larger arrangements this is a named vCIO function; at SME scale it is a proper quarterly or annual conversation with an agenda.
A representative Tuesday
To make it concrete, a lightly fictionalised day across a managed client base like ours: the morning alert queue includes a failing disk in a client’s server (part ordered, swap scheduled before it dies), two backup jobs that need nudging, and an impossible-travel sign-in that turns out to be a director on holiday (verified, not assumed). The help desk handles a few dozen tickets: passwords, a printer, a mailbox rule gone feral, a new starter build. One reported phishing email gets purged from every mailbox it reached. Patches roll to a third of the estate on schedule. A quarterly review meeting walks a client through their hardware-age report. Nobody’s business stopped; that was the deliverable.
How to tell whether yours is doing this
The question that began this page has a practical use: ask your provider for the evidence. A provider doing the invisible work can show it in minutes: monitoring dashboards, patch compliance reports, backup test logs, ticket trends. A provider met by silence or vagueness is selling the visible 20% and pocketing the rest, which is the break-fix incentive problem wearing a subscription. The 12 questions guide turns this into a full interrogation kit.
Frequently asked questions
What does an IT support company do day to day?
Help desk response for staff issues, plus the continuous background disciplines: monitoring and fixing alerts, patching, security operations, backup verification and user administration, with projects and strategic planning layered on periodically.
Why pay monthly if nothing goes wrong?
Because the fee buys the prevention that made nothing go wrong: monitored systems, closed vulnerabilities, verified backups and handled maintenance. Quiet months are the service working; the alternative model bills you generously for loud ones.
What’s the difference between IT support and managed IT services?
“IT support” loosely covers any help arrangement; “managed services” means the proactive monthly model described here, delivered by an MSP. Most modern SME arrangements are managed; the label matters less than whether the invisible work demonstrably happens.
Do IT companies work outside office hours?
Monitoring runs continuously everywhere; human out-of-hours response depends on your arrangement, from emergency-only to genuine 24/7 cover. Maintenance that would disrupt work (updates, migrations) deliberately happens outside your hours.
What should we expect to see as evidence of the work?
Regular reporting: tickets and trends, patch compliance, backup test results, security events handled, and a periodic review meeting in plain English. Ask for last month’s; the reaction is diagnostic.
How many people work on our account at an MSP?
Typically a pool: first-line engineers handling volume, senior specialists behind them, and account oversight, which is the depth a lone in-house person cannot offer. Ask how escalation works and who knows your environment; “the team” should have names.
See a month of the invisible work
The cleanest way to understand the job is to see it reported: our free IT health check produces exactly the artefacts described above for your current setup: what is monitored, patched, backed up and secured today, and what is silently not. Get in touch; if your current provider is doing the work, the audit will show that too, and that is worth knowing either way.