Operational Heartbeat

Is the Traditional IT Support Model Starting to Change?

IT Club Editorial8 minutes read15 September 2026
WhatsAppEmail
Is the Traditional IT Support Model Starting to Change?

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

A calm look at how managed IT is evolving, what Secure-by-Design, Defence in Depth and Zero Trust mean in plain English, and which support model may suit a growing SME.

For many years, outsourced IT had a familiar shape. A business paid a Managed Service Provider, or MSP, a monthly fee to keep systems running, support users, patch devices, manage backups and deal with problems when they appeared.

That model is not obsolete, and it should not be attacked. Many small and medium-sized businesses genuinely need a fully managed IT service. They want one team to understand their users, devices, applications and priorities, and they do not want to build an internal IT department before the business is ready.

But the responsibilities around business technology are expanding. Cloud applications, remote working, identity-based access, supplier platforms and AI tools have made the old question — “Do we have an IT company?” — less useful on its own.

The practical change

SUPPORT → SECURITY → ASSURANCE → SPECIALIST EXPERTISE

What prompted this question?

A recent announcement from Virtual IT Group (VITG) describes a Modern Managed Services proposition that combines everyday managed IT with ongoing security controls, Microsoft 365 security posture management, endpoint vulnerability remediation, application allowlisting, backup, security and compliance reviews, and optional Managed Detection and Response.

The announcement is a useful news hook, not a reason to copy a provider's marketing language. The wider point is more relevant to business owners: some IT services are moving from “we fix it when you report it” towards “we maintain, validate and explain the controls that keep the business operating safely”.

VITG: Modern Managed Services

The old model still has a place

A good managed IT provider can be exactly what an SME needs. It may supply a help desk, device management, Microsoft 365 administration, patching, backup operations, procurement and project support. A single accountable team can be simpler than coordinating several specialist suppliers.

The problem is not the existence of the MSP model. It is the assumption that a monthly support contract automatically covers every security and assurance responsibility. “Managed” needs to be followed by a clear description of what is managed, how often it is checked, who responds to exceptions and what evidence the customer receives.

What has expanded?

A modern SME may need to think about identity and access, Microsoft 365 security configuration, endpoint and email protection, backup and recovery, vulnerability management, Cyber Essentials or other customer requirements, AI governance, supplier and SaaS risk, and evidence that controls are actually working.

These are connected, but they are not the same job. A help desk ticket being answered quickly does not prove that an old administrator account has been removed. A backup job reporting success does not prove that a restore has been tested. A security product being installed does not prove that its alerts are being monitored.

Microsoft 365 Admin Health Check: 15 Things Every Business Should Review

Three principles in plain English

Secure-by-Design

Secure-by-Design means security is considered when a service, device, process or change is designed, rather than added after something goes wrong. For an SME, that might mean setting up a new user with appropriate access from the beginning, choosing a supplier with sensible controls, or making secure configuration part of a device's normal setup.

Defence in Depth

Defence in Depth means using several independent layers so one mistake or failure does not expose everything. Strong identity controls, protected endpoints, email filtering, tested backups, network controls, staff awareness and an incident response plan can support one another. No single product is expected to do every job.

Zero Trust

Zero Trust does not mean “trust nobody” and it does not mean buying a particular platform. It means not automatically trusting a user, device or connection simply because it is inside the network. Access is checked using identity, device, context and need. A request for sensitive data from an unfamiliar or unhealthy device should receive more scrutiny than a routine request from a known, protected device.

Zero Trust for Small Businesses: What It Actually Means

Five models a business might use

  1. 1Fully outsourced managed IT: an external team provides the main day-to-day technology function.
  2. 2Internal IT with specialist support: employees own the environment while an external provider supplies expertise in areas such as security or backup assurance.
  3. 3Co-managed IT: the internal team and provider share responsibilities under an agreed operating model.
  4. 4Modular specialist services: the business adds focused help around Microsoft 365, cybersecurity, compliance, backup or projects.
  5. 5Ad-hoc expert help: the business buys defined expertise when it needs it rather than an all-inclusive support contract.

None is automatically the modern answer. A regulated organisation with internal staff may need specialist assurance. A small business without technical employees may need a fully outsourced service. A growing company may start with managed IT and add security monitoring or project expertise as its risks change.

What should a business owner ask their IT provider?

  • What security controls are actually included in our monthly service?
  • Who is responsible for Microsoft 365 security configuration and ongoing review?
  • Are our identities, endpoints and email independently monitored?
  • How do you demonstrate that our backups work and that recovery is possible?
  • How quickly are vulnerabilities and unsupported software dealt with?
  • Does our service include security assurance, or mainly technical support?
  • How would your approach change if we introduced AI tools?
  • Could specialist services be added without replacing our existing IT arrangements?
  • What are we paying for that we actually use?

The answers should be specific enough to identify an owner, a process and evidence. “It is covered” is less useful than “this control is checked monthly, exceptions are assigned to this team and the result appears in your quarterly review”.

What Your IT Provider Should Monitor

Are You Paying Twice for IT Security?

The IT Club view

The useful question is not whether MSPs are dead. They are not. It is whether the service a business bought still matches the business it has become. A company using Microsoft 365, cloud accounting, remote access, external suppliers and AI tools may need a different balance of support, security and assurance than it needed when its main concern was keeping an office server online.

Business owners should increasingly think less about “Do we have an IT company?” and more about: “Do we have the right combination of support, security, assurance and expertise for the business we are becoming?”

How to Build a Practical AI Governance Approach

Found this useful? Forward it to another business owner.

Still deciding what your business needs?

If you are reviewing an IT arrangement and are unsure which responsibilities belong with your provider, internal team or a specialist, send the question to Ask IT Club with the service scope and the gaps you have already identified.

Ask the Advisor

Source and further reading

This is independent IT Club commentary prompted by VITG's Modern Managed Services announcement, checked on 15 September 2026. The article does not endorse a particular provider or imply that every SME needs every service described.

VITG: Modern Managed Services

Plain-English Takeaway

The important change is not that traditional MSPs are finished. It is that one IT delivery model may no longer suit every organisation. Businesses should choose the right combination of support, security, assurance and expertise for the business they are becoming.

Frequently asked questions

Are traditional managed service providers becoming obsolete?

No. Many businesses still benefit from a fully managed IT service that supports users, devices, applications and infrastructure. The change is that some organisations now need additional security monitoring, assurance or specialist expertise rather than assuming one all-inclusive model fits every need.

What does Zero Trust mean for a small business?

Zero Trust means not automatically trusting a user, device or connection simply because it is inside the network. Access should be checked using identity, device health, context and business need. It is a security principle, not a requirement to buy one particular product.

What is the difference between managed IT support and managed security?

Managed IT support keeps users and systems working. Managed security focuses on reducing and detecting risk through controls such as identity protection, endpoint and email security, vulnerability remediation, monitoring and response. The same provider may offer both, but the responsibilities should still be clear.

Can an internal IT team use modern managed services?

Yes. Specialist services can support an internal team with areas such as Microsoft 365 security, vulnerability management, backup assurance, monitoring or incident response. A co-managed or modular arrangement may provide useful capacity without replacing the people who understand the organisation.

What should I ask my IT provider about modern managed services?

Ask what security controls are included, who owns Microsoft 365 configuration, how identities and endpoints are monitored, how backups are tested, how vulnerabilities are handled, what evidence is supplied, how AI tools would be governed and whether specialist services can be added without replacing the existing arrangement.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor