Posted on

How Do You Know When Your Managed IT Services Are Actually Working

Operations director and IT engineer reviewing a quarterly managed IT performance report

You know your managed IT services are working when the same problems stop coming back. Not when the ticket count drops, and not when nobody complains at the leadership meeting. A quiet month can mean your provider fixed the underlying cause of your outages, or it can mean your staff gave up on filing tickets and started working around the problem. Those two situations produce an identical report. We tell every operations director the same thing: ask your provider to show you recurring incident categories over the last four quarters, and watch whether the top three are shrinking. That single view separates a provider preventing failures from one quietly absorbing them.

The 5 Things That Tell You Where You Stand

  • Repeat incidents matter more than total tickets. A provider closing 400 tickets a month while the same printer, VPN, and mailbox issues repeat is managing symptoms, not causes.
  • Silence is not a metric. Low ticket volume can signal prevention or workaround fatigue, and only root-cause data tells you which one you bought.
  • Response time and resolution time are different promises. Many contracts guarantee the first, report on the first, and stay quiet about the second.
  • Security work is invisible unless someone reports it. Patch completion rates, blocked intrusion attempts, and failed backup restores belong in your monthly review.
  • The review meeting is the product. If your provider cannot walk you through trends, risks, and what they plan to fix next quarter, you are buying reactive labor rather than managed IT.

This article is written for operations directors, controllers, and CIOs at firms between roughly 10 and 500 staff, the people who sign the managed services invoice and get asked whether it is worth renewing. Most of the ranking advice on this topic is written for providers tracking their own margins. This one is written from your side of the table.

Why Ticket Counts Fail as a Measure of Managed IT Services Performance

Ticket volume is the most reported and least useful number in managed services, because it moves for reasons that have nothing to do with the health of your environment. We have watched a client celebrate a 30 percent drop in tickets that turned out to be three departments routing problems through a colleague who was good with computers. The environment was worse. The report looked better.

The incentive problem sits underneath this. A provider paid a flat monthly fee has a reason to want fewer tickets, and there are two ways to get there. One is engineering: find why the wireless drops at 2pm, fix the controller firmware, and the tickets stop. The other is friction: slow first response, confusing intake, an engineer who makes people feel foolish for asking. Both paths produce the same downward line on a graph.

What a healthy ticket trend actually looks like

A healthy trend shows total volume flat or gently declining while the composition shifts. Early in a relationship you should see a spike, because a competent provider inherits years of deferred work and surfaces it. Around month four the profile changes: fewer outages and access failures, more project and onboarding requests. That shift is the real signal. If the mix looks the same in month twelve as it did in month two, nothing structural has been repaired. We cover the operational side of this pattern in our breakdown of how managed IT services cut costly outages.

The opposing read deserves airtime. Some environments genuinely stabilize and stay quiet, particularly small firms on standardized hardware with little change. A flat, low, boring ticket line can be exactly right there. The difference is that a good provider can tell you why it is quiet, naming the changes that produced the calm. A provider who shrugs and points at the graph is guessing alongside you.

Why your staff stop reporting problems

People stop filing tickets when filing them costs more than the workaround. A finance clerk who waits 40 minutes for a password reset learns to keep a second browser signed in. That habit removes a ticket and adds a security exposure nobody logged. We ask clients to run a short internal poll twice a year with one question: when something breaks, do you file a ticket or work around it? The answers tend to reframe the entire performance conversation.

The counter-argument is fair. Not every workaround signals failure, and mature users often self-serve minor issues by design, which is a good outcome when the provider published the guidance. The distinction is whether the workaround is documented and sanctioned or invented in private. Sanctioned self-service reduces tickets and reduces risk. Private workarounds reduce tickets and raise it.

Where root-cause reporting belongs in your contract

Root-cause analysis should be contractual for any incident that recurs three times in a quarter or causes more than an hour of downtime. Ask for the finding in writing, with the corrective action and a date. Providers who do this well keep a running problem register you can read at any time.

Some providers push back that formal root-cause work is heavy for smaller environments, and there is truth in that. A five-person firm does not need an eight-page report on a failed switch. The workable middle is a one-paragraph entry naming the cause, the fix, and whether it is closed. What you should refuse is a verbal assurance that it was “just a glitch” repeated across three quarters.

The Metrics That Tell You If Managed IT Services Are Working

The metrics worth reviewing are the ones that describe outcomes in your business rather than activity in your provider’s queue. Four categories cover almost everything an operations director needs, and every one of them should arrive without you asking.

Availability against the promise you actually bought

Most agreements quote uptime near 99.9 percent, which allows roughly 43 minutes of downtime a month. The number is meaningless until you know what it covers. Uptime on the provider’s monitoring platform is not uptime of your line-of-business application, and a client whose ERP was unusable for a morning does not care that the server responded to pings throughout. Ask which systems the guarantee covers, how downtime gets measured, and what happens when the target is missed. Firms running regulated or clinical workloads should read our practical guide for professional services environments alongside their agreement.

The other side of this argument matters. Chasing a higher availability figure has real cost, and for many firms the money buys less than a proper recovery plan would. We would rather see a client at 99.5 percent with a tested four-hour restore than at 99.99 percent with backups nobody has ever restored.

Response time, resolution time, and the gap between them

Response time measures how fast someone acknowledges you. Resolution time measures how fast the problem goes away. Contracts commonly guarantee the first because it is easy to control, and an automated reply can satisfy it. Insist on both, reported by priority tier, with the median and the worst case. Medians hide the outliers that damage a business, and the ticket that sat open for nine days is the one your staff remember.

There is a legitimate defense of loose resolution targets: some fixes depend on a vendor, a part, or a maintenance window the provider does not control. That is why the report should separate time spent waiting on a third party from time in the provider’s queue. A provider willing to publish that split is confident in their own numbers.

Security and recovery work you would otherwise never see

Patch completion rates, endpoint coverage gaps, blocked intrusion attempts, and backup restore tests are the work you are least able to observe and most exposed by. A restore test is the one that gets skipped. We ask for a quarterly test that recovers a real file to a real machine, with a timestamp, because an untested backup is a plan rather than a protection. Firms with heavier exposure often pair their agreement with dedicated managed security services rather than expecting a general IT contract to carry it.

Cost per outcome instead of cost per ticket

Cost per ticket is a provider-side profitability figure that reveals almost nothing about your value. A more honest view divides your annual managed IT spend by hours of business downtime avoided, or tracks spend against staff productivity hours lost. Neither is precise, and both are more truthful than a metric designed to measure someone else’s margin. Firms comparing models will find the arithmetic laid out in our guide to choosing a managed IT services provider.

How to Run a Review That Gets You Real Answers

A quarterly business review is where a managed services relationship is either proven or exposed. The agenda should be yours, not a slide deck of green checkmarks. Send three questions a week ahead and read the answers before the meeting.

The three questions worth asking every quarter

Ask what broke most often this quarter and what was done about the cause. Ask what the provider believes is the largest unaddressed risk in your environment right now. Ask what they would fix first if you gave them budget for one project. A provider who knows your environment answers all three without notes. A provider treating you as a queue will answer the first, hedge on the second, and propose a hardware refresh for the third.

The opposing view is that this puts a provider on the spot in a way that invites sales pitches, and that risk is real. You reduce it by asking for the risk answer in writing beforehand, which separates considered judgment from improvisation.

Reading the report your provider already sends

Most providers already send a monthly report nobody opens. Open it and look for three things: whether the same asset names appear month after month, whether any metric has changed definition without explanation, and whether anything is reported as a range rather than a number. Definition drift is the quiet one. When “resolved” silently becomes “first responded,” every trend line improves without any work happening.

When co-managed makes more sense than replacing your provider

Not every underperforming relationship needs to end. Firms with internal staff often get better results by shifting scope rather than switching vendors, keeping the provider for after-hours coverage and monitoring while internal people own the applications they know. Our co-managed IT services work exists for that arrangement, and regional teams evaluating coverage can compare local delivery through our managed IT services in Kansas practice.

The case against splitting scope is that shared responsibility creates finger-pointing when something fails at the boundary. That risk is real and it is managed with a written responsibility matrix naming an owner for every system. Without that document, co-managed becomes nobody-managed.

What to do when the numbers look fine and your staff disagree

Trust the staff. When reporting shows healthy trends and the people doing the work describe daily friction, the reporting is measuring the wrong thing, and we have never once found the reverse to be true. The gap usually sits in scope: the provider is measuring the systems they were contracted to watch, while the pain lives in an application, a shared mailbox, or a scanner that nobody put on the list. A monthly report can be accurate and irrelevant at the same time.

The practical move is an asset and application inventory reconciled against the agreement, line by line, once a year. Ask which systems generate alerts, which are patched on a schedule, and which are covered only when somebody reports a fault. Most firms find two or three business-critical systems sitting in that third category, watched by nobody, and that discovery explains the disagreement more often than any dispute about service quality does.

There is a counter-position worth respecting: expanding monitoring scope raises cost, and some low-value systems genuinely belong in break-fix. The decision should be yours and it should be written down. What causes damage is not a system left out of scope, it is a system everyone assumed was in it.

Frequently Asked Questions

How long before new managed IT services show results?

Expect four to six months before trends mean anything. The first sixty days usually show more tickets, not fewer, because a competent provider surfaces deferred problems the previous arrangement absorbed. Sustained improvement in repeat incidents is the milestone worth watching for.

What is a reasonable uptime guarantee for a small business?

Most SMB agreements land between 99.5 and 99.9 percent, and the figure matters less than its scope. Confirm which systems are covered, how downtime is measured, and what remedy applies when the target is missed.

Should I expect root-cause analysis on every incident?

No. Reserve formal root-cause work for incidents that recur three times in a quarter or cause more than an hour of downtime. A short written entry naming cause, fix, and status is enough for smaller issues.

Is a low ticket count a good sign?

On its own, no. Low volume can mean prevention worked or that staff stopped reporting problems. Read it alongside repeat-incident categories and an internal check on whether people file tickets or work around issues.

What are the warning signs a provider is underperforming?

Repeat incidents that never close, reports whose definitions change without notice, resolution times quoted only as averages, and a review meeting where nobody can name your biggest current risk. We walk through more of these patterns in our piece on signs your managed IT support is failing.

Who Is Behind This Advice

Mindcore has spent years running managed IT for firms between 10 and 500 staff across healthcare, professional services, manufacturing, and finance, and the evaluation framework here comes out of quarterly reviews we have sat in on both sides of. We have inherited environments where the outgoing provider reported excellent numbers against a definition of “resolved” that meant an engineer had replied. That experience shaped how we report: repeat incidents first, root causes named, restore tests timestamped.

Matt Rosenthal, our chief executive, focuses on building service delivery where the client can verify the work rather than take it on faith, which is why our managed IT services reporting leads with the problems still open rather than the tickets already closed.

Get a Second Read on Your Current Provider

You do not need to change providers to find out whether the one you have is working. Pull the last four quarters of reporting, list the incident categories that appear in three or more of them, and ask what was done about the cause of each. If that list is short and shrinking, your money is doing its job. If the same names keep surfacing, you are paying a retainer to have failures absorbed rather than removed, and the cost of that shows up in staff hours nobody is counting. The firms that get this right treat the quarterly review as an audit they run, not a presentation they receive.

If you want an outside read on what your reports are telling you, book a free strategy call and we will walk your last year of data with you, no switch required: schedule a free strategy call.

Related Posts

Matt Rosenthal