Break-fix IT support means calling a technician when something goes wrong and paying for the time it takes to fix, usually by the hour. Managed IT services mean paying a provider a fixed monthly fee to look after your technology continuously: a help desk for staff, monitoring and updates, security, backups and planning.
Break-fix can suit a very small office with simple, stable technology. Once a business relies on its systems every day, holds sensitive data or is growing, a managed or hybrid arrangement is usually the better fit, because someone is responsible for preventing problems, not just repairing them. This guide defines the terms, compares how each model is priced and lists the questions to ask any provider before you sign.
Plain definitions: IT support, help desks and MSPs
What is an IT support service?
IT support is help for the people using your technology: fixing a slow laptop, resetting a password, getting email or a printer working, or setting up a new employee. You can buy it per incident, in prepaid blocks of hours or as part of a managed plan.
What is the IT help desk?
The help desk is the front door to IT support: the phone number, email address or portal where staff report problems and ask for help. Each request becomes a ticket that’s prioritized, tracked and closed when it’s resolved, which also shows which problems keep coming back. In larger organizations it’s often called the service desk.
Who is a managed service provider?
The Canadian Centre for Cyber Security describes a managed service provider (MSP) as “a company that remotely manages IT infrastructure and user end systems on behalf of a client.” Citing the MSP Alliance, it lists typical traits: a help desk and network operations service, remote monitoring and management, proactive maintenance and a predictable billing model.
A 2022 joint advisory from cyber security agencies in Canada, the U.S., the U.K., Australia and New Zealand describes MSPs as organizations that deliver, operate or manage IT services for customers under a contract, such as a service level agreement.
What’s the difference between IT services and managed services?
“IT services” is the broad category: consulting, projects, repairs and support. Managed services are the part delivered as an ongoing responsibility under a contract, usually for a fixed monthly fee. Moving your email to Microsoft 365 is an IT project; looking after that environment every month afterwards is a managed service.
How each model is priced, and the incentives it creates
Break-fix
Break-fix is billed for time and materials. On Canadian provider websites we checked in September 2026, published rates included $75 an hour on site with a two-hour minimum, $90 an hour on demand, and $95 an hour during business hours at a provider whose emergency rate is $143, about 50% higher. Travel, parts and after-hours work can add to the bill.
The incentives are awkward. The provider earns more when more goes wrong, and you save money by not calling. That can push updates, security work and small fixes down the list until they turn into bigger problems.
Managed services
Managed IT is usually a fixed fee per user or per device each month. As of September 2026, published Canadian rates ran from about $85 to $275 or more per user per month; our guide to managed IT services costs explains what moves the number.
A flat fee rewards the provider for preventing problems, because every ticket costs it time. The risk runs the other way: a provider can protect its margin with a narrow scope, by billing routine work as projects or by responding slowly. A clear written scope, with response targets, keeps the model working for you.
Pros and cons at a glance
| Factor | Break-fix | Managed IT |
|---|---|---|
| Cost | Low in quiet months, unpredictable when things break | Predictable monthly fee, with projects and licences extra |
| Commitment | None; pay as you go | Monthly fee, often with an onboarding fee and a contract term |
| Prevention | Only if you ask and pay for it | Monitoring, patching and backup checks are part of the service |
| Security | Your responsibility unless you arrange otherwise | Tools and responsibilities set out in the agreement |
| Response | Usually no guaranteed response time | Response targets written into the agreement |
| Knowledge of your systems | Depends on who takes the call | Usually documented as part of the service |
| Planning | Rarely included | Often includes regular reviews and budgeting |
| Best fit | Very small, stable setups | Businesses that rely on IT every day |
When break-fix makes sense
Break-fix is a reasonable choice when most of these are true:
- You have a handful of staff, your main tools are cloud services such as Microsoft 365, and there’s no server in the office.
- Your setup rarely changes: few new hires, moves or new systems.
- Someone on your team makes sure updates install, multi-factor authentication (MFA) is on for every account and backups run.
- A day or two of downtime would be inconvenient rather than a crisis.
- No client, insurer or regulator is asking you to describe your security controls.
If you go this way, set it up before you need it. Agree on rates, minimum charges and after-hours pricing with a provider in advance. Keep admin passwords and account details somewhere the business controls, not with one person, and test a restore from backup regularly. Our small business cybersecurity checklist covers the basics you’ll be responsible for.
Hybrid options: block hours and co-managed IT
Block hours
With block hours, you prepay a set number of hours, sometimes at a lower rate than ad hoc support, and draw them down as needed. One Metro Vancouver provider, for example, offers discounted block-hour packages alongside its $90 hourly rate. Ask whether unused hours expire, what the minimum billing increment is and whether after-hours work uses hours faster.
Block hours lower the cost of support, but on their own they don’t add monitoring or prevention. Some providers sell monitoring, patching or backup as separate services to fill that gap.
Co-managed IT
Co-managed IT pairs an internal IT person or team with an MSP. Your staff handle day-to-day requests and know the business; the provider can add monitoring and security tools, after-hours coverage, specialist skills and cover during vacations. One national provider publishes co-managed plans from $160 per user per month, against $180 for its fully managed service (CAD, as of September 2026).
The internal salary stays in the budget. Job Bank’s median wage for user support technicians in B.C.’s Lower Mainland–Southwest region is $32.93 an hour (2023–2024 data), or about $68,500 a year at 40 hours a week, before benefits and payroll costs. Co-managed works best when the agreement says exactly who does what, down to who patches servers and who answers an alert at 2 a.m.
Signs you’ve outgrown break-fix
- IT invoices swing widely from month to month.
- The same problems keep coming back after each fix.
- No one can say when a backup was last restored successfully.
- Admin passwords and account details live with one employee or your last technician.
- Some computers still run Windows 10. Microsoft ended support on October 14, 2025, and Extended Security Updates for organizations cost US$61 per device for the first year, doubling each year for up to three years.
- You’re hiring, opening another location or supporting staff who work from home.
- A client, insurer or regulator has asked you to describe your security controls.
For context, Statistics Canada found that 16% of Canadian businesses with 10 or more employees were affected by cyber security incidents in 2023. Among businesses without cyber security staff, the most common reason given, cited by 47%, was that they used consultants or contractors to monitor security.
Questions to ask any provider before signing
These questions apply to any IT provider, whether you pay monthly or by the hour. The joint advisory mentioned above recommends that contracts state whether the provider or the customer owns specific security responsibilities, such as hardening, detection and incident response. The Canadian Centre for Cyber Security adds that your organization is still the data owner, and legally responsible for data security, when a provider does the work.
Get these answers in writing
- Documentation: who owns the network diagrams, asset lists, passwords and procedures, and can you get a complete copy at any time, including when you leave?
- Admin accounts: are your Microsoft 365 tenant, domain name, firewall and backup accounts registered to your business, with administrator access you control? Microsoft recommends two or more emergency access accounts in Microsoft Entra ID, the sign-in system behind Microsoft 365.
- Security responsibilities: which of patching, hardening, monitoring, detection and incident response belong to the provider, and which stay with you? Is MFA enforced on every provider account that can reach your systems?
- Incident notice: how, and how quickly, will the provider tell you about a security incident affecting your systems or data?
- What counts as a project: which work the fee covers, which is quoted separately (new computers, office moves, migrations, new software), and what spending needs your approval first?
- Response and hours: what are the response targets by priority, what counts as business hours, and what does after-hours work cost?
- Data location and subcontractors: where are backups and logs stored, and which other companies can access your systems?
- Exit terms: what notice is required, what does leaving cost, and how are documentation, data and admin access handed back? Will the provider’s accounts be disabled when the contract ends?
Don’t skip the last question: the joint advisory notes that disabling a provider’s accounts can be overlooked when a contract ends. For the pricing side, including onboarding fees and contract terms, see our guide to what managed IT services cost.
YVR Technology provides managed IT services and IT consulting for businesses across Greater Vancouver and the Fraser Valley. If you’re weighing break-fix against a managed plan, contact us to talk through which model fits.