Skip to main content

← All posts

What managed IT actually costs for a 10 to 30 user business

Real per-user pricing bands for managed IT with security included, what belongs in the base fee, and why the cheap quote usually is not.

· Jake Schaaf, Founder of Atticus Rowan

Three quotes land on an owner’s desk for the same 18-person company. One says $75 per user per month. One says $145. One says $210. All 3 proposals use the words “fully managed” and “proactive security.” Nothing on any page explains why the top number is nearly 3 times the bottom one.

Most IT providers will not publish pricing, which leaves owners comparing proposals with no frame of reference. So here is the frame, with real numbers.

The honest range

For a 10 to 30 user business in 2026, fully managed IT with a legitimate security stack included typically runs $125 to $250 per user per month. Where a business lands inside that band depends on 4 things:

  • Security stack depth. Basic antivirus and patching sits at the bottom. Managed EDR, MFA management, email security, security awareness training and hardened backup push toward the middle and top.
  • Industry and obligations. A business facing customer security questionnaires or carrying meaningful cyber insurance requirements needs more evidence, more documentation and more controls than one that is not there yet.
  • Environment complexity. On-prem servers, line-of-business applications, multiple sites and specialty hardware all add real labor. A clean cloud-only office is cheaper to run well.
  • Support model. Unlimited remote helpdesk with defined response times costs more to deliver than “we will get to it,” because it requires staffing to a standard instead of to a queue.

A 15-person office at $150 per user is $2,250 a month, roughly $27,000 a year. That is a real number worth taking seriously, and it is also less than half the loaded cost of 1 junior in-house IT hire, for coverage no single hire can provide.

What should be inside the base fee

When we review competing proposals for prospects, the difference between quotes is almost never efficiency. It is scope. A defensible base fee for this market includes:

  • Unlimited remote helpdesk during business hours, with an after-hours path for emergencies
  • Patching and update management for workstations, servers and the Microsoft tenant
  • Managed EDR on every endpoint, with a human response path, not just an install
  • MFA and identity management, including enforcement and exception handling
  • Email security beyond defaults, filtering, authentication records and tenant monitoring
  • Backup for servers and Microsoft 365 data, with restore testing on a schedule
  • Security awareness training and phishing simulation
  • Vendor management, the provider deals with the ISP, the copier company and the software vendors so you do not
  • Documentation the business owns, and quarterly reviews with someone who knows your account

Common legitimate add-ons billed outside the base: projects (a server migration, an office move), hardware purchases and after-hours project work. A provider quoting project labor separately is being honest about it. A provider whose base fee excludes half the security list above is quoting a different product entirely.

About that $75 quote

The cheap quote is almost never dishonest. It is just answering an easier question. Strip out EDR with human response, Microsoft 365 backup, awareness training, email security and quarterly account management, and $75 per user is achievable. The result is a helpdesk with antivirus attached.

The problem is what happens next. Cyber insurance applications now ask directly about MFA, EDR and offline backups, we walked through those questions in our cyber insurance triage post, and the business either pays to bolt those on later at add-on pricing or signs the application inaccurately. Owners who have lived through this cycle usually describe the cheap contract as the most expensive one they ever signed. The pattern shows up again and again in the move from break-fix relationships to managed ones: the sticker price and the cost of ownership are different numbers.

There is a version of this on the high end too. A $250 quote for a 12-person cloud-only office with no compliance pressure deserves scrutiny line by line. Price should map to scope you can point at.

Co-managed and the in-house comparison

Two other models come up in this size range.

Co-managed IT pairs an internal IT person with an outside provider that supplies the security stack, the tooling and escalation depth. It typically prices lower per user than fully managed, since the provider is not staffing the front line. This tends to make sense from about 25 users upward, and it is the natural bridge as a company grows. We covered that transition arc in what changes between 25 and 75 users.

Going in-house rarely pencils below 30 users. One capable generalist costs $70,000 to $95,000 loaded before tools, takes vacations, gets sick and cannot cover security monitoring, helpdesk, projects and strategy simultaneously. The honest in-house comparison is a person plus a co-managed contract, not a person instead of everything.

Onboarding and contract terms, the fine print that matters

Two more numbers belong in your comparison. First, onboarding. Taking over an environment properly, documentation, security remediation, agent deployment and account transfers, is real work, and most providers charge a one-time onboarding fee somewhere around 1 month of service. A provider who waives onboarding entirely is often signaling they do not plan to do the work, and you will feel that decision in month 6.

Second, term length. Month-to-month or annual agreements are normal in this market. A 3-year term with automatic renewal and a 90-day cancellation window is a lot to commit to before a provider has proven anything. If a long term is required, the agreement should say what you get for it, locked pricing or included projects, and the offboarding obligations should be spelled out just as clearly as the onboarding ones.

6 questions that expose any quote

Take these to every proposal meeting and the pricing conversation gets short:

  • What exactly is in the base fee, and can you show me the list in the agreement?
  • Is EDR included on every device, and who responds when it alerts at 2 a.m.?
  • Is Microsoft 365 data backed up, and when did you last test a restore for a client?
  • What are your actual response-time commitments, in writing?
  • What happens at renewal of our cyber insurance, do you fill out the application with us?
  • If we leave, what does the offboarding handoff include?

Any provider worth hiring answers all 6 without discomfort. The answers, not the per-user price, are what you are actually buying.

Atticus Rowan prices in the band described here, because delivering the full list above costs what it costs, and we would rather explain a real number than win on a quote that quietly excludes the parts that protect you. If you want a straight assessment of what your business should be paying for, and what you are getting today, contact us and bring your current agreement. We will read it with you line by line.