· RNITS Managed IT  · 14 min read

✦ Switch to AI view

MSP Pricing Models: Why Break-Fix Still Works for Some Businesses

Every MSP blog says break-fix is dead. It isn't. Here's an honest walkthrough of MSP pricing models, the real cost math, and who each one actually fits.

MSP Pricing Models: Why Break-Fix Still Works for Some Businesses

Search “break-fix vs managed services” and read the first ten results. Every one of them was written by an MSP, and every one of them arrives at the same conclusion: break-fix is dead, reactive IT is irresponsible, and the only sane choice is a monthly managed services contract.

We are an MSP, and we are going to tell you something different: break-fix is not dead. For a specific kind of business, it is still the right answer. The reason you never read that in an MSP blog is not that it is untrue. It is that no MSP makes recurring revenue off a client who calls twice a year.

That conflict of interest sits underneath almost everything written about IT pricing, and it is worth naming before we walk through the models. MSP valuations are built on monthly recurring revenue. When an MSP sells its business, the buyer pays a multiple of contracted monthly revenue — break-fix income barely counts. So the entire industry has a structural reason to declare the reactive model dead, whether or not it is dead for you.

This post is the honest version of the comparison — including which businesses should not hire us on a monthly contract. It is the third post in our un-MSP series, following why SMBs overpay for security tools and what no lock-in, no upsell, no tool sprawl means in practice.

The four MSP pricing models, in plain English

There are more variations than this, but nearly every IT support arrangement in the SMB market is one of four shapes.

Break-fix (pay per incident). Something breaks, you call, someone fixes it, you get a bill. Hourly rates in the NH/MA market run roughly $125 to $250 per hour depending on the shop and the severity. No contract, no monthly fee, no ongoing relationship beyond the vendor knowing your name. You own all the risk of things breaking and all the savings when they do not.

Block hours (prepaid retainer). You buy a block of hours — say 20 or 40 — at a discounted rate, and the provider draws them down as you call. It is break-fix with a volume discount and slightly better response times, because prepaid clients get bumped ahead of pure walk-ins. Blocks usually expire after a year, which is a detail worth reading twice in any agreement.

All-in managed services (per user, per month). The model most MSPs sell. A flat monthly fee per employee covers monitoring, patching, help desk, security tooling, backup management, and vendor coordination. Market rate for a real stack in our region is $100 to $175 per user per month. The MSP takes on the risk of your environment being noisy, so it has a direct financial incentive to keep things from breaking — which is the genuinely good part of the model, and the part the marketing gets right.

Co-managed / hybrid. You have an internal IT person or a small team, and the MSP fills specific gaps: security monitoring, after-hours coverage, patching infrastructure, big projects, or the specialized work — like a cloud migration — that does not justify a full-time hire. Pricing is usually a smaller per-user fee, a fixed monthly scope, or project rates.

None of these models is a scam and none of them is automatically right. They are different allocations of risk and cost between you and the provider. The question is which allocation matches your business — and that depends on numbers, not philosophy.

The math the “break-fix is dead” posts skip

Here is the comparison the industry does not like to write down.

Take a 10-person business at $125 per user per month on a managed contract. That is $1,250 a month, $15,000 a year, every year, whether anything breaks or not.

Now take the same business on break-fix at $175 an hour. For break-fix to cost more than the managed contract, that business needs to consume roughly 85 hours of IT labor a year — more than seven hours of billable break-fix work every single month, indefinitely.

Some 10-person businesses consume that easily. Plenty do not. A landscaping company where eight of the ten employees never touch a computer, the “server” is a QuickBooks file, and email lives in Google Workspace might generate fifteen billable hours in a bad year. Telling that business it is irresponsible not to spend $15,000 annually on managed IT is not advice. It is a sales pitch wearing advice’s clothes.

The honest comparison has three parts, and most blog posts only show you the first:

  1. The direct cost — contract fee versus expected hourly spend. This is the easy part, and it is the part the math above covers.
  2. The downtime cost — what an hour of outage actually costs your business. For a law firm billing $300 an hour per attorney, a half-day email outage is a five-figure event and break-fix response times are intolerable. For the landscaping company, the crew keeps mowing while the office computer waits until Thursday. Same outage, wildly different cost.
  3. The risk cost — the low-probability, high-severity events: ransomware, business email compromise, a failed drive with no tested backup. This is where pure break-fix has a genuine hole, and we will be straight about it below.

If you run this three-part math and break-fix wins, break-fix wins. You are allowed to believe an MSP that tells you that. You should be suspicious of one that never does.

Who break-fix actually fits

Based on what we see across small businesses in New Hampshire and Massachusetts, the reactive model genuinely works when most of these are true:

  • Under about 10 employees, with only a handful doing real computer work.
  • No compliance obligations. No HIPAA, no CMMC, no PCI beyond what your payment processor handles, no contractual security requirements from a big customer.
  • Downtime is an annoyance, not a hemorrhage. If your revenue-producing work continues while a workstation is down, your downtime cost is low.
  • Cloud-first and simple. Email in Microsoft 365 or Google Workspace, files in the same place, no on-premises server doing anything important.
  • Someone on staff is capable of basic triage — rebooting a router, running an update, telling a phishing email from a real one.

That describes a lot of real businesses: trades, small retail, single-location restaurants, owner-operator professional shops. For them, the disciplined move is not a $1,250 monthly contract. It is a relationship with a shop that answers the phone, plus a small set of non-negotiables handled once and checked occasionally.

And that last clause matters, so here is the caveat we owe you.

Where pure break-fix genuinely fails

Security is the one category of IT work that cannot be done reactively.

Nobody calls their break-fix vendor to report an attack in progress, because nobody knows it is in progress. Ransomware does not schedule an appointment. By the time a reactive vendor hears about a compromise, the interesting part is over and the expensive part has begun. The 2026 numbers on this are brutal: recovery from a ransomware event routinely costs more than a decade of managed service fees, and it kills a meaningful percentage of the small businesses it hits.

The same is true of backups — a backup that nobody tests is a theory, not a control — and increasingly of cyber insurance, where carriers now ask for MFA enforcement, endpoint protection, and tested recovery before they will write or renew a policy. Attest to controls you do not have and the carrier can deny the claim precisely when you need it.

So the honest recommendation for a break-fix-appropriate business is not “wing it.” It is break-fix for support, plus a minimal always-on baseline:

  • MFA enforced everywhere, with the built-in security features of the Microsoft or Google license you already pay for actually configured
  • Real endpoint protection on every machine
  • Automated, monitored, periodically test-restored backups
  • Someone patching, even if it is just well-configured automatic updates with a quarterly check

That baseline does not require a full managed contract. Configured properly, it costs a fraction of one — often mostly licensing you already own, which is the same finding at the center of our free cyber security audit for businesses on full managed stacks. Reactive support with a proactive security floor is a legitimate model. The industry just does not have a pricing tier named after it, so nobody writes blog posts about it.

Who all-in managed actually fits

The flat-fee model earns its cost when the three-part math flips:

  • Compliance is in the picture. HIPAA, CMMC, SOC 2, or a customer contract with security requirements effectively mandates continuous monitoring, documented patching, and evidence on demand. Reactive support cannot produce an audit trail.
  • Downtime is expensive. When employees bill by the hour or the business stops when the systems stop, the response-time difference between a contract client and a break-fix call pays for itself in one bad morning.
  • Headcount is 10 to 15 or more. The volume of routine IT work — onboarding, offboarding, license management, the endless stream of small issues — starts consuming enough hours that predictable flat pricing beats the hourly meter, and the owner stops being the de facto IT department.
  • You would rather budget than gamble. Some owners rationally prefer a known $1,250 a month over a lumpy $400-one-month, $6,000-the-next pattern, even when the expected totals are similar. Predictability has value. Just price it consciously instead of being scared into it.

When those conditions hold, all-in managed is not an upsell — it is cheaper than the alternative once downtime and risk are priced in. Both things in this post are true at once: the model is oversold to businesses that do not need it, and it is genuinely the right answer for businesses that do.

Co-managed: the model nobody pitches you

If you already have an IT person, most MSPs see a competitor to displace. That is backwards. A solo internal IT admin covering 40 users is stretched across help desk, projects, patching, and security — and cannot be on call 365 days a year, because they take vacations and get sick. The gaps are predictable: after-hours coverage, security monitoring, and the specialized project work that comes up twice a year.

A co-managed arrangement fills exactly those gaps and nothing else. The MSP provides the monitoring and management infrastructure and the escalation depth; your internal person keeps the local knowledge and the daily relationship. It costs a fraction of full management because the MSP is not duplicating work your employee already does. We have these arrangements, and they are some of our most stable relationships — precisely because the scope is honest on both sides.

Clean cartoon illustration of a small business owner and an IT consultant fitting puzzle pieces labeled with different support models onto a matching board shaped like a storefront

How we handle this at RNITS

The un-MSP position on pricing models is the same as our position on tools and contracts: the model should fit the business, not the MSP’s revenue chart.

In practice, that looks like this.

Our managed pricing is published. Standard is $100 per user per month, Premium is $125, Enterprise is $150 — it is on the pricing page, with what each tier includes. No “call us for a quote,” no “it depends” until a salesperson has qualified your budget.

Month-to-month exists, and the exit clause is on page one. If managed service has to be earned every month, the pricing conversation stays honest permanently. A client who can leave without penalty does not need to be oversold carefully — they need to be served well.

We will tell you if you do not need us monthly. Prospects walk in assuming they have to buy the full contract because that is what every competitor pitched. When the three-part math says a security baseline plus on-call support is the right fit, that is what we say — and we set up the baseline, stay reachable, and check in periodically. It costs them a fraction of the contract they walked in expecting to sign.

Businesses change models as they change. Break-fix clients grow into managed contracts when headcount or compliance arrives. Managed clients hire an internal IT person and shift to co-managed. A few have left for in-house IT entirely and come back years later when it did not pan out. Every one of those transitions is fine. The relationship survives the model changing because the relationship was never held together by an early-termination penalty.

Clients tell us the flexibility is a large part of why they stay — which is mildly ironic, since the industry’s argument for lock-in contracts is retention. Our retention sits at roughly 100 percent without them. When leaving is easy, staying means something.

How to decide: five questions

You do not need an IT assessment to get most of the way to the right model. Answer these honestly:

  1. What did you actually spend on IT support in the last 12 months — invoices, plus the owner-hours spent playing help desk? If it is well under what a managed contract would cost, that is data.
  2. What does one full day of downtime cost you in hard revenue and missed obligations? Under a thousand dollars, break-fix is survivable. In the five figures, it is not.
  3. Does anyone — regulator, carrier, or customer — require you to prove security controls exist? If yes, some form of ongoing management is effectively mandatory, because evidence cannot be produced reactively.
  4. Is your security baseline real? MFA everywhere, endpoint protection, tested backups, current patches. If you cannot say yes with confidence, that gap needs closing regardless of which support model you pick — and closing it is a project, not a contract.
  5. Are you at an inflection point — passing 10-15 employees, taking on compliance-bound work, hiring your first IT person? Model changes belong at inflection points, not at whatever moment an MSP’s sales quarter ends.

If your current provider has never walked you through a version of this — if every conversation ends at the same all-in tier regardless of your answers — you have learned something about whose interests the recommendation serves.

Frequently asked questions

Is break-fix IT support cheaper than managed services?

For small, simple, low-downtime-cost businesses, usually yes — often dramatically. A 10-person business needs to consume roughly 85+ hours of billable work a year before typical managed pricing wins on direct cost alone. The comparison flips when you add downtime cost, compliance requirements, or security risk, which is why the honest answer depends on your numbers rather than on a universal rule.

What does managed IT cost per user in 2026?

In the New Hampshire and Massachusetts market, $100 to $175 per user per month for a genuine stack: monitoring, patching, help desk, endpoint protection, backup management, and security baseline. Meaningfully below that usually means an under-resourced provider; well above it without a clear explanation usually means tool sprawl. Our tiers run $100 to $150 and are published.

Can I mix break-fix and managed services?

Yes, and more businesses should. A common right-size for very small companies is a managed security baseline — MFA, endpoint protection, monitored backups, patching — with support handled on-call. Co-managed arrangements do the same thing for businesses with internal IT. The industry rarely pitches hybrid models because they produce less recurring revenue, not because they do not work.

Why do all MSPs push monthly contracts?

Partly for defensible reasons: proactive maintenance genuinely prevents problems, and flat pricing aligns the MSP’s incentive with your uptime. And partly for a reason nobody puts in the pitch deck: MSP business valuations are calculated on contracted monthly recurring revenue. A break-fix client adds almost nothing to what the MSP is worth; a three-year contract adds a lot. Both motives are real. Only one of them is about you.

When should a business switch from break-fix to managed IT?

At an inflection point: crossing roughly 10-15 employees, taking on compliance obligations (HIPAA, CMMC, cyber insurance requirements with teeth), a downtime scare that revealed the real cost of waiting for a callback, or an owner realizing they have become the unpaid IT department. If none of those has happened, the pressure to switch is probably coming from the vendor’s needs rather than yours.

Talk to an MSP that will run the math with you

If you are trying to figure out which model fits — or you are on a full managed contract and quietly suspect a smaller arrangement would do — the fastest way to find out is to look at the actual numbers: what you spend, what downtime costs you, what your licenses already include, and where the real security gaps are.

That is exactly what our free cyber security audit produces, and it comes with a straight answer about which support model fits your business — even when that answer is “less than you expected to buy.” We are based in Tyngsboro, MA, onsite across New Hampshire and Massachusetts within 150 miles, and remote nationally.

Or just start a conversation. We will run the three-part math with you, on paper, before anyone talks about a contract.

The Rnits Company. The un-MSP. (978) 226-8931.

Back to Blog
Free Cyber Security Audit

Not sure where your business stands on security?

Get a free, no-obligation cyber security audit from RNITS. We'll show you exactly what's exposed and what to fix first — in plain English.

Related Posts

View All Posts »