Security is the part of a managed contract most likely to be half in and half out, and the boundary moves between providers. Almost every contract in this record includes endpoint protection and patching, because those are the running of the estate. Almost none includes detection and response, log retention or security awareness training in the base fee, because those need people watching and people cost more than software. Knowing which side of the line each item sits on is the whole comparison.
What is normally inside the per-seat fee
Endpoint protection on the machines, operating system and application patching, and the administration of whatever mail filtering the platform already provides. These are inside because they are the same work as keeping the estate running, and because leaving them out would make the rest of the contract meaningless. If a proposal prices them separately, that is a signal about the base rate rather than about the security.
What is normally extra, and why
Managed detection and response, a security operations service, log collection and retention, phishing simulation and awareness training, and any compliance-driven work such as an annual penetration test. Each of these needs a person or a licence that scales with your estate rather than with your headcount, which is why they sit outside a per-seat rate. Be Structured's published band tops out at $300 a user a month, and the top of a band like that is where these additions live.
The order to buy in
For a business under a few hundred people the sequence that matters is: patching that actually completes, multi-factor authentication on everything including the remote access nobody remembers, a backup that has been restored from, and then detection. Most incidents at this size begin with something unpatched or an account without a second factor rather than with anything a detection service would have been the only way to catch.
Ask what happens on the day
The question that separates offers is not what is monitored but what the provider does when something is found: whether it investigates, whether it can isolate a machine itself, whether it telephones you at three in the morning, and what it charges for the response. Incident response is billed hourly by most providers in this record and published by none of them.
Questions people ask about managed it security
Is cyber security included in managed IT?
Partly. Endpoint protection and patching are usually inside the per-seat fee. Detection and response, log retention, awareness training and penetration testing are usually priced separately.
What should a smaller business buy first?
Patching that completes, multi-factor authentication everywhere including remote access, and a backup somebody has restored from. Detection is worth buying after those, not instead of them.
What does incident response cost?
No provider in this record publishes a rate for it. It is commonly hourly and commonly outside the monthly fee, which is worth settling in writing before it is needed.