A single compromised mailbox at a London firm rarely stays a single mailbox. It becomes a hidden forwarding rule, an invoice quietly reissued with a different sort code, a 72-hour reporting clock running with the Information Commissioner, and a client asking why nobody noticed for eleven days. Preventing that chain of events is what a business IT support contract is actually bought for, and it is the standard a provider should be measured against in 2026.
The London market is crowded and the language is interchangeable. Proactive monitoring, cloud-first, 24/7 helpdesk: hundreds of firms advertise the same six phrases, and the price spread between two providers quoting for the same forty-seat office can be threefold. Whether you are shortlisting a specialist IT support company UK or deciding whether to renew with the provider you have used since 2019, the questions that separate them are narrow and technical rather than glossy.
What follows is a buyer-side view: what a managed service should genuinely contain, the compliance floor a London business has to clear, the infrastructure deadlines landing in this budget cycle, and the contract clauses that decide whether leaving is straightforward or expensive.
What a managed IT support contract should actually contain
Most disappointing IT relationships are not caused by incompetent engineers. They are caused by a scope that was never written down precisely, so both sides remember the sales conversation differently. Insist that the schedule, not the brochure, defines the service.
Service desk and response times
A meaningful service level agreement separates response from resolution and defines priority in terms of business impact rather than technical severity. A whole-site outage or a suspected security incident is P1; one user unable to print is P4. Ask what proportion of tickets the provider resolved within target last quarter and how that figure is measured, because a provider who cannot answer is not measuring it.
- Priority definitions written in business terms, with named examples for each level.
- Response and resolution targets stated separately, with the working hours they apply to.
- Whether cover is UK business hours, extended hours, or genuinely 24/7, and whether out-of-hours work is billed on top.
- Escalation path with named roles and a route to a senior engineer that does not depend on one person answering a mobile.
- Reporting cadence: a monthly ticket and patching report, and a quarterly service review with someone empowered to change things.
Identity, endpoints and patching
In a Microsoft 365 estate, identity is the perimeter. Expect multi-factor authentication enforced for every account including service and admin accounts, conditional access policies that restrict sign-in by device compliance and location, and privileged accounts kept separate from day-to-day mailboxes. Endpoints should be enrolled in a management platform such as Microsoft Intune so that patch status, disk encryption and device compliance are facts on a dashboard rather than assumptions.
Patching deserves a specific number in the contract. The Cyber Essentials scheme requires updates that fix vulnerabilities rated high or critical to be applied within 14 days of release, and that is a reasonable floor to write into a service schedule for servers, workstations, firewalls and third-party applications alike.
Backup, and the gap between backup and recovery
Microsoft operates its cloud platform on a shared responsibility model: it keeps the service running, but the integrity of your data remains yours, which is why a separate backup of Exchange Online, SharePoint, OneDrive and Teams is standard practice rather than paranoia. The contract should state a recovery point objective and a recovery time objective for each critical system, keep at least one copy immutable and off-platform, and commit the provider to test restores on a schedule. A backup nobody has restored from is a hypothesis, not a control.
The compliance floor a London business has to clear
Compliance is where a good provider earns its fee, because the obligations sit on your business regardless of who administers the servers. Four strands matter for most London companies.
Cyber Essentials is the government-backed baseline, delivered by IASME on behalf of the National Cyber Security Centre. It covers five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Certification lasts twelve months, and Cyber Essentials Plus adds a hands-on technical audit rather than a self-assessment. Some central government contracts and an increasing number of private tenders and insurers will not proceed without it.
The UK GDPR and the Data Protection Act 2018 impose the second layer. A personal data breach likely to result in a risk to individuals must be reported to the ICO within 72 hours of becoming aware of it, which is impossible to meet if nobody has agreed in advance who declares an incident. Your IT provider is a processor, so a written data processing agreement covering security measures, sub-processors, breach notification and deletion on exit is not optional paperwork.
Sector rules form the third layer. Firms regulated by the FCA have had to operate within defined impact tolerances for their important business services since the operational resilience regime took full effect, and that includes oversight of technology suppliers. Financial services firms handling shared account data face further expectations as data-sharing models mature, a theme explored in Why Open Banking is the “New Fair” in 2026 Lending. Solicitors carry confidentiality and client money duties that make undetected mailbox compromise a regulatory event as well as a commercial one.
Industry-specific experience is the fourth strand, and the easiest to test in a meeting. Ask a provider to describe a control they implemented for a client in your sector and what it cost. Generalists give a generic answer; specialists name the practice management system, the case file retention period, or the audit finding that prompted the change.
Three deadlines shaping London IT budgets
- The retirement of the analogue telephone network. Openreach is withdrawing the traditional PSTN and ISDN services, with the industry migration date set for 31 January 2027. The risk is rarely the phones themselves, which usually moved to a cloud platform years ago. It is the forgotten analogue lines: lift emergency phones, intruder and fire alarm signalling, door entry panels, card payment terminals and remote monitoring kit in server rooms. Audit every line on the bill against a physical device before the deadline compresses supplier lead times.
- Windows 10 reaching end of support on 14 October 2025. Extended Security Updates buy time, but they are a bridge with a toll rather than a destination. Where machines cannot meet the Windows 11 hardware requirements, the decision is a refresh cycle with a budget, not an emergency in the middle of a quarter.
- Generative AI tooling colliding with permissions debt. Copilot-style assistants surface whatever a user is already permitted to see, and in most SharePoint estates that is far more than anyone intended. A permissions and sensitivity-label review should precede a rollout, not follow the first uncomfortable discovery.
Comparing delivery models
The right model depends less on headcount than on whether you have internal technical capability and how much unplanned change your business absorbs each year.
| Model | Best fit | Cost shape | Main risk |
|---|---|---|---|
| Break-fix, billed hourly | Under ten staff, simple cloud-only setup, low regulatory exposure | Unpredictable; cheap until it is not | Nobody owns prevention, so problems are found by users |
| Fully managed, per user per month | Ten to two hundred staff with no internal IT | Predictable monthly fee plus project work | Scope creep disputes if the schedule is vague |
| Co-managed alongside internal IT | Businesses with one or two internal staff needing depth and cover | Reduced per-seat fee plus retained specialist hours | Overlapping responsibilities unless a RACI is written |
| Fully in-house | Large or highly regulated organisations with specialist needs | Salaries, tooling and recruitment risk | Single points of failure during leave and turnover |
What London pricing actually looks like
Fully managed support in London is normally quoted per user per month, and the headline number is close to meaningless without the exclusions. Two quotes that differ sharply usually differ in what sits outside the fee. Before comparing figures, establish the following.
- Whether Microsoft 365 or Google Workspace licences are inside the fee or rebilled at list price.
- Whether security tooling, endpoint detection and response, email filtering, backup and password management are bundled or added per seat.
- Whether project work such as migrations, office moves and hardware refreshes is quoted separately, and at what day rate.
- Whether onboarding or transition is charged as a one-off, and what documentation you receive at the end of it.
- Whether the count is per user or per device, which matters greatly if staff have both a laptop and a workstation.
- Whether out-of-hours work, on-site visits and travel within and beyond the M25 attract additional charges.
A provider such as Supporttree or any credible competitor should be able to hand you a single-page summary of inclusions and exclusions without redrafting it. If that summary takes a week to produce, the internal definition of the service is loose, and loose definitions become invoices.
Contract terms that decide how bad an exit is
Every IT relationship ends eventually. The terms below determine whether that ending takes six weeks or six months, and they are far easier to negotiate before signature than after a dispute.
- Notice period and renewal. A twelve-month term that auto-renews for a further twelve months unless cancelled ninety days out is common and quietly costly. Push for a rolling term after year one.
- Tenancy ownership. Your Microsoft 365 tenancy, domain registration and DNS should be owned by your company, with the provider holding delegated access. If your domain is registered in the provider name, you are negotiating from a weak position.
- Administrative credentials. You should hold at least one break-glass global administrator account that the provider does not control, stored securely and tested annually.
- Documentation. Network diagrams, asset registers, licence records, firewall configurations and scripts written for your environment should be yours and handed over in a usable format.
- Offboarding assistance. Specify a defined number of cooperation hours at a stated rate, because goodwill evaporates once notice is served.
- Data deletion. Require written confirmation that copies of your data held in the provider backup or monitoring platforms are destroyed after transition.
Frequently Asked Questions
How much should a London business expect to pay for IT support?
Fully managed support is normally priced per user per month, and the spread across the London market is wide because inclusions vary so much. The only reliable way to compare is to issue every provider the same inventory and the same list of required inclusions, then ask for a total annual cost including licences, security tooling, backup and expected project work. Comparing headline per-seat numbers alone will mislead you.
Do we actually need Cyber Essentials certification?
You need it if you bid for central government work covering certain sensitive contracts, and increasingly if you supply larger private organisations or want straightforward cyber insurance renewal. Beyond procurement, the five controls are a sensible baseline in their own right. Certification runs for twelve months, and Cyber Essentials Plus involves an independent technical audit rather than self-assessment.
Is a London-based provider better than a remote one?
For most cloud-first businesses, remote support resolves the overwhelming majority of tickets, so location matters less than it did. It still matters for on-site work: new office fit-outs, cabling, server rooms, hardware swaps and boardroom audio-visual problems on the morning of a client pitch. Ask for a committed on-site response time and check whether travel is billed.
What is the difference between managed and co-managed IT?
A fully managed service hands the provider end-to-end responsibility for the estate. Co-managed support keeps your internal IT staff in place and buys depth around them: out-of-hours cover, holiday resilience, security specialism, and access to tooling that would be uneconomic to license for one person. Co-managed arrangements only work when a written responsibility matrix records who owns each function.
How long does it take to switch IT providers?
Plan on four to eight weeks from signature to steady state for a typical small or mid-sized office, longer where there are on-premises servers, bespoke line-of-business applications or a hostile outgoing provider. Most of the elapsed time is discovery and documentation rather than technical work. Serving notice before the incoming provider has completed discovery is the most common way to create an avoidable gap in cover.
What to Do Next
Before you speak to a single provider, spend ninety minutes building an inventory: every user account including dormant and shared mailboxes, every device and its operating system, every line-of-business application and who supports it, every analogue phone line and what is attached to it, every domain and where it is registered, and the date of your last tested restore. That document turns a sales conversation into a like-for-like tender, and it is the single most valuable hour of preparation available to you. For related commercial and regulatory reading, see the Business Law section.
This article is general information about procuring IT services and related compliance obligations, not professional legal or regulatory advice.







