Managed IT pricing in Australia looks confusing from the outside because providers quote against different units: per user, per device, or per hour. Once you understand the three models and what a properly scoped agreement should include, comparing quotes becomes straightforward, and the traps become visible.
The three pricing models
Per user, per month
The dominant model for SMEs, and for good reason. One monthly fee covers a person and everything they use: laptop, phone, tablet, peripherals. It's predictable, it scales cleanly with headcount, and it removes the awkward incentive questions that plague other models. Most providers structure it in tiers, from a base level covering helpdesk, monitoring, patching, endpoint protection and backup, up through cybersecurity uplift and vendor management, to a top tier adding round-the-clock support and strategic advisory (sometimes badged as a virtual CIO).
Per device, per month
Each piece of equipment is priced individually, with servers usually costed separately at a higher rate. This can work out cheaper when every person uses exactly one device, and dearer the moment your team carries a laptop and a phone each. Check how shared equipment is treated: reception computers, warehouse terminals and network gear may sit inside or outside the agreement, and that ambiguity is a common source of surprise invoices.
Break-fix, by the hour
Pay per incident, no monthly commitment. Be clear-eyed about what this is: reactive repair, not managed IT. Nothing is monitored, nothing is patched proactively, and nobody is watching your backups. It's the cheapest arrangement while everything works and the most expensive when something fails badly, because no prevention has happened. There's also a commercial misalignment worth naming plainly: a break-fix provider earns more when your systems break. A managed provider on a flat fee earns more when they don't.
What a proper agreement should include
Whatever the tier, a managed service agreement worth signing covers:
- Helpdesk support with defined response times in writing, not verbal assurances
- Proactive monitoring and alerting across servers, endpoints and network
- Automated patching of operating systems and key applications
- Business-grade endpoint protection, not consumer antivirus
- Backup management with periodic restoration testing, because an untested backup is a hope, not a control
- A stated position on cybersecurity, ideally referencing alignment with the Essential Eight
The last two points deserve emphasis. Some low-cost agreements treat backups and security as paid extras, which means the headline price excludes the two things most likely to save your business. Always confirm both are inside the fee before comparing numbers.
What actually drives your quote
Two businesses with identical headcount can receive very different quotes, and the difference usually traces to a few drivers you can assess before you go to market: the age and standardisation of your equipment (a fleet of mixed, ageing machines costs more to support than uniform, current ones), whether you run on-premises servers or are fully cloud-based, how many line-of-business applications need vendor management, your industry's compliance obligations, and how much legacy mess needs remediating in the first months. Providers price risk; the more unknowns in your environment, the more padding in the quote.
Matching the tier to your business
The right tier follows from two questions. First, what does an hour of downtime cost you, in lost work, missed deadlines and client confidence? Businesses where the answer is "a lot" belong on tiers with tighter response commitments and richer monitoring. Second, what does your data attract? If you hold client financial records, health information or anything a criminal could monetise, security uplift isn't optional gold-plating; it's the core of what you're buying. IT sits alongside the other operational foundations we cover on the Operations hub, and weakness in one tends to expose weakness in the others.
Comparing quotes without being misled
Get every quote itemised against the same checklist: response times, patching cadence, backup scope and testing, security inclusions, onboarding and offboarding of staff, and what triggers out-of-scope hourly charges. Ask what happened during the provider's last client security incident and how it was handled. Then weigh scope rather than headline rate: a slightly dearer provider whose agreement genuinely covers security and tested backups is almost always the better buy than a cheap agreement with the important things left out.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →