The minimum baseline (and why)
Every business — regardless of size, regardless of industry — needs four things: MFA on every account, EDR on every device, backups that are tested, and a documented response plan. Below that baseline, you're one mistake from a serious problem. Above it, the question becomes "how much more?"
What size you are vs. what tools you need
A 4-person office on M365 has a different profile than a 30-person office with an on-prem server. The number of users dictates the help-desk load. The number of locations dictates the network spend. The number of servers dictates the backup investment. Get those three numbers right and most of the stack rightsizes itself.
Compliance is the multiplier
If you handle patient data (HIPAA), card payments (PCI), public records (CJIS), or law-firm privilege, the baseline isn't optional — and the documentation requirements double the work. Compliance isn't a bigger budget for the same protection; it's a different kind of protection plus an evidence file.
The two questions every owner should answer first
Before you talk to any MSP, write down the answers to two questions: How much does an hour of full-team downtime actually cost us? And what's the smallest mistake that could end the business? The first sets your investment; the second sets your priorities.
Frequently asked questions
How do I know if I'm being sold more than I need?
What's the most commonly oversold item?
What's the most commonly underbought item?
When does the enterprise stack start to make sense?
Related reading
- What to look for in an MSP
- Break-fix vs. managed: how to do the math
- HIPAA IT checklist for independent pharmacies
- Cyber insurance is requiring MFA and EDR — what that means
- What does IT support actually cost in 2026?
Your next step
Reading is the easy part — the gap closes when someone owns it. Book a free 20-minute call and we’ll walk through how this applies to your environment, in plain English.
