What Kind of IT Support Does Your Small Business Actually Need?
- Shay

- Oct 20, 2023
- 20 min read
Updated: Aug 26

Managed IT, Hourly Support, Projects and Outsourcing Explained
Updated August 2026: I originally wrote this article as a general guide for small business owners trying to decide whether they should outsource IT. Since then, the technology small businesses depend on has changed considerably, and so has the way I think this question should be answered.
Today, a small business may depend on Microsoft 365, Google Workspace, cloud applications, local servers, remote employees, company owned and personal devices, AI tools, cybersecurity platforms, backups, multiple technology vendors, and an internet connection that nearly everything depends on. A business may also encounter cyber insurance, regulatory, contractual, or customer security requirements that were never part of the conversation when the company was smaller.
Some businesses need someone to manage all of it. Others need help with one specific area. Some need a project completed. Some have an owner or employee who enjoys handling the smaller day to day technology issues but needs someone else responsible for infrastructure, security, device management, or the more complicated troubleshooting.
Because of that, I no longer think the most useful question is simply, “Should I outsource my IT?”
A better question is:
What does my business actually need someone to be responsible for?
Once we answer that, it becomes much easier to determine whether the right fit is managed IT, hourly time and materials support, project based work, specialized Microsoft 365 or Google Workspace management, a shared responsibility arrangement, or something else.
Outsourcing IT Does Not Have to Mean Outsourcing Everything
When small business owners hear “outsourced IT,” they often picture turning over every computer, account, support call, and technology decision to an outside company. That is one model, but it certainly is not the only one.
I work with businesses in several different ways because their needs are different. Some clients want me responsible for the larger technology environment under a managed IT agreement. Some use SNL-Tech Services for project based or hourly time and materials support. Some need specialized help with Microsoft 365 or another part of their environment.
I also have a managed client where the owner likes handling many of the smaller everyday technology issues himself. If an employee has a simple problem he knows how to solve, he handles it. I take over when the troubleshooting becomes more involved, while also remaining responsible for device management, RMM, updates, the server, and the underlying IT infrastructure covered by our agreement.
There is nothing inherently wrong with any of those arrangements. What matters is whether the responsibilities are clearly defined and whether the important parts of the environment are actually being managed.
IT support approach | What it can look like |
Project based IT | A defined migration, server project, network upgrade, cloud project, Microsoft 365 implementation, security improvement, or other technical project |
Hourly / T&M support | The business pays for the professional time it uses without necessarily having a comprehensive managed IT agreement |
Specialized IT management | An outside provider manages a particular part of the environment, such as Microsoft 365 or another cloud platform |
Shared or co-managed IT | The business handles certain responsibilities internally while the IT provider owns other areas and provides escalation |
Managed IT | The provider assumes broader ongoing responsibility for the areas defined in the agreement, which may include support, infrastructure, endpoints, security, monitoring, documentation, vendors, and technology planning |
The service model matters, but the label by itself tells me very little about how well a company's technology is actually being managed.
Hourly IT Support Does Not Have to Mean Waiting Until Something Breaks
Traditional break fix IT is generally reactive. Something stops working, the business calls someone, the technician fixes it, and the relationship largely goes quiet until the next problem occurs.
That is not the only way hourly IT support can work.
I provide project based and hourly time and materials support for clients that do not need a managed IT contract. I still want the environments I work on configured properly. If I am responsible for helping secure a client's Microsoft environment, for example, I still want appropriate visibility into Microsoft Defender alerts. The difference is that the client and I establish ahead of time how monitoring, response, authorization, and billing will work.
For some hourly clients, if I receive a security alert that requires attention and I can investigate and address it in approximately 30 minutes or less, my normal approach is to handle it immediately. If I determine that the situation is going to require a more involved investigation, I contact the client. I explain what I am seeing, what I initially think may be happening, and that I need to do a deeper investigation before I can give them reliable remediation options. Once I know more, I follow up with what I found and what the options look like.
That arrangement gives me enough flexibility to respond to something that should not sit unattended while also preventing a client from unexpectedly receiving several hours of unapproved work.
For a business considering hourly IT support, I think one of the best questions to ask is not simply whether the provider uses a particular security product. Ask what actually happens when that product generates an alert.
Who receives it? Who reviews it? What are they authorized to do? When will you be contacted? What happens when the investigation becomes more involved?
Those answers tell you much more about the support relationship.
“The billing model does not secure the business. The technical work and ongoing responsibility do.”SNL-Tech Services
Managed IT Is About Ongoing Responsibility
Managed IT becomes more useful when the business needs someone to assume broader ongoing responsibility for its technology.
That can include endpoints, RMM, patching, Microsoft 365 or Google Workspace, security tools, servers, backups, networks, user support, onboarding and offboarding, vendor coordination, documentation, and technology planning. The exact responsibilities should come from the actual agreement rather than assumptions about what the phrase “managed IT” means.
For some businesses, this becomes practical simply because the company has grown. What worked when five people shared an office may become difficult when there are twenty employees, remote workers, multiple locations, laptops, cloud applications, servers, mobile devices, cybersecurity alerts, employee onboarding and offboarding, and several outside technology vendors.
Nothing necessarily failed. The business may simply have outgrown an informal way of managing IT.
At that point, paying someone to assume ongoing responsibility can make more sense than treating every update, employee issue, security alert, vendor problem, and infrastructure decision as an independent transaction.
Managed IT Can Still Be a Shared Responsibility
Managed IT does not have to mean that the owner or employees are no longer allowed to touch anything.
Some owners enjoy technology. Others have an office manager or technically capable employee who is perfectly comfortable handling routine issues. There is no reason to take those responsibilities away simply to make an IT agreement fit a predefined package.
One of my managed clients works this way. The owner handles many of the smaller day to day employee issues himself. If something goes beyond what he can resolve, I handle the deeper troubleshooting. At the same time, I remain responsible for device management, RMM, updates, the server, and the underlying infrastructure included in our managed agreement.
That works because we understand the division of responsibility.
A small business does not need a formal internal IT department before this kind of shared model can make sense. The important question is whether everyone understands who owns each responsibility and when something should be escalated.
The Business Should Own Its Technology
There is another kind of ownership that I think every business owner should understand.
Your IT provider may manage your technology, but the business should retain appropriate ownership and recovery access to its technology assets and information. That includes understanding where the domain is registered, where DNS is hosted, who controls Microsoft 365 or Google Workspace, who has administrative access, where backups are stored, who controls the firewall and network accounts, what software subscriptions exist, and where important documentation and credentials are maintained.
I want my clients to stay with SNL-Tech Services because they trust me and see value in the relationship, not because they cannot figure out how to regain control of their own systems if they ever decide to make a change.
This is one reason I created the Small Business IT Checklist and Systems Inventory. A business owner should be able to answer basic questions about where important technology lives and who controls it. If the answer to several of those questions is “I don't know,” that does not automatically mean something is wrong. It does tell us where we need more information.
“The business retains ownership of its technology. The IT Partner takes ownership of the responsibilities entrusted to them.”SNL-Tech Services
Those are two very different kinds of ownership, and a healthy IT relationship needs both.
Taking Ownership Also Means Dealing With Other Vendors
This is one of the parts of managed IT that can be difficult to describe until a business owner has experienced the opposite.
An internet connection starts dropping. The ISP says the firewall is responsible. The firewall vendor says the ISP is responsible. A software vendor says its application is fine and tells the client to call IT. Everyone has a ticket open, everyone has an explanation, and nobody is actually taking responsibility for getting the overall problem resolved.
Meanwhile, the business owner or office manager is stuck in the middle making calls, forwarding emails, repeating troubleshooting steps, collecting ticket numbers, and trying to figure out which vendor is correct.
For my managed IT clients, vendor coordination is one of the responsibilities I take on. If the issue involves an ISP, software vendor, phone provider, copier company, cloud application, or another technology provider, I can work as the technical point of contact. I can explain what has already been tested, provide technical information, challenge assumptions when the evidence does not support them, and continue working between the parties to determine where the problem actually resides.
I cannot control another company's response time or force another vendor to resolve an issue. What I can do is take ownership of coordinating the technical problem so my client does not have to become the intermediary.
I also document what happened along the way. If we determine what caused the problem, what was tested, which vendor ultimately resolved it, and what changes were made, I want that information available later. If something similar happens six months from now, we have somewhere to start instead of repeating the entire troubleshooting process from the beginning.
For some business owners, this turns out to be one of the most valuable parts of having an IT Partner. They may initially think they are looking for someone to manage computers. What they really want is someone they trust to take responsibility when technology becomes complicated so they can stop spending their own time chasing vendors, trouble tickets, and status updates.
You Can Outsource One Part of IT Without Outsourcing Everything
Sometimes the business does not need general IT support at all. It needs deeper expertise in one area.
Microsoft 365 is a good example. A company may be perfectly capable of handling basic employee support but have nobody actively responsible for the Microsoft environment underneath Outlook, Teams, OneDrive, SharePoint, identity, authentication, security, and access.
Buying Microsoft 365 licensing is different from managing Microsoft 365. Depending on the licensing and needs of the business, there can be decisions involving Microsoft Entra ID, authentication, Conditional Access, administrative roles, Defender, Intune, device access, SharePoint and OneDrive permissions, third party applications, email security, backup, and other controls.
A business can ask SNL-Tech Services to review or manage that environment without necessarily turning over every other part of IT. My Microsoft 365 Audit, also called a Microsoft 365 Tenant Security Review gives me a point in time look at how the tenant is licensed, configured, secured, and being used. A business that wants ongoing help may also need specialized Microsoft 365 management rather than a broader managed IT relationship.
The same concept can apply to other technology. Outsourcing does not have to be all or nothing.
What If We Have Both Microsoft 365 and Google Workspace?
Another situation I see with small businesses is technology that accumulated over time rather than being deliberately planned.
Google Workspace was introduced years ago for email or file sharing. Later, Microsoft 365 licenses were purchased because employees needed Office applications. Another application uses Google identities. Employees started storing documents in different places. Nobody ever made an intentional decision about which platform should be responsible for what.
Having both Microsoft 365 and Google Workspace is not automatically a problem. There may be legitimate reasons for using both. What I want to understand is why both exist and what each one is responsible for.
Questions worth answering include:
Where is company email hosted?
Where are business files stored?
Which platform manages employee identities?
Which applications depend on Microsoft or Google authentication?
Where is sensitive company information being stored?
How are users added and removed from both environments?
Who has administrative access?
Are employees paying for overlapping capabilities that are not actually needed?
Is there a business or technical reason to keep both platforms?
If the company wants to consolidate, which platform better supports its applications, workflow, security, and future plans?
The answer should come from the business requirements rather than assuming Microsoft or Google is always the better choice.
What If We Want to Move to the Cloud?
Sometimes the support question is really an infrastructure question.
A business may have an aging server and know it does not want to replace it, but that does not automatically tell us what should happen next. Moving to the cloud might involve files, identity, applications, devices, backups, email, collaboration, or some combination of them. A line of business application may still require local infrastructure even when most of the company can move to cloud services.
I have written separately about whether a small business should move to the cloud because the right answer can be fully cloud based, on premises, or somewhere in between. Before recommending a direction, I want to understand the applications the company depends on, where its information lives, how employees work, what internet connectivity is available, what security and compliance considerations exist, and what the business is trying to accomplish.
A cloud migration should solve a business or technical problem. “Everyone is moving to the cloud” is not enough of a reason to redesign a company's infrastructure.
What If We Don't Even Know What We Have?
This may be the most important starting point of all.
Sometimes a business has changed IT providers several times. Equipment has been added over the years. Employees have installed applications. A server was inherited from an earlier setup. Microsoft 365 exists, but nobody is quite sure who originally configured it. There are backups somewhere, but the owner has never seen a restore performed. The network works, but nobody has a current diagram.
In that situation, I would not start by trying to sell the business a support package.
I would start by establishing a baseline.
The SNL-Tech Services IT Baseline Assessment is designed to look more broadly at the technology environment and help establish what the business actually has, what deserves attention, and what should be addressed first. That can include computers, devices, servers, networking, cloud services, security, backups, documentation, and other systems the business depends on.
Once we understand the environment, the next step becomes much easier to determine. The answer might be managed IT. It might be a Microsoft 365 Audit. It might be a cloud project, network improvement, documentation project, or hourly support arrangement.
An assessment is useful precisely because the outcome does not have to be a managed IT contract.
What If AI Is Becoming Part of How Our Business Works?
AI is another reason small businesses need to think about who is responsible for their technology.
A company may start with employees individually using ChatGPT, Claude, Microsoft Copilot, Gemini, or other AI tools. Before long, AI may be used with company documents, email, customer information, meeting notes, research, marketing, or internal workflows. At that point, the question is no longer simply which AI product employees prefer. The business needs to think about how AI fits into its existing technology, security, data, identity, and governance.
This does not automatically mean the business needs a managed IT contract. It does mean someone should understand which AI platforms are being used, what business information employees are putting into them, which accounts and plans are being used, what integrations have been enabled, and whether the company's existing Microsoft 365, Google Workspace, device management, access controls, and data practices support the way the business wants to use AI.
I approach AI the same way I approach other technology decisions. Start with what the business is trying to accomplish, understand the environment underneath it, determine what information and systems are involved, and then decide what technology and governance make sense.
A company may need an AI assessment or governance project rather than full managed IT. Another company may discover that AI adoption exposes larger issues with identity, permissions, data organization, device management, or Microsoft 365 that should be addressed first.
If choosing the platform itself is part of the problem, I have a separate guide on AI tools for small business and how to choose the right AI for the job. The important part is not choosing an AI platform simply because it is popular. It is determining what job the business wants AI to perform and whether the environment around it is ready to support that use responsibly.
What If Our Business Is Growing Into New Compliance Requirements?
Growth can change the technology conversation in another way. A business may begin handling a different type of information, enter a regulated industry, win a contract with new cybersecurity requirements, start working with larger customers that impose security requirements, or encounter new insurance requirements.
That does not mean every growing business suddenly needs the same compliance technology stack.
The first step is understanding which legal, regulatory, contractual, insurance, or industry requirements actually apply to the business. Once those requirements are understood, we can determine what they mean for the technical environment.
Depending on the actual requirements and environment, technical changes could involve identity and access, MFA, device management, encryption, logging, endpoint protection, backups, network architecture and segmentation, administrative access, cloud configuration, documentation, or other controls.
I am careful about the distinction between technical implementation and the broader compliance process. A compliance consultant, assessor, attorney, insurance professional, or another specialist may need to determine or interpret requirements that fall outside my role. My role is to understand the technical environment, implement and manage the IT controls that apply to my scope, and document what has actually been configured.
For businesses dealing specifically with Department of Defense requirements, I have separate CMMC and compliance resources. CMMC is only one example. The broader principle applies whenever a business discovers that its technology now has to support requirements it did not have before.
Cyber Insurance Can Create the Same Kind of Questions
Cyber insurance is another place where business owners sometimes discover that they cannot confidently answer questions about their own technology.
An application may ask about MFA, endpoint security, backups, administrative access, email security, remote access, encryption, or other controls. The owner may believe those protections exist because an IT provider mentioned them years ago, but belief is not the same as verifying the current configuration.
I discuss that problem in more detail in Cyber Insurance Requirements for Small Businesses. My approach is to verify what actually exists before the business answers technical questions on an insurance application. If the questionnaire exposes larger uncertainty about the overall IT environment, an IT Baseline Assessment may be the more appropriate starting point.
Incident Response Is Another Responsibility That Should Be Defined Before an Incident
One area businesses frequently overlook when deciding who manages IT is what happens during an actual cybersecurity incident.
If an employee's Microsoft 365 account appears to be compromised, ransomware is suspected, a device begins behaving unexpectedly, or a security platform generates a serious alert, who makes the first technical decisions? Who documents what was observed? Who determines whether a device should be isolated? Who preserves logs, screenshots, timestamps, and other technical information? Who coordinates with the cyber insurance carrier, legal counsel, a forensic specialist, or other outside parties if the situation requires them?
Those responsibilities are much easier to work through before an incident than during one.
I have had to preserve technical evidence during an actual client incident, including removing a drive, documenting the date and time it was removed, preserving it for the client, and maintaining screenshots, timestamps, and a run book documenting the technical work I performed. That experience is one reason I do not like treating incident response as simply cleaning up a computer and getting everyone working again. Depending on the circumstances, the business may need to understand what happened and preserve information before remediation changes the environment.
Incident response deserves a much deeper discussion than I can give it in this article, so I will be covering incident response planning for small businesses separately.
How Do You Choose IT Support for a Small Business?
I would start with the problem rather than the package.
What you're trying to figure out | A possible starting point |
“We don't really know what technology we have anymore.” | IT Baseline Assessment |
“We're not sure Microsoft 365 is configured or secured correctly.” | Microsoft 365 Audit / Tenant Security Review |
“We only need someone to manage Microsoft 365.” | Specialized Microsoft 365 management |
“We have both Microsoft 365 and Google Workspace and don't know which direction to go.” | Platform, identity, workflow, and data review |
“We only need IT help occasionally.” | Hourly / T&M support |
“We have a specific technology project.” | Project based IT |
“We handle the simple things but need help with the difficult IT work.” | Shared or co-managed IT |
“We want someone to take ongoing responsibility for our technology.” | Managed IT |
“We want to get rid of our server or move more systems to the cloud.” | Cloud and infrastructure assessment and planning |
“We want to start using AI but aren't sure how it fits into our business.” | AI use case, governance, security, and technology readiness review |
“We're growing into regulatory or contractual requirements.” | Identify the applicable requirements, assess the technical environment, then build an implementation plan |
“Our cyber insurance questionnaire is asking things we can't confidently answer.” | Technical verification and cyber insurance readiness review |
“We don't know what happens if we have a cybersecurity incident.” | Incident response planning |
This is why I do not think computer count alone is a particularly useful way to decide what kind of IT support a business needs. Two companies with ten employees can have completely different technology environments and completely different risks.
Questions I Would Ask Before Hiring an IT Provider
Whether you are considering SNL-Tech Services or another provider, I would want clear answers to questions like these:
What exactly are you responsible for?
What remains our responsibility?
Can we keep certain IT responsibilities internally?
Who manages Microsoft 365 or Google Workspace?
Who manages our computers and other endpoints?
Do you use an RMM or another centralized management platform?
Who is responsible for operating system and application updates?
Who receives and reviews security alerts?
What happens when a security alert requires immediate attention?
Who verifies backups and handles recovery?
Who manages the firewall, network, wireless environment, and network segmentation?
Who handles employee onboarding and offboarding?
Who maintains our IT documentation?
Who deals with our ISP and other technology vendors when an issue crosses multiple systems?
Who is responsible for understanding how AI tools interact with company data and systems?
What happens during a cybersecurity incident?
What is included in the agreement and what is billed separately?
Who owns our domain, Microsoft 365 or Google Workspace environment, data, accounts, and documentation?
If we decide to change providers, how do we receive our credentials, documentation, and other information?
A provider does not necessarily have to answer every question with “we do.” The important part is that somebody has an answer.
A Simple IT Responsibility Matrix
One of the easiest ways to expose gaps is to write down who owns each responsibility.
IT Responsibility | Business | IT Provider | Shared |
Basic employee support | ☐ | ☐ | ☐ |
Advanced troubleshooting | ☐ | ☐ | ☐ |
Microsoft 365 / Google Workspace | ☐ | ☐ | ☐ |
User onboarding and offboarding | ☐ | ☐ | ☐ |
Device management | ☐ | ☐ | ☐ |
RMM and endpoint monitoring | ☐ | ☐ | ☐ |
Updates and patching | ☐ | ☐ | ☐ |
Security alert review | ☐ | ☐ | ☐ |
Servers | ☐ | ☐ | ☐ |
Firewall and network | ☐ | ☐ | ☐ |
Backups and recovery | ☐ | ☐ | ☐ |
Vendor coordination | ☐ | ☐ | ☐ |
IT documentation | ☐ | ☐ | ☐ |
AI governance and approved tools | ☐ | ☐ | ☐ |
Incident response | ☐ | ☐ | ☐ |
Technology planning | ☐ | ☐ | ☐ |
If nobody knows which box should be checked for several of those rows, that is useful information. It gives the business somewhere to start.
Is Managed IT Better Than Hourly IT Support?
Not automatically.
Managed IT can make a lot of sense when a business has enough employees, devices, infrastructure, security requirements, support needs, vendors, and ongoing changes that someone needs to assume broader responsibility for the environment. It can also make budgeting more predictable and reduce the amount of technology coordination that falls back onto the owner or office manager.
support can make sense for a smaller or stable business that does not generate enough ongoing work to justify a broader managed agreement. Project based support can make sense when there is a clearly defined technical objective. Specialized management can make sense when the company only needs outside expertise for Microsoft 365 or another particular area. Shared management can work very well when an owner or internal employee wants to remain involved.
What matters is whether the arrangement matches the business.
A company can pay a monthly managed IT fee and still have gaps if important responsibilities are not actually included or nobody is doing the work. A company can use hourly support and still have a thoughtfully configured environment if responsibilities, monitoring, maintenance, and response expectations have been deliberately established.
Frequently Asked Questions
Does a Small Business Need Managed IT?
Not every small business needs a comprehensive managed IT agreement. The right model depends on the complexity of the systems the company relies on, how frequently employees need support, the security and compliance requirements involved, and how much ongoing responsibility the business wants an outside provider to assume.
Can I Hire an IT Provider Only to Manage Microsoft 365?
Yes. A business can outsource management of a particular platform or technical area without outsourcing all of its IT. Microsoft 365 can be reviewed through a Microsoft 365 Audit and can also be managed as a specialized part of the company's technology environment.
Can My Employees or I Still Handle Some IT if We Have Managed IT?
Yes, if the responsibilities are clearly defined. A shared or co-managed arrangement can allow an owner or internal employee to handle routine issues while an outside IT provider manages infrastructure, endpoints, security, servers, cloud platforms, or more complicated troubleshooting.
Is Hourly IT Support the Same as Break Fix IT?
Not necessarily. Traditional break fix is reactive, with the provider generally becoming involved after something fails. Hourly or T&M support can still include a properly configured environment and agreed monitoring or response responsibilities. The important distinction is what the provider has actually agreed to manage between support calls.
Should My Business Use Microsoft 365 or Google Workspace?
Both can be appropriate for small businesses. The decision should consider the applications employees use, existing identities and devices, collaboration needs, security requirements, data location, regulatory or contractual obligations, and the company's future direction. If a business already has both, I would first determine why each platform exists before recommending consolidation.
Does Using AI Change What Kind of IT Support My Business Needs?
It can. AI adoption introduces questions about approved tools, accounts, business data, identity, permissions, integrations, security, governance, and employee use. A business may not need full managed IT simply because it adopts AI, but somebody should be responsible for understanding how those tools fit into the company's existing technology and data practices.
When Should a Small Business Move to the Cloud?
There is no universal point at which every small business should move everything to the cloud. The decision depends on applications, workflow, internet reliability, security, backup, costs, regulatory requirements, and whether any systems still depend on local infrastructure. A hybrid environment may be the better choice for some businesses.
What if I Don't Know What Kind of IT Help We Need?
That is a normal starting point. An IT Baseline Assessment can help establish what technology exists, how the pieces fit together, what deserves attention, and where the business may need deeper expertise. You do not need to diagnose the IT problem before asking for help.
Can an IT Provider Help When New Compliance Requirements Apply to Our Business?
An IT provider can help assess the technical environment, implement applicable technical controls, manage systems, and document configurations. The exact requirements should first be determined from the applicable law, regulation, contract, framework, insurer, or qualified compliance professional. Technical implementation should not be confused with legal advice, certification, or a formal compliance assessment when those require another specialist.
Who Should Own Our Technology if We Outsource IT?
The business should retain appropriate ownership and recovery control over its technology assets, accounts, data, and documentation. An IT provider can manage those systems without becoming the only party capable of accessing or recovering them.
What Happens When an IT Problem Involves Several Vendors?
That depends on the support arrangement. Vendor coordination is part of how I work with my managed IT clients. I act as the technical point of contact and work between the appropriate providers rather than requiring the business owner to troubleshoot which vendor is responsible.
Start With the Problem, Not the IT Package
You do not need to know whether you need managed IT, hourly support, Microsoft 365 management, a cloud migration, AI governance, or something else before talking to an IT provider. Figuring that out should be part of the conversation.
When I talk with a business owner, I want to understand what the company is trying to accomplish, what technology it has today, where the frustration or uncertainty is coming from, what information the business depends on, what responsibilities someone needs to own, and where the company is going next.
Sometimes the answer is managed IT. Sometimes it is an IT Baseline Assessment or Microsoft 365 Audit. Sometimes the business needs a cloud project, specialized platform management, hourly support, vendor coordination, AI planning, compliance related technical implementation, or simply a clearer division of responsibility.
What matters to me is that the technology becomes intentional and that the business knows who is responsible for keeping it that way.
That is also what I mean when I describe SNL-Tech Services as an IT Partner rather than another technology vendor. Sometimes the most useful thing I can give a business owner is not another product or another help desk number. It is knowing that when something becomes complicated, there is someone who understands the environment, takes ownership of the responsibilities we agreed on, documents what happens, works with the other vendors involved, and helps the business determine what should happen next.
ADDITIONAL RESOURCES
NIST Cybersecurity Framework 2.0: Small Business Quick Start Guide
A practical NIST resource for small businesses covering cybersecurity governance, responsibilities, legal and contractual requirements, protection, detection, response, and recovery.https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1300.pdf
NIST: Building Your Small Business Cybersecurity Team, From In-House to Outsourcing
NIST guidance covering different ways small businesses can structure cybersecurity responsibilities, including internal staff, outside providers, and combinations of both.https://www.nist.gov/itl/smallbusinesscyber/guidance-topic/building-your-team
CISA: Assisting Small and Medium-Sized Businesses Assess Vendors and Suppliers
Guidance for evaluating technology vendors, cloud providers, managed service providers, and other suppliers that may have access to important business systems and data.https://www.cisa.gov/resources-tools/resources/assisting-small-and-medium-sized-businesses-assess-vendors-and-suppliers-fact-sheet
NIST Small Business Cybersecurity Corner
Additional cybersecurity guidance and resources designed specifically for small and medium sized businesses.https://www.nist.gov/itl/smallbusinesscyber




Comments