top of page

Managed IT Should Include Cybersecurity by Default, Not as an Add-On

There used to be a tidy line between two jobs. "IT support" kept your computers working, and "cybersecurity" was a separate, specialist concern you thought about later, if at all. That line has quietly disappeared, and any managed IT provider still drawing it is behind the times. Today, keeping your systems running and keeping them secure are the same job, and a provider who sells you the second as an upsell on top of the first is either behind the curve or charging you twice for one thing.


This article explains why the two have merged, what a modern managed IT service should include as standard, and how to tell a provider who gets this from one who is still living in the old model. If you are being quoted for IT support and then quoted separately for security, this is worth reading before you sign anything.


Laptop wrapped in heavy chains and a padlock with a blank tag on a dark surface, symbolizing security or restriction

Where Did the Line Between IT Support and Cybersecurity Go?

It went the moment nearly every attack started coming through ordinary, everyday IT. Consider what actually breaches businesses now. In the UK's official Cyber Security Breaches Survey, 85% of businesses that suffered a breach identified phishing, an ordinary email, as the cause, and phishing is consistently the most disruptive type of attack. The other common routes, unpatched software, stolen passwords, misconfigured settings, are all things that used to sit under plain "IT support". You cannot look after a company's email, devices, updates and logins without those being security tasks, because that is precisely where the attacks land.


The scale makes it unavoidable. Around 43% of UK businesses identified a cyber breach or attack in the past year. Small businesses accounted for 42% of all breaches and medium-sized firms 67%, which puts to bed the idea that only large companies need to worry. When close to half of businesses are being hit, and the hits come through routine IT, treating security as a bolt-on is like treating brakes as an optional extra on a car.


Why Can't the Two Be Separated Any More?

Because every core IT task is now also a security task, and doing one without the other leaves a gap an attacker walks through. Patching software is IT maintenance and the single most effective way to close the holes attackers exploit. Managing who can log in to what is IT administration and the front line against stolen passwords. Looking after email is a daily support job and the main battleground for phishing. Backing up data keeps the business running and is your survival plan for ransomware. Split these apart, hand the "IT" half to one arrangement and leave the "security" half as an optional purchase, and you get exactly the gaps that recent attacks have exploited, where a business thought it was protected but a control was never switched on or never covered every route in.


The market has noticed even if some providers have not. Cybersecurity is now the number one reason organisations turn to a managed provider in the first place, cited by around 60% of them, as firms outsource protection they cannot resource in-house. When security is the main thing customers actually want, selling it as an afterthought makes little sense.


What Does a "Security as an Add-On" Model Actually Cost You?

Glowing blue lock icon on a computer motherboard, symbolizing cybersecurity and protection, with dark circuit details.

Two things, one obvious and one hidden. The obvious cost is money. When a provider itemises MFA, endpoint protection, monitoring and training as separate line items on top of a base support fee, you are paying twice for what should be one joined-up service, and you are paying the margin on each extra. The hidden cost is worse. When security is optional, it becomes the thing that gets declined to save budget, or quietly left off the quote, and the business ends up "supported" but exposed. An add-on model also tends to mean the security pieces are not properly connected to each other or to the day-to-day IT, so nobody has the full picture and things fall between the cracks. You pay more and you are less safe, which is the worst of both.


What Should Be Included in Managed IT by Default?

A modern managed service should treat these as the core of the offer, not extras. At minimum, look for:


  • Multi-factor authentication and proper access control, set up to cover every user and every way into your systems, not just the obvious login.

  • Endpoint protection on every device, so laptops and computers are actively defended rather than just maintained.

  • Regular, prompt patching of operating systems and applications, because unpatched software is one of the most common ways in.

  • Phishing awareness training for staff, given that people, not machines, are the most common target. Only 39% of UK SMEs currently provide any security training, which is why human error remains the biggest risk.  

  • Continuous monitoring and backup, so unusual activity is spotted early and you can recover quickly if something gets through.


None of these are exotic. They are the basics of staying safe in 2026, and they belong inside the core service. Our own managed virtual desktop and security service is built with least-privilege access, enforced multi-factor authentication, backup and rapid restore included as standard rather than sold on the side, and the monitoring and conditional-access approach behind it is described in our overview of virtual desktops and Desktop as a Service in 2026.


Why Do Some Providers Still Sell It Separately?

In fairness, there are reasons, though none of them serve you. Many providers grew up in the old "break-fix" model, where they fixed things when they broke and security genuinely was a separate specialism, and they have not fully rebuilt around the new reality. Splitting security out also makes the headline support price look cheaper in a quote, which wins deals against providers who include it, even though the customer pays more in the end. And some smaller providers simply lack the in-house security skills, so they treat it as an optional extra they can buy in when asked. Understandable as history, but it leaves you carrying the risk.


How Do You Tell a Modern Provider From a Behind-the-Curve One?

Ask direct questions and watch how they answer. Does the core service include MFA, endpoint protection, patching, staff training and monitoring, or are those separate line items? If security is extra, what exactly am I unprotected against if I decline it? Who is watching for suspicious activity, and how would I find out if something happened? Do you help us meet standards like Cyber Essentials as part of the service? A provider who bundles protection into the core offer, and can explain plainly what it covers, is one who understands the job. A provider who reaches for the upsell sheet the moment you mention security is telling you they still see it as someone else's problem, which means it will end up being yours.


The Bottom Line

The question is no longer "do we want IT support or cybersecurity?" because there is no meaningful difference between them any more. Keeping your business running and keeping it safe are one job, done by one provider, as one service. If your current arrangement, or a quote in front of you, splits them apart and prices security as an optional extra, you are looking at an outdated model that costs you more and protects you less. Look for the provider who includes protection by default, and treat "security is an add-on" as the warning sign it has become.


Because the threat landscape shifts quickly, this is a topic worth revisiting each quarter to keep the figures and the advice current.

Comments


Contact Us

Thanks for submitting!

Have a question you want answered quicker?

Give us a ring or try our online chat!

Tel. 02039064600

Please do not block Caller ID so our team can assist you faster.

  • LinkedIn
  • Facebook
  • Instagram
  • Twitter

© 2026 SystemsCloud Group Ltd.

bottom of page