| Small business IT support is the arrangement that gives a business without its own IT department access to monitoring, maintenance and a helpdesk, usually for a fixed monthly fee. What separates a good arrangement from a poor one is not the price. It is how much of the work is actually inside the scope, and how much is quietly nobody’s job. |
New Zealand is a country of very small businesses, and the statistic everybody quotes hides what that really means. It is true that around 97 percent of New Zealand enterprises have fewer than 20 employees. It is also true that most of those have no employees at all.
Stats NZ counted 617,330 enterprises at February 2025, and 74 percent of them had no paid staff. Sort the rest by size and the picture sharpens considerably. MBIE’s small business figures, drawn from that Stats NZ count, put 101,253 businesses in the one to five staff band and 43,068 in the six to nineteen band.

If your business has staff, a network and a shared system that everyone depends on, you are in a much smaller group than the 97 percent figure suggests. That group is the one this page is written for, and it is where small business IT support stops being a nice idea and starts being infrastructure.
What does small business IT support include?
Small business IT support should include monitoring, maintenance, a helpdesk your staff can reach, and someone accountable for the systems in between. In practice the list varies enormously between providers, which is why the scope matters more than the label.
A reasonable small business IT support arrangement covers most of the following, and a good provider will tell you plainly which ones it does not.
- Monitoring of servers, networks and devices, with somebody looking at the alerts rather than just collecting them.
- Helpdesk access for staff, through more than one channel, with a ticket raised every time.
- Security patching and software updates applied on a defined cycle rather than when someone remembers.
- Endpoint protection and email filtering, managed and monitored rather than installed and forgotten.
- Backup monitoring and restore testing, which are two different jobs and only one of them is usually happening.
- Account setup and removal when people join and leave.
- Hardware and licence lifecycle, so replacements are planned rather than urgent.
What is the difference between break-fix and managed support?
Break-fix means you pay per incident and nothing happens between incidents. Managed support means you pay a fixed monthly fee and the maintenance happens whether or not anything has broken.
The distinction that matters is not the billing model but the direction of the provider’s incentive. Under break-fix, a provider earns more when your systems fail. Under a fixed monthly fee, a provider earns more when they do not. Most small business IT support is sold on the managed model for exactly that reason. Our guide to proactive IT support covers what monitoring actually catches before it reaches anybody’s desk.
How much does small business IT support cost in New Zealand?
Nobody can tell you, and anyone who quotes you a market rate is quoting themselves. There is no independent New Zealand benchmark for what small business IT support should cost. No government agency publishes one, no industry body publishes one, and the Business Operations Survey that used to ask New Zealand firms about their ICT arrangements has been paused since 2024.
That absence gets filled by provider price lists presented as market guidance. Every published per-user figure in this market comes from a company with a commercial interest in where the number lands, including ours. So treat any price range you find, on any website, as a sales position rather than a benchmark.
What should you compare instead of price?
Compare scope. Two small business IT support quotes at the same monthly price can differ by thousands of dollars a year once you account for what each one bills separately, and the gap only becomes visible after you have signed.
The practical method is to work out your total current IT spend across every line, not just the support fee, then establish which of those lines your agreement actually covers. Most businesses find the total is larger than they thought and the covered portion smaller. We have put that exercise into a worksheet you can fill in yourself.
Download the IT spend and scope worksheet
Word document, six pages, no email address required.

What are you still responsible for when you outsource IT?
You remain responsible for the personal information your business holds, even when a provider is the one holding it. This is the part of small business IT support that gets least attention and carries the most legal weight, and it is settled New Zealand law rather than anybody’s opinion.
Section 11 of the Privacy Act 2020 deals with information held by one agency on behalf of another. Where your IT provider holds personal information for you and does not use it for its own purposes, the Act says that information is to be treated as being held by you, and not by them. The Office of the Privacy Commissioner puts it more directly in its guidance on third-party providers: your organisation remains fully responsible for what happens to that information, and the third party is you for the purposes of the Act.

One consequence of that catches businesses out. Reporting a notifiable privacy breach is your obligation, not your provider’s, and the Privacy Commissioner generally expects to be told within 72 hours of the breach becoming known. That period starts when your provider knows about the breach, not when your provider gets around to telling you. If your agreement does not say how quickly they must tell you, your clock is already running while you wait.
What should be in the agreement with your provider?
The Office of the Privacy Commissioner lists five things an agreement with a third-party provider should cover. They are worth checking against whatever you signed, because most small business IT support agreements address one or two of them and go quiet on the rest.
| What the agreement should cover | What that means in practice |
|---|---|
| Appropriate security measures | Named controls, not a general assurance that security is taken seriously. |
| Access and correction requests | How the provider helps when someone asks what information you hold about them. |
| Breach notification process and timeframe | How fast they must tell you, in hours. Your 72 hours starts when they know. |
| Compliance with privacy law | An express obligation, so it is a contract term rather than an expectation. |
| What they may do with your information | The limit that keeps section 11 working the way you think it does. |
There is no small business exemption in the Privacy Act, and no small business IT support contract can create one. What the law asks for is security safeguards that are reasonable in the circumstances, and everything reasonably within your power to prevent unauthorised use or disclosure when information is given to someone providing a service to you. What counts as reasonable for a five-person firm is not what counts for a bank. It is not nothing either.
What IT risks actually affect small businesses in New Zealand?
The risks that actually reach small businesses are the ordinary ones: credential theft, phishing, unpatched systems and accounts that nobody closed. The exciting threats get the headlines and the dull ones cause the incidents. Small business IT support earns its fee on the dull ones.
New Zealand’s National Cyber Security Centre received 5,995 incident reports in the year to June 2025, and its own figures are worth reading carefully. Most of those reports came from individuals rather than organisations, and 94 percent of triaged incidents were graded minor. Direct financial loss reported to the agency totalled $26.9 million, which the NCSC itself describes as indicative only. None of that tells you how often small businesses are attacked, and any article claiming otherwise is reading a caseload as a rate.
What the NCSC data does show is how compromises happen. In August 2025 the agency investigated a report covering 19 New Zealand organisations whose devices had been compromised by a suspected ransomware group, and found that every one of the compromised devices was exposed to the same known vulnerability. The organisations included small businesses, councils and managed service providers.
That is the useful lesson, and it is not a flattering one for the industry. Those organisations were not selected for being small or weak. They were found by a scan that looked for one unpatched thing and took whoever had it. Patching is unglamorous work that produces no visible result when it goes well, which is exactly why it is the work most likely to have stopped happening.
Which controls actually reduce the risk?
Multi-factor authentication, current patching, tested backups and prompt account removal do more than anything else available to a business of this size. The NCSC’s own case studies keep landing on the same two causes: a service without multi-factor authentication, and a device left exposed to a vulnerability that already had a fix.
None of those four controls is expensive. All four are things a small business IT support arrangement should be doing without being asked, and all four are things you can verify are happening. Backups are the one worth checking yourself, because monitoring that a backup ran is not the same as proving a file can come back. Our guide to backup and recovery planning sets out what a restore test involves.
How do you tell what your support contract actually covers?
Write down every job that has to happen, then put a person’s name against each one. Not a company name, a person. The gaps appear immediately, and they are rarely where the business expects.
Most small businesses can list what they pay for. Rather fewer can say which of it sits inside the small business IT support agreement and which is billed on top. Almost nobody can name who does the work that never appears on any invoice, and that is the category where things go wrong.
Ten jobs are worth testing. Who applies security updates to computers, and to servers and network gear? Who checks that backups ran, and who has actually restored a file to prove it works? Who removes accounts when someone leaves, and who reviews administrator access? Who holds the master password for the domain name, and the administrator credentials for Microsoft 365? Who would notice a compromised machine, and who decides what happens in the first hour of an outage?
If two or three of those have no name against them, the finding is not that your provider is failing. It is that the work was never in scope and nobody said so. Closing that gap is what a small business IT support agreement is for.
How do you get more from your technology budget?
Start by finding what you are paying for twice. Duplicate licences, overlapping security products and subscriptions nobody cancelled are the most common waste in a small business IT budget, and none of them show up until somebody lists every line in one place.
After that, three things usually move the number. Consolidating licences where two products do one job. Replacing end-of-life hardware on a planned cycle rather than in a panic, because emergency replacement always costs more and always happens at the worst time. And moving services to where they are actually cheaper to run, which is sometimes the cloud and sometimes not.
What rarely helps is switching small business IT support providers on price alone. If the scope is different, the cheaper quote is cheaper because it covers less, and the difference surfaces as separate invoices within the first year. That is the whole argument for comparing scope rather than headline figures, and it is why the worksheet above is structured the way it is.
Where should you look first?
Look at what is billed outside the monthly fee over the last twelve months. If project and hourly work adds up to a large fraction of what you paid in support fees, either the scope is too narrow for how your business actually runs, or work is being reclassified as projects. Both are worth a conversation, and both are invisible until somebody adds the invoices up.
If you would rather have someone else do that analysis with your systems in front of them, that is what an IT assessment is for.
How do you judge a provider once the scope is clear?
Scope tells you what a provider has agreed to do. Judging how well a small business IT support provider does it is a separate exercise, and it turns on response and resolution targets, how first contact resolution is defined, and what monthly reporting you actually receive. We have covered that ground in detail, including why a first contact resolution percentage quoted without a definition tells you nothing, in our guide to what a good IT helpdesk commits to.
Do the scope work first. A small business IT support provider who performs brilliantly against a narrow contract is still leaving the other work undone.
Frequently Asked Questions
What is small business IT support?
Small business IT support is an arrangement that gives a business without its own IT department access to monitoring, maintenance and a helpdesk, normally for a fixed monthly fee. It typically covers patching, endpoint protection, backup monitoring, account administration and day to day fault resolution. What it covers in your case depends entirely on what your agreement says, which is why scope is worth checking line by line.
How much does small business IT support cost in New Zealand?
There is no independent New Zealand benchmark. No government agency or industry body publishes one, and the national survey that asked businesses about their ICT arrangements has been paused since 2024. Every per-user price published for small business IT support in this market comes from a provider quoting its own rates. Compare what each quote includes and what it bills separately, because two quotes at the same monthly price can differ by thousands of dollars a year.
Do most New Zealand businesses have their own IT staff?
Very few could. Stats NZ counted 617,330 enterprises at February 2025 and 74 percent of them had no paid employees at all. Only about 43,000 businesses have between six and nineteen staff. At that size an internal IT hire is rarely practical, which is why small business IT support is bought in as the normal arrangement rather than as a compromise.
Is my business still responsible for privacy if my IT provider holds the data?
Yes. Under section 11 of the Privacy Act 2020, where a provider holds personal information on your behalf and does not use it for its own purposes, that information is treated as held by you rather than by them. The Office of the Privacy Commissioner states that your organisation remains fully responsible for what happens to it. Outsourcing the work to a small business IT support provider does not outsource the obligation.
How quickly must a privacy breach be reported?
The Privacy Commissioner generally expects to be told about a notifiable privacy breach within 72 hours of it becoming known. The important detail is when that period starts: it runs from when your provider knows about the breach, not from when they tell you. If your agreement sets no timeframe for the provider to notify you, that is a gap worth closing before it matters.
What is the difference between break-fix and managed IT support?
Break-fix charges per incident, with nothing happening between incidents. Managed support charges a fixed monthly fee and includes ongoing monitoring and maintenance. The practical difference is the direction of the incentive. A break-fix provider earns more when systems fail, and a managed small business IT support provider earns more when they do not.
Are small businesses targeted more often than large ones?
Nobody can answer that from New Zealand data, and claims that they are targeted because of weaker defences are not supported by any source we could verify. What the NCSC’s published cases show is exposure rather than selection. In one August 2025 investigation, 19 New Zealand organisations were compromised through the same known vulnerability, found by scanning rather than by choosing targets.
What security should be included in small business IT support?
At minimum, multi-factor authentication, current patching on a defined cycle, managed endpoint protection, email filtering, and backups that are tested by restoring something. Confirm each one is inside the contract rather than assumed, because security items are the ones most often sitting just outside small business IT support scope. That gap usually becomes visible after an incident rather than before one.
How do I know whether my backups actually work?
Ask when someone last restored a file, not whether backups are running. Monitoring confirms a job completed, which is not the same as proving data can come back. If nobody can name a date in the last twelve months when a restore was performed and checked, you have a backup nobody has tested and you will find out whether it works on the worst possible day.
Who should hold the administrator passwords for my systems?
Your business should always hold or be able to obtain the master credentials for anything it depends on, particularly the domain name registration and your Microsoft 365 or Google Workspace tenant. A small business IT support provider holding administrative access is normal and sensible, but it should be through named individual accounts that can be logged and revoked, not a single shared login, and never to the exclusion of your own access.
Should a small business use a local or a national IT provider?
Remote support handles the large majority of faults regardless of where the provider sits, so the question really concerns the minority that needs somebody physically present. Ask how quickly a person can arrive, whether that travel is included or billed, and who attends after hours. Distance matters less to small business IT support than the terms do. Get the answer before you need it rather than during an outage.
What should I do before changing IT provider?
Before changing small business IT support provider, establish what you currently pay across every line, what is inside the existing agreement, and what has quietly become nobody’s job. Then ask each candidate to respond to that list rather than to a generic brief. Also check the exit terms of your current agreement, specifically what data, documentation and system configurations come back to you and how long that takes.
NEXT STEP
Find out what your current support actually covers
An IT assessment establishes what your small business IT support actually costs, what is inside your agreement, and which jobs have no owner. You get the findings whether or not you work with us. Christchurch, Dunedin and across the South Island.
Or read more about our managed IT services.

