Small Business IT Support: Costs, Coverage and Responsibilities

Small business IT support is outside help that keeps a business’s staff, devices and systems working. It can be occasional help when something breaks, an ongoing managed arrangement for a monthly fee, or extra capacity alongside an internal IT person. What matters is knowing what your arrangement covers, what costs extra and who is responsible for each task.

 

This guide helps you compare small business IT support arrangements on those details. Start with the scope checklist below, or download the free IT spend and scope worksheet to review your current arrangement.

Looking for ongoing small business IT support? See Exodesk’s managed IT services for businesses in Christchurch, Dunedin and across New Zealand.

What does small business IT support include?

Small business IT support can include day-to-day help for staff, monitoring and maintenance, security, and recovery support when something goes wrong. The list varies between providers and between agreements, so the scope matters more than the label.

Use the list below to check what your small business IT support arrangement covers, and ask any provider to say plainly which items it does not.

  • Monitoring of servers, networks and devices, with somebody looking at the alerts rather than just collecting them.
  • Helpdesk access for staff, through more than one channel, with a ticket raised every time.
  • Security patching and software updates applied on a defined cycle rather than when someone remembers.
  • Endpoint protection and email filtering, managed and monitored rather than installed and forgotten.
  • Backup monitoring and restore testing, which are two different jobs: one confirms a backup ran, the other proves the data comes back.
  • Account setup and removal when people join and leave.
  • Hardware and licence lifecycle, so replacements are planned rather than urgent.

 

What is the difference between break-fix and managed support?

Break-fix support is charged when help is needed. Managed support includes an agreed set of ongoing services, such as monitoring, patching and helpdesk access, for a recurring fee.

Either kind of small business IT support can include planned work or response commitments, so check the scope rather than relying on the label. A fixed fee gives a provider a reason to prevent problems rather than bill for fixing them, but the agreement and how it is delivered decide what happens in practice. Our guide to proactive IT support covers what monitoring can catch before it reaches anybody’s desk.

Who is this guide written for?

Stats NZ counted 617,330 enterprises in New Zealand at February 2025, and about 74 percent of them had no employees. MBIE’s small business figures, drawn from that count, put 101,253 businesses in the one to five staff band and 43,068 in the six to nineteen band.

Bar chart of New Zealand enterprises by employee count showing most have no staff at all

If your business has staff, a network and shared systems that everyone relies on, this guide is for you, whether your small business IT support is occasional help, a managed provider or outside support alongside your own IT person.

How much does small business IT support cost in New Zealand?

The cost of small business IT support depends on the people, devices and systems covered, the support hours and the work included. A monthly fee may cover routine support and maintenance, while software licences, hardware, projects and after-hours work are charged separately.

Ask each small business IT support provider to quote against the same written requirements. Compare the annual support fee, recurring extras and expected one-off work, with GST treated the same way in every quote. Check minimum charges, contract terms, price reviews and exit costs. The useful comparison is what you will pay for the coverage your business needs.

A price published by any provider describes that provider’s offer for its stated scope. It can be useful for that scope, but it is not a market benchmark.

What should you compare alongside price?

Compare three things separately in any small business IT support arrangement: what is purchased, what is managed and who must act. A licence billed separately can still have a clear owner, and a line included in the monthly fee can still be poorly managed.

The practical method is to list your total IT spend across every line, not just the support fee, then establish for each line whether it is included in the fee, who manages it and who acts when it needs attention. We have put that exercise into a worksheet you can fill in yourself.

Download the IT spend and scope worksheet

Word document, free, no email address required.

Three columns comparing what is inside a small business IT support contract, what is billed separately and what has no clear owner

What are you still responsible for when you outsource IT?

You remain responsible for the personal information your business holds, even when your small business IT support provider stores or processes it for you. This is the part of outsourcing with legal consequences, and it is worth understanding before you sign.

Section 11 of the Privacy Act 2020 deals with information held by one agency on behalf of another. Where your IT provider holds personal information for you and does not use it for its own purposes, the Act says that information is to be treated as being held by you, and not by them. The Office of the Privacy Commissioner puts it more directly in its guidance on third-party providers: your organisation remains fully responsible for what happens to that information, and the third party is you for the purposes of the Act.

The position changes if a provider also uses or discloses the information for its own purposes. In that case both organisations can have obligations under the Act, so check what your agreement allows the provider to do.

Diagram showing personal information moving to an IT provider while Privacy Act responsibility stays with the business

Notifying a privacy breach is your obligation. A breach is notifiable when it has caused, or is likely to cause, serious harm. The Act requires you to tell the Privacy Commissioner as soon as practicable after becoming aware of a notifiable breach, and to tell the affected people unless an exception applies. The Commissioner expects notification within 72 hours, which it describes as a guide rather than a fixed legal deadline.

When that awareness begins matters. The Commissioner treats information known by your employees or agents, including third-party providers, as known by your business, and its guidance says the 72-hour period starts when the provider knows about the breach, not when they tell you. Your small business IT support agreement should require the provider to tell you promptly, with named contacts and an escalation route, so assessment and notification are not held up between organisations.

What should be in the agreement with your provider?

The Office of the Privacy Commissioner lists five things an agreement with a third-party provider should cover. Check them against whatever you signed.

What the agreement should cover What that means in practice
Appropriate security measures Named controls, not a general assurance that security is taken seriously.
Access and correction requests How the provider helps when someone asks what information you hold about them.
Breach notification process and timeframe Prompt notification of breaches affecting your information, with named contacts and escalation.
Compliance with privacy law An express obligation, so it is a contract term rather than an expectation.
What they may do with your information The limit that keeps section 11 working the way you think it does.

 

The same guidance recommends agreeing what happens to the information when the agreement ends: whether it comes back to you, how it is disposed of and whether deletion includes backups. It also recommends requiring the provider to make sure any subcontractors protect the information to the same standard.

There is no small business exemption in the Privacy Act, and no small business IT support contract can create one. What the law asks for is security safeguards that are reasonable in the circumstances, and everything reasonably within your power to prevent unauthorised use or disclosure when information is given to someone providing a service to you. What counts as reasonable for a five-person firm is not what counts for a bank. It is not nothing either.

What IT risks actually affect small businesses in New Zealand?

The risks with the clearest evidence behind them are the ordinary ones: credential theft, phishing, unpatched systems and accounts that nobody closed. These are also the areas where day-to-day small business IT support makes a difference.

New Zealand’s National Cyber Security Centre received 5,995 incident reports in the year to June 2025, and its figures are worth reading carefully. Individuals made 4,343 of those reports and organisations 1,321, and 94 percent of triaged incidents were graded minor. Direct financial loss reported to the agency totalled $26.9 million, and the NCSC notes that not all financial loss is reported or recorded. None of that tells you how often small businesses are attacked, because a count of reports is not an attack rate.

What the NCSC data does show is how compromises happen. In August 2025 the agency investigated a report that devices owned by 19 New Zealand organisations had been compromised by a suspected ransomware group, and found that all the compromised devices were exposed to the same known vulnerability. The organisations included small businesses, councils and managed service providers.

The useful lesson is about exposure. The report does not say how the attackers found those devices, but one known vulnerability, left unpatched, was the common factor across very different organisations. Patching produces no visible result when it goes well, which is why it is worth checking that it is still happening.

Which controls reduce the risk?

Multi-factor authentication, current patching, tested backups and prompt account removal are important foundations for a business of this size. The NCSC report names poor patching, weak credentials and misconfigured systems as easy entry points for attackers.

What each control costs and which comes first depends on your systems. Agree in writing which of the four your small business IT support arrangement covers, and check that each one is happening. Backups are worth checking yourself, because a completed backup job is not the same as proving a file can come back. Our guide to backup and recovery planning sets out what a restore test involves.

How do you tell what your support contract actually covers?

Write down every job that has to happen, then record who is responsible for each one: the organisation or team, the accountable role, how to reach them and who covers when they are away. Gaps show up quickly once the list is on paper.

Listing what you pay for is the easy part. The harder questions are which of it sits inside the small business IT support agreement, who manages it, and who does the work that does not appear on any invoice.

Ten jobs are worth testing. Who applies security updates to computers, and to servers and network gear? Who checks that backups ran, and who has restored a file to prove it works? Who removes accounts when someone leaves, and who reviews administrator access? Who controls the domain name registration, and the administrator access to Microsoft 365, with a documented way to recover each? Who would notice a compromised machine, and who decides what happens in the first hour of an outage?

If some of those have no clear answer, ask your provider to confirm in writing before drawing a conclusion. The work may be undocumented, may belong to someone who was not told, or may not have been in scope. Each job needs an owner, and settling that is what a small business IT support agreement is for.

How do you get more from your technology budget?

Start by finding what you pay for twice. Duplicate licences, overlapping security products and subscriptions nobody cancelled are easy to miss until somebody lists every line in one place.

After that, three things can move the number. Consolidating licences where two products do one job. Replacing end-of-life hardware on a planned cycle, because an unplanned replacement leaves less time to compare options and can arrive when the business can least afford the disruption. And running services where they cost least for how you use them, which is sometimes the cloud and sometimes not.

Switching small business IT support providers on price alone can backfire when the quotes cover different work. A lower quote may reflect a narrower scope, a more efficient provider or different commercial pricing, and you can only tell which by comparing the same requirements line by line. That is why the worksheet above is structured the way it is.

Where should you look first?

Look at what was billed outside the small business IT support fee over the last twelve months. If project and hourly work adds up to a large share of what you paid in support fees, find out why. It may reflect planned investment, growth or a migration. It may also mean the scope is narrower than the way your business runs, or that routine work is being charged as projects. Each is worth a conversation, and none is visible until somebody adds the invoices up.

If you would rather have someone else do that analysis with your systems in front of them, that is what an IT assessment is for.

How do you judge a provider once the scope is clear?

Scope tells you what a provider has agreed to do. How well a small business IT support provider does it is a separate question, and it turns on response and resolution targets, how first contact resolution is defined, and what monthly reporting you receive. Our guide to IT helpdesk SLAs and response times covers that ground, including why a first contact resolution percentage quoted without a definition tells you little.

Do the scope work first. A small business IT support provider who performs well against a narrow contract can still leave other work undone.

Frequently Asked Questions

What is small business IT support?

Small business IT support is outside help that keeps the staff, devices and systems of a business working. It can be occasional help when something breaks, an ongoing managed arrangement for a monthly fee, or extra capacity alongside internal IT staff. What it covers in your case depends on what your agreement says, so check the scope line by line.

How much does small business IT support cost in New Zealand?

The cost depends on the people, devices and systems covered, the support hours and the work included. A monthly fee may cover routine support and maintenance, while licences, hardware, projects and after-hours work are charged separately. Ask each provider to quote against the same requirements, then compare annual fees, recurring extras, one-off work and exit costs with GST treated the same way in each quote.

Does a small business need an internal IT person?

It depends on the workload, how complex your systems are and the skills already in the business. A business with standard cloud systems and a light workload may be well served by outside support alone. As systems and headcount grow, some businesses add an internal person for day to day needs and keep a provider for specialist work, security and cover. The right mix is the one where every task has a clear owner.

Is my business still responsible for privacy if my IT provider holds the data?

Yes. Under section 11 of the Privacy Act 2020, where a provider holds personal information on your behalf and does not use it for its own purposes, that information is treated as held by you rather than by them. The Office of the Privacy Commissioner states that your organisation remains fully responsible for what happens to it. Outsourcing the work to a provider does not outsource the obligation.

How quickly must a privacy breach be reported?

A breach is notifiable when it has caused, or is likely to cause, serious harm, and the Privacy Commissioner must be told as soon as practicable after you become aware of it. The Commissioner expects notification within 72 hours, but describes that as a guide rather than a fixed legal deadline. Knowledge held by your provider counts as knowledge held by your business, so your agreement should require the provider to tell you promptly. Affected people must also be told unless an exception applies.

What is the difference between break-fix and managed IT support?

Break-fix support is charged when help is needed. Managed support includes an agreed set of ongoing services, such as monitoring and patching, for a recurring fee. Either can include planned work or response commitments, so compare the scope rather than the label.

Are small businesses targeted more often than large ones?

New Zealand data does not answer that, and we could not verify any source showing that small businesses are chosen because of weaker defences. What the published NCSC cases show is exposure. In one August 2025 investigation, devices owned by 19 New Zealand organisations had been compromised, and all of them were exposed to the same known vulnerability.

What security should be included in small business IT support?

Multi-factor authentication, patching on a defined cycle, managed endpoint protection, email filtering and tested backups are important foundations. The right priorities and costs depend on your systems. Agree in writing which of these your arrangement covers, rather than assuming, so any gap is found before an incident.

How do I know whether my backups work?

Ask what was last restored, when it was tested and whether the recovered data was usable. A completed backup job and a successful recovery test are different checks. Test the files, applications and dependencies needed to resume work, with frequency based on their importance and on changes to the systems. One restored file does not prove the whole business can recover.

Who should hold the administrator passwords for my systems?

Your business should keep ownership of, and authorised administrator access to, anything it depends on, particularly the domain name registration and your Microsoft 365 or Google Workspace tenant, with a documented recovery route. A provider holding administrative access is normal and sensible. That access should be through named individual accounts that can be logged and revoked, not a single shared login, and should not replace your own access.

Should a small business use a local or a national IT provider?

Start with how onsite work is handled, since that is where distance makes a difference. Ask how soon a person can attend when remote help is not enough, whether travel is included or billed, and who attends after hours. Get those answers in writing before you need them rather than during an outage.

What should I do before changing IT provider?

Establish what you currently pay across every line, what is inside the existing agreement, and which tasks have no clear owner. Then ask each candidate to respond to that list rather than to a generic brief. Also check the exit terms of your current agreement, including what data, documentation and system configurations come back to you and how long that takes.

NEXT STEP

Find out what your current support actually covers

An IT assessment establishes what your small business IT support costs, what is inside your agreement and which tasks need a clear owner. You get the findings whether or not you work with us. Christchurch, Dunedin and across New Zealand.

Or read more about our managed IT services.

Start typing and press Enter to search

A staff member raising an IT helpdesk request and an engineer already responding to itOne person and a team both connected to the same business computer, showing the outsourcing choice Call Us Now