
Proactive IT support is a phrase almost every provider in this market uses. Buyers are right to have stopped hearing it. The claim costs nothing to make. None of it can be checked from a website. So here is a version that can be tested: the provider acts on a system’s condition before a person reports a fault. The provider can also produce the figures showing it happened. Monitoring, patching, and a scheduled review are the mechanics. Whether they are running is a question with numbers behind it. In fact, the numbers are easy to ask for.
Proactive IT support has a definition you can test
The NCSC draws the line in its vulnerability management guidance, where the goal is for system and software updates to be a ‘business as usual’ control. Additionally, a mature process separately ‘allows you to react quickly when a critical vulnerability is disclosed’. Two modes, both necessary, one of them scheduled.
The distinction moves the question off the tooling. Every provider in this market runs the same remote monitoring platforms. What differs is whether the scheduled half is evidenced. Evidence means a figure with a date on it. Our earlier piece on preventative maintenance and downtime covers the mechanics of the work itself. What follows is how to check it is being done.
The government’s own cost figure argues against how this gets sold
The Cyber Security Breaches Survey 2025/2026 found 43% of businesses had experienced a breach or attack in the previous twelve months. It also found the median perceived cost of the most disruptive one was £0, with the middle half of businesses reporting between £0 and £200.
That figure deserves quoting by somebody selling the service, because it kills the usual argument. The typical incident at a small UK business costs nothing measurable. A provider implying otherwise is guessing.
The honest case sits in two other numbers from the same survey. At the 95th percentile the cost reaches £4,000 for micro and small businesses and £10,000 for medium and large ones. So the risk lives in the tail instead of the average. And the breach rate climbs steeply with headcount: 42% of micro businesses, 46% of small, 65% of medium and 69% of large. Growing from twelve people to forty changes your exposure more than any single control you buy.
Patch latency is the first number to ask for
The NCSC’s guidance on keeping devices and software up to date sets the expectation plainly: ‘Install updates promptly when notified – ideally within a few days.’ It also says automatic updates should be enabled everywhere possible. Then it adds the part that matters for anyone paying a provider. ‘Check occasionally that your device is keeping itself up to date, as automatic updates can sometimes break.’
Automatic updates fail quietly. A laptop that never restarts, one short of disk space, one off the network for a fortnight: each stops updating while reporting itself healthy. The same page tells organisations to ‘monitor the status of device and software updates using MDM logs or compliance policies’, which is a monthly report. This is a report your provider can already produce.
So the question is what percentage of your devices were fully up to date at the close of last month, and how long the oldest outstanding critical update had been sitting there. A provider doing scheduled work has both figures. A provider doing reactive work has neither, because nobody has needed them.
Monitoring coverage, and the machine nobody is watching
The second number is simpler and catches more. How many devices does the business own, and how many are carrying the monitoring agent?
The NCSC’s vulnerability management guidance puts identifying your assets among its core steps. This is on the grounds that a process only works where you understand ‘which vulnerabilities are present in your technical estate’. In practice the gap between those two counts is where the incidents happen. For example, the reception PC nobody logs into, the server in the cupboard that predates the current provider, or the laptop issued to someone who left.
The third number follows from it. Which systems run software the vendor no longer supports? The guidance is direct that you ‘should replace unsupported software and devices as soon as you are able’, and an unsupported machine is what monitoring cannot fix. Whether the work sits inside the business or outside it is a separate decision. This is covered in our piece on in-house versus outsourced support.
The quarterly review is where proactive IT support becomes visible
The fourth number is the one most businesses fail. Only 25% of UK businesses have a formal incident response plan, according to the same survey: 21% of micro businesses, rising to 57% of medium and 76% of large. Meanwhile, 44% of micro businesses now use an external cyber security provider, up from 39% the year before.
Read those together and a gap appears: more small businesses are buying managed security than hold the document it should have produced. If a provider has held the account for two years and there is still no written response plan, the scheduled half of the work has not been happening. This is true whatever the monitoring dashboard shows.
A review that produces nothing in writing is a meeting. The fifth number shows how many actions came out of the last review and how many the team has since closed.
Five questions to put to your provider, including us
- What percentage of our devices were fully up to date at the close of last month?
- How many devices do we own, and how many carry your monitoring agent?
- Which of our systems run software the vendor no longer supports, and what is the plan for each?
- Where is our written incident response plan, and when was it last revised?
- What actions came out of our last review, and how many are closed?
A provider who cannot answer the first two is selling the word. Ask for the response commitment on a critical fault in writing. Since a contracted figure behaves differently from one offered in a meeting, nobody needs to score five out of five. A provider who says ‘we do not currently report that, and here is when we will start’ has given you a better answer than a confident number with nothing behind it.
We are a Newcastle-based provider and we publish what we commit to: pricing per user instead of per device, a fixed response time for critical requests, proactive patching and out-of-hours planned maintenance, replication with recovery available inside the hour, and quarterly meetings with a named account manager. Our IT support and systems monitoring service sets out what sits in the monthly cost. The first conversation answers those five questions about your own estate.
