What Should an Insurance Agency Expect From a Managed IT Provider?
A complete managed IT plan for an insurance agency should cover at least 10 core service areas: responsive help desk support, proactive monitoring, patch management, cybersecurity, Microsoft 365 administration, backup and disaster recovery, employee onboarding and offboarding, vendor coordination, technology planning, and performance reporting.
For an agency with 25–50 employees, these services should operate as one coordinated system rather than a collection of unrelated products. The provider should protect sensitive client information, keep employees productive, support remote and onsite work, coordinate with insurance software vendors, and give agency leadership a clear technology roadmap.
The agreement should also state exactly what is included, what costs extra, when support is available, how requests are prioritized, and who remains responsible until each issue is resolved.
The 10 Core Services an Insurance Agency Should Receive
- Live help desk and employee support
- Proactive monitoring and maintenance
- Patch and device management
- Layered cybersecurity protection
- Microsoft 365 and identity administration
- Backup, disaster recovery, and business continuity
- Employee onboarding and offboarding
- Insurance application and vendor coordination
- Strategic technology planning
- Reporting, documentation, and accountability
An MSP does not need to package every service in exactly the same way. However, an agency should know who owns each responsibility and whether essential protections are included in the quoted monthly price.
1. Live Help Desk and Employee Support
The help desk is the service employees interact with most often. When an account is locked, Outlook stops synchronizing, a printer fails, a laptop becomes slow, or an employee cannot access an agency application, the support process should be simple and predictable.
A dependable help desk should provide:
- A live method for requesting urgent assistance
- Phone, email, and ticket-based support options
- Remote troubleshooting
- Clearly defined support hours
- After-hours assistance for urgent problems
- Ticket prioritization based on business impact
- Escalation to more experienced technicians when necessary
- Follow-up to confirm that the issue is fully resolved
Ask whether the provider measures both response time and resolution time. A quick automated acknowledgment is not the same as having a technician actively work on the problem.
What Good Support Looks Like
For a critical outage affecting the entire agency, the MSP should begin coordinating a response immediately. A routine request affecting one employee may follow a standard queue, but the employee should still know when to expect help.
Insurance agency owners featured in 911 IT’s client feedback repeatedly emphasize the value of live, responsive support. One agency owner reported that calls were answered and most issues could be resolved remotely within minutes. Another said the team answered the phone whenever help was needed and addressed the issue right away.
Review additional client experiences on the 911 IT client stories page.
2. Proactive Monitoring and Maintenance
Managed IT should do more than wait for employees to report failures. The provider should continuously monitor supported systems for warning signs and correct developing problems before they produce unnecessary downtime.
Proactive management may include:
- Workstation and laptop health monitoring
- Server monitoring
- Disk-space and hardware alerts
- Network and firewall monitoring
- Internet connectivity alerts
- Backup failure notifications
- Security event monitoring
- Service availability checks
- Automated maintenance tasks
The provider should also define what happens after an alert is generated. Monitoring has limited value when no one investigates the warning or takes responsibility for the underlying problem.
Why Proactive IT Matters to an Insurance Agency
An agency may depend on technology to quote coverage, access policy records, communicate with carriers, assist clients with claims, process renewals, and collect payments. A preventable server, network, account, or backup failure can interrupt several of those activities at once.
Proactive monitoring reduces the number of avoidable surprises and gives the agency time to replace aging technology before it fails during a busy workday.
3. Patch and Device Management
Every supported computer should be included in a documented device-management process. This helps the MSP maintain a consistent security and reliability baseline across office, home, and mobile work environments.
Device management should address:
- Operating-system updates
- Supported third-party application updates
- Endpoint security deployment
- Device encryption
- Administrative access
- Hardware inventory
- Warranty tracking
- Remote support tools
- Replacement planning
- Secure disposal procedures
Ask how quickly the provider evaluates and deploys critical security updates. Some patches require testing before broad installation, while actively exploited vulnerabilities may require urgent action.
What About Personal and Unmanaged Devices?
Insurance agencies should establish rules for employees who use personal computers or mobile devices to access business email, documents, and applications. The MSP should help determine whether those devices can be secured adequately or whether agency-owned equipment is the safer option.
At minimum, business access should not depend on an unknown device with no encryption, no security monitoring, and an unsupported operating system.
4. Layered Cybersecurity Protection
Basic antivirus is not a complete cybersecurity program. Insurance agencies should use several overlapping controls because a single tool cannot reliably stop every phishing attempt, stolen password, malicious attachment, vulnerable application, or ransomware attack.
A managed cybersecurity program may include:
- Multi-factor authentication
- Endpoint detection and response
- Managed antivirus
- Email filtering and anti-phishing controls
- Web and domain filtering
- Firewall management
- Device encryption
- Vulnerability scanning
- Security patching
- Employee security awareness training
- Dark-web or credential-exposure monitoring
- Security event investigation
- Incident-response planning
The provider should explain which controls are included, how they are managed, what events are monitored, and who responds when suspicious activity is detected.
Explore the protections available through 911 IT’s cybersecurity services.
Cybersecurity Should Protect Identities, Not Just Computers
Many attacks target user accounts instead of devices. A criminal who captures a valid Microsoft 365 password may be able to read email, impersonate an employee, change payment instructions, or send convincing phishing messages to clients and coworkers.
Identity protection should therefore include:
- Multi-factor authentication
- Strong password standards
- Conditional access where appropriate
- Restrictions on administrative privileges
- Monitoring for unusual sign-in activity
- Rapid account deactivation when an employee leaves
- Regular review of shared and unused accounts
Security Awareness Training
Employees should receive recurring, practical education rather than a single annual presentation that is quickly forgotten. Useful training covers phishing, suspicious attachments, password safety, payment fraud, data handling, lost devices, and incident reporting.
Employees should know exactly whom to contact when they suspect a message, login prompt, payment request, or account activity may be fraudulent.
5. Microsoft 365 and Identity Administration
Microsoft 365 is often central to an insurance agency’s email, documents, collaboration, and remote work. An MSP should manage both the day-to-day environment and the security controls surrounding it.
Microsoft 365 administration may include:
- User-account creation and removal
- License assignment
- Mailbox and email support
- Microsoft Teams administration
- SharePoint and OneDrive support
- Distribution lists and shared mailboxes
- Multi-factor authentication
- Security configuration
- Access and permission reviews
- Spam and phishing protection
- Data retention guidance
- Microsoft 365 backup
Do not assume that Microsoft automatically provides every backup, retention, or recovery function the agency needs. The MSP should explain what Microsoft retains, what the provider protects separately, and how deleted or encrypted data would be restored.
Agencies planning cloud migrations, collaboration improvements, or secure remote access can review 911 IT’s cloud services.
6. Backup, Disaster Recovery, and Business Continuity
Backup is the process of creating recoverable copies of data. Disaster recovery is the process for restoring systems after a serious failure. Business continuity addresses how the agency will continue serving clients while normal technology is unavailable.
A complete managed IT service should address all three.
What Should Be Protected?
The provider should identify and document every important data source, including:
- Servers
- File shares
- Microsoft 365 email
- SharePoint and OneDrive data
- Agency-management data where applicable
- Accounting information
- Critical workstation data
- Cloud applications that require separate protection
- Network and firewall configurations
What Should the Backup Plan Define?
- How frequently data is backed up
- Where backup copies are stored
- How long backups are retained
- Whether backups are encrypted
- How backups are protected from ransomware
- Who monitors backup failures
- How often restoration is tested
- How quickly critical services can be restored
- How much recent data could be lost after an incident
The last two points are often described as the recovery time objective and recovery point objective. Agency leadership does not need to use technical terminology, but it should understand how long a realistic recovery may take and how much data could be unavailable.
Learn more about backup, recovery, and resilience through 911 IT’s business continuity services.
A Backup Is Not Proven Until It Has Been Tested
A dashboard showing successful backup jobs is encouraging, but it does not prove that every important system can be restored. The MSP should periodically test recovery procedures and document the results.
The agency should also know who will communicate with employees, clients, carriers, and vendors during an extended outage.
7. Employee Onboarding and Offboarding
New employees should begin work with the correct equipment, accounts, applications, permissions, and security controls. Departing employees should lose access promptly and consistently.
A New-Employee IT Checklist
- Confirm the employee’s role and start date.
- Prepare an agency-owned computer where required.
- Create the Microsoft 365 account.
- Assign the correct licenses.
- Enable multi-factor authentication.
- Configure email, Teams, OneDrive, and approved applications.
- Grant only the permissions required for the role.
- Provide security and acceptable-use guidance.
- Test access before the employee’s first day.
- Document the equipment and accounts issued.
A Departing-Employee IT Checklist
- Disable the employee’s accounts at the approved time.
- Revoke active sessions and remote access.
- Recover agency-owned devices.
- Preserve required email and business records.
- Transfer access to shared files and mailboxes.
- Remove application and carrier-system access.
- Change shared credentials the employee knew.
- Review forwarding rules and delegated access.
- Reclaim reusable licenses.
- Document completion of the offboarding process.
Ask whether routine onboarding and offboarding are included in the monthly agreement or billed as separate projects.
8. Insurance Application and Vendor Coordination
An insurance-focused MSP should be comfortable coordinating with third-party vendors that support the agency’s business systems.
These may include:
- Applied Epic
- AMS360
- HawkSoft
- EZLynx
- Vertafore applications
- Carrier portals
- Accounting software
- Internet providers
- VoIP and telephone vendors
- Copier and scanner vendors
- Website and hosting providers
- Cyber insurance brokers and assessors
The MSP may not control the third-party application itself, but it should help determine whether a problem is related to the workstation, network, internet service, browser, authentication, Microsoft 365 environment, security configuration, or vendor platform.
One Point of Contact Reduces Vendor Finger-Pointing
Without coordination, an employee may spend hours contacting multiple companies while each vendor claims another system caused the problem. A capable MSP should gather evidence, open the correct support case, communicate technical details, and remain involved until the responsible party provides a solution.
The agreement should explain whether vendor-management time is included or billed separately.
9. Strategic Technology Planning
A managed IT provider should help the agency prepare for future needs instead of focusing exclusively on today’s support tickets.
Strategic planning may include:
- A 12–36 month technology roadmap
- Annual IT budgeting
- Computer and server replacement schedules
- Cybersecurity improvement plans
- Microsoft 365 and cloud planning
- Office expansion and relocation planning
- Merger or acquisition support
- Vendor and licensing reviews
- Business continuity planning
- Cyber insurance readiness
- Policy and documentation development
This service is sometimes called virtual CIO or vCIO guidance. The exact title matters less than the outcome: agency leadership should receive clear recommendations, priorities, costs, risks, and target dates.
Quarterly Technology Reviews
Many agencies benefit from a structured review at least quarterly. A useful meeting may cover:
- Open and recurring support issues
- Security alerts and trends
- Backup and recovery status
- Upcoming hardware replacements
- Microsoft 365 licensing
- Planned business changes
- Technology budget updates
- Progress on previously approved projects
The review should lead to decisions and assigned actions rather than becoming a presentation of technical statistics with no business context.
10. Reporting, Documentation, and Accountability
The agency should not have to take the MSP’s performance on faith. The provider should maintain accurate documentation and give leadership enough information to evaluate service quality, security, risk, and progress.
Useful documentation includes:
- Supported user and device inventory
- Network diagrams
- Approved administrative access
- Software and license inventory
- Backup configurations
- Recovery procedures
- Vendor contact information
- Warranty and lifecycle information
- Technology policies
- Incident-response procedures
- Onboarding and offboarding checklists
Useful management reports may include:
- Ticket volume and trends
- Response and resolution performance
- Recurring support problems
- Security events and remediation
- Patch and device status
- Backup success and recovery tests
- Upcoming replacements and renewals
- Progress against the technology roadmap
Services That May Be Included or Priced Separately
Every MSP structures agreements differently. Ask whether the following are included, available as add-ons, or billed as projects:
| Service | Question to Ask |
|---|---|
| Onsite support | Is onsite labor included, limited, or billed hourly? |
| After-hours support | Which problems qualify, and are additional charges applied? |
| Hardware installation | Is new-computer setup included? |
| Employee onboarding | Are routine account and device setups covered? |
| Office moves | Are relocation services treated as a separate project? |
| Cybersecurity tools | Which licenses and security services are included? |
| Microsoft 365 licenses | Are licenses bundled or billed separately? |
| Microsoft 365 backup | Is cloud data protected by a separate backup platform? |
| Security training | How often is training delivered, and are phishing simulations included? |
| Projects | What qualifies as project work rather than recurring support? |
| Compliance assistance | Does the MSP provide technical evidence, policies, or questionnaire support? |
| Vendor management | Is coordination time included in the fixed monthly fee? |
Basic IT Support Versus Comprehensive Managed IT
| Service Area | Basic IT Support | Comprehensive Managed IT |
|---|---|---|
| Support model | Responds after a problem is reported | Combines responsive support with proactive management |
| Monitoring | Limited or optional | Ongoing monitoring with defined response procedures |
| Cybersecurity | Basic antivirus | Layered endpoint, email, identity, network, and employee protection |
| Microsoft 365 | Basic account assistance | Administration, security configuration, support, and planning |
| Backup | Backup software may be installed | Backups are monitored, protected, documented, and tested |
| Vendor coordination | Agency contacts each vendor | MSP helps coordinate technical troubleshooting |
| Planning | Recommendations are made when something fails | Technology roadmap, budgeting, and lifecycle planning |
| Reporting | Invoices and individual ticket updates | Service, risk, security, and roadmap reporting |
How to Measure Whether the MSP Is Delivering Value
A managed IT relationship should produce measurable operational improvements. The agency can track a combination of service, security, reliability, and business indicators.
Support Metrics
- Average time before a technician begins working
- Average time to restore employee productivity
- Percentage of issues resolved during the first interaction
- Number of reopened tickets
- Number of recurring problems
- Employee satisfaction with support
Reliability Metrics
- Unplanned downtime
- Internet and network interruptions
- Backup success rate
- Recovery-test results
- Number of devices approaching end of life
Security Metrics
- Multi-factor authentication coverage
- Device encryption coverage
- Patch compliance
- Phishing simulation results
- Critical vulnerabilities awaiting remediation
- Security incidents and response outcomes
Strategic Metrics
- Progress against the technology roadmap
- Completion of planned replacements
- Budget accuracy
- Reduction in emergency projects
- Completion of security and continuity improvements
Metrics should be used to improve service, not to create impressive-looking reports that hide unresolved problems.
Questions to Ask Before Signing a Managed IT Agreement
- Will employees reach a live technician when they call?
- What are your support hours?
- How do you prioritize urgent incidents?
- How are unresolved issues escalated?
- Is remote support unlimited?
- When is onsite support available, and does it cost extra?
- Which cybersecurity products and services are included?
- Who monitors security alerts outside normal business hours?
- How do you secure Microsoft 365 accounts?
- How do you protect Microsoft 365 data?
- Which servers, applications, and cloud systems are backed up?
- How frequently do you test restoration?
- Are employee onboarding and offboarding included?
- Will you coordinate with our agency-management software vendor?
- Do you provide technology budgeting and planning?
- How often will agency leadership meet with an advisor?
- What reports will we receive?
- Which services are excluded from the monthly fee?
- What work is treated as a separately billed project?
- How will our documentation and data be returned if the agreement ends?
Red Flags in a Managed IT Proposal
Pause and request clarification when a proposal includes any of the following:
- No written list of included and excluded services
- No defined escalation process
- Security described only as antivirus
- No explanation of backup testing
- No Microsoft 365 security responsibilities
- No employee offboarding process
- No inventory of supported devices
- No technology planning meetings
- No method for measuring support performance
- Long contract terms without a clear service commitment
- Unclear project and after-hours charges
- No documented transition process
A vague proposal almost always produces vague expectations. The agreement should be detailed enough that both parties understand who is responsible for each important function.
Frequently Asked Questions
Should managed IT include unlimited help desk support?
Many fixed-fee managed service plans include ongoing remote help desk support. Agencies should confirm whether there are limits, excluded request types, after-hours charges, or separate project fees.
Should cybersecurity be included in managed IT?
Cybersecurity should be integrated into the service, but the exact controls vary by provider. Confirm whether endpoint protection, email security, multi-factor authentication, vulnerability management, employee training, and incident response are included.
Does an MSP replace the agency-management software vendor?
No. The software vendor remains responsible for its application. The MSP should support the computers, network, internet connection, Microsoft 365 environment, identities, integrations, and security controls surrounding the application while coordinating with the vendor when necessary.
Should Microsoft 365 backup be included?
The MSP should explain how Microsoft 365 email, SharePoint, OneDrive, and Teams data are protected and restored. A separate backup service may be included in the plan or offered as an additional service.
How often should backups be tested?
The appropriate schedule depends on the systems and business risk. At minimum, the provider should perform recurring restoration tests and document whether critical data and systems can be recovered within the agency’s required timeframe.
Should an MSP help with cyber insurance questionnaires?
An MSP can often provide technical information about security controls, backups, identity protection, monitoring, and incident response. The agency, its broker, legal counsel, and insurer remain responsible for interpreting policy questions and submitting accurate answers.
How often should the agency meet with its MSP?
Many 25–50 employee agencies benefit from a formal technology review at least quarterly, along with additional planning meetings before major projects, renewals, expansions, acquisitions, or security changes.
Should onsite support be included?
Some providers include onsite labor, while others charge separately or include a limited number of visits. The agreement should clearly state when onsite service is available and how it is priced.
What should happen when an employee leaves?
The agency should notify the MSP before the departure whenever possible. The MSP should disable accounts, revoke sessions, remove remote access, preserve required records, recover licenses, transfer business data, and document completion.
Can managed IT replace an internal IT employee?
For many 25–50 employee agencies, an MSP can provide help desk, security, cloud, project, and strategic expertise that would be difficult for one employee to cover alone. Agencies with internal IT staff may instead use co-managed IT services for additional coverage and specialized expertise.
What Makes Managed IT Valuable to an Insurance Agency?
The value of managed IT comes from combining employee support, risk reduction, continuity, vendor coordination, and planning under one accountable relationship.
A strong provider should help the agency:
- Resolve employee issues quickly
- Reduce preventable downtime
- Protect sensitive client information
- Secure Microsoft 365 and remote access
- Recover from outages and cyber incidents
- Coordinate with insurance technology vendors
- Prepare employees to recognize security threats
- Plan future technology spending
- Document systems and responsibilities
- Give leadership measurable visibility into IT performance
911 IT’s managed IT services combine proactive monitoring, live 24/7 support, cybersecurity, cloud management, and strategic technology guidance. The company has served businesses since 2004 and provides flat-rate service backed by a satisfaction guarantee.
Build the Agreement Around Clear Responsibilities
Before choosing an MSP, create a list of every important IT responsibility and assign each one to the agency, the MSP, or another vendor. Do not leave critical functions unassigned because everyone assumed another company was handling them.
For an insurance agency, the final managed IT agreement should clearly cover:
- How employees receive support
- How systems are monitored and maintained
- How devices, accounts, and Microsoft 365 are secured
- How data is backed up and restored
- How employees are onboarded and offboarded
- How insurance software vendors are coordinated
- How technology risks and investments are planned
- How the provider’s performance is measured
Need help evaluating what is included in your current IT agreement? Schedule a discovery call with 911 IT to review your support coverage, cybersecurity protections, backup strategy, vendor responsibilities, and technology priorities.
