viabandwidthManaged Service Providers
KNOWLEDGE BASE

Every term on this directory, in plain English.

Provider profiles lean on service models, contract terms and compliance labels that deserve a straight explanation, including what a certification does not prove. Read the full definitions here before you shortlist.

Types of managed service

The directory sorts providers by what they actually do. These are the main models, from running all of your IT to covering security only.

Managed service provider (MSP)

A company you pay a flat monthly fee to run and support your IT so you do not have to hire and manage an in-house team. A good one is proactive, meaning it is paid to prevent problems rather than to bill you when something breaks.

Co-managed IT

The provider works alongside your own IT staff rather than replacing them. It covers gaps like after-hours support, a specialist skill or extra hands during a project, while your team keeps day to day control.

MSSP

A managed security service provider is focused on protecting your systems, watching for threats and responding to incidents. It is different from a general MSP, which handles all of your IT, so many businesses use one of each or an MSP that offers both.

SOC (security operations center)

The team of analysts and the tools that watch your systems around the clock for signs of an attack. Ask whether the provider runs its own SOC or resells someone else's, and whether cover is genuinely 24 hours.

MDR (managed detection and response)

Managed detection and response means the provider actively hunts for threats on your systems and steps in to contain them. It is a step beyond plain monitoring, which only sends you an alert and leaves the response to you.

RMM (remote monitoring and management)

The software an MSP uses to see the health of your machines and fix many problems without visiting your office. It is how a small provider can support hundreds of devices, and it is worth asking how they secure it.

Help desk

The people you call or message when something breaks. A managed help desk handles day to day user problems like password resets, email issues and slow machines, and its response time is one of the clearest quality signals to check.

NOC (network operations center)

A network operations center watches the health and uptime of your systems and networks. Its job is keeping things running, which is different from a SOC, whose job is watching for security threats.

Certifications and what they prove

A badge on a profile means the provider listed that certification. Here is what each one actually commits them to, and what to ask for before you trust it.

SOC 2

An independent audit of how a provider protects customer data. A Type II report covers how those controls held up over a period of months rather than on a single day, so ask for the current Type II report under a non disclosure agreement instead of taking the badge on trust.

HIPAA

The US rule for protecting health information. There is no official HIPAA certificate, so what matters is whether the provider will sign a business associate agreement and can show in writing how it safeguards patient data.

ISO 27001

An international standard for running an information security program. Check that the certificate scope actually covers the service you are buying and the site that delivers it, not just the head office.

PCI DSS

The security standard for handling payment card data. It is relevant if the provider touches any part of how you accept card payments, and the level that applies depends on your card volume.

ISO 9001

A quality management standard. It shows the provider follows consistent documented processes, which speaks to reliability more than to security, so pair it with a security certification when data protection matters.

CMMC

The Cybersecurity Maturity Model Certification is the US Department of Defense standard for contractors that handle controlled unclassified information. Level 2 is the common bar for firms in the defense supply chain.

How the relationship works

The contracts and pricing behind a managed IT deal. Knowing these terms lets you compare quotes on the same footing.

SLA (service level agreement)

The written promise of how fast the provider will respond and resolve problems. Read the response times, what counts as an emergency and the penalties for missing them before you sign, because this is where a cheap quote often falls apart.

MSA (master services agreement)

The master contract that sets the overall terms of the relationship, with the specific work described in separate statements of work. Watch for long lock-in periods and how you get your data back if you leave.

Per-seat pricing

A flat monthly price for every user or device covered. It makes budgeting predictable and is the most common way managed IT is billed, so compare quotes on what each seat actually includes rather than on the headline number.

Break-fix

The older model where you pay per incident when something breaks. Managed service flips this to a flat fee, which aligns the provider with keeping your systems healthy rather than profiting when they fail.

Onboarding

The first weeks where a new provider documents your systems, fixes obvious risks and sets up its monitoring. A rushed or vague onboarding plan is a warning sign, since a provider that does not learn your environment cannot protect it.

Security and continuity

The tools and plans that keep your systems safe and recoverable. Increasingly the core of what buyers want from a provider.

EDR (endpoint detection and response)

Security software on each device that spots suspicious behavior and can isolate a machine before an attack spreads. It is the modern replacement for basic antivirus and is table stakes for any provider selling security.

Backup and disaster recovery

Backup keeps copies of your data. Disaster recovery is the tested plan for getting you running again after an outage, a ransomware attack or hardware failure. Ask when the recovery plan was last actually tested, not just whether one exists.

Patch management

Keeping software and systems up to date so known security holes are closed. Most breaches exploit a hole that a patch had already fixed, which makes this unglamorous work one of the highest value things a provider does.

vCISO (virtual CISO)

A virtual chief information security officer is a part time senior security leader you rent from the provider to set strategy, handle audits and answer to your board without hiring a full time executive.

Zero trust

A security approach that never assumes a user or device is safe just because it sits inside your network, and verifies every request. It is a direction of travel rather than a product, so ask a provider what it means in practice for your setup.

Missing a term?
Tell us what tripped you up and we will add it to the glossary.
Suggest a term