Switching IT support provider is a job many businesses put off for years, usually out of a fear that the changeover will be painful. In reality, when it is handled properly, moving to a new IT support provider should be almost invisible to your team, with no downtime and no lost data. This guide explains how a good handover works, what can go wrong when it is done badly, how to time the switch around your existing contract, and how to switch IT support provider without disrupting your business.
Why businesses put off switching their IT provider
Most businesses stay with an underperforming IT provider far longer than they should. The reason is rarely that the support is good, it is that switching feels risky. There is a worry that systems will break during the move, that data will be lost, or that the team will be left without support while everything transfers across. Some providers quietly rely on that inertia rather than earning your loyalty. The good news is that these fears are almost always unfounded when you choose a provider who runs a proper onboarding process.
Does switching IT support cause downtime?
No, switching IT support does not cause downtime when it is done well. A competent new provider prepares everything in the background before anything changes for your staff, then times the cut-over to avoid disruption, so your team keeps working and your data stays in place.
Behind the scenes, the new provider documents your systems, deploys their monitoring and security, and coordinates the handover, often over a weekend or overnight. Downtime only tends to happen when a provider rushes the move or skips the groundwork, which is why the onboarding process matters more than almost anything else.
What can go wrong if a switch is handled badly
Most of the horror stories people worry about come from switches that were rushed or under-planned, not from switching itself. The most common problems are:
Data or email loss when accounts are moved before backups are confirmed
Downtime caused by misconfigured email, DNS or domain records during the cut-over
Software licences or Microsoft 365 subscriptions not transferred cleanly, leaving staff locked out
Losing administrator access because the outgoing provider held the keys and was not asked to hand them over
A support gap where the old provider has stepped back but the new one is not yet fully set up
Security holes left open, such as old admin accounts and remote access that are never disabled
A good provider plans around every one of these before touching anything live. When you are comparing providers, ask them exactly how they avoid each one, the answer tells you a lot about how they work.
How a good IT provider onboards you, step by step
A well-run switch follows a clear, low-risk process:
Review and audit. The new provider assesses your systems, security, licences and documentation.
Plan. They agree a clear handover plan and timeline with you, and liaise with your outgoing provider.
Document and secure. They take over documentation, deploy monitoring, and put their security in place.
Transfer support. The helpdesk, accounts and access move across, usually with no downtime.
Support and improve. They run your IT day to day and start fixing the things the last provider left.
Throughout, a good provider keeps you informed and makes sure nothing falls between the two of you.
Timing your switch around your contract notice period
Before you switch, check your current agreement for its notice period and any exit terms, as this usually dictates the timeline. Most IT support contracts require between 30 and 90 days notice, and some renew automatically if you miss the window, so it is worth checking early. The smoothest approach is to line up your new provider so their onboarding overlaps the end of your notice period, rather than leaving a gap between the two. That way documentation and access can be transferred while your outgoing provider is still contactable, and support never lapses. A good new provider will happily work around your notice period and help you time the changeover.
How to know it is time to switch
If you are reading this, you probably already sense that your current support is not good enough. Slow response times, the same problems recurring, poor communication, weak security, or a provider that only ever reacts rather than prevents are all common signs. We have written a fuller guide on the 10 signs it is time to change your IT support provider if you want to sense-check it. If several of those ring true, switching is usually well overdue.
What to look for in a new IT support provider
Proactive, managed support rather than reactive break-fix
To switch IT support provider without disruption, follow these steps:
Check your current contract for its notice period and exit terms.
Choose your new provider and agree a start date that fits your notice period.
Let the new provider manage the handover, including liaising with your outgoing one.
Give them access and documentation so they can document and secure your systems.
Confirm the cut-over is complete and support has fully transferred.
You do not need to project-manage this yourself. If you would like to see how straightforward it can be, book a free IT review or get a quote and we will map out exactly how a switch would work for you, with no obligation.
Frequently asked questions
Does switching IT support provider cause downtime?
No. When it is handled properly, switching IT support provider causes no downtime. A good provider prepares everything in the background and times the cut-over to avoid disruption, so your team keeps working and your email, files and systems stay exactly where they are.
How long does it take to change IT support provider?
For most small and medium businesses, changing IT support provider takes a few days to a couple of weeks, depending on the size and complexity of your systems. The disruptive part, if there is any, is usually a single planned cut-over rather than an ongoing project.
Will I lose any data or emails when I switch?
No, you should not lose any data or emails. Your email, files and systems stay in place, and the new provider takes over managing and securing them rather than moving them. A proper handover confirms your backups before anything changes.
How much notice do I need to give my current IT provider?
Most IT support contracts require between 30 and 90 days notice, and some renew automatically if you miss the window. Check your agreement early for the exact notice period and any exit terms, then time your new provider to start as that period ends.
Do I have to deal with my old provider myself?
No. A capable new provider manages the handover for you, including liaising with your outgoing provider to collect documentation, passwords and administrator access. Your involvement is usually limited to approving the plan and granting permission.
What if my current provider will not co-operate?
You can still switch. A good new provider is used to outgoing providers being slow or unhelpful, and can rebuild documentation, reset administrator access and secure your systems independently if needed. It may take a little longer, but it is entirely doable.
How do I choose the right IT support provider?
Look for proactive managed support, fast guaranteed response times, strong cyber security, clear all-inclusive pricing and a structured onboarding process. A short review of your setup is the best way to compare providers properly.
Most businesses wait far too long to change their IT support provider. Not because they are happy, but because switching sounds like a hassle, and the devil you know feels safer than the devil you do not.
That instinct is usually wrong. Poor IT support does not stay the same. It quietly gets worse, and the cost of putting up with it compounds.
Here are the signs it is time to move, and what a good provider should look like instead.
1. You only hear from them when something breaks
This is the biggest one. If your IT company only appears when you raise a problem, they are not managing your IT. They are reacting to it.
A proper managed IT service monitors your systems around the clock and fixes most issues before you know they exist. Failing hard drives, backups that have quietly stopped running, machines missing security updates. All of it should be caught in the background. If every problem you have is one you found yourself, you are paying for a service you are not receiving.
2. Nobody knows your business
You explain your setup from scratch every time you call. You speak to a different person each time. Nobody knows which server matters, which member of staff is travelling, or why the Tuesday morning report is critical.
Good support is not just technical. It is knowing the business well enough to prioritise correctly.
3. Response times are vague, or promised but not delivered
“We will look at it as soon as we can” is not a response time. If there is no guaranteed timeframe in your contract, there is no commitment.
Worse is a provider who promised a response time and quietly stopped meeting it. If nobody is measuring, nobody is accountable.
4. The same problems keep coming back
A printer that fails every month. A machine that needs rebooting every week. An email issue that gets patched and then returns.
Recurring problems mean symptoms are being treated, not causes. A good provider fixes it properly the first time and tells you when the real answer is replacing something rather than nursing it along.
5. Your staff have stopped raising issues
This is the most expensive sign, and the hardest to spot, because it looks like everything is fine.
When support is slow, unfriendly or billed by the hour, people simply stop asking. They struggle on with the slow laptop. They work around the broken process. They lose an hour a week each and nobody ever logs a ticket. The support bill looks healthy while productivity quietly bleeds away.
If your team rolls their eyes at the mention of IT, that is your answer.
6. You are not sure your backups actually work
Ask your provider a simple question: when did you last test that our backup restores?
Having a backup and having a backup that works are different things. Plenty of businesses discover, at the worst possible moment, that the backup has been silently failing for months. Proper backup and disaster recovery is tested regularly, and you should be told the result.
7. Nobody has mentioned security in a year
Cyber threats aimed at small businesses have grown sharply, and the tools to defend against them have moved on. If your provider has not talked to you about multi factor authentication, staff training, email security or Cyber Essentials, they are not thinking about your risk.
Silence on security is not a sign that you are safe. It is a sign that nobody is looking. If you are unsure where you stand, a free cyber security audit will tell you.
8. Every invoice is a surprise
You do not know what next month will cost. Small jobs appear as line items you did not expect. You feel a flicker of anxiety before opening the bill.
IT should be a predictable monthly cost you can budget for, not a series of unwelcome surprises. Our guide to how much IT support costs sets out what you should expect to pay and what should be included.
9. They cannot tell you what you have
Ask for an inventory of your devices, your licences, your warranties and your network setup. A good provider produces it within a day, because they maintain it as a matter of course.
If nobody can tell you what you own or how it is configured, nobody is really in control of your IT, and a serious incident will be far harder to recover from.
10. They never suggest anything
You have never had a conversation about where your IT is heading. Nobody has flagged the ageing server, suggested a better way of working, or planned ahead with you.
A provider should bring you ideas, not just fix what you report. If they are purely reactive, you are the one doing the thinking, and you already have a business to run.
What good actually looks like
A provider worth paying should offer all of the following as standard:
Proactive monitoring around the clock, so most problems never reach you
A guaranteed response time, written into the contract
Unlimited support, so nobody hesitates to ask for help
Backups tested regularly, with the results reported to you
An active security conversation, not silence
A predictable monthly cost with no surprises
A named team who know your business
Regular reviews where they tell you what is coming, not just what broke
But is switching not a nightmare?
This is the fear that keeps businesses stuck, and it is largely unfounded. A competent handover is designed to be invisible to your staff. We have written more about how switching IT provider works in practice.
Here is how it should work:
Audit. Your new provider documents everything you have: devices, licences, servers, network, backups and accounts.
Plan. They agree a switchover date with you and identify anything that needs fixing first.
Deploy. Monitoring, security and support tools are rolled out quietly in the background, usually with no disruption at all.
Handover. Access is transferred from your old provider. A good new provider handles that conversation so you do not have to.
Go live. Your team gets one email telling them who to call. That is usually the only change they notice.
Most businesses are fully switched within two to four weeks, without downtime. The disruption you are imagining is almost always smaller than the disruption you are already living with.
Frequently asked questions
How do I know if my IT support is bad?
The clearest test is whether your provider is proactive or reactive. If they only contact you when you raise a problem, if the same issues keep recurring, if backups are never tested and security is never discussed, the service is falling short regardless of how pleasant the people are. For a quick, objective read, our free IT and cyber benchmark scores your setup in a few minutes.
How difficult is it to change IT support provider?
Less difficult than most people expect. A proper handover takes two to four weeks and should cause no downtime. Your new provider audits your systems, deploys their tools in the background, handles the transfer of access from the outgoing provider, and switches you over. For most staff, the only change is who they contact.
Am I tied into a contract with my current IT provider?
Many IT contracts run on rolling monthly or annual terms with a notice period, commonly 30 to 90 days. Check your agreement for the notice clause. A new provider can usually begin the audit and preparation during your notice period, so no time is wasted.
Will my current provider make the handover difficult?
Occasionally, but rarely. Most behave professionally. Where they do not, a good incoming provider knows how to work around it and will manage that conversation on your behalf rather than leaving you in the middle of it.
When is the right time to change IT support provider?
Sooner than most businesses do. If several of the signs above sound familiar, the cost of staying is already higher than the cost of moving, and it grows every month. There is no advantage to waiting for a serious incident to force the decision.
Thinking about a change?
We have supported businesses across Chichester, Worthing, Arundel and West Sussex since 2015. We are Cyber Essentials certified and a Microsoft Partner, and we look after architects, engineers, hotels, veterinary practices and property firms across the region.
If any of the above sounds like your current setup, book a free IT review. We will look at what you have, tell you honestly what is wrong with it, and you can decide what to do next. No obligation and no hard sell.
How much does outsourced IT support cost in the UK? For most businesses it is charged as a fixed monthly fee, usually per user, and commonly ranges from around £30 to £100 per user per month depending on the level of cover and security you need. That predictable, per-user model is one of the main reasons businesses move away from ad-hoc fixes and expensive in-house hires. In this guide we break down what drives the outsourced IT support cost, what should be included, and how to work out a realistic budget for your business.
What does outsourced IT support cost?
Outsourced IT support, sometimes called managed IT support, is almost always priced as a recurring monthly fee rather than a one-off charge. The most common model is per user, per month, which covers everything a member of staff needs: their devices, accounts, security and support. As a rough guide, UK businesses typically pay somewhere between £30 and £100 per user per month, with the figure depending mainly on how much cover and security is included. A basic helpdesk-only package sits at the lower end, while a fully managed service with layered cyber security, Microsoft 365 management and strategic guidance sits higher. Because it scales with your headcount, the cost stays predictable as you grow. For a wider view of pricing, see our guide on how much IT support costs.
What is included in the cost?
A good outsourced IT support package should be genuinely all-inclusive, so you are not hit with extra charges every time you need help. Typically the monthly fee covers:
An unlimited UK helpdesk with fast response times
Proactive monitoring and maintenance that prevents issues
Always check what is and is not included, particularly project work, new hardware and out-of-hours support, which some providers charge for separately.
What affects the price?
Two businesses of the same size can pay quite different amounts. The main factors are:
Number of users. The per-user model means cost scales with your team.
Level of cover. Helpdesk-only is cheaper than a fully managed, proactive service.
Security requirements. Cyber Essentials, compliance and layered protection add value and cost.
Response time guarantees. Tighter service level agreements typically cost more.
On-site visits. Remote-only support is cheaper than regular on-site cover.
Contract length. Longer agreements often come with better monthly rates.
Common pricing models
Outsourced IT support is usually offered in one of a few ways. Per user, per month is the most common and the easiest to budget. Per device suits businesses with shared machines or a high device-to-user ratio. Some providers still sell pay-as-you-go or block hours, which can look cheaper upfront but is unpredictable and reactive by nature, you only get help once something has already gone wrong. For most businesses, an all-inclusive per-user model gives the best value and the fewest surprises.
Is outsourced IT support cheaper than hiring in-house?
Usually, yes. A single in-house IT hire can cost £35,000 to £50,000 a year once you add salary, National Insurance, training and holiday cover, and one person cannot span every discipline. Fully outsourced IT support gives you a whole team across helpdesk, security, cloud and strategy for a fraction of that, with cover built in and no single point of failure. For most small and medium businesses, outsourcing delivers broader expertise and better resilience at a lower total cost. For a full comparison, see our guide to in-house vs outsourced IT support.
How to get an accurate quote
The honest answer is that the only way to get a precise figure is a short review of your current setup, because it depends on your users, systems and security. Book a free IT review or get a quote and we will give you a clear, costed plan with no obligation. You can also learn more about our fully outsourced IT support service.
Frequently asked questions
How much does outsourced IT support cost per user?
As a guide, UK businesses typically pay between £30 and £100 per user per month, depending on the level of cover and security included. A short review is the best way to get an accurate figure for your business.
Is outsourced IT support charged monthly?
Yes. It is almost always a fixed monthly fee, usually per user, which makes it easy to budget and scales up or down as your team changes.
What is included in outsourced IT support?
Typically an unlimited helpdesk, proactive monitoring, cyber security, Microsoft 365 management, backup and strategic guidance. Always check whether project work, hardware and out-of-hours support are included or charged separately.
Is outsourced IT support cheaper than in-house?
For most businesses, yes. You get a whole team of specialists for a fraction of the cost of a single senior hire, with holiday and sickness cover built in and no single point of failure.
Are there setup or onboarding costs?
Some providers charge a one-off onboarding fee to document and take over your systems, while others roll it into the monthly cost. It is always worth asking what onboarding involves and whether it is chargeable.
Can I scale the cost up or down?
Yes. Because most outsourced IT support is priced per user, the cost scales naturally as you add or remove staff, so you only pay for what you use.
Why outsource your IT support? In short, because it gives your business a whole team of IT specialists, stronger cyber security and predictable costs, without the expense and risk of building an in-house team. For most growing UK businesses, outsourcing means better IT and less hassle for less money. In this guide we look at exactly what outsourcing means, the main benefits, and how to know when it is the right move.
What does it mean to outsource your IT support?
Outsourcing your IT support means handing the running of your technology to a specialist provider, or managed service provider, instead of relying on an internal hire or an unofficial “office IT person”. The provider looks after your helpdesk, security, monitoring, Microsoft 365 and strategy for a fixed monthly fee. It is the model most small and medium businesses now use, because it gives them enterprise-grade IT without an enterprise budget. Our guide to outsourced IT support explains how the service works in full.
Why do businesses outsource IT support?
The reasons vary, but the benefits are consistent. The main ones are:
Lower, predictable costs. One monthly fee replaces salaries, training and the cost of downtime, and it is easy to budget.
A whole team of specialists. Instead of one person who cannot know everything, you get expertise across helpdesk, security, cloud and strategy.
Stronger cyber security. Managed protection, cyber security, Cyber Essentials and staff awareness are built in as standard.
Proactive support and less downtime. Problems are prevented and fixed early, rather than after they have already cost you time and money.
Scalability. The service grows with you, adding or removing users as your team changes.
Focus on your core business. Your team spends time on the work that matters, not wrestling with IT.
Resilience. Holiday and sickness cover are built in, with no single point of failure if a key person leaves.
When should you outsource your IT?
Most businesses start thinking about outsourcing when their current arrangement starts to hold them back. Common triggers include the same IT problems recurring without ever being fixed, relying on one person who has become a risk, cyber security and Microsoft 365 not being actively managed, slow staff onboarding, or simply having no clear IT strategy or budget. If any of those sound familiar, it is usually a sign that a proactive, managed approach would pay for itself.
Is outsourcing right for your business?
Outsourcing suits businesses of almost any size, but it is especially valuable for small and medium firms that cannot justify a full in-house IT team. Larger organisations often use a hybrid model, keeping someone in-house for day-to-day needs and outsourcing the specialist, security and out-of-hours work. The right answer depends on your size, sector and how much you rely on technology, which is exactly what a short review will tell you. If cost is your main question, see our guide on how much outsourced IT support costs, and if you are weighing up hiring instead, read our comparison of in-house vs outsourced IT support.
How to choose an outsourced IT provider
Look for a provider that is proactive rather than reactive, security-led and genuinely accountable, with named engineers and clear reporting. Local matters too: a provider on your doorstep can be on site when needed and understands your area. As an example, our IT support in Chichester and across West Sussex is delivered by a local team, backed by Cyber Essentials certification and Microsoft Partner status.
Ready to outsource your IT?
Start with a free, no-obligation review of your current setup, security and support. We will show you exactly where the gaps and opportunities are, with a clear plan. Book a free IT review or get a quote to see what outsourcing could do for your business.
Frequently asked questions
Why do businesses outsource IT support?
To get a whole team of specialists, stronger security and predictable costs without the expense and risk of hiring and managing an in-house IT team.
Is outsourcing IT support cheaper than in-house?
Usually, yes. You get a whole team for less than the cost of a single senior hire, with holiday and sickness cover built in and no single point of failure.
Will I lose control of my IT if I outsource?
No. You keep ownership of your systems, data and decisions. The provider runs the day-to-day work and gives you clear reporting and strategic guidance.
Is outsourced IT support more secure?
A good provider makes your business more secure, not less, with managed protection, Cyber Essentials support and monitoring built in as standard.
When is the right time to outsource IT?
When IT problems keep recurring, you rely on one person, security is not actively managed, staff onboarding is slow, or you have no clear IT strategy or budget.
What size business should outsource IT support?
Any size can benefit, but it is especially valuable for small and medium businesses that cannot justify a full in-house IT team. Larger teams often use a hybrid model.
In-house vs outsourced IT support is one of the first big decisions a growing business faces. Do you hire someone to look after your IT internally, or hand it to a specialist provider? Both models have their place, but for most small and medium businesses, outsourced IT support wins on cost, expertise and resilience, while larger teams often use a hybrid of the two. This guide compares the two approaches so you can choose the right one for your business.
What is in-house IT support?
In-house IT support means employing one or more people to manage your technology directly. The upside is someone on site who knows your business intimately and is always on your team. The downsides are significant, though: a single hire is expensive once you add salary, National Insurance, training and holiday cover, one person cannot be an expert in everything from networking to cyber security, and if they are off sick or leave, you have a single point of failure with no cover.
What is outsourced IT support?
Outsourced IT support means a specialist provider runs your IT for a fixed monthly fee, covering the helpdesk, security, monitoring, Microsoft 365 and strategy. Instead of one person you get a whole team, with cover built in and broader expertise, usually for less than the cost of a single senior hire. Our guide to outsourced IT support explains how the service works in detail. If you are still deciding, our guide on why outsource your IT support covers the benefits in full.
In-house vs outsourced: the cost comparison
Cost is often the deciding factor. A single in-house IT hire typically costs £35,000 to £50,000 a year once you include salary, National Insurance, training and cover, and you still need to buy tools and monitoring on top. Outsourced IT support is charged as a predictable monthly fee, usually per user, and gives you a whole team for a fraction of that. For a full breakdown, see our guide on how much outsourced IT support costs.
Expertise and cover
This is where outsourcing really pulls ahead. Modern IT spans helpdesk support, cyber security, cloud, Microsoft 365, networking and strategy, and no single person can master all of it. An outsourced provider brings specialists across every discipline, plus holiday and sickness cover so support never stops. An in-house hire, by contrast, is one person with one set of skills and no backup.
Security
Cyber security is now too important and too specialised to leave to one generalist. A good outsourced provider builds managed cyber security, Cyber Essentials and monitoring into the service as standard, with dedicated tools and up-to-date expertise. In-house teams can do this well, but usually need external specialists to fill the gaps, which adds cost.
The hybrid model
It is not always either or. Many larger organisations use a hybrid, or co-managed, model: they keep someone in-house for day-to-day, hands-on needs and outsource the specialist, security and out-of-hours work to a provider. This gives you the best of both, an on-site presence backed by a full external team, and it is often the right answer once you get past a few hundred users.
Which is right for your business?
For most small and medium businesses, outsourced IT support delivers broader expertise, better security and greater resilience at a lower total cost than an in-house hire. Very large organisations, or those with highly specialist needs, may prefer a hybrid model. The best way to decide is to weigh up your size, sector and how much you rely on technology, which a short review will make clear.
Not sure which model fits?
We can help you weigh it up. Book a free IT review or get a quote, and we will give you an honest, costed recommendation for your business, whether that is fully outsourced or a hybrid approach.
Frequently asked questions
Is in-house or outsourced IT support better?
For most small and medium businesses, outsourced IT support is better on cost, expertise and resilience. Larger organisations often use a hybrid of in-house and outsourced.
Is outsourced IT cheaper than in-house?
Usually, yes. You get a whole team for less than the cost of a single senior in-house hire, with cover built in and no single point of failure.
What are the downsides of in-house IT?
Cost, limited breadth from a single person, and a single point of failure with no cover if they are off sick or leave.
Can I combine in-house and outsourced IT?
Yes. A hybrid or co-managed model keeps someone in-house for day-to-day needs and outsources the specialist, security and out-of-hours work to a provider.
Does outsourcing mean losing control of my IT?
No. You keep ownership of your systems, data and decisions. The provider handles the day-to-day work and reports back to you.
Which is more secure, in-house or outsourced?
A good outsourced provider usually offers stronger, more consistent security, with dedicated tools, monitoring and up-to-date expertise built into the service.
Cyber Essentials is a UK government backed certification scheme that shows your business has the basic controls in place to defend against the most common cyber attacks. It is affordable, quick to achieve with the right help, and increasingly expected by customers and required to win certain contracts. This guide explains what it is, the five controls, the two levels, and how to get certified.
In short, Cyber Essentials is a government backed certification that proves your business has the basic controls in place to stop the most common cyber attacks. You can read the official scheme detail on the NCSC Cyber Essentials pages.
What is Cyber Essentials?
Backed by the National Cyber Security Centre, Cyber Essentials sets out a baseline of security controls that stop the large majority of everyday cyber attacks. Certifying proves to customers, insurers and partners that you take security seriously, and it is often a condition of working with government and larger organisations.
The five controls
Firewalls: secure your internet connection so only trusted traffic gets in.
Secure configuration: set up devices and software safely, removing default passwords and unused features.
User access control: give people only the access they need, and protect admin accounts.
Malware protection: defend against viruses and other malicious software.
Security update management: keep operating systems and applications patched and up to date.
None of these are exotic. They are the fundamentals that, done consistently, close the doors most attackers walk through.
Cyber Essentials versus Cyber Essentials Plus
There are two levels. Cyber Essentials is a verified self-assessment: you complete a questionnaire about your controls, which is reviewed and certified. Cyber Essentials Plus covers the same five controls but adds a hands-on technical audit by an assessor, who tests your systems to confirm the controls really work. Plus carries more weight and is often required for higher-value or public sector contracts.
Why bother getting certified?
Win more business: many contracts, especially public sector, require it.
Reduce your risk: the controls block the most common attacks.
Reassure customers: it is visible proof you protect their data.
Support insurance: some cyber insurance policies expect it and it can improve terms.
Build good habits: it puts a security baseline in place you can build on.
How to get Cyber Essentials certified
Review your current setup against the five controls and find the gaps.
Fix the gaps, such as enabling firewalls, tightening access, and getting patching under control.
Complete the assessment, the questionnaire for Cyber Essentials or the audit for Plus.
Certify and maintain it, renewing each year and keeping the controls in place day to day.
Most businesses get there faster and more cheaply with an IT partner who knows the scheme, closes the gaps for you and handles the paperwork. Our free cyber security audit is a simple way to see where you stand before you start.
How ATS Connection can help
We guide West Sussex businesses through Cyber Essentials and Cyber Essentials Plus, from the initial gap review to certification, and keep the controls in place afterwards as part of your managed IT support. Get a quote or call 01903 255 159.
Frequently asked questions
What is Cyber Essentials?
It is a UK government backed certification, supported by the National Cyber Security Centre, that shows your business has five basic security controls in place to defend against common cyber attacks.
What is the difference between Cyber Essentials and Cyber Essentials Plus?
Cyber Essentials is a verified self-assessment questionnaire. Cyber Essentials Plus covers the same controls but adds a hands-on technical audit by an assessor who tests that the controls actually work.
How much does Cyber Essentials cost?
The certification itself starts from a modest fee for the base level, with Cyber Essentials Plus costing more due to the audit. The main cost is usually the work to close any gaps first.
How long does Cyber Essentials take?
With the right help, many businesses achieve base Cyber Essentials within a few weeks, depending on how much needs fixing. Cyber Essentials Plus takes a little longer because of the audit.
Do I need Cyber Essentials?
If you handle customer data, want to reassure clients, or bid for contracts, especially public sector work, it is well worth having, and it is often a formal requirement.
SRA IT Requirements for Solicitors: Complete Compliance Checklist 2026
Understanding SRA IT requirements for solicitors isn’t optional, it’s a fundamental compliance obligation that protects your practice, your clients, and your career. Yet many solicitor practices across the UK struggle to interpret what the Solicitors Regulation Authority actually requires when it comes to technology, information security, and data protection.
The consequences of getting it wrong are severe. SRA interventions, client compensation claims, cyber insurance invalidation, and reputational damage can result from non-compliant IT systems. In 2025 alone, the SRA received over 2,300 reports of data breaches and cyber security incidents affecting solicitor practices, many of which could have been prevented with proper IT compliance.
This comprehensive guide explains exactly what the SRA expects from your IT systems in 2026, providing a detailed compliance checklist you can use to assess your practice immediately. Whether you’re a sole practitioner in Chichester or a 50-person firm in Worthing, these requirements apply to you.
What you’ll discover:
The 10 essential SRA IT requirements every solicitor must meet
A detailed compliance checklist to audit your current systems
Common IT compliance mistakes that trigger SRA intervention
How to achieve and maintain ongoing compliance
Cost-effective ways to implement compliant IT infrastructure
Where to get expert help with SRA technology requirements
The SRA IT requirements for solicitors aren’t contained in a single document titled “IT Requirements.” Instead, they’re woven throughout the SRA Standards and Regulations, the SRA Code of Conduct, and various guidance documents. This can make compliance feel complex, but the underlying principles are clear.
Where IT Compliance Sits in SRA Standards
The SRA Standards and Regulations 2019 (which came into force in November 2019 and have been updated since) set out the fundamental obligations that affect your IT systems:
Key relevant standards:
Principle 2: Acting with integrity
Your IT systems must maintain the integrity of client data
No unauthorised access or disclosure
Secure handling of confidential information
Principle 4: Acting in the best interests of each client
Technology that protects client confidentiality
Systems that safeguard client money and assets
Business continuity to serve clients even during disruption
Principle 5: Providing a proper standard of service
Competent use of technology
Systems that support effective case management
Technology that doesn’t compromise service delivery
Principle 7: Running the business effectively
Effective information governance
Business continuity planning
Risk management including cyber security
The SRA Code of Conduct IT Implications
Paragraph 6.3 states you must ensure that your systems and controls:
Keep client money and assets safe
Account for all client money
Maintain effective governance structures
Paragraph 8.1 requires you to:
Protect client information and confidentiality
Maintain proper systems for this protection
These aren’t suggestions, they’re mandatory obligations.
Recent SRA Guidance Updates (2024-2026)
The SRA has increasingly focused on technology and cyber security:
November 2024: Updated guidance on cyber security risk management March 2025: Enhanced requirements for cloud service providers September 2025: Specific guidance on AI use in legal practices January 2026: Current standards for remote working security
The trend is clear: The SRA expects solicitors to maintain robust, current technology security measures. “We’re a small firm” or “we don’t have the budget” aren’t accepted excuses for non-compliance.
Why IT Compliance is Non-Negotiable
Legal obligations:
SRA Standards and Regulations (mandatory)
Data Protection Act 2018 (criminal offences for breaches)
Before diving into specific requirements, understanding the real-world consequences of non-compliance provides essential context.
Real Consequences of IT Non-Compliance
SRA Interventions:
In 2024-2025, the SRA intervened in 47 practices specifically citing IT security failures as a primary or contributing factor. Common triggers included:
Client data breaches due to inadequate security
Ransomware attacks that compromised client files
Loss of client money due to email compromise
Inability to account for client funds after system failures
Inadequate backup leading to permanent data loss
Once the SRA intervenes:
Your practising certificate can be suspended immediately
An intervention agent takes control of your practice
All client files are frozen pending security audit
Costs typically £50,000-£200,000 paid from practice assets
Your reputation in the legal community is severely damaged
Clients move to other firms
Staff lose jobs
Years of building your practice can be destroyed in days
Client Claims and Compensation
Scenario: A conveyancing practice suffered a ransomware attack that encrypted all active case files three days before scheduled completions. Inadequate backups meant files were unrecoverable.
The IT failure that caused this? Not implementing the basic SRA requirement for secure, tested backups.
Cyber Insurance Implications
Most solicitor cyber insurance policies contain specific requirements around IT security. If you suffer a cyber attack and your IT systems don’t meet these standards, your claim can be denied.
Common policy requirements:
Multi-factor authentication on all systems
Regular software updates and patches
Encryption of sensitive data
Regular tested backups
Security awareness training for staff
Incident response plan
If you’ve been paying £3,000-£8,000/year for cyber insurance but aren’t compliant with these requirements, your coverage may be worthless when you need it most.
Reputational and Commercial Impact
Beyond regulatory consequences:
Client confidence: Once word spreads that your practice suffered a data breach, clients worry:
“Is my information safe?”
“Should I move to another firm?”
“Can I trust them with sensitive matters?”
Referral relationships: Other solicitors, accountants, and IFAs who refer work to you reconsider:
“I can’t risk my clients with a firm that has security issues”
Professional referral networks close
Recruitment and retention: Good solicitors and staff want to work for professionally run practices:
“If they can’t get IT security right, what else is wrong?”
Difficulty attracting quality team members
Personal Liability for Partners
Directors and partners can face personal consequences:
SRA disciplinary action:
Fines
Conditions on practising certificates
Suspension
Strike off (career ending)
Personal liability:
Data Protection Act criminal offences (up to £5,000 fine, unlimited for directors)
GDPR fines (whilst typically organisational, directors can face prosecution)
Professional negligence claims
Insurance doesn’t always cover these personal liabilities, particularly if deliberate non-compliance is proven.
The Bottom Line
Achieving SRA IT compliance isn’t about ticking boxes, it’s about:
Protecting your clients’ interests (your fundamental duty)
Safeguarding your practice from catastrophic failure
Ensuring business continuity
Maintaining your professional reputation
Meeting your legal and regulatory obligations
Sleeping soundly knowing your systems are secure
The investment in proper IT compliance (typically £5,000-£15,000/year for a small-medium practice) is trivial compared to the cost of getting it wrong (£50,000-£500,000+ plus potential practice closure).
The 10 Essential SRA IT Requirements for Solicitors
Let’s break down the SRA IT requirements for solicitors into 10 specific, actionable areas. Each requirement links directly to SRA obligations and includes practical implementation guidance.
1. Client Confidentiality & Data Protection
SRA Obligation: Code of Conduct Para 6.3, 6.4, 8.1 – Protect client information and maintain confidentiality
What the SRA expects:
Your IT systems must ensure client information remains confidential and is protected from unauthorised access, disclosure, or loss.
Specific requirements:
Encryption of sensitive data:
Client files stored on servers or cloud: Encrypted at rest (AES-256 minimum)
Data in transit: TLS 1.2 or higher for all client data transmission
Laptops and mobile devices: Full disk encryption enabled
USB drives containing client data: Hardware encrypted or BitLocker protected
Technical security controls that protect against current cyber threats, regularly updated to address emerging risks.
Specific requirements:
Firewall protection:
Enterprise-grade firewall (not consumer router)
Configured to block malicious traffic
Regular firmware updates
Logging enabled for security monitoring
Regular rule reviews
Antivirus and anti-malware:
Enterprise endpoint protection on all devices
Real-time scanning enabled
Automatic updates
Centrally managed (not individual installations)
Regular scans scheduled
Multi-factor authentication (MFA):
MFA required for all email access
MFA required for case management systems
MFA required for remote access
MFA required for financial systems
MFA required for administrative accounts
Email security:
Advanced spam filtering
Malware scanning
Phishing protection
Sender verification (SPF, DKIM, DMARC)
Email encryption capability
Patch management:
Operating system updates applied within 30 days
Critical security patches applied within 7 days
Application updates managed
Firmware updates for network devices
Testing process for updates
Vulnerability management:
Regular vulnerability scans
Penetration testing annually (for larger firms)
Remediation of identified vulnerabilities
Third-party security assessments
Implementation checklist:
Enterprise firewall installed and configured
Endpoint protection on all devices
MFA enabled for all systems
Email security advanced protection active
Patch management process documented
Updates applied within required timeframes
Last vulnerability assessment: [Date]
Common failure points:
❌ Consumer-grade router as only firewall
❌ Free antivirus on some machines, none on others
❌ No MFA (“it’s annoying”)
❌ Basic email filtering only
❌ Updates applied “when we remember”
❌ Never conducted security assessment
Cyber Essentials Certification:
Many cyber insurance policies and government contracts require Cyber Essentials certification. This certification demonstrates you meet baseline security standards and aligns closely with SRA expectations.
Communication encryption requirements in contracts
Implementation checklist:
Email encryption system available
Staff trained on when to use encryption
Secure client portal deployed
Video conferencing security configured
Mobile device policy documented
Third-party communication channels secure
Client guidance on secure communications provided
Common failure points:
❌ Sending unencrypted emails with client data
❌ No client portal (relying on email only)
❌ Using personal email accounts
❌ Unsecured video meetings
❌ Staff using personal phones/WhatsApp
❌ No verification of recipient before sending
SRA guidance is clear: Unencrypted email should not be used for highly sensitive information. If you’re emailing unredacted identity documents, financial information, or confidential legal advice, you need encryption or a secure portal.
7. GDPR Compliance for Client Data
SRA Obligation: Data Protection Act 2018, GDPR, SRA Standards (client information protection)
What the SRA expects:
Full compliance with data protection legislation, which overlaps significantly with SRA obligations on protecting client information.
Specific requirements:
Lawful basis for processing:
Document lawful basis for processing client data (typically contract or legitimate interests)
Privacy notices for clients
Consent mechanisms where required
Records of processing activities (ROPA)
Data retention and disposal:
Retention policy documented (typically 7 years+)
Secure disposal when retention expires
Shredding or secure digital deletion
Disposal records maintained
Client requests for deletion handled
Data subject rights:
Process for Subject Access Requests (SAR)
Response within 30 days
Verification of requestor identity
Redaction of third-party information
Exemptions understood (legal professional privilege)
Data Protection Impact Assessments:
DPIA for high-risk processing
New systems assessed for privacy impact
Third-party data sharing reviewed
Cloud service providers assessed
Breach notification:
Data breach detection procedures
Assessment of breach severity
ICO notification within 72 hours (if required)
Client notification (if high risk)
Breach register maintained
Third-party processors:
Data Processing Agreements with all processors
Due diligence on processor security
Regular reviews of processor compliance
Processor breach notification obligations
Data Protection Officer (if required):
Larger practices may need DPO
DPO responsibilities understood
Contact details published
Implementation checklist:
Privacy notice on website and provided to clients
Retention policy documented
SAR process documented and tested
Data Processing Agreements with all suppliers
Breach notification procedure documented
Staff trained on GDPR obligations
Records of Processing Activities maintained
Common failure points:
❌ No privacy notice
❌ Keeping client data indefinitely
❌ No process for SARs
❌ No Data Processing Agreements with IT suppliers
❌ Data breaches not reported
❌ Staff don’t understand GDPR
Important: The ICO (Information Commissioner’s Office) can fine organisations up to £17.5 million or 4% of turnover (whichever is higher) for serious GDPR breaches. Solicitor practices aren’t exempt.
8. Case Management System Security
SRA Obligation: Principle 7 – Effective business management with proper systems
What the SRA expects:
Your practice management software must be secure, reliable, and protect client confidentiality whilst enabling effective case management.
Specific requirements:
System selection:
Legal sector-specific software (not generic CRM)
Hosted by reputable provider OR secure self-hosted
Regular security updates from vendor
Vendor financial stability (won’t disappear)
ISO 27001 or equivalent certification
Access security:
Role-based access within system
Matter-level permissions (Chinese walls)
Audit trails of all access
Cannot disable logging
Regular access reviews
Data protection:
Encryption at rest
Encryption in transit
Backup included in service (if cloud)
UK/EU data storage (GDPR compliance)
Data Processing Agreement with vendor
Integration security:
Secure APIs for integrations
Accounting software integration secure
Document management integration
Email integration secure
Third-party plugin assessment
Business continuity:
Service Level Agreement (SLA) with uptime guarantees
Disaster recovery capabilities
Data export capabilities (not locked in)
Support availability and response times
Financial controls:
SRA Accounts Rules compliance
Client money protection
Reconciliation capabilities
Audit trail of all transactions
Cannot delete or alter historical transactions
Popular systems for UK solicitors:
Practice Evolve
Proclaim
Legal Suite
Osprey Approach
LEAP
ActionStep
(These systems, when properly configured and used within secure infrastructure, can meet SRA requirements)
Implementation checklist:
Case management system from reputable vendor
System configured with role-based access
Audit logging enabled and cannot be disabled
Data Processing Agreement with vendor
Regular backups confirmed
SLA in place with acceptable terms
Financial controls meet Accounts Rules
Staff trained on security features
Common failure points:
❌ Using unsupported legacy software
❌ Everyone has full system access
❌ Audit logs not enabled or not reviewed
❌ No DPA with case management provider
❌ No backups (relying entirely on cloud vendor)
❌ Inadequate financial controls
Cloud vs. On-Premise:
Both can be SRA-compliant when properly implemented:
Cloud (SaaS):
✅ Vendor handles infrastructure security
✅ Automatic updates
✅ Scalability
⚠️ Must verify vendor security (ISO 27001, SOC 2)
⚠️ Data Processing Agreement essential
⚠️ Data location matters (UK/EU preferred)
On-Premise:
✅ Full control over security
✅ Data stays in your premises
⚠️ You’re responsible for all security measures
⚠️ Requires expertise and resources
⚠️ Higher upfront cost
Most small-medium practices choose cloud for cost and simplicity, provided due diligence on vendor security is completed.
9. Mobile Device & Remote Working Security
SRA Obligation: Code of Conduct Para 6.3, 8.1 – Protecting client information regardless of location
What the SRA expects:
Secure remote working arrangements that maintain the same level of client confidentiality protection as office-based work.
❌ Staff working on trains/cafes with sensitive data visible
❌ No policy on home working security
❌ No procedure for lost/stolen devices
COVID-19 legacy:
The pandemic forced rapid remote working adoption. Many practices implemented temporary solutions that became permanent without proper security review. Now is the time to formalise and secure these arrangements.
Whilst not explicitly mandated by the SRA, cyber insurance is increasingly essential for prudent risk management. However, having a policy isn’t enough, you must meet the policy requirements.
Specific requirements:
Policy coverage understanding:
Data breach response costs
Business interruption coverage
Cyber extortion (ransomware)
Forensic investigation costs
Legal fees and client notification
Regulatory fines (where insurable)
Reputational damage mitigation
Policy compliance requirements:
MFA implementation
Regular backups
Security patch management
Security awareness training
Incident response plan
Vendor due diligence
Due diligence at renewal:
Accurate declaration of security measures
Update insurers on changes
Disclose any incidents
Review coverage limits
Understand exclusions
Claims procedures:
Know how to report incidents
Preserve evidence
Follow insurer procedures
Breach coach/legal support
Documentation requirements
Continuous compliance:
Maintain required security measures
Document compliance for claims
Regular security attestations
Don’t let standards slip after purchase
Implementation checklist:
Cyber insurance policy in place
Policy requirements fully understood
All policy requirements currently met
Compliance evidence documented
Claims procedure documented
Key contacts identified
Policy reviewed annually
Coverage adequate for practice size
Common failure points:
❌ No cyber insurance
❌ Policy purchased but requirements not met
❌ Requirements met at purchase but not maintained
❌ Inaccurate declarations at renewal
❌ Inadequate coverage limits
❌ Not understanding what’s covered/excluded
Important: If you suffer a cyber attack and your claim is denied because you didn’t meet policy requirements (e.g., no MFA despite policy requiring it), you’ll face the full financial impact with no insurance support. This can be practice-ending.
Typical cyber insurance costs for solicitors:
5-10 users: £1,500-£3,000/year
11-25 users: £3,000-£6,000/year
26-50 users: £6,000-£12,000/year
(Costs vary significantly based on practice area, claims history, and security measures)
SRA IT Compliance Checklist
Use this comprehensive checklist to audit your practice’s current compliance status. Rate each item as:
70-89% GREEN: Good compliance, address amber/red items within 3 months
50-69% GREEN: Moderate compliance, significant improvement needed within 6 months
Below 50% GREEN: Poor compliance, immediate action required, consider professional help
Any RED items are urgent priorities requiring immediate attention.
Download the Complete Checklist
Get the printable PDF version of this checklist plus detailed remediation guidance for common issues.
Common SRA IT Compliance Mistakes Solicitors Make
Understanding where other practices fail helps you avoid the same pitfalls. These are the most common SRA IT requirements mistakes we see when assessing solicitor practices.
Mistake 1: “We’re Too Small to Be Targeted”
The assumption: “Cyber criminals target large firms, not 5-person practices.”
The reality: Small practices are specifically targeted because:
Easier to breach (less sophisticated security)
Less likely to have cyber insurance
More likely to pay ransoms quickly (can’t afford downtime)
Gateway to larger firms and clients
Handle valuable data (property, financial, commercial)
2025 statistics: 67% of cyber attacks on legal practices targeted firms with fewer than 20 employees.
What to do: Implement the same security standards regardless of size. The SRA makes no exemptions for small practices.
Mistake 2: Relying Solely on Your Case Management Provider’s Security
The assumption: “Our case management system is cloud-based and secure, so we’re compliant.”
The reality: Your case management provider handles their infrastructure security, but you’re responsible for:
User access management
Password policies
MFA implementation
Staff training
Endpoint security (laptops, phones)
Email security
Physical security
Business continuity planning
Your vendor’s security doesn’t absolve your SRA obligations.
What to do: Understand the shared responsibility model. Vendor secures their infrastructure; you secure access, usage, and integration points.
Mistake 3: Using Consumer-Grade IT Products
The assumption: “Microsoft 365 Business Basic is enough for our practice.”
The reality: Consumer and basic business products lack essential security features:
Basic M365: No conditional access, limited security tools
Consumer routers: Inadequate firewall for business use
Personal Dropbox: No enterprise controls or encryption
Free antivirus: Limited protection and no central management
Personal devices: No management or security controls
What to do: Invest in business/enterprise-grade security tools with proper management and monitoring.
Mistake 4: No Testing of Backups or Disaster Recovery
The assumption: “We have backups configured, so we’re protected.”
The reality: Many practices discover their backups don’t work when disaster strikes:
Backup job configured but failing silently for months
Backup files corrupted and unrestorable
Backup encryption key lost
Restore process never tested, doesn’t work under pressure
Backup doesn’t include all critical systems
SRA interventions: Multiple cases where practices couldn’t restore client files after ransomware, leading to intervention.
What to do:
Monthly: Test restore of sample files
Quarterly: Full restore test to alternative location
Annually: Disaster recovery simulation
Document all tests and results
Mistake 5: Everyone Has Admin Rights
The assumption: “It’s easier if everyone can install software and make changes.”
The reality: Giving all users administrator rights:
Allows ransomware to spread system-wide
Enables accidental deletion of critical data
Permits unauthorised software installation
Makes forensic investigation difficult after incidents
Violates principle of least privilege
What to do: Standard users for day-to-day work. Admin rights only for IT staff and specific tasks.
Mistake 6: Unencrypted Email for Client Communications
The assumption: “Email is fine for client communications, everyone uses it.”
The reality: Standard email is not secure:
Transmitted unencrypted across the internet
Readable by email providers and intermediaries
Vulnerable to interception
Doesn’t meet confidentiality obligations for sensitive data
SRA position: Unencrypted email inappropriate for highly confidential information.
Use secure client portals for sensitive document exchange
Train staff on when encryption is required
Client guidance on secure communications
Mistake 7: Former Staff Still Have System Access
The assumption: “We’ll disable their account when we remember.”
The reality: Delayed access removal creates serious risks:
Disgruntled ex-staff accessing confidential data
Accounts compromised after staff leave
Data exfiltration by former employees
Violation of access control requirements
What to do:
Immediate account deactivation (same day as departure)
Automated leaver process with checklist
Regular access audits to catch missed accounts
Alert system for dormant accounts
Mistake 8: No Security Training for Staff
The assumption: “Our staff know not to click suspicious emails.”
The reality: Staff are the weakest link in security:
Phishing attacks increasingly sophisticated
Social engineering targets legal practices
Staff unaware of security policies
Poor password practices common
Physical security breaches (tailgating, etc.)
Statistics: 88% of data breaches involve human error.
What to do:
Mandatory annual security awareness training
Quarterly phishing simulation exercises
Regular security reminders and updates
Incident reporting culture (no blame for honest mistakes)
Role-specific training (accounts staff, IT admins)
Mistake 9: Treating Compliance as One-Time Exercise
The assumption: “We did a security review in 2020, so we’re compliant.”
The reality: IT security requires continuous attention:
New threats emerge constantly
Software requires regular updates
Staff turnover changes access requirements
Business changes affect security needs
Compliance standards evolve
What to do:
Annual comprehensive security review
Quarterly access audits
Monthly backup testing
Continuous monitoring and patching
Regular policy reviews and updates
Mistake 10: No Incident Response Plan
The assumption: “We’ll figure out what to do if something happens.”
The reality: During a cyber attack:
Panic prevents clear thinking
Delayed response worsens impact
Evidence gets destroyed
SRA reporting obligations missed
Costly mistakes made
What to do:
Document incident response plan
Assign clear roles and responsibilities
Include external support contacts (IT, legal, insurers)
Practice with tabletop exercises
Update plan regularly
Technology Standards for Different Practice Areas
Whilst core SRA IT requirements for solicitors apply universally, different practice areas have specific technology considerations.
Conveyancing Practices
Additional IT considerations:
Case management integration:
Land Registry portal integration
Search provider integrations
Lender panel management systems
Anti-money laundering checks
ID verification systems
High-risk transactions:
Wire transfer fraud prevention (APP fraud)
Payment verification procedures
Dual authorisation for payments
Client bank detail verification
Secure communication of account details
Volume and speed:
High transaction volumes
Quick turnarounds required
Automated workflows
Template management
Completion day pressures
Specific security measures:
Payment verification protocols
Client education on APP fraud
Secure channels for bank details
Dual sign-off on account changes
Real-time transaction monitoring
Litigation Practices
Additional IT considerations:
Document volume:
Large disclosure exercises
Document management systems
Version control critical
Privileged document protection
E-discovery capabilities
Deadlines and court requirements:
Court portal access
Electronic filing requirements
Serve document systems
Deadline management
Audit trails for service
Expert and counsel collaboration:
Secure file sharing
External collaboration tools
Privileged communication protection
Large file transfer capabilities
Specific security measures:
Chinese walls between matters
Privilege protection in systems
Disclosure audit trails
Secure external collaboration
Chronology and timeline tools
Family Law
Additional IT considerations:
Highly sensitive information:
Financial disclosures
Domestic abuse documentation
Child welfare concerns
Mental health information
Extra confidentiality requirements
Client vulnerability:
Often emotionally distressed clients
Protection from abusive parties
Secure client communications
Address confidentiality
Court and CAFCASS interaction:
Family court portals
CAFCASS documentation
Financial disclosure systems
Specific security measures:
Enhanced client confidentiality
Restricted access to sensitive files
Secure client communication methods
Address protection measures
Staff training on vulnerability
Corporate/Commercial
Additional IT considerations:
Commercial confidentiality:
M&A transaction security
Due diligence data rooms
Commercial sensitive information
Intellectual property protection
Large transaction values:
High-value deals
International parties
Complex structures
Multiple advisors
Data room management:
Virtual data room services
Access controls and permissions
Audit trails of access
Time-limited access
Specific security measures:
Virtual data room due diligence
Chinese walls for conflicted matters
Deal team access restrictions
Confidentiality ring protocols
International data transfer controls
Private Client
Additional IT considerations:
Wills and probate:
Will storage security
Executor access management
Asset information protection
Lasting Power of Attorney documents
Estate planning:
Tax-sensitive information
Financial planning details
Family circumstances
Long-term document retention
Trusts and tax:
Complex financial structures
HMRC interactions
Long-term client relationships
Multi-generational records
Specific security measures:
Long-term secure document storage
Will register access controls
Succession planning for file access
Extended retention periods
Bereaved client sensitivity
How to Achieve and Maintain SRA IT Compliance
Knowing the requirements is one thing; implementing them systematically is another. Here’s a practical roadmap to achieving SRA IT requirements for solicitors compliance.
Step 1: Conduct a Compliance Gap Analysis
Objective: Understand your current state vs. required state
Process:
Use the compliance checklist (provided earlier in this guide)
Rate each requirement (Green/Amber/Red)
Document specific gaps (what’s missing or inadequate)
Assess risk level (which gaps pose greatest risk)
Estimate remediation effort (time and cost for each item)
Output: Prioritised list of compliance gaps requiring remediation
Time required: 4-8 hours for thorough self-assessment, or engage professional IT security audit (more objective)
Step 2: Create a Remediation Plan
Objective: Structured plan to address all compliance gaps
Approach:
Immediate priorities (0-30 days):
Critical security gaps (no MFA, no backups, etc.)
Active non-compliance with SRA standards
High-risk vulnerabilities
Items required for cyber insurance
Short-term priorities (1-3 months):
Important security improvements
Policy and procedure documentation
Staff training programmes
Access control improvements
Medium-term priorities (3-6 months):
System replacements or upgrades
Advanced security measures
Process improvements
Comprehensive testing
Long-term priorities (6-12 months):
Strategic technology improvements
Advanced capabilities
Continuous improvement initiatives
Document the plan:
Specific actions for each gap
Responsible person assigned
Target completion date
Budget required
Success criteria
Step 3: Implement Priority Fixes
Critical actions that most practices need:
Week 1: Emergency security basics
Enable MFA on all email accounts
Enforce strong password policy
Verify backups are running and tested
Review and disable former staff accounts
Update all critical security patches
Week 2: Documentation essentials 6. Write basic information security policy 7. Document incident response procedure 8. Create user access management process 9. Establish backup testing schedule 10. Document business continuity basics
Week 3: Training and awareness 11. Conduct security awareness training for all staff 12. Distribute security policies 13. Test incident response procedure 14. Run phishing simulation 15. Document training completion
Week 4: Technical improvements 16. Deploy endpoint protection on all devices 17. Configure email encryption 18. Implement secure client portal 19. Set up access logging and monitoring 20. Schedule regular security reviews
Step 4: Document Everything
Why documentation matters:
For SRA compliance:
Demonstrates systematic approach
Evidences governance and oversight
Shows policies communicated to staff
Proves compliance during investigations
For cyber insurance:
Required for policy compliance
Needed for claims
Demonstrates due diligence
For business operations:
Staff know what’s expected
Consistency in procedures
Training reference
Continuity when staff leave
Essential documents:
Information Security Policy (10-15 pages)
Scope and objectives
Roles and responsibilities
Technical security standards
User responsibilities
Incident response
Review process
Acceptable Use Policy (3-5 pages)
Email and internet use
Device usage
Password requirements
Remote working
Prohibited activities
Data Protection and Retention Policy (8-12 pages)
Legal basis for processing
Retention periods
Disposal procedures
Subject rights
Breach response
Business Continuity Plan (15-20 pages)
Risk assessment
Recovery strategies
Contact details
Step-by-step procedures
Test schedule
Incident Response Plan (8-10 pages)
Incident classification
Response team roles
Step-by-step procedures
Communication protocols
SRA reporting obligations
Access Control Policy (5-7 pages)
User provisioning
Access levels
Review procedures
Leavers process
Remote Working Policy (5-7 pages)
Device security requirements
VPN usage
Home environment standards
Public working restrictions
Template documents available: Many legal IT providers offer template policies that can be customised for your practice.
Step 5: Staff Training and Awareness
Why training is critical:
Staff are your first line of defense (and your biggest vulnerability):
Most breaches involve human error
Phishing targets staff, not systems
Policy compliance requires understanding
Security culture starts with awareness
Training programme structure:
New starter induction (Day 1):
Information security overview
Acceptable use policy
Password requirements
Confidentiality obligations
Who to contact for IT issues
Annual mandatory training (All staff):
Current threat landscape
Phishing awareness
Password security
Physical security
Incident reporting
Policy updates
Role-specific training:
Accounts staff: Payment fraud prevention
Fee earners: Client confidentiality
IT admins: Security best practices
Partners: Governance and oversight
Ongoing awareness:
Monthly security tips
Quarterly phishing simulations
Incident lessons learned
News about legal sector breaches
Training documentation:
Attendance records
Quiz/assessment results
Training materials provided
Annual refresh completion
Step 6: Implement Monitoring and Review
Ongoing compliance requires continuous attention:
Monthly activities:
Review backup success/failures
Test restore of sample files
Review access logs for anomalies
Check for system updates
Security incident review
Quarterly activities:
Full restore test
Access rights review and recertification
Security policy review
Phishing simulation
Report to partners/board
Annual activities:
Comprehensive security audit
Risk assessment update
Policy review and update
Penetration testing (larger firms)
Business continuity plan test
Staff training refresh
Cyber insurance renewal review
Assign responsibilities:
Don’t assume “someone” will do it
Named partners/directors responsible
IT team or provider accountable
Regular reporting to management
Step 7: Engage Professional Support
When to get expert help:
Immediate professional help needed if:
✓ Current state is seriously non-compliant (50%+ red on checklist)
✓ You’ve suffered a security incident
✓ SRA has raised concerns
✓ Cyber insurance application rejected due to security
Cost of Non-Compliance vs Investment in Compliance
Understanding the financial implications helps justify proper investment in SRA IT requirements compliance.
The True Cost of Non-Compliance
Direct costs of a serious IT security incident:
SRA intervention:
Intervention agent fees: £50,000-£200,000
Legal costs: £20,000-£100,000
Lost practice value: £100,000-£1,000,000+
Partner personal liability: Variable
Total: £170,000-£1,300,000+
Data breach response:
Forensic investigation: £15,000-£50,000
Legal advice: £10,000-£30,000
Client notification: £5,000-£20,000
Credit monitoring for affected clients: £50-£100 per person
PR/reputation management: £10,000-£50,000
Total: £40,000-£150,000+
Ransomware attack:
Ransom payment (if paid): £5,000-£500,000
Recovery costs: £20,000-£100,000
Lost revenue during downtime: £10,000-£50,000 per week
Data restoration: £15,000-£75,000
System rebuild: £10,000-£50,000
Total: £60,000-£775,000+
ICO fines:
GDPR fines: Up to £17.5M or 4% turnover
Realistic for solicitors: £10,000-£500,000
DPA criminal fines: Up to £5,000 (summary), unlimited (indictment)
Client compensation claims:
Professional indemnity claims: £50,000-£500,000+ per incident
Excess payments: £5,000-£25,000 per claim
Premium increases: 50-200% for 3-5 years
Business impact:
Revenue loss during incident: £5,000-£50,000 per week
Client attrition: 20-40% over following year
Staff departures: Key staff leave
Reputational damage: Difficult to quantify, potentially practice-ending
Total potential cost of serious non-compliance incident: £500,000-£3,000,000+
This doesn’t include the stress, anxiety, sleepless nights, and career impact on partners.
Investment in Compliance
Annual cost of proper IT compliance for solicitor practices:
5-10 person practice:
Managed IT support: £850-£1,100 per user = £5,100-£11,000/year
Cyber Essentials certification: £300-£500/year
Cyber insurance: £1,500-£3,000/year
Security training: £500-£1,000/year
Annual security audit: £1,000-£2,000/year
Total: £8,400-£17,500/year
11-25 person practice:
Managed IT support: £850-£1,100 per user = £11,220-£27,500/year
Cyber Essentials Plus: £1,000-£2,000/year
Cyber insurance: £3,000-£6,000/year
Security training: £1,000-£2,000/year
Annual security audit: £2,000-£3,500/year
Total: £18,220-£41,000/year
26-50 person practice:
Managed IT support: £850-£1,100 per user = £26,520-£55,000/year
ISO 27001 or advanced certification: £3,000-£8,000/year
Cyber insurance: £6,000-£12,000/year
Security training: £2,000-£4,000/year
Penetration testing: £3,000-£8,000/year
Total: £40,520-£87,000/year
Return on Investment Calculation
Example: 15-person litigation practice
Annual compliance investment: £25,000
Risk mitigation value:
Without compliance, 10-year probability:
Serious cyber incident: 60% chance
Average cost: £400,000
Expected cost: £240,000
With compliance:
Serious cyber incident: 5% chance (12x reduction)
Average cost: £100,000 (better response, insurance covers more)
Expected cost: £5,000
10-year comparison:
Without compliance: £240,000 expected incident cost
With compliance: £250,000 investment + £5,000 incident cost = £255,000
Difference: £15,000 more spent BUT…
Additional value of compliance:
✓ Practice continues operating (priceless)
✓ Professional reputation intact
✓ Partners sleep soundly
✓ Cyber insurance actually pays claims
✓ Client confidence maintained
✓ SRA intervention avoided
✓ Business value preserved
The “£15,000 more” buys £1,000,000+ in protection and peace of mind.
Cost Per Transaction Perspective
Putting IT security cost in context:
15-person conveyancing practice:
500 completions per year
IT security cost: £25,000/year
Cost per completion: £50
Question: Would clients happily pay £50 per transaction for proper data protection and security?
Answer: Absolutely. It’s a trivial cost vs. the value and sensitivity of the transaction.
The cost of SRA IT compliance is a small fraction of 1% of most practices’ turnover, it’s a fundamental cost of professional practice, like indemnity insurance.
Choosing SRA-Compliant IT Support for Your Practice
Not all IT support providers understand SRA IT requirements for solicitors. Here’s how to select one that does.
What to Look For
Legal sector experience:
✓ Current solicitor clients (ask for references)
✓ Understanding of SRA standards
✓ Knowledge of legal practice management systems
✓ Experience with law society requirements
✓ Familiarity with conveyancing/litigation-specific needs
Security credentials:
✓ Cyber Essentials certified (minimum)
✓ ISO 27001 (desirable for larger practices)
✓ Microsoft Partner status
✓ Security-focused rather than general IT
✓ Incident response capabilities
Service delivery:
✓ Local presence for on-site support
✓ Defined response times (SLA)
✓ 24/7 emergency support available
✓ Proactive monitoring (not just reactive)
✓ Regular security reviews and reporting
Compliance support:
✓ Help with SRA compliance requirements
✓ Policy and procedure documentation
✓ Staff training provision
✓ Audit support
✓ Incident response planning
Transparent pricing:
✓ Clear, predictable monthly costs
✓ What’s included vs. extra
✓ No hidden fees
✓ Scalable as practice grows
Essential Questions to Ask
About their legal sector experience:
“How many solicitor practices do you currently support?”
Look for: 5+ current solicitor clients
“Can you provide references from practices similar to ours?”
Insist on speaking with actual clients
“What specific SRA requirements do you help practices meet?”
Should demonstrate knowledge of SRA standards
“Which legal practice management systems have you supported?”
Experience with your specific system beneficial
About security and compliance:
“Are you Cyber Essentials certified?”
Minimum credential to look for
“How do you ensure our systems meet SRA IT requirements?”
Should have systematic approach
“What’s your process for security incident response?”
Detailed procedure, not vague promises
“How often do you conduct security reviews?”
Quarterly minimum
About service delivery:
“What are your guaranteed response times?”
4-hour response for critical issues reasonable
“How quickly can you get someone on-site to our office?”
Same-day for local provider
“Is 24/7 emergency support available?”
Essential for serious incidents
“What’s included in your monthly fee vs. what costs extra?”
Transparency critical
About practical support:
“Do you provide staff security training?”
Should offer or facilitate
“Can you help us with SRA compliance documentation?”
You’ve read the guide. You understand the SRA IT requirements for solicitors. Now it’s time to take action.
Your Immediate Next Steps (This Week)
Day 1: Assess Your Current State
Download the compliance checklist (provided earlier)
Block 2 hours in your diary
Complete the self-assessment honestly
Count your Red/Amber/Green scores
Identify your critical gaps
Day 2: Secure Quick Wins
Enable MFA on all email accounts (30 minutes)
Enforce password complexity (15 minutes)
Test your last backup restore (1 hour)
Review user access and disable ex-staff (30 minutes)
Schedule security updates (15 minutes)
Day 3: Documentation Basics
Write basic security policy (2 hours, or use template)
Document incident response procedure (1 hour)
Create leavers checklist (30 minutes)
Start compliance evidence folder
Schedule partner discussion about IT security
Day 4: Training and Awareness
Brief staff on security importance (15 minutes)
Share password requirements
Explain incident reporting process
Schedule formal training session
Send phishing awareness reminder
Day 5: Plan Next Steps
Review your assessment results
Create 90-day action plan
Assign responsibilities
Schedule follow-up reviews
Consider professional support if needed
30-Day Compliance Sprint
Week 1: Critical security
MFA everywhere
Backup testing
Access reviews
Emergency patching
Week 2: Documentation
Security policy
Incident response
Business continuity basics
Retention policy
Week 3: Training
All-staff security awareness
Role-specific training
Phishing simulation
Policy distribution
Week 4: Technical improvements
Endpoint protection
Email encryption
Client portal
Monitoring setup
90-Day Full Compliance Programme
Month 1: Foundation
Complete gap analysis
Implement critical fixes
Essential documentation
Staff training programme
Month 2: Technical improvements
Security tool deployment
System hardening
Integration security
Testing and validation
Month 3: Process and governance
Advanced documentation
Continuous monitoring
Review procedures
Ongoing improvement plan
When to Get Professional Help
DIY is realistic if:
✓ Under 10 staff
✓ Someone has IT knowledge
✓ Modest compliance gaps
✓ Time to invest
✓ Comfortable with technology
Get professional help if:
✓ Over 15 staff
✓ Significant non-compliance
✓ Previous security incident
✓ No internal IT expertise
✓ SRA concerns raised
✓ Complex technology environment
✓ Want it done properly first time
Take Action Now
The SRA is clear: You must protect client information with appropriate systems and controls.
Every day of non-compliance increases your risk.
Every week without proper backups is a gamble with your practice’s future.
Every month without MFA is an open invitation to cyber criminals.
Don’t wait for an incident to force action. Don’t wait for an SRA investigation. Don’t gamble with your professional reputation and your clients’ confidentiality.
Start today.
Conclusion: SRA IT Compliance is Non-Negotiable
SRA IT requirements for solicitors aren’t optional extras or aspirational goals, they’re fundamental professional obligations that protect your clients, your practice, and your career.
The key messages from this guide:
✅ SRA compliance affects every solicitor – Size doesn’t exempt you ✅ IT security is integral to professional obligations – Not separate ✅ Consequences of non-compliance are severe – Practice-ending potential ✅ Compliance is achievable – Systematic approach works ✅ Investment is justified – Tiny vs. cost of failure ✅ Professional help available – Don’t struggle alone
The 10 essential requirements:
Client confidentiality & data protection
Information security management
Cyber security measures
Data backup & business continuity
Access control & user management
Secure communications
GDPR compliance
Case management system security
Mobile device & remote working security
Cyber insurance
Your practice likely has some compliance gaps. Every practice does. The question is: What are you going to do about it?
Get Expert Help with SRA IT Compliance in West Sussex
ATS Connection specialises in IT support for solicitors across West Sussex, helping practices achieve and maintain SRA compliance.
If you’re a small business owner trying to understand Microsoft Entra ID for small business, you’re not alone. Microsoft’s rebrand from Azure Active Directory (Azure AD) to Microsoft Entra ID has created confusion, and many SME owners are wondering: “What is this? Do I need it? And how much will it cost?”
Here’s the straightforward answer: Microsoft Entra ID is your business’s digital identity and access management system. It controls who can access what in your Microsoft 365 environment and other cloud applications. For small businesses with 5+ employees, it’s becoming essential for security, but understanding when you need it, and which version, requires cutting through the marketing jargon.
This comprehensive guide explains Microsoft Entra ID in plain English, helping you determine if your small business needs it, what it costs, and how to implement it without getting overwhelmed by technical complexity.
What you’ll discover:
What Microsoft Entra ID actually is (and why Microsoft changed the name)
Microsoft Entra ID for small business is essentially your company’s digital identity system in the cloud. Think of it as a sophisticated security guard and administrator that manages who in your company can access what applications and data.
The Simple Explanation
In the simplest terms, Microsoft Entra ID:
✓ Manages user accounts – Creates and controls employee login credentials ✓ Controls access – Determines who can access which applications and files ✓ Enforces security – Adds extra protection layers like multi-factor authentication ✓ Provides single sign-on – Lets employees use one login for multiple applications ✓ Monitors activity – Tracks who’s accessing what and when
Real-world analogy: If your business were a building, Entra ID would be the combination of:
The employee badge system (identity)
The security desk (authentication)
The access card readers (authorisation)
The security camera system (monitoring)
The building manager (administration)
All of this happens in the cloud, so it works whether employees are in your office, working from home, or accessing systems from their mobile devices.
The Technical Definition (For Those Who Want It)
Microsoft Entra ID is a cloud-based identity and access management (IAM) service. It provides:
Identity management – Centralised user and group administration
Authentication – Verifies users are who they claim to be
Authorisation – Determines what authenticated users can access
Single sign-on (SSO) – One login for multiple applications
Identity protection – Threat detection and response
Identity governance – Access lifecycle management
For most small businesses: You don’t need to understand all these terms. You just need to know that Entra ID keeps your business applications secure and makes life easier for your employees.
What Microsoft Entra ID is NOT
Common misconceptions:
❌ It’s not just for large enterprises – Small businesses benefit significantly from Entra ID’s security features
❌ It’s not a separate product you buy – If you use Microsoft 365, you already have basic Entra ID included
❌ It’s not only for Microsoft applications – It works with thousands of third-party cloud applications (Salesforce, Dropbox, Zoom, etc.)
❌ It’s not complicated to use – Whilst setup requires some technical knowledge, daily use is straightforward for employees
❌ It’s not optional for security – Modern cybersecurity essentially requires identity management for businesses with cloud applications
According to Microsoft’s 2024 Digital Defence Report, 99.9% of compromised accounts didn’t have multi-factor authentication enabled, a feature that Entra ID provides.
Why Did Microsoft Change from Azure AD to Entra?
If you’ve been confused by the name change from Azure Active Directory to Microsoft Entra ID, you’re not alone. Here’s what happened and why.
The Timeline
Before November 2022:
Service was called “Azure Active Directory” or “Azure AD”
Part of the broader Azure cloud platform
Name suggested it was primarily for Azure services
November 2022:
Microsoft announced the Entra product family
Azure AD became “Microsoft Entra ID”
Rebranding completed through 2023-2024
Today:
Official name is Microsoft Entra ID
Azure AD still appears in some documentation
Both names refer to the same service
Why Microsoft Made the Change
1. Clearer Identity Focus
The Azure branding made it sound like the service was primarily for Azure cloud infrastructure. But most businesses use it for Microsoft 365, not Azure services. The Entra name clarifies it’s about identity management, not just cloud infrastructure.
2. Product Family Expansion
Microsoft now offers multiple “Entra” products:
Microsoft Entra ID (formerly Azure AD) – Core identity service
Microsoft Entra ID Governance – Advanced identity lifecycle management
Microsoft Entra External ID – Customer/partner identity management
Microsoft Entra Permissions Management – Multi-cloud permission control
Microsoft Entra Verified ID – Decentralised identity solutions
3. Reduced Confusion
Many business owners thought Azure AD was:
Only for Azure cloud services (false)
Only for technical Azure developers (false)
Separate from Microsoft 365 (false)
The Entra rebrand helps clarify the service is for all businesses using Microsoft cloud services.
What This Means for Your Small Business
The important part: If you were using Azure AD, you’re now using Microsoft Entra ID. Nothing changed except the name. Your settings, configurations, licences, and functionality remain exactly the same.
You don’t need to:
Migrate to a new service
Reconfigure anything
Purchase new licences
Learn a completely new system
You should know:
Documentation now says “Entra ID” instead of “Azure AD”
Support articles use the new terminology
The Microsoft admin portal displays “Entra ID”
Both names still work in conversation (people understand both)
Bottom line for SMEs: This is purely a naming change. Focus on understanding what the service does, not worrying about the rebrand.
Microsoft Entra ID vs Azure AD: What’s Different?
Let’s clear up the confusion once and for all.
The Short Answer
Microsoft Entra ID and Azure AD are the same service with a new name. Period.
Detailed Comparison
Aspect
Azure AD (Old Name)
Microsoft Entra ID (New Name)
Core functionality
Identity & access management
Identical – identity & access management
Features
SSO, MFA, conditional access, etc.
Exactly the same features
Pricing tiers
Free, P1, P2
Same three tiers with same pricing
Integration with M365
Built-in
Built-in (unchanged)
Licensing
Included with Microsoft 365
Included with Microsoft 365 (same)
Admin portal
Azure portal
Same portal, updated branding
Technical capabilities
Full IAM platform
Identical capabilities
Support
Microsoft support
Same Microsoft support
There is literally no functional difference. It’s a rebrand, not a new product or upgrade.
Why the Confusion Exists
Common questions we hear:
Q: “Do I need to migrate from Azure AD to Entra ID?” A: No. You’re already using Entra ID. Microsoft changed the name automatically.
Q: “Will my Azure AD licences become Entra ID licences?” A: They already did. Same licences, new label.
Q: “Is Entra ID newer/better than Azure AD?” A: It’s not newer, it’s the same service. The technology is continuously updated regardless of name.
Q: “Should I tell my IT provider we want Entra instead of Azure AD?” A: Both terms are fine. Any competent IT provider understands they’re the same.
What You Should Call It
In 2025 and beyond:
Official documentation: “Microsoft Entra ID”
Microsoft support: “Entra ID”
General conversation: Either name works
Technical discussions: Increasingly “Entra ID”
Our advice: Start using “Microsoft Entra ID” to stay current, but don’t worry if you say “Azure AD”, everyone still understands.
Do Small Businesses Need Microsoft Entra ID?
This is the critical question. Microsoft Entra ID for small business isn’t a one-size-fits-all answer. Here’s how to determine if your business needs it.
You Already Have Entra ID (Basic) If…
If you use Microsoft 365, you already have Microsoft Entra ID Free tier. It’s automatically included with:
Microsoft 365 Business Basic
Microsoft 365 Business Standard
Microsoft 365 Business Premium
Any Microsoft 365 subscription
You’re already using Entra ID when you:
Log into Microsoft 365
Reset passwords through the Microsoft portal
Add new users to your Microsoft 365 account
Use OneDrive, Teams, Outlook, or SharePoint
So the real question isn’t “Do I need Entra ID?” but rather “Do I need the paid premium versions?”
When Small Businesses Should Upgrade to Paid Entra ID
You should consider Entra ID P1 or P2 if:
✓ You have 10+ employees
Greater security risks with more users
More complex access requirements
Need for automated user management
✓ Employees work remotely or use mobile devices
Requires conditional access policies
Device management integration
Location-based access controls
✓ You handle sensitive data
Client information (legal, financial, healthcare)
Financial records
Intellectual property
Compliance requirements (GDPR, industry regulations)
✓ You’ve had security incidents
Previous breaches or near-misses
Phishing attempts targeting staff
Unauthorised access attempts
✓ You use multiple cloud applications
Salesforce, Zoom, Dropbox, Adobe, etc.
Want single sign-on across all apps
Need centralised access control
✓ Your industry has compliance requirements
Legal practices (SRA regulations)
Financial services (FCA requirements)
Healthcare (CQC, data protection)
Any regulated industry
✓ You’re growing and need scalability
Adding employees regularly
Expanding to new locations
Need efficient user onboarding/offboarding
When Small Businesses Can Skip Premium Entra ID
The free tier is probably sufficient if:
❌ You have under 5 employees ❌ Everyone works in the same office ❌ You only use Microsoft 365 applications ❌ You have minimal sensitive data ❌ No compliance requirements ❌ Very limited budget for IT security ❌ Simple access needs (everyone has same permissions)
Honest assessment: Even if you meet these criteria, you should still enable basic MFA (multi-factor authentication) which is available in the free tier.
Decision Framework: Do You Need Premium Entra ID?
Ask yourself these questions:
Question
If Yes…
Do you have remote employees?
Consider P1 (conditional access)
Do employees access work from personal devices?
Consider P1 (device policies)
Do you need to restrict access by location?
Consider P1 (conditional access)
Is your industry regulated?
Likely need P1 minimum
Do employees use risky/old passwords?
Consider P1 (password protection)
Have you had phishing attempts?
Consider P1 or P2 (identity protection)
Do you need detailed security reports?
Consider P2 (advanced reporting)
Is automated security response important?
Consider P2 (identity protection)
Score:
0-2 “yes” answers: Free tier is probably fine (but enable MFA!)
3-5 “yes” answers: Strongly consider Entra ID P1
6+ “yes” answers: You should be using Entra ID P1 or P2
Real-World Small Business Scenarios
Scenario 1: 8-Person Accounting Firm in Chichester
Included in Entra ID pricing: ✅ All user licences ✅ Unlimited device registration ✅ Basic support ✅ Standard integrations ✅ All tier-specific features
What typically costs extra:
❌ Microsoft 365 licences (separate cost: £4.50-£20/user/month depending on plan)
❌ Advanced support plans
❌ Some premium SaaS application integrations
❌ Third-party identity tools
❌ Professional implementation services
Hidden Costs to Consider
1. Implementation Time/Cost
DIY setup: 4-12 hours of internal time
Professional setup: £500-£2,000 for SMB
Ongoing management: 1-3 hours/month internal time
2. Training
User training: 30-60 minutes per employee
Admin training: 4-8 hours
Possible training materials: £200-£500
3. Integration with Existing Systems
Most integrations: Included
Complex on-premise integrations: May need professional help (£500-£2,000)
4. Device Management (if needed)
Intune (device management) is separate: £4.40/user/month
Often bundled in Microsoft 365 Business Premium (£18.30/user/month)
ROI: Is Premium Entra ID Worth the Cost?
Cost-benefit analysis for 15-person business:
Entra ID P1 annual cost: £846/year
Potential savings/value:
Benefit
Annual Value
Prevented data breach
£10,000-£100,000+ (avg small business breach cost: £25,000)
Reduced password reset support
£300-£600 (30 resets/year × £10-20 each)
Improved employee productivity
£1,000-£3,000 (SSO time savings, less downtime)
Avoided compliance fines
£1,000-£50,000+ (depends on regulations)
Reduced unauthorised access incidents
£500-£5,000 (per incident avoided)
Insurance premium reduction
£200-£800 (some cyber insurance discounts)
Conservative estimate: £12,000-£25,000 in value/savings vs. £846 cost
ROI: 14:1 to 30:1 return on investment
Even if you prevent just ONE data breach, Entra ID P1 pays for itself many times over.
Licensing Simplification: Microsoft 365 Bundles
Entra ID P1 is included in:
Microsoft 365 E3 (enterprise, likely too expensive for SMBs)
Some EMS E3 bundles
Entra ID P2 is included in:
Microsoft 365 E5 (enterprise)
Microsoft 365 Business Premium includes many P1 features (but not full P1)
For most SMBs:
Buy Microsoft 365 Business Standard or Premium
Add Entra ID P1 or P2 separately if needed
Simpler than enterprise bundles
Payment Options
Annual prepayment:
Lower per-user cost
One annual payment
Commitment for full year
Monthly payment:
Slightly higher cost
More flexibility
Can cancel anytime
Most small businesses choose: Annual prepayment for cost savings, unless testing or uncertain about needs.
Entra ID Free vs P1 vs P2: Which Tier Does Your Small Business Need?
Let’s cut through the confusion and help you choose the right Microsoft Entra ID for small business tier.
Quick Decision Tree
Start here: Do you use Microsoft 365?
↓ Yes → You already have Entra ID Free
→ Are you satisfied with basic security (MFA, simple policies)?
↓ No (want better security)
→ Do you have remote workers or need conditional access?
↓ Yes → You need at least Entra ID P1
→ Do you have high security requirements or compliance needs?
↓ Yes → You need Entra ID P2
Detailed Tier Recommendations
Choose FREE (included with M365) if:
✓ Under 5 employees ✓ Everyone works in same office ✓ Only use Microsoft applications ✓ Minimal sensitive data ✓ No compliance requirements ✓ Very limited IT budget
But still enable: MFA (it’s free and critical)
Limitations you’ll accept:
No conditional access (can’t restrict by location, device, etc.)
No password protection (weak passwords possible)
Limited SSO (only 10 apps)
Basic reporting only
Choose P1 (£4.70/user/month) if:
✓ 5-50 employees ✓ Remote or hybrid work ✓ Use multiple cloud applications ✓ Handle sensitive business data ✓ Want strong security without breaking budget ✓ Need location/device-based access control ✓ Want to prevent weak passwords ✓ Have basic compliance requirements
If your small business uses Microsoft 365, understanding how Microsoft Entra ID for small business integrates with it is essential.
The Foundation: Entra ID Powers Microsoft 365
Microsoft Entra ID is not optional with Microsoft 365, it’s the underlying identity system.
Every time you or your employees use Microsoft 365, you’re using Entra ID:
✓ Logging into Outlook → Entra ID authenticates ✓ Accessing SharePoint → Entra ID authorises ✓ Opening Teams → Entra ID verifies identity ✓ Using OneDrive → Entra ID controls access ✓ Mobile device access → Entra ID manages
Think of it this way: Microsoft 365 is the applications (Outlook, Word, Excel, Teams), and Entra ID is the security guard that decides who gets in.
What’s Included with Microsoft 365 Subscriptions
With any Microsoft 365 Business subscription, you automatically get:
Entra ID Free tier
User account management
Basic MFA (multi-factor authentication)
Limited single sign-on (10 apps)
Azure AD Join (for Windows devices)
Self-service password reset (basic)
Group management
You’re already using Entra ID if you:
Add users in Microsoft 365 admin centre
Set up MFA for email accounts
Manage permissions in SharePoint
Control Teams access
You DON’T automatically get with standard M365:
Conditional access (requires P1)
Password protection (requires P1)
Identity protection (requires P2)
Unlimited SSO (requires P1)
Microsoft 365 Plans and Entra ID
Microsoft 365 Plan
Entra ID Included
Monthly Cost/User
Business Basic
Free tier
£4.50
Business Standard
Free tier
£10.00
Business Premium
Free + some P1 features*
£18.30
E3 (Enterprise)
P1 included
£28.10
E5 (Enterprise)
P2 included
£49.60
*Business Premium includes conditional access and some security features but not full P1.
For most SMBs: Business Standard (£10/user) + Entra ID P1 separately (£4.70/user) = £14.70/user total
Alternative: Business Premium (£18.30/user) includes some Entra features plus advanced threat protection
Integration Benefits
1. Seamless User Management
When you add a user in Microsoft 365 admin centre, you’re actually creating an Entra ID account. This account then works across:
All Microsoft 365 apps
Azure services (if you use them)
Integrated third-party applications
Windows device sign-in
One identity, everywhere.
2. Unified Security Policies
With Entra ID P1/P2, set policies that apply across all Microsoft 365 services:
Example policy: “Users accessing Outlook on mobile must use MFA”
Applies to Outlook app
Applies to Outlook Web Access
Applies to Teams mobile
Applies to all Microsoft 365 mobile apps
One policy, everywhere
3. Device Management Integration
Entra ID works with Microsoft Intune (device management) for:
Windows device management
Mobile device policies
Application protection
Conditional access by device compliance
Example: “Only company-managed devices can access SharePoint”
4. Simplified Third-Party App Access
With Entra ID, employees use their Microsoft 365 login for:
Salesforce
Adobe Creative Cloud
Zoom
Slack
Thousands of other business applications
No separate passwords for each app = better security and user experience.
Practical Example: A Day in the Life with Entra ID + M365
Sarah, Marketing Manager, starts her workday:
8:00 AM – Opens laptop → Signs in with Entra ID (Windows Hello) → Automatically logged into Microsoft 365
8:15 AM – Checks email in Outlook → No additional login needed (SSO via Entra ID)
9:00 AM – Joins Teams video call from coffee shop → Entra ID P1 conditional access: “Unusual location detected” → Requires additional MFA verification → Sarah approves on phone, gains access → Security maintained without disrupting legitimate work
10:30 AM – Needs to access Salesforce → Clicks Salesforce link → Entra ID SSO: automatically logged in → No password to remember
11:00 AM – Uploads client proposal to SharePoint → Entra ID checks permissions → Grants access based on security group → Seamless experience
2:00 PM – Accesses company files on mobile phone → Entra ID device compliance check → Requires MFA (mobile device) → Access granted after verification
Throughout the day:
Entra ID monitors all activity
Detects and blocks suspicious sign-ins
Enforces security policies automatically
Sarah works productively without thinking about IT security
That’s the power of Entra ID integration with Microsoft 365.
Common Integration Scenarios
Scenario 1: Secure Remote Access
Goal: Employees work from home securely
Entra ID + M365 solution:
Conditional access policy: “From home office IP, allow; from public WiFi, require MFA”
Problem: Company uses Microsoft 365, Xero accounting, Salesforce CRM, Adobe Creative Cloud. Employees juggle 4 sets of credentials, frequently forget passwords.
Pain points:
10-15 password reset requests per month
Employees write passwords down (security risk)
IT spends 3-5 hours/month on password resets
Employee frustration
With Entra ID P1 (SSO):
One login for all applications
Entra ID handles authentication
Employees remember one strong password
Password resets drop to 1-2/month
IT time saved: 3-4 hours/month
ROI:
Cost: £564/year (12 users × £4.70 × 12 months)
IT time saved: 40 hours/year × £30/hour = £1,200
Improved productivity: Immeasurable
Better security: Fewer written-down passwords
Use Case 3: Secure Remote Work
Problem: 8-person solicitor practice. Staff working from home during COVID continued hybrid work. Concerned about accessing client files from home networks.
Security concerns:
Home networks less secure than office
Client confidentiality requirements
SRA compliance obligations
Potential unauthorised access
With Entra ID P1:
Conditional access policy created:
From office network: normal access
From known home IPs: require MFA
From unknown locations: block or require approval
From risky locations (foreign countries): block
Additional policy:
Only company-managed devices can access sensitive files
Personal devices blocked from client folders
Result:
Secure remote work enabled
Compliance maintained
Client data protected
Staff productivity maintained
Compliance benefit: Can demonstrate to SRA that appropriate security controls are in place.
Use Case 4: Managing Contractor Access
Problem: Marketing agency uses 5 full-time staff plus 3-8 freelancers depending on projects. Freelancers need temporary access to specific client folders, but not company financials or other client work.
Contractors shouldn’t see confidential business info
With Entra ID P1:
Guest accounts for contractors (free)
Conditional access: Guests can only access specific SharePoint sites
Access reviews every 90 days
Automatic access expiration after project end date
MFA required for all guest access
Implementation:
Create guest account
Assign to “Client X Project” security group
Group has access only to Client X SharePoint folder
Set expiration: Project end date + 7 days
Automatic removal, no manual follow-up needed
Result:
Secure contractor collaboration
Automatic access control
Reduced admin burden
Better client data protection
Use Case 5: Preventing Weak Passwords
Problem: 15-person company had several accounts compromised via password guessing. Employees were using weak passwords like “CompanyName2024” and “Summer2025”.
Why it happened:
No password complexity enforcement
Employees chose easy-to-remember passwords
No checking against known breached passwords
With Entra ID P1 (Password Protection):
Custom banned password list created:
Company name variations
Location names
Industry terms
Common patterns
Microsoft’s global banned password list enabled:
Blocks 500+ common passwords
Checks against known breach databases
Employee tries to set “ATSConnection2025”:
Blocked automatically
Must choose stronger password
Guided to better options
Outcome:
Zero compromises via password guessing in 12 months
Improved overall security posture
Minimal user disruption (most users set stronger passwords first time)
Use Case 6: Audit and Compliance Reporting
Problem: Accountancy firm needs to demonstrate compliance with professional standards. Auditor asks: “Who has access to client files? How do you review this? Can you prove appropriate access controls?”
Without premium Entra ID:
Manual spreadsheet of permissions
Time-consuming to create
Quickly outdated
No automated reviews
Difficult to prove ongoing compliance
With Entra ID P2 (Access Reviews):
Automated quarterly access reviews:
“Should these 8 people still access Client X financial files?”
Sent to practice manager
Manager approves or removes access
Enforcement automatic
Audit reporting:
Complete access history
Who accessed what and when
Who approved access
When reviews occurred
Automatic compliance documentation
Auditor visit:
Generate report in 5 minutes
Shows systematic access governance
Demonstrates compliance
Professional standards met
Compliance value: Can mean difference between clean audit and compliance issues. Peace of mind: Priceless.
How to Set Up Microsoft Entra ID for Your Small Business
A practical guide to implementing Microsoft Entra ID for small business without getting overwhelmed.
Before You Start: Prerequisites
You’ll need:
✓ Microsoft 365 subscription (any business plan) ✓ Global administrator access to Microsoft 365 ✓ List of users who need accounts ✓ Organisational structure (departments, teams) ✓ 2-4 hours for initial setup ✓ Decision on which Entra ID tier (Free/P1/P2)
Optional but helpful:
List of third-party applications to integrate
Security policies document
Device management requirements
Compliance requirements list
Step 1: Access Entra ID Admin Centre
You’re already using Entra ID Free if you have M365. To configure it:
Go to admin.microsoft.com (Microsoft 365 admin centre)
Sign in with global administrator account
In left menu, select Identity or Azure AD / Entra ID
This opens Entra ID admin centre (entra.microsoft.com)
Or directly: Go to entra.microsoft.com and sign in
First time: Interface shows current users (imported from M365) and basic settings
Step 2: Enable Multi-Factor Authentication (Critical – Do This First!)
This is the single most important security step. It’s free and takes 15 minutes.
In Entra ID admin centre, go to Users → All users
At top, click Per-user MFA (or Multi-factor authentication)
Select all users (or specific users)
Click Enable in right panel
Confirm enabling MFA
User experience:
Next time users log in, prompted to set up MFA
Choose method: Mobile app (recommended), SMS, phone call
Takes 2-3 minutes per user
Required for every login going forward
Pro tip: Enable for administrators first, then roll out to all users with advance notice.
Step 3: Organise Users into Groups (Foundation for Access Control)
Why groups matter: Instead of giving permissions to individuals, assign to groups. Much easier to manage.
Common group structure for small businesses:
Go to Groups → All groups → New group
Create security groups:
All Staff (everyone)
Management (directors, managers)
Finance Team
Sales Team
IT Administrators
etc.
Add members to each group
Use groups to:
Assign application access
Control SharePoint permissions
Apply conditional access policies
Simplify administration
Example: Instead of giving 8 people individual access to accounting software, add them to “Finance Team” group, give group access to application. New finance hire? Just add to group.
Step 4: Set Up Single Sign-On for Third-Party Apps (P1 Feature)
If you have Entra ID P1/P2 and use other business applications:
Go to Enterprise applications → All applications
Click New application
Search for your application (Salesforce, Zoom, Adobe, etc.)
Note: Requires device management (Intune) to work properly
Step 6: Enable Password Protection (P1 Feature)
Go to Protection → Authentication methods → Password protection
Custom banned passwords:
Add company name variations
Add location names
Add industry terms
Add common local patterns Example: “ATSConnection”, “Arundel”, “Sussex”, “Worthing”, “Chichester”
Enable Custom smart lockout (prevents brute force attacks)
Enforce for Azure AD: Set to “Enforced”
Save
Effect: Users cannot set weak or company-specific passwords. Stronger security immediately.
Step 7: Configure Self-Service Password Reset
Reduces IT support burden significantly.
Go to Users → Password reset
Self-service password reset enabled: Select “All” or specific groups
Authentication methods: Require 2 methods:
Mobile phone
Email
Security questions
Registration: Require users to register on next sign-in
Notifications: Enable notifications to users and admins
Save
User experience:
Employee forgets password
Goes to password reset portal
Verifies identity with 2 methods
Resets password immediately
Back to work in 2 minutes
Step 8: Set Up Monitoring and Alerts
Stay informed about security events:
Go to Monitoring → Sign-ins
Review who’s logging in and from where
Look for suspicious activity
Go to Security → Risky users (P2 feature)
See users with detected risks
Investigate and remediate
Set up alerts:
Go to Monitoring → Alerts
Create alert rules for:
Failed sign-in attempts (multiple)
Risky sign-ins
Admin activity
Step 9: Roll Out to Users (Communication is Critical)
Don’t just turn on features without warning users!
Communication plan:
1 week before:
Email all staff explaining changes
Benefits: Better security, easier access to applications
What they need to do: Set up MFA, may need to re-authenticate
When it happens
Who to contact with questions
Day of rollout:
Morning email: “Today is the day”
IT support available
Walk-through instructions
First week:
Monitor for issues
Quick support responses
Gather feedback
Sample email:
Subject: Important Security Update – Multi-Factor Authentication Next Monday
Hi Team,
Next Monday, we’re implementing enhanced security for all our business applications. This means you’ll set up multi-factor authentication (MFA) – an extra security step that protects your account even if someone steals your password.
What you’ll do:
Log in as normal on Monday
Follow prompts to set up MFA on your mobile phone (takes 2 minutes)
Going forward, you’ll approve logins on your phone app
Why we’re doing this:
99.9% better protection against account hacking
Industry best practice
Protects our business and client data
Questions? Reply to this email or call IT support.
Thanks, [Your IT Team]
Step 10: Ongoing Management and Optimisation
Setup is just the beginning. Ongoing management:
Monthly tasks:
Review sign-in logs for suspicious activity
Check conditional access policy effectiveness
Review any blocked sign-ins (legitimate or threats?)
Update groups as staff join/leave
Quarterly tasks:
Access reviews (P2 feature – who still needs access to what?)
Policy optimisation (are policies too strict or too loose?)
User feedback (is anything frustrating?)
Review audit logs for compliance
Annual tasks:
Full security audit
Update banned password lists
Review and update all policies
Training refresher for staff
Common Setup Mistakes to Avoid
❌ Enabling MFA without warning users → Causes confusion and support calls
❌ Creating overly restrictive policies immediately → Start with “Report-only” mode, monitor, then enforce
❌ Not testing policies before enabling → Test on small group first
❌ Forgetting to exclude break-glass admin account → Always have emergency admin account not subject to conditional access
❌ Not documenting policies and reasons → Future you (or your replacement) needs to know why policies exist
❌ Setting up SSO without user training → Users don’t understand how it works, frustrated
❌ No communication plan → Users resist changes they don’t understand
When to Call for Professional Help
DIY setup works for basic configurations, but consider professional help if:
✓ Over 50 users ✓ Complex compliance requirements ✓ Multiple office locations ✓ Hybrid (cloud + on-premise) environment ✓ Integration with legacy systems ✓ Previous security incidents ✓ Limited internal IT expertise ✓ You’re not confident in security configuration
Professional setup costs: £500-£2,000 for SMB implementation
The problem: Need to prove Entra ID implementation for audits, but don’t have proper documentation.
What auditors want:
Who has access to what
How access is controlled
Access review processes
Security policy documentation
Incident response logs
Solutions:
1. Document from the start:
Policy purposes and justifications
Configuration settings
Access control decisions
Review processes
2. Use built-in reporting:
Entra ID provides numerous reports
Sign-in logs
Audit logs
Access reviews (P2)
Security dashboard
3. Regular compliance checks:
Quarterly reviews
Document reviews in writing
Action items tracked
Maintain history
4. Third-party compliance tools:
For complex compliance (ISO 27001, SOC 2)
Automate evidence collection
Continuous compliance monitoring
Professional help: Compliance requirements often benefit from MSP support for proper documentation and processes.
When to Get Professional Help with Microsoft Entra ID
Whilst Microsoft Entra ID for small business can be set up by technical business owners, professional help often provides better security outcomes and saves time.
DIY vs Professional Help: When to Choose Each
DIY Setup Appropriate If:
✓ Under 15 users ✓ Simple Microsoft 365-only environment ✓ Someone internal has IT experience ✓ No compliance requirements ✓ Time to learn and implement ✓ Comfortable troubleshooting issues ✓ Just need basic MFA and policies
Real example: Employee enters password on phishing site. Attacker tries to log in from Ukraine. Entra ID blocks immediately (impossible travel detection). Employee notified, changes password. Breach prevented.
Decision needed: Approve budget and implementation timeline
Step 4: Implementation Plan
Option A: DIY Implementation
Week 1:
Purchase Entra ID P1/P2 licences
Read implementation documentation
Plan policies and groups
Week 2:
Configure basic settings
Set up groups
Enable MFA for pilot group
Week 3:
Create conditional access policies
Test with pilot group
Refine based on feedback
Week 4:
Roll out to all users
Provide support
Monitor and adjust
Ongoing:
Monthly reviews
Policy optimisation
User support
Option B: Professional Implementation
Week 1:
Select provider
Initial consultation
Requirements gathering
Week 2:
Provider configures Entra ID
Policy creation
Testing
Week 3:
Admin training
Pilot rollout
Refinements
Week 4:
Full user rollout
User training
Documentation delivery
Ongoing:
Managed service (if chosen)
Regular reviews
Optimisation
Step 5: Launch and Communicate
User communication template:
Subject: Important Security Update – Better Protection, Easier Access
Dear Team,
We’re implementing enhanced security for all our business applications starting [DATE]. This improves our security whilst making your work easier.
What’s changing:
Multi-factor authentication for all accounts
Single sign-on for multiple applications
Better protection against cyber threats
What you need to do:
[DATE]: Set up multi-factor authentication (5-minute process)
Keep your mobile phone handy for approvals
Contact IT support if you have issues
Benefits for you:
One login for multiple applications
Better protection for your work account
Faster password resets
Enhanced security for remote work
Support:
Training session: [DATE/TIME]
Step-by-step guide: [LINK]
IT support: [CONTACT INFO]
Thank you for your cooperation in keeping our business secure.
[Name]
Step 6: Measure Success
Track these metrics:
Security metrics:
Account compromise attempts (should drop to near zero)
Successful phishing attacks (should be zero)
Unauthorised access attempts blocked
Password strength improvement
Operational metrics:
Password reset requests (should decrease 60-80%)
IT support time on access issues
User satisfaction with login experience
Compliance metrics:
Audit readiness
Access review completion
Policy compliance rate
Review monthly for first 3 months, then quarterly.
Step 7: Optimise and Improve
After 90 days, review:
Are policies too strict or too loose?
Adjust based on user feedback and security logs
Are we using all features we’re paying for?
Maximise value from licences
Have security incidents decreased?
Measure effectiveness
Is user experience acceptable?
Balance security and usability
Do we need to upgrade/downgrade?
Right-size licensing
Continuous improvement is key to maximising Entra ID value.
Conclusion: Is Microsoft Entra ID Right for Your Small Business?
Microsoft Entra ID for small business provides enterprise-grade security at SME-friendly pricing. For most businesses with 5+ employees using Microsoft 365, the answer is clear: Yes, you should be using at least Entra ID P1.
Key takeaways:
✅ You’re already using Entra ID Free if you have Microsoft 365 ✅ Enable MFA immediately – it’s free and critical ✅ Most SMBs benefit from P1 (£4.70/user/month) for conditional access and password protection ✅ Regulated industries should use P2 (£7.10/user/month) for identity protection and compliance features ✅ Professional help often provides better outcomes for 15+ user businesses ✅ ROI is clear: One prevented breach pays for years of Entra ID licensing
The real question isn’t whether you can afford Entra ID Premium, it’s whether you can afford NOT to have it.
Get Expert Microsoft Entra ID Implementation in West Sussex
ATS Connection specialises in Microsoft 365 security and Entra ID implementation for West Sussex small businesses.
Our Entra ID Services:
✓ Security assessment – Identify your specific requirements ✓ Right-sized recommendations – Free/P1/P2 guidance based on your needs ✓ Professional implementation – Expert configuration following best practices ✓ User training and rollout – Smooth deployment with minimal disruption ✓ Ongoing management – Licence optimisation, policy management, security monitoring ✓ Compliance documentation – Audit-ready reports and documentation ✓ Local support – Fast response across West Sussex
Why ATS Connection:
✓ 20+ years combined IT security experience ✓ Microsoft Partner ✓ Cyber Essentials certified ✓ Based in Arundel, serving Chichester to Worthing ✓ Transparent pricing, no hidden fees ✓ Proven track record with West Sussex SMBs
Ready to improve your security with Microsoft Entra ID?
A: Yes, they are identical. Microsoft rebranded Azure Active Directory to Microsoft Entra ID in 2022-2023. It’s the same service with a new name, no migration needed, no feature changes.
Q: Do I already have Microsoft Entra ID?
A: If you use Microsoft 365, yes. Every Microsoft 365 subscription includes Entra ID Free tier automatically. You’re using it every time you log into Microsoft 365.
Q: How much does Microsoft Entra ID cost for a small business?
A:
Free tier: Included with Microsoft 365 (£0)
Entra ID P1: £4.70 per user per month (£56.40/user/year)
Entra ID P2: £7.10 per user per month (£85.20/user/year)
For a 15-person business: P1 costs £846/year, P2 costs £1,278/year.
Q: Do small businesses really need Microsoft Entra ID Premium (P1 or P2)?
A: Most small businesses with 5+ employees, remote workers, or sensitive data benefit significantly from at least P1. The cost (£4.70/user/month) is minimal compared to potential breach costs (£10,000-£100,000+). Free tier provides basic security, but lacks conditional access and password protection, features that prevent most attacks.
Q: What’s the difference between Entra ID Free, P1, and P2?
When you search for “IT support companies near me,” you’re likely facing an IT challenge that needs solving, fast. Whether you’re a growing business in Chichester looking for reliable tech support, a Worthing-based company tired of dealing with slow response times, or an Arundel business ready to upgrade from break-fix support to managed services, choosing the right local IT provider is one of the most important decisions you’ll make.
But here’s the challenge: local search results are flooded with options. National MSPs, remote-only providers, one-person operations, and established local firms all compete for your attention. How do you separate the truly capable local IT support companies from those who just rank well in search results?
This comprehensive guide reveals exactly how to find, evaluate, and select the best local IT support company for your business, with practical advice you can use today. If you would rather talk to a local team now, ATS Connection provides managed IT support across West Sussex, so get a quote or book a free IT review.
What you’ll discover:
Why local IT support genuinely matters (beyond marketing claims)
How to evaluate IT support companies near you
Essential questions to ask before signing a contract
Red flags that signal you should keep searching
The true cost difference between local and remote support
How to verify a provider’s local presence and capabilities
When you search for “IT support companies near me,” you’re instinctively recognizing something important: proximity matters in IT support. But why exactly does location make such a difference in the age of remote access and cloud computing?
The Genuine Advantages of Local IT Support
1. Faster On-Site Response When You Need It Most
Despite advances in remote support technology, some situations absolutely require hands-on intervention:
Server hardware failures that need immediate physical access
Network infrastructure problems that can’t be diagnosed remotely
New equipment installations and office moves
Printer and peripheral issues that require physical troubleshooting
Emergency situations where multiple systems are down
Real-world example: When a water pipe burst in a Chichester office building, the local business needed immediate on-site support to assess water damage to servers, safely power down equipment, and coordinate recovery. A remote-only provider couldn’t have helped.
A genuinely local IT support company can typically provide on-site support within 2-4 hours for emergencies across their service area. Remote or distant providers might quote next-day or even longer timeframes, downtime that could cost your business thousands.
2. Understanding of Local Business Landscape
Local IT support companies develop familiarity with:
Regional infrastructure challenges – They know which areas have reliable internet connectivity and which don’t
Local supplier relationships – Established connections with local vendors speed up hardware procurement
Area-specific compliance needs – Understanding of regional business requirements and standards
Community business networks – Connections that can help your business beyond just IT
Example: A West Sussex IT provider understands the unique needs of businesses in market towns like Arundel versus coastal commercial areas like Worthing, and can tailor solutions accordingly.
3. Accountability and Reputation
Local businesses live and die by their community reputation. When an IT support company operates in your area:
Their reputation is on the line locally – Poor service spreads quickly in business communities
You can verify references easily – Speaking with other local clients is straightforward
They’re invested in long-term relationships – They can’t disappear after providing poor service
According to a 2024 BrightLocal study, 87% of consumers read online reviews for local businesses, and 79% trust them as much as personal recommendations. For B2B services like IT support, this trust factor is even more critical.
4. Timezone Alignment and Availability
Working with local IT support companies means:
Same business hours – Support available when you need it, not tied to distant time zones
Cultural and communication alignment – No language barriers or cultural misunderstandings
Holiday schedules match – Your provider isn’t closed when you’re working (and vice versa)
After-hours emergencies are manageable – Local technicians can respond to urgent after-hours calls more readily
5. Economic Impact and Community Investment
When you choose local IT support:
Money stays in your local economy – Supporting local employment and business growth
Community involvement – Local providers often sponsor local events, charities, and business groups
Mutual business support – Relationships that can benefit both businesses beyond the service contract
This isn’t just feel-good marketing, it’s practical business sense. Strong local business relationships often lead to referrals, partnerships, and community support that benefit your bottom line.
When Remote Support Is Actually Fine
To be fair and honest: Not every business needs a local IT support company. Remote support works well for:
Very small businesses (1-3 people) with simple, cloud-only setups
Businesses with minimal on-site infrastructure
Companies with internal IT staff who just need specialist backup
The key question: How often do you need physical access to your IT infrastructure? If the answer is “rarely or never,” remote support might suffice. But for most SMEs with on-premise servers, complex networks, or regular hardware needs, local IT support provides measurable value.
Local vs Remote IT Support: The Real Differences
Understanding the practical differences helps you determine what you actually need when searching for “IT support companies near me.”
Comprehensive Comparison
Factor
Local IT Support
Remote-Only IT Support
On-site response time
2-4 hours typically
Next day to never
Emergency hardware support
Immediate physical access
Ships parts, talks you through fixes
Relationship building
Regular face-to-face meetings
Phone/video calls only
Local knowledge
Understands area infrastructure
Generic approach
Cost
Typically £75-£110/user/month
Often £50-£80/user/month
Office moves/installations
Hands-on support
Limited assistance
Network infrastructure
Can physically inspect/fix
Remote diagnostics only
Business reviews
In-person quarterly reviews
Virtual meetings
Vendor coordination
Local supplier relationships
You coordinate deliveries
Accountability
Local reputation matters
Easier to provide poor service
The Hybrid Reality: Best of Both Worlds
Most modern local IT support companies offer hybrid support models:
✓ Remote support for 80-90% of issues:
Password resets
Software troubleshooting
Account management
Most helpdesk tickets
System monitoring and alerts
✓ On-site support when genuinely needed:
Hardware failures
Network infrastructure issues
Major installations or upgrades
Office moves
Complex troubleshooting
Equipment audits
The advantage: You get fast remote resolution for most issues, with the peace of mind that someone can be on-site quickly when physical access is necessary.
Important: Ranking highly doesn’t mean they’re the best, just that they’re good at SEO or willing to pay for ads. Use search as a starting point, not your decision-maker.
What to look for in search results:
✓ Actual local addresses (not just PO boxes or virtual offices)
✓ Local phone numbers (not generic 0800 numbers only)
✓ Service area clearly stated
✓ Years in business mentioned
✓ Real client testimonials
Google Business Profile Investigation
Click through to company Google Business Profiles and examine:
Review count and ratings – Look for 20+ reviews minimum, 4.5+ stars
Review consistency – All 5-stars is suspicious; 4-5 stars with detailed reviews is authentic
Response to reviews – Do they respond professionally to both positive and negative feedback?
Photos – Real office photos, team photos, not just stock images
Complete information – Hours, website, phone, address all filled out
Posts/updates – Active profiles indicate engaged, current businesses
Red flag: Profiles with just a few suspiciously positive reviews or no reviews at all may be new, unproven, or have reputation issues.
Technician qualifications – What certifications do staff hold?
Industry specialization – Experience with your industry?
Technology expertise – Familiar with your specific systems and software?
Training investment – Do they regularly train staff on new technologies?
Technology partnerships – Microsoft Partner, Cisco, Dell, etc.?
Red flag: Vague answers about qualifications or an inability to speak confidently about the technologies you use.
Service Level Agreement (SLA) Review
What are you actually guaranteed?
Response times defined – For each priority level (critical, high, medium, low)
Resolution time targets – Not just response, but actual fix timeframes
Availability hours – Business hours? Extended? 24/7?
On-site visit commitments – When and how quickly for your location
Escalation procedures – What happens if initial response is inadequate?
Performance reporting – Will you receive regular service reports?
Penalties for non-performance – Are there consequences if SLAs aren’t met?
Critical: Get the SLA in writing before signing anything. Verbal promises mean nothing.
Cultural and Communication Fit
Will you actually enjoy working with them?
Communication style matches your preferences (formal vs. casual)
Technical explanations are clear without being condescending
Responsiveness in the evaluation process (quick replies, professional follow-up)
Listening skills – Do they actually understand your needs or just pitch services?
Business values alignment – Do their values match yours?
Client relationship approach – Partnership mentality vs. vendor mentality
This matters more than you might think. You’ll be working with this company regularly. If initial interactions feel off, it rarely improves after signing.
Financial Transparency
Do you understand exactly what you’ll pay?
Pricing model clarity – Per-user, fixed-fee, or hybrid?
What’s included in base pricing – Explicitly detailed
What costs extra – Out-of-scope charges clearly defined
15 Essential Questions to Ask Local IT Support Companies
When you’re evaluating IT support companies near you, these questions separate truly capable providers from those just trying to win your business.
Questions About Their Business
1. “How long have you been providing IT support in this area?”
What you’re looking for:
Minimum 3-5 years of local operation
Stability and local reputation
Understanding of area-specific infrastructure
Red flags:
Very new companies (under 2 years) carry higher risk
Recently relocated from elsewhere (lost local knowledge)
Evasive answers about tenure
2. “How many clients do you currently support in [your area]?”
What you’re looking for:
Established local client base (10+ similar-sized businesses)
Not over-extended (one technician supporting 100+ businesses is problematic)
Experience with businesses like yours
Red flags:
Can’t or won’t give approximate numbers
Only have 1-2 local clients (mostly remote)
Supporting hundreds with tiny staff (stretched too thin)
3. “Can you provide 3-5 references from current clients similar to our business?”
What you’re looking for:
Willingness to provide references immediately
References from your industry or similar size businesses
Long-term clients (3+ years) showing satisfaction
Red flags:
Reluctance to provide references
Only offer cherry-picked testimonials
References are all very new clients
Follow-up: Actually call the references and ask about response times, communication, problem resolution, and any issues they’ve experienced.
Questions About Service Delivery
4. “What’s your guaranteed response time for critical issues affecting our business?”
What you’re looking for:
Critical: 15-60 minutes
High: 2-4 hours
Medium: Same or next business day
Written SLA documenting these commitments
Red flags:
Vague answers like “as soon as possible”
No written SLA
Response times over 4 hours for critical issues
5. “How quickly can you get a technician on-site to our location if needed?”
What you’re looking for:
Same-day for emergencies (2-4 hours typical)
Specific commitment for your location
Clear process for requesting on-site visits
Red flags:
“We’ll try our best” without commitments
Next-day or longer for all on-site visits
Unclear about who would actually come on-site
6. “What hours is your helpdesk available, and what happens if we need support outside those hours?”
What you’re looking for:
Clear coverage hours
After-hours emergency support process
Reasonable after-hours premiums (if any)
Red flags:
No after-hours support available
Extreme after-hours premiums (3x+ normal rates)
Requires separate after-hours contract
7. “How do you proactively monitor our systems, and what tools do you use?”
What you’re looking for:
24/7 automated monitoring
Specific RMM (Remote Monitoring and Management) tools mentioned
Proactive alerting before you notice issues
Regular health reports
Red flags:
No proactive monitoring (“we wait for you to call”)
Can’t name specific monitoring tools
Only monitor during business hours
According to Gartner research, proactive monitoring reduces critical incidents by 40-60% compared to reactive-only support.
Questions About Security and Compliance
8. “What security measures do you implement and maintain for your clients?”
What you’re looking for:
Multi-layered security approach
Endpoint protection (antivirus/anti-malware)
Firewall management
Email security and spam filtering
Regular security patching
Security awareness training
MFA (Multi-Factor Authentication) implementation
Red flags:
Vague answers about “we handle security”
Only mention antivirus
Don’t discuss patch management or updates
9. “Are you Cyber Essentials certified, and can you help us achieve certification?”
What you’re looking for:
They hold Cyber Essentials (or higher) certification
Can guide you through certification if needed
Understand UK cybersecurity requirements
Note: Cyber Essentials is a UK government-backed scheme. Certification shows they meet baseline security standards.
Red flags:
Not certified and don’t plan to be
Dismissive of certification importance
Don’t understand UK cybersecurity standards
10. “How do you handle data backup and disaster recovery?”
What you’re looking for:
Comprehensive backup strategy (local + cloud)
Regular backup testing and verification
Documented disaster recovery plan
Clear recovery time objectives (RTO) and recovery point objectives (RPO)
Business continuity planning
Red flags:
“We set up backups and forget about them”
No backup testing mentioned
Can’t explain recovery process
No documented disaster recovery plan
Questions About Costs and Contracts
11. “What exactly is included in your monthly support fee, and what would cost extra?”
What you’re looking for:
Comprehensive list of included services
Clear definition of out-of-scope work
Transparent about additional costs
Written documentation of inclusions/exclusions
Red flags:
Very narrow definition of “support”
Long list of common tasks that cost extra
Refusal to document what’s included
Vague boundaries between included and extra
12. “What are your contract terms, and what’s required to terminate the agreement?”
What you’re looking for:
12-month contracts (reasonable)
30-90 day termination notice
No or minimal early termination fees
Clear data extraction/transition process
Red flags:
36+ month contracts (excessive lock-in)
Large early termination penalties
Auto-renewal without adequate notice period
Unclear about data return process
13. “Are there any setup, onboarding, or migration fees?”
What you’re looking for:
Transparent about any initial costs
Reasonable onboarding fees (or none)
Clear breakdown of migration work
Option to amortize costs
Red flags:
Hidden setup fees revealed later
Excessive onboarding charges (£5,000+ for small business)
Charges to fix issues created by previous provider
Questions About Their Approach
14. “What makes your company different from other IT support companies in this area?”
What you’re looking for:
Genuine differentiators (not generic claims)
Specific examples of how they add value
Focus on outcomes, not just services
Honest assessment of their strengths
Red flags:
Generic answers (“we’re the best,” “great customer service”)
Can’t articulate clear differentiation
Primarily compete on price alone
Bash competitors rather than explain their value
15. “If we become a client, who will be our main point of contact, and how often will we meet?”
What you’re looking for:
Dedicated account manager or primary contact
Regular business reviews (quarterly minimum)
Clear escalation path
Proactive relationship management
Red flags:
No dedicated contact (ticket queue only)
Rarely or never meet in person
Different person each time you call
Reactive-only relationship
Red Flags: When to Keep Searching for IT Support Companies Near You
Not every company that appears in “IT support companies near me” searches is worth your time. Here are the warning signs that should make you continue your search.
🚩 Business Red Flags
1. Can’t Verify Physical Local Presence
Warning sign:
Only have virtual office or P.O. box
Evasive about office location
Can’t schedule in-person meeting
No local phone number
Why it matters: If they’re not truly local, you won’t get the on-site support benefits you’re expecting.
2. Very Few or Suspiciously Perfect Reviews
Warning sign:
Under 5 total reviews
All 5-star reviews with generic praise
Reviews all posted within short timeframe
No reviews on multiple platforms
Why it matters: Could indicate fake reviews, brand new business, or clients who won’t provide testimonials.
3. High Staff Turnover
Warning sign:
LinkedIn shows constant employee changes
Different contacts each time you interact
Can’t introduce your “team” because everyone’s new
Why it matters: Continuity matters in IT support. High turnover often signals management issues or poor working conditions.
🚩 Service Delivery Red Flags
4. No Written Service Level Agreement
Warning sign:
Verbal promises only
“We’ll document that later”
SLA only provided after signing contract
Vague performance commitments
Why it matters: Without written SLAs, you have no recourse for poor performance.
5. Reactive-Only Support Model
Warning sign:
No proactive monitoring mentioned
“Call us when something breaks” approach
Can’t describe their monitoring tools
Don’t offer strategic IT planning
Why it matters: You’ll pay more long-term in downtime and emergency fixes than proactive prevention costs.
6. Slow Response During Evaluation
Warning sign:
Takes days to return calls or emails
Doesn’t follow up on promised information
Misses scheduled meetings
Generally unresponsive
Why it matters: If they’re slow when trying to win your business, imagine how slow they’ll be once you’ve signed.
🚩 Financial Red Flags
7. Refuses to Provide Pricing Ranges
Warning sign:
Won’t give any pricing until after extensive assessment
Extremely secretive about costs
“Every client is different” without any ranges
Bait-and-switch pricing after proposal
Why it matters: Legitimate providers can give approximate ranges. Refusal often means they’re trying to maximize extraction.
8. Pressure to Sign Immediately
Warning sign:
“This price is only good today”
Pressure tactics about competitors
Won’t give you time to evaluate
Aggressive sales approach
Why it matters: Reputable IT support companies want long-term relationships with satisfied clients, not quick sales.
9. Excessive Long-Term Contracts
Warning sign:
3+ year minimum contracts
Large early termination penalties
Auto-renewal with minimal notice period
Locks in pricing with vague increase terms
Why it matters: Confidence in their service should allow shorter, more flexible terms.
🚩 Technical Red Flags
10. Can’t Discuss Your Specific Technology
Warning sign:
Unfamiliar with your line-of-business applications
Can’t speak knowledgeably about your infrastructure
Suggests replacing everything you have
Pushes only technologies they’re comfortable with
Why it matters: You need a provider who can support your actual environment, not force you into theirs.
11. No Security Certifications or Knowledge
Warning sign:
Don’t hold Cyber Essentials or similar certifications
Can’t discuss current threat landscape
Dismissive about security concerns
No formal security processes
Why it matters: Cybersecurity is critical. An IT provider who doesn’t take it seriously puts your business at risk.
12. “Yes” to Everything Without Qualification
Warning sign:
Claims to do everything perfectly
Never admits limitations
No specializations mentioned
Promises immediate solutions to complex problems
Why it matters: Honest providers acknowledge their strengths and limitations. Everyone who claims to do everything usually does nothing well.
🚩 Communication Red Flags
13. Technical Jargon Without Explanation
Warning sign:
Uses acronyms without defining them
Condescending when explaining technology
Makes you feel stupid for asking questions
Can’t translate technical concepts to business terms
Why it matters: Good IT providers educate and empower clients, they don’t confuse or condescend.
14. Primarily Criticize Current Setup
Warning sign:
Focus on tearing down previous provider
Criticize without offering solutions
Use scare tactics about your current state
Create fear rather than confidence
Why it matters: Professional providers focus on solutions and value, not fear-mongering about competitors.
15. Won’t Provide Client References
Warning sign:
Refuses reference requests
“All our clients are confidential”
Only offers testimonials, not actual contacts
Provides references that don’t match your business type
Why it matters: If they can’t provide any satisfied clients willing to speak with you, what does that tell you?
Understanding Local IT Support Costs
When evaluating IT support companies near me, understanding typical local pricing helps you identify fair offers versus overpriced or suspiciously cheap services.
Typical Local IT Support Pricing (UK)
Per-user managed services pricing:
Region
Basic Support
Standard Support
Premium Support
London
£95-£140/user
£110-£160/user
£130-£200/user
South East (excluding London)
£75-£110/user
£90-£130/user
£110-£150/user
Rest of UK
£65-£95/user
£80-£110/user
£95-£130/user
West Sussex specifically: £75-£110 per user per month for standard managed services
What Affects Local Pricing?
1. Geographic Cost of Living
Areas with higher property costs and salaries typically charge more:
London premiums: +20-40%
Major cities: +10-20%
Regional markets: Baseline
Rural areas: Sometimes +10-15% (travel time costs)
2. Competition Density
More local providers = more competitive pricing:
High competition areas: Better value, more options
Low competition areas: Limited options, sometimes higher prices
3. Service Scope
Basic support: Remote helpdesk only, business hours
Standard support: Remote + periodic on-site, extended hours
True cost comparison: Often breaks even or local costs less when factoring total value.
Warning: Suspiciously Low Pricing
If a local IT support company quotes significantly below market rates (£40-£50/user), investigate:
Possible reasons:
❌ Very limited service scope (many exclusions)
❌ Slow response times
❌ Minimal proactive monitoring
❌ One-person operation (can’t scale)
❌ Trying to gain clients then raise prices
❌ Offshore helpdesk (not truly “local”)
Fair pricing reflects quality service. Rock-bottom prices usually mean rock-bottom service.
Finding IT Support Companies in West Sussex
If you’re specifically searching for IT support companies near me in the West Sussex area, here’s what you should know about the local market.
West Sussex IT Support Landscape
Key business areas:
Chichester – Strong professional services sector (legal, accounting, medical)
Worthing – Mix of retail, hospitality, and SME businesses
Arundel – Market town with tourism and local businesses
Bognor Regis, Littlehampton – Coastal commercial areas
Horsham, Crawley – Larger commercial centers
Typical local business needs:
5-50 employee businesses
Mix of cloud and on-premise infrastructure
Compliance requirements (professional services)
Mobile workforce support
Reliable support during tourist season (seasonal businesses)
What to Expect from West Sussex IT Providers
Pricing:
Standard managed services: £75-£110 per user per month
On-site emergency response: Typically 2-4 hours across the region
Travel charges: Most providers include travel within West Sussex in base pricing
Service characteristics:
Personal, relationship-focused service
Understanding of coastal connectivity challenges
Familiarity with seasonal business needs
Strong local reputation importance
Evaluating West Sussex IT Support Companies
Specific questions to ask local providers:
“How quickly can you get to [your specific town] for on-site support?”
Should be same-day for emergencies
“Do you charge travel fees within West Sussex?”
Most established providers include local travel
“How do you handle support during peak tourist season?” (if applicable)
Shows understanding of local business rhythms
“What other businesses in [your town/industry] do you support?”
Demonstrates local experience and references
“Are you familiar with [local business concern, e.g., coastal internet reliability]?”
Shows genuine local knowledge vs. generic service
West Sussex Business Advantages
Choosing a West Sussex-based IT support company offers:
✓ Genuine local presence – Office in Arundel, Chichester, Worthing, or nearby ✓ Fast on-site response – 2-4 hours across the region ✓ Local business network – Connected to your business community ✓ Regional infrastructure knowledge – Understands area-specific challenges ✓ No London premiums – Competitive pricing compared to London providers ✓ Personal service – Smaller market means more relationship focus
At ATS Connection, we’re proud to serve businesses across West Sussex from our Arundel base, providing fast local support from Chichester to Worthing and throughout the region.
You’ve researched IT support companies near you, asked the right questions, and narrowed your options. Here’s how to make your final decision confidently.
Compare Your Top 2-3 Candidates
Create a comparison matrix:
Criteria
Weight (1-5)
Provider A
Provider B
Provider C
Response time commitments
5
Local presence/accessibility
5
Technical expertise
5
Service scope
4
Security capabilities
5
Pricing transparency
4
Contract flexibility
4
Client references
4
Cultural fit
3
Additional services
2
Scoring: Rate each provider 1-10 for each criterion, multiply by weight, sum the totals.
Run a Trial Period (If Possible)
Consider asking for:
30-day trial period (some providers offer this)
3-month initial contract before longer commitment
Pilot project to assess capabilities
During trial, evaluate:
Actual response times vs. promised
Quality of communication
Problem resolution effectiveness
Proactive monitoring results
Relationship development
Review the Contract Carefully
Before signing, verify:
SLA response times clearly documented
All included services explicitly listed
Out-of-scope work clearly defined
Pricing terms and increase conditions
Contract length and termination terms
Data ownership and extraction process
Liability and insurance provisions
Renewal and notice requirements
Pro tip: Have your solicitor review the contract if it’s a significant commitment.
Trust Your Instincts
Beyond the data, ask yourself:
Do I trust this company?
Do I feel confident they’ll be responsive?
Can I see a long-term partnership?
Do they genuinely understand my business?
Would I recommend them to another business owner?
If something feels off, it usually is. Don’t ignore gut feelings, they’re often based on subtle cues you’ve picked up.
Next Steps: Getting Quotes from Local IT Support Companies
Ready to move forward with finding the right IT support company near you? Here’s your action plan:
Your 7-Day Action Plan
Day 1-2: Initial Research
Search “IT support companies near me” and compile 8-10 options
Check Google reviews and business profiles
Ask your business network for referrals
Review company websites
Day 3-4: First Contact
Email 4-5 providers requesting information
Ask for pricing ranges and service overviews
Request client references
Schedule initial calls with 3-4 providers
Day 5-6: Evaluation Calls
Conduct 30-45 minute calls with each provider
Ask the 15 essential questions from this guide
Request detailed proposals and SLAs
Contact client references
Day 7: Final Decision
Compare proposals using the matrix above
Review contracts carefully
Make your selection
Schedule onboarding/transition
What to Prepare Before Contacting Providers
Have this information ready:
About your business:
Number of employees/users
Industry/sector
Locations/addresses
Operating hours
About your IT environment:
Number of devices (laptops, desktops, mobile devices)
Server infrastructure (if any)
Cloud services in use (Microsoft 365, etc.)
Line-of-business applications
Current IT challenges or pain points
About your needs:
Support hours required
On-site visit frequency needed
Budget range
Timeline for transition
Specific compliance requirements
Having this ready makes initial conversations much more productive.
Questions to Ask During Your Initial Call
Beyond the 15 essential questions, also ask:
“What’s your onboarding process and timeline?”
“How do you handle the transition from our current provider?”
“What happens if we’re not satisfied after 90 days?”
“Can you provide a detailed service proposal in writing?”
“Who would be my main contact and can I meet them?”
Conclusion: Finding the Right Local IT Support Partner
Searching for “IT support companies near me” is just the beginning. The real work is in thorough evaluation, asking the right questions, and selecting a provider who will genuinely partner with your business for the long term.
Remember the key principles:
✓ Local presence genuinely matters for on-site support, accountability, and relationship building
✓ Cheaper isn’t better – fair pricing reflects quality service and business sustainability
✓ Written SLAs are non-negotiable – verbal promises don’t protect your business
✓ Technical expertise matters – verify certifications, experience, and specializations
✓ Cultural fit impacts success – you’ll work with this company regularly; compatibility matters
✓ References tell the truth – always speak with actual clients before deciding
✓ Contracts should be fair – avoid excessive lock-ins and hidden fees
Get Local IT Support in West Sussex
ATS Connection provides comprehensive managed IT support for businesses across West Sussex. Based in Arundel, we serve Chichester, Worthing, and throughout the region with fast local support, transparent pricing, and genuine partnership.
Why businesses choose ATS Connection:
✓ True local presence – Based in Arundel with technicians throughout West Sussex ✓ Fast response times – 2-4 hour on-site response across the region ✓ Transparent pricing – No hidden fees, clear service scope ✓ Proactive support – 24/7 monitoring prevents problems before they impact you ✓ Security-focused – Cyber Essentials certified with comprehensive security management ✓ Flexible contracts – Fair terms without excessive lock-ins ✓ Personal service – Dedicated account management and regular face-to-face reviews
Ask how much does IT support cost and most IT companies will give you a vague answer and a request for a meeting. That is frustrating when all you want to know is whether this is a £300 a month decision or a £3,000 a month decision.
So here is a straight answer, with real numbers.
The short answer: how much does IT support cost?
Most UK small and medium businesses pay between £30 and £90 per user per month for managed IT support. A typical 15 person business should expect somewhere in the region of £600 to £1,200 a month for a properly managed service that includes support, monitoring, security and backup.
Pay as you go support, where you call someone only when something breaks, usually runs at £75 to £150 per hour.
The rest of this guide explains what drives those numbers, what should be included, and where providers quietly add cost.
WORK OUT YOUR OWN NUMBER
IT support cost calculator
Move the slider to your headcount and pick the level of cover you need. You will get a per user figure and a monthly range straight away, with no form to fill in first.
What would managed IT support cost your business?
Use the calculator for a realistic ballpark. Your exact price depends on your current setup, licences, sites and security requirements.
15 users
Rough ballpark
£0 per user / month
A guide to the likely investment, not a formal quote.
£0/mo
Managed support with a full team behind you
£2,500+/mo
One £30k in-house salary before employment costs
£75 to £150/hr
Ad hoc support after something has already gone wrong
What is included at this level
What your exact price depends on
This estimate covers managed support and service. Your final price may also reflect:
The Microsoft 365 and cyber security licences you choose
Cyber Essentials or Cyber Essentials Plus certification
Multiple sites and remote or hybrid workers
Hardware, migrations and one-off projects
Onboarding work, usually between £500 and £2,000
A short review lets us provide a clear exact quote with no hidden assumptions.
No obligation. We will tell you clearly what is included and whether managed support is the right fit for your business.
Email me this estimate
We will send a copy to your inbox. Tick the box if you would also like ATS to review it and provide an exact quote.
Cyber Essentials certified · Microsoft Partner · rated 5.0 on Google
OUR PRICING
IT support packages: what ATS actually charges
Most pricing guides stop at the market range and leave you no better off. Here is what we charge, so you have something concrete to hold any other quote against. Both packages are billed per user, per month, on a rolling annual agreement with a minimum monthly spend of £500. Microsoft and cyber security licences are billed separately, at cost.
Core support
£30 to £48 per user, per month
Everything needed to keep a business running properly day to day. For a team of 15, roughly £500 to £700 a month.
Unlimited helpdesk support
24/7 proactive monitoring
Patching and security updates
Endpoint protection
Guaranteed response times
Named engineers who know you
Complete IT and security
£55 to £90 per user, per month
For businesses with compliance requirements or sensitive client data. For a team of 15, roughly £850 to £1,350 a month.
Everything in Core support
Managed cyber security
Microsoft 365 management
Backup and disaster recovery
Cyber Essentials guidance
Regular IT strategy reviews
For context, a single in-house IT hire on a £30,000 salary costs upwards of £2,500 a month before employment costs, and covers one person’s skill set with no holiday cover. Ad hoc support runs at £75 to £150 an hour and only starts after something has already gone wrong.
OUR PRICING
IT support packages: what ATS actually charges
Most pricing guides stop at the market range and leave you no better off. Here are our own IT support packages and what they cost, so you have something concrete to hold any other quote against. Both are billed per user, per month, on a rolling annual agreement with a minimum monthly spend of £500. Microsoft and cyber security licences are billed separately, at cost.
Core support
£30 to £48 per user, per month
Everything needed to keep a business running properly day to day.
Unlimited helpdesk support
24/7 proactive monitoring
Patching and security updates
Endpoint protection
Guaranteed response times
Named engineers who know you
Complete IT and security
£55 to £90 per user, per month
For businesses with compliance requirements or sensitive client data.
For a team of 15, that is roughly £500 to £700 a month on Core support, or £850 to £1,350 a month on Complete IT and security. For comparison, a single in-house IT hire costs upwards of £2,500 a month before employment costs, and ad hoc support runs at £75 to £150 an hour once something has already gone wrong.
The three ways IT support is priced
1. Per user, per month
The most common model, and generally the fairest. You pay a fixed monthly fee for every member of staff who uses IT, whatever devices they have. Someone with a laptop, a desktop and a mobile counts once.
Typical range: £30 to £90 per user per month.
It is easy to budget for, it scales cleanly as you hire, and it does not punish you for giving people the equipment they need.
2. Per device, per month
You pay for every machine, server and piece of hardware being supported.
Typical range: £15 to £50 per device per month, with servers charged considerably more.
This can work out cheaper if your staff share machines. It works out expensive if everyone has a laptop and a desktop, and it can create an odd incentive where you avoid buying equipment your team actually needs.
3. Pay as you go, or ad hoc
You call when something breaks and you pay for the time.
Typical range: £75 to £150 per hour, often with a minimum charge.
It looks like the cheapest option and it is the most expensive one for most businesses. More on that below.
What should be included in a managed IT contract
The headline price means nothing until you know what sits behind it. A proper outsourced IT support service should include all of the following as standard:
Unlimited remote support during business hours, so nobody hesitates to raise an issue
Proactive monitoring of your systems around the clock, so most problems are caught before you notice them
A guaranteed response time, in writing, not a vague promise
Patching and updates applied automatically across every machine
Account management, meaning someone who knows your business and reviews it with you regularly
If a quote looks unusually cheap, one of these is almost certainly missing. Usually it is backup testing or monitoring, and those are the two you will miss most on the day something goes wrong. To see how your own setup measures up against this checklist, try our free IT and cyber benchmark.
What is usually charged separately
Even with a good contract, some things sit outside the monthly fee. That is normal and reasonable, but you should know about them upfront:
Onboarding or setup fee. Typically £500 to £2,000, covering the work to audit, document and take over your systems properly
Hardware. Laptops, servers, firewalls and phones are bought, not rented, unless you agree otherwise
Microsoft and software licensing. Usually billed at cost or with a small margin, on top of support
Projects. Office moves, migrations, new server installs and similar are quoted separately
Out of hours support. Some providers include it, most charge extra
Why the cheapest quote is usually the most expensive
Businesses that stay on pay as you go support tend to believe they are saving money. In practice they pay in three ways.
They pay in downtime. With no monitoring, nobody spots the failing hard drive, the backup that stopped running three months ago, or the machine quietly missing security updates. Problems are only found when they become emergencies.
They pay in hesitation. When every call costs money, staff put up with slow machines and broken processes rather than pick up the phone. That lost productivity never appears on an invoice, but it is real.
They pay in the bad month. Reactive support is cheap until the month it is not. A serious incident, a failed server or a security breach turns a modest monthly saving into a very large bill, alongside days of lost trading.
Managed support is not just cheaper support. It is a different product. You are paying for problems that never happen.
What drives the price up or down
Two businesses of the same size can get very different quotes. The main factors are:
Number of users and devices. The single biggest driver
Servers. On premise servers cost meaningfully more to support than a cloud only setup
Security and compliance needs. Businesses handling sensitive data, or working in regulated sectors, need more protection and often managed cyber security and Cyber Essentials certification
Age of your equipment. Old hardware breaks more, so it costs more to support
Number of sites. Multiple locations mean connectivity between them and more to keep in sync
Response times. A 15 minute guarantee costs more to deliver than a next working day one
Does the price change by industry?
Somewhat. What changes most is what you need, rather than the rate itself. Sectors handling sensitive client data or working to compliance requirements tend to need more security, tighter access control and formal certification, which pushes them towards the upper end of the range.
Most UK businesses pay between £30 and £90 per user per month for managed IT support. The range depends on what is included, particularly whether security, backup and Microsoft 365 management are part of the package or charged separately.
How much does IT support cost for a small business?
A 10 person business should typically budget £400 to £900 a month for a fully managed service. A 25 person business should expect £1,000 to £2,000 a month. Businesses with on premise servers or higher security requirements sit at the upper end. See our small business IT support page for more.
Is managed IT support worth it for a small business?
For most businesses with five or more staff, yes. Below that, ad hoc support can be reasonable. Above it, the cost of downtime, the security risk and the productivity lost to staff struggling on alone usually outweigh the monthly fee comfortably.
What is the difference between managed IT support and pay as you go?
Pay as you go is reactive. You call when something breaks and pay for the time. Managed support is proactive. Your systems are monitored continuously, problems are prevented rather than fixed, and support is included in a fixed monthly fee so there is no hesitation about picking up the phone.
Should IT support include Microsoft 365 licences?
Not usually. Licences are typically billed separately from support, because the cost depends entirely on how many people you have and which Microsoft plan you are on. Your provider should manage the licences as part of the service, but the licence cost itself sits on top.
How much does an IT support contract cost to set up?
Expect an onboarding fee of £500 to £2,000 depending on the size and complexity of your setup. This covers auditing your systems, documenting them, deploying monitoring and security tools, and taking over from your previous provider properly.
Get a real number for your business
We have supported businesses across Chichester, Worthing, Arundel and West Sussex since 2015. We are Cyber Essentials certified and a Microsoft Partner, and we look after everyone from architects and engineers to hotels, vets and property firms.
If you would like a straight answer on what IT support would cost for your business, book a free IT review or get a quote and we will give you a real number.
Free Cyber Security Audit
Request your free cyber security audit and find out how safe your business is from cyber related crime. Simply fill in the form and one of our cyber security experts will be in touch.