# IT helpdesk outsourcing: 5 benefits, their trade-offs and best practices

> IT helpdesk outsourcing buys longer hours, broader skills, predictable cost and capacity, at a price in context and control. How to decide, price and run it.

- URL: https://computese.com/unlocking-the-power-of-it-helpdesk-outsourcing-top-5-benefits-and-best-practices/
- Author: Duong Quan Nguyen, CEO, Computese
- Published: 2023-12-01
- Updated: 2026-09-25
- Topics: IT support

## In short
- IT helpdesk outsourcing buys five things: longer coverage hours, a broader bench of skills, predictable cost, capacity that scales and a measured service. Each one has a catch that the contract has to handle.
- The risks are lost context, dependency on one provider and security exposure: a provider holds privileged access to many customers at once, which is why attackers target providers.
- You outsource the work, not the accountability. You remain responsible for your data and your users, so someone on your side has to manage the provider.
- Best practices: start from your own ticket and cost numbers, choose a provider on evidence, write an SLA that measures outcomes, plan the transition and the exit at signing, and review monthly.
- Outsourcing is the wrong answer when ticket volume is small and well handled, when fixes depend on undocumented knowledge, when outside admin access is not allowed, or when a lower price is the only goal.

IT helpdesk outsourcing means paying a specialist provider to run your help desk: it answers your staff's calls, chats and tickets, fixes or routes each one, and reports against targets agreed in a service level agreement (SLA). It buys longer hours, broader skills, predictable cost and spare capacity. You give up some context and control, and keep the accountability.

This guide makes the business case honestly: five benefits and the catch in each, the risks you take on, how in-house, outsourced and co-managed support compare, how providers price the work, five best practices from your first numbers to the exit, and when outsourcing is the wrong answer. If your staff work remotely, our guide to [outsourced help desk support for remote teams](https://computese.com/optimizing-remote-work-through-outsourced-it-help-desk-support/) covers devices, provider access, caller verification and the agreement clause by clause. If the vocabulary is new, start with [what an IT help desk is](https://computese.com/demystifying-the-it-help-desk-navigating-the-world-of-outsourced-support/): tiers, tickets and the metrics an SLA is written in.

## What you buy when you outsource the help desk

ITIL, the IT service management framework, describes the [service desk](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-service-desk-3706) as the central point of contact between a service provider and its users. Most businesses call it the help desk, and this guide uses both names for the same thing. Outsourcing it means another company runs that point of contact: its engineers take every call, chat and email, log each one as a ticket, fix what they can and escalate the rest, under a contract that sets the hours, the targets and the systems covered.

That company is usually a managed service provider (MSP). A joint [advisory on MSPs](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a) from the cyber security agencies of the UK, Australia, Canada, New Zealand and the United States (May 2022) defines them as organizations that deliver, operate or manage IT services for customers under a contractual arrangement such as a service level agreement. You can buy the help desk alone, or as part of [fully managed IT](https://computese.com/understanding-it-support-a-vital-role-in-the-digital-era/), where the same provider also administers your cloud tenant, devices, servers and security tools.

Scopes differ more than prices, so read them line by line. A scope names the users, devices, applications, channels and service hours covered, and the work included: accounts and passwords, email, laptops and phones, printers, access changes, new starters. Check just as carefully what it leaves out: projects such as a tenant migration or an office move, on-site visits, hardware and licences, and applications a third party supports.

## Five benefits of help desk outsourcing, and the catch in each

These are the reasons outsourcing works when it does. Each comes with a catch the contract has to handle, which is why the figure at the top of this page pairs every benefit with its control.

### 1. Longer coverage hours

One or two internal people cover their own working hours, minus holidays, sick days and training. A provider runs a rota across a larger team, so someone answers when your IT person is away, early in the morning, or at the weekend if you pay for it. For staff who start before the office opens or work in several time zones, that alone can justify the contract.

The catch: coverage is whatever the contract says. "24/7" can mean a person answers every contact at every hour, or an engineer on call for the top priority while everything else waits for the morning. Write down which priorities get a human reply in which hours.

### 2. A broader bench of skills

An internal generalist has to know Windows and macOS, Microsoft 365 or Google Workspace, the network, the printers and the security tools. A provider spreads that knowledge across a team that meets the same problems at many customers, and can put a specialist on the unusual ones: a Mac fleet, a mail-flow fault, a firewall rule. You get depth you could not justify hiring one role at a time.

The catch: the engineer who answers knows many systems and none of your business. They do not know which application matters at month-end, who may approve access to payroll, or why the warehouse PC runs an old browser. That context has to be written down, in runbooks and a knowledge base you own, or it is lost on every call.

### 3. Predictable cost

Running a help desk yourself means salaries, recruitment, training, cover for absences, and the tools: ticketing, remote support, device management. Outsourcing turns much of that into a fee that follows the number of users or devices. The joint advisory notes that many organizations use MSPs to scale and support their environments without expanding internal staff or developing the capability themselves.

The catch: predictable is not the same as cheaper. The UK Government's [Sourcing Playbook](https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html) points out that the cost of buying a service from a supplier includes market factors such as risk and profit. Any saving has to come from the provider's scale and tools, and it shrinks fast when much of your work falls outside the scope and is billed on top.

### 4. Capacity that scales

A wave of new starters, a new office or an email migration creates a spike of tickets that a small team cannot absorb. A provider can add engineers to your account for the spike and step back down afterwards, and a per-user fee grows with the team without a hiring round.

The catch: you become one customer in a shared queue. The Canadian Centre for Cyber Security's guidance for [consumers of managed services](https://www.cyber.gc.ca/en/guidance/cyber-security-considerations-consumers-managed-services-itsm50030) (October 2020) warns that a request urgent to you can sit in a provider's queue while it handles critical issues for other customers. Priority definitions, targets and named escalation contacts are what move your ticket up.

### 5. A measured service, and your team's time back

Informal support runs on favours: people walk over to the one colleague who knows. An outsourced desk works from tickets, priorities and monthly reports, so you can see what breaks, how often, and how fast it gets fixed. If you have internal IT staff, the provider takes the password resets and routine requests, and your people get time back for projects.

The catch: a report is only as honest as its measures. A desk can meet every target on paper while users stay unhappy, by closing tickets early or counting an automatic reply as a response. Measure outcomes as well as speed, and keep someone on your side who reads the report.

## The risks you take on: context, dependency and security

The catches above are operational. The risks below are structural, and they belong in the decision before any contract is signed.

### Lost context

Every business runs on knowledge nobody wrote down. When the help desk moves out, that knowledge has to move with it, and if outsourcing replaces the one person who held it, it leaves with them. Document the estate before anyone's role changes, not after.

### Dependency and vendor lock-in

The Canadian guidance describes vendor lock-in as the point where moving your data to another provider is no longer financially feasible, because of penalties, proprietary formats or who owns the data, and advises considering an exit strategy when you sign. In a help desk, lock-in rarely comes from data formats. It comes from where the knowledge lives: ticket history, documentation, admin credentials and the agents installed on every device. The Sourcing Playbook adds that bringing a service back in-house is a substantial transformation, and harder when you rely on intellectual property held by the supplier. The UK National Cyber Security Centre's [supply chain principles](https://www.ncsc.gov.uk/collection/supply-chain-security/principles-supply-chain-security/ii-establish-control) put it simply: know where you rely too heavily on a single supplier.

### Security exposure

To support you, a provider needs what the joint advisory calls trusted network connectivity and privileged access to your systems. That makes providers a target. The agencies warn that a vulnerable MSP can be an initial access vector into many customer networks at once, and that compromising one can enable ransomware and espionage across its whole customer base.

![One management server in the middle, drawn in orange with an open padlock, connects by thin lines to five small office networks around it, each holding a laptop, a desktop and a server.](https://computese.com/images/blog/unlocking-the-power-of-it-helpdesk-outsourcing-top-5-benefits-and-best-practices/blast-radius.ffee171ac7-1536.webp)

*One breached provider reaches every customer it manages: the access that makes remote support efficient is the access an attacker inherits.*

It has happened. From July 2, 2021, [CISA and the FBI responded](https://www.cisa.gov/news-events/news/kaseya-ransomware-attack-guidance-affected-msps-and-their-customers) to ransomware attacks that exploited a vulnerability in Kaseya VSA, remote monitoring and management (RMM) software used by MSPs, to hit MSPs and their downstream customers. CISA advised affected customers, some left without their RMM service, to revert to manual patch management. Help desks are also targeted directly, by callers posing as employees to get passwords and MFA reset; the [remote teams guide](https://computese.com/optimizing-remote-work-through-outsourced-it-help-desk-support/) covers verifying callers and giving a provider's engineers access safely.

### Accountability stays with you

The Canadian guidance is plain: your organization is the data owner and is legally responsible for its security, whoever operates the systems. Privacy law agrees. The Office of the Privacy Commissioner of Canada's [guidelines on processing across borders](https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/) explain that under PIPEDA an organization remains responsible for personal information it transfers to a third party for processing, must secure a comparable level of protection by contract or other means, and should keep the right to audit how the third party handles it. One of their examples is an internet service provider using a third party so that technical support is available around the clock.

> [!IMPORTANT]
> You can outsource the work of the help desk, not the responsibility for it. Name the person on your side who owns the provider relationship before the contract starts.

## In-house, outsourced or co-managed: which model fits

There are three ways to run a help desk, and plenty of businesses sit between them.

|                   | In-house                                         | Fully outsourced                                       | Co-managed                                        |
| ----------------- | ------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------- |
| Who answers users | Your staff                                       | The provider                                           | Split by an agreed rule, often the provider first |
| Business context  | Deepest                                          | Must be written down and kept current                  | Shared, if both teams use the same records        |
| Coverage hours    | Your staff's hours                               | As contracted                                          | The provider fills your team's gaps               |
| Skills            | Limited by headcount                             | The provider's bench                                   | Both                                              |
| Cost profile      | Salaries, tools and turnover, in steps           | A fee per user, device or ticket                       | A smaller fee plus your team                      |
| Main risk         | The one person who knows everything              | Dependency and exposure                                | Unclear ownership between the teams               |
| Fits when         | Volume is steady and the knowledge is specialist | There is no IT team, or one person does IT on the side | An IT lead needs cover, depth or extra hands      |

Co-managed support is the most underrated of the three. The provider takes first-line tickets, after-hours cover, overflow or projects, while your team keeps ownership of systems, priorities and decisions. It fails in one predictable way, tickets that fall between the teams, and works when both teams draw from one queue and every type of ticket has a written owner.

![Laptops and a phone send tickets into one shared queue. Most tickets go on to a provider's help desk console, one goes to an internal IT desk, and both desks are linked to one binder of records.](https://computese.com/images/blog/unlocking-the-power-of-it-helpdesk-outsourcing-top-5-benefits-and-best-practices/co-managed.925a4bd83f-1536.webp)

*Co-managed support works when both teams draw from one queue, with a written rule for which tickets each one owns.*

Our [IT support service](https://computese.com/services/it-support/) works either way: fully managed, as your help desk and administrators, or alongside your IT team, which keeps day-to-day ownership while we take escalations, overflow and projects. Whichever it is, admin access goes to named engineers with multi-factor authentication and is removed when the work ends.

## How help desk outsourcing is priced

No pricing model is better in general. What matters is whether it fits your volume, and what it rewards the provider for.

| Model                      | How it works                                                                  | Fits                                              | Watch for                                                     |
| -------------------------- | ----------------------------------------------------------------------------- | ------------------------------------------------- | ------------------------------------------------------------- |
| Per user                   | A monthly fee for each person supported, typically covering all their devices | Teams where most people have a laptop and a phone | How "user" is defined: shared mailboxes, contractors, leavers |
| Per device                 | A monthly fee for each laptop, desktop, phone or server                       | Shared workstations, kiosks, device-heavy sites   | Servers and network devices priced at a different rate        |
| Per ticket                 | A price for each incident or request                                          | Low or irregular volume, overflow                 | It pays the provider more when things break, not less         |
| Retainer or block of hours | A fixed monthly amount of time, or a prepaid bank of hours                    | Small, predictable workloads and advisory time    | Hours that expire unused, and the rate once they run out      |
| Time and materials         | Hourly rates for the work done                                                | Projects with an unclear scope                    | No ceiling unless you set one                                 |

A fixed fee per user or device aligns the provider with you: every ticket it prevents is margin it keeps. A per-ticket price aligns it with volume, so pair it with targets for removing recurring causes, or accept that nobody is paid to remove them.

Then compare what sits outside the fee. Onboarding charges, after-hours work, on-site visits, projects, licences for the provider's own tools, and the minimum term and notice period can each move a quote more than the headline rate.

To judge quotes at all, you need a benchmark. The Sourcing Playbook recommends a should-cost model: an estimate of the whole-life cost of each option (in-house, bought from the market, or a mix), built early, before prices come in. It also guards against what the Playbook calls low-cost bid bias: favouring a quote because it is the lowest rather than because it is realistic.

## Best practice 1: start from your own numbers

Before you ask anyone for a price, describe what you have. The Sourcing Playbook calls this a delivery model assessment: an evidence-based comparison of delivering a service in-house, buying it, or mixing the two. A small business does not need the civil service version, but it needs the same inputs:

- **Ticket volume** by month and by category, for as long as you have records. An export from the ticket system or a count of the IT inbox will do.
- **When tickets arrive:** hour of day, day of week and time zone, which tells you what coverage you need.
- **What is supported:** users, devices by platform, sites, business applications, and who holds admin rights today.
- **What the current setup really costs:** salaries and benefits, recruitment, training, tools, cover for absences, and the hours other staff lose fixing IT themselves.
- **Constraints:** regulated data, where data may be stored, who may hold admin rights, and vendor contracts that require an authorized partner.
- **What stays with you:** decisions, system ownership, and any work you want kept in-house.

With these numbers you can compare quotes on the same basis, spot a price model that does not fit your volume, and check a year later whether anything improved.

If you already employ help desk staff, check employment law before you announce anything. In the UK, for example, the TUPE regulations can transfer the employees doing the outsourced work to the new supplier automatically, on their existing terms.

## Best practice 2: choose a provider on evidence

A pitch tells you what a provider intends; evidence tells you what it does. Ask for the following, and treat a refusal as information.

| Ask for                                                  | What it tells you                                                                                         |
| -------------------------------------------------------- | --------------------------------------------------------------------------------------------------------- |
| A sample monthly report and a sample runbook, anonymized | Whether the reporting and documentation you are paying for exist                                          |
| ISO/IEC 20000-1 certification, and its scope             | That a service management system is in place for the services in scope                                    |
| ISO/IEC 27001 certification, or a SOC 2 Type 2 report    | Independent assurance of the provider's information security                                              |
| Who does the work, and from where                        | Whether your tickets go to the provider's staff or to a subcontractor                                     |
| Where tickets and your data are stored                   | Which country's laws apply to them                                                                        |
| How their engineers access customer systems              | Whether each engineer has a named account with MFA, and no admin credentials are shared between customers |
| Two references from customers of your size               | Whether the service holds up after the sales phase                                                        |
| The exit terms                                           | Notice, fees and what they hand back when you leave                                                       |

Some rows need a sentence more. [ISO/IEC 20000-1](https://www.iso.org/standard/70636.html) sets the requirements for a service management system, and ISO lists customers seeking assurance about the quality of services among its users; its requirements apply to the services in the scope of that system, so check the help desk you are buying is inside it. [ISO/IEC 27001](https://www.iso.org/standard/27001) sets the requirements for an information security management system. The Canadian guidance explains that a SOC 2 Type 2 report assesses how security controls worked over a period of six months or more, and that providers willing to share one usually do so under a non-disclosure agreement. The joint advisory asks customers to understand the risk from their provider's own subcontractors, and the NCSC principles tell you to decide whether you allow a supplier to subcontract at all. For the full set of access questions, including remote sessions and caller verification, use the checklist in the [remote teams guide](https://computese.com/optimizing-remote-work-through-outsourced-it-help-desk-support/).

> [!TIP]
> Pilot before you move everyone. The Sourcing Playbook notes that testing a service on a small scale before full implementation gives you real data about it. For a help desk, that can be one team, one site or after-hours cover only, with a review before the rest moves over.

## Best practice 3: write an SLA that measures outcomes

ITIL's [service level management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-4-practitioner-service-level-management-3867) practice exists to set clear, business-based targets for what a service does, how reliably it does it and how it feels to use (in ITIL's words, utility, warranty and experience). The Canadian guidance lists what the SLA should specify: turnaround times, communication channels, escalation processes, performance metrics and penalties for missed turnaround times. For a help desk, that means:

1. **Scope and hours.** Users, devices, applications and sites covered; exclusions; service hours with the time zone and public holidays; the channels users can use.
2. **Priorities.** Definitions by impact and urgency, with examples from your own business, so nobody argues at month-end about whether a locked-out finance team is urgent.
3. **Targets for each priority.** The time to a first reply from a person and to a resolution or workaround; whether the clock runs in business or calendar hours; when it may pause, for example while waiting for the user, and who decides.
4. **Experience measures.** Satisfaction at ticket close, reopened tickets, first contact resolution and the age of the open backlog. These stop speed targets being met at the users' expense.
5. **Reporting and review.** What the monthly report contains, and who meets to discuss it.
6. **Service credits and remedies.** What the provider owes for a missed target, and what follows repeated misses, such as a formal review or a right to terminate.
7. **Security responsibilities.** The joint advisory says the contract should state whether you or the provider own tasks such as hardening, detection and incident response, and how and when the provider tells you about an incident affecting your environment.
8. **Exit.** The arrangements in best practice 4.

Keep the list of measures short. The Sourcing Playbook warns that more than 10 to 15 KPIs per service makes contracts overcomplicated, and that KPIs should be designed to minimize perverse incentives. The classic one on a help desk: a resolution-time target on its own rewards closing tickets early, so pair it with the reopen rate.

Treat service credits as a signal, not compensation. The refund for a missed target is usually small next to what the miss cost your business; its value is that it forces the failure onto the review agenda. For a clause-by-clause checklist of the whole agreement, see the table in the [remote teams guide](https://computese.com/optimizing-remote-work-through-outsourced-it-help-desk-support/).

## Best practice 4: plan the transition, and the exit

The move is where outsourcing projects most easily lose goodwill. Run it as a project with an owner on each side:

1. **Hand over the numbers** from best practice 1, including the most common ticket categories and how each is solved today.
2. **Write down the estate:** an asset register of devices and licences, accounts and who holds admin rights, vendors and contracts, known issues and their workarounds.
3. **Set up the provider's access properly:** named accounts, MFA and the narrowest roles that do the job, and retire old shared admin logins.
4. **Transfer knowledge:** the provider's engineers shadow whoever handles tickets today, starting with the most frequent categories, and turn what they learn into runbooks you can read.
5. **Start small:** move one team, one site or after-hours cover first, then the rest.
6. **Tell your staff** how to reach the new desk, what changes for them, and how the desk will verify who they are.
7. **Watch closely at first:** a short daily check-in in the first weeks, then weekly, with every escalation reviewed.
8. **Hold the first formal review** after the first month, using the SLA's own measures.

Agree the exit plan at signing, while both sides still want the deal. The Sourcing Playbook says contracts should require an exit plan that joins the outgoing supplier's exit to the start of the next provider or of in-house delivery. It lists activities, milestones, roles, a joint risk register, and asset registers and transfers, with time for knowledge transfer and incentives for the incumbent to keep performing to the end.

Two steps close it. The NCSC principles say contracts should set out how the supplier returns and deletes your information and assets when the contract ends or transfers. And the joint advisory reminds customers to disable MSP accounts that no longer manage their infrastructure, noting that this can be overlooked when a contract terminates.

![A stack of documents, an asset card and a key travel along an arrow from a provider's desk back to a small office, while the provider's access line into the office ends at a closed orange padlock.](https://computese.com/images/blog/unlocking-the-power-of-it-helpdesk-outsourcing-top-5-benefits-and-best-practices/exit.7b4655deaf-1536.webp)

*An exit plan hands back the records and the keys, and closes the provider's access, a step the agencies warn is easy to overlook when a contract ends.*

## Best practice 5: manage the provider, and fix causes

Outsourcing changes your job from running the desk to managing a supplier. ITIL has a practice for that, [supplier management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-4-practitioner-supplier-management-3869), whose purpose is to make sure suppliers and their performance are managed well enough to support quality services. In practice:

- **Name an owner on your side** who reads every report and runs the review.
- **Review monthly for the first quarter, then quarterly:** targets by priority, satisfaction, reopened tickets, the backlog and the top ticket categories.
- **Ask for causes, not only counts.** ITIL's [problem management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-problem-management-3688) practice is about finding and managing the root causes of incidents so they do not recur. A good provider brings the three causes behind most tickets to the review, with a proposal to remove them.
- **Check, do not just trust.** The NCSC principles recommend building a [right to audit](https://www.ncsc.gov.uk/collection/supply-chain-security/principles-supply-chain-security/check-your-arrangements) into contracts and using it. At a minimum, review which provider accounts exist in your systems and what they did.
- **Decide on renewal early.** The Sourcing Playbook advises considering an extension well before notice is due and reviewing the benefits every year, so the choice is never forced by the calendar.

## When outsourcing the help desk is the wrong answer

Outsourcing is a tool, not a default. It is usually the wrong choice when:

- **Volume is small and already handled well.** If a capable person inside the business resolves a handful of tickets a week, a provider's minimum fee and the transition effort may cost more than the problem.
- **Most fixes depend on undocumented, fast-changing knowledge:** bespoke systems, lab or production equipment, or processes that change weekly. You would pay to transfer knowledge that is out of date by the time it is written.
- **Outside access is not allowed.** Regulation, client contracts or data residency rules may stop an outside company holding admin rights or storing tickets where it would. The Canadian guidance reminds consumers that data stored outside the country falls under different privacy, security and ownership laws.
- **The real problem is ownership or process.** Outsourcing an undocumented mess produces the same mess with a ticket number. Settle who decides what first, or make it the provider's first project.
- **Price is the only goal.** A quote chosen only for being low tends to exclude the work you need, and the market price includes the provider's profit either way.

Between all and nothing sit the partial options: after-hours cover only, overflow when your team is busy, or a co-managed desk where your team keeps ownership. They keep your context in-house and still buy the hours and depth you lack.

For more on running everyday IT for a growing team, see the [IT support topic](https://computese.com/category/it-support/).

## Key terms
- **Service desk**: The single point of contact between an IT provider and the people it supports, where incidents and requests are logged, prioritized and tracked. It is ITIL's name for what most businesses call the help desk.
- **Managed service provider (MSP)**: A company that delivers, operates or manages IT services for its customers under a contract, usually with a service level agreement. A help desk can be bought from an MSP on its own or as part of fully managed IT.
- **Co-managed IT**: An arrangement in which an internal IT team and a provider split the work, for example first-line and after-hours support to the provider, and ownership of systems and decisions to the internal team.
- **Service level agreement (SLA)**: The written agreement on what a provider covers, in which hours, and to which targets, such as the time to a first reply and to a resolution for each priority.
- **Service credit**: A fee reduction the provider owes when it misses an SLA target. It signals that something is wrong; it rarely compensates for what the miss cost the business.
- **Should-cost model**: An estimate of what a service ought to cost over its whole life, delivered in-house, bought from the market or mixed, built before asking for quotes so that each quote can be judged against it.
- **Vendor lock-in**: The point at which changing provider is no longer practical, because of penalties, data formats or knowledge that only the provider holds.
- **Exit plan**: The agreed sequence for ending a contract: what the provider hands back, how knowledge is transferred, when its access is removed and how service continues in the meantime.
- **Problem management**: The ITIL practice of finding and removing the root causes of incidents, so that the same ticket stops coming back.

## Common questions

### What are the benefits of outsourcing an IT help desk?

Longer coverage hours, a broader bench of skills, a cost that follows your users or devices instead of salaries and tools, capacity that grows with the business, and a ticketed, reported service that frees internal IT staff for projects. Each benefit has a trade-off: less business context, dependency on one provider and a new security exposure.

### Is outsourcing the help desk cheaper than hiring?

Not automatically. A provider's price includes its own risk and profit, so any saving comes from its scale, its tools and its cover for absences, and only while most of your work falls inside the agreed scope. Compare quotes with the whole-life cost of doing it yourself: salaries, recruitment, training, tools and cover.

### How is outsourced help desk support priced?

Common models are a monthly fee per user or per device for a defined scope, a price per ticket for low or irregular volume, and a retainer or block of hours. Projects, on-site visits and after-hours work may be quoted separately, so compare what each quote includes, not only the headline fee.

### What should a help desk SLA include?

Scope and exclusions, service hours, priority definitions, response and resolution targets for each priority, how the clock is measured, escalation contacts, reporting, service credits, security responsibilities and the exit arrangements. Add experience measures such as satisfaction and reopened tickets, so speed targets cannot be met at the users' expense.

### What is co-managed IT support?

An arrangement where an internal IT team and a provider share the work under one set of rules. The provider typically takes first-line tickets, after-hours cover, overflow or projects, while the internal team keeps ownership of systems and decisions. It works when every type of ticket has a named owner and both teams use the same queue and records.

### When should you not outsource your help desk?

When ticket volume is small and already handled well, when most fixes depend on undocumented knowledge of your business, when regulation or contracts prevent giving an outside company admin access or storing data where it would sit, or when the only goal is a lower price.

## Sources
1. [ITIL 4 Practitioner: Service Desk](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-service-desk-3706), PeopleCert
2. [Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A)](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a), CISA
3. [The Sourcing Playbook](https://www.gov.uk/government/publications/the-sourcing-and-consultancy-playbooks/the-sourcing-playbook-html), UK Government Commercial Function
4. [Cyber security considerations for consumers of managed services (ITSM.50.030)](https://www.cyber.gc.ca/en/guidance/cyber-security-considerations-consumers-managed-services-itsm50030), Canadian Centre for Cyber Security
5. [Kaseya Ransomware Attack: Guidance for Affected MSPs and their Customers](https://www.cisa.gov/news-events/news/kaseya-ransomware-attack-guidance-affected-msps-and-their-customers), CISA
6. [Guidelines for processing personal data across borders](https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/), Office of the Privacy Commissioner of Canada
7. [Supply chain security guidance: II. Establish control](https://www.ncsc.gov.uk/collection/supply-chain-security/principles-supply-chain-security/ii-establish-control), National Cyber Security Centre (UK)
8. [ISO/IEC 20000-1:2018 Service management system requirements](https://www.iso.org/standard/70636.html), ISO
9. [ISO/IEC 27001:2022 Information security management systems](https://www.iso.org/standard/27001), ISO
10. [ITIL 4 Practitioner: Service Level Management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-4-practitioner-service-level-management-3867), PeopleCert
11. [ITIL 4 Practitioner: Supplier Management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil-4-practitioner-supplier-management-3869), PeopleCert
12. [ITIL 4 Practitioner: Problem Management](https://www.peoplecert.org/browse-certifications/it-governance-and-service-management/ITIL-1/itil4-practices-problem-management-3688), PeopleCert
13. [Supply chain security guidance: III. Check your arrangements](https://www.ncsc.gov.uk/collection/supply-chain-security/principles-supply-chain-security/check-your-arrangements), National Cyber Security Centre (UK)
