Do Retainer MSPs Exist? How to Buy Block Hours or Co-Managed IT

You called five providers. Every one came back with the same shape of quote: per user, per month, all-inclusive, 25-seat minimum, 36-month term. You have eleven people, one file server you are about to retire, and maybe two IT problems a month. When you asked about buying fifty hours and calling when something breaks, two explained why that is not how it works, one quoted an hourly rate that made the per-seat deal look cheap, and two stopped returning calls.

You are not imagining the pattern, and you are not being gouged.

Retainer MSPs do still exist, mostly among smaller regional providers and independent IT consultancies. They are a shrinking share of the market for a structural reason: a provider paid a fixed fee per seat earns more when your environment breaks less, and a provider paid by the hour earns more when it breaks more. The one selling you hours has the least financial reason to fix a root cause. That is not a character judgment. It is what happens when you point the invoice in that direction.

Worth knowing early: most people asking this actually want a co-managed agreement. Small recurring fee for the tooling and the watching, hours for everything else, one page saying who owns what. Asking for that by name gets a very different reception than asking for a block of hours.

The four things you can actually buy

The pricing model decides what your provider does on a quiet Tuesday, which is when the useful work gets done.

Per-seat or per-device, all-inclusive. Fixed monthly fee, most support included, named exclusions, a term. The incentive is to reduce your ticket volume, because every ticket is unpaid labour against revenue already booked. That is genuinely aligned with you, and it is why the model won. Its failure modes are seat minimums that price out small buyers, fights over what “all-inclusive” excludes, and a provider optimising to touch you as rarely as possible, which looks like neglect until you check the patch reports.

Block hours or a prepaid retainer. You buy hours up front at a discount to the walk-up rate and draw them down. The incentive is to consume the block, and the mechanism is quieter than anyone deciding to bill you badly. The engineer who could spend six hours rebuilding your DNS properly knows those hours land on a statement you will read, and a twenty-minute workaround will not. So the workaround wins, eleven times, and the twelfth time it wins at 2am.

Pure time and materials. No commitment either way. The incentive is billable hours, but the bigger effect is queue position: a provider with forty contracted clients schedules them first, because their revenue arrives whether or not your problem does. You are the overflow.

Co-managed with a defined scope. A recurring fee covers a named list of functions, usually tooling, monitoring, patching and backup verification, plus an escalation path. Everything else is hourly. The incentive depends on what sits in which column, which is why the scope split is the whole product.

Why the market consolidated, from the provider’s side of the desk

Run the economics as the provider experiences them and the shift stops looking like a sales trend. Their tooling stack is priced per endpoint per month and billed to them whether you call or not: remote monitoring and management, endpoint detection and response, backup, a secrets vault, documentation, ticketing. Recurring revenue covers that fixed cost. Block hours do not, so the provider either marks tooling up on its own monthly line, which you read as a hidden fee, or declines to deploy it, which is worse.

Coverage works the same way. After-hours response needs a staffed rota, and a rota costs money on the nights nothing happens. Fund that from variable demand and you either charge a premium that looks absurd in a quiet month or let the rota quietly become one tired person’s mobile number. MSPs are also financed and sold on recurring revenue: a book of monthly contracts is an asset with a multiple attached, a book of hourly clients is a schedule.

The consequence is what matters to you. Proactive work only gets funded under a model that pays for outcomes rather than effort. Patch compliance reporting, firmware, hardening a sloppy identity tenant, killing the recurring fault behind a third of your tickets: invisible when done well, unbillable-feeling under an hourly arrangement. Buying hours is not just paying differently. It is buying a service that structurally omits the work that would reduce your need for it.

When a retainer MSP is genuinely the right buy

Four situations where block hours are correct and a per-seat contract means paying for capability you already have.

You have internal IT and need overflow or escalation. Your admin handles day-to-day; you need someone above them for firewall changes, a mail migration, a storage decision, or the week they are away. Senior hours, not operations. Strongest case for a block, and providers do sell it.

You need project capacity, not operations. Office move, tenant-to-tenant migration, Wi-Fi rebuild, acquisition integration. Defined outcome, defined end. Buy it against a statement of work and do not let it drift into unmanaged operations.

Your environment is small and structurally stable. Not small by headcount. The test is how much of your estate can break: identity and email in one cloud tenant, no on-premises server, no line-of-business database, laptops enrolled in device management, no inbound network services. Few failure modes, most of them a vendor’s problem. Add a legacy application server and the calculation inverts.

You want a second opinion, not a provider. Review an architecture, sanity-check someone else’s quote, answer a security questionnaire. That is a fractional advisory retainer: scope it as advice, with no implied response time.

The case not on that list is the most common one. You want block hours because managed pricing exceeds what you planned to spend, and you are hoping nothing goes badly wrong. That is an accepted risk, not a purchasing preference, and it deserves a named owner and a number. If a two-day outage would cost more than a year of per-seat fees, you have just talked yourself out of the block.

Co-managed is the thing you were probably asking for

Co-managed IT means a provider owns a named subset of IT functions under a recurring fee while you or your internal person owns the rest, with the boundary written down rather than assumed. It separates the two things a block-hour deal jams together: scheduled work goes in the fixed column, where the provider is paid to make it efficient, and unpredictable work goes in the hourly column, where you stop paying a premium for capacity you rarely use.

Write the split as functions with four columns: who performs it, who holds the administrative rights, who is contacted when it fails, and which column it bills from. Cover at least these.

  • Identity and email tenant administration. Who holds Global Admin, who approves new admins, who makes licence changes.
  • Endpoint management and patching. Operating system, third-party apps, firmware. Who approves rings, chases failures, reports compliance.
  • Endpoint protection and alert triage. Who sees a detection at 3am and what they may do about it unaided.
  • Backup configuration versus restore testing. Two jobs, commonly split by accident, meaning nobody has the second.
  • Network, firewall and connectivity, including who owns the ISP relationship and sits on hold.
  • Level 1 helpdesk. Whether end users contact the provider directly or only via your internal person. This one decision moves hour consumption more than any other.

Co-managed still has a fixed monthly floor, smaller than an all-inclusive seat price because you are not buying unlimited labour. That is the honest trade. If a provider says the fixed part can be zero, either they are deploying no tooling or recovering the cost somewhere you cannot see.

The hidden terms: exclusions, and whose tooling it is

A per-seat contract lists exclusions because the default is inclusion. An hourly agreement needs none, because nothing is included until you call. That is why block-hour proposals are short, and why the short proposal is the risk.

Get these in writing, and treat a vague answer as a no

  • Monitoring. Is anything watching, or does the clock start when a human notices? If alerts exist, who receives them out of hours, and is responding billable?
  • Patching. Automated under their tool? Is failure remediation included? Third-party applications and firmware, or only Windows updates?
  • Backup verification. Not “are backups configured.” When was the last successful test restore, who does the next, and from which budget column?
  • Licence and tooling costs. Separate, nearly always monthly, often on their own minimum term. Get the per-endpoint total in writing: it is the recurring commitment hiding inside your non-recurring deal.
  • After-hours. A rota or an individual? What hours, what multiplier, and is there a response target at all rather than an intention?
  • Whether the clock runs while waiting. On hold with the ISP, sitting in a vendor’s queue, waiting for hardware. Also travel, ticket documentation, and time when their junior escalates to their own senior.
  • Rounding, minimums and expiry. A 15-minute increment with a one-hour minimum per ticket gives a very different effective rate from the same headline number. Ask both, plus whether unused hours roll over and whether out-of-hours work draws at a multiple.

The stack is usually theirs, not yours

Their RMM agent is on every machine. Endpoint protection lives in their console. Backups may go to their storage, under their retention policy, on their contract with the underlying vendor. Credentials sit in their vault, documentation in their platform. That is how a provider delivers at volume, so none of it is wrong. But it means “how hard is it to leave” is decided at signature, and it bites hardest on a small hourly agreement, where you have no leverage on the way out. Four questions, answered in the contract rather than the sales call:

  • Whose paper are the licences on, and can they be assigned to us? Some vendors permit transfer of a subscription to the end customer; some do not. Find out which of your tools is which before you put data in one.
  • Is our cloud tenant under your partner agreement, and how is it detached? Then ask for a break-glass Global Administrator account that you control, excluded from their delegated access. The most valuable item on this list.
  • Where does backup data live, and on exit can we get a restorable copy? An export you cannot restore without their console is not an export.
  • Do we get the configuration and documentation on exit? Diagrams, device configs, runbooks, asset register, DNS records, with a format and a deadline in days.

This is not an exotic ask. NIST’s Cybersecurity Framework 2.0 has a subcategory for precisely it: GV.SC-10 requires that supply chain risk management plans “include provisions for activities that occur after the conclusion of a partnership or service agreement.” Put the clause in while they are still selling to you.

Security terms that should not depend on how you pay

The pricing model changes who does the work. It should not change what the work is. CISA’s Cross-Sector Cybersecurity Performance Goals, version 1.0.1 published March 2023, are written in plain language, which makes them unusually usable as contract terms for a buyer with no security team. Five map straight onto this relationship.

  • Privileged access. CPG 2.E requires that no user account always holds administrator privileges and that admins keep separate accounts for non-admin work; 2.C requires unique credentials so a compromised one cannot be reused laterally. Applied here: named technician accounts, never a shared one, removed when their staff leave. Ask how you would find out a technician had left.
  • MFA. CPG 2.H calls for the strongest available method: hardware-based phishing-resistant MFA such as FIDO or PKI first, app-based tokens or passkeys second, SMS or voice only where nothing else is possible. It applies to their access into your tenant as much as to your own staff, and theirs are administrative accounts.
  • Logging. CPG 2.T asks that access and security logs be collected and stored for detection and response, and specifically that security teams be notified when a critical log source is disabled. Under a block-hour deal there is usually nobody to notify. Say so plainly, record it as an accepted risk with an owner, then decide whether monitoring is the one thing you buy recurring.
  • Backups. CPG 2.R requires backups on a regular cadence, stored separately from source systems, and tested recurringly. CSF 2.0 says it twice: PR.DS-11, backups are “created, protected, maintained, and tested,” and RC.RP-03, integrity is verified before restoration. A test restore is billable under an hourly agreement, so it gets deferred. Buy it as a calendared, priced item.
  • Incident response. CPG 2.S expects response plans maintained, updated and drilled. The line to quote at a provider is CSF 2.0’s RS.MA-01: the plan is “executed in coordination with relevant third parties once an incident is declared.” Meaningless unless someone wrote down who declares an incident, who they call, what that person may do at 4am unapproved, and what happens if the block runs out mid-breach.

These are not big-company questions. CSF 2.0 puts them in procurement: GV.SC-05 wants security requirements “established, prioritized, and integrated into contracts and other types of agreements with suppliers.”

How to actually get the deal done

“Do you sell block hours” reads to a provider as a low-value prospect who will call once a quarter and query the invoice. Lead with the work instead. Send a short brief before the first call: headcount, device count, where identity and email live, servers and line-of-business applications, what you have internally, what actually happened in IT last year, and what you want covered. Then state it in their language: a co-managed arrangement, monitoring, patching and backup verification on a recurring fee, a block of hours for everything else. You have now described a product they sell.

The realistic minimum has three parts. A recurring per-endpoint fee covering tooling plus a management margin, because their tool costs are recurring and per device: non-negotiable in principle, negotiable in scope. A prepaid block of hours below their walk-up rate, where the prepayment is what buys queue position. And onboarding as a one-off project, because documenting an environment they have never seen is real work that a per-seat contract amortises over three years. Pay that up front and a 12-month term often appears where the website said 36.

Then the terms that make it survive contact with reality:

  • Hours that roll over within the term, and a top-up trigger at a stated balance so you are never empty mid-incident.
  • A written response target for the fixed-scope items only, explicit best-effort language for the rest. A target you both believe beats one neither of you does.
  • A root-cause clause. If one fault category consumes more than an agreed number of hours in a quarter, both sides scope a permanent fix and fund it from the block at a reduced rate. This repairs the incentive problem behind this whole article, costs the provider little to agree to, and almost nobody asks for it.
  • An exit clause covering licence assignment, restorable backup export, documentation handover with a deadline, and removal of their agents and admin accounts.

Search for IT consultancy, co-managed IT, fractional IT and IT project services rather than MSP; the providers who still do this rarely have a website with three pricing tiers. When one says no, ask who they would refer you to, because the firms that standardised on per-seat often keep a consultancy relationship for exactly this.

Then price the two offers against each other honestly. Take last year’s IT problems out of your inbox, estimate hours for each, apply the block rate plus the minimum increment, add the separate tooling line, and compare with twelve times the per-seat quote. The per-seat number is certain; yours is an estimate of a variable. Part of what a fixed fee buys is the removal of variance, and that is worth far more to a business that cannot absorb a surprise five-figure month than to one that can.

If you have landed on the co-managed shape, with monitoring, patching, backup verification and out-of-hours cover on a recurring line and your own people or a block of hours doing the rest, AB7 Solutions works the side buyers find hardest to fill: managed cybersecurity and SOC cover, VAPT and firewall and server security for the monitored scope a block-hour deal leaves out, plus contract staffing and staff augmentation when what you need is your own IT capacity rather than a provider. Send us the scope document and the exclusions list from the proposal in front of you and we will tell you where the risk sits, including when the honest answer is that your environment is small and stable enough that you do not need us. Call +1 321 341 7733, email ab@ab7solutions.com or director@ab7solutions.com, or start at www.ab7solutions.com.

Sources: CISA, Cross-Sector Cybersecurity Performance Goals, version 1.0.1 (March 2023), goals 2.C, 2.E, 2.H, 2.R, 2.S and 2.T; NIST, The NIST Cybersecurity Framework (CSF) 2.0, NIST CSWP 29 (26 February 2024), subcategories GV.SC-05, GV.SC-10, PR.DS-11, RS.MA-01 and RC.RP-03. Hourly rates, seat prices and market-share figures are not quoted here because published MSP pricing data is vendor-supplied and not independently verifiable; the mechanisms are described instead.

Leave a Comment

Your email address will not be published. Required fields are marked *