Pricing & Cost

Explore Managed IT →

How much does IT support cost for a small business in Canada?

Most Canadian small businesses pay between $100 and $250 per user per month for fully managed IT support, depending on the level of security, compliance requirements, and after-hours coverage included. A 10-person business should expect $1,200–$2,500 per month for a complete package covering help desk, monitoring, patching, backup, and security. Break-fix (hourly) support typically runs $125–$200 per hour, which seems cheaper until an outage or security incident hits. The biggest pricing variable isn't headcount — it's how much risk the business carries: regulated data, remote workers, and legacy systems all add cost.

What's the difference between per-user and per-device IT pricing?

Per-user pricing charges a flat monthly fee for each employee regardless of how many devices they use, while per-device pricing charges separately for each computer, server, and mobile device. Per-user pricing is usually better for modern businesses where one person uses a laptop, phone, and tablet. Per-device pricing can be cheaper for businesses with shared workstations, like manufacturing floors or retail. Always ask which model a provider uses and run the math against your actual environment — the "cheaper" headline rate often isn't.

Why is break-fix IT support more expensive in the long run?

Break-fix support costs more over time because you pay for downtime, not just repairs — and the provider only earns money when something is broken. With hourly support, a single ransomware incident or server failure can cost $10,000–$50,000 in emergency labour, data recovery, and lost revenue. Managed services flip the incentive: the provider profits by keeping your systems healthy, so problems are caught before they become outages. Studies consistently show businesses on managed contracts experience 50–80% less unplanned downtime than break-fix customers.

Are there hidden costs in managed IT contracts?

The most common hidden costs in managed IT contracts are project work billed separately, after-hours surcharges, onboarding fees, hardware markups, and per-incident security response fees. Before signing, ask specifically: What is not included in the monthly fee? Is after-hours support extra? Are security incidents covered or billed hourly? What does offboarding cost if we leave? A reputable provider will answer these in writing. If the proposal is vague about exclusions, the exclusions are where you'll be billed.

Is managed IT worth it for a business with under 10 employees?

Yes — businesses with under 10 employees often benefit most from managed IT because they have no internal IT staff and a single outage affects a large percentage of the company. A 5-person firm losing email for a day loses 20% of its workforce capacity per affected person. Small businesses are also disproportionately targeted by cyberattacks precisely because attackers assume they're unprotected. Many providers offer scaled-down plans for micro-businesses covering the essentials: email security, backup, patching, and a help desk.

Managed Services vs. Alternatives

Explore Managed IT →

What is a managed service provider (MSP)?

A managed service provider (MSP) is a company that takes ongoing responsibility for a business's IT systems — monitoring, maintenance, security, support, and planning — for a fixed monthly fee. Unlike an hourly "IT guy," an MSP works proactively: patching systems before vulnerabilities are exploited, monitoring for failures before they cause downtime, and managing backups before they're needed. Most MSPs operate as an outsourced IT department, including strategic guidance on technology budgets and upgrades.

Should I hire an in-house IT person or outsource to an MSP?

For most businesses under 50–75 employees, outsourcing to an MSP costs less and provides broader expertise than hiring in-house. A single in-house IT hire costs $70,000–$100,000+ per year in salary and benefits, covers one skill set, takes vacations, and can quit. An MSP at the same or lower cost provides a full team: help desk technicians, network engineers, and security specialists, with coverage that doesn't depend on one person. In-house starts making sense when daily hands-on needs exceed what remote support can deliver — and many businesses then choose a hybrid (co-managed) model.

What is co-managed IT?

Co-managed IT is a partnership where an internal IT employee or team works alongside an external MSP, splitting responsibilities. Typically, the internal staff handles day-to-day user support and business-specific applications, while the MSP provides security operations, after-hours monitoring, patching infrastructure, and escalation expertise. It's the fastest-growing MSP model because it solves the "one person can't know everything" problem without replacing existing staff.

What does an MSP actually do every month?

A managed service provider's monthly work includes patching operating systems and applications, monitoring servers and networks 24/7, managing antivirus/EDR alerts, verifying backups completed and are restorable, responding to help desk tickets, reviewing security logs, and maintaining documentation. Most of this work is invisible when done well — which is exactly the point. The monthly report from your MSP should show patch compliance rates, backup success rates, ticket response times, and any security events handled.

How do I switch IT providers without disruption?

Switching IT providers safely requires three things before you give notice: a complete inventory of your accounts and passwords, confirmation of who legally owns your licenses and domain registrations, and a copy of your data and backups. A professional incoming MSP will run a discovery and onboarding period (typically 2–4 weeks) that overlaps with your outgoing provider's notice period. The transition should be invisible to your staff. If your current provider resists handing over credentials or documentation, that's a sign you're leaving at the right time — and in Canada, your business data and domain belong to you, not them.

How do I know if my small business is secure?

You can assess your business's basic security posture by checking five things: whether multi-factor authentication is enabled on email and banking, whether your email domain has SPF, DKIM, and DMARC configured, whether backups exist and have been test-restored, whether all computers receive automatic updates, and whether employees have had any phishing awareness training. Most small businesses fail at least two of these. Free tools can check your email domain configuration in seconds — misconfigured email authentication is one of the most common gaps and directly enables domain spoofing against your customers.

Do small businesses really get targeted by hackers?

Yes — small businesses are targeted more often than large ones because attackers know they have weaker defences and valuable data. The Canadian Centre for Cyber Security and industry reports consistently show that roughly 40–60% of cyberattacks hit small and medium businesses, and the Canadian Federation of Independent Business has reported nearly half of Canadian small businesses experiencing attempted attacks. Attacks are mostly automated: bots scan every internet-connected business regardless of size, looking for unpatched systems and exposed credentials. "Too small to be a target" is the single most expensive myth in small business IT.

What is the most common way small businesses get hacked?

The most common way small businesses get breached is through email — phishing messages that steal passwords or deliver malware account for the large majority of incidents. The typical pattern: an employee receives a convincing email, enters their Microsoft 365 password on a fake login page, and the attacker uses that account to redirect payments, send invoices to customers, or move deeper into the network. The second most common entry points are unpatched software vulnerabilities and reused passwords exposed in previous breaches.

What is multi-factor authentication and why does it matter?

Multi-factor authentication (MFA) requires a second proof of identity — like a phone app code — in addition to your password, and it blocks the vast majority of account takeover attacks. Microsoft has reported that MFA stops over 99% of automated credential attacks. For a small business, enabling MFA on email, banking, and cloud accounts is the highest-impact security improvement available, and it's typically free. Cyber insurance providers now routinely require it; without MFA, many insurers will decline coverage or deny claims.

What does cyber insurance require from a small business?

Most cyber insurance policies in Canada now require multi-factor authentication on email and remote access, endpoint detection and response (EDR) on all computers, tested offline or immutable backups, and security awareness training for staff. Insurers increasingly verify these controls during underwriting and — critically — during claims. A business that attested to having MFA but didn't can have a six-figure claim denied. Before renewing a policy, review the application questions with your IT provider and confirm every "yes" is actually true.

What should I do in the first hour after a ransomware attack?

In the first hour of a ransomware attack, disconnect affected machines from the network (unplug ethernet, disable Wi-Fi), do not power them off, do not pay or contact the attackers, and call your IT provider and cyber insurer immediately. Powering machines off can destroy forensic evidence and encryption keys held in memory. Your insurer likely requires you to use their approved incident response team — engaging anyone else first can jeopardize coverage. Businesses with tested backups and an incident response plan typically recover in days; businesses without them average weeks of downtime.

What is EDR and do I need it instead of antivirus?

EDR (Endpoint Detection and Response) is modern security software that watches for malicious behaviour on computers rather than just matching known virus signatures, and it has largely replaced traditional antivirus for businesses. Traditional antivirus misses modern attacks that use legitimate tools and fileless techniques. EDR detects suspicious activity patterns — like a Word document spawning PowerShell commands — and can isolate an infected machine automatically. Cyber insurers now commonly require EDR as a condition of coverage.

What is phishing simulation training and does it work?

Phishing simulation training sends realistic fake phishing emails to your own staff and provides instant teaching moments to those who click, and it measurably reduces click rates over time. Organizations running regular simulations typically see employee click rates drop from 25–30% to under 5% within a year. The goal isn't to punish employees — it's to build a reflex of suspicion and a culture where reporting a suspected phish is fast and blame-free. One reported phish can stop a campaign targeting your whole company.

Email & Domain Security

Explore Cybersecurity →

How do I check if my business email can be spoofed?

You can check if your email domain is spoofable by looking up its SPF, DKIM, and DMARC records — three DNS settings that tell receiving mail servers which senders are legitimate. If DMARC is missing or set to "p=none," anyone on the internet can send email that appears to come from your domain, and many receiving servers will deliver it. Free online checkers can verify this in seconds. Spoofed domains are commonly used to send fake invoices to your own customers — damage that lands on your reputation even though your systems were never breached.

What are SPF, DKIM, and DMARC in plain English?

SPF, DKIM, and DMARC are three DNS records that work together to prove your email is genuine: SPF lists which servers are allowed to send mail for your domain, DKIM adds a cryptographic signature to each message, and DMARC tells receiving servers what to do with mail that fails those checks. Without all three correctly configured, your legitimate email is more likely to land in spam, and criminals can impersonate your domain. Configuration takes under an hour for most businesses but is wrong or missing at the majority of small companies.

Why are my business emails going to spam?

Business emails most commonly go to spam because of missing or misconfigured SPF, DKIM, and DMARC records, a poor sending reputation, or sending from a domain that mail providers don't trust yet. Since Google and Yahoo tightened sender requirements in 2024, businesses without proper email authentication see significantly worse deliverability. Other causes include blacklisted IP addresses (common on shared hosting), spam-trigger content, and sudden volume spikes. Fixing authentication records resolves the majority of deliverability problems.

Has my business email been involved in a data breach?

You can check whether your business email addresses appear in known data breaches using breach databases like Have I Been Pwned, which index billions of compromised credentials from past incidents. If an address appears in a breach, the password used on that service — and anywhere it was reused — should be considered compromised. For businesses, the bigger risk is credential stuffing: attackers take leaked passwords and try them against your Microsoft 365 login. This is why breach monitoring plus MFA plus unique passwords (via a password manager) form a standard baseline.

Cloud, Microsoft 365 & Infrastructure

Explore Cloud & 365 →

Does my business still need a server in the office?

Most small businesses no longer need an on-premises server — email, files, and applications have moved to cloud services like Microsoft 365 — but exceptions exist for specialized line-of-business software, large local file workloads, and some manufacturing or design environments. The real question is total cost: an aging server carries hardware refresh costs ($8,000–$20,000 every 5 years), backup infrastructure, electricity, and a single point of failure sitting in a closet. Cloud equivalents shift that to predictable monthly costs with built-in redundancy. A proper assessment looks at your actual applications, not ideology in either direction.

What's the difference between Microsoft 365 Business Basic, Standard, and Premium?

Microsoft 365 Business Basic provides web-only Office apps and email, Standard adds the full desktop Office applications, and Premium adds the security layer — device management (Intune), advanced threat protection, and conditional access. For most businesses handling any sensitive data, Business Premium is the right answer despite the higher per-user cost, because it includes security capabilities that would cost far more to assemble separately. The most common licensing mistake is putting the whole company on Standard and assuming security is included — it isn't.

What is the difference between OneDrive and SharePoint?

OneDrive is personal cloud storage tied to an individual employee, while SharePoint is shared company storage organized by team or department — and confusing the two causes most small business file chaos. When employees store company files in personal OneDrive, those files leave with them, sharing breaks, and nobody can find anything. The correct structure puts company documents in SharePoint document libraries with permissions by team, and reserves OneDrive for personal working files. Migrating from a tangled OneDrive setup to structured SharePoint is one of the most common cleanup projects MSPs perform.

How long does it take to migrate email to Microsoft 365?

A typical small business email migration to Microsoft 365 takes one to two weeks of preparation and a cutover weekend, with staff experiencing little or no interruption when done correctly. The preparation includes auditing mailboxes, pre-syncing historical mail, configuring DNS authentication records, and setting up devices. A rushed or amateur migration is where horror stories come from — lost folders, broken calendars, days of bounced mail. Ask any provider proposing a migration to walk you through their cutover plan and rollback procedure before agreeing.

Is the cloud safe for business data?

Cloud platforms like Microsoft 365 are generally safer than small business on-premises servers because they're maintained by dedicated security teams — but the cloud provider only secures the infrastructure, not your configuration. Microsoft secures the data centre; you're responsible for MFA, access permissions, sharing settings, and backing up your own data. Most "cloud breaches" at small businesses are actually configuration failures: no MFA, overshared links, or compromised passwords. The cloud is safe when configured properly, and a major liability when set up with defaults and forgotten.

Do I need to back up Microsoft 365?

Yes — Microsoft 365 should be backed up separately because Microsoft's built-in retention protects against their infrastructure failing, not against your data being deleted, encrypted by ransomware, or lost to a malicious insider. Microsoft's own service agreement recommends third-party backup. Deleted items eventually purge permanently, ransomware can sync encrypted files to the cloud, and a departing employee can wipe their own mailbox. Third-party 365 backup costs a few dollars per user per month and is the difference between an annoyance and a catastrophe.

Backup & Disaster Recovery

Explore Backup & Continuity →

How often should a small business back up its data?

Small businesses should back up critical data at least daily, with most modern backup systems running continuous or hourly protection for servers and key systems. The standard to aim for is the 3-2-1 rule: three copies of your data, on two different types of media, with one copy off-site or offline. The off-site/offline copy is what saves you from ransomware, which deliberately seeks out and encrypts connected backups. Frequency matters less than two other questions: has a restore ever been tested, and can backups be reached by an attacker who's inside your network?

What is the 3-2-1 backup rule?

The 3-2-1 backup rule means keeping three copies of your data, on two different types of storage, with one copy off-site — and it remains the baseline standard for business data protection. A modern implementation might be: production data on your systems, a local backup appliance for fast restores, and encrypted cloud backup for disaster scenarios. Many businesses add a fourth element: one copy that's immutable or offline, which ransomware cannot encrypt or delete. Having backups isn't the goal; having a restorable copy that survives the same incident that destroyed the original is.

How do I know if my backups actually work?

The only way to know backups work is to perform a test restore — recover actual files or a full system and verify the data is intact and current. Industry surveys repeatedly find that a substantial share of businesses discover their backups are broken only during a real emergency. A proper backup program includes automated verification, regular test restores (at least quarterly), and documented recovery time measurements. Ask whoever manages your backups one question: "When was our last successful test restore, and how long did it take?" If there's no confident answer, assume you don't have backups.

What's the difference between backup and disaster recovery?

Backup is a copy of your data; disaster recovery is the complete plan for getting your business running again — including how fast, in what order, and on what systems. A backup answers "is our data safe?" Disaster recovery answers "how many days are we down?" Two businesses with identical backups can have wildly different outcomes: one restores critical systems in four hours because they planned and tested, the other takes two weeks because nobody knew the recovery order, passwords, or dependencies. The plan matters as much as the data.

Choosing & Evaluating an IT Provider

See our services →

What questions should I ask before hiring an IT company?

The most revealing questions to ask a prospective IT provider are: What is your guaranteed response time, in writing? What exactly is excluded from the monthly fee? Who owns our passwords, licenses, and documentation? What happens when we want to leave? Can you provide references from clients our size in our industry? How do you handle a security incident at 2 a.m.? A competent MSP answers all of these directly and in writing. Evasiveness on ownership and exit terms is the single biggest red flag.

What are red flags when choosing an IT provider?

The biggest red flags in an IT provider are refusing to document or share admin passwords, contracts with no defined exit process, vague answers about what's included, no written response-time commitments, pushing hardware sales over solving problems, and being unreachable outside business hours with no escalation path. Another subtle one: a provider who never says no or never recommends anything proactively is just an order-taker, not a partner. Your IT provider should occasionally tell you things you don't want to hear.

Who owns my passwords and data when I use an MSP?

Your business owns its data, domain names, software licenses, and administrative credentials — always — and any IT provider who withholds them is acting improperly. A professional MSP maintains documentation on your behalf and hands it over completely upon termination. Before signing with any provider, confirm in the contract that admin credentials, license ownership, domain registrar access, and documentation are your property and will be surrendered within a defined period after termination. "Credential hostage" situations are the most common ugly breakup in small business IT, and they're entirely preventable with one contract clause.

How do I compare IT provider proposals that all look the same?

Compare IT proposals by ignoring the marketing language and lining up five concrete items: exact response time commitments (with penalties), the specific security stack included (EDR, email filtering, MFA management, backup — by name), what's excluded and billed separately, contract length and exit terms, and the per-user math at your actual headcount. Most proposals look identical because the industry uses the same vocabulary; the differences live in the exclusions and the SLA fine print. A useful test: send each provider the same specific scenario ("an employee's laptop is encrypted by ransomware on Saturday morning — walk me through what happens") and compare the answers.

What does a good IT service level agreement (SLA) include?

A good IT SLA includes specific response times by severity (e.g., critical issues acknowledged within 15–30 minutes, resolved or escalated within defined windows), coverage hours stated explicitly, what counts as an emergency, escalation procedures, and remedies if commitments are missed. Beware of SLAs that only commit to response times with no resolution targets, or that define "response" as an automated email. Realistic small business SLAs: 1-hour response for critical outages during business hours, same-day for standard issues, with after-hours emergency coverage defined separately.

Compliance & Privacy (Canada)

Explore Cybersecurity →

What is PIPEDA and does it apply to my small business?

PIPEDA (the Personal Information Protection and Electronic Documents Act) is Canada's federal private-sector privacy law, and it applies to virtually every business in Canada that collects personal information during commercial activity — regardless of size. There is no small business exemption. PIPEDA requires you to protect personal information with appropriate safeguards, obtain meaningful consent, and report breaches that create a real risk of significant harm to the Privacy Commissioner and affected individuals. For IT purposes, "appropriate safeguards" increasingly means the security baseline insurers also demand: access controls, encryption, and breach detection.

Do I have to report a data breach in Canada?

Yes — under PIPEDA, Canadian businesses must report breaches of personal information that pose a "real risk of significant harm" to the Privacy Commissioner of Canada, notify affected individuals, and keep records of all breaches (even unreported ones) for two years. Failure to report can result in fines up to $100,000 per violation. Quebec's Law 25 imposes parallel and in some respects stricter obligations for businesses handling Quebec residents' data. The practical takeaway: you need detection capability (you can't report what you don't notice) and a documented incident response process before an incident, not after.

What IT requirements does Quebec's Law 25 add?

Quebec's Law 25 requires businesses handling Quebec residents' personal information to appoint a privacy officer, conduct privacy impact assessments, report confidentiality incidents to the Commission d'accès à l'information, and implement specific safeguards — with penalties that can reach into the millions or a percentage of worldwide revenue. Even businesses based outside Quebec are affected if they serve Quebec customers. From an IT perspective, Law 25 raises the bar on access logging, data inventory, and encryption compared to PIPEDA alone.

About BSD IT Services

BSD IT Services is a managed IT and cybersecurity provider based in the Greater Toronto Area, with more than 30 years of hands-on experience. We hold small and mid-sized businesses to the same IT and security standards as the corporations that could afford their own departments — and we provide services both locally and around the world.

The answers above reflect how we actually work with clients across law, finance, real estate, manufacturing, and professional services. If your situation doesn't fit neatly into one of them, that's exactly the kind of question we're happy to take by phone.

Last reviewed June 2026. We update this hub as the threat landscape and Canadian regulations change.

Start here

See where your business stands against these standards.

A free security assessment, with no obligation. We'll show you, plainly, where your business is solid and where it's exposed, measured against the same standards we hold for every client.

Book a free security assessment