How to compare managed IT and cyber security quotes
Three proposals land, at three different prices, structured three different ways, and none of them make the comparison easy on purpose. A framework for putting them on the same page before you decide.
Why the quotes never line up
Ask three managed IT and cyber security providers to quote the same organisation and you will get back three different structures, not just three different numbers. One prices per device, one per user, one as a flat site fee. One bundles cyber security into the base fee, one lists it as an optional module, one does not mention it until you ask. None of this is necessarily dishonest — pricing models genuinely differ across the industry — but it means the lowest number on the page is not automatically the lowest cost, and the comparison has to be built by you before it means anything.
Get everyone to a per-seat number first
Whatever the pricing model, convert every proposal to a single per-seat, per-month figure before you compare anything else. Per-device pricing on an environment with two monitors and a phone per person will land higher than per-user pricing covering the same estate — a difference that is invisible until you do the arithmetic yourself.
Include everything genuinely recurring in that number: the base fee, any mandatory security add-on, backup, and licensing passed through at a margin. Leave out genuine one-off costs — onboarding, hardware refresh, migration work — and list those separately so they do not distort the ongoing comparison.
Build a coverage matrix, not a price table
Once the price is normalised, build a simple matrix: one row per capability you actually need — patching, endpoint protection, email security, identity/MFA enforcement, backup and restore testing, Essential Eight reporting, after-hours coverage — and one column per provider. Mark whether each is included in the base fee, available as a paid add-on, or absent entirely.
This is usually where the real gap between proposals shows up. Two providers quoting within ten per cent of each other on price can differ enormously on what that price actually includes, and the matrix makes that visible in a way a price table alone never does.
Read the SLA definitions, not the SLA number
Every proposal will state a response time. Almost none of them define what starts the clock, and that is where the number stops meaning what you assume it means. Does the clock start when the ticket is logged, or when an engineer is assigned — a gap that can run to hours on a busy day? Does "response" mean acknowledgement, or someone actually working the issue? Is the target measured and reported monthly, or simply asserted?
Ask each provider for their actual monthly SLA performance — a real report, not a promise — and for their P1 definition specifically. "Response within 15 minutes" attached to a P1 defined as "complete outage of a critical system" is a meaningfully different commitment to the same words attached to a P1 defined however the engineer on duty decides that day.
What "top 10" and "best MSP" lists don't tell you
If your search for providers turned up a "top 10 managed IT providers" or "best MSPs in Australia" listicle, treat it as a starting point for names, not a verdict. A meaningful share of these lists are built on submission and review-platform fees rather than independent evaluation — providers pay to be listed, or pay for prominence within the list, and the ranking criteria are rarely published in enough detail to check. That does not make every name on the list a bad choice. It does mean the ranking itself tells you almost nothing about fit for your organisation specifically.
Use those lists to build a longlist, then apply the framework above to the three or four names that actually respond to your brief. The comparison you build yourself, from real proposals against your real requirements, is the only ranking that means anything for your decision.
The exclusions clause is where the real price lives
Every managed services agreement has a scope boundary, and the exclusions list is usually shorter and vaguer than the inclusions list — which is precisely why it is worth reading first, not last. Common gaps: after-hours work billed separately despite a "24/7" headline, a device count that excludes servers or network equipment, a security incident response carved out as a separate paid engagement rather than covered under the base agreement.
Ask directly: "if we have a confirmed security incident tomorrow, what is covered under this agreement and what would generate a separate invoice." A provider who answers cleanly has priced honestly. A provider who has to check is telling you something too.
Questions
Is the cheapest quote ever the right choice?
Occasionally, if the coverage matrix comes back equivalent. More often a materially cheaper quote means a narrower scope, offshore delivery, or a lower engineer-to-client ratio — any of which can be a reasonable trade, but should be a deliberate one, not a surprise in month four.
How many providers should I actually get quotes from?
Three. It is enough to see a genuine spread in pricing and scope without turning the comparison into a research project, and it is a fair number to ask of each provider's time.
Should I tell providers what competitors quoted?
Tell them you are running a competitive process and how many providers are involved — that is fair and improves the quality of what comes back. Sharing a specific competitor's number usually just anchors everyone to the same figure rather than surfacing their actual best offer.
Want a proposal that survives this framework
Per-seat pricing, security included in the base agreement, and a written SLA with a real definition behind it — ask us for the same matrix we just described.