A provider can run a competent help desk and still be out of its depth the moment a problem crosses systems. The tell is not how fast tickets close. It is what happens to the ones that do not fit the script: the intermittent fault, the security control nobody implemented, the migration that stalled six months ago and never came back up.
Downtime is where the gap shows up first. Estimates for Australian small and medium businesses put the cost of unplanned downtime anywhere from a few hundred to several thousand dollars an hour depending on how dependent the business is on its systems, and most guidance for businesses in the 10–200 employee range treats more than one to two hours of critical-system downtime a month as a sign something is wrong, not normal variance. A provider that treats repeat outages as routine, rather than investigating the underlying cause, is optimising for ticket volume, not for your risk.
Security is the second tell. The Australian Cyber Security Centre's Annual Cyber Threat Report 2024–25 recorded the average self-reported cost of a cyber incident for a small business at $56,600, up 14 per cent on the year before; for medium businesses it was $97,200, up 55 per cent. Those are the costs businesses report after an incident, not the cost of the prevention work that would have stopped it. If your provider cannot tell you, specifically, what your current identity, backup and monitoring posture is actually protecting against, that is worth treating as a finding, not a formality.
The third tell is what happens to the work that never quite gets scheduled. Every environment accumulates a backlog of things that should happen — a licence cleanup, a firewall rule that was meant to be temporary, an access review that is a year overdue. A help-desk-first provider tends to let that backlog grow indefinitely, because none of it generates a ticket. A provider capable of owning infrastructure risk turns that backlog into a visible, prioritised list and reports progress against it — not because a client asked, but because that is the job.
None of this means the help desk is the problem. Fast, competent day-to-day support is genuinely valuable and hard to do well. The distinction is whether it sits on top of real infrastructure ownership, or whether it is the entire relationship.
All technical perspectives