Most small businesses can’t tell proactive IT support from reactive IT support until something breaks. This 12-point self-test scores your provider on monitoring, patch speed, backup testing, response time, and communication, so you know before it costs you money.
Score under five and you’re paying managed-services prices for glorified break-fix. Score nine or higher and your provider is actually doing the job. Everything in between is where most Rockland, Westchester, and Bergen businesses actually sit, and that gray zone is exactly what this test is built to expose.
A quick caveat before you start scoring anything. Every MSP in the Tri-State area, including mine, will tell you they’re proactive. Almost none of them mean the same thing by it. So instead of asking your provider to grade themselves, here’s a way to check whether the managed IT services you’re paying for actually get delivered, using twelve concrete behaviors instead of a sales pitch.

Why the Gap Actually Costs You Money
Ransomware showed up in 88% of confirmed small-business breaches in 2024, compared with 39% at large enterprises, according to the Verizon 2025 Data Breach Investigations Report SMB Snapshot. That’s backwards from what most owners assume. Bigger companies feel like the bigger target, or so the thinking goes, but attackers go where the defenses are thin. Thin defenses are a reactive-support problem. Not a company-size problem.
The 2026 edition of the same report found something worse. Median time to fully patch a known vulnerability stretched to 43 days in 2025, up from 32 days the year before, and organizations fully closed out only 26% of the vulnerabilities on CISA’s Known Exploited Vulnerabilities catalog, down from 38%, according to reporting on the report. Patching is getting slower. The window attackers need is getting shorter. Nobody’s catching up.

Small organizations made up 96% of ransomware victims in that same DBIR dataset. Unpatched edge devices played a role in 29% of those cases, and 69% of the small businesses that got hit avoided paying a ransom because they had backups they could actually restore from, according to the Cyber Readiness Institute’s summary of the report. Notice what’s doing the work in that last number. Not luck. A tested backup.
The Uptime Institute’s 2026 Annual Outage Analysis surveyed data center operators, not small businesses, so treat this next part as scale, not a direct comparison. In the same report, human error factored into 92% of respondents’ worst outage of the year, at least a little. Eighty-seven percent said it could have been avoided with better process or monitoring. Better process. Better monitoring. Nothing exotic. If professionally staffed data centers with dedicated operations teams say most of their worst outages were preventable, a 30-person accounting firm running on a break-fix contract has far less margin for the same mistake. Far less, really.
What Actually Separates Proactive From Reactive Support
Reactive IT support waits for something to break, fixes it, and bills you for the visit. Proactive support catches the failure before it happens through constant monitoring, scheduled patching, and tested backups, then reviews your systems with you on a regular cadence so small issues get resolved before they turn into outages.
That’s the textbook version. In practice the difference shows up in specific, checkable behaviors, not whatever a provider’s marketing page claims. Twelve of those behaviors are below.
The 12-Point Self-Test
Score yourself one point for every statement that’s true of your current provider right now. Not what got promised in the sales meeting. Not what the contract says on paper.
| # | True for your provider right now? (1 point each) |
|---|---|
| 1 | Someone, or something automated, is watching your network right now, this minute, not just when you call in a problem. |
| 2 | Patches and updates go out on a schedule, set in advance. Nobody’s waiting for “a good time” that never actually arrives. |
| 3 | Your backups get test-restored on a real, recurring basis, not just backed up once and left alone. |
| 4 | A person responds to a support request inside a defined time window every single time, not “when we get to it.” |
| 5 | Your monthly IT bill is the same number every month. No surprise line items show up after an incident. |
| 6 | You’ve sat down with your provider for an actual strategic review in the last six months, not just a renewal email. |
| 7 | Someone can tell you, without three days of digging around, exactly what hardware and software are running on your network today. |
| 8 | Multi-factor authentication is enforced across your accounts. Not recommended. Enforced. |
| 9 | You’ve been warned about a security risk before it turned into an incident, at least once, in the last year. |
| 10 | There’s a written plan for what happens if ransomware hits your systems tonight, and you have actually seen it. |
| 11 | When a problem gets fixed, it stays fixed. The same ticket doesn’t reopen three weeks later under a different number. |
| 12 | Whoever answers the phone already knows your setup. You’re not re-explaining your network from scratch on every single call. |
Add up your points out of 12.
What Your Score Actually Means
- 0 to 4: You’re running break-fix with a monthly retainer bolted on top of it. The contract might say managed services. The behavior says something else. Thin defenses. Slow patching. No real monitoring loop worth mentioning. That’s the profile the Verizon data above describes best, and it’s the one most likely to turn one bad email into a six-figure problem.
- 5 to 8: This is the middle, and it’s where most businesses in the 5 to 60 employee range actually land. Monitoring might exist without a real patch cadence behind it. Backups might get run without ever getting test-restored. Partial proactive coverage still leaves real gaps, and gaps are exactly what attackers and bad luck both find eventually.
- 9 to 12: Your provider is doing the job the contract implies. Good. Keep asking the same twelve questions anyway, every six months or so. A good score today doesn’t lock in a good score next year, especially once a provider grows fast and stops matching headcount to how many clients they’ve taken on.
What Proactive Actually Looks Like Day to Day
I can only speak to how my team runs it at VJNetworks, so take this section as one working example, not the universal standard. Someone from my team responds within 15 minutes of a ticket coming in. Every time. The alternative is a client sitting on a broken system wondering if anyone noticed yet. My team has held a 97% client retention rate over 20 years serving businesses across the Tri-State area, most of them in the same 5 to 60 employee range this self-test was built for.

None of that is luck. It’s process, repeated on a schedule, the kind behind “Big enough to manage your IT. Small enough to care.” Monitoring catches an issue before a user notices it. Patches go out during the scheduled window, not a slow week. Backups get tested. Not assumed. That’s the whole difference this self-test measures, just applied consistently instead of promised once during a sales call.
A tighter cybersecurity program is usually the first place the twelve-point gap shows up, mostly around items eight and nine on the list above, enforced multi-factor authentication and advance warning on risk. If your provider can’t speak specifically to either one, ask directly. Don’t assume it’s handled.
If your test above landed in the 0 to 4 range, or even solidly in the middle, it’s worth reading about the billing surprises and undocumented systems that push most Tri-State businesses toward switching providers in the first place. It’s rarely one dramatic failure. It’s usually this same slow accumulation of missed items. If you’re already fairly sure your score is low, 5 signs you need a new IT company is a reasonable next read before you start taking meetings with anyone new.
What Owners Ask After They See Their Score
Is proactive IT support actually more expensive than break-fix billing?
What if my score comes out somewhere in the middle, not clearly one or the other?
Can a reactive provider turn proactive without me switching companies?
How often should I actually redo this self-test?
Does a high score mean my business isn’t at risk anymore?
A Free IT Assessment gives you an outside, provider-agnostic read on where your current setup actually falls on this scale, no obligation, no sales pressure attached.
