Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

Is Your Current IT Company Proactive or Just Reactive? A Self-Test

Choosing an IT ProviderManaged IT
Last updated: August 12, 2026

Most small businesses can’t tell proactive IT support from reactive IT support until something breaks. This 12-point self-test scores your provider on monitoring, patch speed, backup testing, response time, and communication, so you know before it costs you money.

Score under five and you’re paying managed-services prices for glorified break-fix. Score nine or higher and your provider is actually doing the job. Everything in between is where most Rockland, Westchester, and Bergen businesses actually sit, and that gray zone is exactly what this test is built to expose.

A quick caveat before you start scoring anything. Every MSP in the Tri-State area, including mine, will tell you they’re proactive. Almost none of them mean the same thing by it. So instead of asking your provider to grade themselves, here’s a way to check whether the managed IT services you’re paying for actually get delivered, using twelve concrete behaviors instead of a sales pitch.

Business owner in a blazer holding a pen over a printed proactive vs reactive IT support self-test checklist at her desk

Why the Gap Actually Costs You Money

Ransomware showed up in 88% of confirmed small-business breaches in 2024, compared with 39% at large enterprises, according to the Verizon 2025 Data Breach Investigations Report SMB Snapshot. That’s backwards from what most owners assume. Bigger companies feel like the bigger target, or so the thinking goes, but attackers go where the defenses are thin. Thin defenses are a reactive-support problem. Not a company-size problem.

The 2026 edition of the same report found something worse. Median time to fully patch a known vulnerability stretched to 43 days in 2025, up from 32 days the year before, and organizations fully closed out only 26% of the vulnerabilities on CISA’s Known Exploited Vulnerabilities catalog, down from 38%, according to reporting on the report. Patching is getting slower. The window attackers need is getting shorter. Nobody’s catching up.

IT technician connecting a network patch cable inside an open server rack cabinet

Small organizations made up 96% of ransomware victims in that same DBIR dataset. Unpatched edge devices played a role in 29% of those cases, and 69% of the small businesses that got hit avoided paying a ransom because they had backups they could actually restore from, according to the Cyber Readiness Institute’s summary of the report. Notice what’s doing the work in that last number. Not luck. A tested backup.

The Uptime Institute’s 2026 Annual Outage Analysis surveyed data center operators, not small businesses, so treat this next part as scale, not a direct comparison. In the same report, human error factored into 92% of respondents’ worst outage of the year, at least a little. Eighty-seven percent said it could have been avoided with better process or monitoring. Better process. Better monitoring. Nothing exotic. If professionally staffed data centers with dedicated operations teams say most of their worst outages were preventable, a 30-person accounting firm running on a break-fix contract has far less margin for the same mistake. Far less, really.

What Actually Separates Proactive From Reactive Support

Reactive IT support waits for something to break, fixes it, and bills you for the visit. Proactive support catches the failure before it happens through constant monitoring, scheduled patching, and tested backups, then reviews your systems with you on a regular cadence so small issues get resolved before they turn into outages.

That’s the textbook version. In practice the difference shows up in specific, checkable behaviors, not whatever a provider’s marketing page claims. Twelve of those behaviors are below.

The 12-Point Self-Test

Score yourself one point for every statement that’s true of your current provider right now. Not what got promised in the sales meeting. Not what the contract says on paper.

#True for your provider right now? (1 point each)
1Someone, or something automated, is watching your network right now, this minute, not just when you call in a problem.
2Patches and updates go out on a schedule, set in advance. Nobody’s waiting for “a good time” that never actually arrives.
3Your backups get test-restored on a real, recurring basis, not just backed up once and left alone.
4A person responds to a support request inside a defined time window every single time, not “when we get to it.”
5Your monthly IT bill is the same number every month. No surprise line items show up after an incident.
6You’ve sat down with your provider for an actual strategic review in the last six months, not just a renewal email.
7Someone can tell you, without three days of digging around, exactly what hardware and software are running on your network today.
8Multi-factor authentication is enforced across your accounts. Not recommended. Enforced.
9You’ve been warned about a security risk before it turned into an incident, at least once, in the last year.
10There’s a written plan for what happens if ransomware hits your systems tonight, and you have actually seen it.
11When a problem gets fixed, it stays fixed. The same ticket doesn’t reopen three weeks later under a different number.
12Whoever answers the phone already knows your setup. You’re not re-explaining your network from scratch on every single call.

Add up your points out of 12.

What Your Score Actually Means

  • 0 to 4: You’re running break-fix with a monthly retainer bolted on top of it. The contract might say managed services. The behavior says something else. Thin defenses. Slow patching. No real monitoring loop worth mentioning. That’s the profile the Verizon data above describes best, and it’s the one most likely to turn one bad email into a six-figure problem.
  • 5 to 8: This is the middle, and it’s where most businesses in the 5 to 60 employee range actually land. Monitoring might exist without a real patch cadence behind it. Backups might get run without ever getting test-restored. Partial proactive coverage still leaves real gaps, and gaps are exactly what attackers and bad luck both find eventually.
  • 9 to 12: Your provider is doing the job the contract implies. Good. Keep asking the same twelve questions anyway, every six months or so. A good score today doesn’t lock in a good score next year, especially once a provider grows fast and stops matching headcount to how many clients they’ve taken on.

What Proactive Actually Looks Like Day to Day

I can only speak to how my team runs it at VJNetworks, so take this section as one working example, not the universal standard. Someone from my team responds within 15 minutes of a ticket coming in. Every time. The alternative is a client sitting on a broken system wondering if anyone noticed yet. My team has held a 97% client retention rate over 20 years serving businesses across the Tri-State area, most of them in the same 5 to 60 employee range this self-test was built for.

Business owner and IT services consultant discussing a strategic IT review across a conference table

None of that is luck. It’s process, repeated on a schedule, the kind behind “Big enough to manage your IT. Small enough to care.” Monitoring catches an issue before a user notices it. Patches go out during the scheduled window, not a slow week. Backups get tested. Not assumed. That’s the whole difference this self-test measures, just applied consistently instead of promised once during a sales call.

A tighter cybersecurity program is usually the first place the twelve-point gap shows up, mostly around items eight and nine on the list above, enforced multi-factor authentication and advance warning on risk. If your provider can’t speak specifically to either one, ask directly. Don’t assume it’s handled.

If your test above landed in the 0 to 4 range, or even solidly in the middle, it’s worth reading about the billing surprises and undocumented systems that push most Tri-State businesses toward switching providers in the first place. It’s rarely one dramatic failure. It’s usually this same slow accumulation of missed items. If you’re already fairly sure your score is low, 5 signs you need a new IT company is a reasonable next read before you start taking meetings with anyone new.

What Owners Ask After They See Their Score

Is proactive IT support actually more expensive than break-fix billing?
$995 a month is where our proactive plans start for a typical 5 to 60 employee client. That number looks bigger than an occasional break-fix invoice, until you count what break-fix actually costs across a full year: emergency callouts, repeat visits for the same unresolved issue, and the hours your own staff loses waiting around for a fix. Flat and predictable usually wins once you actually run that math.
What if my score comes out somewhere in the middle, not clearly one or the other?
That’s actually the most common result, not an edge case. A mixed score usually means one piece of the proactive stack is real, monitoring, say, and another piece is missing entirely, like tested backups. Ask your provider directly which of the twelve items they’d score themselves on. Watch how fast they answer that question.
Can a reactive provider turn proactive without me switching companies?
Wrong question, a little. The real question is different. Are they willing to be measured on it? Some providers genuinely will build out monitoring and a patch schedule if you ask directly and set a deadline. Others have been saying “we’re working on that” for two years running. The self-test above is a good way to tell which kind you actually have before you commit to another contract term.
How often should I actually redo this self-test?
Twice a year is enough for most small businesses. Redo it sooner if you’ve had a security incident, a bad outage, or a provider that’s grown quickly and seems to be spreading thinner across more clients. Scores drift over time. A provider that scored 10 out of 12 two years ago can quietly slide to 6 without anyone ever announcing it.
Does a high score mean my business isn’t at risk anymore?
No, and that distinction matters. A 9 to 12 score means your provider is doing the structural work that lowers your risk substantially. It doesn’t mean risk hits zero. Verizon’s own data shows ransomware and vulnerability exploitation both keep climbing across the board, so proactive support narrows the odds. It doesn’t eliminate them.
Where did your score land?

A Free IT Assessment gives you an outside, provider-agnostic read on where your current setup actually falls on this scale, no obligation, no sales pressure attached.

Get Your Free IT Assessment →

Or call (845) 440-5000