What Are Managed Services? What Does an MSP Do?
Managed services hand the operation of infrastructure and systems to a provider under contract. What an MSP does, the models, and what to check in an SLA.

Short answer: Managed services means handing the operation of an organization's technology infrastructure or systems to a provider under contract. The company doing this work is called a managed service provider, or MSP. The provider monitors the systems continuously, maintains them and responds to failures; what gets done and how fast is written into the service level agreement (SLA). What transfers is the operation; accountability to the regulator stays with the organization.
What are managed services?
Managed services are easiest to understand next to the alternative. In the classic model ("call us when it breaks"), someone is called in when a problem appears and the work is billed by the hour or per call. Nobody watches the systems when nothing is broken; nobody warns you that a disk is about to fill up or notices the server whose patches are overdue.
With managed services, the relationship is continuous:
- Proactive operations: Systems are monitored 24/7; a disk approaching its threshold, a certificate about to expire or a server behind on patches is dealt with before it turns into a failure.
- Defined scope: Which systems, which tasks and which hours the service covers is written into the contract.
- Measured service level: Targets for availability, response time and resolution time are set and reported every month.
- Predictable cost: The fee depends on scope, not on the number of calls. The provider earns when failures don't happen, not when they do, so the incentive points the right way.
What does an MSP do?
The work a managed service provider takes on usually falls under these headings:
- Infrastructure management: Day-to-day operation of physical and virtual servers, network devices and storage systems (infrastructure management).
- Managed cloud: Monitoring, patching, backing up and tracking the cost of cloud resources (managed cloud services). We explain the difference in our IaaS article.
- Backup and disaster recovery: Taking backups, testing that they restore and rehearsing the disaster scenario (backup and recovery).
- Monitoring and incident response: 24/7 monitoring, first response to alerts and escalation (24/7 monitoring).
- Security operations: Patch management, log monitoring and response to security incidents (security operations).
- Database and platform operations: Running databases and enterprise platforms as a service (managed platform services).
- End-user support: Help with employees' device and application problems (end-user support).
There is no need to buy all of this from one provider. Starting with a single layer (backup or monitoring, for example) and widening the scope as trust builds is also an option.
Managed service models
- Full handover: Operation of the defined area moves entirely to the provider; inside the organization, only a counterpart who tracks the contract and the service level remains.
- Co-managed: Routine operations sit with the provider, while architecture decisions and work close to the business stay with the internal team. In the organizations we work with, this is the most common arrangement; the internal team does not disappear, it gets out of night shifts and repetitive work.
- Layer-based: Only a specific layer is handed over: for example, only backup and disaster recovery, or only 24/7 monitoring and first response.
Why do organizations use managed services?
The first reason is how hard it is to find skilled people. In ISC2's 2025 Cybersecurity Workforce Study, 95% of respondents said their team has at least one skills need, and 59% reported critical or significant skills needs, up from 44% a year earlier. The picture on the infrastructure side is similar: in Uptime Institute's 2026 data center survey, more than half of operators said they struggle to find qualified candidates.
The second reason is the math of 24/7 operations. A year has 8,760 hours; after leave, public holidays and training, one person works roughly 1,800 hours a year. Keeping a single on-call seat filled all year therefore takes about five people, and that covers only the first response layer; we show the calculation in detail in our SIEM and SOC article. Building that headcount across several areas of expertise is not economical for most organizations.
The third reason is focus. Infrastructure running smoothly is critical for every organization, but for most it is not the core business. When routine operations move to a provider, the internal team can spend its time on projects that affect the business directly.
What to check in an SLA
The service level agreement is the heart of a managed services contract. When comparing offers, look at the answers to these questions before the price:
- What does it measure? For which system is availability measured, and from which point? Are response time and resolution time defined separately?
- Who measures it, and how is it reported? Do you have access to the measurement data too, and does the report put results next to targets every month?
- Who is on call at night? Is the 24/7 rotation staffed by the provider's own team, or handed to a subcontractor?
- What happens if you want to leave? Are the inventory, runbooks, access details and handover period written into the contract?
You can find a detailed list of these questions in our article on 10 questions to ask when choosing an MSP, and what companies in Türkiye actually look for in a provider in our MSP selection article.
Who is accountable in regulated organizations?
Handing over operations does not mean handing over obligations. For banks, BDDK regulation keeps responsibility with the bank when it buys cloud or outsourced services; in an outage or a breach, the regulator deals with the bank, not the provider (our BDDK article). For organizations covered by Cyber Security Law No. 7545, obligations such as incident reporting also stay with the organization itself (our Cyber Security Law article). That is why the contract should spell out the records, reports and notification times the organization needs to meet its own obligations.
We do this work as a managed service provider headquartered in Türkiye, and in 2026 we ranked first in the Türkiye-based Managed Services category of the Bilişim 500 survey. You can see the full scope on our managed services page.
Frequently asked questions
What does managed services mean? Handing the operation of technology infrastructure and systems to a provider, with the scope and service level defined in a contract.
What does MSP mean? Managed service provider: a company that runs organizations' infrastructure and systems under contract.
Are managed services the same as outsourcing? Managed services are a kind of outsourcing, but narrower and measurable. Classic outsourcing models often supply staff or labor; with managed services you buy an outcome: a defined scope run at a measured service level.
Do managed services replace the internal team? Usually not. In the most common arrangement we see, routine operations and on-call duty move to the provider, and the internal team focuses on architecture decisions and projects close to the business. Full handover is possible too, but it should be a deliberate decision.
How is the fee for managed services set? Mostly by scope: the number and type of systems managed, service hours (business hours or 24/7), the target service level and the tasks included. That is why you should make sure two offers for the same systems cover the same scope before comparing them.
Sources
- ISC2, 2025 Cybersecurity Workforce Study: skills gaps in security teams (December 4, 2025)
- Uptime Institute, 2026 Global Data Center Survey: staffing difficulties among data center operators (July 2026)
- How we build this layer: infrastructure management