The Honest Truth About MSPs: What Reddit Gets Right and What It Gets Wrong

Table of Contents

A post on r/sysadmin titled “MSPs: The Snake Oil of the IT Industry” got 604 upvotes. It accused managed service providers of doing the bare minimum for clients, lying about proactive monitoring, exposing client networks to the internet, and building a business model designed to undermine the businesses they serve. We decided to share the honest truth about MSPs from our own perspective.

The comments tore it apart. The top reply got more upvotes than the original post.

We read the whole thread. In our opinion, much of it is accurate. Some of it is the frustration of someone who worked at bad companies and assumed that made them all bad. This post goes through the specific criticisms, calls out the ones that are real (in our opinion), and explains where the argument falls apart at times.

What Reddit Gets Right

“The same 2 or 3 competent people carry the whole team”

This one is accurate more often than MSPs would like to admit. The original post described working as one of three engineers propping up a staff of 25. Several commenters backed it up from their own experience.

The root cause, as one commenter put it, is the race to the bottom on pricing. When a business buys IT support at the cheapest possible rate, the provider has to cut costs somewhere. That usually means low wages, high turnover, and a small core of competent technicians buried under too many clients and too many tickets. Those techs are also invariably offshore especially if the MSP has been bought out by a much larger firm.

The honest answer is that technician-to-client ratio matters, and most MSPs don’t publish it. When evaluating a provider, ask directly: how many clients does each technician support? How many active tickets does a typical engineer carry at once? If they won’t answer or the numbers are vague, that tells you something.

“Proactive monitoring is often a lie”

The original poster described alerts piling up until something breaks, then the MSP scrambling to fix it and calling it proactive. This happens at providers who install monitoring tools and then don’t staff the response side.

True proactive monitoring means alerts get reviewed and acted on before they cause downtime, not after. It requires people on the other end of those alerts with the time and authority to act. A monitoring dashboard with no one watching it is just a more expensive version of finding out the hard way.

If your current provider can’t show you a record of issues caught and resolved before they affected your team, ask for it. If it doesn’t exist, the monitoring is mostly for show.

“Their cybersecurity pitch is often surface level”

The post described MSPs installing an EDR agent and telling clients they’ve built Fort Knox. This is a real pattern. Basic endpoint detection is a starting point, not a security program. A genuine security posture includes MFA enforcement, email filtering, patch management, network monitoring, documented incident response procedures, and backup verification. None of those are covered by a single tool.

The insurer version of this is increasingly visible. Businesses renewing cyber insurance are discovering that their MSP’s “security stack” doesn’t satisfy underwriter requirements because it was never built with those requirements in mind.

Where the Argument Falls Apart When Talking About The Honest Truth About MSPs

“Build your own internal IT team, you can afford it”

The original post’s conclusion was that businesses of any size should hire internal IT instead of using an MSP. The thread destroyed this argument within minutes.

The most upvoted reply: “What are small businesses supposed to replace MSPs with exactly? Your average 5-seat accountant certainly can’t hire a part-time or full-time tech.”

This is the correct objection. A Toronto business with 15 to 30 employees cannot justify a full-time IT hire. The salary alone for a level 2 IT technician in Toronto runs $70,000 to $80,000 before benefits, vacation, training, and overhead. That gets you one person, with one skill set, working business hours only, with no coverage when they’re sick or on vacation. You also get a single point of failure. If that person leaves, your IT knowledge walks out the door with them. 

Now that is a Level 2 Help desk technician that can handle your general laptop issues and basic networking problems. That is not someone experienced or certified in cybersecurity, managing your backup, creating automation and AI routines.   So for a properly setup IT shop you want a $75,000 L2 Support person and a Senior IT Manager with cybersecurity certifications at around $110,000 plus benefits and bonus. Don’t forget the tools, licensing and cloud servers to manage it all.

A managed IT engagement for the same company costs a fraction of that and gives you access to specialists across networking, security, cloud, and compliance. The math simply doesn’t support internal IT until you’re past roughly 100 employees.

For more, see what managed IT actually costs compared to hiring in-house. 

“I never met a business owner happy with their MSP”

Several commenters pushed back on this directly. One had clients who had been with their MSP for over 30 years. Another noted that unhappy clients switch providers, and many don’t. The sample was one person’s experience at a handful of companies, not a representative picture of the industry.

The more accurate version is that satisfaction varies dramatically by provider quality, client expectations, and pricing. A business paying $60 per user per month is buying a different level of service than one paying $150. The dissatisfaction that exists is often downstream of a pricing decision, not proof that the model is broken.

“Co-managed IT is a Trojan horse to gut internal teams”

Co-managed IT done badly can look like this. Done honestly, it’s the opposite. The best co-managed relationships happen when an internal IT person handles day-to-day user support and the MSP provides infrastructure management, security, after-hours coverage, and specialist work that one generalist can’t reasonably own.

Multiple commenters in the thread said exactly this. One IT manager described their MSP as “still our supplemental support” years after leaving them, because there are things you genuinely need a specialist vendor for. Another said their internal IT person was “our man on the inside” and made the MSP relationship work better, not worse.

What the Thread Actually Tells You About Choosing a Provider

The real signal from the thread is not “MSPs are bad.” It’s that bad MSPs exist, they’re common enough to generate genuine anger, and the warning signs are specific and recognizable.

The businesses that get burned tend to share a pattern. They chose on price. They didn’t ask hard questions before signing. They had no way to verify what was actually being done each month. And by the time the problems became visible, they were deep in a contract with a provider who had no real accountability structure.

The businesses that are satisfied tend to share a different pattern. They found a smaller, owner-operated provider rather than a large one. They asked specific questions about technician ratios, security practices, and reporting before signing. They pay a fair rate and get genuine coverage in return.

One commenter put it simply: “MSPs are worth it at their sweet spot when you find a smaller, boutique one that is highly selective about clients and employees and doesn’t have ‘we can be the next Accenture’ ambitions. Otherwise it just devolves.”

That’s an accurate description of where the model works.

selective focus of sticky notes with question marks on laptop with blank screen near notebook, questions to ask for the honest truth about MSPs

The Questions Worth Asking Before You Sign

If you’re evaluating a managed IT provider in Toronto, the Reddit thread effectively handed you a checklist. These are the questions that separate providers worth working with from those you’ll regret.

For a more complete list of questions see our post: How to Choose a Managed Service Provider (MSP)

How many clients does each technician support?

There’s no universal right number, but if a tech is responsible for more than 20 distinct environments, surface-level attention is the realistic outcome.

Where is your support staff based?

A technician who knows your environment, is in your time zone, and speaks your language resolves issues faster and with less friction.

What does your security stack actually include?

Ask them to list every tool and what it does. Basic antivirus and an EDR agent are different things. If they can’t explain the difference clearly, they can’t explain it to an insurer either.

Can you show me a record of issues caught before they caused downtime?

Any provider claiming to be proactive should be able to produce examples. If there are none, the monitoring is decorative.

What does your monthly report include?

This is the accountability question. A provider who reports clearly on what was done, what was found, and what needs attention has nothing to hide. One who can’t answer this has no accountability mechanism.

What happens to our documentation if we leave?

Your environment configuration, passwords, and network diagrams should be yours. Some providers treat documentation as leverage. Ask explicitly how it’s stored and what happens to it if the relationship ends.

How long do your clients stay with you and can we talk to some of your long term clients?

A good MSP with lots of industry experience should have clients that have been with them 5 to 10 years or more.

See: How managed IT compares to break-fix on total cost 

The Bottom Line When It Comes To The Honest Truth About MSPs

The Reddit post got some things right. Technician overload is real. Fake proactive monitoring exists. Surface-level security sold as a full program happens. These are legitimate criticisms of bad providers, and they’re worth taking seriously when you’re evaluating who to trust with your IT environment.

But the conclusion that businesses should abandon the MSP model entirely doesn’t hold up. For a Toronto business with fewer than 100 employees, the economics of internal IT don’t work. The alternative to a bad MSP is not internal IT. It’s a better MSP.

The difference between a good one and a bad one isn’t hard to identify if you ask the right questions before you sign anything. See what to expect from a well-run managed IT service.

If you want to see how Xoomler approaches the things this thread called out specifically, the managed IT services page covers our service structure, and a free IT assessment is available for businesses that want a straight read on their current environment before making any decision.