"24/7 support" appears on almost every managed IT provider's website, and it describes at least three genuinely different products. The gap between them only becomes apparent at two in the morning, which is a poor time to discover it.
Here is what the phrase can mean, and how to establish which version you are buying.
The three models
24/7 monitoring
Automated systems watch your infrastructure continuously and generate alerts. Whether anyone acts on an alert at 3am is a separate question entirely.
This is the weakest version, and the most commonly advertised. It is genuinely useful — alerts create a record and often trigger automated remediation — but it is not support. If a server fails overnight under monitoring-only coverage, the alert waits in a queue until morning.
On-call rotation
An engineer carries a phone outside business hours. Real humans, real response, and the standard model for small and mid-sized providers.
The honest limitations: it is one person rather than a team, they were probably asleep, and they may be handling another client. Response is typically 30 to 60 minutes rather than immediate, and complex incidents needing several people wait for daylight. Ask how many engineers are in the rotation — if it is one or two, holiday and illness create genuine gaps.
Staffed 24/7
People working overnight shifts, awake and at desks. Immediate response at any hour, and the only model that genuinely delivers what the phrase implies.
It is also expensive, which is why it is generally found at larger providers, at providers using follow-the-sun coverage across time zones, or via a subcontracted overnight desk. That last arrangement is common and perfectly legitimate — but worth knowing about, because the overnight team will not know your environment the way your daytime engineers do.
What is usually covered outside hours
Even under genuine 24/7 arrangements, overnight coverage is normally restricted to incidents rather than requests. Expect:
- Covered: server and infrastructure outages, network failure, security incidents, business-wide email failure, anything blocking the whole organisation
- Not covered: password resets, new user setup, software installation, individual issues with a workaround, project work
This is reasonable — it reflects what genuinely cannot wait. But it means the definition of an emergency matters, and you should know who decides. Some providers let you declare an emergency and charge if it turns out not to be one; others triage first.
The billing question
Establish clearly whether after-hours support is included in the monthly fee or billed separately. Three common structures:
- Fully included, at any hour. Simplest, usually reflected in a higher monthly figure.
- Included for critical incidents, billed for anything else.
- Billed at a premium rate for all after-hours work, often 1.5 to 2 times standard.
None is wrong, but the third creates a hesitation you should be aware of — staff who know an after-hours call is expensive will sometimes wait until morning on something that should not have waited. If your business genuinely needs overnight coverage, an included arrangement removes that judgment call from people not well placed to make it.
Questions worth asking
- Is your overnight coverage monitored, on-call, or staffed?
- If on-call, how many engineers are in the rotation?
- Is overnight support delivered by your own team or subcontracted?
- What is the committed response time at 2am on a Sunday, and does the SLA clock run then?
- What qualifies as an emergency, and who decides?
- Is after-hours work included or billed, and at what rate?
- Can the overnight team actually resolve issues, or only triage and escalate?
That last question separates real coverage from an answering service. A team that can only take details and wake someone else has value, but it is not the same as a team that can fix your problem at 3am.
Do you actually need it?
Worth asking honestly, because it is not free. Genuine 24/7 matters if you operate outside standard hours, run shifts, serve clients in other time zones, depend on overnight processing, or carry obligations where an outage has regulatory consequences.
For a business operating standard hours in a single time zone, on-call coverage for genuine emergencies is usually sufficient, and the money saved is better spent on the controls that reduce the chance of a 3am incident in the first place — monitoring, patching, tested backups and resilient infrastructure.