The phone goes off at 2:14 in the morning. Not a ring, a specific tone that only means one thing, and the person on call is awake before they are conscious, reaching for a laptop that lives on the nightstand for exactly this reason. The screen says a backup job on a server in an office twenty minutes up the road has failed twice in a row. The building is empty. Nobody there will know anything happened.

Most of what a managed service provider does is invisible by design, which makes it hard to evaluate and easy to undersell. A managed service provider, or MSP, is a company you pay a flat monthly rate to run your technology instead of calling somebody when it breaks. So we are pulling the curtain back. This is the first in an ongoing series about how the work actually looks from the inside, including the parts less impressive than the marketing suggests. If you are paying a monthly fee, you deserve to know what happens between the invoices.

The Dashboard, and What It Is Actually Telling Us

There is a screen. It is less exciting than television has led everyone to believe. No world map, no glowing red arcs. It is a list, and the list is mostly green.

The software behind it is called remote monitoring and management, or RMM, which means an agent, a small program, installed on every computer and server we look after, quietly reporting its condition back to one place. Here is what actually lives on that list on a normal morning.

  • Disks that are filling up. The single most common cause of a server failing at an inconvenient hour is a hard drive that quietly ran out of room. Catching it at eighty percent full is a five minute task. Catching it at one hundred percent is a bad afternoon for everybody in the building.
  • Backups that did not finish. A backup job that ran but did not complete is worse than one that obviously failed, because it looks fine in a summary email. This is the line we check first, every day.
  • Machines that have gone quiet. A computer that stopped checking in is either turned off, taken home, or genuinely broken, and the only way to know is to ask a human. A surprising amount of this job is figuring out where a laptop went.
  • Updates that failed to install. Not the ones that installed. The ones that tried and did not. Those machines are the actual work.
  • Security software that is not reporting. Protection that is installed but silent is the same as protection that is not installed, and it happens more often than anyone would like.

Patch Night

Microsoft’s own documentation confirms that its monthly security updates publish on the second Tuesday of each month, a rhythm the industry calls Patch Tuesday. A patch is a small fix from a software company that closes a hole or repairs a defect. The updates come out Tuesday. Most of the actual work happens Wednesday and Thursday night, after everyone has gone home.

The honest version of patch night is that it is deeply boring for long stretches and then briefly stressful. It goes roughly like this.

  1. Read what is actually in the batch first. Some months are routine. Some contain a fix for something criminals are already exploiting, which changes the urgency. The Cybersecurity and Infrastructure Security Agency, the federal agency known as CISA, maintains a public catalog of flaws under active exploitation, and it is a good tiebreaker when deciding what cannot wait.
  2. Send it to a small group first. Nobody sane pushes a batch of updates to every machine in every client at once. A handful of machines get it first, then a wider group, then everything. If an update is going to break something, we want it to break on five computers, not five hundred.
  3. Servers get scheduled, not surprised. Servers reboot on a window agreed with the client in advance, and somebody watches them come back up. Watching a server reboot is the least glamorous ninety seconds in this profession, and also the moment you find out whether tomorrow is normal.
  4. Then comes the cleanup, which is the real job. A percentage of machines always fail to update. Somebody left a laptop off, an update conflicted with a piece of industry software, a machine is too full to install anything. Chasing that remainder is unglamorous and it is exactly the thing that separates a maintained network from one that just has maintenance software installed on it.

The 2am Alert

Back to the phone. Here is the part worth being honest about: most middle of the night alerts turn out to be nothing serious. A backup that failed because a machine was rebooted mid job. A monitoring agent that lost its connection for four minutes. An internet provider doing maintenance nobody announced.

That is not a failure of the system. That is the system working the way it is supposed to. The whole point of getting woken up is that you cannot tell which alerts are nothing until you look at them, and the ones that are something are catastrophic if they sit until morning. The industry has a name for what goes wrong when this is handled badly, and it is worth knowing as a buyer.

  • Alert fatigue is the real enemy. When monitoring is configured lazily, it produces so many meaningless notifications that people stop reading them. The failure mode is not missing an alert. It is receiving four hundred alerts, all of which are ignored, and one of which mattered. Good monitoring is defined by what it stays quiet about.
  • The right question to ask a provider is about tuning, not coverage. Everybody monitors everything now, because the software makes it easy. Ask instead how many alerts a night your account generates and what they did last month to reduce that number. That answer tells you whether a human is paying attention.
  • The genuinely bad calls are quiet ones. A ransomware event or a compromised account rarely announces itself dramatically. It shows up as an odd pattern, a login from somewhere strange, a wave of file changes at an hour when nobody is working. Those are the alerts that justify the other ninety nine.

The Parts That Do Not Make the Brochure

Since we said honest, here is honest. A large share of this work is documentation, which nobody enjoys and everybody needs, because the value of knowing which closet the switch is in only shows up on the worst day. Another large share is asking people the same questions repeatedly and being cheerful about it. A meaningful amount is admitting we were wrong about something at 4pm that we were confident about at 10am.

And the best days are the ones where absolutely nothing happens, which is a strange thing to build a business around. When we are doing this well, your experience is that technology is boring. Boring is the product.

The Bottom Line

If you are paying for managed technology and you have never seen the dashboard, ask to see it. Ask what your alert volume looks like. Ask what percentage of your machines actually completed last month’s updates. A good provider will show you without hesitating, because the numbers are the work.

Future installments in this series will cover what onboarding a new client actually involves, how tickets get prioritized when everything is urgent, and what happens on the day a business decides to switch providers. In the meantime, if you want somebody to walk through your current setup and tell you plainly what is being watched and what is not, we do that for businesses across Denton County, from Lewisville to Frisco. Reach us at https://harrisonward.com/contact/.


Sources

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).