Frequently Asked Questions

Your questions about managed IT services for SMEs

27 clear answers on the topics that matter most to your business. Published by ECLAUD IT, created in 2021, with IT experience dating back to 2010.

27

Questions

6

Topics

2010

IT experience since

01

Managed IT

5 questions
What exactly is managed IT services?

Managed IT services means outsourcing the complete or partial management of your IT infrastructure to a specialist provider: hardware fleet maintenance, security, backups, user support and strategic advisory. It is the equivalent of an outsourced IT Director (CIO). Rather than hiring a full-time CIO (£70–120K/year), you gain access to a team of experts for a predictable monthly fee.

Full guide
What is the difference between managed services and IT maintenance?

IT maintenance generally addresses incidents and upkeep. Managed services may add monitoring, updates, security and advisory services, but assets, coverage windows, responsibilities and exclusions must be defined in the contract.

Full guide
How much do managed IT services cost for an SME?

Price depends on workstations, sites, infrastructure, support hours, monitoring, backup, security and on-site conditions. ECLAUD IT confirms inclusions, exclusions, setup costs, recurring charges and usage limits in a written proposal; no universal saving is claimed.

Full guide
From how many workstations does outsourcing IT make sense?

There is no universal workstation threshold. The decision depends on critical processes, internal skills, sites, support needs, security and regulatory obligations. Costs should be compared using the same documented scope and service levels.

Full guide
Does managed IT mean losing control of your IT systems?

No. You retain ownership of your data and should retain appropriate access credentials. A solid managed services contract defines reversibility, including the data, credentials and documentation to be transferred if you change provider. The ECLAUD IT proposal states the reporting format and governance arrangements for the selected scope.

Full guide
02

Cybersecurity

5 questions
How much does a cyberattack cost an SME?

Cyber-incident impact depends on downtime, restoration, legal obligations and customer effects. Estimate it from the organisation's own processes and verify current national statistics from authoritative sources rather than applying a universal cost or closure rate.

Full guide
Are SMEs really targeted by cyberattacks?

Yes, and increasingly so. 43% of cyberattacks target SMEs (ANSSI 2024). Hackers target them precisely because they are less protected than large corporations, yet hold exploitable data (customers, accounting records, intellectual property). 144 ransomware compromises were reported to ANSSI in 2024, the majority involving organisations with fewer than 250 employees.

Full guide
What should I do in the event of a ransomware attack on my business?

4 immediate actions: 1) Disconnect infected machines from the network (do not switch them off). 2) Notify your IT provider and report to the relevant cybercrime authority (cybermalveillance.gouv.fr in France). 3) Never pay the ransom — there is no guarantee of data recovery, and you are funding criminals. 4) File a police report. ANSSI recommends never negotiating directly. The best protection remains prevention: tested off-site backups and EDR on every workstation.

Full guide
What is the difference between an antivirus and an EDR?

A traditional antivirus detects known threats using signatures (a database of viruses). An EDR (Endpoint Detection & Response) analyses suspicious behaviour in real time using artificial intelligence. It can detect an unknown ransomware, automatically isolate a compromised workstation and enable post-incident investigation. In 2025, antivirus alone is no longer sufficient against current threats.

Full guide
Does the NIS2 directive apply to my SME?

The NIS2 directive (transposed into French law in October 2024) applies to companies with 50+ employees or €10M+ turnover in 18 sectors (healthcare, energy, transport, digital, food…). However, even if your SME is not directly in scope, your principal clients may require compliance from their subcontractors. Achieving compliance is an opportunity to structure your cybersecurity posture properly.

Full guide
03

Cloud & Microsoft 365

4 questions
Which Microsoft 365 licence should I choose for my SME?

Microsoft 365 plans differ by applications, storage, device management and security features. Check current Microsoft terms and pricing, then document the selected licence, billing responsibility and required configuration in the proposal.

Full guide
How long does a migration to Microsoft 365 take?

Duration depends on users, mailboxes, data, applications, identity design, change windows and acceptance tests. The project plan defines batches, testing, rollback and any training included in the agreed scope.

Full guide
Is my data safe in the Microsoft cloud?

Microsoft operates a shared-responsibility model. Current certifications, data location and service terms should be checked in official Microsoft documentation. Any ECLAUD IT backup, access, MFA or licensing responsibilities are those in the proposal; no CSP status is implied.

Full guide
What is the difference between SharePoint and OneDrive?

OneDrive is your personal storage space (like a hard drive in the cloud). SharePoint is the collaborative team storage space, with version management, granular permissions and workflows. In practice: your personal files go into OneDrive; shared files (projects, documentation, templates) go into SharePoint. Both sync to your workstation via the OneDrive app.

Full guide
04

Backup

4 questions
What is the 3-2-1 backup rule?

The 3-2-1 rule recommends keeping 3 copies of your data, on 2 different media (local disk + cloud, for example), with 1 copy stored off-site (remote datacentre). This is the minimum standard recommended by ANSSI. In 2025, the 3-2-1-1-0 rule is becoming the norm: add 1 immutable copy (unmodifiable, even by an administrator) and target 0 errors in restoration tests.

Full guide
What is the difference between a DRP and a BCP?

A DRP aims to restore operations after an incident, while a BCP plans how critical activities continue. RTO, RPO, architecture, cost and continuity targets depend on the organisation and become commitments only after sizing, testing and contractual confirmation.

Full guide
How often should backups be tested?

ANSSI recommends a restoration test at least once per quarter. 34% of companies never test their backups — and discover the problems when a disaster actually occurs. For an ECLAUD IT service, the restoration-test scope, frequency, evidence and comparison with the contractual RTO must be specified in the contract.

Full guide
What happens if ransomware encrypts my backups too?

This is the primary risk if your backups are on the same network as your workstations. The solution: immutable backups stored off-site. Veeam and Acronis offer air-gapped or immutable copies that even a compromised administrator cannot delete. The rule: if your backup is accessible from any workstation on the network, it is not secure.

Full guide
05

Support

4 questions
What are the response times for outsourced IT support?

Response objectives vary with incident priority, support hours, service area and selected plan. For ECLAUD IT, only the priorities, locations, escalation process, exclusions and targets written into the signed SLA apply.

Full guide
What is an SLA in IT and why does it matter?

An SLA (Service Level Agreement) is your provider's contractual commitment on measurable criteria: response time, resolution time, IT system availability, satisfaction rate. Without an SLA, you have no leverage if the provider fails to deliver. Always demand a written SLA with penalties for non-compliance — that is the difference between a partner and a repairman.

Full guide
Should I sign a maintenance contract or pay per incident?

The suitable billing model depends on incident frequency, required preventive work, response objectives and budget. Compare an ad hoc and recurring contract using the same scope, inclusions, exclusions and actual usage history.

Full guide
How does remote support work?

A technician may connect through an authorised remote-support tool after permission is granted. Whether the issue can be resolved remotely, and any on-site service area or response objective, depends on the incident and the signed support scope.

Full guide
06

ECLAUD IT

5 questions
What types of SMEs do you work with?

ECLAUD IT structures managed IT proposals for SMEs that need an external operating model. The relevant scope depends on the organisation's business software, data sensitivity, regulatory duties, internal skills and continuity requirements.

Full guide
Does ECLAUD IT only operate in Reunion Island?

ECLAUD IT is headquartered in Saint-Paul, Reunion Island. The proposal confirms the locations covered for on-site work and the conditions that apply to remote support, administration and monitoring.

Full guide
What is the difference between ECLAUD IT and a standard IT repair shop?

A repair shop focuses on individual incidents. An MSP can combine maintenance, monitoring, backups, cybersecurity and service governance within one documented scope. For ECLAUD IT, the monitored systems, contacts, responsibilities and escalation process are those stated in the contract.

Full guide
What does the first contact with ECLAUD IT look like?

The first conversation is used to understand the number of workstations and sites, servers, business software, current issues and regulatory constraints. If an audit is required, its scope, price and deliverables are confirmed before work begins. The proposal then defines the service scope and any transition plan.

Full guide
What happens if I want to change provider?

The contract must define reversibility: the data, credentials and technical documentation to be transferred, the applicable notice period, each party's responsibilities and any transition support. These terms are confirmed in writing for the selected ECLAUD IT scope.

Full guide

Didn't find your answer?

Every infrastructure is unique. Contact us to discuss your context and determine whether a scoped assessment is required.