What does an IT guy actually do for a small business?
About half the work is visible: fixing what broke, setting up new people, answering questions. The other half you never see. Every month I patch computers and servers, verify that backups actually restore, review who has access, check antivirus and email security, watch the firewall and network, and keep documentation current. Skip the invisible half and the visible half gets much busier.
Answered by Anthony Omini, Cross River Tech, Dallas

Key takeaways
- Roughly half of IT work is reactive support you see, and half is maintenance you never notice until it stops happening.
- The monthly minimum is patching, backup restore testing, security review, account clean-up and documentation updates.
- Quarterly work covers access reviews, firewall firmware, license reconciliation and reviewing what broke most often.
- Annual work is a hardware replacement plan, a full restore test, contract renewals and a look at next year.
- If your provider only appears when something is broken, you are buying repairs, not IT support.
What does an IT guy actually do for a small business?
Two jobs at once. The first is reactive: something broke, someone calls, it gets fixed. The second is preventive: keeping computers patched, backups verified, accounts tidy, security current and the network healthy so that the first job stays small. Most business owners only ever see the first one, judge the value of IT support by how often they call, and quietly conclude that a quiet month was a wasted invoice. It is usually the opposite.
I am Anthony Omini and I run Cross River Tech in Dallas. When I take on an office, the reactive calls are heavy for the first month or two, because there is always a backlog of things people have learned to live with. Then they drop, because the causes get fixed rather than the symptoms. The invisible work stays constant either way, and it is the reason the call volume falls.
Below is the full job, split by rhythm: what happens every day, every month, every quarter and every year. If you are evaluating a provider or wondering whether you are getting what you pay for, use it as a checklist.
What does an IT person do day to day?
Daily work is the part you see, plus a layer of monitoring you do not. On a normal day it looks like this.
- Answering the phone and triaging. How many people are affected, can they work around it, and does this jump the queue. You should always know which category your problem is in.
- Fixing what broke. Email not sending, a file nobody can open, a printer offline, a laptop that will not connect to the Wi-Fi, a program that will not launch after an update. Most of this is remote and takes minutes.
- Reviewing overnight alerts. Failed backup jobs, a drive reporting errors, a server that rebooted on its own, an antivirus detection, a device that went offline. This happens before anyone in the office is awake, and it is why some problems never reach you.
- Watching sign-in and security alerts. A login from an unusual location, a mailbox rule created by someone who did not create it, repeated failed sign-ins.
- Onboarding and offboarding. New starter: account, license, device, multi-factor authentication, access groups, shared drives, phone. Leaver: the reverse, quickly. The IT onboarding checklist is the version you can hand to an office manager.
- Answering the small questions. How do I share this folder, why does this PDF look wrong, is this email real. Small questions prevent big incidents, and the last one prevents the biggest.
- Vendor chasing. Sitting on hold with an internet provider, a software vendor or a hardware warranty desk so that nobody in your office has to.
That last item is worth more than it sounds. A meaningful share of small business IT time is not technical at all; it is being the person who deals with the ISP so the office manager can do their actual job.
What should my IT person be doing every month?
Monthly work is the heart of it, and it is the part you should ask about explicitly. If a provider cannot tell you what they do every month without your involvement, they are selling repairs.
- Patching computers and servers. Operating system and application updates, applied on a schedule with a way to roll back a bad one. Unpatched machines are the most common way small businesses get hurt.
- Verifying backups by restoring something. Not looking at a green dashboard. Actually pulling a file back and opening it. A backup that has never been restored is an assumption.
- Reviewing accounts. Who left and still has a mailbox, who has administrator rights they no longer need, which accounts have no multi-factor authentication, which shared logins still exist.
- Checking antivirus and email security. Coverage on every device, no machine silently unprotected, quarantine reviewed, filtering rules still doing their job.
- Looking at the network. Firewall logs and health, access point performance, switch errors, whether the internet circuit is behaving.
- Reconciling licenses. Microsoft 365 or Google Workspace seats against actual headcount. Paying for departed employees for a year is one of the most common invisible costs I find.
- Updating documentation. Asset inventory, network diagram, what changed and why. This is what makes you able to leave any provider, including me.
- Checking disk space and device health. Failing drives usually announce themselves for weeks before they die, if somebody is listening.
None of that generates a phone call, an invoice line item or a thank you. It is exactly why it gets skipped by anyone billing purely by the hour, and why the choice between hourly and monthly support is really a choice about whether the quiet work happens.
What do managed IT services include day to day?
Here is the whole job on one grid, so you can see what should be happening and how often.
| Rhythm | What happens | What you notice |
|---|---|---|
| Continuous | Monitoring of computers, servers, network equipment and backups; alerting | Nothing, until an alert becomes a fix |
| Daily | Support calls, triage, fixes, onboarding and offboarding, alert review, vendor chasing | The visible half of IT |
| Weekly | Backup job review, patch approvals, security detections, open items follow-up | Nothing |
| Monthly | Patching, restore testing, account and license review, antivirus and email security check, network health, documentation update | An invoice, and fewer problems |
| Quarterly | Administrator access review, firewall firmware and rule clean-up, device age and warranty check, review of what broke most often, spend review | A short conversation and a short list |
| Annually | Full restore test, hardware replacement plan, license renewals, contract and internet renewal dates, security baseline review, next year's budget | A planning meeting |
| As needed | New computers, office moves, cabling, new locations, software rollouts, incidents | A project and a quote |
My managed IT plan covers the first six rows for a monthly fee, quoted per user or per device after a short conversation, month-to-month with no lock-in. Projects in the last row are quoted separately, because pretending an office move or a cabling job is included in a monthly fee just makes the monthly fee dishonest.
What happens when the invisible half is skipped?
Nothing, for a while. That is what makes it dangerous. Skipped maintenance does not produce an incident on the day it is skipped; it produces a worse incident later, and a slow rise in daily friction in the meantime.
- Patching skipped. Machines drift months behind. One phishing click that would have gone nowhere becomes an actual compromise. Software starts failing in odd ways because versions no longer match.
- Backups never tested. The day you need one, you find that the job has been failing since a server change, or that it backs up the file server but not the cloud mailboxes, or that the restore takes four days. This is the single most expensive omission in small business IT.
- Accounts never reviewed. Former employees keep mailboxes and file access. Half the office has administrator rights. Shared logins mean nobody can tell who did what, which is a problem the first time something goes wrong.
- Licenses never reconciled. You pay monthly for people who left, for tools nobody opens, for a tier you do not need.
- Documentation never written. Everything lives in somebody's head, so a routine change becomes an archaeology project and switching providers becomes a hostage negotiation.
- Firewall and network ignored. Firmware ages out of support, rules accumulate from projects that ended, Wi-Fi degrades as the office fills, and everyone concludes the internet is bad.
- Hardware unmanaged. Machines run until they die, always at the worst moment, and always with a day of lost work and an emergency purchase at retail prices.
The pattern is consistent: the office adapts. People restart things twice a day, keep files on the desktop, work around the printer, and stop reporting problems because reporting them changed nothing. By the time somebody calls a new provider, the phrase is almost always "it has been like this for a while".
What does an IT guy do that is not technical at all?
A surprising amount, and it is often where the money is saved.
- Buying decisions. Which laptops to standardize on, which specification is enough, when to repair and when to replace, what warranty to buy. Standardising on business machines from one or two manufacturers makes every later problem cheaper.
- Vendor management. Internet provider, phone system, practice or agency software, copier company, alarm and camera vendors. Someone has to be the technical contact who can tell one vendor's story from another's.
- Budgeting. Telling you in October which five computers will need replacing next year, so it is a line in a budget instead of a surprise. What a small business should budget for IT each year covers how to shape that.
- Translating. Explaining what a cyber-insurance questionnaire is actually asking, what a compliance requirement means for your office, or what a vendor's quote is really proposing.
- Documentation and process. A one-page starter checklist, a leaver checklist, a written note of who to call for what.
- Saying no. Talking you out of hardware you do not need, a project that solves nothing, or a subscription that duplicates something you already own.
- Planning ahead of change. A new hire, a second location, a build-out, a move. Involving IT early is far cheaper than involving IT afterwards, which is the whole point of the office move IT checklist.
How do you tell whether your IT person is doing the invisible half?
Ask for evidence rather than reassurance. Six questions, and you should get six concrete answers.
- "Show me a file restored from backup this quarter." A date and a file, not a dashboard screenshot.
- "What percentage of our computers are fully patched right now?" A number should exist. If the answer is a shrug, nothing is being monitored.
- "Who currently has administrator access to our Microsoft 365 or Google Workspace?" The list should be short, current and explainable.
- "How many licenses are we paying for and how many people work here?" These two numbers should match, and often do not.
- "Can I have a copy of the network diagram and asset inventory?" If it does not exist, that is the finding.
- "What broke most often in the last three months, and what did you do about the cause?" This is the question that separates a repair service from IT support.
If those answers are thin, it does not automatically mean you need a new provider; sometimes it means nobody ever asked and the scope you bought never included it. The wider version of this review is in the annual IT check-up every Dallas office should run, and if the answers are thin two years running, the signs you need to change provider are worth reading honestly.
Does a small office really need all of this?
Not all of it, all the time. Scale is a legitimate answer, and I would rather scope honestly than sell you a program built for a company four times your size.
- Under about five people, entirely in the cloud. Multi-factor authentication everywhere, managed antivirus, patching, a backup of your cloud data, and hourly help when something breaks. That is genuinely enough, and hourly break/fix support at $100 remote and $150 onsite during business hours is often the whole answer.
- Roughly five to twenty-five people. Add monitoring, documented onboarding and offboarding, license management, a business firewall and proper Wi-Fi, and someone accountable for the network. This is where a monthly plan starts paying for itself.
- Twenty-five people and up, or any server, or regulated data. All of the above plus tested restores, access reviews, security baselines and a hardware replacement plan. At this size the invisible half is not optional. What changes when a Dallas office grows past 25 people goes through the order to add things in.
Industry changes it too. A dental or medical practice carries HIPAA duties, a law firm carries confidentiality obligations, and an insurance agency answers to carriers, which pulls the security and backup work forward regardless of headcount. See dental practices and law firms for what that looks like in practice.
If you want to know which of these you are actually getting today, send me your headcount and what has broken recently or call (214) 612-7080. I will tell you what I would do in the first month and what it would cost, whether that turns into a monthly plan or a single afternoon of work.
Questions people ask
What should my IT person be doing every month?
At minimum: patch computers and servers, verify backups by restoring something real, review user accounts and administrator rights, check antivirus and email security coverage, look at firewall and network health, reconcile licenses against headcount, and update documentation. None of that produces a phone call, which is exactly why it gets skipped. Ask for evidence of each rather than a summary.
Is it normal not to hear from my IT provider for weeks?
Silence between support calls is fine and often a good sign. Silence about maintenance is not. You should get something on a regular rhythm: a note that patching ran, confirmation that a restore was tested, a short quarterly review of what broke and what it cost. If months pass with no contact of any kind, ask for the evidence questions in this checklist.
What is the difference between IT support and managed IT services?
IT support usually means someone fixes things when you call, billed by the hour. Managed IT services means someone is responsible for the systems continuously: monitoring, patching, backups, security and documentation happen whether or not you call, for a monthly fee. The first is a repair service. The second is an outsourced IT department, sized for a small business.
Can one person do all of this for an office?
For an office of roughly five to fifty people, yes, because most of the maintenance is automated and monitored rather than done by hand, and at Cross River Tech my team handles that routine work while I stay your point of contact. What a small company should not pretend to offer is a staffed overnight desk or several large rollouts at the same time. Above about a hundred seats, or with a requirement for round-the-clock staffed cover, hire a larger firm.
How much of IT work is actually fixing things?
Less than most owners expect, and it shrinks over time. In the first month or two with a new office it dominates, because there is a backlog of tolerated problems. Once the causes are fixed rather than the symptoms, the balance shifts toward maintenance, planning and buying decisions. A rising volume of reactive calls after the first quarter usually means something structural is unresolved.
What should I expect in writing from an IT provider?
A written scope of what is included and excluded, an asset and account inventory, a simple network diagram, a list of licenses and who holds administrator rights, and a record of significant changes. You should be given copies, not shown them. That documentation is what makes it possible to change providers without a crisis, which is precisely why some providers avoid producing it.



