Most businesses in the Peoria area pay between $100 and $200 per user per month for fully managed IT services, and most land in the lower half of that range. The figure is not a flat rate applied to everyone. It is the output of a handful of specific factors: how many users and devices you have, what security your industry requires, how much of your operation runs in the cloud, and how many locations you cover. Understanding those factors is the difference between a price that looks arbitrary and one that makes sense. This article walks through what actually goes into a managed IT quote, so you can read any provider’s number, including ours, and know what you are looking at.
At a glance: Fully managed IT services in the Peoria area typically run $100 to $200 per user per month, with most businesses landing in the lower half of that range. The top of the range is usually reached only by businesses with heavy security or compliance needs. A managed IT price is the output of specific factors: user and device counts, security requirements, cloud usage, and number of locations. Cloud storage and cloud infrastructure can change the monthly number as your usage changes. Physical security appliances like firewalls are priced by location, not headcount, so multi-site businesses should expect that to shape the quote. Co-managed arrangements typically cost less than fully managed service for a business of the same size, because the provider covers only part of the work. Compliance consulting for frameworks like HIPAA or CMMC is billed separately and is not included in the managed services fee. A trustworthy provider discloses upcoming project costs, like an aging server, before you sign, so nothing arrives as a surprise.
Most providers keep pricing off their site, usually because every client is different and they would rather have the conversation first. There’s some truth to that, but most buyers just want a straight answer to a fair question. Here is ours.
This page assumes you have already decided you want a managed IT provider and you want to know what it costs. If you are still weighing whether an MSP is worth it compared to hourly or break/fix support, start with our break/fix versus managed IT comparison instead. If you are comparing the cost of an MSP against hiring someone in-house, our managed IT versus in-house staff breakdown has the salary math.
What Is the Price Range for Managed IT in Peoria?
For a fully managed arrangement, where a provider acts as your complete IT department, most Central Illinois businesses pay $100 to $200 per user per month, and most land in the lower half of that range. We rarely quote under $100 per user, and the top is typically reached by businesses with heavy security or compliance requirements rather than the average office. Some environments, like shops where several people share equipment, are counted per workstation instead, in the same range.
National pricing guides often quote wider ranges, anywhere from $100 to $400 per user, but those figures pull in expensive coastal markets. Managed IT pricing tracks local wages and cost of living, so a New York or San Francisco business pays far more than a Central Illinois one for the same service. Peoria’s lower cost of living is a large part of why our market sits at the lower end of the national spread.
That monthly fee is the flat, predictable foundation of the relationship. It covers the day-to-day work of running your technology: a staffed help desk that answers live, monitoring of your network and systems, patching and updates, security tools, backup management, and regular strategic reviews, quarterly or twice a year depending on your preference. The idea behind flat-rate managed services is simple: you should know what IT costs each month, and the model gives your provider a reason to keep your systems healthy rather than profit when they break.
What Goes Into a Managed IT Quote?
A managed IT quote is built from a handful of inputs. Once you see them, the number stops looking arbitrary and starts looking like arithmetic. Here are the factors that shape it, roughly in the order they matter.
Users and devices. This is the foundation, and it’s where user-count-only pricing goes wrong. A per-user figure works cleanly for an office where everyone has a laptop and a phone. It works less well for a manufacturer where 25 shop-floor workers share a handful of terminals. Two 40-person companies can need very different amounts of support, so a flat per-user price overcharges one and undercharges the other, and the undercharged business usually discovers the gap later as add-on costs. At Facet, we count both users and devices, and you won’t be penalized for having more of one than the other. When comparing quotes, it’s worth asking each provider what their price is based on, and what falls outside it.
Security requirements. A business handling protected health information, defense contract data, or financial records needs more than baseline security: advanced monitoring, stricter access controls, and additional tooling. Our cybersecurity services scale to match those requirements, and the monthly price scales with them. This is one of the most common reasons a business lands toward the top of the range. Note that compliance consulting is a separate matter, covered below.
Cloud usage. Cloud servers, virtual desktops, and large amounts of cloud-stored data carry their own monthly costs, and those can change as your usage grows or shrinks. A business with terabytes of data in the cloud will see that reflected in its monthly number, and a business that adds cloud infrastructure mid-contract will see the price adjust to match. A good provider is upfront about this from the start, so cloud growth never reads as a mystery charge.
Firewalls and hardware. A firewall is a physical security appliance, and it’s priced by location, not headcount. A ten-person business with three sites needs three firewalls; a fifty-person business under one roof needs one. Whether you rent or own your equipment matters here too, for firewalls and workstations alike. A managed firewall arrangement builds the appliance, its maintenance, and its replacement on a three-year cycle into the monthly fee, while owned equipment shifts those costs to periodic purchases. Neither approach is wrong, but they show up differently on a quote, and multi-location businesses should expect the location count to shape the number more than the user count does.
Special circumstances. Every business has something unusual about it: a line-of-business application that needs specific care, multiple locations, seasonal staff, equipment with unusual requirements. These don’t always change the price, but they belong in the conversation before a quote is final. Any provider who doesn’t ask about them is planning to find out later, at your expense.
How Is Co-Managed IT Priced?
Co-managed arrangements, where we work alongside your internal IT staff, typically run less per user/workstation than fully managed because we cover a portion of the work rather than all of it. The range is wide because these engagements are built so differently from one another.
One co-managed client may license security tools through us and handle everything else internally. Another may keep help desk in-house and rely on us for after-hours coverage, projects, and security. Another may need us for one location while their internal team covers the rest. Because the division of labor varies so much, so does the price, and a per-user figure means very little until the roles are defined. If you have internal IT and want to see how the model works, our co-managed IT page explains how the arrangements typically work.
What Costs Should You Expect Beyond the Monthly Fee?
Projects. Most businesses will have some project costs over the life of an IT relationship, and you should be suspicious of any provider who implies otherwise. Servers age out. Networks need refreshes. Offices move. Software gets migrated. These are normal, and they’re separate from the monthly managed services fee.
The difference between providers is not whether projects happen. It is whether you see them coming. There is a practice in this industry we think is indefensible: a provider shows up at contract renewal and announces that your server is end-of-life, must be replaced within the month, and will cost tens of thousands of dollars. The problem was visible for years. It was simply not mentioned until the moment it created maximum pressure.
We handle it the opposite way. If a server project or anything like it is on the horizon, we tell you before you sign, and we plan it into your budget through regular strategic reviews so the cost arrives on a schedule you chose. You will likely have project costs with us, the same as with anyone. Our aim is that none of them ever arrive as a surprise. That commitment to planning ahead is a large part of why clients stay with us for over a decade on average.
Two things sit outside the managed services fee and are worth naming directly. Compliance consulting, the advisory work of getting a business ready for HIPAA, CMMC, PCI, or a similar framework, is a separate line item, not part of the managed number, though some cybersecurity tools may be included in your monthly fee. The range in this article assumes a business without a heavy compliance-consulting need. And in rare cases, a large, tangled environment that isn’t well documented may need a scoping project to map what’s there before an accurate quote is possible. For the large majority of businesses this never comes up, and the assessment itself is always free.
How Do You Get an Accurate Quote?
Through a free assessment of your actual environment. Before we quote, we look at your systems, count what’s really there, ask about your security and compliance obligations, and flag anything on the horizon, including problems you didn’t know about. We tell you what we find whether you hire us or not, at no charge. The monthly range in this article is the price for a business that knows what it has and can show us in that assessment, without heavy compliance-consulting or other advanced needs. When those conditions hold, and they usually do, the number lands in the range and stays there, because it reflects your real environment rather than an estimate that gets corrected after you sign. It is also why we won’t give a final price over the phone.
Frequently Asked Questions
How much do managed IT services cost per user per month?
In the Peoria area, fully managed IT services typically cost $100 to $200 per user per month, with most businesses landing in the lower half of that range. Some environments are counted per workstation instead, in the same range. Businesses with heavy security or compliance requirements, such as healthcare or defense contractors, are the ones that reach the upper end.
How much does co-managed IT cost?
Co-managed arrangements typically run less than fully managed for a company in the same industry with similar complexity, because the provider covers a portion of the work rather than all of it. The range is wide because scope varies: one client licenses security tools through us and handles the rest internally, another keeps helpdesk in-house and relies on us for after-hours coverage and projects. A per-user figure means little until the roles are defined.
Is compliance consulting included in the managed services price?
No. Compliance consulting, the advisory work of preparing a business for HIPAA, CMMC, PCI, or a similar framework, is billed separately and is not part of the monthly managed services fee. Some cybersecurity tools may be included in your plan, but compliance consulting is its own engagement, scoped and quoted on its own.
Do you charge for the initial assessment?
We offer a free IT assessment for Peoria-area businesses. We look at your environment, identify risks and upcoming needs, and share what we find with you whether you hire us or not.
Get a Real Number for Your Business
The exact number depends on your environment, and finding it takes a conversation.
Facet Technologies has served Central Illinois businesses from Peoria since 1989. Call (309) 689-3900 or reach us through facettech.com/contact-us to schedule a free assessment and get a quote built on your actual environment.
Fun fact: Sticky Keys, one of the oldest accessibility tools in computing, was invented twice: once at a lab at the University of Wisconsin, and once by a programmer fed up with his stiff IBM keyboard. The lab’s version shipped with Macintosh System 6’s Easy Access bundle, and PC Magazine published STAYDOWN in April 1988, the same month.
Phishing Vultures and the World of Re-Scams
Getting scammed is bad enough. What could be worse? The FBI answered this week by issuing a warning: “recovery scams.”
Scammers find recent fraud victims, sometimes because they ran the original scam themselves, sometimes by lurking in social media support groups. Many created fake persona profiles and joined groups for financial fraud victims, posing as fellow victims before steering people toward the fake “recovery” contact.
Either way, someone claiming to be an FBI agent reaches out with good news: your money has been recovered, or can be, if you click this link or pay this fee.
The “polish” behind these attempts is what’s new. Some victims saw AI-generated videos of a real, senior FBI official directing them to file a complaint on a lookalike version of the FBI’s Internet Crime Complaint Center (IC3) website. Some received messages from profiles impersonating the IC3 or FBI.
The fake site collects your name, phone number, email, and how much you lost, then hands you a reference number and promises follow-up. The follow-up is the next round of the scam: a malicious link, a request for your bank details to “process the return,” or a fee to release your “recovered funds.”
Here’s how to spot it (worth sharing with anyone you know who’s been hit by fraud):
The IC3 has no social media accounts, so any profile claiming to represent it is fake, and no legitimate FBI account will ever DM you about recovering money.
The FBI never asks for payment to recover lost funds. “We found your money, small fee required” is always a scam.
Type www.ic3.gov directly into your address bar and skip sponsored search results, which are often paid imitators.
Real follow-up on an FBI complaint comes from a local field office, not a DM.
This playbook shows up in the business world too. After a company loses money to wire fraud or a compromised email account, “recovery specialists” tend to come calling. Work only with your bank, actual law enforcement, and your IT provider.
Had a security incident, or want to prevent one?
Call us at (309) 689-3900 for a complementary cybersecurity assessment and harden your defenses.
Facet out and about and in the news:
Facet Senior Account Executive Trey David was featured in a WMBD story about new phishing techniques. Check it out here!
On July 19, Jason, Marie, and Trey beat the heat at Five Points Washington’s Annual Golf Outing supporting Five Points Memory Makers Cafe, a social program for individuals living with memory loss and their caregivers. We were proud to sponsor this event for a great cause!
Now Available On-Demand: AI-Fluent Leader Sessions 1-6
The AI Fluent Leaders Series resumes August 19.
In the meantime, you can catch up on our previous sessions and be ready to join for Session 7!
Unlike gardens, cybersecurity’s finest yield is nothing at all.
The Phishing Scam That Skips Your Password
If you’ve been reading Cyber Treats for a while, you know the usual phishing checklist: check the sender, hover over links, watch for lookalike domains and urgency cues. The FBI’s latest alert covers a scam that passes all of those tests. How? The sign-in page is legit.
Kali365 is a phishing kit that criminals can rent to target Microsoft 365 accounts (pretty cheaply, too: reports from cybersecurity researchers say it’s around $250 per month).
How It Works:
You get an email that looks like someone shared a document with you. To view it, you’re told you need to verify your identity by signing in and entering the code provided.
The page the link leads to really is Microsoft’s. You enter the code and sign in like normal, password and MFA prompt included.
That code tied your login to the attacker’s device, and you just verified them. There was never a document.
From there, the attackers can access your Outlook, Teams, and OneDrive without ever needing your password or another MFA prompt.
How To Avoid This Scam:
Real document shares never arrive with a code already in the email. Those codes exist to connect a new device to your account, like signing into a streaming app on a TV. If an email hands you a code and tells you where to type it, stop. You didn’t set up a device, which means someone else did.
And while this campaign targets Microsoft 365, the same login shortcut exists on Google and many other services, so the habit travels: never enter a code you didn’t request.
Is MFA Still Worth It?
Yes. Criminals are paying subscription fees to get around it, which tells you how well it works everywhere else!
The best defenses against phishing include robust security measures and employee training.
Need guidance on cybersecurity training measures or reliable IT support? Reach out at (309) 689-3900 to book time with us to go over your strategy.
Now Available On-Demand: AI-Fluent Leader Sessions 1-6
The AI Fluent Leaders Series resumes August 19.
In the meantime, you can catch up on our previous sessions and be ready to join for Session 7!
The federal government has a published blueprint for adopting AI safely, and the structure is refreshingly clear. The NIST AI Risk Management Framework organizes responsible AI adoption around four jobs: govern it, map where it lives, measure how it performs, and manage the risks over time. The framework tells you what good looks like. Doing all four well, across a real business with real data, is the part that takes serious work.
At a glance: The NIST AI Risk Management Framework is the leading U.S. guidance for adopting AI responsibly, built around four functions: Govern, Map, Measure, and Manage. NIST guidance is voluntary, but enterprise buyers, cyber insurers, and regulators increasingly treat alignment with it as the baseline expectation. A 2026 Compliance Week survey found that 83% of organizations use AI tools while only 25% have a strong governance framework around that use. Building and maintaining AI governance and security is an ongoing program, not a one-time setup, and it spans your data, your tools, your policies, and your people. Facet Technologies delivers this same structure as a managed service through its SAFE approach, so businesses get enterprise-grade AI security without building the capability themselves.
NIST is the National Institute of Standards and Technology, a U.S. Department of Commerce agency that writes the technical standards much of American business already runs on, including the cybersecurity framework many companies use today. When NIST publishes guidance on AI, it carries weight.
What Is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework, often shortened to the AI RMF, is a voluntary set of guidelines that helps any organization identify, assess, and manage the risks that come with using AI. NIST released version 1.0 in January 2023 and has continued to expand it since, including a profile specifically for generative AI tools like ChatGPT and Microsoft Copilot.
The framework is built to be flexible. It does not hand you a rigid list of rules to pass or fail. Instead, it gives you four functions to work through, and you apply them at whatever depth matches your business. A 25-person manufacturer in Central Illinois follows the same four functions as a national bank, just scaled to fit the size of the risk.
Flexible does not mean easy. Working through all four functions means inventorying every place AI touches your data, locking down file permissions, writing and enforcing policy, vetting tools, and monitoring it all as your usage grows and the tools change month to month. Adopting the framework is an ongoing program, not a one-time project you finish and file away. Large enterprises staff entire teams for exactly this work.
What Are the Four Functions of the NIST AI Framework?
The NIST AI framework is built on four functions that work together: Govern, Map, Measure, and Manage. Each one answers a different question about how AI runs inside your business.
Govern is the foundation. It sets the culture, the policies, and the clear ownership for how AI gets used. Govern is the cross-cutting function, which means it runs through everything else rather than sitting as a separate step. In plain terms, govern answers: who decides what AI we use, and what are the rules?
Map is about knowing where AI actually lives in your operation. That includes the tools your team chose on their own, often without telling anyone. Map answers: where is AI being used, and what could go wrong with each use?
Measure is how you check that AI is doing what you expect. It covers testing, watching for errors, and keeping an eye on whether a tool drifts off course over time. Measure answers: is this working the way we think it is?
Manage is the response. It covers prioritizing the real risks, putting controls in place, and having a plan for when something goes sideways. Manage answers: what do we do about the risks we found?
You do not have to run these in strict order, and most businesses cycle through them again and again as their AI use grows. Govern comes first because it sets the rules. After that, the work loops.
Why Should a Central Illinois Business Care About a Voluntary Framework?
The NIST AI framework is voluntary, which means no law forces you to follow it. So why bother? Because the people you do business with are starting to expect it.
Three pressures are converging. Enterprise customers now build AI governance questions into the security questionnaires they send vendors, so a business without a documented approach can face longer sales cycles and extra due diligence. Cyber insurance underwriters are writing AI-specific terms into policies, and showing a structured approach helps maintain your standing at renewal. And regulators increasingly point to the NIST framework as the reference point for what responsible AI looks like.
For a business owner, the takeaway is simple. Following a recognized framework is how you show a customer, an insurer, or an auditor that your AI use is deliberate rather than accidental. It is the difference between “our team uses some AI tools” and “here is how we govern AI.” This is the same principle behind zero trust security: structure and verification beat assumption.
How Does This Connect to Shadow AI?
Shadow AI is the use of AI tools by employees without company approval or oversight. It is the single most common gap the NIST framework helps you close, and it maps directly to the Govern and Map functions.
Here is how it happens. Someone pastes customer data into a free chatbot to draft emails faster. Someone else uploads a spreadsheet to summarize it. None of it is malicious, and most of it even improves productivity, but none of it is visible. You cannot protect data you do not know is leaving the building.
That is what the Map function is for: knowing where AI is actually being used before you can secure it. A clear acceptable-use policy is part of the answer, since giving people approved tools is what stops them from reaching for risky ones. The same dynamic drives shadow IT risk more broadly, and the fix is the same: visibility first, then guardrails.
There is a second half to the Map problem that catches even careful businesses off guard. A tool like Microsoft Copilot does not browse the way a person does. It searches every file an employee’s account can reach, including places that account has never actually opened. For decades, sensitive files stayed safe partly because nobody knew where to look. AI erases that protection in seconds. The 2025 Concentric AI Data Risk Report found that 16% of business-critical files are overshared across the average organization, more than 800,000 files per company. Facet’s cybersecurity for AI readiness work closes that gap by tightening file access and permissions, so AI enables your team without exposing your data.
What Makes Facet’s Approach Different?
Most of the AI conversation right now is about speed. Adopt faster, automate more, get ahead. That part matters, and we believe in it. But speed without security is how companies end up explaining a data leak to their biggest customer. Facet Technologies built its approach the other way around: secure first, then fast.
We call our managed approach to AI adoption the Facet SAFE approach. We run the govern, map, measure, and manage work for you, sized for a company that does not have a dedicated risk department and does not want to build one. You get the outcome NIST describes without assigning the project to someone on your staff.
That security focus is not a bolt-on. Facet Technologies is a managed IT and cybersecurity provider first, which means we look at every AI tool the way we look at every other piece of technology touching your data: what does it access, where does that data go, and who is watching it. A lot of providers have moved into AI enablement recently. Far fewer come at it from a security-first foundation, with a 24/7 Security Operations Center and layered protection already in place behind the work. That foundation is the difference between someone telling you what the framework says and someone actually implementing it across your environment.
The economics tend to favor bringing in a partner, too. A single overshared dataset reaching the wrong AI tool can undo far more value than a year of managed security costs, and building the capability internally pulls leadership and IT off revenue work for months. A managed engagement turns an open-ended internal project into a predictable monthly cost, with people who do this every day accountable for the outcome.
We meet businesses at two points. The AI Fluent Leaders webinar series, hosted by Brian Ford and Ellie Shaw, is our free education on-ramp. It helps leaders understand AI well enough to make good decisions, with no cost and no pitch. When you are ready to actually secure and govern AI across your business, the SAFE engagement is where we take that off your plate. The AI readiness assessment bridges the two: it scores your business across six areas, from strategy to security, and gives you a clear picture of where you stand and what implementing this would involve, before you commit to anything.
What Should a Business Do First?
A few early moves help you get oriented, and they cost nothing but attention. Name one person as the owner of AI decisions, even if that is the owner, so the topic has a home. Ask your team, plainly and without blame, which AI tools they are already using and for what. Write down a short ground rule everyone can follow today: which tools are approved, and what kinds of data should never go into a public AI tool. Those three moves give you a rough map of where you stand.
What they do not do is finish the job. That early map almost always surfaces more than expected, like the overshared files mentioned earlier, and closing those gaps is where the real work begins: tightening permissions across your environment, vetting and configuring tools, building enforceable policy, and monitoring it all as your AI use grows. This is genuine data governance, the kind of detailed, environment-wide work that specialized teams handle full time. Getting it right across an entire business is a substantial, ongoing engagement, not a weekend project.
That is the honest dividing line. The orientation steps you can take yourself this week. The full build is where most businesses bring in a partner, because doing it properly the first time is faster, safer, and less expensive than discovering the gaps after something has already gone wrong. Facet’s AI readiness assessment is the simplest way to see both at once: where you stand today, and what the full engagement would actually involve.
FAQ
What is the NIST AI Risk Management Framework?
The NIST AI Risk Management Framework is voluntary federal guidance that helps organizations identify, assess, and manage the risks of using AI. It is organized around four functions: Govern, Map, Measure, and Manage. NIST released it in January 2023 and continues to expand it with profiles for specific AI types. It is voluntary, but enterprise customers, insurers, and regulators increasingly treat alignment with it as a baseline expectation.
What are the four functions of the NIST AI framework?
The four functions are Govern, Map, Measure, and Manage. Govern sets the policies and ownership for AI use. Map identifies where AI is being used and what could go wrong. Measure tests how AI performs over time. Manage prioritizes risks and puts controls in place to respond to them.
What is shadow AI and why does it matter?
Shadow AI is the use of AI tools by employees without company approval or oversight. It matters because it moves company data into tools no one is monitoring, which creates security and privacy exposure. The NIST framework addresses it directly through the Govern and Map functions, which call for visibility and clear policy.
Can a small business actually use the NIST AI framework?
Yes. The framework scales to organizations of any size, and a small business follows the same four functions as a large enterprise. You can start on your own by naming an AI owner, inventorying which tools your team uses, and setting a basic acceptable-use policy. The heavier work of securing and governing AI across an entire environment is where many small and mid-sized businesses bring in a security partner.
How does Facet Technologies help with AI security?
Facet Technologies helps Central Illinois businesses through two doors: the free AI Fluent Leaders webinar series for learning, and the managed SAFE engagement for securing and governing AI across your business. As a managed IT and cybersecurity provider first, Facet runs the implementation so your team does not have to build the capability internally.
Ready to Adopt AI Without Building the Capability Yourself?
You do not have to choose between moving fast and staying secure, and you do not have to build the whole program in-house to get there. The fastest path is to see where you stand, then let a team that does this every day handle the rest. Start with Facet’s AI readiness assessment for a clear picture, or reach out to talk through what securing AI across your business would look like.
Call Facet Technologies at (309) 689-3900 or visit facettech.com/contact-us to talk through what safe, practical AI adoption looks like for your business in Peoria and across Central Illinois.
Wishing all our readers a Happy (early!) 4th of July on this semiquincentennial!
Five Tech Tips Guaranteed to Save You Time
Before you log off for next weekend’s festivities or a summer vacation, save these five useful keyboard shortcuts.
1. Drop in a symbol, emoji or GIF → Win + . (period)
Opens a little picker in any text field. Great for the ° or ™ you always need, or adding a little ✨pizazz✨.
2. Rename a File Instantly → Fn + F2
Select a file and press Fn + F2 — the name highlights, ready to retype. Bonus: after you rename one, press Tab to jump straight to the next file. Great for cleaning up a folder full of “Scan_001, Scan_002.”
3. Screenshot precisely withSnipping Tool → Win + Shift + S or PrtSc (Windows 11 Update)
Drag a box around any part of your screen and it copies, ready to paste into an email or chat. No more full-screen capture and crop. On Windows 11, the PrtSc button also opens the Snipping Tool by default.
4. Snap two windows side by side → Win + Arrow
Press Win + ← to shove the active window to the left half. Windows then offers up your other open windows for the right half. Just arrow-key to the one you want and hit Enter. No mouse required!
5. Lock your screen in one move → Win + L
Stepping away from your desk? One keystroke locks it. This one’s a freebie from the security side of the house. It’s a small habit that provides real protection.
Need guidance on cybersecurity measures or reliable IT support? Reach out at (309) 689-3900 to book time with us to go over your strategy.
There’s Still Time:Sign Up forAI Fluent Leaders: Session 6
How SMBs Can Move Faster Than the Competition Using AI
Your competition has more people, more budget, and more time than you do. The good news: smart AI use can flip that math. Smart SMBs are using it to move faster than companies many times their size, and in this session we’ll show you exactly how, sharing the tips and tricks we use ourselves.
This session will cover:
How to get found by buyers and AI search without a big marketing team
Real examples of the grunt work we’ve handed off to AI, and what it gave us back
Why small teams have the speed advantage, and how small wins compound into a real edge
Where to point AI next, so you’re positioned for what’s coming
At just 45 minutes (30 minute presentation + 15 minute Q&A), this one’s going to provide huge value and lots of ideas for your team.
HIPAA is changing in 2026, but the picture is far more complicated than the urgent headlines suggest. Some changes are real, finalized, and have deadlines that have already passed. Other changes were widely covered last year, then quietly vacated by a federal court ruling that most articles still have not updated to reflect. The big Security Rule overhaul that everyone is talking about is still proposed and may never be finalized in its current form. Knowing the difference matters, because preparing for the wrong rule wastes money, and ignoring the right ones creates real liability. For healthcare practices in Central Illinois, the right response to 2026 is neither panic nor inaction. It is steady security work, accurate documentation, and a clear-eyed view of what is actually required versus what is being talked about.
At a glance: The February 16, 2026 deadline to update Notices of Privacy Practices is real, but the rule that survived is the substance use disorder (Part 2) alignment, not the reproductive health protections most articles still describe. The reproductive health portion of the 2024 HIPAA Privacy Rule was vacated by a federal court in June 2025 and is no longer enforceable. Practices that already updated their NPPs with reproductive health language should consider removing it. The major 2026 Security Rule update is still a proposed rule. The Notice of Proposed Rulemaking was published in late 2024, the comment period closed in March 2025, and HHS missed its May 2026 target for finalization. The most-cited HIPAA deficiency in OCR enforcement actions remains inadequate risk analysis. This has been true for many years and is not changing. The right preparation is steady, ongoing security practice that holds up under audit. It is not last-minute compliance theater for rules that may shift again.
If you run a healthcare practice in Central Illinois and you have been reading articles about the 2026 HIPAA changes, you are probably encountering a mix of urgent deadlines, vague timelines, partially obsolete information, and conflicting interpretations. This is what we have sorted out, and what we recommend to the practices we work with.
What Is Actually Required Right Now?
Before talking about what is changing, it helps to know what is already in effect, because the answer is different from what most articles describe.
The February 16, 2026 deadline for updating Notices of Privacy Practices (NPPs) is real and has passed. But the rule that actually survived to that deadline is not the one most articles still reference. Two separate 2024 rulemakings both pointed at the February 2026 NPP deadline: a reproductive health privacy rule and an alignment between HIPAA and 42 CFR Part 2 (the regulations governing substance use disorder treatment records).
In June 2025, the U.S. District Court for the Northern District of Texas vacated most of the reproductive health rule in Purl v. HHS. The reproductive health provisions, including the attestation requirement many practices started preparing for, are no longer enforceable. HHS confirmed in a follow-up press release that covered entities are not required to implement the vacated provisions. Practices that already updated their NPPs to include reproductive health language should remove it, because it now describes a requirement that no longer exists.
The Part 2 alignment update did survive and is what the February 16, 2026 NPP deadline actually applies to. Every HIPAA-covered entity must have updated their NPP to reflect the substance use disorder confidentiality framework changes. If your practice has not done this, that is an immediate compliance gap with no ambiguity.
The HIPAA Security Rule, which governs the technical and administrative safeguards around electronic protected health information (ePHI), is what most of the 2026 conversation is actually about. The Security Rule itself has not changed yet. The version currently being enforced is the same one that has been in place for years. Risk analysis remains the most-cited deficiency in OCR enforcement actions, and that has been true for more than a decade.
So as of mid-2026, the practical state of affairs is: NPPs needed to be updated for substance use disorder confidentiality by February 16 (not for the vacated reproductive health rule), Security Rule technical requirements are unchanged from prior years, and the dramatic Security Rule overhaul is still proposed but not finalized.
What Is Actually Being Proposed?
The big 2026 HIPAA conversation centers on the Notice of Proposed Rulemaking (NPRM) that HHS published on December 27, 2024. The proposed changes would represent the most substantial overhaul of HIPAA security requirements since the original rule.
The largest proposed changes include:
Elimination of “addressable” controls. Currently, certain HIPAA safeguards are “addressable,” meaning your practice can document a reason for not implementing them. The proposed rule would eliminate this flexibility for most controls, making them mandatory across the board.
Mandatory encryption of ePHI at rest and in transit, regardless of organization size.
Mandatory multi-factor authentication (MFA) for all systems accessing ePHI.
Annual risk assessments and compliance audits with documented methodology and remediation tracking.
Network segmentation to isolate ePHI systems from general business networks.
72-hour incident response capability with documented procedures and rehearsed plans.
Annual penetration testing by qualified third parties.
Asset inventories and network mapping that are kept current rather than static.
Stricter business associate oversight, including written attestations and enhanced documentation.
These are the changes that healthcare IT consultants have been writing about urgently. Most articles treat them as essentially inevitable, with compliance dates in late 2026 or early 2027.
Why You Should Be Careful About Trusting That Timeline
Here is the part most articles skip. As of June 2026, the final rule has not been published.
HHS originally targeted May 2026 for finalization. That window has passed. The comment period on the NPRM closed in March 2025, and the agency has been working through the feedback since then. A coalition of over 100 hospital and healthcare provider groups submitted formal requests asking HHS to withdraw the proposal entirely, citing implementation costs, technical complexity, and concerns about the timeline. The Trump administration’s regulatory priorities are different from the Biden administration that proposed the rule, which adds uncertainty about whether and when the rule will be finalized.
None of this means the proposed changes will not happen. They probably will, in some form, eventually. But the confident 2026 deadlines you see in some articles are not actually backed by a finalized rule. The compliance timeline that most articles cite assumes the rule is published soon, with a 180 to 240 day grace period after publication. As of right now, the clock has not started.
For practice owners, this creates a strange situation. You should not ignore the proposed changes, but you also should not invest heavily in compliance work for a rule that may be modified or withdrawn. The right approach is to do the security work that is valuable regardless of whether the rule is finalized, and to position your practice to be ready when the final rule actually publishes.
What Should You Actually Be Doing Right Now?
The honest answer is that most of the proposed changes are security practices that healthcare organizations should already be doing. The proposed Security Rule update is mostly codifying what reasonable healthcare security has looked like for years. If your practice has implemented these controls already, the eventual final rule will require documentation work but probably not major new implementation.
Here is what we actually recommend to healthcare clients in Central Illinois:
Verify your Notice of Privacy Practices is current. The February 16, 2026 deadline applied to the substance use disorder (Part 2) alignment update. If your NPP has not been updated to reflect those changes, that is an immediate gap. At the same time, if you updated your NPP in anticipation of the reproductive health rule (which was vacated by a federal court in June 2025), the reproductive health language should be removed. NPP accuracy matters more than NPP urgency.
Conduct or update your HIPAA Security Risk Assessment. Inadequate risk analysis is the single most-cited deficiency in OCR enforcement actions, and this has been true for years. This is not a checkbox exercise. It is a written evaluation of where ePHI lives in your practice, what threats it faces, what controls are in place, and what gaps still exist. The free OCR/ONC Security Risk Assessment tool helps with the structure. Professional risk assessments typically cost $5,000 to $30,000 depending on practice complexity, but they produce documentation that survives an audit. Either way, the assessment must exist, must be dated, and must be reviewed at least annually.
Implement multi-factor authentication on everything. This is going to be mandatory eventually, and even before then, MFA is one of the most effective security controls a practice can implement. If your EHR, email, and remote access systems do not have MFA, the eventual rule will require it and your insurance carrier probably already does.
Verify encryption of ePHI at rest and in transit. Modern systems handle this by default in most cases, but practices using older infrastructure sometimes have gaps. Verify rather than assume.
Build a real incident response plan. A documented plan that has been rehearsed at least once by the people who would actually execute it. The 72-hour response window in the proposed rule is aggressive, but practices that have an actual plan can meet it. Practices relying on improvisation cannot. The IBM 2025 Cost of a Data Breach Report puts the average healthcare breach at $11 million, which is the most expensive category they track. The financial gap between practices with rehearsed response plans and practices without is measured in millions.
Review your business associate agreements. Every vendor who touches ePHI needs a current BAA, and your practice needs documentation that you are verifying their compliance posture rather than just trusting it. This is a practical area where proposed and final rules align: vendor oversight is going to get stricter regardless.
Document everything. OCR enforcement actions reliably focus on what practices can prove they did, not what they actually did. Written policies, documented procedures, dated assessments, and incident response records are the difference between defensible compliance and confident-but-undocumented compliance.
Why DIY HIPAA Compliance Is Harder Than It Looks
Most small healthcare practices try to handle HIPAA compliance internally. The practice administrator becomes the de facto compliance officer. The IT person who runs the EHR becomes the technical security lead. Documentation lives in a binder somewhere or on a shared drive that nobody updates.
This works until it does not. The patterns we see when small practices fail HIPAA audits are similar. The risk assessment is several years old or was never done. Policies exist but were not updated when systems changed. The incident response plan is theoretical because nobody has rehearsed it. The encryption status of various systems is assumed but never verified. The business associate agreements are signed but not actively managed.
None of this is incompetence. It is just the reality of trying to manage compliance alongside running a healthcare practice. The administrator and IT person are doing their actual jobs full-time, and compliance gets the attention left over. When OCR shows up, that gap becomes visible.
The practices we work with that have the cleanest compliance posture have one of two things: a dedicated compliance officer (rare in practices under 100 employees), or an IT partner who handles the security and documentation work as part of an ongoing relationship. Either approach works. Trying to do it ad hoc rarely does.
How Does Facet Approach Healthcare IT and HIPAA?
Facet has supported Central Illinois businesses for over 30 years, and our healthcare client base includes medical practices, dental practices, chiropractors, med spas, and behavioral and mental health providers across the region. Our approach to HIPAA is built around a recognition that good security and HIPAA compliance are mostly the same project. Practices with real security postures generally pass audits. Practices that treat compliance as a separate documentation exercise generally do not.
We handle the technical implementation: encryption verification, MFA deployment, network segmentation where needed, endpoint protection, backup and recovery testing, and the ongoing patching that keeps systems current. For the formal compliance pieces (risk assessments, policy documentation, business associate agreement management, incident response planning), we partner with independent third-party auditors rather than serving as both the implementer and the auditor. This avoids the conflict of interest that comes with self-attesting and produces documentation that holds up under OCR scrutiny.
The honest conversation with any prospective healthcare client starts with where the practice currently is on compliance, not where the IT provider’s service tier sits. The right level of support depends on what gaps actually exist and what the practice is trying to protect.
Frequently Asked Questions
Is the 2026 HIPAA Security Rule update finalized?
As of mid-2026, no. The Notice of Proposed Rulemaking was published in December 2024, the comment period closed in March 2025, and HHS missed its targeted May 2026 finalization date. A coalition of over 100 healthcare provider groups has asked HHS to withdraw the proposal. The eventual final rule may differ from what was proposed, and the timeline for finalization is not currently confirmed. Practices should prepare for the likely controls (MFA, encryption, annual risk assessment) but should not invest heavily in compliance work specifically for a rule that may shift.
What is the most common reason practices fail HIPAA audits?
Inadequate risk analysis is the single most-cited deficiency in OCR enforcement actions, and this has been true for more than a decade. The risk assessment must be documented, dated, and reviewed at least annually. Most failures involve either no risk assessment at all or one that is years out of date. Updating policies without updating the underlying risk assessment is one of the most common gaps practices have.
Should small practices do their own HIPAA risk assessment?
The free OCR/ONC Security Risk Assessment tool is genuinely useful for small practices and helps structure the work. The tool’s own documentation notes that completing it does not guarantee compliance. Most practices benefit from professional support to validate findings, document them properly, and translate them into a remediation plan.
Will MFA actually be required?
Multi-factor authentication is in the proposed Security Rule update as a mandatory control. Even before the rule is finalized, MFA is one of the most effective security controls available and is increasingly required by cyber insurance carriers. Practices that have not implemented MFA on EHR, email, and remote access systems should do so now regardless of regulatory timing. The financial cost of MFA is small. The risk of not having it is large.
How much does HIPAA compliance cost for a small healthcare practice?
The cost depends on practice size and current security posture, but typical small practices in Central Illinois budget $5,000 to $30,000 for a professional risk assessment, plus ongoing managed IT services that cover the technical security work. The hidden cost most practices underestimate is the cost of NOT being compliant. The IBM 2025 Cost of a Data Breach Report puts the average healthcare breach at $11 million, which is the most expensive category they track. Practices that treat HIPAA as ongoing security work rather than annual documentation theater spend less in total.
Ready to Talk About Where Your Practice Actually Stands?
If you are a healthcare practice in Central Illinois trying to figure out what the 2026 HIPAA changes mean for you specifically, the right conversation starts with where you currently are. We can walk through your existing security posture, identify the gaps that matter most, and help you build a plan that does not depend on guessing about regulatory timelines.
Facet Technologies has provided IT services to Central Illinois businesses for over 30 years. Based in Peoria, we serve healthcare, manufacturing, agriculture, professional services, and government organizations across the region.
Most businesses still running on-premises Microsoft Exchange in 2026 are not doing it for a strategic reason. They are doing it because nobody made the decision to stop. The server is still there because it has been there. Email still works because it always has. The patches mostly get installed. The backups mostly run. The IT person who was supposed to migrate this two years ago never quite got to it. And every month that the server stays in the closet, the business absorbs a little more risk that nobody is actively managing.
We have completed hundreds of email migrations for Central Illinois businesses, and the pattern is almost always the same. The Exchange server outlived the strategy. The business outgrew the setup. The right time to move was two years ago. The second best time is now.
At a glance: The reason most businesses still run on-premises Exchange in 2026 is rarely strategic. It is usually inertia. Running Exchange in 2026 carries real business risk that has nothing to do with Microsoft’s product roadmap and everything to do with how email actually works now. A properly planned migration takes 2 to 4 weeks of project time for a typical small business, with your team experiencing effectively no disruption. The migration project itself for most Central Illinois businesses runs $10,000 to $25,000, depending on size and complexity. This is one-time work.
Why Are You Still Running Exchange?
This is worth answering honestly before anything else.
The businesses we encounter still running on-premises Exchange in 2026 fall into a few buckets. The most common is the one where Exchange just kept working, so nobody touched it. The IT person who built the setup left years ago. The current IT support knows enough to keep it running but not enough to migrate it. Every few months someone says “we should really move to the cloud,” and every few months it gets bumped down the priority list because nothing is actively on fire.
The second bucket is businesses that tried to migrate at some point and got scared off. A bad vendor quote. A horror story from another business. An IT person who insisted it would be disruptive. The decision was made to wait, and then nobody revisited it.
The third bucket is businesses that genuinely had a reason at some point. Compliance concerns about cloud storage. Specific integrations with legacy line-of-business software. Custom transport rules that nobody wants to touch. In 2026, these reasons mostly do not hold up anymore. Microsoft 365 is HIPAA-eligible, supports nearly every modern integration, and has matured to the point where what used to be edge cases now have documented solutions.
None of these reasons are bad reasons. They are just not strategic reasons to still be running Exchange in 2026. Inertia is the actual reason, and inertia has been compounding into risk for a while now.
What Running Exchange Actually Costs You
The cost is not the licensing. Microsoft’s licensing for on-premises Exchange is not the expensive part of the equation.
The cost is what runs in the background and accumulates. Every month your server is on, it accumulates patches that need to be installed and tested. Every month, security advisories come out for Exchange that have to be evaluated. Every month, your backups need to run, and someone needs to verify they actually completed. Every month, somebody is supposed to be reviewing the security logs.
In the businesses we assess, this work is almost never being done. Patches are 6 to 18 months behind. Backup verification is theoretical. Security log review is nonexistent. The server is running, but nobody is actually managing it. This is the gap between “Exchange is working” and “Exchange is safe.”
The risk that accumulates in that gap is the actual cost. Unpatched Exchange servers have been the entry point for some of the most expensive ransomware events of the last several years. The 2021 ProxyLogon vulnerability alone gave attackers access to tens of thousands of unpatched Exchange servers worldwide. Most of those servers were not compromised because the IT teams were incompetent. They were compromised because the businesses had moved past the point where anyone was really paying attention to the server.
Modern email security capabilities that small businesses now need (advanced phishing detection, conditional access policies, encryption, retention policies, eDiscovery for compliance) are either difficult to implement on on-premises Exchange or simply not available. Microsoft 365 has these built in. Running Exchange in 2026 means accepting a security posture that is meaningfully behind the modern standard, regardless of how attentive your IT team is.
Add to this the operational drag: VPN setup for remote workers, the special procedures to access email from a phone, the disaster recovery plans that depend on the server room staying powered, the storage that fills up at the worst possible moment. None of these are catastrophic on their own. Together, they are a quiet tax on the business that competitors using modern email do not pay.
What a Migration Actually Looks Like When It Is Done Right
Most of the migration anxiety comes from people who have either seen a bad one or read about one online. A properly planned migration is genuinely boring from the user perspective.
Your team keeps working in their existing email throughout the project. The transition happens in waves rather than all at once. The cutover moment, when email officially switches over, happens outside business hours and takes a few hours rather than days. Users open their Outlook the next morning, it reconfigures itself once, and they go back to work. The whole experience for end users is closer to a software update than a major project.
The project around the cutover is where the real work happens. We document the existing environment, identify any mailboxes or configurations that need special handling, set up the Microsoft 365 tenant with appropriate security policies, coordinate the DNS changes that direct email to the right place, prepare end users for the small visible changes, and validate everything works before close-out. This is roughly 80% of the project. The actual mailbox migration is the simple part once the rest is in order.
For a typical small business in Central Illinois, this whole project runs about 2 to 4 weeks. Mid-sized organizations take 4 to 8 weeks. The leadership time required is usually under ten hours total, spread across the project. We have not had a client experience meaningful business disruption from a properly planned migration in years. The migrations that do go badly are almost always ones where someone tried to skip the planning work to save money or time.
Why You Should Not DIY This
Microsoft has built solid migration tools. The technical execution is well-documented. In theory, a capable IT person could run a migration themselves. We have seen this attempted many times, and we know how it usually goes.
The technical work is roughly 20% of the project. The other 80% is the planning, the security configuration, the communication with department heads, the coordination with the prior IT setup, the validation checklist, and the troubleshooting when something does not work the first time. The Microsoft migration wizard handles the 20%. It does not handle the 80%.
What goes wrong when businesses DIY is rarely the migration itself. It is usually one of the surrounding pieces. The MX records get set up wrong and email delays for two days. Multi-factor authentication gets turned on before users are prepared and the helpdesk gets flooded. A line-of-business application that depends on email integration stops working because nobody noticed it had specific configuration. Compliance retention policies do not get migrated and the next audit becomes a problem. None of these are technical limitations. They are planning limitations.
If your business is very small, very simple, and has someone with real IT experience who can dedicate proper time to the project, DIY is possible. For most businesses in the 25 to 250 employee range, the math on doing it yourself stops working pretty quickly once you factor in the value of leadership time and the risk of doing it wrong.
How Should You Think About the Timing?
There are a few real signals that the time to plan is now rather than in another year.
Microsoft has announced that Exchange Web Services protocols will be blocked in Exchange Online starting October 1, 2026. For businesses with hybrid setups or legacy connections, this creates a real deadline. The companies waiting until late 2026 to plan are going to compress their planning window in ways that make the project riskier than it needs to be.
Beyond the Microsoft deadline, the more practical signal is whether your Exchange server has gotten the attention it deserves. If it has been more than six months since anyone validated the backups, more than 18 months since the patches were current, or more than two years since anyone evaluated the security configuration, the server is no longer being managed. It is being tolerated. That is the moment to address it.
The third signal is harder to name but real: businesses that have grown past the size where a single-server setup made sense. If you have remote workers, multiple locations, compliance requirements, or anyone in your business who needs reliable email access outside the office, you are paying a tax to keep Exchange running that does not match what your business actually needs anymore.
How Does Facet Handle Migrations?
Facet has completed many email migrations for Central Illinois businesses, ranging from small offices to mid-sized organizations with serious compliance requirements. We do this work constantly. The approach is built around making the project feel boring to your team.
We start with an honest assessment of your current environment, not a generic quote based on user count. From there, we recommend the right migration approach for your situation, walk through the licensing options that fit your team, coordinate with whoever is currently managing your Exchange server, handle the technical execution, and validate everything works before close-out. For most businesses, the entire migration project requires less than ten hours of leadership time total, spread across several weeks.
After migration, our managed IT services include Microsoft 365 management as part of the ongoing relationship. For businesses that want strategic guidance on broader cloud and platform decisions, our strategic IT advisory service handles the platform roadmap.
How long does an Exchange to Microsoft 365 migration take?
A typical small business migration takes 2 to 4 weeks of total project time. Mid-sized organizations of 100 to 500 users typically take 4 to 8 weeks. The actual email cutover for end users is usually invisible, happening in the background while users keep working.
Will my team be without email during the migration?
With proper planning, no. Modern migration approaches allow users to keep working in their existing email throughout the transition. The actual cutover moment is scheduled outside business hours with effectively no downtime. Reports of “email was down for a week” come from migrations that skipped the planning work, not from properly executed projects.
What does a migration project cost?
For most small and mid-sized businesses in Central Illinois, one-time migration project costs run $10,000 to $25,000 depending on size, complexity, and how much additional security setup is included. This is one-time work, not an ongoing cost. The Microsoft 365 licensing for users after migration is billed separately.
Can my office manager handle this with Microsoft’s migration wizard?
For very small environments (fewer than 5 mailboxes) with simple configurations, possibly. For most businesses, the wizard handles roughly 20% of the project. The other 80% (planning, security configuration, user communication, validation, DNS coordination) is what separates a smooth migration from a chaotic one. Most businesses benefit from a partner who handles the complexity rather than navigating it themselves.
What is the October 2026 Microsoft deadline?
Microsoft has officially announced that Exchange Web Services (EWS) protocols will be blocked in Exchange Online starting October 1, 2026. This affects businesses still running on-premises Exchange Server. Practically, businesses should plan migration before that deadline rather than after.
What licensing tier fits my team?
Microsoft 365 offers multiple business tiers with different security and capability levels. The right tier depends on whether your business has compliance obligations, remote workers, or other security needs. Rather than recommend a single number, we walk through the right fit role by role during the migration assessment.
What if my current IT person resists the migration?
This is more common than people expect. Sometimes the resistance is legitimate technical caution. More often, it is the human discomfort of admitting that something they have been managing should have been retired years ago. We work alongside existing IT teams during migrations rather than around them, and the conversations tend to go better than businesses expect.
Ready to Move Past the Exchange Server in Your Closet?
If you have been thinking about this migration for a while and never quite getting to it, that is the most common reason businesses end up calling us. We can walk through your specific situation, give you a realistic timeline, and help you make the decision you have probably already known you needed to make.
Facet Technologies has provided IT services to Central Illinois businesses for over 30 years. Based in Peoria, we serve healthcare, manufacturing, agriculture, professional services, and government organizations across the region.
The World Cup kicks off today, summer concert season is in full swing, and somewhere out there a scammer’s photoshopping a ticket.
Ticket fraud is a big business. The FBI just issued a warning about fake FIFA websites, and researchers have found over 4,300 fraudulent domains impersonating FIFA’s ticketing portal, including one pixel-perfect clone with a working login page.
This isn’t just a World Cup problem. The same machine runs year-round for concerts, festivals, and the big game, and the BBB logs hundreds of complaints about it every year.
What do ticket scams look like?
Clones: A lookalike website (often with a slightly-off URL, like fifa.help) selling tickets that don’t exist. These show up in search ads, so the fake sits right next to the real thing on Google.
Copied Tickets: Scammers buy one real ticket, screenshot it, and sell it to ten people on Facebook Marketplace. The first person through the gate gets in, but everyone else bought a very expensive JPEG.
Fake Events: Sometimes the whole event is fake: a festival that was never happening, advertised with polished AI-generated pages and real artist and venue names.
This winter, Dutch police ran fake ticket ads themselves as an experiment. Of 300,000 people who saw the ads, about 3,400 tried to buy. That may sound small, but that 1% is the business model. Ticket scammers cast a wide net expecting to get only a small percentage of takers.
How to avoid ticket scams:
Buy from the official venue, team, or event site. Type the URL yourself.
Pay with a credit card. Never Zelle, Venmo “Friends & Family,” wire, or gift cards, as those have no recourse.
Treat urgency (“13 other people are viewing these tickets”) as a red flag: a sales tactic on both real sites and fake ones.
How does this relate to the usual phishing scams we cover in Cyber Treats? Ticket scams are built on the same psychology behind the phishing emails hitting your team’s inboxes. Whether it’s fake invoices, “your account will be suspended,” urgent requests from “the boss,” or World Cup tickets, it’s the same foundation. Staying cyber aware means spotting the pattern for both concert tickets and fake invoices.
Need guidance on cybersecurity measures or reliable IT support? Reach out at (309) 689-3900 to book time with us to go over your strategy.
Sign Up forAI Fluent Leaders: Session 6
How SMBs Can Move Faster Than the Competition Using AI
Smart SMBs are using AI to outpace their competition, even their large competitors. In this session, we’ll show you how, sharing our own experience, tips, and tricks so you can start supercharging your efficiency and growth with AI.
Topics we’ll cover:
Marketing easier and smarter (including proven AEO/GEO tips we use ourselves!)
Eliminating grunt work with agents and workflows
How to navigate the “quirks” of AI and keep your work feeling human
Where to avoid using AI — and where it will benefit you most.
Trivia answer: B, Railroad Tickets. Railways charged less per mile for longer trips, so a traveler going New York to Chicago could buy a ticket all the way to San Francisco, hop off in Chicago, and sell the unused portion to a “scalper” who resold it for less than the railway’s price. The term later spread to event tickets.
In most small businesses, the “IT person” was never hired to be the IT person. They are the office manager, the controller, the operations coordinator, or the most technically curious employee in the building. They got the WiFi password first, so people started asking them when the printer broke. Five years later, they are managing the firewall, troubleshooting Microsoft 365, and trying to figure out HIPAA compliance in their spare time. The business gets cheap IT support. The employee gets burned out and starts looking for a job that does not involve resetting passwords at 9 PM.
At a glance: Most small businesses (10 to 50 employees) have an “accidental IT person”, a non-IT employee who became the default technology resource over time. The hidden cost shows up in three places: the strain on that employee, the strategic decisions made without proper guidance, and the security gaps nobody is watching. Untrained people making confident IT decisions are often a higher cybersecurity risk than untrained people who are openly overwhelmed, because false confidence resists outside review. This is not a problem you solve by replacing the employee. It is a problem you solve by moving IT decisions to a provider qualified to make them, with the internal person remaining as the point of contact. Full managed IT services is usually the right answer for this pattern. Co-managed only fits when the internal person has actual technical training and current cybersecurity expertise. The right time to fix this is before the employee leaves, not after.
You probably know exactly who this is in your business. The person who handled the new laptop setup for the last three hires. The one who knows the password to the accounting software. The one everyone messages on Teams when the projector is not working. If your business is between 10 and 50 employees, there is a strong chance you have this person. They are usually excellent at their actual job. That is exactly the problem.
How Do You Know You Have an Accidental IT Person?
The pattern is hiding in plain sight once you know what to look for. Check whether any of the following sound like your business.
Signal
What It Looks Like in Practice
One person knows all the passwords
Admin credentials, vendor logins, network configuration all live with one employee who never officially signed up to own them
IT work happens after hours
Software updates, troubleshooting, new employee setup all happen on evenings or weekends because there is no time during the workday
The “IT person” has another full-time job
They are the controller, office manager, or operations lead. IT is the second job they never asked for
Technology decisions get deferred
Hardware replacements, security upgrades, software migrations sit on a list because nobody has time to research them
The same problems keep recurring
Recurring printer issues, recurring login problems, recurring slow days. Nobody has the time to actually solve them at the root
The “IT person” is talking about leaving
Quiet job searching, increased frustration, comments about being pulled in too many directions
Compliance documentation does not exist
HIPAA risk assessments, security policies, backup verification. These are supposed to exist but nobody owns them
If two or more of these describe your business, you have an accidental IT person. The question is whether you address it now, while they are still with you, or later, after they have left and taken every password and vendor relationship with them.
What Is the Real Cost of the Accidental IT Person Model?
The cost is rarely measured because it does not show up on an invoice. It shows up in three places: the employee, the business decisions, and the security posture.
The employee cost is the most visible. Someone who was hired to do operations, accounting, or office management is now spending 15 to 30% of their week on IT work they have no formal training for. They are problem-solving alone, often outside business hours, often under pressure. The work is invisible to leadership because it does not produce a tangible deliverable. Over time, this is one of the most common reasons high-performing employees in small businesses quit. They leave for a role where they get to focus on the work they were actually hired to do.
The business decision cost is harder to see but more expensive. When the person making IT decisions does not have time to research them or expertise to evaluate them, the decisions get made under pressure with incomplete information. A firewall gets purchased because a vendor cold-called at the right moment. A backup solution gets selected because it was the cheapest option that came up in a Google search. A software platform gets chosen because the salesperson was persistent. None of these decisions are bad in isolation. Together, they produce a technology environment that nobody designed and nobody fully understands.
The security cost is the one that becomes existential when something goes wrong. A 2025 Verizon Data Breach Investigations Report found that small and medium-sized businesses experience ransomware data breaches at more than double the rate of large enterprises, 88% versus 39%. The reason is rarely technical sophistication. It is that smaller businesses do not have anyone whose actual job is to watch their network, and the accidental IT person cannot do that job on top of their real one. By the time a problem surfaces, the attacker has been in the network for an average of nine months, according to IBM’s 2025 Cost of a Data Breach Report.
Why Does This Pattern Keep Happening?
This is a structural problem, not a personal one. Three forces push businesses into the accidental IT person model.
The first is cost perception. Hiring a dedicated IT employee feels expensive. The average fully loaded cost runs $130,000 to $150,000 per year, and the work does not always look like a full-time job at smaller sizes. So businesses do not hire. They distribute the work to whoever is willing to absorb it.
The second is availability. The person who knows the most about technology is usually the most willing to help. They get a reputation for being good with computers, and the requests start coming. Saying no requires constant social friction with coworkers who genuinely need help. Most people stop saying no and absorb the role by default.
The third is invisibility. Because IT work does not produce a discrete deliverable, leadership rarely sees how much of it is happening. The office manager who spent four hours on Tuesday troubleshooting a printer and three hours on Wednesday updating a server has no manager noticing that those hours came out of their actual job. The work is invisible until the person doing it quits.
What Does the Right Answer Look Like?
The right answer almost always involves giving the IT work to someone whose actual job is to do it. There are two clean ways to get there.
The first, and usually the better fit, is full managed IT services. The accidental IT person stops being responsible for IT and becomes the single point of contact between the business and the provider. They get to return to the job they were hired for, whether that is operations, accounting, or office management. The provider absorbs everything: helpdesk, monitoring, security, vendor management, compliance, strategic planning. The internal person still has institutional knowledge of the business and the people, which is genuinely useful, but they do not need to be the one fixing the printer or managing the firewall. They just need to be the person who picks up the phone and connects the right conversation.
The second option is co-managed IT, but this fits a much narrower set of situations than most people assume. The decision is not whether the internal person wants to keep doing IT. The decision is whether they are qualified to keep doing IT. Those are different questions, and conflating them is a common cybersecurity risk.
An untrained person who enjoys being the IT person but lacks formal training is often more exposed than one who is openly overwhelmed. They tend to be confident in decisions that should be reviewed by someone with security expertise. They configure firewalls based on what they read online. They set up cloud services without understanding identity and access management. They install software without checking dependencies or vendor reputation. They believe their security posture is fine because nothing has gone wrong yet. The false confidence is the risk. An accidental IT person who is honest about the limits of their expertise is usually safer than one who has convinced themselves they have it covered.
Co-managed IT only fits when the internal person has actual technical training, current certifications, and genuine cybersecurity expertise. If they are a credentialed IT professional working part-time on IT alongside other duties, co-managed lets them keep that work while getting backup for what they cannot cover alone. For everyone else, including most office managers, controllers, and operations leads who got handed the IT role by default, the safer answer is to move the strategic and security decisions to a provider whose job is to make them. The internal person remains the helpful point of contact. The technical judgment lives with someone qualified to exercise it.
The honest reading is this: full managed services usually makes more sense for the accidental IT person pattern, regardless of how much the internal person wants to stay involved. The cybersecurity exposure of an untrained person making security decisions is the most expensive part of this whole problem, and it is the part most businesses do not see until something goes wrong.
Either way, the institutional knowledge stays in the building. The relationships stay in place. The provider absorbs the work that should not have been absorbed by an untrained person in the first place.
How Should You Think About Making the Change?
There are three signals that the change should happen now rather than next year.
The first is when the accidental IT person starts talking about being overwhelmed. By the time someone says this out loud in a small business, they have usually been feeling it for six months. The conversation is a warning, not an opening complaint.
The second is when a security incident, audit failure, or compliance scare puts the business in a position where IT decisions cannot wait anymore. These moments tend to be expensive. Addressing the underlying staffing problem before the incident is meaningfully cheaper than addressing it after.
The third is when the business grows past 20 employees. This is the rough threshold where the accidental IT person model stops being a stretch and starts being a structural risk. The technology footprint at that size is too large for someone to manage on the side. The security exposure is too real to leave to part-time attention.
Most businesses delay the change too long because there is never a convenient moment. The IT person is too busy to switch models. The leadership team is focused on growth. The budget conversation gets pushed to next quarter. The result is that the change happens after a crisis rather than before one.
How Does Facet Approach This?
When Facet engages with businesses that have an accidental IT person, the first conversation is usually with that person. They have done a remarkable job under conditions they should never have been asked to manage. The right model depends less on what they want to do and more on what they are qualified to do.
For most businesses in this pattern, our full managed IT services are the better fit. The accidental IT person stops being responsible for IT and becomes the point of contact between the business and our team. We absorb the technology work, document the environment thoroughly, and free up that employee to return to the job they were originally hired for. The strategic and security decisions move to our team, where they belong. The internal person remains a valuable connection to the business without carrying decisions they were never trained to make.
For businesses where the internal person genuinely is a credentialed IT employee with technical training, our co-managed IT model provides specialized depth alongside their existing role. This fits a different and much narrower set of situations than the accidental IT person pattern, and we are honest with prospects about which side of the line their business falls on.
The honest conversation is about what model fits the business now and what makes the work sustainable for the people involved. For the broader framework on evaluating IT providers, see our 7 questions to ask before signing and What an IT partnership looks like blog.
Frequently Asked Questions
Should I replace the accidental IT person with a managed service provider?
Usually not in the sense of letting them go. They have institutional knowledge and relationships that are useful to keep. But the IT work itself usually should move to an external provider. The accidental IT person stays in their actual role (operations, accounting, office management) and becomes the point of contact for the IT provider, rather than the person responsible for IT.
Can a non-IT employee safely handle IT for a small business?
For very simple environments and very small businesses, sometimes. For most growing businesses with compliance obligations, remote workers, or any meaningful security exposure, the honest answer is no. The risk is not whether they can keep the printers working. The risk is whether they are equipped to make confident decisions on firewalls, identity management, backup architecture, and incident response. Most accidental IT people are not, and the absence of obvious problems is not the same as the presence of real security.
When is the right time to move IT work to a managed services provider?
Three signals: when the accidental IT person starts talking about being overwhelmed, when a security or compliance scare forces the issue, or when the business grows past 20 employees. The right time is usually before any of these reach a crisis point, but the change is still possible and often necessary even after one of them does.
What is co-managed IT, and when does it fit?
Co-managed IT is a service model where an external managed services provider works alongside an existing internal IT employee. It fits a narrow set of situations: when the internal person has actual technical training and current cybersecurity expertise. For the accidental IT person pattern, where the internal person is not formally trained in IT, full managed services is usually the safer and more effective answer.
What happens to the accidental IT person after the change?
In the typical scenario, they return to spending their full time on the job they were actually hired for. They stay in the building, they keep their institutional knowledge of the business, and they become the point of contact between the business and the IT provider. They are no longer the person responsible for IT decisions. The strain comes off, and the employee retention risk goes down meaningfully.
Ready to Talk About Your Current Setup?
If you recognize the accidental IT person pattern in your business, the right time to address it is before the person leaves or before something breaks. We can walk through what the right model looks like for your specific situation, with the goal of moving the IT work to a team whose actual job is to handle it.
Facet Technologies has provided IT services to Central Illinois businesses for over 30 years. Based in Peoria, we serve healthcare, manufacturing, agriculture, professional services, and government organizations across the region.
A managed IT partnership is a long-term relationship where an external team takes responsibility for the technology side of your business, working alongside leadership rather than waiting to be called. The right partnership looks less like buying a service and more like adding a department. The signals that tell you you’re ready usually show up in your business before you start looking for the language to describe them.
At a glance:
A managed IT partnership—often delivered by a Managed Service Provider (MSP)—combines day-to-day support with strategic planning, vendor management, and risk reduction across a multi-year horizon.
Industry research from BETSOL found that organizations working with a strategic IT partner report 40% improvements in IT efficiency and 25% reductions in technology-related risk.
The transition from reactive IT support to a partnership model typically happens when a business hits a complexity threshold—whether that’s 5 employees handling sensitive data, a 15-person team with strict compliance obligations, or simply a growing company that can no longer afford downtime.
A partnership is not the same as a vendor relationship. The provider is invested in your direction, not just your problems.
The signals that tell you you’re ready are usually visible in how your team works around technology problems rather than solving them.
This piece walks through what a managed IT partnership actually looks like when it’s working, the signals that suggest your business is ready for one, and the honest comparison between a partnership model and the more transactional support models that come before it. It’s a framework, not a sales pitch. The goal is to give you the language to recognize what you’re already experiencing.
What Does an IT Partnership Actually Look Like Day to Day?
A real IT partnership operates on two tracks at once. The first track is the day-to-day support: helpdesk, monitoring, security tools, and the things that make technology work when your team needs it. The second track is the strategic conversation: where your business is going, what technology decisions need to happen in the next 12 to 36 months, and how the operational side connects to leadership goals.
What this means in practice is that the relationship is not just transactional. You have one accountable team that knows your network, your vendors, your business model, and the people who use the technology. The same team that resolves a help desk ticket on Monday is the team that meets with you quarterly to walk through the technology roadmap. Documentation lives with the provider, not in one person’s head. Vendor contracts get reviewed, negotiated, and managed as part of the relationship. Security and compliance are ongoing functions, not one-time projects.
The result is a relationship where you stop thinking about IT as a problem to manage and start thinking about it as an area of the business where someone has it covered. That shift is what most business owners are actually looking for when they start evaluating providers, even if the conversation starts with cost.
The “Break-Fix” Freelancer vs. The Managed IT Partnership
This is the distinction most buyers do not have language for yet. The model that comes before a partnership is usually called “break-fix”—something breaks, you call a freelancer or vendor, they fix it, and they bill you for the time. Here is how the break-fix model compares to an MSP partnership.
Dimension
Break-Fix / Freelancer IT
Managed IT Partnership (MSP)
Engagement model
Transactional, called when something breaks
Ongoing, integrated into how the business operates
Strategic planning
Not included, you handle it yourself
Quarterly business reviews, 12 to 36 month technology roadmap
Vendor management
You manage vendors directly
Provider manages technology vendors on your behalf
Documentation
Lives in the technician’s head
Lives with the provider, accessible to you
Risk & compliance
Reactive, addressed when audits or incidents force it
Proactive, built into ongoing service
Communication cadence
Only when there’s a problem
Regular, structured, two-way
Pricing model
Hourly or per-incident
Flat monthly fee with predictable budgeting
Time horizon
This week’s issue
A strategic view of the next years of your business
A break-fix relationship is fine for businesses that genuinely just need someone to call when something breaks. A partnership is what businesses need when technology has become integrated enough into operations that “wait until it breaks” is too expensive a strategy.
What Are the Signals That You’re Ready for a Partnership?
The signals show up in patterns of behavior, not in single events. If two or more of the following describe your business, the partnership conversation is worth having.
You are making technology decisions under pressure. Hardware fails and you scramble to replace it. A software vendor calls and you make a decision without much research. A compliance requirement surfaces and you address it reactively. The decisions get made, but they get made without context.
Your team is working around problems instead of solving them. Recurring printer issues. Recurring login problems. Recurring network slowness. The workarounds become the way work happens, and the underlying issue never gets fixed because nobody has time to dig into it.
Nobody owns the technology strategy. When you think about where IT should be a year from now, the answer is “we’ll see.” Hardware refreshes are reactive. Cloud strategy is whatever happens when a server fails. Cybersecurity is whatever the cyber insurance application forced you to put in place.
A single person carries too much. This might be your accidental IT person, the office manager or controller who became the IT person by default. The business has a single point of failure that nobody planned to create.
The freelancer’s availability is your bottleneck. When your “IT guy” goes on vacation, gets sick, or takes on another full-time job, your business is left exposed. The break-fix model relies on a single individual’s schedule, whereas a partnership relies on a fully staffed team that guarantees coverage.
Compliance or insurance requirements are getting harder to meet. HIPAA, PCI, CMMC, and cyber insurance applications are all becoming more demanding. If you are addressing these by checking boxes rather than by maintaining a posture, the gap between what is required and what you have in place is growing.
You have outgrown the support model that worked when you were smaller. The freelancer who handled IT when you were 8 employees cannot handle IT for 35 employees the same way. The break-fix shop that fixed things when something broke does not have the depth your business now requires. The model that worked then is not the same model that works now.
Leadership spends time on IT that should not be leadership time. If you, as the owner or executive, are the person making vendor calls, evaluating quotes, or troubleshooting things that should be solved at a different level, the support model has outgrown its appropriate scope.
None of these signals are catastrophic on their own. They become problems when they are persistent. They become urgent when they start to compound.
What Does a Partnership Actually Cost?
The financial reality of a partnership is straightforward, and it should not be the headline of the decision. Managed IT services in the Central Illinois market typically run $100 to $200 per workstation per month, depending on what is included in the base rate. The flat monthly fee replaces the variable cost of hourly support, the gaps in proactive monitoring, the unbudgeted projects, and the cost exposure of incidents that proactive support would have prevented.
For most businesses moving from a reactive support model into a partnership, the line-item cost goes up. The total cost of running the business goes down, because incidents become rarer, decisions get made with proper context, and the time leadership spends on technology returns to the business. Industry research from ITIC puts the average small or mid-sized business loss at $25,000 or more per hour during an IT outage. A partnership that prevents two preventable incidents in a year typically more than offsets the difference between reactive and proactive support models.
The conversation that matters is not “what does the monthly fee cost?” It is “what is the total cost of running my business under each model, including the things that cost money when nobody is paying attention?” That question rarely produces a clear answer that favors reactive support for any business past the very smallest sizes.
When Is a Partnership Not the Right Answer?
Honest framing requires naming the cases where a partnership is not what a business needs.
Very small businesses (under 5 employees) with simple technology, no compliance obligations, and no remote workers can often operate on a freelancer or break/fix model for years. The cost of a partnership is more than the situation requires, and the time horizon of strategic planning matters less when the business is not navigating growth or change. That said, even very small businesses still need basic cybersecurity (firewall, MFA, endpoint protection, backups), so “no partnership” does not mean “no security.”
Businesses that are still figuring out what they want technology to do also may not be ready. A partnership works best when there are business goals to align technology against. If the business is in a transitional period where direction is unclear, a partnership may be premature, and a more transactional relationship may serve until the direction settles.
Businesses looking for the lowest possible monthly cost will not find a fit in a partnership model. Partnerships are priced on the relationship, not on individual tasks. If price is the deciding factor rather than fit, the partnership model probably is not what the business is looking for.
How Does Facet Approach the Partnership Model?
When Facet engages with a business, the first conversation is rarely about what is in the service tier. It is about the business itself. What does the next 12 to 36 months look like? What does your team experience around technology that frustrates them? What decisions are getting deferred because nobody has time to make them properly? Once we understand the business, the question of which service model fits becomes much easier to answer.
Our managed IT services are built around the partnership model: quarterly business reviews, a 12 to 36 month technology roadmap, vendor management, ongoing security and compliance posture, and a single accountable team that knows your environment. Our co-managed IT model extends the partnership to businesses that already have internal IT, providing specialized depth alongside the existing team. Our strategic IT advisory service is the partnership component for organizations whose day-to-day operations are already handled but whose strategic technology leadership is not.
For the broader framework on evaluating any IT provider, see our 7 questions to ask before signing blog. For the experience of switching to a new provider, see What to Expect When Switching to a New Managed IT Provider.
The right partnership for your business is the one where the conversation feels like a conversation, not a sale. If you recognize your business in the signals above, that is usually a sign the conversation is worth having.
Frequently Asked Questions
What is the difference between a managed IT partnership and a break-fix vendor?
A vendor relationship is transactional: you call when something breaks, you pay for the work, and you handle strategy and planning yourself. A partnership is integrated: the MSP handles day-to-day support AND meets with you regularly to plan technology direction, manage vendors, address compliance, and reduce risk over a multi-year horizon. The pricing model, the communication cadence, and the time horizon all differ.
When does a business become ready for a managed IT partnership?
The transition is driven by complexity, not headcount. A 10-person healthcare clinic dealing with HIPAA or a 12-person engineering firm with strict cyber insurance requirements often needs a partnership more urgently than a 40-person landscaping company. The best signals are situational: when technology decisions are being made under pressure, when problems are being worked around rather than solved, when a single person carries too much of the IT load, or when leadership is spending time on IT instead of running the business.
Is a partnership the same as having a vCIO?
A vCIO (virtual chief information officer) is one component of a partnership. The vCIO provides strategic technology leadership, planning, and budgeting. In a full partnership, the vCIO function is integrated with day-to-day support, security, and operational services. Some businesses contract with a vCIO separately from their support provider, but the model works best when both functions are integrated.
Will a partnership work alongside our existing IT staff?
Yes. The co-managed IT model is designed specifically for businesses with internal IT staff. The partnership provides specialized expertise (security, compliance, after-hours support, strategic planning) that complements what the internal team is doing rather than replacing them. The result is usually that the internal person can refocus on the business-specific work that only they can do.
What is the smallest business that benefits from a partnership?
The defining factor isn’t your headcount; it’s your reliance on technology. We frequently partner with businesses in the 5 to 15 employee range. If an hour of downtime costs you significant money or reputation, or if you handle sensitive data, the math works. The size of the business matters less than the complexity of what your technology has to support.
How long does a partnership relationship typically last?
Industry-standard managed services agreements run one to three years, with three years being the most common. Strong partnerships typically continue well past the initial term because the provider has become integrated into how the business operates. Switching providers is possible but sometimes disruptive, which is why the initial fit matters.
What is the most important factor in choosing a partnership?
Fit. Cost matters, capability matters, and so do specific industry experience and references. But the deciding factor is usually whether the provider seems genuinely interested in the business or just in the contract. A partnership only works when both sides are invested in the relationship.
Ready to Talk About What This Could Look Like for Your Business?
If you recognize your business in the signals above, the right conversation starts with what you are experiencing, not with what we offer. We are happy to walk through your situation and help you figure out whether a partnership model fits, even if the answer is that you should stay where you are for now.
For broader background, see our 7 questions to ask before signing and our What to Expect When Switching guide.
Facet Technologies has provided IT services to Central Illinois businesses for over 30 years. Based in Peoria, we serve healthcare, manufacturing, agriculture, professional services, and government organizations across the region.