IT jargon, explained
Every term a managed provider will use on you, in plain language. If we ever use a word here without explaining it, that is our mistake, not yours.
Terms and definitions
- vCIO: virtual Chief Information Officer
-
A part-time IT director. Sets the technology roadmap, plans the budget, and handles vendor decisions, without a full-time executive salary.
Most small businesses have nobody whose job is to think about technology beyond this week. Decisions get made reactively, by whoever is closest to the problem. A vCIO fills that gap on a schedule: reviewing what you have, planning what comes next, and putting a number against it so it lands in the budget instead of arriving as a surprise.
- RMM: remote monitoring and management
-
Software on each computer and server that reports its health back to us, and lets us fix things without interrupting you.
RMM is how a managed provider sees a problem before you do. Agents on your devices report disk health, failed backups, missing security patches and dozens of other signals. Most of what it catches gets resolved remotely, often before anyone notices. It is also how updates get applied consistently, rather than whenever someone remembers.
- EDR: endpoint detection and response
-
Security software that watches for suspicious behaviour on a device and can isolate it automatically, rather than only recognising known viruses.
Traditional antivirus compares files against a list of known threats, so anything new gets past it. EDR watches what software actually does (a process encrypting files, a program reaching somewhere it never has before) and reacts to the behaviour. Faced with something serious enough, it can pull that device off the network on its own, before it spreads.
- MDR: managed detection and response
-
EDR with people behind it. Someone reviews the alerts and responds, instead of leaving them for you to notice.
Detection software produces alerts around the clock, and most of them are noise. MDR means a team triages that stream, decides what is real, and acts on it, including at two in the morning. Without it the alerts still get generated; they just sit in a console until somebody opens it.
- Endpoint
-
Any device someone works on, or that holds your data: laptop, desktop, server, phone.
Pricing in this industry is often quoted per endpoint rather than per person, because one employee might have both a laptop and a desktop, and a server has no user at all. When you see a per-endpoint price, count devices, not staff.
- Co-managed
-
You keep your own IT person or team, and we cover the parts you choose, instead of handing over everything.
Not every business wants to outsource all of it. Co-managed means picking individual pieces (monitoring, after-hours coverage, security, backups) while your own staff keeps the rest. It is common where someone internal is already in place and good but stretched, or where the gap is a skill rather than a shortage of hours.
- SLA: service level agreement
-
A written commitment on how fast we respond, stated per severity rather than left to goodwill.
An SLA turns "we'll get to it" into a number somebody can be held to. What matters is what it measures: response time is when a person starts working on the problem, which is not the same as when it is fixed. Ours are stated per priority level and per plan.
- P1: priority 1
-
The most urgent severity: work has stopped, or a system the business runs on is down.
Tickets carry a priority so the urgent ones do not queue behind the routine ones. P1 means production has halted: the office cannot work, or a system the business depends on is unavailable. It carries the shortest response commitment in the plan.
- RTO: recovery time objective
-
How long you can afford to be down before it really hurts, and therefore how fast a restore has to be.
RTO is a business decision, not a technical one. It asks how many hours offline your operation can absorb. The answer drives what the backup design has to look like, because restoring a full server from an offsite copy is slower and cheaper than failing over to a standby, and both are defensible depending on the number.
- RPO: recovery point objective
-
How much recent work you can afford to lose, which sets how often backups have to run.
If backups run overnight and a server fails at four in the afternoon, you lose the day's work. That is an RPO of one day. Deciding you can only afford to lose an hour means backing up hourly, which costs more. The point of naming the number is that it becomes a choice rather than an accident.
- BCDR: business continuity and disaster recovery
-
The plan for keeping the business running through a serious failure, and getting back to normal afterwards.
Backups are a component, not the plan. BCDR covers the rest: who declares an incident, what runs in the meantime, what order systems come back in, and who calls the clients. Most of it is decisions made in advance, which is precisely the part that improvises badly on the day.
- MSP: managed service provider
-
A company that runs your IT for a predictable monthly fee, instead of billing by the hour when something breaks.
The older model is break-fix: something fails, you call, you get an invoice for the hours. The incentives point the wrong way: the provider earns more when things go wrong. A managed provider charges a flat monthly amount and absorbs the support hours, so preventing problems is in their interest too. That is the whole reason the model exists.
Not sure which tier fits?
A quick conversation will sort it out. We'll look at your team size, your tools, and what's actually breaking.