Key Takeaway: The terms in this glossary are defined the way they are used in practice, not the way a vendor would define them in a sales deck. Understanding the difference between what is promised and what is delivered starts with the language.
This glossary defines the terms that matter most in the managed services industry, for MSP owners building better businesses and for business owners trying to understand what their IT provider is actually doing. Every term is defined the way it is used in practice, not the way a vendor would define it in a sales deck.
If a term is missing, it is either not worth defining or it has not come up yet. This glossary is updated as the industry evolves.
A
Acceptable Use Policy (AUP)
A written document that defines how employees are permitted to use company technology resources, including computers, networks, email, and AI tools. An AUP sets expectations, creates accountability, and provides the legal and operational foundation for enforcing technology governance. In 2026, every AUP should include a section on AI tool usage.
Alert Fatigue
A condition in which IT staff become desensitized to monitoring alerts because the volume of alerts is too high to meaningfully review. Alert fatigue is a security risk: when technicians are conditioned to dismiss alerts, the alerts that signal real threats get dismissed along with the noise. The solution is not fewer monitoring tools. It is better-configured monitoring that surfaces signal rather than volume.
Agentic AI
AI systems that can take autonomous actions, browsing the web, executing code, sending emails, interacting with other software, without requiring a human to approve each step. Agentic AI introduces new security and governance risks because the system can act on behalf of a user in ways that may not be fully visible or controllable.
B
Backup
The practice of copying data to a secondary location so it can be restored if the primary copy is lost, corrupted, or encrypted by ransomware. Backup is a component of business continuity, not a substitute for it. A backup that has never been tested is not a backup. It is an assumption. See also: Business Continuity, Restore Testing.
Break-Fix IT
A reactive IT support model in which a business calls for help when something breaks and pays for the repair. The break-fix model has a structural flaw: the IT provider makes money when things go wrong, which creates no financial incentive for prevention. The managed services model was designed to replace break-fix by aligning the provider’s incentives with the client’s.
Business Continuity
The practice of ensuring that a business can keep operating. Or resume operating quickly, after a disruption. Business continuity encompasses backup, disaster recovery, incident response, and the operational planning required to minimize downtime. Backup is one component of business continuity. It is not the whole thing.
C
Churn Rate
The percentage of clients who end their relationship with an MSP in a given period, typically measured annually. A 10% annual churn rate means one in ten clients leaves each year. Churn is the most important metric most MSPs undertrack. Because MSP revenue is recurring, churn has a compounding effect: a client who leaves takes not just their current monthly fee but their entire remaining lifetime value.
Client Lifetime Value (CLV)
The total revenue a client is expected to generate over the duration of the relationship. CLV is calculated by multiplying average monthly recurring revenue by the expected number of months the client will remain. CLV is the metric that makes the economics of client retention visible: a client paying $3,000 per month who stays for four years has a CLV of $144,000.
Co-Managed IT
A model in which an MSP works alongside an internal IT team rather than replacing it. Co-managed IT is common in mid-market businesses that have internal IT staff but need additional capacity, specialized expertise, or after-hours coverage. The MSP and the internal team share responsibility for the environment under a defined scope of work.
Cyber Insurance
Insurance coverage that protects businesses against the financial consequences of cybersecurity incidents, including breach response costs, legal fees, regulatory fines, and business interruption losses. Modern cyber insurance policies require documented security controls as a condition of coverage. Carriers are denying claims when those controls were not in place at the time of the incident.
D
Disaster Recovery (DR)
The process of restoring IT systems and data after a significant disruption, hardware failure, ransomware attack, natural disaster, or facility loss. Disaster recovery is distinct from backup: backup preserves the data, disaster recovery defines how and how quickly the systems that use that data are restored to operation. Recovery time objective (RTO) and recovery point objective (RPO) are the key metrics.
Documentation
In the MSP context, documentation refers to the recorded knowledge of a client’s IT environment, network topology, hardware inventory, software licenses, credentials, known issues, and the processes used to manage and support the environment. Documentation is the infrastructure of operational consistency: it is what allows any competent technician to support any client without starting from scratch. See also: SOP, Runbook.
DNS Filtering
A security control that blocks access to malicious or inappropriate websites at the DNS level, before a connection is established. DNS filtering prevents users from reaching phishing sites, malware distribution points, and command-and-control servers even if they click a malicious link. It is a foundational security control that should be part of every MSP’s baseline security stack.
E
EDR (Endpoint Detection and Response)
A security technology that monitors endpoint behavior, what processes are running, what files are being accessed, what network connections are being made. And detects anomalies that may indicate an attack. EDR is distinct from antivirus: antivirus detects known threats by signature, EDR detects unknown threats by behavior. In 2026, EDR is the minimum standard for business endpoint security.
E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness)
Google’s framework for evaluating the quality of content and the credibility of the sources that produce it. In the MSP context, E-E-A-T is relevant for any MSP that publishes content to attract clients: content written by practitioners with demonstrable experience in the subject matter ranks better and earns more trust than generic content produced for SEO volume.
F
Fiduciary Standard
The obligation to act in the best interest of the person you are advising, rather than in your own financial interest. In the financial advisory industry, fiduciaries are legally required to recommend what is best for the client. In the MSP industry, there is no equivalent regulation. But the principle applies directly to the vCIO role. A vCIO who earns commissions on the products they recommend cannot fully meet the fiduciary standard.
G
Generative AI
AI systems that produce new content, text, images, code, audio, based on patterns learned from training data. ChatGPT, Claude, Gemini, and Copilot are examples of generative AI tools. Generative AI introduces data privacy risks when employees use these tools with sensitive business information, because the data submitted to the tool may be used to train future models or stored on servers outside the organization’s control.
H
Helpdesk
The function within an MSP that handles day-to-day user support requests, password resets, software issues, hardware problems, connectivity questions. The helpdesk is the operational layer of managed services. It is distinct from the strategic layer (vCIO) and the monitoring layer (NOC). A well-run helpdesk resolves issues quickly and documents the resolution so the same issue does not require the same effort next time.
I
Incident Response Plan
A documented procedure that defines how an organization responds to a cybersecurity incident. Who does what, in what order, and how decisions are made under pressure. An incident response plan is not a theoretical document. It is a practiced playbook. MSPs that have never walked through their incident response plan with a client have not delivered an incident response plan. They have delivered a document.
IT Documentation
See: Documentation.
M
Managed Service Provider (MSP)
A company that takes ongoing responsibility for a business’s IT infrastructure and end-user systems under a proactive, subscription-based model. See: What Is an MSP?
MFA (Multi-Factor Authentication)
A security control that requires users to verify their identity using two or more factors, typically something they know (a password) and something they have (a phone or hardware token). MFA significantly reduces the risk of credential-based attacks, which account for a large percentage of breaches. In 2026, MFA on all remote access and privileged accounts is a baseline security requirement, not an optional enhancement.
Monthly Recurring Revenue (MRR)
The predictable, subscription-based revenue an MSP earns each month from its managed services agreements. MRR is the primary financial metric for MSPs because it represents the stable, compounding revenue base that makes the managed services model economically attractive. MRR growth is a function of new client acquisition and retention; MRR decline is a function of churn.
N
NOC (Network Operations Center)
The function within an MSP that monitors client environments continuously, watching for alerts, anomalies, and performance issues that require attention. A NOC is distinct from a helpdesk: the helpdesk responds to user-reported problems, the NOC proactively identifies problems before users report them. In smaller MSPs, these functions are often combined; in larger MSPs, they are separate teams.
O
Owner Bottleneck
The condition in which an MSP’s growth is limited by the owner’s personal capacity. Because decisions, client relationships, and operational knowledge are concentrated in the owner rather than distributed across the team and documented in systems. The owner bottleneck is the most common growth constraint for founder-led MSPs. The solution is systematization: documenting processes, building decision frameworks, and developing team members who can operate at the owner’s standard without requiring the owner’s constant involvement.
P
Post-Mortem
A written review of a significant incident that captures what happened, why it happened, and what changes as a result. A blameless post-mortem focuses on system failures rather than individual mistakes. Post-mortems are one of the most powerful trust-building tools available to MSPs: a client who receives a clear, honest post-mortem after an incident is a client who understands that their MSP learns from failure rather than hiding it.
PSA (Professional Services Automation)
The software platform that MSPs use to manage tickets, client records, contracts, billing, and documentation. Common PSA platforms include ConnectWise Manage, Autotask, and HaloPSA. The PSA is the operational backbone of an MSP: if the documentation, the ticket history, and the client environment records are not in the PSA, they effectively do not exist.
R
Ransomware
Malicious software that encrypts a victim’s files and demands payment for the decryption key. Ransomware attacks have become more sophisticated and more targeted: modern ransomware crews conduct reconnaissance before deploying the encryption, exfiltrate data before encrypting it (to enable double extortion), and specifically target backup repositories to prevent recovery. The defense requires layered security controls, not just backup.
Recovery Point Objective (RPO)
The maximum acceptable amount of data loss in the event of a disruption, measured in time. An RPO of four hours means the business can tolerate losing up to four hours of data. RPO drives backup frequency: if the RPO is four hours, backups must run at least every four hours.
Recovery Time Objective (RTO)
The maximum acceptable time to restore operations after a disruption. An RTO of eight hours means the business must be operational within eight hours of an incident. RTO drives disaster recovery architecture: the faster the required recovery, the more investment is required in redundant systems and tested recovery procedures.
RMM (Remote Monitoring and Management)
The software platform that MSPs use to monitor client endpoints and networks, deploy patches, run scripts, and provide remote support. Common RMM platforms include NinjaRMM, ConnectWise Automate, and Datto RMM. The RMM is the operational tool that makes proactive managed services possible. But it is only as effective as the alerting configuration and the human review process behind it.
Runbook
A documented procedure for responding to a specific type of incident or operational scenario. A runbook is more specific than an SOP: where an SOP defines how to perform a recurring task, a runbook defines how to respond to a specific situation, server down, ransomware detected, backup failure, network outage. A good runbook is a decision tree that gets the right person doing the right thing in the first ten minutes of a crisis.
S
Shadow AI
The use of AI tools by employees without IT department approval or oversight. Shadow AI is the AI equivalent of shadow IT: employees use tools that solve their immediate problems without considering the data privacy, security, or compliance implications. Research suggests that 80% of employees use AI tools their IT department has never approved. Shadow AI is not a future risk. It is a current exposure in most organizations.
SLA (Service Level Agreement)
A contractual commitment that defines the level of service a client can expect from their MSP, including response times, resolution times, uptime guarantees, and escalation procedures. An honest SLA is a commitment the MSP can actually keep. An SLA that promises response times the MSP cannot consistently deliver is not a service commitment. It is a marketing document that creates liability.
SOP (Standard Operating Procedure)
A documented, step-by-step procedure for performing a recurring task. SOPs are the building blocks of operational consistency: they allow any trained technician to perform a task at the same standard, regardless of their individual experience or familiarity with a specific client. SOPs are what make delegation possible, you cannot hand off a process that has never been written down.
T
Technology Roadmap
A multi-year plan that connects a client’s IT investments to their business goals. A technology roadmap answers three questions: where is the technology environment today, where does it need to be in 12 to 36 months, and what specific investments in what order will close that gap. The technology roadmap is the vCIO’s primary deliverable and the primary proof of strategic value in the MSP relationship.
V
vCIO (Virtual CIO)
A strategic IT advisor who provides the guidance of a Chief Information Officer to a business that does not have a full-time technology executive on staff. See: What Is a vCIO?
Vendor Neutrality
The practice of recommending technology solutions based on what is best for the client rather than what generates the best margin for the MSP or the best commission for the advisor. Vendor neutrality is the foundation of the vCIO fiduciary standard. An MSP that earns vendor incentives on the products it recommends cannot be fully vendor-neutral. The financial relationship creates a structural conflict of interest, regardless of the advisor’s intentions.
This glossary is maintained by Rewired MSP. Terms are defined based on how they are used in practice in the managed services industry, with a focus on what MSP owners and business owners need to understand to make better decisions.
About Brent Lacy: Brent Lacy is a technology advisor and the voice behind Rewired MSP. He is the author of Rewired MSP: Mastery, Scalability & Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.