
Before hiring a managed IT provider, a 15–30 employee nonprofit in Victoria should evaluate at least five areas: nonprofit experience, pricing, support, cybersecurity, and strategic guidance.
Price matters, but it rarely tells you enough on its own. Managed IT support for an organization this size may fall somewhere around $75–$150 per person per month, depending on the technology environment, cybersecurity requirements, and services included. Two providers can quote similar monthly prices while offering very different levels of support.
A better comparison starts with understanding what you are actually getting, how your team will be supported, and whether the provider understands the way your organization operates.
Does the IT Provider Actually Understand Nonprofits?
Plenty of IT companies can work with a nonprofit. That is different from having experience with the realities nonprofits deal with every day.
Technology decisions may need to fit an annual budget approved months in advance. A new project might depend on grant funding. Staff, volunteers, contractors, and board members may all need different levels of access. There may also be nonprofit pricing available for software your organization already uses.
Before choosing a provider, ask:
- How many nonprofits or charities do you currently support?
- How long have you worked with the sector?
- How do you account for nonprofit budgeting and approval processes?
- Can you help us identify nonprofit technology programs and discounts?
- Can you show us an example of working with an organization similar to ours?
Listen for specifics rather than a general claim that the provider "works with nonprofits."
For example, The Human IT Company has supported charities, nonprofits, associations, and other mission-driven organizations across BC for years, with charities and nonprofits becoming a deliberate focus of the business in 2012. That experience matters because good IT recommendations have to work within the organization's operational and financial reality, not just make sense technically.
A provider should be able to explain how its experience changes the advice it gives you.
What Exactly Is Included in the Monthly Price?
Once you know the provider understands your type of organization, the next step is making the quote understandable.
A monthly price of $75–$150 per person can include a fairly comprehensive managed IT service, or it can leave several important services outside the agreement. The only useful comparison is one that looks at the scope behind the number.
When reviewing quotes, build a simple table like this:
| Service | Included | Extra Charge | Not Provided |
|---|---|---|---|
| Help desk support | ☐ | ☐ | ☐ |
| Onsite support | ☐ | ☐ | ☐ |
| Device management | ☐ | ☐ | ☐ |
| Microsoft 365 management | ☐ | ☐ | ☐ |
| Cybersecurity | ☐ | ☐ | ☐ |
| Backup and recovery | ☐ | ☐ | ☐ |
| System monitoring | ☐ | ☐ | ☐ |
| Strategic IT planning | ☐ | ☐ | ☐ |
Then dig one level deeper.
If cybersecurity is included, what does that actually cover? If onsite support is included, is there a travel charge? If Microsoft 365 is managed, are license costs included or billed separately? If backup is included, what is being backed up?
The goal is not necessarily to find the provider with the longest list. It is to understand what your monthly payment takes care of and what could still create an additional bill.
For a small nonprofit with a tightly managed operating budget, that predictability can be just as important as the headline price.
What Happens When Someone Actually Needs Help?
Most managed IT proposals look fairly similar when everything is working.
The difference becomes much easier to see when someone cannot log in five minutes before a meeting, a laptop stops connecting, or an employee is unable to access a file they need to finish a funder report.
That is why support should be evaluated as an actual employee experience, not just a line on a proposal.
Ask the provider:
- How does an employee request support?
- Who answers when they call?
- What are your regular support hours?
- How are urgent problems handled?
- Do you provide onsite IT support in Victoria?
- What response commitments do you make?
- How do you decide which issues are handled first?
- Will your technicians explain the problem in language our employees can understand?
Pay particular attention to measurable answers.
"We respond quickly" does not tell you very much. "We aim to respond within one business hour for most issues" gives you something you can evaluate.
At Human IT, for example, the published target is to respond within one business hour for most issues, with immediate attention when an issue is stopping the team from working. The company also provides 24/7 system monitoring so potential technical problems are not limited to the hours when someone happens to be sitting at a help desk.
The other half of support is how people are treated once someone responds.
An employee should not finish an IT call more confused than when they started it. For organizations without internal technical staff, the ability to explain what happened, what was fixed, and what the employee needs to do next is part of the service.
How Will the MSP Protect the Organization?
Cybersecurity can quickly become one of the hardest parts of comparing managed IT providers because every proposal seems to contain a different collection of products, tools, and acronyms.
A simpler approach is to look at security in five layers: people, identities, devices, data, and recovery.
People
Technology cannot prevent every mistake, so employees need to understand the risks they are likely to encounter.
Your provider should be able to help with areas such as security awareness, phishing, suspicious email, safe technology practices, and what employees should do when something does not look right.
Identities
A password should not be the only thing standing between an attacker and an employee's account.
Ask how the provider handles multi-factor authentication, account permissions, administrator access, password practices, and employee onboarding and offboarding.
For nonprofits with staff, volunteers, contractors, and board members accessing systems in different ways, access management needs particular attention.
Devices
Every laptop, desktop, and mobile device that connects to organizational information creates another place that needs to be managed.
Your MSP should have a process for keeping supported devices updated, monitored, configured appropriately, and protected against common threats.
It should also be clear what happens when someone uses a personal device or works remotely.
Data
Ask what is being done to protect the information your organization relies on.
That may include documents in Microsoft 365, financial records, program information, donor data, staff records, and information stored in specialized applications.
Protection should cover more than where the data is stored. Your provider should also help you think about who can access it, how it is shared, how long it is retained, and how it is backed up.
Recovery
Even good security cannot make risk disappear completely.
Ask what happens if a file is deleted, an account is compromised, a computer fails, or a larger incident affects the organization.
Your provider should be able to explain what is backed up, how restoration works, who becomes involved during an incident, and how the organization gets back to work.
Taken together, these five layers give you a much more useful cybersecurity conversation than simply asking whether "security is included."
Will the Provider Help Us Plan, or Just Fix Things?
There is one question that can reveal a lot about the relationship you are being offered:
What happens after our immediate IT problems are fixed?
For a 15–30-person nonprofit, managed IT should eventually become less about individual problems and more about keeping technology aligned with where the organization is going.
A useful planning process generally moves through five stages:
Current-state assessment → risk priorities → technology roadmap → annual budget → scheduled reviews
The current-state assessment gives everyone a clear understanding of the equipment, systems, security, licensing, and existing problems.
From there, the provider should help separate what genuinely needs attention from what can wait. That matters when an organization cannot reasonably replace every aging device or tackle every improvement at once.
Those priorities can then become a technology roadmap. Hardware replacements, Microsoft 365 changes, security projects, software needs, and other improvements can be planned instead of arriving as unrelated surprises throughout the year.
The roadmap should also connect to an annual budget. If several laptops are approaching replacement age next year, leadership should know about that before next year's budget has already been approved.
Finally, the plan should be revisited regularly. Technology changes, staff change, programs grow, funding shifts, and priorities move with them.
When talking to a potential MSP, ask how often technology planning happens, who participates, what timeframe the provider plans against, and what you actually receive afterward. You should leave those conversations with clearer priorities and decisions, not simply another technical report to file away.
Look for Evidence, Not Just Promises
By the time you have worked through these five areas, you should have a much clearer picture of each provider.
The final step is checking whether their claims can be backed up.
Look for things such as:
- A documented history working with nonprofits and charities
- Existing clients with similar needs
- Local or Victoria-area support capability
- Relevant technical certifications and technology partnerships
- Testimonials or case studies from nonprofit clients
- Published service commitments or measurable response statistics
For Human IT, nonprofit and charity support has been a deliberate focus since 2012, backed by experience with mission-driven organizations across British Columbia. That includes organizations in the Victoria area, along with support for staff working in different locations throughout the province and across Canada.
The company's existing nonprofit clients also provide a useful kind of evidence: not simply that their computers were fixed, but that the provider understood nonprofit-specific needs, helped identify appropriate technology options, and explained technical issues in a way employees could understand.
Those are much more meaningful signals than a long list of promises on a proposal.
Choose the Provider You Can Understand
Hiring a managed IT provider is not just a decision about who fixes computers.
You are choosing who your employees will call when they are stuck, who will help protect organizational information, who will advise you when a technology decision needs to be made, and who will help you plan for costs that may not arrive until next year.
That makes the comparison fairly straightforward. Look at nonprofit experience, what the price actually includes, the support experience, cybersecurity coverage, and the quality of ongoing planning.
A good provider should be able to give you clear answers in all five areas without making you learn another language just to evaluate the proposal.
If you want to see what a more people-focused approach to managed IT looks like, see how The Human IT Company works with mission-driven organizations.

