Skip to content
Borg ITS

Answers

Managed IT, answered — 100 common questions

Plain-language answers to the questions Ontario businesses ask us most, across managed IT, cybersecurity, Microsoft 365, cloud, backup, and compliance.

Managed IT Services

How managed IT works, what it costs, and what to expect from an MSP.

What is a managed IT services provider (MSP)?
A managed IT services provider (MSP) runs and supports a business's technology for a fixed monthly fee — covering helpdesk support, monitoring, cybersecurity, backups, and IT strategy — so the business avoids downtime and unpredictable costs.
What does an MSP do?
An MSP monitors and maintains your systems, resolves support issues, manages security and backups, and provides IT strategy and budgeting. It effectively acts as your outsourced IT department.
How much do managed IT services cost in Ontario?
Most Ontario SMBs pay a predictable monthly fee per user that scales with headcount. Borg ITS publishes transparent pricing starting at $59.99/month, with no hidden project fees and a 60-day money-back guarantee.
What is the difference between managed IT and break/fix support?
Break/fix charges you each time something breaks, which rewards downtime. Managed IT is a flat monthly fee focused on preventing problems, so costs are predictable and systems stay healthy.
What is co-managed IT?
Co-managed IT supports an existing internal IT team rather than replacing it — adding helpdesk overflow, after-hours coverage, specialist expertise, and enterprise tooling while your staff keep ownership.
What is included in a managed IT contract?
A typical managed IT contract includes 24/7 helpdesk support, proactive monitoring and patching, endpoint management, cybersecurity, backups, and IT strategy — all for a fixed monthly per-user fee.
How fast should an MSP respond to support requests?
A good MSP commits to a defined response-time SLA. Borg ITS guarantees a 20-minute response, backed by a 24/7 helpdesk and senior engineers on first contact.
What is an SLA in managed IT?
A Service Level Agreement (SLA) is a written commitment to specific response and resolution times. It turns 'we'll get to it' into a measurable, accountable promise.
What is a virtual CIO (vCIO)?
A virtual CIO provides strategic IT leadership — technology roadmaps, budgeting, risk management, and business reviews — without the cost of a full-time executive hire.
How do I choose a managed IT provider?
Look for a published response-time SLA, transparent pricing, strong security included by default, local references, and documented onboarding. Avoid providers that won't commit to response times in writing.
What size of business needs an MSP?
Businesses from roughly 5 to 250 employees benefit most from an MSP — large enough to depend on technology, but without the budget for a full in-house IT team.
What is proactive IT maintenance?
Proactive maintenance uses 24/7 monitoring and automated patching to catch and fix issues — failing drives, unpatched vulnerabilities, full disks — before they cause downtime.
What is remote monitoring and management (RMM)?
RMM is the software an MSP uses to monitor, manage, and patch your devices and servers remotely, enabling problems to be detected and resolved before you notice them.
Can an MSP support remote and hybrid teams?
Yes. A modern MSP secures and supports laptops, mobile devices, and cloud apps wherever staff work, using endpoint management, VPN or zero-trust access, and cloud collaboration tools.
How long does it take to onboard with an MSP?
Onboarding typically takes a few weeks: the MSP documents your environment, deploys monitoring and security tooling, and standardizes configurations. Borg ITS runs a structured onboarding so nothing is missed.
What questions should I ask before hiring an MSP?
Ask about response-time SLAs, what's included vs extra, security controls, backup testing, onboarding process, references, and whether support is local and senior-staffed.
What is endpoint management?
Endpoint management is the centralized security and administration of all company devices — laptops, desktops, and mobiles — including configuration, patching, encryption, and remote wipe of lost devices.
What is the typical contract length for managed IT?
Managed IT agreements are often one to three years, though terms vary. Borg ITS focuses on transparent terms backed by a 60-day money-back guarantee rather than locking clients in.

Cybersecurity

The threats facing Ontario businesses and the controls that stop them.

What cybersecurity do small businesses need?
At minimum, small businesses need endpoint detection and response (EDR), email protection, multi-factor authentication, tested backups, and security awareness training — the same controls most cyber-insurance policies require.
Is antivirus enough to protect my business?
No. Traditional antivirus only blocks known malware. Effective protection layers next-gen antivirus with EDR, email security, MFA, and 24/7 monitoring.
What is EDR (endpoint detection and response)?
EDR monitors device behaviour in real time, detects threats that signature-based antivirus misses, and automatically isolates a compromised device before ransomware can spread.
What is the difference between antivirus and EDR?
Antivirus blocks known malware by signature; EDR detects suspicious behaviour in real time and contains threats automatically. EDR is now a baseline requirement for most cyber-insurance policies.
What is multi-factor authentication (MFA)?
MFA requires a second proof of identity — such as a phone app or code — in addition to a password, so a stolen password alone can't grant access.
Why is MFA important?
MFA blocks the vast majority of account-takeover attacks because attackers rarely have the second factor. It is one of the cheapest, most effective security controls available.
What is phishing and how do I prevent it?
Phishing is a fraudulent message designed to trick staff into revealing credentials or installing malware. Prevention combines email filtering, MFA, correct DMARC/SPF/DKIM records, and staff training.
What is business email compromise (BEC)?
BEC is a scam where an attacker impersonates an executive or vendor to trick staff into sending money or data. Impersonation protection, MFA, and payment-verification processes defend against it.
What is ransomware and how do I protect against it?
Ransomware encrypts your data and demands payment. Protection requires EDR, MFA, email security, staff training, and — critically — immutable, tested backups so you can recover without paying.
What is a security awareness training program?
It is ongoing staff training plus simulated phishing tests that measurably reduce click rates over time and satisfy cyber-insurance requirements.
Does cyber insurance require specific IT controls?
Yes. Most Canadian cyber-insurance policies now require MFA, EDR, tested backups, and security awareness training. Without them, claims can be denied or coverage refused.
What is a SOC (security operations centre)?
A SOC is a team and toolset that monitors your environment for threats 24/7 and responds to incidents. Many SMBs access one through their MSP rather than building it in-house.
What is zero trust security?
Zero trust assumes no user or device is automatically trusted. Every access request is verified based on identity, device health, and context — reducing the damage of a stolen credential.
What is a firewall and do I still need one?
A firewall controls traffic between your network and the internet. You still need one, but a modern firewall must be properly configured, monitored, and paired with endpoint and identity controls.
What is DNS filtering?
DNS filtering blocks devices from connecting to known malicious or inappropriate websites at the domain level, stopping many threats before they reach a device.
How often should we run security assessments?
Most businesses should run a security assessment at least annually, and after any major change. Regular assessments identify gaps before attackers or auditors do.
What is penetration testing?
Penetration testing is an authorized simulated attack on your systems to find exploitable weaknesses before real attackers do. It is often required for compliance or larger contracts.
What should a small business do after a data breach?
Contain the affected systems, preserve evidence, engage IT and legal/insurance support, assess what data was exposed, and meet any mandatory breach-reporting obligations. An incident response plan makes this faster.
What is the principle of least privilege?
Least privilege means giving each user only the access they need to do their job. It limits the damage if an account is compromised.
How do I secure remote workers?
Secure remote workers with managed, encrypted devices, MFA, zero-trust or VPN access, EDR, and clear policies — so working from anywhere doesn't widen your attack surface.

Microsoft 365

Getting the most security and value from Microsoft 365.

What is Microsoft 365?
Microsoft 365 is a cloud subscription bundling Office apps, Exchange email, Teams, SharePoint, OneDrive, and security and management tools for businesses.
What is the difference between Microsoft 365 and Office 365?
Office 365 referred to the productivity apps and email; Microsoft 365 is the broader bundle that adds security, device management, and Windows licensing in some plans. Microsoft now uses the Microsoft 365 name.
Is Microsoft 365 secure by default?
Not fully. Microsoft 365 includes strong security capabilities, but they must be configured — enabling MFA, conditional access, and secure defaults is essential and often overlooked.
How do I secure Microsoft 365?
Enable MFA for all users, configure conditional access, harden email against phishing, apply data loss prevention, and review admin privileges. Borg ITS configures and monitors these for you.
What is Microsoft 365 Business Premium?
Business Premium is a plan for small and mid-sized businesses that adds advanced security and device management — including Intune and Microsoft Defender — to the standard productivity apps.
Can I reduce Microsoft 365 licensing costs?
Often, yes. A licensing audit frequently finds unused or over-provisioned licenses. Right-sizing plans can lower monthly costs while improving security.
What is SharePoint used for?
SharePoint is Microsoft 365's platform for storing, organizing, and collaborating on documents and building intranet sites, with controlled access across teams.
What is Microsoft Teams?
Teams is Microsoft 365's hub for chat, video meetings, calling, and collaboration, integrated with SharePoint and the Office apps.
Does Microsoft 365 back up my data?
Not in the way most businesses assume. Microsoft replicates data for service availability but recommends a third-party backup to protect against accidental deletion, ransomware, and retention gaps.
What is conditional access in Microsoft 365?
Conditional access enforces security rules based on context — for example, requiring MFA, a compliant device, or a trusted location before granting access.
How do I migrate email to Microsoft 365?
Email migration involves preparing the tenant, syncing mailboxes, and cutting over DNS with minimal downtime. An MSP plans the cutover so no email is lost or delayed.
What is Microsoft Entra ID (Azure AD)?
Microsoft Entra ID, formerly Azure Active Directory, is Microsoft's cloud identity service that manages user sign-in, MFA, and access across Microsoft 365 and connected apps.
What is Microsoft Intune?
Intune is Microsoft's cloud service for managing and securing devices — enforcing policies, deploying apps, and enabling remote wipe of lost or stolen devices.
How do I protect Microsoft 365 from phishing?
Layer advanced email filtering, impersonation protection, MFA, correct DMARC/SPF/DKIM records, and user training. Microsoft Defender for Office 365 adds link and attachment scanning.
What is data loss prevention (DLP)?
DLP automatically detects and restricts the sharing of sensitive data — such as financial or health information — to prevent accidental or malicious leaks.
Can Microsoft 365 meet compliance requirements?
Yes, when configured correctly. Microsoft 365 offers data residency, retention, audit logging, and DLP features that support PHIPA, PIPEDA, and other compliance needs.

Cloud Services

Cloud migration, costs, and security for Ontario businesses.

What is cloud computing?
Cloud computing delivers servers, storage, software, and services over the internet on a pay-as-you-go basis, instead of running them on hardware you own and maintain.
Should my business move to the cloud?
Most SMBs benefit from cloud for email, files, and line-of-business apps — gaining flexibility, resilience, and predictable costs. A readiness assessment determines the right mix of cloud and on-premise.
What is the difference between IaaS, PaaS, and SaaS?
IaaS provides raw infrastructure (servers, storage); PaaS provides a platform to build and run apps; SaaS provides finished software you simply use, like Microsoft 365.
What is Infrastructure as a Service (IaaS)?
IaaS provides servers, storage, and networking as a managed, pay-as-you-go service, letting you replace capital hardware purchases with a predictable operating cost.
How long does a cloud migration take?
A typical SMB cloud migration takes a few weeks, depending on data volume and applications. A readiness assessment and planned cutovers keep downtime to a minimum.
Is the cloud more secure than on-premise?
The cloud can be more secure, thanks to major providers' investments, but security depends on correct configuration. Misconfigured cloud is a leading cause of breaches.
What is a hybrid cloud?
A hybrid cloud combines on-premise systems with public cloud, letting businesses keep some workloads local while using the cloud for others — useful for data residency or legacy apps.
How do I control cloud costs?
Control cloud costs by right-sizing resources, removing unused services, using reserved capacity where appropriate, and monitoring usage. An MSP can optimize and manage spend on your behalf.
What is Microsoft Azure?
Azure is Microsoft's cloud platform offering virtual servers, storage, databases, identity, and hundreds of other services, widely used for hosting business applications and infrastructure.
What is cloud backup?
Cloud backup automatically copies your data to secure offsite cloud storage, protecting it from hardware failure, ransomware, and on-site disasters.
What happens to my data if my internet goes down?
With cloud services, data stays safe in the cloud but access requires connectivity. Businesses mitigate this with redundant internet connections or failover, and offline-capable apps.
What is a private cloud?
A private cloud is cloud infrastructure dedicated to a single organization, offering more control and isolation than public cloud — often chosen for sensitive data or compliance.
How do I choose between Azure and AWS?
Both are strong. Azure often suits Microsoft-centric businesses for its tight integration with Microsoft 365 and identity; AWS has the broadest service catalogue. The right choice depends on your apps and team.
What is cloud disaster recovery?
Cloud disaster recovery replicates your systems and data to the cloud so you can fail over and keep operating if your primary environment goes down.
Is the cloud cheaper than on-premise servers?
The cloud trades large capital purchases for predictable operating costs and removes maintenance overhead. Total cost depends on workloads; well-managed cloud is often more cost-effective for SMBs.

Backup & Disaster Recovery

Protecting your data and keeping the business running through disruption.

What is the difference between backup and disaster recovery?
Backup copies your data so it can be restored; disaster recovery is the broader plan to get systems, connectivity, and operations running again after a major disruption.
What is the 3-2-1 backup rule?
The 3-2-1 rule means keeping three copies of your data, on two different media, with one copy offsite. It is the baseline standard for reliable backup.
How often should we back up our data?
Most businesses should back up critical data at least daily, and more frequently for high-change systems. The right frequency is set by your recovery point objective (RPO).
What is RTO and RPO?
RTO (recovery time objective) is how quickly you must be back online; RPO (recovery point objective) is how much data you can afford to lose. Both drive your backup and recovery design.
How often should backups be tested?
Backups should be tested at least quarterly. An untested backup is unreliable — Borg ITS performs scheduled restore tests and documents recovery times.
What is an immutable backup?
An immutable backup cannot be altered or deleted once written, which makes it resistant to ransomware that tries to encrypt or destroy your backups.
Does Microsoft 365 need a separate backup?
Yes. Microsoft protects its service availability but recommends third-party backup to recover from accidental deletion, ransomware, and retention gaps in email, OneDrive, and SharePoint.
What is business continuity?
Business continuity is the plan and capability to keep operating during a disruption — covering systems, data, connectivity, communications, and recovery procedures, not just backup.
How long does it take to recover from ransomware?
Recovery time depends on your backups and plan. With tested, immutable backups and a defined RTO, critical systems can be restored in hours; without them, recovery can take weeks.
What is a business impact analysis?
A business impact analysis identifies your critical systems and processes and the cost of losing them, so recovery priorities and RTO/RPO targets can be set sensibly.
What is a disaster recovery plan?
A disaster recovery plan documents how to restore IT systems and data after an outage or disaster — including responsibilities, steps, and recovery targets — and is tested regularly.
Where should backups be stored?
Backups should be stored in at least two locations, including one offsite or in the cloud, and ideally in immutable storage to resist ransomware.
What is Backup as a Service (BaaS)?
BaaS is a managed service where a provider handles your backups end to end — automated, monitored, tested, and stored securely offsite — for a predictable fee.
Can we recover individual files or only whole systems?
A good backup solution allows granular recovery of individual files, mailboxes, or folders, as well as full-system restores — so you don't have to rebuild everything for one lost file.
How much does data loss cost a business?
Beyond recovery costs, data loss causes downtime, lost revenue, reputational harm, and potential compliance penalties. For many SMBs, prolonged data loss is an existential risk — which is why tested backups matter.

Compliance

Canadian and Ontario IT compliance, explained in plain language.

What is PHIPA and who does it apply to?
PHIPA is Ontario's Personal Health Information Protection Act. It applies to healthcare providers and organizations that handle personal health information, requiring safeguards for that data.
What is PIPEDA?
PIPEDA is Canada's federal private-sector privacy law governing how businesses collect, use, and disclose personal information in commercial activities.
What IT controls does cyber insurance require?
Most cyber-insurance policies require MFA, EDR, tested backups, security awareness training, and email security. Lacking these can mean higher premiums, denied claims, or refused coverage.
What is SOC 2 and do we need it?
SOC 2 is an audit framework that verifies how a service organization protects customer data. You may need it if you handle clients' data and they require assurance of your security.
What is the difference between compliance and security?
Security is protecting your systems and data; compliance is demonstrating you meet specific legal or contractual requirements. You can be compliant yet insecure, or secure yet non-compliant — you need both.
What is a compliance audit?
A compliance audit is a formal review verifying that your controls and documentation meet a given standard or regulation, often required by regulators, insurers, or enterprise clients.
How do we prepare for a compliance audit?
Prepare by documenting your controls, policies, and evidence; closing known gaps; and ensuring access, encryption, monitoring, and backups are in place and demonstrable. An MSP can assemble the technical evidence.
What is data residency and why does it matter in Canada?
Data residency is the physical location where data is stored. Many Canadian organizations require data to stay in Canada for privacy, contractual, or public-sector reasons.
What records do we need for compliance?
Common requirements include security policies, access logs, training records, backup and test reports, incident records, and evidence of controls like MFA and encryption.
What is PCI DSS?
PCI DSS is the security standard for any business that stores, processes, or transmits payment-card data, defining controls to protect cardholder information.
Do Ontario law firms have IT compliance obligations?
Yes. The Law Society of Ontario expects firms to safeguard client information and manage technology competently, which in practice means encryption, access control, backups, and breach prevention.
What is a written information security policy?
It is a documented set of rules defining how your organization protects its data and systems. Many regulations, insurers, and clients now require one.
What is mandatory breach reporting in Canada?
Under PIPEDA, organizations must report breaches that pose a real risk of significant harm to the Privacy Commissioner and affected individuals, and keep records of all breaches.
How long must we retain business data?
Retention periods vary by data type and regulation — tax, employment, and health records each have their own rules. A retention policy ensures you keep data long enough and dispose of it properly.
What is GDPR and does it affect Canadian businesses?
GDPR is the European Union's privacy regulation. It can apply to Canadian businesses that offer goods or services to, or monitor, individuals in the EU.
How does Borg ITS help with compliance?
Borg ITS implements and documents the technical controls — access control, encryption, MFA, monitoring, and tested backups — and provides the reporting needed to support PHIPA, PIPEDA, cyber-insurance, and audit requirements.

Still have a question?

Ask a senior Borg ITS engineer directly — no sales script, no obligation.

Call usFree assessment