In a lot of UAE small businesses, IT is a job nobody was ever given. The operations manager resets passwords because she is good with computers. The founder's cousin comes in on a Saturday when the file server stops. Somebody set up the wifi in 2019 and nobody has touched the router since.
That arrangement is not stupid. It is cheap, it is quick, and it works for a surprisingly long time. This guide is about the point where it stops working, and about the three ways of buying IT support that sit above it.
It also says something up front that most guides on this subject will not. The honest sequence is break-fix, then block hours, then a managed contract, and plenty of small businesses genuinely do not need the last one yet. If that is you, we would rather tell you than sell you a retainer.
One clarification before anything else, because these two things get searched with the same words. Our helpdesk software guide is about software for supporting your customers: shared inboxes, ticketing, WhatsApp. This guide is about supporting your own staff and your own systems: laptops, patching, backups, accounts, wifi. Different buyer, different budget, different failure modes. If you came looking for the customer side, that other article is the one you want.
We set up and support business systems for UAE companies from our Dubai and Bengaluru teams [15]. We are not lawyers and none of this is legal advice.
The three ways to buy IT support
Break-fix. You call somebody when something breaks and you pay for that visit or that fix. No retainer, no standing relationship. The cost is lumpy and hard to forecast, and nothing in the arrangement pays anyone to prevent the next problem.
Block hours. You pre-pay for a bundle of hours, commonly ten or twenty a month, and draw them down. You get better rates than ad hoc calls and a provider who already knows your setup. What you do not get is a change in incentive. The provider is still paid for hours worked, not for the incident that never happened.
A managed contract. A flat recurring fee, usually per user or per device per month, covering ongoing monitoring, patching, a helpdesk for your staff, and normally backup and security tooling too, under a written scope with service targets. Here the incentive flips. Fewer incidents means better margin for the provider, which is the real structural argument for the model.
None of these three terms is defined by a government body or a standards organisation. They are commercial vocabulary. The closest formal reference points are ISO/IEC 20000-1, the international standard for service management systems [5], and the ITIL practice framework, which defines the service desk as the single point of contact between a service provider and its users for incident resolution and service requests [4]. Neither tells you which commercial model to buy.
The trigger is not headcount
Businesses usually assume they will know it is time because they have hit some number of staff. That is the wrong signal. Plenty of twenty person offices run comfortably on break-fix, and plenty of six person offices are one laptop failure away from a very bad fortnight.
The real trigger is when nobody can answer three questions without guessing.
- Who patched what, and when? Not the policy. The evidence. If nobody can show you which machines are current and which are two versions behind, patching is not happening, it is being assumed.
- Where are the backups, and when did somebody last restore one? A backup nobody has ever restored is a hope. Ask what was restored, when, and whether it opened.
- Does the person who left last month still have access to anything? Every system, not just email. Shared logins count. If the answer is a pause, you already have your answer.
If those three come back clean, you do not have a managed IT problem, and buying a contract will mostly buy you an invoice. If any of them makes the room go quiet, that is the moment, whether you have four staff or forty.
None of the three questions is about volume. They are about whether anybody is accountable. A business can pay for plenty of IT hours and still have nobody who owns the outcome.
What a managed contract actually covers
Scope varies enormously between providers, which is precisely why it needs to be written down. The usual line items:
- Staff helpdesk. One route for employees to raise problems and requests, instead of messaging whoever they think might know. ITIL calls this the service desk and treats it as the single point of contact [4].
- Device management and patching. Central configuration, updates and security settings across every laptop, desktop and phone. CISA guidance for small businesses treats automatic updates as one of the most cost-effective steps available [8].
- Backup and tested recovery. Not the existence of backups. The proven ability to restore.
- Email and identity administration. Provisioning, mailbox setup, access rules, and the unglamorous work of removing accounts.
- Network and wifi. Firewall and router configuration, coverage, and keeping guest wifi genuinely separate from business systems.
- Security tooling. Endpoint protection, multi-factor authentication enforcement, email authentication records. NIST publishes small business guidance on multi-factor authentication specifically [7], and CIS publishes an Implementation Group 1 control set aimed at exactly this size of organisation [9].
- Licence management. Tracking what you own, who holds it and when it renews. Unused seats are pure waste and nobody notices them.
- Onboarding and offboarding. Day one accounts for a new starter, and same-day removal for a leaver.
- Asset tracking. A live inventory of devices and who has them.
Offboarding deserves singling out. It reads like an administrative chore and it is actually a security control. A departed employee's live account is trusted, forgotten and unwatched. Put a revocation turnaround in the contract and treat it as testable.
Hiring instead of contracting
An in-house hire is a legitimate answer and sometimes the right one. Be honest about what it covers. It is a fixed cost of salary plus visa, insurance and gratuity accrual, payable in quiet months as well as busy ones, and one person cannot cover helpdesk, patching, backups, network and security at once. When they are on leave, nobody is behind them.
A contract converts that into a variable cost with a team behind it, at the price of less physical presence in your office. Many growing businesses end up with both: one internal person who knows the business, and a contract covering the specialist and out-of-hours work behind them. That hybrid is usually cheaper than a second hire.
How to read the SLA
Response and resolution are two different clocks. Response measures how long until somebody acknowledges the issue. Resolution measures how long until it is fixed. They fail for different reasons. Slow response is usually routing or staffing. Slow resolution is usually process, or a dependency on somebody outside the support team. Report them together and you hide both.
Priority levels need to exist. ITIL frames incident priority as urgency combined with impact [4]. A whole office unable to work is not the same as one person wanting a second monitor. A single blanket response target for every issue is a weak contract, because in practice everything becomes urgent or nothing does.
Translate uptime into minutes. Around 99.9 percent allows roughly forty three minutes of downtime a month. Around 99.5 percent allows about three hours and thirty nine minutes. Two numbers that look nearly identical on a slide, one of which is a bad afternoon.
Treat SLA credits as a signal, not insurance. A credit is a discount on your fee if the provider misses its own target. If a missed target costs you a day of trading, a slice of one month's fee does not make you whole. There is no standard percentage, so read the credit as a measure of how confident the provider is in the numbers they just gave you.
Get these in writing: the working hours calendar the clock runs against including public holidays, separate response and resolution targets per priority, a plain definition of resolved, a named escalation path, the reporting you get to verify performance, the leaver access revocation turnaround, and how often restores are tested with evidence.
Coverage, the working week and Ramadan
Coverage is where UAE contracts quietly go wrong. It is worth being precise here.
The official UAE government portal states that standard private sector working hours are eight hours a day or forty eight hours a week under Article 17 of the labour law, with an entitlement to a break after five consecutive working hours [2]. Separately, federal government entities moved to a Monday to Thursday week with a half day on Friday and a Saturday to Sunday weekend from 1 January 2022 [3]. That second rule is a public sector one and should not be read across to private companies.
The practical consequence for a support contract is simple. Do not assume your provider's working calendar matches yours. Many private businesses now run a Monday to Friday pattern, but plenty do not, and businesses with retail, logistics or hospitality operations often need weekend cover that an office-hours contract will not give them. Ask which days and hours the clock runs, and what happens outside them.
Ramadan is the specific case people forget. Private sector working hours are reduced by two hours a day during Ramadan, according to the same government portal [2]. If the support contract's clock keeps running on the ordinary calendar for that month, targets get missed for reasons that have nothing to do with performance. Agree it in writing before the month starts.
Security is where this stops being an admin question
Managed IT support is largely the delivery mechanism for a security baseline you probably already know you should have. Our small business cybersecurity guide sets out that baseline properly, so this guide will not restate it. NIST publishes a cybersecurity framework that most of it maps onto [6], and the UAE Cyber Security Council is the national authority for the country's cyber security strategy [14].
The point worth making here is about who does the work. Multi-factor authentication, patching, endpoint protection and least-privilege access are not hard to understand. They are hard to sustain when nobody owns them. That is the actual product you buy with a managed contract: not the controls, but the accountability for them still being true in month nine.
Be clear about what the contract is not. It is not a penetration test, which is a one-off technical assessment. It is not ISO 27001 certification, which is a formal management system with an external audit. A well-run managed contract makes both easier later. It replaces neither.
Your data, your provider and where backups live
If a provider administers your systems, they touch your staff and customer data. The UAE personal data protection law, Federal Decree-Law No. 45 of 2021, has been in force since 2 January 2022 and applies to the processing of personal data through electronic systems, inside or outside the country. The official government portal states that organisations must secure personal data and maintain its confidentiality [1]. Our PDPL compliance guide covers the detail.
What that means practically for a support contract is a short list of things to ask for: a written arrangement covering the fact that they process your data on your instructions, clarity on where backups and administrative data live, who on their side can access your systems and how, and a commitment to tell you immediately if they become aware of a breach.
On location, the options are real rather than theoretical. AWS opened a Middle East region in the United Arab Emirates, me-central-1, with three Availability Zones, in August 2022 [11]. Microsoft lists UAE North in Dubai and UAE Central in Abu Dhabi as Azure regions [12]. Keeping backups in country is available if you want it. Whether it is necessary for your situation is a question for a qualified adviser rather than an article, and our cloud migration guide covers the residency decision in more depth. The thing to avoid is not knowing the answer.
What managed IT support costs
No government body, standards organisation or official vendor publishes managed IT support pricing. It is a competitive commercial price set contract by contract, and the numbers you will find on provider marketing pages are advertising rather than a survey. So we will give you ours and label it as ours.
With us, managed IT support starts from around AED 100 per user a month, and a small business contract typically starts from around AED 1,500 a month once a minimum applies. That is our own figure, not a market rate. Final pricing depends on scope.
It helps to see that against our other recurring figures. Website maintenance starts from around AED 150 a month. Mobile app maintenance starts from around AED 500 a month. A helpdesk software setup starts from around AED 2,500 as a one-off engagement. Each of those covers one system. A managed IT contract covers the estate: every device, every account, the network, the backups and the security baseline underneath them.
Two things sit outside the support fee. Software licences are separate: Microsoft's own plan comparison shows device management through Intune and its advanced threat protection sitting on the Business Premium tier rather than the entry plans [10], and published prices vary by region and change, so read that page live from a UAE session rather than trusting a figure in an article. And VAT is separate: the Federal Tax Authority publishes the UAE standard rate as five percent, applying to services [13]. Ask any provider whether their quote is before or after tax.
Real client stories
These are anonymised situations from work we have done.
The contract they did not need. A twelve person consultancy asked us to quote for full managed IT because a client had asked about their security arrangements. We ran the three questions. They knew which machines were current, somebody had genuinely restored a file that quarter, and the one person who had left had been removed properly. We did not quote a contract. We tightened multi-factor authentication, wrote a one page offboarding checklist, and told them to call us when any of the three answers stopped being clean.
The backups that had been failing since February. A trading company had a backup job with a green tick on the dashboard. Nobody had opened a restored file in over a year. When we tested one, the job had been silently excluding the folder that mattered most since a server change months earlier. The fix cost almost nothing. Only a restore test would ever have found it, and no restore test was going to happen while backups belonged to whoever was least busy.
The accounts that never closed. A retail business with three locations could not tell us how many staff accounts were active. When we counted, several belonged to people who had left, one of them with administrative rights, and two shared logins were in use across all three branches. Nothing had gone wrong yet. The remediation was ordinary: individual accounts, least privilege, and a same-day revocation step written into the support scope so it was somebody's job rather than somebody's memory.
How SKIMBOX approaches IT support
We start with the three questions, not a proposal. If your answers are clean, we will say so and we will not push a retainer at you. We would rather have that conversation than the one where you cancel in month four.
If the answers are not clean, we scope from what is actually failing. Usually that is patching, restore testing and access removal, because those are the three that go quiet without anyone noticing. We write the scope in plain language, put the working hours calendar and the Ramadan adjustment in the contract rather than in an email, and state a revocation turnaround you can hold us to.
We report on our own performance in a form you can check, because self-reported numbers with nothing underneath them are not evidence. And we keep the boundary honest: a managed contract is operational delivery, not a certification and not a security audit. Where something turns on UAE legal obligations, that goes to a qualified adviser, not to us.
Managed IT support starts from around AED 100 per user a month, with a small business contract from around AED 1,500 a month once a minimum applies. Final pricing depends on scope.
See our core business operations services and cybersecurity services, or contact us to talk through what you actually need. Our digital transformation guide for UAE SMEs covers how these decisions fit alongside everything else.
References
[1] U.AE Official UAE Government Portal - Data protection laws. u.ae/en/about-the-uae/digital-uae/data/data-protection-laws
[2] U.AE Official UAE Government Portal - Working hours and overtime, private sector. u.ae/en/information-and-services/jobs/employment-in-the-private-sector/working-hours
[3] U.AE Official UAE Government Portal - Working hours in the public sector. u.ae/en/information-and-services/jobs/working-in-uae-government-sector/working-hours-in-the-public-sector
[4] Axelos - ITIL 4 Practitioner: Service Desk. axelos.com/certifications/itil-service-management/itil-practices-manager/itil-4-specialist-monitor-support-and-fulfil/itil-4-practitioner-service-desk
[5] ISO - ISO/IEC 20000-1:2018, Information technology, Service management, Part 1: Service management system requirements. iso.org/standard/70636.html
[6] NIST - Cybersecurity Framework. nist.gov/cyberframework
[7] NIST - Multi-factor authentication guidance, Small Business Cybersecurity Corner. nist.gov/itl/smallbusinesscyber/guidance-topic/multi-factor-authentication
[8] CISA - Cyber guidance for small businesses. cisa.gov/cyber-guidance-small-businesses
[9] CIS - Critical Security Controls, Implementation Group 1. cisecurity.org/controls/implementation-groups/ig1
[10] Microsoft - Microsoft 365 Business plans and pricing. microsoft.com/en-us/microsoft-365/business/microsoft-365-plans-and-pricing
[11] AWS - Now open: AWS Region in the United Arab Emirates. aws.amazon.com/blogs/aws/now-open-aws-region-in-the-united-arab-emirates-uae/
[12] Microsoft Azure - Global infrastructure, geographies. azure.microsoft.com/en-us/explore/global-infrastructure/geographies/
[13] Federal Tax Authority, UAE - Value Added Tax. tax.gov.ae/en/taxes/vat.aspx
[14] UAE Cyber Security Council. csc.gov.ae
[15] SKIMBOX - Internal experience setting up and supporting business systems for UAE companies, 2026. skimbox.co



