Skip to main content
Mako Logics

Blog / Buyer's Guide

A Week Inside Mako: What Your Houston MSP Actually Does All Day

·5 min read
ShareLinkedInEmail

Most business owners have no idea what their MSP does between invoices. That's not a criticism — you're running a law firm, a CPA practice, a refinery contractor, or a construction shop. You shouldn't have to know. But when the monthly bill lands, "managed IT services" reads like a black box, and it's fair to want a look inside.

Here's an honest walk-through of a real week at Mako, working for real Houston clients. Names of clients are omitted, but the work is exactly what an outsourced IT team should be doing for you.

Monday — the week starts before you get to the office

By 7:00 AM Monday, our overnight and weekend automation has already produced a queue. Not tickets from users — a queue of things we look at before users are awake.

  • Patch reports from Sunday night. Which servers took the Windows cumulative update cleanly, which ones rebooted twice, which one at a Sugar Land client's back office is still pending because the vendor's ERP won't tolerate a specific KB. That last one becomes a conversation with the vendor, not a silent skip.
  • Backup verification. Every Veeam and immutable-copy job from the weekend gets checked. Not "did it turn green" — we look at job duration, deduplication ratio, and any file-lock warnings. A backup that finished 40% faster than last week is usually a problem, not a win.
  • EDR alerts from SentinelOne and Huntress overnight. Most are noise — a PowerShell script a controller ran to reconcile bank feeds. Some are not. The ones that aren't get triaged before 8am.

By the time the client's front desk unlocks the door, roughly 40 items have been touched. Zero of them will show up on a monthly report as "tickets," because a ticket only exists when something breaks. This is the 90% you don't see.

Monday afternoon is usually a client business review — a scheduled sit-down with an office manager or partner at a Woodlands law firm or an Energy Corridor engineering shop. Not a sales call. We walk through the last month, upcoming renewals, and whatever's on their roadmap. This is where strategic IT actually lives.

Tuesday — onboarding, offboarding, and the boring stuff that saves you later

Tuesdays tend to be onboarding-heavy. A new hire at a CPA firm starts next Monday, which means today:

  • M365 license provisioned, MFA enforced, conditional access policy applied to the accounting group.
  • Laptop imaged with the firm's standard build — SentinelOne, Huntress agent, the tax software the firm uses, printer drivers for the office they'll sit in.
  • Access to the file shares that match their role, not the "all staff" bucket that a lazy MSP would default to.
  • IRS Publication 4557 Written Information Security Plan updated to reflect the new user. Yes, that document has to stay current. See our CPA and accounting page for why.

Offboardings run the same day. When a paralegal leaves a Galleria law firm, the clock on disabling her account, revoking her MFA tokens, forwarding her mailbox to her supervisor, and pulling her laptop out of Autopilot is measured in minutes, not days. We've cleaned up after the alternative more than once.

Wednesday — the middle of the week is the maintenance day

Wednesdays are the day we do the work that nobody schedules but everyone needs.

  • Firewall rule review. A construction client running Procore from three job trailers had a rule opened up two years ago for a subcontractor who's long gone. It gets closed.
  • Restore tests. Backups that aren't tested aren't backups. Once a month, per client, we pull a random file, a random VM, and (for the healthcare practices on HIPAA managed IT) a full Athena or eClinicalWorks database restore into an isolated sandbox. Documented RTO, documented RPO, dated screenshot.
  • Admin account audits. Who has domain admin? Why? When did they last use it? A quarter of the security incidents we've cleaned up in 25 years traced back to a stale privileged account nobody was watching.

None of this generates a user-visible event. Done well, it prevents the events that would.

Thursday — on-site day for Houston and the Woodlands

Remote is the default. Roughly 85% of what a modern MSP does is better done remotely, faster, and with a full audit trail. But some work is genuinely on-site work, and Thursdays are usually when our engineers are in trucks.

What actually needs a person on the floor:

  • New workstation deployment at a Woodlands medical practice — physical setup, dual monitors, label printer, badge reader for the EHR.
  • Network closet work — a failed switch at an Energy Corridor tenant space, a UPS battery replacement at a Sugar Land CPA firm, structured cabling for a new conference room.
  • Ship Channel and refinery contractor sites where site access is governed by TWIC and the operator's own vetting platform. Some of this work simply can't be done by a remote hand.

For colocation clients whose gear sits in the Westland Bunker, "on-site" means our engineers who already work inside the facility. That's a different model — same-day hands on hardware without dispatching a truck.

Friday — the 3am call you hope never comes

Fridays are quiet until they aren't. Ransomware crews prefer weekends, and so do disgruntled ex-employees. When a call comes in at 3am — and we've taken plenty over 25 years — the work looks like this:

  1. Isolate. Yank the affected endpoints off the network via SentinelOne, kill the compromised M365 sessions, rotate the tokens.
  2. Assess. What was touched, what wasn't, what does the backup posture look like right now.
  3. Communicate. The owner gets a phone call, not an email. Legal counsel gets looped in. If PHI or CJI is in scope, the compliance clock starts, and we know what §164.408 requires.
  4. Restore. From the immutable copies we tested on Wednesday.

Most of our clients have never taken this call. That's the point of everything Monday through Thursday.

How to tell if your current MSP is actually doing this

Pull your last monthly report and look for these specifics:

  • Patch compliance percentage by system, not a green checkmark.
  • Backup job outcomes with restore-test dates, not just "backups running."
  • EDR/MDR alert volume — alerts received, alerts triaged, alerts escalated.
  • Ticket-to-proactive ratio. If 100% of the work billed is reactive tickets, you're not paying for management, you're paying for a help desk.
  • Named engineer time on your account each month.

If your report is a one-page PDF that says "everything is fine," that's not a report. That's a receipt.

Where this fits

ShareLinkedInEmail

Talk through your situation.

The articles cover the general shape. Your specific situation deserves a real conversation.

Related

Keep reading.