Why Your IT Support Closes When Your Shop Is Busiest

A shop owner phones for help after six in the evening while the card terminal shows an error and the street outside is dark

There is a mobile number saved in your phone for someone technical who might pick up on a weekend, and a quiet agreement with yourself that you will not use it too often. Most people running a shop, a venue or a trade have that number, and most have stopped noticing it. It is doing real work, and it is worth saying out loud, because it means you have been carrying a gap in your IT support as though it were your own fault.

It is not your fault, and it is not yours to keep patching over with goodwill. Your IT support closes when your business is busiest because support hours are a product decision, and the band written into your agreement was almost certainly set to an office week. That one line decides whether anyone answers when the till stops working on a Saturday morning. There is a five-minute check that shows you the gap: write your contracted support hours on one line and your real trading hours underneath. If the two windows do not overlap where your money comes in, that is not an inconvenience you have to live with. It is the till, on a Saturday.

TL;DR: What to remember

  • ✅ Support hours are a product decision, and the default band on most agreements is an office week. If your revenue arrives at night and on the weekend, that default is a poor fit for you.
  • ✅ Run the five-minute check: contracted support hours on one line, real trading hours underneath. The uncovered gap between them is your exposure, measured in hours per week.
  • ✅ After you close, an ordinary fault and the first sign of an attack can look identical. What you are actually buying is someone who can tell them apart before Monday.
  • ✅ Cover that matches your trading hours is a product you can buy. inSUPPORT publishes a Retail tier that runs into Thursday and Friday nights and Saturday morning, because retail came first.

Contents

Where your support week actually stops

Start with the document you already have. Your managed IT agreement states the hours your support is available. Find that clause and write the hours down exactly as they appear, including the days that differ from the rest. Outside those hours you are doing one of three things: paying an after-hours rate, waiting for the next business day, or leaning on somebody's goodwill. The agreement usually tells you which.

Now write your own trading hours next to it, and use the real ones rather than the ones printed on the door. Include the late trade on Thursday, the Saturday morning rush, the Sunday shift at the venue, and the hour after close when someone is still reconciling the day. Those are the hours your systems are carrying money, and they are the only hours that matter in this comparison.

Then hold the two windows side by side. A business-hours-only agreement can leave a seven-day operation with no contracted support across part or all of the weekend, and on the covered days the support often sits over the quieter half of the trading day. None of that is hidden. It is written in the agreement, and the hours clause is one of the least-read lines in it because it reads like boilerplate. The whole exercise takes five minutes and a pen.

  • Find the support hours clause in your current agreement and write the hours down as they appear.
  • Write your actual trading hours underneath, weekends and late nights included.
  • Highlight the hours you trade with no support. That is your exposure, in hours per week.
  • Check what the after-hours rate is, and whether anyone has ever actually used it.

What actually breaks after you close

The failures that hurt a trading business are rarely dramatic. A card terminal loses its connection. The point of sale cannot reach the server that holds pricing. A network link drops at one site and the stock system stops updating. Most of the time these are ordinary faults with quick fixes, and the real cost is the twenty minutes you spend finding someone rather than the fault itself.

The catch is that the same symptoms can be the first visible sign of something far worse. Ransomware, a compromised account or a malicious change to a network can all present as a terminal that will not connect or a system that has gone quiet. You cannot tell which it is from the symptom alone, and that is the argument for reaching someone who can triage it, rather than waiting until Monday to find out. The Australian Signals Directorate (ASD) received more than 84,700 cybercrime reports in 2024 to 2025, an average of one every six minutes, and the average self-reported cost per report for a small business was $56,600, up 14 per cent on the year before. A weekend is a long time for something to run unattended.

There is also a clock that starts whether or not anyone is at a desk. An entity covered by the Notifiable Data Breaches scheme that suspects an eligible data breach has to take all reasonable steps to complete an assessment within 30 calendar days of becoming aware of it, and to give the Commissioner a statement as soon as practicable once it forms the belief that the breach is notifiable. Those are calendar days, so Saturday counts. Where the scheme applies, your organisation has to make sure the assessment and notification obligations are met, and shared-information arrangements and statutory exceptions can affect who actually performs them. The practical question underneath all of it is still the simple one: can you reach anyone who can begin the work.

So the exercise here is short. List the systems that stop revenue when they fail, not the ones that merely stop work. For each one, write down who you would actually call at seven o'clock on a Thursday night, and whether that answer is a company or a single person's mobile. Then ask what happens when that person is unavailable, and who decides whether a fault is just a fault or the start of an incident. If you cannot answer those in a sentence, you have found the gap the saved mobile number has been hiding.

What cover that matches your trading hours looks like

Coverage that matches your trading hours is a product you can buy, and it should be specific rather than aspirational. Ask for the hours in writing, ask what a call in those hours actually reaches, and ask what the escalation path is when the first person cannot resolve it. A published tier with published hours is far easier to hold a provider to than a promise of flexibility. ASD suggests a related question worth adding to the list: is the provider prepared for, and able to respond to, cyber security incidents. Hours are only useful if the person answering can act on them.

inSUPPORT publishes three support tiers on its pricing page, and they are worth reading as three answers to the same question about when your money is on the line.

Business support runs the office week

The Business tier runs Monday to Friday, 8:30am to 5:30pm, at $68 per user per month. It is the standard office-week band, and it is a sound fit for a business whose systems carry money between nine and five and go quiet after that. If your trading week looks like that, this is the honest tier and you should not pay for more than you use.

Retail support extends into nights and Saturday morning

The Retail tier runs $100 per user per month and extends Thursday and Friday to 9:00pm, then adds Saturday 8:30am to 12:00pm. The reason it exists is plain: inSUPPORT came up through retail IT, its parent is Retail Innovation Group Australasia, and the retail trading week never stopped on Friday afternoon. The extended hours were built into the product from the start, not bolted onto an office-hours plan later.

Complete support runs around the clock

The Complete tier runs $135 per user per month, 24 hours a day, seven days a week. It is the tier for an operation that never really closes. All three are published rates for the support component, with insurance, backup and security awareness quoted separately as their own line items, so you can see exactly what the hours cost before you add anything to them.

Whichever tier fits, get those answers in writing rather than as a promise of flexibility, then price the gap: the hours you trade uncovered, set against the difference between one tier and the next. That turns a vague worry into a number you can actually decide on.

The after-hours questions, answered straight

Why does managed IT support usually stop at 5:30pm?

Because support hours are a product decision, and the default band on most agreements is an office week. That is a defensible commercial choice, and it is not a criticism of any particular provider. It simply means the default is designed for a business whose revenue arrives between nine and five, and if yours does not, the default is a poor fit. The useful move is not to argue about it. It is to check the hours in your own agreement against your own trading pattern, then ask for a band that matches, or find a provider who already publishes one.

Can I just pay an after-hours rate when I need it?

You can, and for the occasional problem that is often the sensible answer. It works less well when the after-hours need is predictable and weekly, because you end up paying a premium rate for something you could have bought as standing cover, and ad hoc call-outs rarely come with a named escalation path. If you are calling after hours more than once a month, put a year of those rates next to the difference between support tiers before you assume the ad hoc route is the cheaper one.

How long does it take to change to a tier that covers my trading hours?

Moving between tiers with your existing provider is normally a contract variation, so ask when it can take effect and check your agreement for any minimum term on the current band. Moving to a new provider takes longer, because the new provider has to document and take control of the environment first. inSUPPORT reports that technical onboarding takes about four hours, with the wider remediation program running over a period set by how complex the environment turns out to be. Ask any provider for both numbers, because the gap between them is where the surprises live.

Where should I start if I am not sure what my exposure is?

Start with the environment rather than the contract. A gap analysis tells you which systems would actually stop revenue, how they are currently configured, and where the weak points sit, which turns the hours conversation into a costed decision instead of a hunch. inSUPPORT runs that as a Cyber Strength Audit, covering identity and access, patching, backup and recovery, email and endpoint security, and configuration drift.

Put your two windows side by side

Work out your uncovered hours first, then look at what is actually running in them. inSUPPORT grew out of retail IT, where the customers were retailers and the trading week did not stop on a Friday afternoon, and Kane Nawrocki has spent more than 25 years in the industry. It now supports more than 5,500 desktops and users, and the Retail tier exists because that experience came first and the product came second. A Cyber Strength Audit examines the systems your trading depends on and returns a plain English risk assessment ranked by business impact rather than by technical severity. You will finish the conversation knowing which failures would actually cost you a Saturday, and what it would take to cover them. We don't take your money, hand you the problem and walk away.

Book a Cyber Strength Audit →

Citations

  • Questions to ask managed service providers, Australian Signals Directorate. Five questions ASD recommends putting to a managed service provider, the last of which asks whether the provider is prepared for, and able to respond to, cyber security incidents. Last updated 6 October 2021. cyber.gov.au
  • Annual Cyber Threat Report 2024 to 2025, Australian Signals Directorate. Records more than 84,700 cybercrime reports, an average of one every six minutes, and an average self-reported cost per report for small business of $56,600, up 14 per cent. Published 14 October 2025. cyber.gov.au
  • Quick reference guide for responding to data breaches, Office of the Australian Information Commissioner. Sets out the 30 calendar day requirement to complete an assessment of a suspected eligible data breach, and the duty to give a statement to the OAIC as soon as practicable. Dated 29 June 2026. oaic.gov.au
Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE