The Recurring Problem: A Managed Services Story–Chapter 2

Previously –  https://blog.ciaops.com/2026/07/26/the-recurring-problem-a-managed-services-story-chapter-1/

image

The first sign was so small that nobody flagged it as a sign at all. In the second quarter of 2023, Priya noticed that ticket volume was up 22 percent year over year, but billable project revenue — the stuff that actually moved the profit needle — was flat. She mentioned it in a leadership meeting almost as an aside.

“We’re doing more work for the same money,” she said. “I don’t love that trend line.”

“Clients are just using more stuff,” Marcus said. “More cloud apps, more devices, more everything. It’s not a red flag, it’s a growth signal.”

Dave agreed with Marcus, because Dave usually agreed with Marcus, and because the alternative explanation — that the fundamental economics of the business were quietly eroding — wasn’t one he particularly wanted to entertain over lunch.

image

The second sign was harder to wave away. In August, Bridgepoint lost a competitive bid for a fifty-user logistics company to a firm nobody on the leadership team had heard of, a two-year-old outfit calling itself Sentio Cyber, operating out of what appeared to be a single shared office suite in Charlotte. Sentio’s pitch, as far as Marcus could reconstruct it from the prospect’s polite rejection email, was startlingly simple: a flat monthly fee that included twenty-four-seven security monitoring, an AI-driven help desk that resolved routine tickets in minutes instead of hours, and a guarantee — an actual contractual guarantee — of a four-hour response time on anything security-related, backed by an insurance-style penalty clause if they missed it.

“They’re a five-person company promising an SLA we can barely hit with forty-one people,” Marcus said, half-laughing, in the debrief. “It’s not sustainable. They’ll collapse the first time they get three ransomware calls in the same week.”

He wasn’t entirely wrong. But he also wasn’t entirely right, and in the meantime, Bridgepoint had lost the account.

image

The third sign arrived in October, and this one Dave couldn’t laugh off, because it showed up in the form of Denise Okafor’s voice on the phone, tighter than he’d ever heard it. Denise was the CFO of Lakeside Medical Group, a nine-location physical therapy and outpatient practice that had been a Bridgepoint client since 2018 and, at just under $640,000 a year, was Bridgepoint’s second-largest account.

“We had a laptop stolen from the Millbrook office on Friday,” Denise said. “Nobody called us until Monday morning, because apparently the ticket sat in a queue over the weekend. Dave, that laptop had patient records on it. We are now looking at a HIPAA breach notification, and I need to understand, in writing, what your security stack actually does, because right now I genuinely don’t know, and neither does our compliance auditor, and he is asking me very pointed questions I can’t answer.”

image

Dave promised a full incident report within twenty-four hours. It took Priya’s team most of three days to reconstruct what had actually happened, because the honest answer was uncomfortable: Bridgepoint’s after-hours monitoring caught the anomaly, generated an alert, and the alert sat in a shared inbox until a technician came in Monday and saw it. There was no automated escalation. There was no weekend on-call rotation with real teeth. There was Jordan, and two other senior techs, and a rotating list of who was supposed to be reachable, which in practice meant whoever hadn’t turned their phone to Do Not Disturb.

Lakeside didn’t fire Bridgepoint that week. But Denise asked, pointedly, whether Bridgepoint had a healthcare-specific compliance program, a documented incident response plan mapped to HIPAA’s Security Rule, and a named security lead she could speak to directly. Dave did not have satisfying answers to any of those questions, and he knew it while he was giving them.

image

Leave a comment