Choosing managed IT for a Texas plant comes down to 9 factors, and 7 of them never appear on a standard MSP checklist. Shift coverage, ICS patch windows, and who is contractually allowed to touch the control network decide the outcome long before pricing does.
A generic MSP evaluation grades support, security, strategy and pricing. Those 4 still matter. They just don’t tell you whether a provider survives contact with a running production line. These 9 factors do. Each one is written as a question you can ask on a sales call, paired with the answer that should end the conversation.
We’ve delivered managed IT services for Texas manufacturers for more than 20 years, and the evaluations that go badly nearly always fail the same way. A plant runs the standard checklist. Every provider on the shortlist passes it. Then 4 months into the contract somebody gets a 9:40 PM call about a barcode gateway on Line 3, and it turns out nobody ever wrote down whether that gateway was in scope.
Scope is the whole game. Not price.
The threat side of this is well documented by now. Dragos tracked 119 ransomware groups hitting 3,300 industrial organizations in 2025, a 64% year-over-year rise, with manufacturing accounting for more than two thirds of the victims and an average dwell time of 42 days in OT environments, according to its 2026 OT Cybersecurity Year in Review. Fine. That’s the backdrop, and it’s the part every MSP will quote back at you. What actually hurts a Texas shop is quieter. It’s the 40 hours between an alert firing and someone with plant-floor authority deciding what to do about it.
What manufacturing-grade managed IT actually means
Manufacturing-grade managed IT is a support model scoped to a production calendar rather than a business day. It covers the office network, the ERP and MES layer, and a defined boundary into the control network, with change windows tied to planned line stoppages and response targets measured against the cost of a stopped shift.
Notice what that definition doesn’t say. It doesn’t say the provider programs your PLCs. It doesn’t say they own the safety system. Plenty of good manufacturing IT contracts stop at the demilitarized zone between the enterprise network and the control network, and that’s a legitimate scope as long as everybody signed something that says so.
Why a standard MSP checklist stops working at the plant door

We publish a general MSP evaluation checklist and I still think it’s right for an office. Support and reliability, cybersecurity, strategic guidance, pricing transparency. Four categories, and a provider who fails any of them is going to be painful to work with no matter what industry you’re in.
Here’s the problem with running it on a plant. All 4 categories are graded against an environment where the worst case is a person who can’t work. On a production floor the worst case is a line that can’t run, and those failures behave differently. An office outage is annoying and additive. You lose an hour, you make it up. A line stoppage is multiplicative, because the restart is its own event with its own cost, and the scrap you generate on the way back up doesn’t come back either.
So the 9 factors below sit on top of that checklist. Not instead of it.
The 9 factors, in the order they break deals

1. Does their coverage match your shift calendar or their business hours?
Almost every MSP in Texas advertises 24/7. Ask what happens at 11 PM on a Tuesday and the answers split fast. Some run a genuine overnight desk. Some route to an on-call engineer with a 30-minute callback. And some hand the phone to an answering service that takes a message for the morning queue.
All 3 are sold with the same 2 digits and a slash. Ask instead who picks up on second shift, where that person physically sits, and what they’re authorized to change without waking a manager. At Uprite every issue is triaged within 10 minutes and assigned to a named technician, and our field teams sit in Houston, Dallas, Austin and San Antonio rather than 3 time zones away. That’s the shape of the answer you want. Specific about authority, not just availability.
Answer that should worry you. “We have 24/7 monitoring.” Monitoring isn’t coverage. A dashboard turning red at 2 AM with nobody rostered to act on it is a very expensive screensaver.
2. Is there a written change window for anything that touches production?
Patch Tuesday is an office ritual. It has no business anywhere near a control network, because a plant patches when the line is already down and that calendar belongs to the maintenance planner, not to IT. NIST SP 800-82 Rev 3 is explicit that OT patching has to be scheduled around operational availability rather than a vendor release cadence.
The volume makes this worse every year. 2025 was the first year CISA published more than 500 ICS advisories, covering 2,155 CVEs at an average of 4.2 per advisory, and the average severity score has climbed above 8.0, per Infosecurity Magazine’s analysis of the advisory record. Nobody is absorbing that on a monthly cycle. You need a provider who triages which of those actually reach your equipment and then queues the rest against your next planned stoppage.
Ask for the change window in the statement of work. In writing. With the emergency exception path named, and a human named on both sides who can invoke it.
3. Who is contractually allowed to touch the control network?
Ask this one out loud and count the pause. The most common answer isn’t a wrong model. It’s silence, followed by something about working closely with your team.
There are 3 defensible answers, and a provider should be able to name theirs without thinking about it.
- Hands off. The provider owns everything up to the boundary firewall and nothing past it. Cheapest, cleanest, and it leaves the plant floor exactly as exposed as it was before you signed.
- Co-managed, with plant engineering holding the veto. The provider can see and recommend inside the control network, and any change needs a sign-off from the person who owns the equipment. This is where most mid-sized Texas plants land.
- Full OT scope with named engineers. Rare below 250 employees. It costs real money and it should, because the provider is now carrying operational risk.
- Undefined. Not a model. This is the one that produces the 9:40 PM phone call.
4. How do they inventory OT assets without knocking a PLC over?
Standard IT discovery tools sweep a subnet at roughly 1,000 packets per second. Point that at a controller built in 2006 and you can overwhelm its memory buffer, which on some equipment is indistinguishable from a fault condition and trips an emergency stop. The controller didn’t get attacked. It got asked a question it wasn’t designed to answer.
So ask what runs on day 1 of onboarding. Passive traffic analysis first is the right instinct, and any provider who says “we’ll just run a scan” should be asked whether they’ve ever done it on a live line.
I want to correct something the security industry oversells here, though. Passive-only isn’t safe, it’s just non-destructive. A device that stays quiet on the wire never shows up in passive discovery at all, so a passive-only inventory reliably undercounts. The honest answer is passive baseline first, then slow targeted active queries against specific devices with engineering standing there. Claroty’s Team82 found the manufacturing sector carrying the highest count of devices with confirmed known exploited vulnerabilities, more than 96,000, with 68% of them tied to ransomware groups, in its State of CPS Security report on OT exposures. None of that gets patched on equipment nobody has mapped.
5. Who governs remote access for your OEMs?
Your press builder has a way in. So does the integrator who commissioned the cell, the CMMS vendor, the scale calibration company, and whoever supports the labeler. Secomea surveyed 400 OT leaders for its State of Industrial Remote Access 2026 and found 57% of North American organizations managing 6 or more external vendors with remote access into OT. Only 46% could fully audit those sessions. Just 23% review vendor credentials monthly or more often.
That gap is where the dwell time comes from. Vendor access outlives the project it was created for, quietly, because nobody owns the offboarding step. Ask the MSP whether they’ll take that inventory on, and then ask the harder version. Can they produce a session log per vendor for the last 90 days? If the answer involves a shared password in a spreadsheet, you’ve learned something useful for free.
6. If ITAR touches your drawings, who is sitting on the help desk?

A screen share is an export. That’s the sentence most defense suppliers haven’t internalized yet. Under ITAR, releasing controlled technical data to a foreign person inside the United States is a deemed export, treated as if it went to that person’s country of nationality, and a Tier 1 technician taking remote control of an engineer’s workstation to fix a printer driver is very much a release if a controlled drawing is open on screen.
Offshore Tier 1 is the cheapest lever in the MSP business and it’s used constantly. Ask directly whether any queue that can reach your endpoints is staffed outside the United States, and ask how they evidence the determination rather than just asserting it. We walked through the registration and access-control mechanics in detail for ITAR and cyber compliance for DFW manufacturers.
On the CMMC side, don’t let a provider tell you the pressure is off. The Department of War suspended CMMC Phase 2 on July 13, 2026, and froze the later phases, but as Latham and Watkins notes in its analysis, that’s a policy pause and not a repeal. DFARS 252.204-7012 didn’t move. Neither did the 110 controls or your SPRS score.
7. Is the recovery target written in shift minutes or business hours?
A 4-hour recovery time objective sounds reasonable in a boardroom. Put it on a shift schedule and it eats most of one. Then add the restart, which is the number nobody prices in. Siemens found the average restart after an unplanned stoppage has stretched from 49 minutes to 81 minutes, in its True Cost of Downtime research. Your 4-hour RTO is really a 5-hour-21-minute event.
Ask for the RTO on the specific handshake that stops production, not on “the servers.” For most Texas plants that’s the ERP or MES connection to the floor. If Epicor can’t talk to the line, the machines are fine and you still aren’t shipping.
8. Was the security stack built for OT, or just pointed at it?
Try installing a modern endpoint agent on an HMI running Windows 7 Embedded. One of 2 things happens. It refuses, or it installs and your controls vendor tells you the warranty is now a conversation. Either way the MSP has learned something about your environment on your dime.
The useful question is what they deploy on the plant side specifically, and whether they’ve already had the compatibility conversation with Rockwell or Siemens or whoever built your cells. Pointing an IT tool at an OT network is one of the recurring failures we covered in what Texas manufacturers get wrong about OT and IT security, and it’s the mistake with the shortest distance between good intentions and a stopped line.
9. What documentation do you get back when you leave?
Asking about the exit on the first call feels rude. Do it anyway. The answer tells you more about how the provider actually runs than any reference call will, because a shop that documents well can hand everything over in a week and a shop that doesn’t will need 90 days and a lawyer.
Get the termination artifact list into the contract. Asset inventory including OT, current network diagrams, a credential vault export, OEM and vendor contacts with their support contract numbers, warranty and licence records, and the change log. Providers who won’t put that list in writing are quietly counting on switching cost to hold the account.
Score every provider on the same 9 rows
Print this, take it into the meeting, and score each provider 0 to 2 on every row. Anything under 12 out of 18 is a plant that will end up managing its own MSP.
| Factor | Ask this | Answer that should worry you |
|---|---|---|
| 1. Shift coverage | Who answers at 11 PM, where do they sit, and what can they change alone? | “We have 24/7 monitoring” |
| 2. ICS change window | Show me the production change window in the SOW | “We patch on a monthly cycle” |
| 3. Control network authority | Which of the 3 scope models are you proposing? | “We work closely with your team” |
| 4. OT asset discovery | What runs on day 1, passive or active? | “We’ll run a scan” |
| 5. Vendor remote access | Can you produce a 90-day session log per OEM? | Shared credentials, no session record |
| 6. ITAR and CUI staffing | Is any queue that reaches our endpoints staffed offshore? | “Our tools are compliant” |
| 7. Recovery target | What is the RTO on the ERP to line handshake? | An RTO quoted for “the servers” |
| 8. OT security tooling | What do you deploy on the plant side, and what does the OEM say? | The same agent they use in offices |
| 9. Exit documentation | List the artifacts we get on termination | Reluctance to name any |
The 3 factors most providers quietly fail
Numbers 3, 5 and 9. Control network authority, vendor remote access, and exit documentation.
They fail together, and the reason is structural rather than lazy. Those 3 are the only factors on the list with no product behind them. Any MSP can buy an endpoint detection licence and check the security box by Friday. Any MSP can staff an overnight desk if the contract value justifies it. But governance over who touches what, a maintained record of every OEM session, and a documented handover the day you leave, those are operating habits. You can’t procure them in a quarter, and there’s no SKU a salesperson can point at.
Factor 3 is also where we say no most often. If a plant wants us to take full ownership of the control network on day 1, before a joint inventory and without plant engineering holding a veto, that isn’t a scope we’ll sign. It reads as a win on the sales call and it’s a bad contract by month 3.
Run the downtime math before the first sales call

You cannot evaluate a response SLA without a number to hold it against. Work out your own cost per stopped hour first, then judge every proposal against it. The arithmetic isn’t complicated.
- Lost contribution margin. Units per hour multiplied by gross margin per unit.
- Idled labor. Fully loaded hourly rate multiplied by everyone standing on that line, including the 2 people who now have nothing to inspect.
- Restart cost. Scrap and first-article rework on the way back up, plus the 81 minutes of ramp Siemens measured.
- Downstream penalties. Expedited freight, late delivery clauses, and the customer scorecard hit that shows up 2 quarters later.
The published benchmarks span 2 orders of magnitude, so borrow them only as guardrails. Siemens put fast-moving consumer goods plants around $36,000 per stopped hour and large automotive plants at $2.3 million, with unplanned downtime costing the world’s 500 largest companies roughly 11% of annual revenue. A 90-person fabrication shop in Schertz is nowhere near either end. That’s exactly why you need your own figure rather than a statistic from a slide.
Once you have the number, the SLA conversation changes character completely. A 4-hour response stops being a line item and becomes a dollar figure you’re agreeing to absorb. Some plants look at that and buy a faster tier. Others look at it and realize the money belongs in redundancy instead. Both are good outcomes. Neither is available to a buyer who never did the math.
Where Uprite fits, and where we don’t
We’re not an ICS integrator and we don’t pretend otherwise. We don’t program PLCs, we don’t touch the safety system, and we don’t replace your controls vendor. What we own is the IT side of the boundary. Segmentation between the enterprise and control networks, identity and access, backup and tested restore, the ERP and MES layer, and the coordination that keeps your OEM’s remote sessions accounted for.
That work runs through our Uprite MFG framework, which comes in 4 shapes depending on whether you have internal IT already. MFG Complete is fully managed. MFG rComplete is remote-first for dispersed sites. MFG Impact is co-managed and sits alongside an existing IT lead, which is where most 100 to 400 employee plants land. MFG Secure adds vCISO and compliance work for contract-driven environments. On the application side our teams work in SAP, Epicor, NetSuite and Fishbowl, plus the Autodesk stack including Inventor and Vault.
42 people, Texas-based, more than 20 years in. Every issue triaged within 10 minutes, a 120-day satisfaction guarantee, and your rate locked for the first year. If you want the metro-level detail, we’ve written it up for Houston, Dallas and San Antonio. And if you’d rather see how we stack up against the field before you talk to anyone, we keep a comparison of the MSPs that actually work with manufacturers, ourselves included.
One honest limit. If you already run an internal IT team with dedicated OT security staff and a working change board, you probably don’t need a full managed IT services contract at all. Buy the pieces you’re short on. We’d rather sell you MFG Impact and be useful than sell you MFG Complete and be resented.
Score your current provider on all 9 factors
Book a Manufacturing IT Assessment and we’ll walk your plant against these 9 factors, map your IT and OT boundary, and hand you the scored gap list. You keep the list whether or not you hire us.
What plant leaders ask us before they sign
Do we really need an MSP that knows OT, or is a good IT provider enough?
A good IT provider is enough only if nothing on your network can stop a line. The moment a barcode gateway, an MES link or a shared HMI sits between IT and production, you need someone who understands both sides.
The test isn’t whether the provider has OT in their marketing. It’s whether they can describe your boundary back to you after a walkthrough. Plenty of strong generalist MSPs pass that test. Plenty of self-described OT specialists don’t.
How much more does manufacturing IT cost than office IT?
Expect a premium from 3 places. Extended coverage to match your shifts, specialist handling for legacy and OT systems, and device density, because a plant carries far more scanners, terminals and gateways per named user than an office.
Per-user pricing is what distorts the comparison. A 120-person plant with 40 office users and 300 floor devices looks cheap on a per-seat quote and then generates ticket volume that doesn’t match the price. Ask any provider to quote against your device count as well as your headcount, and watch which number they’d rather use.
Our controls vendor already handles the plant floor. Isn’t that covered?
Your controls vendor is responsible for their equipment working. That’s a different job from your network being defensible, and nothing in a typical integration contract obligates them to secure the path between the plant floor and the rest of your business.
Read the service agreement and look for the word security. Usually it isn’t there. What’s there is uptime on their hardware, which they’ll honor, and a remote access method they set up in 2019 that nobody has reviewed since.
Can an MSP patch a PLC?
Technically yes, practically almost never alone. PLC firmware updates are an OEM-validated activity that usually voids something if performed by a third party, so the realistic MSP role is identifying the exposure, coordinating the OEM, and scheduling the outage.
If a provider tells you they’ll just patch your controllers, that’s a red flag rather than a capability. Ask who signs off and what happens to the warranty.
What belongs in the SOW that a standard MSP agreement leaves out?
Five clauses. The IT and OT boundary drawn on an actual diagram, the production change window, the vendor remote access policy with an owner named, response targets tied to shift times rather than business hours, and the termination artifact list.
None of those 5 are unreasonable and none of them cost the provider anything to agree to if they were planning to do the work anyway. That’s what makes them a good filter. The negotiation itself tells you the answer.
How long does switching providers take when we’re running 2 shifts?
Plan on 60 to 90 days for a 2-shift plant, with the cutover itself landing in a scheduled shutdown rather than a weekend. The variable is documentation quality from the outgoing provider, not the incoming one’s speed.
Start the OT asset inventory before you give notice. Every time. Plants that walk into a transition with a current list of devices, accounts and OEM contacts finish near 60 days. Plants rebuilding that list from scratch, while the outgoing provider is already disengaged and answering slowly, land closer to 120 and spend the difference on stress.









