The glossary

IT terms in plain English.

AI made tech knowledge free. Anyone can look up these terms in seconds. What stayed rare is knowing what they mean for your business. These definitions are written for the person who signs the checks, not the person who runs the servers.

Six terms

What the words on every IT proposal actually mean.

Every definition here does three things. It says what the term means in business terms. It says when it matters to a firm of 10 to 100 people. And it points to where the work happens. Knowing a term is one thing. Knowing what to do about it is another. That gap is what we call the Interpretation Economy.

Jump to: Managed IT Services · vCIO · Zero Trust · AI Governance · Co-Managed IT · MSP

Managed IT Services

Managed IT services is a setup where a business hands the day-to-day running of its technology to an outside firm for a fixed monthly fee. That covers monitoring, upkeep, security, updates, and support. The provider is paid to keep things healthy, not to bill for repairs. That flips the old break-fix model on its head. The fewer problems you have, the better the deal works for both sides.

When it matters: for a firm of 10 to 100 people, it matters the day technology stops being a background convenience and starts carrying revenue. That day usually comes before anyone budgets for it. This work is PCI’s Managed IT practice.

vCIO (virtual CIO)

A vCIO, or virtual Chief Information Officer, is a senior advisor. It does for a smaller company what a CIO does for a large one. The role owns the technology roadmap. It ties each tech decision to revenue, risk, and operations. And it puts a name behind the advice. An outside firm usually provides it a few hours a month. You get executive-level tech judgment without adding an executive to payroll.

When it matters: it matters when real-money tech decisions keep landing on the owner’s desk with no one to test them. That is the role PCI delivers through Technology Advisory.

Zero Trust

Zero trust is a security model built on one rule. No user, device, or app is trusted by default. That holds inside the network and out. Every request for access has to prove it should be allowed, every time. In practice, you deny everything first. Then you allow only what a person needs to do their job. It is not a product you buy. It is a choice about how access works in your company.

When it matters: it matters to a 10-to-100-person firm because of how ransomware spreads. Once inside, it moves from machine to machine. Deny access by default and that spread stops working. It is central to PCI’s Cybersecurity work.

AI Governance

AI governance is the set of choices a business makes about how it uses AI. Which tools are approved. What data they can touch. Who answers when the output is wrong. And how results get checked before they reach a client. It is not about blocking AI. It is about steering it. Good governance is the line between AI that adds real productivity and AI that quietly creates risk no one owns.

When it matters: it matters the moment your team starts pasting client information into AI tools no one approved. At most firms of 10 to 100 people, that has already happened. This is PCI’s AI Governance practice.

Co-Managed IT

Co-managed IT is a shared setup between a company’s own IT staff and an outside provider. The internal team keeps the work that gains from being close to the business. The provider adds the depth one or two people cannot carry alone. That means around-the-clock monitoring, security operations, special projects, and cover when someone is out. It is a split of the work, not a replacement. The internal team gains reach, and the company adds no headcount.

When it matters: it matters when your one IT person is stretched past what one person can hold. That shape is common by 50 employees. See how PCI structures this under Managed IT.

Managed Service Provider (MSP)

A managed service provider, or MSP, is a firm that runs technology for other businesses. It treats that as an ongoing job, not a string of billable repairs. A good MSP monitors and maintains the environment, manages security, supports the people using it, and answers for the results. All for a set monthly cost. The term covers a wide range of firms, from help desks with contracts to advisory practices. What they share is that they answer for outcomes, not hours.

When it matters: it matters because choosing an MSP really means choosing whose judgment sits behind your technology for years. Here’s what that includes at PCI, so you can hold any provider to it.

Beyond definitions

Definitions are free. Judgment is the job.

Knowing what zero trust means is one thing. Knowing whether your firm needs it this year is another. Bring the question. You will get a straight answer.

30 Years — coming in 2027