Most advice about choosing an IT provider arrives as a list of questions to ask. The questions are the easy part. What matters is whether the answer arrives without checking, because everything below is something a provider doing the work already knows.
Use these on a prospective provider. Use them on your current one, which is the more interesting exercise.
About the work itself
1. When did you last restore one of our backups, and how long did it take?
You want three facts: a date, what was restored, and a duration. "We monitor them daily" answers a different question.
The reason this one separates providers is covered at length in the cyber insurance questionnaire, question by question, because your underwriter asks it too, in almost the same words.
2. Who currently has administrator access to our Microsoft 365 or Google Workspace tenant?
This should take under a minute. It is a short list, and it is the most sensitive thing anyone holds on your behalf.
Ask to see it. You are looking for former staff, a vendor who did a project two years ago, and accounts belonging to people who left the provider.
3. What is your response time, and what happens when you miss it?
Most providers answer the first half. The second half is where you learn whether it is a commitment or a marketing number.
Confirm the figure is in the agreement rather than on the website, and ask what specifically happens inside the window. There is more on how these clauses are written in what is in a managed IT contract.
4. What is explicitly out of scope, and what does it cost?
Every managed agreement has a boundary. The good ones write it down.
The answer you want is a document. The answer that should worry you is a reassurance that everything is covered, because it never is, and you will meet the exception in month four with an invoice attached.
5. How do you handle offboarding when one of our staff leaves?
You are testing for a procedure rather than a habit. Ask the timeframe, who triggers it, and what happens to the person's mailbox and files.
If it depends on somebody remembering to send an email, accounts will stay live for months. Your cyber insurance application asks this too, so a vague answer costs you twice. The full sequence is in the offboarding checklist most small businesses skip.
About the money
6. What would we pay each month, all in, at our current headcount?
Not the base rate. The number that lands on the invoice.
Two quotes at $125 and $220 per user can both be fair, because they are frequently not selling the same thing. Security bundled in one and billed as line items in the other. Help desk uncapped in one and quietly metered in the other. We put the whole Metro Vancouver range, including ours, in what managed IT actually costs.
7. Is help desk time capped?
Ask directly, and ask what happens at the cap. Uncapped help desk with no per-ticket charge is common enough that it is worth confirming rather than assuming, because the alternative creates a problem: you hesitate to call about small things, small things become large things, and the provider earns more when your systems behave worse.
8. What is the onboarding fee, and what does it cover?
Onboarding runs from nothing to a couple of thousand dollars in this market, and both ends can be reasonable. Zero onboarding usually reappears in the monthly rate.
It should buy real work: your environment documented, devices enrolled, your tenant properly taken over, backups and multi-factor switched on and tested. If it covers an account setup and a handshake, question it.
About the relationship
9. What is the term, and what does leaving look like?
A long contract solves the provider's retention problem, not yours. It gets reached for when a provider is worried you might leave, and it works by removing your options rather than by improving the service.
There is a fair argument on the other side. Onboarding costs the provider money before it earns any, and an onboarding fee is the honest version of that same protection.
Ask what notice period applies, whether there is an exit fee, and what you receive on the way out.
10. Who owns the documentation, and do we get it if we leave?
The answer should be that it is yours. Where a provider treats your network documentation as their own property, leaving has been made expensive on purpose, and the next provider will bill you to rediscover what somebody already knew.
11. Will we deal with the same person?
At small scale this matters more than any technology question. Continuity is most of the value. A provider who already knows your setup solves in ten minutes what a stranger spends two hours rediscovering.
There is no correct answer. A large provider routes you through a queue with better after-hours coverage. A smaller one gives you continuity and less redundancy. Both are legitimate trades. What you want is a provider who tells you which one you are buying.
12. What do you not do?
The most revealing question on the list.
Every provider has a boundary. Penetration testing, formal audits, incident forensics, data-centre-scale network builds, industry software nobody else supports. A provider who names theirs and explains who they bring in has thought about it. A provider who says yes to everything has not, and you will find the edge yourself, later, at cost.
What the hesitation tells you
None of these are trick questions and none require preparation. They are all things a provider actively doing the work would answer from memory.
Which is why the useful signal is not the content of the answer. It is the pause before it.
A provider who has to check when your last restore was has not done one. A provider who cannot produce the admin list this week is not watching it. A provider whose response time exists only on the website has not committed to it.
The delay before the answer is the answer.
For the record, ours: response times written into the agreement at two business hours on the Complete plan and thirty minutes if you are down, uncapped help desk with no per-ticket charge, month to month with no exit fee, a written scope that says what is not included, and your documentation is yours to take.
Pricing is published rather than quoted on request. If you want a neutral read on your current setup, the free insurance-readiness review covers most of the technical questions above in half an hour, and you keep the findings whether or not you hire anyone.
Related guides
- The IT checklist accounting firms should finish before tax seasonThe work to finish in the quiet months, so nothing breaks between February and April 30.
- Payment redirection fraud, and why construction gets hit firstHow the scam works on a progress draw, the controls that stop it, and the first hour if it lands.
- Windows 10, a year after support ended: the October decisionWhat year two of Extended Security Updates costs, and how to decide machine by machine.