10 Questions to Ask Before You Hire an IT Provider
Every IT quote looks the same on paper. These ten questions separate them, including what a good answer sounds like and the answer that should worry you.
By Cohesive Security
Three quotes land on your desk. They are within a few hundred dollars of each other, they use roughly the same words, and none of them tells you what it is actually like to be a client. So the decision gets made on price, or on whoever was easiest to talk to, which is how businesses end up switching providers again eighteen months later.
The questions below are the ones that actually separate providers. We have put our own answers in where it seems useful, including in the places where the honest answer is not the most flattering one, because a provider who only tells you the good parts is showing you something in itself.
Key takeaways:
- The most important question is the one almost nobody asks: can you leave, and take your data, licences, and documentation with you in a usable form?
- Your IT provider holds administrative access to everything you own, so their security is your security. Ask about it directly.
- Be suspicious of anyone promising round-the-clock human response at a small business price. Ask what is automated and what is staffed, separately.
- Compare what is included versus what generates an extra invoice, not the headline monthly number.
What you are actually buying
Worth naming first, because it shapes every answer. Under a managed agreement you are not buying hours, you are buying an outcome: systems that work, get patched, get watched, and get fixed. That is why we recommend it, and why a provider whose revenue depends on your problems recurring has an awkward incentive. We have written before about how the two models compare.
You are also buying a relationship with someone who will hold the keys to everything. Which brings us to the questions.
Money and scope
1. What is included, and what generates an extra invoice? Ask for the boundary explicitly. Projects, new user setup, after-hours work, hardware procurement, vendor management, and moving offices are the usual extras. A good provider hands you the line and does not flinch. A worrying answer is a vague “we take care of everything”, which tends to become itemized later.
2. How does the price change as we grow or shrink? Per-user pricing should move in both directions. Ask what happens in a seasonal business where headcount swings, and what the notice period is for reducing seats.
3. What does a typical quote in this market look like? Not to haggle, but to calibrate. A price far below the market usually means something is not included, and a price far above should come with a reason. We publish market ranges rather than our own rate card, so you can tell where a number sits before you negotiate.
Your data and your exit
4. If we leave, what do we take with us? This is the single most important question in the list and the one owners forget. Do you own your Microsoft 365 tenant, your domain, your licences? Will you get documentation, network diagrams, and passwords in a usable format? Is there an offboarding process, or does it depend on goodwill? The NCSC’s guidance on choosing a managed service provider puts it well: define roles and responsibilities, and set out clearly what the provider takes on and what stays with you. Get the exit answer before you sign, while you still have room to negotiate.
5. What is the term, and what happens at renewal? Here is our honest answer rather than a marketing one: some of our managed agreements do include a commitment, because building out and stabilizing an environment is front-loaded work. We think the fair test is not whether a term exists, but whether the exit is clean and the renewal is not automatic-and-silent. Separately, we also do break-fix and on-demand work with no long-term contract, so if that is genuinely what you need, you are not being pushed into something larger.
How they secure themselves
6. What protects your access to our systems? Your provider has administrative rights across your entire business. If their tooling is compromised, so are you, and this has happened at scale. The UK and US agencies published joint guidance on exactly this risk, and NCSC’s advice for buyers is direct: check whether the provider holds recognised security certifications, and whether multi-factor authentication protects the administrative credentials they use to reach your systems. Ask which accounts of theirs can touch yours, what protects those accounts, and whether access is logged.
7. What is your patching standard, and how do you prove it happened? Anyone can say they patch. Ask what the target is for critical updates, and ask to see a report. Same for backups: not “do you back up” but “show me the last restore test”. If neither can be evidenced, they are intentions rather than controls.
When it goes wrong
8. Who answers, and during what hours? Ask for the automated and the human parts separately, because they get blurred deliberately. Our answer: monitoring runs 24/7 and it is automated, so tooling can detect and contain something on an endpoint at 3 a.m. without waking anyone. Human response is during business hours, with a defined path for genuine after-hours priorities. If a provider your size claims staffed round-the-clock support at a small business price, ask who specifically is awake at 3 a.m. and what happens when they are on holiday.
9. What happens the day something serious goes wrong? Who declares an incident, who they call, whether incident response is included or billed by the hour, and whether they have done it before. NCSC frames this as simply asking what will happen if things go wrong, and expecting clear steps in return. Vague reassurance here is a real warning sign, because incidents are exactly when improvisation costs the most.
The human one
10. Who will I actually deal with? Not the person selling. Ask who handles your account day to day, whether you will speak to the same people, and what happens when they are away. In a small business relationship this matters more than any feature list, and it is the thing that most often goes wrong quietly.
Worth adding to the list if they apply to you: do they have experience with your compliance obligations and will they produce the evidence auditors ask for, and will they deal with your other vendors directly or expect you to relay messages between two companies pointing at each other.
Now ask us the same ones
We would rather be chosen by someone who asked all ten and compared the answers than win on a lower number. If you want ours in writing, that is part of a free assessment: what we would take on, what stays with you, what it costs, and what leaving would look like if it came to that. Our reasoning on the rest is on why Cohesive, and you can email hello@cohesivesecurity.com with the awkward questions directly.