Eleven questions to ask before you change IT provider

Including the answers that should make you walk away — and yes, these apply to us too.

Choosing a provider · 7 min read

Most businesses stay with an IT provider they have outgrown for far longer than they should, because changing feels risky and the sales process is hard to see through. Every provider says the same things: proactive, responsive, trusted partner.

These are the questions that actually separate them. We have included what a good answer sounds like and what should worry you — and in fairness, you should put all of these to us too.

On the contract

1. What is the minimum term and the notice period?

Worrying: three years, or twelve months' notice.

A long tie-in protects the provider, not you. It removes any pressure on them to keep earning the work — which is precisely when service quietly degrades. Rolling agreements with short notice are a sign of confidence.

2. What is explicitly not included?

Worrying: "everything's covered" with no detail.

Something is always out of scope — projects, out-of-hours, third-party liaison, hardware. That is fine and normal. What matters is that it is written down, so the first invoice is not a surprise.

3. What happens to our data and documentation if we leave?

Worrying: hesitation, or "we'd discuss that at the time".

Your data, your admin credentials and your documentation are yours. A provider who is vague here is telling you that leaving will be made difficult. The answer should be in the agreement, not a promise.

On service

4. What are your response times, and what happens if you miss them?

Worrying: targets with no consequence attached.

Ask for the SLA in writing, and ask specifically what counts as "critical". Some providers define it so narrowly that almost nothing qualifies.

5. Who actually answers the phone?

Worrying: "log a ticket on the portal".

A portal is fine for a password reset. When the server is down, you want a person. Ask whether the person answering can fix things or only route them.

6. Will we have the same engineers?

Worrying: whoever is free.

Someone who knows your setup solves in ten minutes what a stranger spends an hour rediscovering. Ask whether you get a named engineer and what happens when they are on holiday.

7. Can I speak to a client of a similar size in a similar sector?

Worrying: only a written testimonial.

Any provider worth hiring has clients who will take a ten-minute call. Ask for one that resembles you — a 200-person manufacturer's experience tells a 15-person practice very little.

On security and risk

8. What security is included as standard, and what costs extra?

Worrying: antivirus described as a security strategy.

MFA, endpoint detection, email filtering, patching and tested backup are baseline now. If they are all chargeable extras, the headline price is not the price.

9. When did you last restore something from our backup?

Worrying: "backups are running fine".

That is not the question. Backup running and backup restoring are different claims, and the gap between them is discovered at the worst possible moment. Ask for the date of the last tested restore and what was recovered.

10. Do you hold Cyber Essentials yourselves?

Worrying: "we help clients with it" — without holding it.

A provider recommending security controls they have not applied to themselves is worth a raised eyebrow. They have privileged access to your systems; they are part of your attack surface.

On the switch

11. What does onboarding look like, and who deals with our current provider?

Worrying: vagueness, or leaving the handover to you.

A provider who has done this often has a documented process and will handle the outgoing relationship themselves. You should not be chasing your old provider for admin passwords.

One more, off the list. Ask what they would not recommend doing. A provider who agrees with every idea you float is selling, not advising. The useful ones will tell you when something is a waste of money — including when it is their own service.

What switching actually involves

The fear is worse than the reality. A typical move runs about two weeks: a review of what you have, a written proposal, then onboarding — documentation, monitoring, security baseline and credential handover. The disruptive part is mostly the provider's problem, not yours.

The one thing that genuinely can be awkward is an outgoing provider who drags their feet on credentials. It is worth asking your prospective provider how they handle that, because the good ones have handled it many times.

Our answers to all eleven are on the managed IT support page, and if you want the short version in person, the free IT review is exactly that conversation.