When an IT provider is doing its job well, technology should feel dependable rather than mysterious. Your team should know where to get help, your directors should understand the risks, and you should be able to see what you are paying for.

Unfortunately, many businesses only discover gaps in their IT arrangements after an outage, cyber incident or difficult supplier change. These ten questions to ask your IT company will help you test whether your provider is actively managing your technology or simply waiting for something to break.

1. What exactly do you manage, monitor and support?

Your IT company should be able to give you a clear list covering users, devices, servers, Microsoft 365, networks, backups, security tools and third-party services. They should also explain what is outside the agreement.

Ambiguity creates risk. A director may believe every laptop is protected while the provider only supports selected devices. Your provider should maintain an accurate inventory and be able to identify unmanaged or unsupported systems.

Ask for a plain-English service summary showing:

  • Which users and devices are covered
  • What is monitored automatically
  • Which security and backup services are active
  • What support is included each month
  • What will incur an additional charge

A good managed service should make responsibility obvious. See how Bitwise-IT structures its managed IT services for Essex businesses.

2. How do you protect our business against cyber attacks?

“We install antivirus” is no longer a sufficient answer. Modern attacks commonly target email, cloud accounts, passwords and people as well as computers.

Your provider should describe a layered approach that includes device protection, email filtering, multi-factor authentication, vulnerability management, security updates, account monitoring and staff awareness. They should also explain who reviews alerts and what happens when suspicious activity is detected outside normal office hours.

The most important test is whether these controls are actively managed. Security software that is installed but never checked can create a dangerous false sense of confidence.

IT professional explaining server monitoring alerts to a colleague

3. Are all our devices patched and monitored?

Unpatched operating systems and applications are a common route into business networks. Your IT company should be able to tell you which devices are up to date, which have failed to patch and whether any machines are too old to support securely.

Monitoring should also identify warning signs such as failing disks, low storage, stopped services and security alerts before they become major interruptions. Ask whether your provider can produce a current device report rather than relying on memory or an old spreadsheet.

4. What is backed up, how often, and when was recovery last tested?

A backup is only useful if it contains the right data and can be restored when needed. Ask your provider to identify every protected system, the backup frequency, retention period, storage location and recovery process.

Do not assume Microsoft 365 removes the need for a separate backup. Retention features and recycle bins do not provide the same protection as an independently managed backup of important Exchange, OneDrive and SharePoint data.

Your IT company should also confirm how failed backup jobs are handled and when a real recovery test was last completed. If nobody is checking alerts or testing restores, you do not have a dependable recovery plan, you simply have hope.

Data-centre technician checking server and network infrastructure

5. What happens if we suffer a cyber incident or major outage?

You need more than a promise that someone will “look into it”. Your provider should have a documented process for triage, containment, communication, recovery and escalation.

Ask who you call, who has authority to make urgent decisions, whether assistance is available out of hours and how frequently you will receive updates. It is also worth confirming the difference between normal technical support and specialist incident response, including any potential additional costs.

Clear incident procedures save valuable time when pressure is high.

6. Who has administrator access to our systems?

Administrator accounts can change security settings, access sensitive information and potentially take control of the business environment. Your IT company should know exactly which privileged accounts exist, who uses them and how they are protected.

Look for named accounts, strong authentication, restricted permissions and secure password management. Shared administrator passwords, dormant accounts and former suppliers retaining access are warning signs.

Your business should also retain appropriate ownership of its Microsoft 365 tenant, domains, licences and key systems. A reputable provider helps you maintain control rather than making it difficult to leave.

7. How quickly will you respond when we need help?

“Fast support” means little unless it is defined. Ask for documented response targets by priority, the hours during which support is available and the route your staff should use to report a problem.

Clarify the difference between response and resolution. A response target tells you when someone will begin handling the issue; resolution depends on the cause, complexity and any third parties involved.

You should also understand how urgent incidents are classified, how they are escalated and whether your provider measures its performance. Predictable service is more valuable than vague assurances.

8. How do you help us plan rather than just fix problems?

An effective IT partner should understand your plans for recruitment, new premises, remote working, compliance and growth. That context allows technology changes to be budgeted and delivered before they become emergencies.

Ask how often your provider reviews your environment, discusses upcoming risks and recommends improvements. They should be able to identify ageing equipment, licence changes, security priorities and projects that may affect future spending.

This proactive approach is one of the key differences between managed IT and traditional break-fix support. It reduces surprises and helps technology support the direction of the business.

9. Can you explain our IT risks in plain English?

Directors do not need a stream of technical jargon, but they do need enough information to make informed decisions. Your provider should be able to explain what a risk means to the business, how likely it is, what the potential impact could be and what a proportionate improvement would involve.

Good reporting should highlight trends and actions, not simply list thousands of alerts. Ask for examples of the reports or reviews you will receive and how priorities are agreed.

If your IT company cannot make an issue understandable, it is difficult for you to judge whether the recommendation is sensible.

10. How would you support a smooth handover if we changed provider?

This can feel like an uncomfortable question, but a professional IT company should answer it confidently. Your business should know where its documentation is held, which accounts it owns and how access and technical information would be transferred securely.

A provider should not withhold passwords, domains or business data to create dependency. There may be reasonable handover charges for project work, but the process and responsibilities should be transparent.

Asking this question at the start of a relationship is an excellent way to test the provider’s approach to documentation, ownership and professionalism.

What should you do with the answers?

You are not looking for ten perfect sales answers. You are looking for clarity, evidence and ownership. A strong IT company will welcome sensible scrutiny and will be able to show how its processes protect your people, data and ability to operate.

Watch for answers based on assumptions, undocumented arrangements or tools that nobody actively manages. One weak answer may simply reveal an improvement to make; several weak answers can indicate that the relationship is more reactive than you realised.

If these questions uncover uncertainty in your current setup, Bitwise-IT can provide a straightforward review and explain the priorities without unnecessary jargon. You can compare our managed IT and cyber security packages or contact our Essex IT team for a practical conversation about your business.

RETURN TO BLOG