15 Questions to Ask Before Hiring an IT Provider

Hiring an IT provider is a multi-year decision most owners make after a one-hour sales meeting. These fifteen questions — grouped into five areas — are how you make that hour count. The good providers will enjoy answering them; the wrong ones will get vague. Both reactions are data.

The short version: demand written response-time SLAs, named security tooling with someone watching it, proof that backups restore, transparent scope, and exit terms that leave you owning your own documentation and passwords. Any provider who stumbles on those fundamentals has answered your real question.

Response & Support: Will Someone Actually Show Up?

1. What are your guaranteed response times, by severity, in writing? A real answer cites a tiered SLA — e.g., critical outages acknowledged in 15–60 minutes, standard requests same-day — with remedies for misses. "We're usually really fast" is not an SLA. (Our explainer on how response-time SLAs work covers what good tiers look like.)

2. Who answers the phone — your engineers or an answering service? You want to know whether the first contact can actually fix things, where the helpdesk sits, and what after-hours coverage looks like.

3. Do you provide on-site support here, and how fast? Remote resolves most tickets, but networks, hardware, and some outages need feet in the building. A provider serving the Sacramento region should give you a realistic on-site window for your city, not a promise from three time zones away.

Security: Prove It's Real

4. Which EDR do you deploy, and who responds to its alerts at 2 a.m.? Named platform, named monitoring arrangement (in-house SOC or MDR partner). "We install antivirus" ended the conversation in about 2019.

5. Is MFA enforced — not offered — across 100% of your clients' accounts? The correct answer is yes, without exceptions for complaining executives. Stolen credentials remain the top small-business breach vector in every major industry report.

6. When did you last test-restore a client's backup, and can I see how you document it? Backups that have never been restored are a hypothesis. Look for scheduled, documented restore testing — the core of real backup and disaster recovery.

7. How do you secure your own company? MSPs hold the keys to dozens of businesses, which makes them premium targets. A provider that can't describe its own MFA, access controls, and audit practices is a supply-chain risk you'd be signing up for. Our cybersecurity services page shows the stack we hold ourselves to.

8. Walk me through the last security incident you handled. Timeline, communication, outcome, and what changed afterward. A provider who claims they've never had one is either brand new or not being straight with you.

Scope & Money: What Am I Actually Buying?

9. Exactly what's unlimited, and exactly what bills hourly? Get the boundary in writing. The classic trap is a low monthly fee where every meaningful task is "project work."

10. Which licenses are included, and who owns them if we part ways? EDR, backup storage, email security, password manager — bundled or billed? Portable or provider-locked?

11. What does onboarding involve, cost, and take? Expect 2–4 weeks, a documented security baseline pass, and a clear fee (free to roughly one month's contract value is market-typical).

Use this quick scorecard during meetings:

Area Green flag Red flag
Response Tiered written SLA with remedies "We're always available"
Security Named EDR + 24/7 monitoring + enforced MFA "Enterprise-grade security" (no specifics)
Backups Scheduled, documented restore tests "Backups run nightly"
Scope Written unlimited/hourly boundary Everything interesting is a change order
Exit You own docs & credentials, clean handoff clause Vague or punitive exit terms

Fit & Accountability: Will This Last?

12. What size and industries are most of your clients? You want a provider whose sweet spot is businesses like yours — a 10-person shop gets lost at an enterprise-focused MSP, and vice versa. Industry familiarity matters double if you carry HIPAA, FTC Safeguards, or CMMC obligations.

13. How will we review the relationship — and will anyone talk strategy? Look for quarterly business reviews and someone playing the vCIO role: budgets, roadmaps, risk. A provider with no review cadence plans to be invisible until renewal.

14. Can I speak to two current clients my size — and one who left? The departures question is the revealing one. Confident providers handle it gracefully.

The Exit Question Everyone Forgets

15. If we leave, what do we walk away with, and how does handoff work? The only acceptable answer: you own all documentation, admin credentials, and licenses purchased on your behalf, with a defined transition-assistance period. Providers who engineer painful exits are telling you how they plan to retain you.

Want to see how we answer all fifteen? Book a free IT assessment — bring this list, and we'll answer every question in writing.

How to Run the Process

Shortlist two or three providers, put these questions to each, check references, and read the contract's exit clause before the pricing page. Businesses across the region — Sacramento, Roseville and Rocklin, and beyond — tell us the same thing after switching providers: the red flags were visible in the first meeting; they just didn't know which questions surfaced them. Now you do.

Frequently asked questions

What's the single most important question to ask an IT provider?
"What are your guaranteed response times, in writing, and what happens when you miss them?" Every provider claims fast response; only some contractually commit to it with defined severity levels and remedies. The presence or absence of a real SLA predicts the whole relationship.
How do I check an MSP's security claims?
Ask for specifics, not assurances — which EDR platform they deploy, who watches its alerts after hours, whether MFA enforcement is universal across their client base, and when they last test-restored a client backup with documentation. Then ask how they secure their own company, since MSPs themselves are prime attack targets.
What contract terms should worry me?
Auto-renewing multi-year terms with no performance-based exit, vague scope language where everything interesting is "billable project work," and — worst of all — unclear ownership of your documentation and admin credentials. If leaving the provider would be technically painful by design, that's the business model.
Should I choose the cheapest quote?
Only after normalizing scope, and usually not even then. Quotes vary mostly because inclusions vary — one bundles EDR, backup licensing, and after-hours support; another bills each separately. A dramatically cheap per-user price almost always signals thin service, offshore-only helpdesk, or a plan to bill back the difference hourly.
How many references should I ask for, and what should I ask them?
Two or three clients of similar size and industry, plus ideally one that left. Ask references about the worst incident they've had — how fast the provider responded, how honestly they communicated, and what changed afterward. Everyone's happy in a demo; incidents reveal the truth.
How long should choosing an IT provider take?
For a 10–100 person business, expect 3–6 weeks: shortlist two or three providers, run these questions, check references, and review contracts. Rushing it invites a bad multi-year marriage; dragging it out past a quarter usually means you're deferring a decision your outage history already made.

Find out what your IT should be doing for you

Get a free, no-obligation IT assessment — a plain-English report on your security, backups, and support gaps.

Get Your Free IT Assessment