Most managed IT services agreements look similar on the surface, help desk support, monitoring, "proactive" management. The real differences only show up when you ask the right questions before signing, not after something goes wrong.

Here's a structured set of questions to take into any conversation with a prospective IT provider, organised by the areas that matter most.

Response Times & SLAs

  • What are your guaranteed response times, by priority level? A vague "we respond quickly" isn't a commitment. Ask for written SLAs, e.g. under 15 minutes for critical issues.
  • Is support available after hours or only during business hours? Find out exactly what happens if a server goes down at 9pm on a Friday.
  • Do you have a local team, or is support outsourced offshore? This affects both response quality and how well the provider understands local compliance requirements.

Security

  • What's included in your standard security stack? Ask specifically about EDR, MFA enforcement, email security and vulnerability scanning, don't accept "we handle security" as an answer.
  • Do you support Essential 8 or SMB1001 compliance? If compliance matters to your industry, this should be a structured, ongoing part of the service, not a one-off project.
  • What is your incident response process if we're breached? Ask what happens in the first hour of a suspected security incident, and whether that's included in your base fee.

Contracts & Pricing

  • Is this a fixed monthly fee, or are there variable/hidden charges? Ask explicitly what falls outside the base fee, see our guide to managed IT inclusions.
  • Is there a lock-in contract, and what's the exit process? Find out the notice period and whether there are penalties for leaving.
  • How is pricing structured as we grow or shrink? Per-user or per-device pricing should scale cleanly with your headcount.

The Team & Local Presence

  • Will we have a consistent point of contact, or a different technician every time? Continuity matters for understanding your specific environment.
  • Can you attend our site in person if needed? Confirm response times for on-site visits, especially for hardware issues that can't be resolved remotely.
  • How many clients does each technician typically support? An overloaded team, however skilled, will struggle to be genuinely proactive.

Onboarding & Documentation

  • What does the onboarding process look like, and how long does it take? See our guide on switching IT providers for what a proper transition should involve.
  • Will you document our environment, network, systems, credentials? Proper documentation protects you if you ever need to switch providers again.

Backups & Disaster Recovery

  • How often are backups tested with an actual restore, not just a completed job log? This is the single most important backup question, and the one most providers hope you don't ask.
  • What's your documented recovery time in a worst-case scenario? Ask for a specific number, not a general reassurance.

๐Ÿ’ก Ask for it in writing: A confident, credible provider will happily put SLAs, inclusions and response times in a formal proposal. Vague verbal reassurances that don't survive being written down are a warning sign.

Red Flags to Watch For

  • Reluctance to provide references or put commitments in writing
  • No clear answer on what happens to your data and access if you leave
  • Pressure to sign a long-term contract before a proper assessment of your environment
  • Vague answers about security capabilities beyond "we have antivirus"
  • No mention of regular reporting or strategic reviews

Choosing an MSP is a long-term relationship, not just a purchase decision. BITS is happy to answer every one of these questions directly and in writing as part of a free, no-obligation consultation, so you can compare us against anyone else you're considering.