HomeInsights › Buyer’s guide

Guide · Buyer’s guide

How to Choose an IT Provider: A Buyer’s Guide

Short answer: almost every IT provider will tell you they are proactive, responsive and security-focused. Those words cost nothing to say. The questions below cost something to answer, because a provider who is not doing the work cannot answer them specifically. Ask for dates, numbers and names, not adjectives.

Seven questions that actually separate providers

1. “When did you last test a restore from backup, and how long did it take?”

The single most revealing question in this industry. A good provider answers with a date and a duration, immediately, because they run restore tests on a schedule. A weak one talks about how backups run nightly. Backups running is not the same as backups working — the failure everyone eventually discovers is the backup that has completed successfully for eleven months and cannot actually be restored.

2. “What percentage of our users have multi-factor authentication enabled?”

The answer should be a number, and the number should be one hundred. Anything less is a decision somebody made, and you should know who made it and why.

3. “Who exactly will we be speaking to?”

Ask whether you get a named engineer who learns your environment or a rotating queue where you re-explain your setup every time. Both models exist legitimately, and larger providers genuinely offer depth a solo operator cannot. But you should know which one you are buying, because the experience differs enormously on a bad day.

4. “What is your actual response time, not your guaranteed one?”

Contractual response times are often generous to the provider — a four-hour guarantee sounds firm until you are the one waiting three and a half hours. Ask what typical response actually looks like, and ask what “response” means in their contract. An automated ticket acknowledgement is not a person looking at your problem.

5. “Do you resell the products you recommend?”

Not disqualifying — margin on hardware and licensing is normal and often fine. But you are entitled to know where a recommendation sits on the line between what you need and what pays best. A provider who answers this straightforwardly is one you can trust on the next recommendation.

6. “If we leave, what do we get?”

Ask this before signing, when your use is highest. Documentation, admin credentials, domain and DNS control, license ownership. The answer tells you whether you are buying a service or acquiring a hostage situation. A confident provider has no problem with this question.

7. “Can we speak to a client who looks like us?”

Not a curated testimonial — an actual conversation with a business of similar size in a similar sector. Any provider with long-standing happy clients can arrange this. A provider who cannot, or who offers only written quotes, is telling you something.

Contract terms worth arguing about

  • Term length and auto-renewal. Three-year terms with automatic renewal and a narrow cancellation window are common and rarely in your favor. Annual with a clear exit is reasonable.
  • What is genuinely included. Get specific about after-hours work, project work, on-site visits and hardware procurement. “Unlimited support” with four carve-outs is not unlimited support.
  • Who owns your licenses and domain. These should be in your name, in your tenant, on your account. Providers holding your domain registration have far more power over you than they should.
  • Offboarding, in writing. What you receive, in what timeframe, at what cost. Ambiguity here is expensive precisely when relations have soured.
  • Price escalation. Ask what has happened to existing clients’ pricing over the past three years. Past behavior predicts future behavior better than any clause.

Warning signs

  • Scare-selling. Cybersecurity risk is real and worth taking seriously. A provider whose entire pitch is fear, with a same-day discount attached, is selling anxiety rather than protection.
  • No written documentation of your environment. If everything lives in one engineer’s head, you are one resignation from a problem.
  • Vagueness about security specifics. Ask a direct question about patching cadence or MFA coverage and listen for whether you get a direct answer.
  • Reluctance to put anything in writing. Verbal assurances during a sale have a poor survival rate.
  • Guaranteed rankings, if they also sell SEO. Nobody can guarantee a Google position. Anyone claiming otherwise is either misinformed or counting on you being so.

Bigger is not automatically better, and neither is smaller

Larger providers bring depth, coverage, redundancy and formal process. If your business genuinely needs 24/7 staffed cover or specialist compliance expertise, that has real value. What you often trade is being a small account inside a large system.

Smaller and founder-led providers bring continuity and someone who actually knows your environment without reading a ticket history. What you should ask about honestly is what happens when that person is on holiday, ill, or handling another emergency. There should be a real answer — a named backup, documented environments, monitoring that runs on its own schedule, and defined escalation, not a shrug.

We are the second kind, and we would rather say plainly what that means than pretend the trade-off does not exist. Our own answer to that question: a small dedicated team covering after-hours and holidays, every client environment documented in writing rather than held in one head, monitoring and backups running continuously regardless of who is working, and your domain and licenses in your name so you are never locked in. For most businesses under about a hundred people, continuity and genuine familiarity with your setup are worth more than scale.

The one thing most people skip

Ask for references and then actually call them. It takes twenty minutes and it is the most reliable signal available to you. Ask the reference one question in particular: what has gone wrong, and how did they handle it? Every provider has had something go wrong. How they behaved on that day tells you more than any proposal.

If you would like to have this conversation with us, get in touch — and ask us every question on this page. We wrote them down because we are comfortable answering them. References available on request.

Common questions

When did you last test a restore from backup, and how long did it take? A provider doing the work answers with a date and a duration immediately. A provider who is not will talk about backups running nightly, which is a different and much weaker claim.

Most small-business managed IT lands somewhere between roughly $100 and $250 per user per month depending on what is included, your security requirements and your industry. What matters more than the number is what it covers — we break the pricing models down in a separate guide.

Larger providers offer depth, formal process and staffed out-of-hours cover, but you may be a small account inside a big system. Smaller providers offer continuity and someone who actually knows your environment. Ask a small provider directly what happens when their main engineer is unavailable — there should be a real answer.

Long auto-renewing terms with narrow cancellation windows, vague definitions of what is included, and any arrangement where the provider holds your domain registration or licenses in their own name. Also get offboarding terms in writing before you sign, not after.

No, and anyone who says otherwise should be treated with suspicion. Hardware fails, providers have outages and people make mistakes. What a good provider guarantees is that problems get caught early, that backups actually restore, and that someone answers when you call.

Related: How much does managed IT cost? · Switching IT providers · Managed IT & support. See all guides and insights. If distance is your concern, read how remote IT support actually works.

Questions? Just ask.

Prefer to pick a time? Book an appointment →

Or call (978) 885-1819 — if we’re on a job, leave a message and you’ll hear back the same business day.