Most providers you shortlist will describe themselves in similar words: proactive, responsive, security focused. The sales presentation will not separate them. What separates them is how they answer a small number of specific questions, and whether the answers are backed by something you can read, test or verify before you sign. Here are the questions we think are worth asking, and what a good answer sounds like.
Response, resolution and showing up
Response is not resolution
Every provider quotes a response time. Fewer quote a resolution target, and the gap between the two is where frustration lives. A ticket acknowledged in fifteen minutes and closed three days later has met a response promise and failed the business. Ask for both figures, ask how they are measured, and ask to see the actual numbers from a recent month rather than the ones in the brochure. Then ask how priorities are set: who decides that a payroll outage outranks a printer, and can you escalate when the queue gets it wrong?
Ask too who picks up the phone. A help desk staffed by people who can actually fix things is very different from a call-logging service that passes everything upward.
Can they come to site, and how often will they?
Remote tools resolve most tickets, but a failed switch, a new office fit-out or a server that will not boot needs a person in the room. Ask whether on-site attendance is included, capped or billed, and how far away the nearest engineer actually is. For a business in the GTA that answer should be measured in a short drive, not a flight. Ask how many people know your environment; a single named technician is comforting until that person is on holiday.
What is in the security stack, and who watches it?
The honest answer describes layers: endpoint detection and response on every device, email filtering, multi-factor authentication administered centrally, patching with a stated cadence, and some form of monitoring that a human reviews. Then ask the harder question: when an alert fires at night, who sees it and what do they do? A tool that nobody watches is a receipt, not a control. Ask whether awareness training is included and how phishing simulations are run, and ask what happens on the day a user flags a suspicious message. A good provider can walk you through the sequence without notes.
Backups: not “do you”, but “have you tested”
Everybody has backups. The questions that matter are how often restores are actually tested, whether at least one copy is offline or immutable so ransomware cannot reach it, how long data is retained, and how long a full recovery of your most important system would take. Ask to see the log from the last test restore. If the answer is that restores are tested “as needed”, assume they have not been tested.
Documentation, ownership and the exit
The relationship may last a decade or it may not, and the terms of leaving are easiest to negotiate before you arrive. Ask who owns the documentation, the administrative credentials, the domain registration, the licences and the backup data. The right answer is that you do, and that they are held in a form you can access. Ask what an exit looks like: how much notice, what is handed over, and whether the provider will cooperate with a successor. Then ask about the contract itself: term, renewal, what triggers a price change and what happens if the service falls short. Our own how we work page sets out our approach because we would rather you know it before the first meeting.
Reference checks that actually tell you something
Ask for references in a business of similar size and sector, and then ask those references the same operational questions: how long tickets take, what happened during their worst outage, whether the provider ever said no to something and why. Ask the provider what they will not do, or what kind of client is a poor fit for them. A firm that has never turned work away has not thought hard about what it does well.
Common questions
Should we choose the largest provider we can find?
Not necessarily. Size brings depth of bench and after-hours coverage, but it can also bring a ticket queue where your business is a small account. A smaller provider may know your environment intimately but struggle when two people are sick. Ask how many staff will know your systems, how escalation works, and what happens during a busy incident affecting several clients at once.
How long should a managed IT contract be?
Long enough for the provider to invest in learning your environment properly, and short enough that a poor fit does not become a multi-year problem. Whatever the term, the important clauses are the ones about service failure, notice, price adjustment and the exit process. Read those before you compare monthly fees, because they are what you will rely on if the relationship sours.
What documentation should we expect to receive?
A current asset list, network diagram, list of accounts and licences, vendor contacts, and a record of standard configurations and known issues. It should be updated as work happens rather than written once. Ask to see a sanitized example from another environment. If the provider cannot show you what documentation looks like, that is a signal about how yours will be kept.
Is a free assessment before signing worthwhile?
Usually, yes, provided it produces something concrete: an inventory of what you have, the risks found, and a proposed scope with the reasoning behind it. Treat it as a chance to watch how the provider works, how they explain things and whether they listen. Be cautious of an assessment that ends in a fear-based pitch rather than a plain list of findings.
If you are comparing providers now and want to see how we answer these questions ourselves, our managed IT services page describes the scope and standards we work to, and you can contact us to put the questions to us directly.


