Posted on

What to Look for in a Managed IT Company: A Buyer Checklist

What to Look for in a Managed IT Company: A Buyer Checklist

Use this during evaluation rather than after it. Most proposals differ from each other on scope rather than on price, so the questions below are designed to surface what a proposal leaves out. Work through it with every provider on your list, including us, and write the answers down. Two or three items will eliminate candidates quickly, which is the point.

Anything a provider will not put in the agreement should be treated as marketing rather than a commitment.

1. Before You Talk to Anyone

Do this first. Without it, the best proposal writer defines your requirements for you.

  • Counted your users and your managed devices, including servers and network equipment
  • Listed your sites and which have technical staff present
  • Listed applications that resist standardisation, and who supports each today
  • Decided your genuine coverage hours, including whether nights and weekends are real requirements
  • Identified every compliance framework that applies through regulation or customer contract
  • Written one page of requirements to send to every provider

Why it matters: a one-page requirements document is the highest-return hour in the whole exercise. It makes proposals comparable.

2. Scope and What Is Included

  • Received a line-item response to your document, not the provider’s own template
  • Read the exclusion list before the inclusion list
  • Confirmed whether third-party application patching is included, or only Microsoft updates
  • Confirmed what counts as a project versus included lifecycle work, in writing
  • Got the out-of-scope hourly rate in the agreement
  • Confirmed whether software licensing is passed through at cost or marked up
  • Confirmed whether hardware procurement is included, marked up, or excluded
  • Asked for the onboarding assessment findings before signing

Red flag: a provider unwilling to scope onboarding remediation up front is deferring an invoice, not absorbing a cost.

3. Security Operations

The largest source of price variance between similar-looking proposals.

  • Established what “endpoint security” means here: detection and response, or managed antivirus
  • Confirmed whether a security operations centre is staffed overnight, and by whom
  • Confirmed which containment actions the provider will take without asking you
  • Confirmed which actions require your approval, and who they call at 3am
  • Got the list of telemetry sources ingested, by name: endpoint, identity, cloud, email, network
  • Confirmed log retention length, and the cost of extending it
  • Confirmed who remediates after containment, on their side or yours
  • Confirmed multi-factor coverage across every remote access path, including vendor access

Why it matters: stolen session tokens bypass multi-factor entirely, so identity telemetry matters as much as endpoint coverage. See our managed security services.

Security Operations

4. The Provider’s Own Security

The section most buyers skip. Your provider will hold privileged access into your environment, which makes their security posture part of your risk. CISA publishes guidance for managed service provider customers on exactly this.

  • Defined the provider’s required privilege levels before contract award, rather than granting broad access and narrowing later
  • Confirmed least privilege applies to the provider and any subcontractor, for the shortest necessary duration
  • Asked how client environments are isolated from one another, answered with specific controls
  • Asked what the blast radius is if another of their clients is compromised
  • Asked how their own administrative accounts are protected, including multi-factor on their side
  • Asked how their remote management tooling is secured
  • Required incident response provisions in the contract, including where the incident is theirs
  • Asked for their own independent attestations
  • Asked for their subcontractor list

Red flag: a provider selling you security evidence who cannot produce any of its own.

5. People and Staffing

  • Got named engineers who will work on your environment, and what happens when they are unavailable
  • Confirmed a documented escalation path with names and hours
  • Confirmed where the service desk is physically staffed, for every tier including overnight
  • Confirmed where the network operations centre is staffed
  • Asked whether any subcontractor holds administrative credentials in your environment
  • Asked about staff turnover on the service desk

If you hold export-controlled technical data: staffing location is a compliance question rather than a service preference. Administrative access by non-US persons is restricted regardless of intent.

Onsite and Coverage

6. Onsite and Coverage

  • Counted the last twelve months of work that genuinely required hands on hardware
  • Got a written onsite response window, not an address
  • Confirmed whether onsite is delivered by employees, a partner, or dispatch
  • Confirmed onsite hours are included, capped, or billed
  • Confirmed which time zone published support hours refer to
  • Asked how many people work at any local office they cite, and what they do

Why it matters: most delivery is remote regardless of address. Proximity only affects the hands-on portion, and that should be a commitment rather than an inference.

7. Compliance and Evidence

  • Confirmed which frameworks they have produced evidence for before, in your sector
  • Confirmed evidence production is a standing deliverable with a cadence, not an annual scramble
  • Confirmed who owns access reviews, and how often they run
  • Confirmed backup immutability and the date of the last tested restore of an environment like yours
  • Confirmed recovery objectives are set per system rather than as one company-wide number
  • Confirmed where backups replicate to, and that it is outside your regional risk footprint
  • Confirmed whether they can support a customer security questionnaire response

Note: a provider managing your environment is generally not independent of it for audit or PCI DSS testing purposes. Those need separating. See our compliance work.

8. Strategy and Roadmap Ownership

  • Asked who owns your technology roadmap, by name
  • Confirmed whether advisory time is included, priced separately, or not offered
  • Confirmed the review cadence, and whether it aligns to your fiscal planning cycle
  • Confirmed what artifacts you receive: roadmap, categorised budget, renewal calendar, risk register
  • Asked for a redacted sample roadmap and a sample board-level report
  • Asked who the advisory relationship reports to on strategy

Red flag: “we handle that as part of the relationship,” with no name, no cadence, and nothing in the agreement. If nobody owns the roadmap you have bought support rather than an IT function. Retained virtual CIO capacity is the usual fix.

9. Contract Terms

  • Modelled the full term with annual escalators, not the first month
  • Confirmed notice periods and termination terms
  • Confirmed any offboarding fees and what transition assistance is included
  • Confirmed documentation and data portability: diagrams, configurations, licence records, credentials, in a usable format, at any point
  • Confirmed how the count is trued up, and whether it can go down as well as up
  • Asked who owns the company now, whether they have been acquired recently, and what happens to your terms if they are acquired again
  • Confirmed response and resolution commitments separately

Why it matters: a one-hour response target with no resolution target is a commitment to acknowledge your outage promptly.

10. References and Due Diligence

  • Took three reference calls at organizations of similar size and sector
  • Asked references: was communication clear
  • Asked references: did problems surface early enough to fix
  • Asked references: were scheduling commitments met
  • Asked references: did invoices contain surprises
  • Asked references: would you sign again
  • Asked for a client of similar profile rather than accepting whoever was offered
  • Read published case studies as background rather than as evidence

11. Onboarding and the First Ninety Days

  • Agreed the scope of the first ninety days before signing
  • Agreed what remediation happens, when, and at whose cost
  • Named an accountable owner on each side, a person rather than a mailbox
  • Agreed the point at which the provider takes full operational responsibility
  • Agreed monthly reporting content, in terms your leadership recognises
  • Agreed a quarterly conversation about direction rather than tickets

Why it matters: the tuning and documentation period determines what the relationship becomes. Providers who resist a defined onboarding scope are telling you how the next three years will go.

12. Red Flags Summary

  • Proposal written in their template rather than against your requirements
  • Reluctance to put a commitment in the agreement
  • No exclusion list, or an exclusion list you had to ask for
  • Vagueness about overnight staffing locations
  • A local address presented as proof of local staffing
  • Discomfort with the question of how you would leave
  • Cannot produce evidence of their own security posture
  • Cheapest quote by a wide margin, which usually means it excluded the most

How to Score It

Do not weight every item equally. Three groups decide most outcomes.

Deal-breakers. Out-of-scope rate not in writing. No named escalation path. No data portability. Cannot answer section 4 at all.

Heavy weight. Security operations depth, staffing locations, onsite commitment in writing, and roadmap ownership. These are the four that separate similarly priced proposals.

Tie-breakers. Reporting quality, references, and onboarding rigour.

If two providers still look identical after this, the differentiator is usually the onboarding conversation. Ask each to describe the first ninety days in detail and see who has done it before.

IT Provider Selection Expertise from Matt Rosenthal

In 30 years of both buying and selling technology services, I have watched buyers spend weeks on feature comparisons without once asking a provider about its own security. What I have seen firsthand is a company choosing the lowest monthly figure, then spending eighteen months buying back everything the quote excluded at project rates and finishing above the proposal it rejected. Our team quotes from an assessment rather than a headcount, and we expect prospects to work through this list with us the same way they would with anyone else. Send every provider the same document. Everything gets easier after that. See our managed IT services and cybersecurity services.

If You Are Keeping Internal IT

Most of this still applies, with one addition. A co-managed arrangement needs a written responsibility matrix: every function, one accountable owner, and explicit handover rules across the time boundary. Split by function and by time of day rather than by system, because system splits produce disputes at exactly the integration points where the hard problems live.

Add these three items:

  • Responsibility matrix agreed and signed before the contract
  • Explicit answer on who owns a ticket at 2am
  • Your internal IT lead involved in provider selection, genuinely rather than as a courtesy

Talk to Us

If you are partway through an evaluation and want a second opinion on your requirements rather than another proposal, that is a reasonable place to start. Schedule a consultation.

Related Posts

Matt Rosenthal