Most guides to choosing a managed IT provider ask the same five generic questions. These five are specific to operating in Lafayette, because this market has conditions that catch providers out and that most buyers never think to raise. A provider who answers all five precisely has worked here. A provider who has to think about them probably has not. Ask every candidate, including us, and get the answers into the agreement rather than the proposal.
Overview
- Energy sector compliance changes your third-party risk profile. Suppliers to energy companies inherit security requirements through their contracts.
- Gulf Coast continuity is not a checkbox item. A recovery copy inside the same storm corridor is not a recovery copy.
- Lafayette sits between Baton Rouge and Lake Charles. Understand whether a provider’s local team is genuinely local or a dispatch operation.
- Energy industry downtime costs by the hour. Your recovery objectives should reflect what operations actually cost when they stop.
- Louisiana has a breach notification statute with a defined deadline.
1. Have You Supported Energy Sector Customers or Their Suppliers Here?
Lafayette is the service hub for offshore and onshore oil and gas operations across the Acadiana region. That concentration produces a specific pressure for businesses in the supplier and vendor ecosystem: the energy companies they serve run third-party risk programs that function as a de facto compliance framework, requiring evidence of access controls, patching practice, incident response capability, and increasingly formal security assessments.
Failing one of those assessments does not generate a fine. It generates a delayed or lost contract, and it arrives on the energy company’s schedule with no warning. A provider who has never worked with an oilfield services firm, an engineering contractor, or a logistics operator serving the energy sector will not know what those assessments ask for or how to maintain the evidence continuously rather than assembling it in a scramble when a deadline arrives.
What a good answer sounds like: specific experience with energy sector vendor assessments, a clear description of what evidence they maintain on an ongoing basis, and references in the oilfield services or energy supply chain sector.
Red flag: generic reassurance about security certifications without a specific answer about third-party assessment support.
Ask also whether they can help with NIST Cybersecurity Framework alignment and documentation, since that is increasingly what energy sector customers reference in their vendor requirements.
2. Where Does Your Backup Replicate To, and Has It Been Tested?

Lafayette sits in the Gulf Coast storm corridor, and a recovery copy inside the same regional power and fiber footprint as your primary environment fails the same test your primary environment fails during a major storm. Two facilities in the same part of Louisiana are one facility when a storm covers the region.
A workable continuity plan replicates outside the corridor, sets recovery objectives per system rather than one number for the business, keeps at least one immutable copy that ransomware and a failed restore cannot delete, and has been tested with an actual restore rather than a backup dashboard report. For operations in the energy supply chain, the recovery order matters as much as the recovery time, because bringing systems back in the wrong sequence means bringing operations back late.
What a good answer sounds like: replication to a region outside the Gulf Coast, a specific recovery time objective for your critical systems, a named date for the last tested restore, and an explanation of what the test covered.
Red flag: backup described in terms of job completion rather than restore testing. A completed backup job tells you data exists somewhere. Only a tested restore tells you how long recovery actually takes.
Ask specifically whether the provider offers immutable backup, meaning a copy that cannot be deleted or altered even by a compromised administrator account, because ransomware operators look for backup infrastructure early. Our disaster recovery work covers this in depth.
3. What Onsite Response Can You Commit to in Acadiana, in Writing?
Most delivery in a managed IT relationship is remote: monitoring, patching, ticket resolution, security operations, and cloud work do not require anyone to be nearby. What does require presence is hardware replacement, plant or field office work, and problems that need someone standing in front of the equipment.
Lafayette anchors a region that extends west toward Lake Charles, east toward Baton Rouge, and south toward the coast. A provider claiming to serve Acadiana may be covering that footprint genuinely or may be covering Lafayette proper with everything else as a longer dispatch. For businesses with locations in Morgan City, New Iberia, or Houma, the distinction matters.
What a good answer sounds like: a written response window for your specific sites, a clear answer about whether onsite is delivered by employees or by a dispatch partner, and any geographic boundaries on that commitment.
Red flag: “We cover the Lafayette area” without a specific response window or a named dispatch arrangement. An address is not a commitment.
Ask what happens if your site is south of the Atchafalaya when a storm is approaching. That is a real scenario in this region, and a provider who has not considered it is telling you something about how they plan.
4. How Does Your Incident Response Plan Account for Louisiana’s Breach Notification Deadline?

Louisiana’s Database Security Breach Notification Law, codified at La. R.S. 51:3074, requires notification to affected Louisiana residents when a breach of personal information is reasonably believed to have occurred, in the most expedient time possible and without unreasonable delay. The Attorney General must be notified when 500 or more Louisiana residents are affected. The practical consequence is the same as any prompt-notification law: meeting it requires logging and detection that produces a documented discovery date, an incident response plan with named steps and contacts already in it, and a provider who has thought about this before you call them with a problem.
What a good answer sounds like: a written incident response process that references Louisiana notification obligations, an explanation of how their logging creates a defensible discovery date, and a named contact for regulatory filing.
Red flag: a provider who hears this question for the first time during your evaluation call. This is not an obscure requirement in a state where energy, healthcare, and financial services are all significant industries.
Ask specifically how long logs are retained, because an investigation that starts weeks after an access event depends entirely on whether the records still exist. Short default retention is the quiet gap that makes notification timelines impossible to meet accurately.
5. What Is Your Security Operations Capability After Business Hours, and Who Specifically Staffs It?
Lafayette’s energy sector clients and their suppliers are not eight-to-five operations. A pipeline monitoring outage, a drilling support system failure, or a security event that starts at eleven on a Friday does not wait for Monday morning. The question is not whether 24/7 coverage is advertised, it is who actually responds when something happens overnight.
Ask for specifics: how many staff are monitoring overnight, where they are physically located, what their authority to act is, and what the escalation path looks like from a first-line alert to someone who can make a containment decision. A security operations center staffed by five analysts and a staffed desk that routes alerts to an on-call engineer are both marketed as 24/7 coverage and are not the same purchase.
What a good answer sounds like: named staffing levels for the overnight shift, a physical location for those staff, and a clear description of what actions they are authorized to take without waking you up.
Red flag: “We have 24/7 monitoring” without any specifics on who monitors, from where, or what they can do. Also ask where the overnight staff are located, because for businesses handling export-controlled technical data that is a compliance question rather than a service preference.
See our managed security services for how we handle this.
Two More Worth Adding
What is excluded, and what is the out-of-scope rate? Most competing proposals differ on scope rather than price. Send every provider the same requirements document and require line-item responses. Read the exclusion list before the inclusion list, and get the hourly out-of-scope rate in the agreement before signing.
What happens when we leave? Ask during the sales process, because it is easiest to get answered before you are a customer. Your network diagrams, configurations, licence records, and administrator credentials should be yours in a usable format at any point, and documentation held only in the provider’s platform is a dependency unrelated to service quality.
Louisiana IT Expertise from Matt Rosenthal
In 30 years of working with businesses across Louisiana, I have seen the same pattern cause the most damage: a business in the energy supply chain that had no documented incident response plan, inadequate log retention, and a backup that had never been tested discovering all three problems simultaneously during an actual event. In Lafayette that combination is particularly costly because the recovery timeline intersects with a customer’s operations, not just your own. Our team maps notification obligations and recovery sequences before we discuss tooling, because a provider who has never considered the Louisiana notification statute or what a storm-corridor backup means will not mention either until you are in the middle of a problem. Ask all five questions. See our managed IT services in Lafayette and cybersecurity services in Lafayette.
How to Use These
Send the same requirements document to every provider, then ask these five questions in the same order on each scoping call. Write the answers down. Two of them will eliminate candidates quickly.
Then ask for three references at organizations of similar size in the Lafayette or Acadiana region, and ask each one: was communication clear, did problems surface early enough to fix, were commitments met, and would they sign again.
Then read the contract before you negotiate the rate. Term length, escalators, the out-of-scope rate, and exit terms determine what the relationship costs more than the monthly figure does.
For related reading, see our guides to IT support in Lafayette, co-managed IT in Lafayette, IT consulting in Lafayette, and our Louisiana service area.
Schedule a consultation if you want a second opinion on your requirements rather than another proposal.

