What to ask before you hire an IT support provider

Before you hire or renew an IT support provider, ask five things: how the pricing is structured, what response times are actually contracted, what security credentials they hold and what those credentials prove, what happens when something goes wrong, and whether the arrangement can grow with you. This checklist works whether you are sitting across from a new provider or quietly reassessing the one you already have. It assumes nothing about switching. Five groups of questions follow, each with a note on what a good answer sounds like, and a short worked example at the end showing how Lanmark answers the same list.

Why it is worth asking these questions now, not after signing

Most businesses do not choose their IT arrangement so much as inherit it. Someone set it up years ago, the invoices kept arriving, and nobody has revisited it since. So the first hard question usually gets asked on the day something has already gone wrong, which is the worst possible day to learn that the response time you assumed was contractual was only ever a friendly assurance over the phone.

These are questions for a calm day: a renewal, a budget review, or the week a new provider approaches you out of the blue. Ask them of the provider you already have, and treat the quality of the answer as information in its own right. For a plain-English picture of what the service should cover, our guide to managed IT services in London sets out the usual scope.

Questions about pricing and what is actually included

The headline monthly number is the least informative part of any IT proposal. What matters is the shape of the pricing, because that determines what your bill does over the next three years as you hire people and add devices. For market context, see our guide to what managed IT support typically costs.

  1. Is pricing per user, per device, or per incident, and what does that mean for our costs as we grow or add devices? A good answer explains the model and shows the arithmetic for ten more staff. Per-incident billing rewards not fixing root causes.
  2. What is included in the monthly fee, and what is billed separately? Ask for a written inclusion list. Honest answers name the exclusions, usually hardware, third-party licences and project work.
  3. Are security monitoring and out-of-hours support included, or are they add-ons? A good answer is unambiguous either way. Beware a low headline price that excludes what matters most at three in the morning.
  4. Is there a minimum contract term, and what does leaving cost or involve? A confident provider states the notice period and exit process without becoming defensive. The willingness to answer matters more than the term.
  5. Will the price change during the contract, and under what circumstances? Look for a stated uplift mechanism, such as an annual review tied to a published index, not a discretionary right to raise prices.

Questions about response times and SLA commitments

An SLA, or service level agreement, is the contractual promise about how quickly the provider will react and how quickly they will fix things. It is the difference between a courier promising next-day delivery in writing and one saying your parcel will arrive sometime this week. Only one of them owes you anything if it does not happen. Note the two halves: response time is how long before a human engages, resolution time is how long before the problem is solved. A fifteen-minute response with no resolution commitment is a fast hello.

  1. What are the contracted response and resolution times, in writing, not just spoken assurance? A good answer is a document or a clause reference, produced without hesitation. Numbers that exist only in conversation do not exist.
  2. Do response times change for critical issues versus minor ones, and how is “critical” defined? Tiered targets are normal. Check who decides the tier: if the provider classifies severity alone, the top tier becomes hard to reach.
  3. Is support available out of hours, and at what cost? A good answer covers who is on duty overnight and at weekends, and whether it is a full service or an answering line.
  4. Who actually picks up the phone, an in-house team, an offshore desk, or a subcontractor? There is no single right answer, only a right behaviour: telling you straightforwardly. Ask whether the same engineers will learn your business.
  5. Can we see real performance data against the SLA, not just the target? A good answer is a report of achieved times over the last quarter, including the months that went badly.

Questions about security credentials and accreditations

Two pieces of jargon come up constantly here. MDR stands for managed detection and response: a service that watches your systems for signs of attack and acts on what it finds. A SOC, or security operations centre, is the team doing that watching. Think of a night guard who raises the alarm while the intruder is still climbing through the window, rather than an alarm you hear about next morning when you find the door forced.

  1. What security monitoring is in place, and is it continuous (24x7x365) or business hours only? Attacks are launched outside working hours precisely because nobody is watching. A good answer states the coverage hours and what happens at two in the morning.
  2. What accreditations do you hold, and what did you have to prove to get them? The second half of that question is the useful half. Certifications differ enormously in how much evidence they demand.
  3. Are you a Microsoft-accredited partner, and at what level? Partner status comes in tiers, some bought and some audited. Ask which designations they hold, and whether they buy Microsoft licences directly or through an intermediary.
  4. How do you handle patching and updates across our systems? Look for a centrally managed process with reporting, so someone can say which machines are current. Automatic updates on laptops is a setting, not a process.
  5. Can you demonstrate compliance relevant to our sector, where relevant? If you operate under a regulator, ask for the evidence pack they would send. Providers used to regulated clients have one ready.

Questions about what happens if things go wrong

Every provider looks capable when nothing is broken. This group is about their failure modes: what they do in a genuine incident, and whether your data would come back to you intact if you asked for it.

  1. What happens in the first hour of a suspected cyber incident? A good answer is a sequence, not a sentiment: who is contacted, who can isolate a machine or disable an account, and when you are told. Vagueness here is the clearest warning sign on the checklist.
  2. Do you have a documented disaster recovery and business continuity plan, and have you tested it? The word to listen for is tested. Ask when the last restore was performed and what it proved. A backup nobody has restored from is a theory.
  3. Who owns our data and documentation, and can we get it in a usable format if we ever need to? Ownership should sit with you, with network documentation, passwords and licence records available on request. Treating your documentation as their property creates a dependency, not a service.
  4. What is your record on major outages or incidents, and how did you communicate during them? Nobody has a clean sheet, so you are testing candour. A provider who describes a bad week honestly, and what changed after it, is the safer bet.
  5. Is there a single point of failure, one person or one system, if something goes wrong? Ask what happens when the engineer who knows your setup is on holiday. Good providers answer with documentation, not a reassuring name.

Questions about scalability

The arrangement that suits you at forty users can become the thing holding you back at ninety. These questions test whether the provider is built to move with you.

  1. How do you handle onboarding new starters and offboarding leavers? Look for a defined process with a stated turnaround, particularly how fast a leaver’s access is revoked. Slow offboarding is a security exposure, not just an irritation.
  2. Can the arrangement flex up and down as headcount changes, without renegotiating the whole contract? A good answer explains how user numbers are counted and adjusted, and confirms that dips count as well as increases.
  3. How do you support a new office, a merger, or a move to hybrid working? Ask what this looks like commercially as well as technically: whether a second site is a separate quotation or already covered.
  4. Do you offer strategic input (a technology roadmap), or purely reactive support? A good answer names the person you would meet periodically and what those conversations produce, such as a budgeted plan rather than a list of products.
  5. What is your capacity to take on a business twice our current size, and have you done it before? You are asking about engineering headcount and bench strength. A candid provider names their comfortable ceiling; one with no ceiling has not thought about it.

How Lanmark answers these questions

The list above is deliberately neutral, so it is only fair to run it over ourselves. Lanmark has supported UK businesses since 1994.

Pricing. Our managed support is unlimited and priced per user, with no per-device and no per-incident billing. If somebody picks up a second laptop your bill does not move, and nobody has to weigh up whether an issue is worth logging.

Response and SLA. Our response and resolution commitments are contractual and set out in writing in the service agreement, not offered as a verbal assurance during a sales conversation. We report achieved performance, not just the target.

Security. Managed detection and response is delivered by our own security operations centre, monitoring 24x7x365, and it is part of the managed service rather than a separately priced add-on.

Credentials. We are a Microsoft Direct CSP, holding the Microsoft licensing relationship directly rather than reselling through an intermediary, and we hold Microsoft’s Support Service Designation, an accreditation held by only a handful of partners worldwide and assessed on measured support quality rather than sales volume. We also hold Cyber Essentials, the UK government-backed certification covering the basic technical controls.

Continuity and scalability. If you would rather see how we work before committing to anything, our free Microsoft 365 licence review is the lowest-friction way to do it: a review of what you are paying for against what you are using, with no obligation attached.

What to do with your answers

Run this checklist on whoever is in front of you, including the provider you already have, and write the answers down. The value is in comparing them side by side rather than in any single response. If the exercise reassures you, it has cost you an hour. If it does not, our guide to switching IT support provider explains how a handover works. Either way, you are welcome to put the same questions to us.

Put these questions to us

Or call 020 7123 4910

Frequently asked questions

What is the single most important question to ask an IT support provider?

Ask what happens in the first hour of a suspected cyber incident. It is the question a provider cannot answer well without having genuinely thought it through, because a good answer is a sequence of named actions and decision-makers rather than a reassurance. It also reveals how they communicate under pressure, which is the thing you will care about most on your worst day.

How do I know if my current IT provider is actually good?

Ask for evidence rather than opinions. Request achieved performance against your service level agreement for the last quarter, a dated report showing which devices have current security patches, and the date of the last successful test restore from backup. A provider doing the work will produce all three without difficulty. Difficulty producing them is itself the finding.

Should I ask these questions even if I am not planning to switch?

Yes, and arguably especially then. Asking on a calm day, at a renewal or a budget review, gives you a baseline while there is no pressure and no crisis colouring the conversation. A capable provider will welcome the questions because the answers are things they already track. The exercise costs an hour and either reassures you or tells you something worth knowing.

What is an SLA and why does it matter?

An SLA, or service level agreement, is the contractual promise about how quickly your provider will respond to a problem and how quickly they will resolve it. It matters because it turns an intention into an obligation. A verbal assurance that someone will get to you quickly carries no weight when it does not happen, whereas a written commitment gives you something to hold them to.

What does MDR and SOC mean in plain English?

MDR stands for managed detection and response: a service that watches your systems for signs of attack and acts on what it finds rather than simply logging it. A SOC, or security operations centre, is the team doing that watching. Think of a night guard who patrols continuously and raises the alarm during the break-in, not the following morning when the damage is already done.

What accreditations should a good IT support provider hold?

Look for Cyber Essentials, the UK government-backed certification covering basic technical controls, and a current Microsoft partner status with the specific designations named rather than described vaguely. Ask what each accreditation required them to prove, because certifications differ enormously in how much evidence they demand. Sector-specific compliance evidence matters too if you operate under a regulator.

Is per-user pricing better than per-device pricing?

For most businesses, yes, because it is predictable. Per-user pricing stays flat when someone picks up a second laptop, a tablet or a phone, whereas per-device pricing rises every time hardware multiplies, which it tends to do quietly. Per-device can suit an organisation with very few devices per person. The important thing is understanding which model you are on before you sign.

How do I compare answers from two different providers fairly?

Ask both exactly the same questions, in the same order, and write down the answers rather than relying on impressions. Compare inclusions rather than headline prices, since the cheaper monthly figure often excludes security monitoring or out-of-hours cover. Note where either provider was vague, because consistent vagueness on a specific topic usually indicates a genuine gap rather than an oversight.

Book a no-obligation conversation

Or call 020 7123 4910