10 Questions to Ask an IT Support Provider Before You Sign
A vendor-neutral guide for UK SMEs choosing an IT provider: 10 questions that cut through the pitch, what a strong answer looks like, a provider scorecard and a red-flag cheat sheet.
Want a printable version with the full scorecard table?
Download the PDF guideWhy this matters
You rely on a Managed Service Provider (MSP) for your email, your devices, your backups and your security. Every provider will tell you they're proactive, secure and responsive. The hard part is knowing who can prove it.
Here's what the National Cyber Security Centre (NCSC) now says plainly: your MSP has more access to your business than almost anyone. They can read your email, control every laptop, reach your files and backups, and create or delete accounts. If their standards slip, your security inherits the weakness, silently.
And unlike accountants, solicitors or IFAs, the MSP industry isn't regulated. Anyone can call themselves one. No regulator is doing the checking for you, so this guide is your toolkit for doing it yourself.
The one idea to hold onto: most MSPs promise they keep you secure and well run. Very few can prove it. The gap between promise and proof is where your risk lives. Your job as a buyer is to close it.
Four things about this market most buyers never realise:
No licence to lose, no register to be struck off. The checking is on you.
They show a provider cleared a bar on one day, often months ago - not that they're still meeting it today. An MSP can be fully certified and materially insecure at the same time.
You can feel whether they answer the phone. You can't feel whether MFA is enforced, patches are current, or backups would actually restore.
A compromise of them can become a compromise of you. When you assess an MSP, you're inheriting their security posture as your own.
How to use this guide: Ask all 10 questions. Score each provider as you go using the scorecard near the end. For each question you'll see what a strong answer sounds like, the answer that should give you pause, and the follow-up that separates the providers who evidence their work from the ones who just talk a good game. The first five work in an early call or demo; the second five are worth pushing on before you sign anything. A good provider will welcome these questions. The strongest will have the answers ready.
How do you evidence your security practices to clients, and can I see examples?
Anyone can say they take security seriously. The question is whether they can show you.
Strong answer: "Here's a sample security report, here's how often we produce them, and here's the independent proof behind the claims." Something real, redacted if needed.
Pause: "We follow best practice" with nothing to look at, or a glossy PDF with no dated evidence behind it.
Follow-up: "Can I see something dated in the last 90 days?"
What certifications do you hold, and are they current?
Certifications are a useful floor, not a ceiling. Cyber Essentials is the UK baseline. Cyber Essentials Plus adds hands-on, independently assessed technical testing (insist on Plus, not the self-declared tier, and verify it on the NCSC/IASME register). ISO 27001 and SOC 2 are broader information-security standards. Every certificate describes a moment in the past, so what matters as much as the badge is how they keep it true between assessments.
Strong answer: they name what they hold, when it was last assessed and by whom, and can show the standard is maintained day to day.
Pause: "We're basically Cyber Essentials level" (they either hold it or they don't), or a certificate that expired 18 months ago.
Follow-up: "What's the renewal date, and how do you keep it true between assessments?"
How do you handle a security incident, and what's your guaranteed response time?
Incidents are a question of when, not if. What matters is what happens in the first hour: a plan, a clock, and a named human.
Strong answer: a clear, written incident process, a defined response time in the contract, out-of-hours cover, and an example of a real incident they handled well. (NCSC benchmark: under 1 hour for urgent issues.)
Pause: "We'd deal with it straight away" with no written process and no response time you can hold them to.
Follow-up: "Is that response time in the contract, and what happens if you miss it?"
What compliance frameworks do you support?
If you're in a regulated or sensitive sector (finance, healthcare, legal, anything under FCA, NHS DSPT or GDPR obligations, or subject to your own clients' security questionnaires), your IT provider either makes compliance easier or quietly makes it your problem.
Strong answer: they ask which frameworks apply to you before answering, then explain how they support them with evidence you can hand to an auditor or a client.
Pause: a blanket "yes, we do all of that" with no detail.
Follow-up: "When my client sends me a security questionnaire, how much of it can you help me answer with evidence?"
Can I speak to references in a similar industry to mine?
A reference from a business that looks like yours is worth more than any case study.
Strong answer: two or three relevant references offered without hesitation, ideally in your sector or size band.
Pause: reluctance, delay, or a single hand-picked reference who happens to be the owner's mate.
Follow-up: "How long have they been with you, and has anything ever gone wrong?"
How do you keep your own business secure?
Your provider holds the keys to your systems, and a growing share of serious incidents now start at the provider, not the business. Their security is your security.
Strong answer: they evidence their own controls, are independently assessed, and can prove it's maintained, not just claimed.
Pause: surprise at the question, or "we're the experts, don't worry about us."
Follow-up: "Who independently checks that, and how often?"
If we part ways, who owns my data and accounts, and how do you hand them over?
The easiest time to leave a provider is before you join one. You're checking for lock-in: do you own your Microsoft tenant, domains and documentation, and can you get them back cleanly?
Strong answer: "You own everything, it's all in your name, and we have a written offboarding process to hand it over."
Pause: vagueness about who owns what, licences or domains under the provider's account, or an offboarding "fee" that looks like a penalty for leaving.
Follow-up: "Are my Microsoft 365 tenant and domain names registered in my company's name today?"
Who actually does the work, and will I have a named point of contact?
The person who sells you is rarely the person who supports you. Response times on paper mean little if every ticket goes to a different stranger.
Strong answer: a clear picture of the support team, a named account manager or lead engineer, and honesty about what's in-house versus handled by partners.
Pause: "You'll get through to the team" with no names.
Follow-up: "When I raise a ticket on a Tuesday afternoon, who sees it and how quickly?"
What's not included, and what triggers an extra charge?
The gap between the monthly fee and the real annual cost is where a lot of relationships sour.
Strong answer: a straight walk through what's in and out of scope, honest examples of what gets billed extra, and clear pricing for the common ones.
Pause: "It's all included" (nothing ever is), or a contract where the exclusions are buried and the day rate is a surprise.
Follow-up: "Show me three things clients commonly assume are included but aren't."
How will you prove, month to month, that you're doing what you promised?
Onboarding promises are easy. The question is what proof you get in month 8, when nobody's watching, that patching is happening, backups are working and security is holding.
Strong answer: regular reporting you can actually read, review meetings that show evidence rather than reassurance, and ideally independent verification.
Pause: "We'll let you know if there's a problem", which puts the entire burden of proof on the one party who can't see inside the systems: you.
Follow-up: "What can you show me, on demand, that proves it's still being done?"
Behind questions 1, 3 and 10 sit the technical points the NCSC says every SME should confirm. Ask for evidence, not assurance.
Patching: critical and high-risk fixes applied within 14 days, with a documented policy and compliance data.
Backups: "When did you last test a full restore?" Confirm off-site or off-network storage, encryption and immutability.
Access and MFA: multi-factor enforced on all accounts, including their own admin access into your systems, with least privilege and prompt removal when people leave.
Logging: security logs kept for a defined retention period and reachable by you or your incident responder.
End-of-life systems: a named owner for tracking when hardware or software goes end-of-life, and acting before support ends.
SLAs: response and resolution times. NCSC benchmarks: response around 1 business day for routine, under 1 hour for urgent; resolution 2 to 3 business days for routine medium-priority issues. Faster costs more, so decide what you need.
Regular reporting: scheduled audits (surfacing unapplied patches, unnecessary admin rights, weak passwords) and infrastructure health reports (uptime, patch compliance, backup success and failure, security alerts). This creates an auditable trail, which matters because cyber insurers may ask to see recent reports when validating a claim. No evidence can mean no payout.
Incident notification: the timeframes you'll be told about a breach, scaled to severity, with the process documented.
Liability: who's accountable for vulnerabilities, damages and incidents, including any third parties they use.
A responsibilities matrix: a written split of what the MSP does and what's left to you.
Businesses rarely leave over one dramatic failure. They leave over the slow accumulation of small doubts. Recognise several of these in the provider you've got, and you're closer to the exit than you think.
Slow when it matters: demand a clear SLA (urgent under 1 hour) and live reporting that proves they hit it.
The same things keep breaking: demand evidence they fix the cause, not just re-close the ticket.
When it breaks, no one owns it: demand a documented escalation path plus satisfaction data.
Only ever problems, never ideas: demand proof they catch issues via monitoring before you feel them.
No one talks about your business: demand regular business reviews aligning IT to where you're heading.
You're privately worried about security or backups: demand current, independent evidence that patching, encryption and backup restores actually work.
Invoices keep surprising you: demand clear, itemised invoices and a defined query process.
You feel like you don't matter: demand structured check-ins, senior visibility of complaints, low staff turnover.
The thread through every "what to demand" is the same: proof.
Score each provider 0, 1 or 2 across all 10 questions and compare up to three side by side. 0 = couldn't answer or a red flag; 1 = answered, but vague; 2 = clear answer, backed by proof.
A provider who can evidence their work - shortlist them.
Decent, but push hard on the low scores before you commit.
Lots of promises, little proof - keep looking.
(The downloadable PDF includes a printable scorecard table.)
- "We follow best practice" with nothing to show you.
- A certificate that's out of date, or "we're basically [certification] level".
- No response time they'll put in the contract.
- Surprise or defensiveness when you ask about their own security.
- Your Microsoft tenant, domains or licences registered in their name, not yours.
- An offboarding fee that reads like a penalty for leaving.
- No named contact, and no straight answer on where support sits.
- "It's all included" with the exclusions buried in the small print.
- "We'll let you know if there's a problem" as the entire proof model.
- Only one reference, and it's the owner's mate.
The shortcut: find a provider who can already prove all this
Asking good questions is half the job. The other half is knowing which providers can back up their answers. A small but growing number of UK IT providers now hold an independent trustmark called Assurix Trusted MSP. It checks 64 controls covering their security and how they run the business, every control has to pass, it's monitored continuously between annual assessments, and it's aligned to the NCSC Cyber Assessment Framework. Unlike a certificate, which is a photograph of one day, the trustmark pulls live evidence from the provider's own systems and can be suspended or revoked if their controls lapse. An Assurix Trusted MSP has already answered most of these 10 questions, and had the answers independently checked.
Browse verified providers and build your shortlist faster than a cold search.
Browse verified providersGrounded in the NCSC's "Choosing a managed service provider (MSP)" (v1.0, November 2025) and Assurix's SME guidance. General information to help you evaluate providers, not legal, financial or insurance advice.
Want a printable version with the full scorecard table?
Download the PDF guide