Choosing a managed IT provider is easy to do badly and expensive to unwind. You’re handing someone the keys to your systems, your data, and much of your ability to operate — and every provider will tell you they’re responsive, secure, and a great fit. The trick is knowing which questions actually separate a good MSP from a mediocre one, and which answers should make you walk away. Here’s what to look for, what to look out for, and the contract terms that matter more than the monthly price.
What to look for
- Clear response and resolution commitments, in writing and tiered by urgency — a down server isn’t a broken printer. “We’re very responsive” is not an answer.
- Proactive work, not just faster fixes. Ask what they actually do between incidents: patching, monitoring, backup verification, security reviews. If it’s vague, you may be buying break-fix with a monthly invoice attached.
- Security baked into the base service — MFA enforcement, endpoint protection, backup, patching, awareness training. A provider who treats basic security as an upsell is telling you something about their priorities.
- Real, tested disaster recovery. Ask how they’d get you running again after a server failure or ransomware, and how they test it. “We have backups” is not a recovery plan.
- Documentation and transparency. If you parted ways, would you get complete documentation of your own systems, passwords, and configurations? That should be an easy yes.
- References from businesses like yours — then ask those references what happens when something breaks at 4 p.m. on a Friday.
What to look out for
- Long contracts with no exit. A three-year lock-in with steep termination penalties is a red flag; a confident provider earns your business monthly.
- “We hold your passwords.” Some providers make it hard to leave by refusing to hand over credentials, documentation, or domains that are yours. Your systems and access belong to you — make sure the contract says so.
- Vague or bundled pricing you can’t decode. If every real problem becomes an “out of scope” charge, the flat fee was fiction.
- No mention of security in the sales conversation. If the whole pitch is help-desk speed and never touches backups or breach response, that tells you where their attention is.
- One-person shops with no coverage plan. Small can be excellent, but ask: what happens when your one technician is on vacation or unreachable in an emergency? A good small MSP has a real answer — documented systems, a partner, defined coverage. “It’s just me and I’m always available” is a single point of failure, not a plan.
- Overselling and fear tactics. A provider who tries to scare you into the priciest package before understanding your business is selling fear, not fit.
The contract terms that matter most
Beyond the monthly price, read for scope (exactly what’s included and what triggers extra billing), response and resolution commitments in writing, term and termination (length, notice period, early-exit terms), data and access ownership (explicit language that your data, credentials, and documentation are yours and returned in full if you leave), and a clear split of security responsibilities between you and them.
The real test
Underneath every question is one thing you’re trying to learn: is this a company that will do the quiet, unglamorous work of keeping your systems healthy when nobody’s watching — or one that shows up only when something’s on fire and bills you for the privilege? The good ones don’t mind hard questions; they appreciate them, because a client who asks about backup testing and data ownership understands the value of doing it right. If a provider gets defensive when you ask how you’d leave, you’ve learned what you needed to know.
Interviewing providers right now? Book a free 30-minute consult. We’re glad to answer every one of these about how we work — and if we’re not the right fit, we’ll tell you.