MCR Business Tech Solutions

Services

Managed IT

We Are Interviewing Three IT Companies Next Week and Nobody Here Knows What to Ask

MCR Business Tech SolutionsAugust 18, 20269 min read

The credit union has twenty two employees across two branches, one in Greenville and one in Sharpsville. Their IT arrangement had been the same for eleven years: a local shop that answered when called, invoiced by the hour, and never appeared otherwise. Then the examiner asked for documentation of how they oversee their technology vendor, and nobody could produce anything except a folder of invoices.

So they did what most businesses do. They asked around, got three names, and scheduled three meetings. Then the CEO called us and said the thing we hear constantly: all three sound the same in the room, and we do not know enough to tell them apart.

That is the honest problem. Choosing an IT company for a small business is not like choosing a landscaper, where you can see the result from the parking lot. Most of what a good provider does is invisible on purpose. The difference between a strong one and a weak one shows up eighteen months later, on the morning something fails, and by then you have already signed.

What follows is the list of questions we would want a business to ask us. Some of them we get asked constantly. Most of them we almost never do.

What is the difference between an IT company that fixes things and one that prevents them?

This is the first fork in the road, and it decides most of the rest.

The break/fix model is straightforward: something stops working, you call, somebody bills you for the time it takes to fix it. It feels fair. The trouble is what it quietly teaches everybody. The provider only earns when things are broken, and you only call when the pain is bad enough to justify the invoice, so the small warning signs (a backup that has been failing for three weeks, a drive at ninety six percent capacity, twelve machines that never took the last security patch) sit there unaddressed until they become the outage.

Managed IT, the model where one company handles your technology for a flat monthly fee, inverts that. Monitoring, patching, backup verification, and security maintenance happen whether or not anybody calls, because the provider absorbs the cost of the emergency. It is the same reason your equipment vendor sells service plans. Nobody wants the 2 a.m. call, so the incentive is to prevent it. We wrote a full breakdown of what flat-fee IT actually covers if that comparison is where your evaluation currently sits.

The question to ask each of the managed IT companies on your list is simple: what do you do for us in a month where nothing breaks? A real provider will describe specific recurring work and show you a report of it. A break/fix shop in managed clothing will change the subject to response times.

What should we ask before we sign anything?

Get these answers in writing, not in the room. The room is where everybody sounds the same.

What exactly is included, and what generates an extra invoice? Ask for the list of things that fall outside the monthly fee. Every agreement has one. Project work, hardware, third party software licensing, and after hours emergencies are common and reasonable exclusions. What matters is whether the provider will state them plainly before you sign or let you discover them on a surprise invoice in month four. If the pricing conversation is still fuzzy, our guide to managed IT pricing models explains what drives the number up and down. What is the response time, and is it response or resolution? These are not the same thing and the difference is where most disappointment lives. Response time is how long until a human being engages with your problem. Resolution time is how long until you are working again. A provider who promises a one hour response is promising contact, not repair. Ask how tickets are prioritized, who decides the priority, and what happens when your definition of urgent and theirs disagree. What are the hours, and what happens outside them? A dental office cares about 7 a.m. A manufacturer on second shift cares about 9 p.m. Ask what after hours coverage means: a person on call, or a voicemail box checked in the morning. What is the term, and how do we get out? Long initial terms are not automatically bad, but they should buy you something. Ask what happens if service quality drops in month five of a thirty six month agreement. A provider confident in its work will offer a way out with notice.

Who actually answers the phone when we call?

Ask this one bluntly, because the answer reveals the shape of the whole company.

You want to know how many technicians there are, whether you will speak to the same few people over time, and what happens when the person who knows your network is on vacation. Both extremes fail. A one person operation is genuinely responsive right up until that person is sick, on another job, or retires, which is the same single point of failure you were trying to fix. A very large provider has depth, but a twenty person account can end up cycling through whichever technician is free, each one relearning your setup on your time.

The follow up question is better: how is what you learn about our business written down? Good providers document relentlessly, because documentation is what lets any technician help you competently on the first call. Ask to see a sample (anonymized) of what they maintain for a client of your size. Ask whether help desk support is staffed by their own people or subcontracted, and if it is outsourced help desk services from a third party, ask who is accountable when something falls through.

What happens to our passwords and documentation if we leave?

This is the question almost nobody asks, and the one that costs the most when it goes unasked.

Over the course of a relationship, your IT company accumulates the keys to your business: administrator accounts, domain registrar and DNS access, firewall configurations, Microsoft 365 tenant ownership, backup credentials, license records, network diagrams. If the relationship ends badly, or the provider is acquired, or the owner retires, whoever holds those keys holds real leverage.

Ask directly. Do we own our own Microsoft 365 tenant and our domain registration, or are they inside your account? Will you hand over documentation and credentials at the end of the agreement, and is that obligation written down? Is there a transition period? A provider who answers cleanly has nothing to protect. A provider who gets uncomfortable is telling you exactly what a departure would look like. We have written about what happens when the relationship changes without warning, which is what to do when your IT provider gets acquired.

How do we tell if an IT company takes security seriously?

Every provider says security is a priority. Very few can show it, and the difference is easy to test.

Ask what security is included in the base agreement rather than sold as an upgrade. At minimum you should hear about endpoint protection on every machine, patching on a defined schedule, multi-factor authentication (a second verification step beyond a password) on email and remote access, email filtering, and backups that are tested rather than merely running. Ask when they last restored a file from backup for a client, and how they know a backup would work.

Then ask the question that separates them: can we see a sample of the monthly security report you send clients? A provider with a real program produces one that day. A provider without one produces a proposal.

Two more that matter for a small business. Ask whether they will help you complete your cyber liability insurance questionnaire, because insurers now ask about controls you may not have, and answering yes to something you cannot demonstrate puts a future claim at risk. And ask what their own security looks like, since your provider is a doorway into your business. Named accounts for each technician rather than a shared login, multi-factor authentication on their remote tools, and session logging are the baseline. If you want an outside read before you commit, an independent cybersecurity assessment will tell you what shape you are actually in.

Does an IT company need to understand our industry?

For a regulated business, yes, and you can test it in five minutes.

The credit union in Greenville is a good example. Financial institutions live under the FTC Safeguards Rule, which requires a written information security program, multi-factor authentication, encryption, and (this is the part that decided their vendor search) documented oversight of the service providers who touch their systems. Their IT company was not just a vendor. It was a compliance obligation they had to be able to evidence.

The same is true elsewhere. A dental office or an independent pharmacy operating under HIPAA needs a business associate agreement signed before a technician ever touches a workstation, plus access controls and audit logs. A hardware store or restaurant taking cards lives under PCI rules about unique credentials and remote access. A defense or aerospace supplier around the Shenango Valley may need CMMC status to stay eligible for contracts.

So ask each provider a question from your own world: what would you need to do differently because we are a credit union, or a dental practice, or a machine shop with a government customer? You are not testing their memory of a regulation. You are testing whether they have done it before. The provider who has will answer with logistics (the agreement to sign, the logging to turn on, the reporting you will need at exam time). The provider who has not will answer with reassurance.

What should the first thirty days look like?

Onboarding is where you find out what you bought, so ask for the plan before you sign rather than after.

A real onboarding is an inventory and a documentation exercise. Every machine, server, network device, cloud account, license, and vendor relationship gets found and written down. Backups get verified, not assumed. Security gaps get listed with a plan and a sequence. Accounts belonging to people who left in 2023 get closed. You should come out of it with a written picture of your own technology that you could hand to somebody else, which is worth having no matter who you hire.

If a provider cannot describe that in specifics, they are planning to learn your business one emergency at a time, on your clock. That is also why we run an assessment before quoting anything: here is what an IT assessment actually involves.

Making the decision

When three providers sound the same in the room, put them on paper. Same questions, same order, written answers. The differences show up immediately, and they are rarely about price. One will send documentation samples and a security report by the next morning. One will send a proposal. One will send a follow up asking when you would like to start.

Weigh the boring answers heaviest. Documentation, backup testing, exit terms, and who picks up the phone will matter far more over three years than anything in the presentation. And take the reference calls, but ask the references a sharper question than whether they are happy: ask what happened the last time something went badly wrong.

We support small and mid-sized businesses across Mercer, Lawrence, Butler, Crawford, Venango, and Erie counties (Greenville, Sharpsville, Hermitage, Sharon, Grove City, New Castle, Ellwood City, Meadville, Franklin) along with bordering eastern Ohio. If you are running an evaluation right now, we are happy to be one of the three, and we will give you the written answers to every question above whether or not you pick us. Call 833-859-9021 or Request an IT assessment through our contact page, and if you would rather start with a plain look at managed IT support, start there.

it company for small businessmanaged it companieschoosing an it providermanaged it supportmercer countywestern pa

Talk to us

Ready for IT
that just works?

No commitment. No sales pitch. Just a straightforward conversation about your tech.

Call 833-859-9021Get Assessment