Checklist · Buying IT
12 Questions to Ask Any IT Provider
Whether you’re hiring your first provider or rethinking your current one, these twelve questions separate a real security partner from a break-fix shop. Print it and bring it to the meeting.
The checklist
Each question comes with what a strong answer sounds like — the part after the dash.
Ownership & accountability
- Do you own the infrastructure you host on, or resell someone else's? — One accountable partner beats a finger-pointing chain.
- When I call, do I reach an engineer or a ticket queue? — Ask for the real response-time target, in writing.
- Who is my point of contact, and what happens when they're out? — Coverage should not depend on one person.
Security posture
- Do you run a 24/7 SOC, or is monitoring business-hours only? — Attacks come at night and on weekends by design.
- Is MFA enforced on every account you manage, including your own admin access? — This is table stakes now.
- How are your backups protected from ransomware? — The answer you want is "immutable, and we test-restore them."
Compliance & evidence
- Can you produce the documentation an auditor or cyber-insurer asks for? — Controls you can't evidence don't count.
- Will you sign the agreements my regulations require (e.g., a BAA for HIPAA)? — A "no" is disqualifying for regulated firms.
Money & exit
- Is your pricing published, or only revealed after a sales call? — Transparency now predicts transparency later.
- What is the contract term, and how do I leave if it isn't working? — Look for reasonable notice and no exit fees.
- What's included versus billed extra? — Get the à-la-carte list so there are no surprises.
Proof
- Can I talk to a current client in my industry? — Real partners arrange references; ask before you sign.
Curious how we’d answer all twelve? That’s the whole assessment. Book a free 30 minutes →