Skip to main content

Ikenegbu Extension, Owerri, Imo State, Nigeria

+234 905 403 1378 [email protected] Mon – Fri · 8:30am – 5:30pm (WAT)

The buyer's guide to managed IT: what to ask before you sign

Managed IT agreements vary enormously in what they actually cover. These are the questions that separate a genuine service commitment from a retainer for occasional phone calls.

Managed IT is one of the most inconsistently defined services in the technology market. Two providers can quote the same monthly figure for radically different obligations. The difference only becomes visible during an incident, which is precisely when you have least capacity to deal with it.

These are the questions we would want answered if we were buying.

What exactly is in scope?

Insist on a written list of covered assets and covered activities. "Your IT" is not a scope.

Specifically establish whether the agreement covers:

  • endpoints, servers, network equipment, cloud tenancies — which of these, and how many
  • third-party software support, or only the operating system
  • user onboarding and offboarding, including access revocation
  • vendor liaison when the fault belongs to someone else's product
  • after-hours and weekend cover, or business hours only
  • project work, or purely reactive and maintenance activity

If project work is excluded, ask what the day rate is and whether it is fixed for the contract term.

What are the response and resolution commitments?

A response time is not a resolution time, and contracts often specify only the first.

Ask for a severity matrix with both:

SeverityDefinitionResponseTarget resolution
1Whole organisation unable to workUnder 30 minutes4 hours
2Department or critical system downUnder 2 hours8 hours
3Single user affected, workaround existsUnder 4 hours2 business days
4Request or non-urgent changeUnder 1 business dayScheduled

Then ask what happens when a target is missed. If the answer is nothing, it is a target rather than a commitment.

Who is my named engineer?

Rotating through an anonymous helpdesk means every incident starts with a stranger relearning your environment.

Ask whether you get a named engineer or account lead, whether they are employed by the provider or subcontracted, and what the handover process is when they leave. A provider with low staff turnover can answer this comfortably.

How is backup actually verified?

Almost every provider says backups run. Very few can show you evidence of a successful restore.

Ask:

A provider that tests restores quarterly and can show you the log is worth significantly more than one that runs nightly jobs nobody verifies.

What security is included, and what costs extra?

Endpoint protection, patching cadence, multi-factor authentication, access reviews and security awareness training are sometimes bundled and sometimes sold separately at multiples of the bundled price.

Ask what is included today, what it would cost to add the rest, and whether the provider will tell you about gaps they find — or only about gaps you ask about.

How do I leave?

This is the question that reveals the most about a provider.

Ask for:

A provider that resists answering this is telling you something important. A good one has an exit process already written down, because confident providers do not expect you to need to use it under duress.

What does reporting look like?

Monthly reporting should tell you something you did not already know. Ask to see a sample.

Useful reporting includes incident volumes and trends, time against target, recurring problems and their root causes, asset and licence status, security posture changes, and recommendations. Reporting that is only a list of tickets closed is an activity log, not a service review.

What is not covered?

Get the exclusions in writing. Common ones include hardware replacement costs, third-party licence fees, physical site visits beyond a monthly allowance, disaster recovery invocation, and major projects.

Exclusions are normal. Undisclosed exclusions discovered during an outage are not.

A practical test before you sign

Ask the provider to walk you through their last significant client incident: what happened, how it was detected, how long resolution took, what the client was told and when, and what changed afterwards.

A provider with real operational maturity can answer this in detail within a minute. One that cannot is either inexperienced or has not been honest about their track record.

Finally: check the incentives

A provider paid a flat monthly fee has an incentive to keep your environment stable and to reduce incidents. A provider paid per incident has an incentive for you to have more of them. Neither model is inherently wrong, but you should know which one you are buying and whether it aligns with what you need.

Chidi Okonkwo Head of Infrastructure

Chidi leads infrastructure and managed IT delivery at Vida ICT. He has spent over a decade running multi-site IT estates across energy, healthcare and education, and is responsible for the SLAs, security baselines and monitoring standards the whole delivery team works to.

Full profile
Vida Technologies

Applying this to your own organisation?

We would rather diagnose your situation than sell you a product. Book a call and we will tell you honestly whether this is worth doing now, later, or not at all.

Keep reading

Related insights