The buyer's guide to managed IT: what to ask before you sign
Managed IT agreements vary enormously in what they actually cover. These are the questions that separate a genuine service commitment from a retainer for occasional phone calls.
COChidi OkonkwoHead of Infrastructure22 June 202610 min read812 words
Managed IT is one of the most inconsistently defined services in the technology market. Two providers can quote the same monthly figure for radically different obligations. The difference only becomes visible during an incident, which is precisely when you have least capacity to deal with it.
These are the questions we would want answered if we were buying.
What exactly is in scope?
Insist on a written list of covered assets and covered activities. "Your IT" is not a scope.
Specifically establish whether the agreement covers:
endpoints, servers, network equipment, cloud tenancies — which of these, and how many
third-party software support, or only the operating system
user onboarding and offboarding, including access revocation
vendor liaison when the fault belongs to someone else's product
after-hours and weekend cover, or business hours only
project work, or purely reactive and maintenance activity
If project work is excluded, ask what the day rate is and whether it is fixed for the contract term.
What are the response and resolution commitments?
A response time is not a resolution time, and contracts often specify only the first.
Ask for a severity matrix with both:
Severity
Definition
Response
Target resolution
1
Whole organisation unable to work
Under 30 minutes
4 hours
2
Department or critical system down
Under 2 hours
8 hours
3
Single user affected, workaround exists
Under 4 hours
2 business days
4
Request or non-urgent change
Under 1 business day
Scheduled
Then ask what happens when a target is missed. If the answer is nothing, it is a target rather than a commitment.
Who is my named engineer?
Rotating through an anonymous helpdesk means every incident starts with a stranger relearning your environment.
Ask whether you get a named engineer or account lead, whether they are employed by the provider or subcontracted, and what the handover process is when they leave. A provider with low staff turnover can answer this comfortably.
How is backup actually verified?
Almost every provider says backups run. Very few can show you evidence of a successful restore.
Ask:
what is backed up, how often, and retained for how long
where backups are stored, and whether a copy is off-site or immutable
when a full restore was last tested, and what the result was
what the recovery time and recovery point objectives are, in hours
whether ransomware protection is included and how it works
A provider that tests restores quarterly and can show you the log is worth significantly more than one that runs nightly jobs nobody verifies.
What security is included, and what costs extra?
Endpoint protection, patching cadence, multi-factor authentication, access reviews and security awareness training are sometimes bundled and sometimes sold separately at multiples of the bundled price.
Ask what is included today, what it would cost to add the rest, and whether the provider will tell you about gaps they find — or only about gaps you ask about.
How do I leave?
This is the question that reveals the most about a provider.
Ask for:
the notice period and any early-termination charges
what happens to documentation, credentials and configurations on exit
whether they will hand over directly to your internal team or a successor provider
how long a transition period is included
A provider that resists answering this is telling you something important. A good one has an exit process already written down, because confident providers do not expect you to need to use it under duress.
What does reporting look like?
Monthly reporting should tell you something you did not already know. Ask to see a sample.
Useful reporting includes incident volumes and trends, time against target, recurring problems and their root causes, asset and licence status, security posture changes, and recommendations. Reporting that is only a list of tickets closed is an activity log, not a service review.
What is not covered?
Get the exclusions in writing. Common ones include hardware replacement costs, third-party licence fees, physical site visits beyond a monthly allowance, disaster recovery invocation, and major projects.
Exclusions are normal. Undisclosed exclusions discovered during an outage are not.
A practical test before you sign
Ask the provider to walk you through their last significant client incident: what happened, how it was detected, how long resolution took, what the client was told and when, and what changed afterwards.
A provider with real operational maturity can answer this in detail within a minute. One that cannot is either inexperienced or has not been honest about their track record.
Finally: check the incentives
A provider paid a flat monthly fee has an incentive to keep your environment stable and to reduce incidents. A provider paid per incident has an incentive for you to have more of them. Neither model is inherently wrong, but you should know which one you are buying and whether it aligns with what you need.
Chidi leads infrastructure and managed IT delivery at Vida ICT. He has spent over a decade running multi-site IT estates across energy, healthcare and education, and is responsible for the SLAs, security baselines and monitoring standards the whole delivery team works to.
We would rather diagnose your situation than sell you a product. Book a call and we will tell you
honestly whether this is worth doing now, later, or not at all.
We use strictly necessary cookies to keep your session alive while you move between pages and submit
forms, and to remember your name and organisation if you use the customise feature. We do not use
advertising or cross-site tracking cookies.
Cookie & privacy policy
Your experience
Customise your experience
Tell us who you are and where to start. We will remember it on this device, pre-fill your
enquiries, and route you straight to the right pillar.