Managed IT
Questions to Ask Before Signing With an MSP
Choosing an MSP is not just about price. Ask these practical questions about responsibility, security, support, tools and contracts before you sign
· 8 min read
Start with what the MSP will actually own
Choosing a managed service provider is partly a technical decision, but it is also a decision about responsibility. You are not simply buying access to engineers. You are handing another organisation responsibility for parts of your IT environment, so you need to understand exactly what they will operate and what remains with your team.
Start by asking the provider to describe your environment in practical terms. Which endpoints, servers, network devices, Microsoft 365 services, cloud platforms, backup systems and security tools will they manage? If an important system is missing from the answer, do not assume it is included because the proposal uses a broad phrase such as "fully managed IT".
Ask these questions before comparing monthly prices:
- What systems are included?
- Who monitors them?
- Who maintains them?
- Who responds when something fails?
- What work is included in the monthly fee?
- What becomes a separate project?
- What responsibilities remain with us?
A good MSP should be comfortable answering these questions without hiding behind generic service descriptions. The purpose is not to make the contract complicated. It is to make responsibility clear.
Ask how support actually works
"24/7 support" and "fast response" sound useful until you understand what they mean operationally. You need to know who receives an alert, who investigates it, when an engineer becomes involved and how serious incidents are escalated.
Ask for the provider's priority definitions. A failed laptop for one user is different from a failed domain controller, firewall or Microsoft 365 authentication problem affecting the whole company. The MSP should have a process for distinguishing these situations and assigning the right level of response.
Also ask what happens outside normal business hours. Some providers have engineers available overnight. Others have automated monitoring that raises an alert but only investigate during business hours. Neither model is automatically wrong, but you need to know which one you are buying.
The same applies to projects. A good provider should tell you whether activities such as migrations, major network changes, new office deployments and complex application troubleshooting are included in the managed service or billed separately. This is one of the areas where a detailed managed IT services description is more useful than a generic promise of unlimited support.
Ask who is responsible for security
Cybersecurity should not be treated as a separate conversation from IT operations. The MSP may manage the endpoint protection platform, patching, Microsoft 365 administration, user accounts, firewall and other controls. If nobody clearly owns those tasks, gaps can develop between the security tools you have purchased and how they are actually operated.
Ask which security products they will manage and what "management" means. Does it include policy configuration, alert investigation, isolation of compromised endpoints and remediation? Or does the provider simply install the software and forward alerts to your internal team?
You should also ask about administrator access. Find out which accounts the MSP will use, how privileged access is protected, whether MFA is required and how access is removed when an engineer leaves the provider.
If the MSP performs security reviews, ask what happens after weaknesses are identified. A report alone does not improve security. Someone has to decide which findings matter, assign ownership and carry out remediation. A broader security assessment can be useful where you need an independent view of the environment rather than relying entirely on the provider managing it.
Ask what happens when something goes badly wrong
An MSP should be able to explain how it handles serious incidents without turning the discussion into fear-selling. Ask what happens if ransomware is detected, a critical server fails, an administrator account is compromised or an important backup cannot be restored.
The answers should cover escalation, communication and decision-making. Who contacts your management team? Who has authority to isolate systems? Who coordinates with a software vendor? Who is responsible for restoring services? What information will you receive while the incident is being investigated?
Backup deserves particular attention. Ask what is backed up, where copies are stored, how long they are retained and who monitors backup failures. Then ask the uncomfortable but important question: when was the last successful restore test?
A provider may have excellent backup software and still have a weak recovery process. What matters is whether your business can actually recover the information and systems it depends on.
What people get wrong when choosing an MSP
The biggest mistake is choosing based mainly on price. A low monthly fee may look attractive because important work has been excluded. You can then end up paying separately for projects, security incidents, after-hours work, infrastructure changes or recovery tasks.
Another mistake is assuming that a large MSP is automatically a better MSP. Size can provide useful resources, but it can also mean your company is one account among many. A smaller provider may offer more direct access to senior engineers, while a larger provider may have broader specialist coverage. The right choice depends on your environment and the service model.
References also need to be handled carefully. Ask for examples of environments similar to yours, but do not rely on a list of logos. What matters is whether the provider understands the technology, operational requirements and constraints that affect your business.
Do not ignore documentation either. Ask how the MSP documents your environment, where that documentation is stored, how often it is updated and whether your organisation can access it. If critical knowledge exists only inside the provider's engineers' heads, you have created unnecessary dependency.
Finally, ask how the relationship ends. You may have no intention of changing providers, but a professional MSP should still have a clear handover process for credentials, configurations, documentation, backups and administrative access.
Ask about the people, tools and operating process
The tools an MSP uses matter, but they should not be the main reason you choose them. Most established providers can deploy remote monitoring, endpoint management, ticketing, backup and security platforms. The difference is usually in how those tools are operated.
Ask which tools are used for remote monitoring, patching, endpoint security, ticket management and backup. Then ask who reviews the information they generate. A dashboard full of green indicators tells you very little if nobody investigates exceptions.
You should also understand the people behind the service. Is there a named service manager? Will you have access to senior engineers? Is work handled entirely by a help desk, or can technical issues be escalated to infrastructure, cloud or security specialists?
For businesses considering offshore delivery, geography should be evaluated separately from operational capability. A remote team in Sri Lanka can work effectively with an overseas organisation when access controls, documentation, communication procedures and escalation are properly designed. The important question is whether the provider can operate your environment securely and consistently, not simply where its engineers sit. If you are evaluating that model, see how IT outsourcing to Sri Lanka can fit into a broader support strategy.
What to do before you sign
Start by documenting your current environment and identifying the systems that genuinely matter to the business. Then give every prospective MSP the same information and ask each one to define exactly what it will manage.
Next, compare support hours, response commitments, escalation processes, security responsibilities, backup coverage and project exclusions. Do not compare monthly fees until you understand what each price actually buys.
Then test the provider's thinking with scenarios. Ask what they would do if a critical server stopped responding, ransomware appeared on an endpoint, a senior administrator lost access or a backup failed. You are not looking for dramatic answers. You are looking for a clear process with defined ownership.
Finally, read the contract and exit terms carefully. Confirm who owns your data, credentials, configurations and documentation. An MSP should make your IT more manageable, not create a dependency that makes changing direction unnecessarily difficult.
Common questions
- What questions should I ask an MSP before signing a contract?
- Ask which systems they will manage, what support hours apply, how incidents are prioritised, what security responsibilities are included, how backups are handled, what work costs extra and how escalation works. Also ask how they document your environment and what happens when the contract ends. These answers reveal the actual service behind the sales proposal.
- How do I compare managed IT service providers?
- Compare providers on scope, responsibility, response process, security operations, backup and recovery, engineering capability, documentation and contract terms rather than price alone. Give each provider the same environment information and ask them to explain what is included. A cheaper service is not cheaper if important operational work is routinely billed separately.
- Should my MSP manage cybersecurity as well as IT?
- It can make sense when the MSP has the capability and clearly accepts responsibility for the relevant security controls. Ask whether security management includes configuration, monitoring, alert investigation, endpoint isolation, patching and incident escalation. If security is excluded, establish who owns those tasks internally or through a separate security provider.
- Is offshore IT support a good option for a small business?
- Offshore IT support can work well when the provider has secure access controls, documented processes, suitable technical skills and clear communication and escalation procedures. The location itself does not determine service quality. Businesses should assess data access, compliance requirements, operating hours, engineering capability and accountability before choosing an offshore model.
Let's talk about your environment
Tell us what you are running and what worries you. We will come back with a straight assessment and a costed plan — no obligation.
