Skip to main content

Free — no email required

12 questions to ask an MSP before you sign

Before signing with a managed IT provider, ask these twelve questions. Each one has an answer that should reassure you and an answer that should not. Written by a Houston MSP that has been on both sides of the conversation since 2013 — and yes, you should ask us these too.

The twelve questions

  1. 1. Who actually answers when something breaks?

    Strong answer Named engineers you meet before signing, with a documented escalation path.

    Red flag "Our team" — with no names, and no offer to introduce you.

  2. 2. Where are your engineers physically located?

    Strong answer A local team, with honest disclosure of anything offshore or after-hours.

    Red flag Vagueness about location, or "24/7" that turns out to mean an overseas answering service.

  3. 3. What does your escalation path look like in writing?

    Strong answer A document showing who is engaged at each severity and how long each step takes.

    Red flag A verbal assurance that urgent things get handled urgently.

  4. 4. Who owns our documentation if we leave?

    Strong answer You do, in a portable format, handed over without negotiation.

    Red flag Documentation that lives only in their platform, or an exit fee to retrieve it.

  5. 5. What security work is inside the monthly fee, and what is extra?

    Strong answer A written line between included operations and separately scoped projects.

    Red flag "Security is included" with no definition of what that covers.

  6. 6. Can we see a redacted assessment report you have produced?

    Strong answer A real report, redacted, showing how findings are prioritised and explained.

    Red flag A sample from a vendor, or a raw scanner export with no analysis.

  7. 7. How do you handle cyber-insurance questionnaires?

    Strong answer They have completed them before and can describe which controls they evidence.

    Red flag They hand it back to you, or answer yes to everything without checking.

  8. 8. What happens in the first 48 hours of an incident?

    Strong answer A rehearsed sequence with named roles, logging retention and notification awareness.

    Red flag An improvised answer, or one that stops at "we restore from backup".

  9. 9. What does a quarterly review actually contain?

    Strong answer Posture, incidents, spend, and a prioritised backlog with owners and dates.

    Red flag A ticket-count report, or a meeting that has quietly stopped happening.

  10. 10. Can you work alongside our internal IT?

    Strong answer A written split of responsibilities so nothing sits in the gap between you.

    Red flag Enthusiasm with no detail about where their remit ends.

  11. 11. What is scoped as a project versus included?

    Strong answer Clear examples of each, given before you ask.

    Red flag You find out at the first invoice.

  12. 12. Why did your last client leave?

    Strong answer A straight answer, including what they would do differently.

    Red flag "Nobody ever leaves" — or blame directed entirely at the client.

Want it as a checklist you can take into the meeting?

Same twelve questions, formatted to print or share with whoever else is in the room. We will email it over.

Get the printable version

Ask us the twelve

We publish our pricing, our escalation model and what each tier does not cover, so most of this is already answered. Bring the rest to a twenty-minute call.