Choosing a provider
What to ask any IT provider
Nine questions worth asking before you sign with anyone — including us. Most are uncomfortable, which is rather the point: the answers are where providers differ, and none of them are visible on a brochure.
Will you sign a GDPR Article 28 data processing agreement, and can I see your sub-processor list?
Why it matters
A managed provider holds your passwords, remote access to every machine, and copies of your data. Article 28 is not a formality for anyone in that position — it is the contract that sets out what they may do with it, who else touches it, and what happens when something leaks.
A good answer sounds like
“Yes, here it is” — with a named list of every sub-processor, where each one processes your data, and notice before that list changes. A provider who has never been asked will not have one ready.
What is your response time for a critical outage, in writing — and does the clock measure when you start, or when it is fixed?
Why it matters
Most published response times measure the start of work rather than the repair, which is honest, because how long a fix takes depends on the fault. The number only means something once you know which of the two it counts.
A good answer sounds like
A figure that appears in the contract, with the measurement stated plainly and the hours it applies to. Vagueness on this one is the tell.
What happens if two of your clients have an emergency at the same time?
Why it matters
Every provider has more clients than engineers. A response time that quietly assumes you are the only one in trouble is an average, not a commitment.
A good answer sounds like
An order of service that is written down — who gets picked up first, and what the second one is told while they wait. Nobody enjoys this question, which is exactly why it is worth asking.
Is out-of-hours support included or billed? Can I see the rate card?
Why it matters
The hours you are most likely to need help are the hours most contracts quietly exclude. If the rate is not published, you will meet it on an invoice.
A good answer sounds like
Published rates, banded by time of day and day of week, and a clear statement of what your plan includes — not merely what you are able to buy.
Does your security monitoring include responding, or only alerting?
Why it matters
Detecting and responding are different products at very different prices. A line on an invoice reading “endpoint detection” does not tell you which of the two you bought.
A good answer sounds like
A plain answer about what happens when an alert fires at two in the morning: who looks at it, within what time, and whether that is in the contract or simply the intention.
Who handles my website, email and business applications — you, or a second supplier?
Why it matters
When the website is one company's job and the mail server is another's, the gap between them becomes yours to manage — usually on the day something breaks across both at once.
A good answer sounds like
Either “all of it, and here is the contract that says so”, or a straight account of what falls outside it. What is no use to you is a maybe.
What happens to my data and my access on the first day after we part ways, in writing?
Why it matters
The exit is negotiated at the beginning or it is not negotiated at all. By the time you want to leave, you have no leverage and they have your passwords.
A good answer sounds like
A written handover with a price and a deadline, that does not depend on the two of you parting on good terms.
How do you count what you manage, and what happens when you find a machine that is not on the list?
Why it matters
Per-device pricing drifts — people join, laptops get replaced, a server appears. Providers know this, and some contracts turn a forgotten machine into a penalty, or into grounds to walk away.
A good answer sounds like
A stated counting rule, a reconciliation you can see, and an adjustment that works in both directions. If the count can only ever go up, that is a billing mechanism rather than an accurate one.
Am I in scope for NIS2, and who files the 24-hour report?
Why it matters
Greek law 5160/2024 puts the duty on your business, not on your provider — an early warning within 24 hours, a report within 72, and a final one within a month. A good many businesses now in scope have not realised it.
A good answer sounds like
Someone who can tell you whether you are in scope, what they will see, what they will not, and how they help you meet a deadline that remains legally yours.
Our answers
Ours are in the contracts themselves — terms of service, service levels, rate card, and the data processing agreement with its sub-processor list. Ask us any of the nine and we will point you at the clause rather than the brochure.
Want our answers to all nine?
Tell us about your setup and we'll walk you through how we'd handle each one.