Home › Guides › Choosing an IT support company: questions that expose a poor one
Choosing an IT support company for your small business or charity is one of the most important decisions you will make. A good provider saves you money, prevents disasters, and keeps your staff productive. A poor one will drain your budget, miss problems, and leave you vulnerable to security breaches. The difference comes down to the questions you ask.
Understand what you actually need
Before you talk to providers, think about what IT support means to your business. Is it reactive (you call when something breaks) or proactive (they monitor and prevent problems)? Do you need someone to come to your office, or is remote support enough? What is your tolerance for downtime? A supermarket cannot afford an hour without tills; a charity office might tolerate a 4-hour internet outage. Be honest about this, because different providers offer different levels of service.
Ask about the SLA—and understand it
The Service Level Agreement (SLA) is the most important document in your contract, but many small business owners gloss over it. The SLA specifies how quickly the provider will respond to problems and how long they guarantee to have you fixed. These are two different things.
Ask these specific questions:
Response time: “What is your average response time when something breaks?” Under 1 hour is standard. If they say “within 24 hours,” that is too slow for most businesses.
Resolution time: “How long do you guarantee to have us up and running?” This is different from response time. A provider might respond in 10 minutes but not resolve the issue for 4 hours. Ask specifically about resolution time for different types of problems: email down, network down, server down. An SLA should distinguish between business-critical and non-critical issues.
Uptime guarantee: “What uptime percentage do you guarantee?” (95% or 99.5%? The difference matters.) What happens if they miss that? Do you get a credit? How much?
Out-of-hours support: “If we have a problem at 6 PM on Friday, what happens?” Some providers include out-of-hours cover; others charge extra. If you work 9–5 only, you might not need it. If you operate on weekends or evenings, you do.
Penalties for missing the SLA: “If you fail to meet the SLA, what compensation do we get?” A serious provider will offer service credits if they miss their guarantees. If they do not mention this, the SLA is probably not enforced.
Ask about their pricing and what is included
Many providers quote a low headline price then surprise you with extra charges. Ask for a written breakdown that clearly defines what is covered:
- Is the monthly fee all-inclusive, or are there extra charges for on-site visits, software updates, or security patches?
- What is the cost of out-of-hours support?
- Are new user setup and hardware procurement included?
- What about anti-virus, firewall, and backups—are these separate?
- What happens at the end of the contract—who owns the data and who can access it?
A reputable provider will give you a detailed, written quote that explains exactly what you are paying for. Be suspicious of any provider who will not clearly itemise their charges or who refuses to put the service scope in writing.
Ask how they monitor your network
Proactive providers continuously monitor your network for problems—before they affect you. Ask:
- “What monitoring tools do you use?” (They should use industry-standard tools like Connectwise, Datto, or Palo Alto.)
- “How do you know if a problem is happening?” (Real-time alerting is essential.)
- “Who monitors the alerts?” (It should not be an automated system with no human check.)
- “Do you run regular backups and test restores?” (Many providers back up data but never test if they can actually restore it. This is dangerous.)
A provider who cannot tell you specifically how they monitor your network is probably not monitoring it at all.
Ask about security and compliance
Cyber security is not optional anymore. According to the NCSC, you should ask any IT support provider:
- “What security standards do you meet?” Look for Cyber Essentials certification (a government-backed scheme) or ISO 27001. These indicate the provider has demonstrated their security practices.
- “Do you provide staff training on security?” The NCSC identifies human error as a key risk; your provider should train their staff on phishing, password security, and data protection.
- “What happens if there is a breach?” The provider should have documented incident response procedures and should be able to explain how they would notify you.
- “Do you have a Data Processing Agreement?” Under UK GDPR, if your IT provider processes customer data on your behalf, you must have a written contract that defines data ownership, access rights, and responsibilities. The ICO provides guidance on what must be included.
A provider who cannot discuss these topics in detail is not meeting basic security standards. When evaluating providers, check whether they hold Cyber Essentials certification and whether their senior management understands their security responsibilities.
Ask about their customers and references
Request references from businesses similar to yours (same size, same industry). A provider who works well for a 200-person manufacturing company might be terrible for a 5-person charity.
Ask current customers:
- “Do they actually respond when you call?”
- “Have they prevented problems or only fixed them after they happen?”
- “Have they helped you plan technology upgrades?”
- “Is the pricing what they quoted?”
If a provider refuses to give references, that is a red flag.
Watch for these red flags
- They focus more on selling you new equipment than fixing the problems you have
- They cannot tell you specifically how they monitor your systems
- They refuse to put the SLA in writing
- They cannot explain what you are paying for
- They do not ask questions about your business—they just quote a price
- They have no experience with your industry
- They dismiss security concerns as “over the top”
- They pressure you to sign a long contract quickly
Get competing quotes
Talk to at least three providers. Ask them all the same questions, so you can compare fairly. The cheapest is rarely the best, but the most expensive is not always better either. You are looking for a provider who understands your business, can articulate their service level, and has customers who trust them.
Key points
- An SLA is essential; make sure you understand response time, resolution time, and what happens if they fail
- Ask for a clear, written price breakdown; hidden costs are common
- Proactive monitoring with real testing of backups is the mark of a serious provider
- References from similar businesses matter more than general experience
- Security and compliance should be a core part of their offer, not an afterthought
- Get competing quotes from at least three providers
Related: Find IT support near you