Hiring a managed service provider is a bigger commitment than most business owners realize going in. You’re not buying a one-time fix—you’re entering an ongoing relationship that affects how your staff works, how your data is protected, and how fast your business recovers when something goes wrong. Asking the right questions before you sign tells you far more than any sales conversation will.
This guide covers what to ask before hiring a managed service provider, what the answers actually mean, and where businesses most often get burned by skipping these conversations.
What’s Actually Included—and What Isn’t
The most common mistake businesses make when evaluating an MSP is assuming that “managed IT” covers everything. It rarely does, and the gaps show up at the worst possible time.
Ask for a written scope of services and go through it line by line. Common items that get left out of standard agreements include:
- On-site support (many providers only offer remote help desk)
- After-hours and weekend coverage
- Microsoft 365 administration beyond basic email setup
- Backup monitoring and tested restores
- Security tools like endpoint detection or email filtering
- Vendor management—meaning, who calls your internet provider when service goes down
A real example of where this matters: a 40-person office moves locations and their internet and VoIP phones go offline. Who coordinates with the ISP? Who troubleshoots the router configuration? If your agreement only covers end-user help desk tickets, that situation may fall entirely outside your contract—even if it puts your whole team on hold for two days.
Always ask: *”What specifically is not included in this agreement?”* A good provider will answer that directly.
Response Times and What an SLA Actually Means
Every MSP will tell you they respond quickly. What you want is a written Service Level Agreement with defined targets—not a general promise.
Ask for specific numbers:
- How fast will someone acknowledge a critical issue? (A server outage, a ransomware alert, a full email outage)
- What’s the target resolution time for an urgent but non-critical problem?
- How are tickets prioritized, and who decides severity?
- What happens if SLA targets aren’t met?
The difference between a provider who says “we prioritize urgent issues” and one who says “critical issues receive a response within 30 minutes with escalation if unresolved in two hours” is significant. Vague language in this area is a red flag. It usually means accountability is limited.
Also ask about after-hours coverage. Many smaller providers have a single on-call technician. That’s fine to know—but you need to know it before you sign, not after a Saturday evening incident.
Security Responsibilities: Who Owns What
One of the most important—and most skipped—conversations is about who is responsible for security. Managed IT support and managed cybersecurity are not automatically the same thing.
Ask specifically:
- Is endpoint protection included, or is that a separate contract?
- Who manages patching for servers, workstations, and third-party applications?
- Who monitors for security alerts, and what happens when one is triggered?
- What is the provider’s incident response process if malware or a breach is suspected?
- Do you carry cyber liability insurance, and what does it cover?
This matters beyond IT—it affects your own cyber insurance. Many commercial cyber policies now require businesses to demonstrate that basic controls are in place: multi-factor authentication, patching, backups, and documented incident response. If your MSP isn’t handling these things and you assume they are, you may face a coverage dispute after a claim.
Don’t accept vague answers here. Ask for documentation on what security controls are actively managed on your behalf.
Backup and Recovery—Before You Need It
A backup that’s never been tested isn’t really a backup. It’s a file that might work when you need it most.
Ask your prospective provider:
- What exactly is backed up, and how often?
- Are Microsoft 365 mailboxes and SharePoint included? Many businesses assume Microsoft backs this data automatically. Microsoft’s own documentation makes clear that data retention for recovery purposes is the customer’s responsibility—not Microsoft’s.
- How long would it take to restore operations after a server failure? After ransomware?
- Are backups tested? How often, and can you see the results?
- Where is backup data stored, and is it separated from your primary environment?
A business that discovers its backups haven’t been successfully completing for three months—usually right after an incident—is in a far worse position than one that never had backups at all, simply because of the false confidence involved. Ask for proof of working backups, not just confirmation that a backup solution exists.
Red Flags in Contracts and Conversations
Beyond the specific questions, there are patterns in how providers talk that tell you a lot about what working with them will actually be like.
Watch for:
- Scope that describes services in vague or broad terms without specifics
- No defined escalation process for emergencies
- Security described as “best effort” rather than a defined set of controls
- Resistance to answering what’s *not* included
- Long auto-renewal terms with significant cancellation penalties
- No clear answer on who owns your data and documentation if you leave
That last point matters more than people expect. If you part ways with your MSP, you should be able to walk away with your system documentation, your license keys, your admin credentials, and your configuration details. Some providers make this difficult by design. Ask up front: *”If we end this relationship, what does offboarding look like, and what documentation do we receive?”*
What This Means for Your Business
The questions above aren’t designed to make the evaluation process harder. They’re designed to surface the things that matter before you’re locked into an agreement—and before an incident shows you what’s missing.
A strong MSP will answer these questions clearly, provide written SLAs, and be transparent about what falls outside their scope. That clarity is itself a signal of how they’ll handle problems when they come up.
If you’re evaluating outsourced IT support options for your business, TECHZN works with growing companies in the Dallas and Austin areas to provide IT support with defined scope, documented SLAs, and security controls built into the agreement—not sold as add-ons. Reach out to talk through what your business actually needs before making a decision.











