Skip to main content Scroll Top

How to choose a managed IT provider (and check the one you have)

FTI Insights: Managed IT

Every managed IT provider has a good sales pitch. The difference between providers shows up later: when a server fails, when you ask for a copy of your network documentation, or when you find out the backups were never tested.

If you are choosing a managed service provider (MSP), this guide gives you the questions to ask before you sign. If you already have one, it helps you check whether they are doing the job you pay for.

Start with what you need

Before you talk to anyone, write down what IT means for your organization. How many people and computers? Which systems would stop the business if they went down? Do you have remote staff or several locations? Are there industry rules you need to meet?

That list keeps the conversation on your needs rather than the provider’s menu, and makes proposals easier to compare.

The seven things that matter most

1. Proactive or reactive?

A proactive provider finds and fixes problems before you notice them. Monitoring software watches disk health, failed backups, security alerts and missing updates, and someone acts on those alerts. A reactive provider waits for your call. Both will say they are proactive, so ask what they monitor, who responds to alerts, and what happened last month for a client like you. We explain the difference in proactive IT management.

2. Documentation you own

Your IT documentation is the blueprint of your business: what equipment you have, how the network is set up, where the licenses are, and how everything connects. It should be thorough and kept current by the provider’s tools.

Just as important, it is yours. Ask directly: “If we part ways, what documentation do we get, in what format?” A provider who hesitates is telling you something.

3. Is security included and integrated?

Look for security layers that work together: a business firewall, endpoint protection on each computer, email filtering, secure Wi-Fi, and tools that share information so a problem on one computer can trigger a response on the network. Ask what is included in the base price and what costs extra.

4. Tools that fit together

Good providers run an integrated set of tools for monitoring, patching, backup, ticketing and documentation. When those tools do not talk to each other, you get gaps: a server nobody is monitoring, or a backup nobody checks.

5. Contract clarity: flat rate or time and materials

A flat-rate contract gives you a predictable monthly cost. Make sure it clearly covers what you need, including after-hours support, projects and new users. A time-and-materials contract bills by the hour; it can be flexible, but costs can climb if nobody is watching.

Flat rate carries its own risk. A provider paid the same whether they work or not has an incentive to do less. The better ones use that predictability to invest in upkeep, because a well-maintained network costs them less to support. Your job is to know which kind you have.

6. Technical depth, not just sales talk

Some MSPs are better at selling service than delivering it. The technical side needs real people: network engineers, server and security specialists, and someone who understands the physical side, such as wiring and equipment rooms. Tools help, but they do not replace experience.

7. How they protect their access to you, and how they use AI

Your provider holds the keys to your systems, which makes the provider itself a target. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and its partners advise MSP customers to require multifactor authentication (a second proof of identity beyond a password) on every provider account, limit that access to the systems the provider manages, spell out in the contract how and when you will be told about an incident, and disable provider accounts when a contract ends.

AI is the newer question. According to Kaseya’s 2026 State of the MSP Report (April 2026, a survey of more than 1,000 providers), 53% of providers have implemented AI to automate ticketing, patching and monitoring. Ask what the AI is connected to, what it is allowed to do on its own, and who reviews its work. The answer you want: engineers decide and act.

Your checklist of questions

Ask this A good answer sounds like
What do you monitor, and who responds to alerts, including at night? Specific systems, named alert types and a clear escalation path.
How do you handle updates? Automated, but tested and deployed in stages, not pushed blindly.
How do you back up our data, and when did you last test a restore? On-site and off-site copies, with restore tests on a schedule.
What security is included in the base price? A clear list: firewall, endpoint, email, Wi-Fi and how they work together.
How do your staff sign in to our systems, and what happens to that access if we leave? Multifactor authentication on every account, access limited to what they manage, and accounts removed at the end.
Where do you use AI, and who makes the decisions? A clear description of what it watches, with engineers approving and carrying out changes.
What documentation do we get, and do we keep it if we leave? Yes, in a usable format, without argument.
What exactly does the contract cover, and what is billed separately? Plain-English scope, with examples of what is extra.
Can we talk to one of your engineers before signing? Yes. Reluctance here is a warning sign.
Can we speak with current clients about their experience? Yes, with references similar in size to you.
What reports will we see each month? Updates applied, backup status, alerts handled and open issues.

Ask the provider to explain their technical approach in plain English. If the salesperson cannot answer and cannot put you in touch with someone who can, keep looking. And trust your instincts: if it feels oversold, it probably is.

How to verify your current provider

If you already have an MSP, you do not need to be technical to check their work. Ask for evidence:

  • Backup: the date of the last successful backup and the last test restore. Promised services are not the same as installed and tested ones.
  • Updates: a report showing which computers are current and which are behind. See our view on keeping updates timely, not rushed.
  • Documentation: a copy of your network documentation. Is it complete and recent?
  • Security: what alerts were raised last quarter and what was done about them.
  • Access: a list of the provider accounts on your systems, and confirmation that each uses multifactor authentication.
  • Regular reviews: a scheduled meeting to go through the reports and plan ahead.

A good provider will welcome these questions.

How FTI helps

We are happy to be measured against this list. Finite Technologies has been an Alaskan technology company since 1990, and we build our own technology. Our managed IT services run on Kaseya for monitoring, automation, patching, on-site and cloud backup, and documentation, and are secured with Sophos. AI-assisted operations connect our monitoring, security logs, tickets and documentation, so our engineers see the full picture; they make the decisions. Our help desk answers 24/7 with senior engineers on call behind it. If you want to talk to an engineer before you decide, just ask.

Talk to us about your IT