Most guides to choosing an IT provider are a list of things to look for: experience, certifications, responsiveness, good communication. Nobody disagrees with any of it, and it helps nobody, because every provider claims all four.
The useful version of this exercise is different. It is a set of questions where the answer is difficult to fake, and where a weak provider gives themselves away by how they respond rather than by what they claim.
What follows is that set of questions, and what a good answer sounds like.
First, decide what you are actually buying
Before evaluating anyone, get clear on which of these you need. They are different products sold under the same name.
- Helpdesk only. Someone to call when things break, with no responsibility for the underlying environment. Cheapest, and appropriate only if someone else owns strategy.
- Fully managed IT. The provider owns the environment: monitoring, patching, backups, security, procurement, and the helpdesk. One accountable party.
- Co-managed IT. You keep internal IT staff and the provider fills specific gaps — after-hours coverage, security, project capacity. Common in businesses with one overloaded internal person.
- Project-only. A defined piece of work with an end date. Not a relationship, and should not be priced as one.
A provider who does not ask which of these you want, early and directly, is selling you whatever they have rather than what you need.
The questions that actually separate providers
"What happens in the first 30 days?"
A serious provider has a defined onboarding process and can describe it without improvising: documentation, discovery, credential handover, agent deployment, backup verification, a remediation list. They will also tell you that the first month is when problems surface rather than disappear.
A vague answer here is the strongest single predictor of a bad engagement. Onboarding is where the work is, and providers who have not systematised it have not done it often.
"Who will I actually be talking to?"
Ask whether you get a named engineer, a pooled queue, or a tiered escalation path. All three are legitimate. What matters is whether the answer is specific and whether the person selling you the contract has anything to do with delivering it.
"What is your response time commitment, and what happens when you miss it?"
Every provider has an SLA. Far fewer have a remedy attached to it. A commitment with no consequence is a marketing figure. Ask what you are entitled to when it is breached, and ask how often it was breached last quarter.
"What does your security stack include, specifically?"
Not "we include security" — the specific products and what they do. Endpoint protection is not EDR. EDR is not managed detection and response. Email filtering is not the same as anti-phishing training. Providers who cannot name their tooling either do not know it or do not want you comparing it.
"How do you handle work that falls outside the agreement?"
There will be such work. The question is whether the process for approving and billing it is defined in advance or negotiated in the moment, which is when relationships sour.
"What happens if we leave?"
Ask this in the sales conversation, before signing. You want a straightforward answer covering documentation, credentials, backup data, and notice period. Any hesitation is informative. A provider confident in their service has no reason to make leaving difficult.
Credentials: which ones mean something
Certifications are a weak signal generally, but not a useless one. The distinction worth drawing is between vendor partner status and independent audit.
- Microsoft Solutions Partner designations require demonstrated deployments and skilled staff. Reasonable evidence of capability.
- SOC 2 Type II means the provider has been independently audited on their own controls, over a period. This is meaningful, particularly if you carry compliance obligations yourself.
- Vendor certifications for the tools they deploy are baseline. Their absence is a flag; their presence is not distinguishing.
- Membership badges from industry associations generally indicate a paid subscription rather than a standard met.
If you are in healthcare, legal, or financial services, ask directly whether they have other clients under the same regime and whether they will sign a Business Associate Agreement or its equivalent. A provider learning your compliance regime on your account is a risk you are funding.
References, asked properly
Every provider supplies three happy clients. To get value from a reference call, ask questions the reference cannot answer with generic praise:
- What went wrong during onboarding, and how was it handled? Something always does.
- Tell me about the worst incident you have had with them.
- What do you wish you had asked before signing?
- Has the monthly cost changed since you started, and why?
Ask for a reference in your industry and of roughly your size. A provider excellent with 200-seat manufacturers may be poorly configured for a 15-person law firm.
Local or national?
In the New York and Connecticut market you will be choosing between regional providers and national ones, and the tradeoff is real in both directions.
National providers bring scale: deeper bench, genuine 24/7 staffing, mature process. They are also structurally less able to be at your office this afternoon, and you are a small account inside a large system.
Regional providers bring proximity and accountability — the same people, reachable, able to appear physically when something needs hands. The risk is depth: capacity limits, key-person dependency, and thinner after-hours coverage.
The right answer depends on whether your business genuinely needs on-site presence. Businesses that have moved substantially to cloud infrastructure need it far less than they think, which widens the field considerably.
Signals to walk away from
- Pressure to sign before a discovery process. Nobody can responsibly quote an environment they have not examined.
- Reluctance to put scope in writing.
- Disparaging your current provider heavily rather than describing their own approach.
- No documented offboarding process.
- A contract that auto-renews for a long term with a short notice window buried in it.
- Inability to produce a client reference in your industry.
The decision
Choosing a provider is less about finding the best one and more about finding the one whose model matches your situation. A business with heavy compliance obligations and no internal IT needs something different from one with a capable internal admin who needs after-hours cover.
Get the scope in writing, get the exclusions in writing, get the exit terms in writing, and speak to a reference who resembles you. That process eliminates most bad outcomes, which is a more realistic goal than guaranteeing a perfect one.