Category: blog
Choosing a managed IT provider affects:
- System availability
- Cybersecurity
- Backup recovery
- IT spending
- Employee productivity
- Business continuity
The right provider should manage daily operations and support long-term business requirements.
The wrong provider can create:
- Unclear costs
- Slow support
- Security gaps
- Failed backups
- Contract disputes
- Unplanned downtime
Use the following criteria before selecting an MSP.
Selection Criteria

1. Match the Provider to Your Business
Start with your operating requirements.
Document:
- Number of users
- Number of locations
- Servers and endpoints
- Cloud platforms
- Critical applications
- Remote work requirements
- Compliance obligations
- Current support problems
- Growth plans
- Budget limitations
Determine whether you need:
- Fully managed IT
- Co-managed IT
- Project-based support
- Remote support
- On-site support
- 24/7 monitoring
- Extended help desk coverage
A provider should support your current environment and planned changes.
Experience with similar organizations is important.
Ask for examples involving:
- Companies with similar user counts
- Similar industries
- Similar infrastructure
- Similar compliance requirements
- Similar cloud and communications platforms
The provider’s service model should match your operational risk.
2. Review the Service Level Agreement
A verbal response promise is not enough.
The SLA should define:
- Support hours
- Response targets
- Severity levels
- Escalation procedures
- Resolution expectations
- On-site support terms
- Maintenance windows
- Uptime targets
- Security incident notification
- Reporting requirements
- Contract termination
- Offboarding responsibilities
Response times should be separated by priority.
For example:
- Critical outage
- Security incident
- Multiple-user issue
- Individual-user issue
- Service request
- Planned change
The SLA should also identify what is included in the monthly service.
Review whether the agreement includes:
- Help desk support
- Remote monitoring
- Patch management
- Endpoint management
- Server maintenance
- Network monitoring
- Backup monitoring
- Security management
- Vendor coordination
- Strategic reviews
Project work should be identified separately.
Ask how migrations, hardware replacement, cabling, cloud changes, and major repairs are billed.
The National Cyber Security Centre MSP guidance provides additional questions for evaluating provider security and accountability.
3. Confirm the Security Model
Security should be part of the operating model.
It should not be presented as an optional product added after a breach.
Ask how the provider manages:
- Endpoint detection and response
- Antivirus and malware protection
- Firewall configuration
- Email security
- Multi-factor authentication
- Identity and access management
- Patch management
- Vulnerability management
- Security awareness
- Incident response
- Security logging
- Privileged access
Request details about internal provider security.
Ask about:
- Staff access controls
- Administrative account management
- Remote access security
- Password management
- Employee background checks
- Security training
- Incident reporting
- Business continuity
- Provider backup procedures
A provider should be able to explain who can access your systems and how that access is controlled.
Least-privilege access should be used.
Administrative access should be logged and reviewed.
Security tools should be monitored.
Alerts should be investigated.
Threats should be remediated through a defined process.
X-Tek provides business IT services covering managed support, server maintenance, PC and Mac maintenance, cloud services, and network infrastructure. Details are available on the X-Tek services page.
4. Validate Backup and Disaster Recovery
A backup status that says “successful” does not confirm recoverability.
Ask:
- What data is backed up
- How often backups run
- How long backups are retained
- Where backup copies are stored
- Whether backups are encrypted
- Whether backups are isolated
- Whether immutable storage is used
- How cloud data is protected
- How backup failures are escalated
- How restores are tested
Define recovery objectives.
RPO
The amount of data that can be lost after an incident.
RTO
The amount of time allowed for system restoration.
These objectives should be documented for critical systems.
Ask for restore test evidence.
Acceptable evidence may include:
- Restore logs
- Test reports
- Recovery records
- System screenshots
- Quarterly review documentation
The disaster recovery plan should also define:
- Incident roles
- Communication procedures
- Recovery priorities
- Vendor contacts
- Temporary operating procedures
- Restoration approval
- Post-incident review
Backups should be monitored continuously.
Failures should be investigated.
Restore testing should be scheduled.

5. Evaluate Support Operations
Support quality depends on process and staffing.
Ask:
- Who handles first-line support
- Where support staff are located
- Whether on-site support is available
- How urgent issues are escalated
- Whether a dedicated account contact is assigned
- How tickets are tracked
- How status updates are provided
- How recurring problems are analyzed
Remote support should use secure access controls.
On-site service should be available when remote resolution is not practical.
The provider should have a documented escalation process.
Ask for sample reports showing:
- Ticket volume
- Response time
- Resolution time
- Open tickets
- Recurring incidents
- Patch status
- Backup status
- Security alerts
- Device health
- Capacity concerns
A provider should report more than the number of tickets closed.
The reports should show infrastructure risk and service trends.
6. Examine the Pricing Structure
Price comparisons are difficult when services are not defined consistently.
Request a written breakdown of:
- Monthly recurring fees
- Per-user charges
- Per-device charges
- Security tool charges
- Backup charges
- Cloud management charges
- On-site rates
- Project rates
- Hardware costs
- Licensing costs
- After-hours charges
- Contract fees
- Cancellation terms
Ask whether core security and backup services are included.
Confirm whether the monthly rate covers:
- Monitoring
- Maintenance
- Patching
- Help desk support
- Backup monitoring
- Endpoint protection
- Reporting
- Vendor coordination
Avoid proposals using terms such as:
- “As needed”
- “Standard support”
- “Best effort”
- “Additional fees may apply”
- “Security available upon request”
These terms require clarification.
Predictable pricing requires a defined scope.
7. Review the Onboarding Process
The first 90 days establish the working relationship.
Ask how onboarding is handled.
A structured process should include:
- Infrastructure assessment
- Asset documentation
- Account and access review
- Security review
- Backup review
- Network review
- Monitoring deployment
- Critical issue remediation
- Documentation transfer
- Service reporting
The provider should identify urgent risks before routine improvements.
Onboarding documentation should include:
- Device inventory
- Network diagrams
- Vendor contacts
- Licensing details
- Administrative accounts
- Backup configuration
- Recovery procedures
- Warranty information
- Application dependencies
Ownership of documentation should be clear.
Your business should be able to access its system records throughout the contract.
8. Confirm Strategic Support
Managed IT should include more than ticket resolution.
Ask how the provider supports:
- Hardware lifecycle planning
- Cloud migration
- Network upgrades
- Software selection
- Security planning
- Compliance preparation
- Business expansion
- Remote work changes
- Disaster recovery
- Technology budgeting
X-Tek supports Google Cloud and Microsoft Cloud environments. Businesses preparing for cloud changes can also review X-Tek’s cloud migration guidance.
Strategic reviews should connect technology decisions to business requirements.
The provider should identify:
- Aging equipment
- Unsupported software
- Capacity limits
- Security exposure
- Backup weaknesses
- Vendor dependencies
- Upcoming licensing changes
Recommendations should be documented with cost, timing, and business impact.

Red Flags
Review proposals carefully for these conditions.
No Written SLA
A provider that only promises fast support without measurable targets creates accountability problems.
Security as an Add-On
Basic security controls should not depend on an emergency upgrade.
Ask what is included before comparing prices.
No Restore Testing
A provider that cannot show restore evidence may be monitoring backup jobs without validating recovery.
Unclear Scope
Unspecified services often become additional charges.
Every recurring service and project service should be identified.
No Similar References
The provider should be able to describe relevant client experience without exposing confidential information.
Long Contract Before Assessment
Do not accept a multi-year commitment before reviewing:
- Scope
- SLA
- Security controls
- Backup design
- Pricing
- References
- Offboarding terms
No Exit Process
Your data, documentation, credentials, and configurations should remain accessible during a transition.
The contract should define the offboarding process.
A Practical Selection Process
Use this sequence:
- Document your current IT environment
- Identify business-critical systems
- Define support and recovery requirements
- Shortlist three to five providers
- Request an assessment
- Compare written scopes
- Review SLAs
- Validate security controls
- Confirm backup testing
- Check references
- Review pricing and exclusions
- Define onboarding
- Define offboarding
- Measure performance after launch
Do not select based on price alone.
Compare the amount of risk being managed.
Compare the visibility being provided.
Compare the provider’s ability to support future requirements.
X-Tek’s Managed IT Services Approach
X-Tek provides managed support plans with coverage across:
- Business IT support
- Server maintenance and repair
- PC and Mac maintenance and repair
- On-site repair
- Google Cloud
- Microsoft Cloud
- Network design
- Network equipment
- Network maintenance
- Website security
- Managed DNS
- Web hosting
- Domain registration
- Cloud and on-premise VOIP systems
Our approach includes proactive monitoring, maintenance, security, backup oversight, remote support, and on-site support options.
Problems are identified before they become larger interruptions where possible.
Infrastructure is documented.
Systems are maintained.
Backup and security status are reviewed.
Recommendations are aligned with business requirements.
More information is available through X-Tek’s managed IT services resource.
Businesses can submit requirements through the Business Solutions Information Request.
A managed IT provider should reduce operational risk, improve system visibility, and create a defined process for support and recovery.
Review the contract.
Test the claims.
Confirm the scope.
Measure the results.
Contact Information
Business Solutions Information Request:
https://xtekit.com/business-solutions-information-request/
815-516-8075

