What should I look for when choosing a managed IT support provider for a small business?

Updated 26 September 2026: Broken local-file contents links and unverified performance figures have been removed. Use the questions below to compare a provider’s written scope and evidence.

A managed IT support provider may handle user requests, devices, accounts, monitoring and agreed maintenance. The exact work varies by contract. For a small business, the useful test is whether the provider can explain what it will do, how it will protect access to your systems and what happens when an issue falls outside scope.

An IT professional operates a computer in a server room, managing network systems and connected devices.
Photo by panumas nikhomkhai on Pexels

Check the service scope before the headline price

Ask for a service description that names the users, devices, systems, locations and support hours covered. Find out who looks after Microsoft 365 administration, backups, security changes and vendor escalations. A provider may support these areas directly or hand them to a specialist; ask how that handoff works.

  • Which requests are included, and what would be charged separately?
  • How are urgent incidents prioritised, escalated and reported?
  • What is the response commitment, and does it differ from a fix-time promise?
  • What information and access will the provider need?

Verify security and recovery evidence

A provider may have privileged access to your systems. Ask how that access is protected, recorded and removed when no longer needed. Request evidence for any claimed certification and check that it covers the company and service you are buying. The NCSC’s guidance on choosing an MSP offers a practical due-diligence checklist and questions about security and contracts.

Backups need a named owner and a realistic restore route. Ask what is backed up, what is excluded, how often recovery is tested and who makes the decision to restore. Do not infer that every service includes a backup simply because the provider offers one elsewhere.

Close-up view of a computer displaying cybersecurity and data protection interfaces in green tones.
Photo by Tima Miroshnichenko on Pexels

Make onboarding and leaving workable

Before signing, agree how users and assets will be inventoried, how the outgoing provider will hand over access and how open incidents will be handled. Check the term, notice, renewal, price changes, data return and support during exit. Keep administrator access and key records under your organisation’s control where practical.

Use a comparison you can check

Ask each shortlisted provider to answer the same questions against the same inventory. Compare the written scope, evidence, support route and total expected cost. Customer references can help if they describe work similar to yours, but ask permission and do not treat a single testimonial as proof of a guaranteed outcome.

Kilwhiss Support handles day-to-day managed IT enquiries. Microsoft 365 tenant security and Copilot readiness are separately scoped with Kilwhiss 365; Cyber Essentials readiness sits with Kilwhiss Tech. Tell the Group what you need if you are unsure which specialist should lead.

← Back to Insights