
Home / Guides / Choosing an IT company
How to choose an IT company: 12 questions (with the self-serving answers included)
We're an IT company telling you how to vet IT companies — including how to vet us. Twelve questions that separate a real partner from a lock-in machine, and the answers a good one gives.
Choosing an IT provider comes down to twelve questions across four areas: ownership (do you keep your credentials, data, and documentation?), security (is it built in or sold as an upsell?), the relationship (who actually answers, and how fast?), and the exit (can you leave without a hostage negotiation?). The answers to the ownership and exit questions matter more than the monthly price — because they determine whether the price ever stops being your only leverage.
Yes, we're an IT firm writing the guide to choosing an IT firm — so read this with appropriate suspicion, and use the questions on us too. We wrote it because the most common thing new clients tell us is a version of the same story: they'd cycled through providers, never quite knowing what to ask, and got burned on the parts that don't show up in a quote. These are the twelve questions that surface those parts, with the answer a good provider gives — and the answer that should make you keep looking. The clients who stopped shopping around asked most of these.
Area 1 — Ownership: do you actually keep your own company?
1. Who owns the documentation, passwords, and network diagrams? Good: "You do — it lives in your accounts from day one; you get a copy any time." Keep looking if it's "proprietary" or "ours." If your own runbooks are hostage, you don't have a vendor, you have a landlord.
2. Whose accounts is our cloud and tooling under? Good: "Yours. We administer, you own the tenancy." Keep looking if EDR, backups, and Microsoft 365 are all under the provider's umbrella account — that's an exit tax disguised as convenience.
3. If we leave, what do we walk away with? Good: "Everything — credentials, data, docs, configs — and a documented handover." A provider comfortable with your departure is one confident in their work. We hold this as a structural rule: clients own every repository and credential from day one.
Area 2 — Security: built in, or billed later?
4. Which security controls are in the base rate, and which cost extra? Good: a specific list — "EDR, MFA, patching, backup, and monitoring are included; here's what's add-on." Keep looking if "security" is a vague upsell tier. Cross-check their base rate against our 20-point checklist — how many do they actually cover?
5. Do you do the security work yourselves, or resell it? Good: honest about what's in-house vs. partnered, and accountable either way. Fine to partner; not fine to be unable to explain who's responsible when something's on fire.
6. Who's watching alerts, and when? Good: "Security analysts, and here's the 24/7 coverage / escalation path in writing." Keep looking if the answer blurs helpdesk with security monitoring — they're different products, as we cover in EDR vs. MDR vs. SIEM.
Area 3 — The relationship: who answers, how fast?
7. What's your contractual response time for a down server at 2 a.m.? Good: a specific SLA, and honesty about what's contractual vs. best-effort. Keep looking if it's adjectives ("fast," "responsive") with no number behind them.
8. Will we talk to engineers, or only account managers? Good: "You reach the people doing the work." Layers of account management between you and a technical answer are a tax on every interaction.
9. Can I see a sample monthly report? Good: they show you one — what was patched, what was caught, what's aging. Keep looking if reporting is "available on request" and never materializes; you manage what you can see.
10. Can you give me references at my size and in my situation? Good: yes, relevant ones — or candid about being a newer firm and what that buys you. A small hungry firm can be an excellent choice; evasiveness about it is the problem, not the size.
Area 4 — The exit and the contract
11. What's the term, and how do we cancel? Good: reasonable term, clear cancellation, no auto-renew traps. Keep looking at multi-year auto-renewal with a 90-day cancellation window you're statistically going to miss. The contract clauses cost more than the invoice.
12. What's excluded from "all-inclusive," in writing? Good: a straight list — projects, after-hours, on-site, "advanced" work. Every exclusion is a future surprise invoice; get them named before you sign, not discovered after.
The two questions that predict everything else
If you only remember two, make them #1 (who owns the documentation) and #11 (how do we leave). Here's why they're load-bearing: a provider who lets you own everything and leave easily has to keep you through quality, because they've given up lock-in as a strategy. A provider who owns your accounts and traps you in the contract has told you how they intend to retain you — not by being good, but by being expensive to escape. Everything else on this list correlates with those two answers. The genuinely good firms find these questions easy and slightly refreshing; the ones you should avoid get cagey, pivot to the discount, or explain why ownership is "more complicated than that." The cageyness is the answer.
How to run the actual selection
Practically: shortlist three, send all twelve questions in writing (writing matters — it's harder to be vague on the record), and score the answers for specificity, not charm. Weight ownership and exit heaviest, security second, relationship and price after. Normalize the quotes by adding each provider's likely exclusions at their hourly rate — the cheapest headline frequently finishes third once the exclusions are priced. Then trust the pattern: the provider who answered fast, specific, and comfortable about you leaving is the one who'll still be worth having in year three. We'd rather lose a deal to these questions than win one by dodging them — a client who chose on the answers stays; a client who chose on the discount is already half-gone.
Red flags in the sales process itself
Before the contract, the sales conversation already tells you most of what you need — if you watch for the tells. A quote before questions: a provider who prices your environment before counting your servers, users, and compliance drivers is either guessing or planning to "discover" scope later, on your invoice. Pressure and urgency: "this rate is only good this week" is a tactic, not a partnership; good providers know a considered decision produces a better client. Dodging the ownership question: if "who owns the documentation and accounts" produces a pause, a pivot, or a "that's more complicated than it sounds," you have your answer. Adjectives instead of specifics: "world-class," "enterprise-grade," and "proactive" are free; a response-time SLA, an exclusions list, and a sample report cost the provider something to stand behind. Reluctance to talk to their engineers: if you can't get a technical person on a pre-sales call, you won't get one after you sign either. None of these is disqualifying alone, but they cluster — the provider who quotes fast, pressures hard, and gets vague about ownership is showing you the whole relationship in miniature. The sales process is a free preview of how they'll treat you as a client; believe what it shows you.
Frequently asked questions
Is a bigger IT company safer than a small one?
Not inherently. Bigger can mean more coverage and process; it can also mean you're a small account routed through account managers and junior staff. Small can mean senior attention and hunger, or thin coverage. Judge by the twelve answers — ownership, security depth, response, exit — not by headcount. Size is a factor, not a verdict.
What's a fair contract length to accept?
An annual term with a clear, reasonable cancellation clause is defensible — onboarding costs are real and providers need some commitment. What to resist is multi-year auto-renewal combined with provider-owned tooling and a narrow cancellation window; that combination isn't a term, it's a trap. Month-to-month after onboarding is possible when the provider doesn't rely on lock-in.
Should security and IT be the same provider or separate?
There are good arguments both ways, but the failure mode of separate vendors is the handoff — the gap where each assumes the other has it, which is where incidents are born. One accountable team removes that gap; it's the entire reason our firm combines them. If you do split them, define in writing who owns what, especially for incident response.
How do we switch without downtime?
Secure your credentials, documentation, and backup access first — if the incumbent owns them, negotiate that handover before signing anywhere new. A competent new provider runs a parallel onboarding over a few weeks, and the cutover itself is an evening, not an outage. The difficulty is proportional to how much the old contract locked you in — which is why question #11 matters at selection, not departure.
How much should price factor into the decision at all?
It matters, but as a tiebreaker among providers who pass the ownership, security, and exit questions — not as the primary filter. The cheapest provider who owns your accounts and traps you in the contract is the most expensive one over three years. Normalize quotes by pricing in likely exclusions, then let the answers to the twelve questions lead; price breaks ties, it doesn't make the call.
What's the biggest mistake companies make choosing IT?
Choosing on monthly price alone and discovering the real cost in exclusions, lock-in, and thin security after they've committed. The price is the visible number; ownership, exit terms, and included security are the expensive ones. Ask the twelve questions and the invisible costs become visible before they're yours.
Put us through the 12 questions How we work
General guidance shaped by our own client engagements and takeovers from prior providers. We're an interested party — use the questions on us as rigorously as on anyone else.