21 Questions Businesses Should Answer Before Outsourcing IT Support
Learn which 21 questions businesses should answer about support, cybersecurity, backups, pricing, ownership, and contracts before outsourcing IT.
7/21/202610 min read


One overlooked backup failure, unprotected administrator account, or misunderstood response-time promise can leave a business unable to serve customers, access records, or recover critical data. Outsourcing IT should create clearer ownership and stronger coverage, not another layer of confusion. These 21 questions will help you define your needs, compare providers consistently, and avoid signing an agreement that leaves important systems or responsibilities uncovered.
Understand What the Business Needs
A provider cannot build the right support plan from an employee count alone. Start by identifying which systems matter, how interruptions affect the company, and what is likely to change.
1. Which Systems Are Critical to Daily Operations?
What it is: Critical systems are the devices, applications, networks, and services the business cannot operate without.
What to do: List email, file storage, accounting, phones, internet access, cloud platforms, customer databases, production systems, and industry software. Rank each system by the damage caused if it becomes unavailable for one hour, one day, or longer. This ranking helps the provider prioritize protection and recovery.
2. How Much Downtime Can Each System Tolerate?
What it is: Downtime tolerance is the longest a system can remain unavailable before the disruption becomes unacceptable.
What to do: Define a realistic limit for every critical system. A public website, payroll platform, production workstation, and shared printer do not require identical urgency. Record the financial, customer, safety, and compliance consequences of an outage. Avoid saying everything is critical because that gives the provider no useful priority order.
3. Which Technology Problems Keep Returning?
What it is: Recurring problems often reveal weaknesses in equipment, configuration, documentation, training, or maintenance.
What to do: Review support requests, employee complaints, outages, security alerts, and vendor invoices from the past year. Group incidents by root cause. Repeated password problems may require better identity management, while frequent Wi-Fi failures may point to poor network design. The goal is to remove patterns instead of repeatedly closing similar tickets.
4. What Changes Are Planned During the Next Two Years?
What it is: Growth, relocation, hiring, software adoption, or new compliance requirements can change the support your company needs.
What to do: Document planned offices, remote positions, acquisitions, cloud projects, equipment replacements, and major software changes. Share this roadmap with potential providers. A support agreement designed only for today may become expensive or restrictive when the company adds employees, opens another location, or adopts a new operational system.
Define the Support Scope
“IT support” can describe anything from occasional troubleshooting to complete management of devices, networks, cybersecurity, cloud platforms, vendors, and technology planning. The agreement needs to state what the provider owns and what remains with your team.
5. Which Users, Devices, Applications, and Locations Need Coverage?
What it is: Support scope identifies exactly which people, systems, and sites the provider must manage.
What to do: Inventory employees, contractors, computers, mobile devices, servers, network hardware, printers, phones, applications, and locations. Include remote and traveling workers. Ask whether pricing applies per user, device, site, or service. An incomplete inventory leads to inaccurate proposals and unexpected charges after onboarding.
6. When Must Support Be Available?
What it is: Support hours determine when employees can request help and when technicians respond to urgent problems.
What to do: Compare the provider’s help desk, monitoring, and emergency coverage with your operating schedule. Ask what “24/7” means because it may describe automated monitoring rather than immediate access to an engineer. Define business hours, after-hours contacts, holiday procedures, and which incidents qualify for emergency support.
7. How Should Employees Request and Escalate Help?
What it is: The ticket process controls how users report problems, provide information, receive updates, and escalate urgent cases.
What to do: Confirm whether employees can request assistance through phone, email, portal, chat, or an installed tool. Ask how priority is assigned and who may request an escalation. A clear process prevents lost requests, side conversations, and disputes about whether the provider received notice of a serious issue.
8. Which Services Are Included, Limited, or Excluded?
What it is: Service boundaries separate work covered by the recurring fee from projects, products, and support billed separately.
What to do: Request a service matrix covering help desk, monitoring, patching, backups, cybersecurity, cloud administration, vendor coordination, cabling, equipment installation, and strategic planning. Mark each item as included, limited, excluded, or separately priced. Broad promises such as “complete support” mean little without written definitions.
Examine Cybersecurity and Recovery
Outsourcing technical work does not transfer every security decision. Leadership still needs to understand risk, approve controls, and know what happens when an incident occurs.
9. Who Makes Cybersecurity Decisions?
What it is: Security ownership covers risk decisions, control approvals, alert review, exceptions, and incident communication.
What to do: Assign an internal decision-maker and define the provider’s authority. Ask who monitors tools, reviews alerts, approves security exceptions, and documents accepted risks. The provider can recommend and operate controls, but business leadership must still decide which risks to reduce, accept, avoid, or insure against.
10. How Are Administrator Accounts Protected?
What it is: Administrator accounts can change systems, access sensitive information, create users, and disable security protections.
What to do: Require named administrator accounts, multifactor authentication, limited privileges, and a documented approval process. Ask how shared credentials are removed and emergency access is controlled. Confirm that former employees, contractors, and technicians lose access promptly. One poorly protected administrator account can weaken several otherwise effective security controls.
11. How Are Updates and Security Patches Managed?
What it is: Patch management is the process of testing and installing updates that correct security and reliability problems.
What to do: Ask which operating systems, applications, servers, network devices, and third-party tools are covered. Confirm the routine schedule, emergency-patch procedure, reboot policy, failure reporting, and exception process. A report showing that most devices are current is not enough if the remaining systems contain sensitive information or face the internet.
12. How Will Employees Be Protected From Email and Identity Attacks?
What it is: Email and identity attacks attempt to steal credentials, impersonate trusted people, redirect payments, or enter company systems.
What to do: Ask about multifactor authentication, email filtering, domain protection, employee training, login monitoring, and verification procedures for sensitive requests. When comparing a Huntsville IT company, confirm whether these safeguards are part of the standard agreement or sold as separate cybersecurity services.
13. Can the Provider Prove That Backups Can Be Restored?
What it is: A backup stores copies of data, while a restore test confirms that those copies can actually support recovery.
What to do: Ask what data and systems are protected, how often copies run, where they are stored, and how long they remain available. Confirm how backups are isolated from the main network. Request the restore-testing schedule, last test result, recovery time, and procedure for reporting failures.
Clarify Ownership and Daily Operations
The provider may administer your technology, but the business should retain control of its accounts, data, licenses, and records. This becomes especially important when employees leave or the service relationship ends.
14. Who Owns the Accounts, Licenses, and Data?
What it is: Ownership determines whether your company controls its domains, cloud environments, subscriptions, licenses, warranties, credentials, and business data.
What to do: Require business accounts to use the company’s legal name and company-controlled contact details. The provider may hold delegated administrative access without becoming the owner. Verify ownership of domain registration, Microsoft or Google environments, security products, internet accounts, backup systems, software portals, and hardware warranties.
15. How Will Employees Be Added, Changed, and Removed?
What it is: User lifecycle management covers onboarding, role changes, leaves of absence, and departures.
What to do: Define who submits requests, what approvals are required, and how much notice the provider needs. Separate onboarding and offboarding checklists should cover email, cloud access, software licenses, mobile devices, remote sessions, shared credentials, file ownership, forwarding, retention, and equipment return. Urgent departures need a clearly documented process.
16. Who Manages Vendors and Software Renewals?
What it is: Vendor management coordinates internet providers, software companies, phone systems, equipment warranties, and other technology suppliers.
What to do: Ask whether the provider opens cases, attends vendor calls, reviews invoices, and tracks renewal dates. Clarify who can approve purchases and contract changes. Keep vendor names, account numbers, support contacts, renewal dates, and ownership details in a company-accessible record rather than one technician’s email.
17. What Documentation Will Be Maintained?
What it is: IT documentation explains how systems are configured, connected, protected, licensed, supported, and recovered.
What to do: Require current hardware and software inventories, network diagrams, backup procedures, vendor contacts, security controls, warranty dates, administrative ownership, and standard procedures. Ask how often records are updated, who can access them, and what format you receive during a provider transition. Documentation should serve the business, not lock it in.
Compare Performance, Pricing, and Contract Terms
The monthly price matters, but an inexpensive proposal can become costly when projects, after-hours calls, licenses, or onboarding work sit outside the agreement.
18. How Are Response and Resolution Times Measured?
What it is: Response time measures how quickly the provider acknowledges or begins work, while resolution time measures how long it takes to restore service or complete the fix.
What to do: Ask for definitions by priority level. Confirm when each clock begins, what pauses it, and whether business hours or calendar hours apply. A 15-minute response promise may mean only that someone acknowledges the ticket. It does not guarantee resolution within 15 minutes.
19. What Is the Likely Total Cost?
What it is: Total cost combines recurring service fees with onboarding, projects, software licenses, hardware, travel, and work outside the agreement.
What to do: Request a pricing schedule for user or device counts, minimum charges, onboarding, annual increases, projects, after-hours support, software, hardware margins, and termination assistance. Give every provider the same inventory and requirements. Comparing unequal scopes by monthly price creates a misleading result.
20. What Happens When the Agreement Ends?
What it is: The exit process determines how access, documentation, data, licenses, equipment, and administrative control return to your business or transfer to another provider.
What to do: Review notice periods, auto-renewal, early-termination fees, data-export charges, and transition support before signing. Require a timeline for credential handoff, documentation delivery, account removal, and data return. A clear exit clause protects both parties and reduces disruption during a future change.
21. Who Guides the Long-Term Technology Roadmap?
What it is: Technology planning connects security, equipment replacement, software, budgets, and future projects to business goals.
What to do: Decide whether you need routine support only or continuing strategic guidance. Ask who leads business reviews, prepares budgets, evaluates risk, and recommends investments. Confirm meeting frequency and expected reports. Every recommendation should connect to a business requirement, measurable risk, compliance obligation, or operational improvement.
IT Outsourcing Readiness Checklist
Complete this checklist before requesting proposals.
Business and Support
Critical systems have been identified.
Downtime tolerance has been defined for each critical system.
Recurring technology problems have been documented.
Planned growth and major projects have been listed.
Users, devices, applications, and locations have been inventoried.
Required support hours have been defined.
Ticket priorities and escalation contacts have been identified.
Required, optional, and excluded services have been separated.
Security and Recovery
An internal security decision-maker has been assigned.
Administrative accounts have been identified.
Multifactor authentication requirements have been defined.
Patch-management expectations have been documented.
Email and identity protections have been reviewed.
Backup scope, frequency, retention, and restore requirements have been defined.
Incident-notification expectations have been documented.
Regulatory, contractual, and insurance obligations have been collected.
Ownership and Contracts
Domain, cloud, software, and security account ownership has been verified.
Employee onboarding and offboarding procedures have been documented.
Vendor and renewal responsibilities have been assigned.
Required IT documentation has been listed.
Response and resolution targets have been defined.
A complete pricing breakdown has been requested.
Exit and transition requirements have been reviewed.
Long-term planning expectations have been defined.
Consultation Script You Can Use
“We are evaluating outsourced IT support for [number] users across [number] locations. Our critical systems are [systems], and our main operational concerns are [concerns]. We need support during [hours] and after-hours coverage for [specific emergencies].
Please explain which help desk, monitoring, patching, cybersecurity, backup, cloud, vendor-management, documentation, and strategic-planning services are included. We also need your response and resolution definitions, escalation process, full pricing, account-ownership policy, and contract-exit procedure.
Please identify every service, license, project, limit, or fee that is not included in the recurring price.”
Proposal Comparison Scorecard
Score each provider from one to five in these areas:
Scope clarity: Are included, limited, and excluded services clearly identified?
Support coverage: Do the support hours, channels, and escalation process match your operations?
Cybersecurity: Are identity, email, endpoint, patching, and incident responsibilities defined?
Recovery: Are backup scope, retention, isolation, and restore testing documented?
Ownership: Does your company control its accounts, licenses, data, and documentation?
Pricing: Can you calculate the likely total cost without guessing?
Reporting: Will reports provide useful information about tickets, security, backups, and assets?
Strategy: Does planning connect technology recommendations to business priorities?
Transition: Are onboarding and contract-exit procedures clear?
Communication: Are contacts, responsibilities, approvals, and decision paths easy to understand?
Don’t choose solely by the total score. A weak rating in backups, security, ownership, or contract exit can outweigh several high ratings in less critical areas.
Questions to Ask About the Proposal
Before approving a proposal, ask:
Which assumptions did you make about our users, devices, and locations?
Which required products are included in the monthly price?
What happens when our employee or device count changes?
Which projects require a separate statement of work?
Who approves after-hours or out-of-scope charges?
Which service targets are contractual?
What reports will we receive each month or quarter?
Which risks should be corrected during onboarding?
What documentation will exist after the first 90 days?
What assistance is included if the agreement ends?
Five Quick Wins Before Outsourcing IT
Create a current list of users, devices, applications, vendors, and subscriptions.
Confirm that the company owns its domain and primary cloud accounts.
Enable multifactor authentication on administrator and remote-access accounts.
Locate the most recent backup restore-test result.
Document who can approve purchases, access changes, and emergency work.
These steps make proposals more accurate and help the incoming provider focus on real risks instead of spending the first several weeks discovering basic account information.
Frequently Asked Questions
Is outsourced IT only for businesses without internal IT employees?
No. A provider can act as the primary IT team or supplement internal staff with monitoring, help desk coverage, cybersecurity, projects, and specialized knowledge. The agreement should clearly divide responsibilities between the two teams.
Does managed IT automatically include cybersecurity?
Not always. Basic monitoring and patching do not necessarily include email security, identity protection, awareness training, advanced threat detection, or incident response. Request a written security scope and pricing for every required product.
Does a small business need 24/7 support?
Only when important operations continue after hours or certain failures cannot wait until the next business day. Define which systems and incidents justify emergency coverage instead of paying for immediate response to every minor request.
How often should a business review its IT provider?
Review operational performance at least quarterly and evaluate the overall relationship annually. Discuss recurring problems, response results, security findings, backup tests, upcoming renewals, business changes, planned projects, and unresolved risks.
Closing
Outsourcing IT support works when responsibilities become clearer, systems become easier to manage, and leadership receives better information for making technology decisions. It fails when the agreement hides exclusions, account ownership remains uncertain, backups go untested, or every unexpected problem becomes an extra charge.
Define the systems, risks, support expectations, and ownership requirements before requesting proposals. Then give each provider the same information and compare the answers in writing.
Good info, in one place—so you can move forward.
Contact
Questions? Reach out anytime.
Phone
hello@21goodinfo.com
© 2025. All rights reserved.
