
This guide is published by a managed IT provider, which is a reason to read it sceptically rather than a reason to skip it. We sit on the other side of these evaluations constantly, and we know which questions make a supplier go quiet.
So it is written to be used against us as easily as against anyone else. Put every question below to NetFusion Designs in the same words you put it to the other firms on your list. If any provider, this one included, will not answer in writing, you have learned something worth knowing.
Most proposals look alike. The pricing table, the logo wall and the service list are close to interchangeable. These five questions are where providers stop sounding the same, because each has an answer that is either written down or is not.
Ask for the number, the severity definitions attached to it, and the document it lives in. A provider who answers “we are very responsive” has answered a different question. Definitions matter more than the number: if the agreement does not say what counts as critical, the provider decides after the fact, and nothing is ever critical.
Documentation is the real lock-in. Network diagrams, administrator credentials, licence records and the runbooks describing how your environment fits together usually sit inside the provider’s own tooling. Ask whether it is yours, whether you can export it at any time without asking permission, and whether your Microsoft 365 tenant and domain registrations are held in your name rather than theirs.
Ask for the exclusions list before the inclusions list. Every agreement has one, and a provider who will not produce it either does not have it or would rather you did not read it. Exclusions are where the monthly fee meets reality, and they predict better than anything whether your invoices will resemble the quote you accepted.
Inheriting an environment is not the same as running one. Ask what the provider does before supporting you: what they audit, what they document, what they expect to find, and what they will charge to put it right. Remediation of inherited problems is almost always billed separately, and you want that said out loud now, not discovered in month two.
Ask at the first meeting, because the reaction is as informative as the answer. What is the notice period, who returns what, in which format, at whose cost? A provider confident in the work has an offboarding clause and will happily read it to you. Anyone who treats the question as bad faith is telling you the exit was designed to hurt.
Response time is the interval between your ticket arriving and a human taking ownership of it. Resolution time is the interval between the ticket arriving and the problem going away. These are unrelated numbers, and the first is far easier to promise. A fifteen-minute response target tells you someone is watching the queue. It tells you nothing about whether your file server comes back today.
Ask for both, and ask what each is measured against. A response target that starts when a technician opens the ticket, rather than when you raised it, can be met by a provider who has not yet done anything. A resolution target with no severity definitions attached is not a target.
“24/7” is the most elastic phrase in this industry. It can mean an engineering team working in shifts, or an answering service that takes your name at two in the morning and passes it on at eight. Both are truthfully described as 24/7 support. Ask plainly: at three on a Sunday morning, who picks up — an employee of your provider, a subcontracted service, or a voicemail? Can that person fix the problem, or only log it? And does after-hours work carry a different rate?
Get four things on paper: the response target by severity, who decides severity and when, the hours the targets apply, and the remedy if they are missed. The remedy is the honest part — most agreements have none, which is itself worth knowing. For how a support desk should work, see IT helpdesk support.
Two quotes with a wide gap between them are rarely pricing the same work. Most of the difference lives in the exclusions, which fall into six groups.
None of these exclusions is unreasonable. A provider who included all six at a fixed price would be either mispricing the work or planning not to do it. The problem is never that exclusions exist. It is a quote that keeps them out of sight until the first invoice. For how the pieces add up, see what managed IT costs.
None of these proves a bad provider. Each is a reason to slow down and ask a second question.
One more is harder to spot: a proposal that agrees with everything you said in the discovery call. A provider who has genuinely looked will disagree about something. If nobody pushes back, nobody has looked.
“IT provider” covers at least five distinct business models. They are less competitors than different answers, and the commonest procurement mistake is comparing quotes across categories as though they priced the same work.
| Model | Genuinely best at | Weaker at | Typically suits |
|---|---|---|---|
| Generalist MSP | Day-to-day support across everything: helpdesk, patching, backups, vendor wrangling, one accountable owner. | Deep specialization. Complex security engineering or a niche application often still needs a second party. | Organizations with no internal IT and a mixed estate that mostly needs to work. |
| Security-led MSSP | Detection and response, log monitoring, and evidencing controls for insurers and auditors. | General user support. Many run no helpdesk at all. | Regulated organizations, or anyone whose contracts or insurance now demand demonstrable controls. |
| Co-managed partner | Adding capacity, tooling and after-hours coverage to an internal team, and taking routine work off it. | Ambiguity. Split responsibility fails quietly when the boundary is not written down. | Organizations with one to three internal IT staff who are competent and outnumbered. |
| Staffing and augmentation | Supplying people you direct yourself, for a defined period or a project with a known end. | Outcomes. You are buying hours and managing them; the tooling, process and accountability stay yours. | Organizations with the management capacity to run technical staff but not the headcount to hire them. |
| Break-fix | Occasional expert help at an hourly rate, with no monthly commitment. | Prevention. Nobody is paid to notice the failing disk or the stalled backup. | Very small or very simple environments where a day of downtime is survivable. |
Two of these boundaries deserve their own page: co-managed versus fully managed IT, and break-fix versus managed services. Categories blur in practice, so read what a provider does rather than what they call themselves.
Plenty of organizations are sold managed services they do not need. Three cases come up often enough to name.
A small, entirely cloud-based team. If you are ten people, everything you use is a browser tab, your devices are current and nobody runs a server or a line-of-business application, your real requirement is closer to identity management, device enrolment and a tested backup of your Microsoft 365 data than to a support contract. A one-off project to set those up properly, plus somewhere to call when something breaks, often fits better.
A capable internal hire. One good systems administrator, given a tooling budget and a couple of specialist relationships to lean on, covers a surprising amount of ground. What eventually breaks is coverage rather than capability — holidays, illness, evenings, and the fact that one person cannot be both the person who plans and the person who is interrupted. Co-managed support is the normal answer, and it is worth reaching for before a full outsource.
One specialist application with real vendor support. If your business runs on a single industry application and its vendor supports it properly, inserting a generalist between you and that vendor can slow you down. Where a generalist earns its place is everything around the application — identity, endpoints, network, backups — not the application itself.
If a provider cannot describe the circumstances in which you should not hire them, they are not describing a service. They are describing a sales process. If your choice is hiring rather than outsourcing, that comparison is set out under managed IT versus in-house IT.
Ask us the same eight. For the record: a one-hour response target for critical issues, 95% of tickets resolved same day, a 24/7 staffed helpdesk and security operations centre, and a SOC 2 Type 2 attestation you may ask us to evidence. Put those beside the answers everyone else gives you. That is what the list is for.
Three is usually enough to see the shape of the market; beyond four you get diminishing returns and a very long spreadsheet. What matters more is putting the same questions to all of them in the same words, so the answers are comparable. Ask in writing where you can — written answers survive a change of account manager.
It helps most where the industry has genuine technical particulars: clinical software, regulated data handling, engineering workloads. It matters rather less than it is marketed to matter. A provider who understands your applications and obligations is valuable; one whose industry experience amounts to a website page is not. Ask which of their people have worked with your applications, and what went wrong.
Most support work is remote regardless of where the provider sits, so proximity matters mainly for what cannot be: hardware failures, new office builds, and the occasional value of somebody walking through the door. If you have real on-site needs, ask what is included and what a visit costs. If you do not, weight location lightly and coverage heavily.
Twelve months is common and one to three years is normal. Longer terms are not automatically worse, because they often buy better pricing, provided the exit terms are clear and there is a defined way out if targets are missed repeatedly. Judge the notice period and the offboarding clause, not the headline term.
Rebuild them on your template rather than theirs. List every cost that will appear across a year: monthly support, per-user licensing, security tooling, backup capacity, after-hours work, on-site visits, project work you know is coming, and any remediation quoted at the start. Providers structure proposals so they read well; a common format removes that advantage and often reorders the list.
Put the same questions to your current provider before going to market. One who answers well is worth keeping; one who has never been asked may have drifted rather than failed. If you do move, secure your documentation and administrative control of your own tenants and domains first, because those are painful to recover afterwards.
We are not going to chase you. If you want a second opinion on a proposal you have already received, or straight answers to the eight questions above, our head office is at 141 Main Street North in Markham and the number is 647-476-5259. If the conclusion is that you do not need us, or that somebody else fits better, that is a legitimate outcome and we would rather reach it early.