RESOURCES · CHOOSING AN IT PARTNER

How to choose an IT provider:
10 questions to ask

On the surface, most IT companies look the same — the same logos, the same buzzwords, the same "we do managed IT and cyber security". Underneath, the difference is enormous. You're handing over your data and your most critical systems, so it pays to ask the right questions. Here are the ten that separate a genuine partner from a glorified help desk.

Applies to: Anyone choosing an IT provider Read: ~6 min Level: Business owners & managers
Quick answer

Ask every provider the same ten questions and score their answers side by side. The businesses you actually want look after three things brilliantly: a genuinely senior support team, comprehensive cyber security as standard, and proactive, strategy-led leadership — not just someone to call when something breaks.

WHY IT MATTERS

The choice matters more than the sales meeting suggests.

Your IT provider quietly holds the keys to everything — your data, your email, your finances, your security. A weak one is a slow, expensive risk you won't notice until something goes wrong. A great one makes the whole business faster, safer and better-led. The catch is that they can look identical across a boardroom table. These questions surface the difference before you sign.

THE CHECKLIST

The ten questions to ask every provider.

Ask all of them, of everyone you're considering — including your current provider.

  1. Where are your staff located?When something breaks, you want a senior, local engineer who answers — not an offshore call centre reading from a script. Green flag: an Australian-based team you can actually reach, with support that isn't outsourced offshore.
  2. Are the tools and systems you use approved by insurers?Cyber-insurers increasingly require specific controls — MFA, modern endpoint protection, tested backups. If your provider's setup doesn't meet them, a claim can be denied when you need it most. Green flag: a security stack aligned to insurer and framework expectations, and they can show you how.
  3. Do you have a proven specialisation in cyber security — and can you prove it?"We do security" is easy to say. Many providers bolt on basic antivirus and call it done. Cyber security is now the core of good IT, not an add-on. Green flag: a genuine, demonstrable specialisation — layered defences, 24/7 monitoring, and real evidence like case studies and frameworks.
  4. How do you handle our data?Where your data lives, who can access it and how it's protected is your liability just as much as theirs. Green flag: clear data-handling practices, Australian data sovereignty where it matters, least-privilege access and encryption.
  5. What's the mix of your support team across Levels 1 to 3?Many providers front-load cheap Level 1 staff who escalate most issues — so you wait on hold, then wait again for a callback. Green flag: a senior-weighted team where you reach Level 2 and 3 engineers who resolve most issues on the first call.
  6. What's outside your scope?The gap between "managed" and "actually covered" is exactly where surprise bills and finger-pointing live. Green flag: a clear, written scope with no nasty exclusions — and honesty up front about anything that costs extra.
  7. How do you keep access to our systems safe?Your IT provider holds the keys to everything. If they're careless with access or get breached themselves, so do you. Green flag: MFA everywhere, least-privilege access, audited administrator accounts and secured management tools.
  8. Do you have a proper ticketing system and reporting?No ticketing means no accountability, no history and no visibility — you can't manage what you can't see. Green flag: a real ticketing system with response targets, plus transparent reporting so you can see how your support is actually performing.
  9. What best-practice frameworks do you follow?Good IT isn't ad-hoc. Recognised frameworks show maturity, consistency and repeatable quality. Green flag: frameworks like the ACSC Essential Eight, with a plan to lift your maturity over time.
  10. Can you offer whole-of-IT governance, strategy and CIO-as-a-service?The best partners don't just close tickets — they lead: budgets, roadmaps, risk and vendor management. That's what turns IT from a cost into an advantage. Green flag: a virtual CIO who owns strategy, governance and a forward roadmap, like a great internal IT manager would.
  11. Are you locked-in, or do you earn it?Long, punishing lock-in contracts are often a sign a provider expects you'll want to leave. Green flag: flexible, month-to-month terms — a partner confident enough to earn your business every single month.
Red flags to watch for. A few answers should give you pause: support that's entirely offshore Level 1; "cyber security" that turns out to be basic antivirus; a scope that's vague or only ever spoken, never written; long lock-in contracts; no ticketing system or reporting; a purely reactive "we fix it when it breaks" model; and — tellingly — any provider who can't answer these questions clearly and confidently.
HOW CLARITY MEASURES UP

Put us through the same ten questions.

We built Clarity to answer every one of these the way a great internal IT team would. Here's the short version:

Turn it into a scorecard. Print the ten questions, ask every provider the same set, and score each answer out of ten. Put the sheets side by side — the gaps between "we do IT" and a genuine strategic partner tend to speak for themselves. Our goal is simple: to be your clear number-one choice, then shape the commercial details around what fits.
PUT US TO THE TEST

Ask us the ten questions.

Book a free IT Health Check and we'll answer every one of them — and show you, in your own environment, exactly where great IT looks different from what you have today. No jargon, no hard sell.

KEEP READING

Related resources