News
News

How to Choose an IT Support Provider in 2025: 10 Questions UK Businesses Should Ask

12 September 2025

 

Picking an IT support partner isn’t just about who answers the phone fastest or who offers the lowest price. It’s a decision that touches every part of your business: security, compliance, productivity, customer experience and, ultimately, revenue. Get it right and your teams move faster with fewer headaches; get it wrong and you’ll pay for it in downtime, data risk, and spiralling “extras” that weren’t in the quote.

This plain‑English guide sets out the 10 questions we recommend every UK organisation asks before signing a support contract—whether you’re an SME scaling up or an enterprise re‑platforming your service desk. We’ve included red flags and practical scoring tips so you can compare providers on a level playing field.

Why this matters: Cyber incidents are commonplace—the UK government’s 2025 survey found 43% of businesses experienced a breach or attack in the past 12 months, with an average total cost of £1,600 for the most disruptive cases (higher for medium/large firms). You need a partner who can prevent, detect and respond—and help you meet your legal obligations.

1) “What outcomes and SLAs do you actually commit to?”

What to look for

  • Clear definitions of response vs resolution times (these are not the same). 
  • Business‑hour vs 24×7 cover, holidays, and out‑of‑hours escalation. 
  • Priority tiers (P1/P2/P3) with examples and clock rules (when timers start/stop). 
  • Service credits and a named service owner who attends your reviews. 

Red flags

  • Vague promises (“we respond quickly”) without numbers. 
  • SLAs that reset when a ticket is “awaiting customer”. 
  • No mechanism for continuous improvement. 

Score it (0–5): Are the SLAs specific, measurable, and backed by credits? Do they reflect your business hours and peaks?

2) “How do you secure our data and day‑to‑day operations?”

What to look for

  • Evidence of security hygiene (MFA everywhere, privileged access controls, patch cadence). 
  • Recognised certifications suited to the UK, e.g. Cyber Essentials / Cyber Essentials Plus and ISO/IEC 27001 for information security management. Cyber Essentials is the NCSC‑backed baseline for controls, while ISO 27001 is the international ISMS standard 
  • Clear separation between your tenant and the provider’s tools (least privilege, audited access). 
  • Documented backup strategy (including restore testing). 

Red flags

  • No independent assurance (no CE/CE+; no ISO 27001 roadmap). 
  • Shared admin accounts or weak joiner‑mover‑leaver process. 

Score it (0–5): Certifications + technical controls + evidence (screenshots, policies, audit extracts).

3) “What happens when something does go wrong?”

Incidents will happen. The question is how quickly your provider contains and resolves them—and what they tell you along the way.

What to look for

  • A written Incident Response Plan with roles, comms templates, and forensic partners. 
  • Runbooks for common threats (ransomware, BEC, identity compromise). 
  • A lessons‑learned loop that fixes root causes (not just closes tickets). 
  • Familiarity with UK guidance from the NCSC on supply chain and MSP security. 

Red flags

  • “We’ll figure it out on the day.” 
  • No evidence of tabletop exercises or recent drills. 

Score it (0–5): Ask for anonymised post‑incident reports; assess clarity and timeliness.

4) “How will you help us meet UK GDPR obligations?”

When an IT provider processes personal data on your behalf, they are a processor and you remain the controller. Your contract needs specific clauses under Article 28—it’s not optional.

What to look for

  • A Data Processing Agreement (DPA) that covers: documented instructions, confidentiality, security measures, sub‑processor controls, support for data subject rights, deletion/return of data, and audit rights—all required under Article 28 
  • Clarity on when a contract is needed and how multi‑party arrangements still bind the processor to you. 
  • Breach notification timelines and who informs the ICO (and when). 

Red flags

  • Generic NDAs offered “instead of” a DPA. 
  • No register of sub‑processors or change notification process. 

Score it (0–5): Contract completeness + evidence they’ve operated as a processor before (templates, checklists).

5) “Who actually delivers the service—your people or subcontractors?”

Supply chains introduce risk. You need transparency on who touches your estate.

What to look for

  • Named delivery team, with BPSS/DBS checks where appropriate. 
  • A list of sub‑processors, what they do, where data is stored, and how they’re vetted. 
  • Alignment to NCSC supply chain security principles (assurance, onboarding, monitoring). 

Red flags

  • “We use partners when needed” without detail. 
  • No right to approve or veto high‑risk sub‑processors. 

Score it (0–5): Transparency + contractual control + measurable oversight.

6) “What visibility and reporting will we get?”

If you can’t see performance, you can’t manage it.

What to look for

  • Monthly dashboards for volumes, SLA performance, CSAT, top drivers, ageing tickets. 
  • Asset/inventory accuracy, patch compliance, and vulnerability trends. 
  • Security event summaries (EDR/XDR findings) and actions taken. 

Red flags

  • End‑of‑quarter PDFs with cherry‑picked stats. 
  • No access to raw metrics or ticket data exports. 

Score it (0–5): Real‑time access + actionable insights, not just vanity KPIs.

7) “How do you support hybrid work and modern security (Zero Trust)?”

Today’s reality: people, devices, and apps are everywhere.

What to look for

  • Strong identity controls (MFA, conditional access), device compliance (MDM/endpoint management), and least‑privilege admin. 
  • Practical experience with Microsoft 365, Intune/Endpoint Manager, and modern network patterns (SASE/SD‑WAN) to keep remote users fast and safe. 

Red flags

  • Castle‑and‑moat thinking (“we’ll put a big firewall in the office and call it done”). 
  • No plan for unmanaged devices, contractors, or BYOD—areas Cyber Essentials highlights as in‑scope for secure configuration. 

Score it (0–5): Clear reference architectures + change plan that suits your estate.

8) “What does onboarding and—crucially—offboarding look like?”

A good partner plans the end at the start. That way, you’re never locked in.

What to look for

  • A 30‑60‑90‑day onboarding plan: discovery, “quick fixes”, standards, and service baselines. 
  • Config ownership: you retain admin of your tenant; provider uses named, just‑in‑time access. 
  • Documented exit plan: data return/deletion, handover of runbooks, credential transfer, and tool disentanglement. 

Red flags

  • Provider holds the only global admin or hides configuration behind their tools. 
  • No commitment to export ticket history, asset lists, and monitoring configs. 

Score it (0–5): Clarity + your ownership of credentials and documentation.

9) “How will you improve our resilience and reduce total cost over 12–24 months?”

Great IT support isn’t only about reacting—it’s about removing toil and risk.

What to look for

  • A quarterly roadmap to reduce incidents (fix noisy apps, stabilise Wi‑Fi, right‑size connectivity). 
  • Cost optimisation (licence rationalisation, cloud storage tiers, automations). 
  • A frank discussion about the cost of downtime in your context, anchored in data (remember that government survey’s cost estimates—and that 43% figure—to build a business case for resilience). 

Red flags

  • Ticket‑taking with no trend analysis. 
  • “Unlimited support” that rewards more incidents, not fewer. 

Score it (0–5): Roadmap + measurable savings and risk reduction.

10) “Can you prove it?”

What to look for

  • Case studies with outcomes (not just “we migrated 200 users”). 
  • Named references willing to take a call. 
  • External assurance: Cyber Essentials (Plus) and, where appropriate, ISO/IEC 27001 certification. 

Red flags

  • Anonymous testimonials only. 
  • Certifications “in progress” for years. 

Score it (0–5): Independent proof + measurable results.

A quick scoring grid you can copy

Give each question a score out of 5. Add weighting if needed (e.g., security x2). Shortlist the top two and run a time‑boxed pilot before committing to a long term.

Area Score (0–5)
SLAs & coverage
Security controls & assurance
Incident response readiness
GDPR contract & data handling
Supply chain transparency
Reporting & visibility
Hybrid/Zero Trust capability
Onboarding & offboarding
Resilience & cost optimisation
Evidence & references
Total /50

 

Practical contract pointers (don’t skip)

  • Article 28 DPA: make sure your contract contains the required processor clauses (instructions, confidentiality, security, sub‑processors, assistance with data rights, data return/deletion, audits). The ICO sets out exactly what needs to be included. 
  • Right to audit / assurance: include the ability to review controls annually (reports, pen test summaries, CE/ISO certificates). 
  • Change & exit: specify handover artefacts (config backups, O365/Intune baselines, network diagrams). 
  • Security alignment: ask providers to evidence alignment to NCSC supply chain security guidance. 

Why businesses are raising the bar in 2025

With nearly half of UK businesses reporting cyber incidents, and with material costs even for relatively small organisations, decision‑makers are placing greater weight on security posture, compliance and resilience when selecting an MSP—not just headline price. Cyber Essentials remains a recognised baseline; ISO/IEC 27001 signals a mature, auditable approach to information security. Combine those with a realistic SLA, transparent reporting and a clean exit plan, and you’ll avoid the common pitfalls that lead to friction—or worse, failure—mid‑contract. 

How Verstech can help (and how to de‑risk your choice)

If you’d like to evaluate your current setup before you decide, our free IT audit looks at:

  • Ticket and incident patterns (where time is lost and why). 
  • Security hygiene (identity, device compliance, patching, backups). 
  • Connectivity and performance bottlenecks. 
  • Quick wins for resilience and cost reduction. 

We’ll map findings to a 90‑day plan you can implement with us—or use as a benchmark with any provider. No fluff, just clear actions and measurable outcomes.