Most business owners talk to their IT provider when something is broken. That is reasonable if you think of technology as plumbing: you call when there is water on the floor, you pay, you move on. The trouble is that plumbing does not have license renewals, security exposure, aging equipment, or a five year cost curve. Technology has all four, and none of them announce themselves during a support call.
The fix is one scheduled meeting, a few times a year, that has nothing to do with any open ticket. In our industry it is usually called a quarterly business review. We should be honest up front that plenty of these meetings are terrible, because plenty of providers use them to present a slide deck of alarming charts and then propose a purchase. That version deserves the skepticism it gets. A good version looks completely different, and it is one of the highest value hours a small business can spend on technology.
What This Meeting Is, and What It Is Not
A real review is a planning conversation. It looks backward at what actually happened, sideways at what is quietly aging or expiring, and forward at what the business is trying to do next. The output should be a short list of decisions and a rough budget, not a signed order form.
It is not a sales meeting. It is not a status report read aloud. And it is not a performance review, although if the numbers are bad you should absolutely say so. The point is to move the relationship from reactive to planned, because almost everything expensive in technology is expensive because it was handled at the last minute.
Frequency deserves a candid note. Quarterly suits most companies of fifty people or more. If you have twelve employees and a stable setup, twice a year is honest and useful, and a provider who insists on four meetings a year for a twelve person business may be optimizing for their own pipeline rather than your calendar.
What Belongs on the Agenda
Five things, in this order. If your provider’s agenda has ten items and eight of them are product names, that is a tell.
- What happened last quarter, in plain numbers. How many tickets, what the most common causes were, how long things took, and which problems came back more than once. Repeat issues matter far more than raw ticket counts, because a recurring problem is usually a root cause nobody has been funded to fix.
- What is aging or expiring. Equipment past its useful life, warranties ending, subscriptions renewing, and software approaching end of support. Microsoft Learn describes the Microsoft Lifecycle Policy as consistent and predictable guidelines for the availability of support throughout the life of a product, with a Fixed Policy for products that have defined end of support dates set at release. Those dates are published in advance, which means an end of support surprise is a planning failure rather than a genuine surprise.
- Security posture and any known gaps. Not a threat lecture. A specific list of what is in place, what is not, and what we recommend you accept as risk on purpose. CISA’s Cyber Guidance for Small Businesses recommends a written incident response plan with defined roles and responsibilities, reviewed quarterly, which makes this meeting the natural home for that review.
- Budget, and what is coming. A twelve month view of expected spending, separated into what is already committed, what is recommended, and what is optional. Nobody should learn about a five figure replacement cycle in the month it is due.
- The business goals we should be planning around. New location, a hire wave, an acquisition, a new line of business, a compliance requirement a customer is starting to ask about. This is the part providers most often skip, and it is the part that actually changes recommendations.
Who Should Be in the Room from Your Side
Fewer people than you think, but the right ones. The meeting fails when it is attended only by whoever is designated as the technology contact, because that person often cannot approve spending or speak to next year’s plans, and the whole conversation turns into note taking.
- Someone who can approve money. Owner, general manager, or finance lead. Without this person, every decision becomes a follow up email that dies quietly.
- Someone who knows the operational plan. The person who knows about the new location, the seasonal hiring, or the contract you are bidding on in the spring.
- Your internal technology point of contact, if you have one. They know the daily friction that never becomes a ticket, which is often the most useful information in the meeting.
- Occasionally, a department head with a specific problem. Invite them for the agenda item that concerns them rather than the whole hour.
The Questions You Should Be Asking Us
Good questions make providers better. These are the ones we think you should ask, including the uncomfortable ones. If a provider gets defensive at any of them, that reaction is your answer.
- What is the biggest risk in our environment right now, and what would it cost to fix? Then ask what happens if you do nothing, because sometimes accepting a risk is the correct business decision.
- What are we paying for that we are not using? Unused licenses and forgotten subscriptions are extremely common, and they are the easiest money you will ever recover. We have written about what that neglect costs in more detail.
- What did we ask for that you could not deliver? Every provider has gaps. The useful ones name them.
- If we lost everything tonight, what does tomorrow look like, in hours? Ask when the last actual restore test happened, not when the last backup ran.
- What would you change if this were your business? The answer tells you whether you are working with a vendor or a partner.
If Your Provider Never Proposes This Meeting
Here is the part that does not flatter our industry. If nobody has ever offered you a planning conversation, that absence is information. It usually means one of three things: the provider is purely a break fix operation and is content to be, they are stretched too thin to do anything beyond closing tickets, or your account is small enough that it does not get attention. None of those are moral failings. All of them are things you should know.
You can fix this without changing providers: ask for the meeting, send the agenda above, and see what comes back. A good provider will be relieved. A provider who cannot produce plain numbers about your own environment has told you something important, and it is worth reading our thoughts on what to look for in a partner before you decide what to do next.
One last framing helps here. NIST’s Cybersecurity Framework 2.0 organizes its guidance into six functions, and the first, Govern, is defined as the organization’s cybersecurity risk management strategy, expectations, and policy being established, communicated, and monitored. Establishing, communicating, and monitoring are not things that happen inside a support ticket. They happen in a meeting on a calendar.
The Bottom Line
A good review meeting is an hour, a handful of plain numbers, an honest list of gaps, and a budget you can see coming. It is not a sales pitch and it does not require a consultant. It just requires both sides to show up with real information and the willingness to say what is not working. Do it two to four times a year and most technology emergencies turn into scheduled line items, which is the entire goal.
If you have never had a review like this, or the last one you sat through felt like a product demonstration, we are glad to run one properly and show you the agenda before we show you anything else. No slide deck of scary charts, just your environment, your numbers, and what we would do about it. Contact us today.
Sources:
Comments are closed