We are an IT services company, so writing this is awkward. But somebody in our industry should say it plainly, because the businesses hurt most by a bad provider are the ones who assumed the relationship was normal. If you have never worked with a good one, you have no baseline. Things feel slow, expensive, and vaguely opaque, and you assume that is how IT works.

It is not how it works. Below are the signals that your provider is failing you, written from inside the industry, including a few that describe habits we have seen at companies that look a lot like ours. At the end there is the part nobody writes about: how to actually leave without wrecking your own operations in the process.

Start With One Question About Your Backups

Ask your provider this, in writing: “When was our last successful full restore test, what was restored, and how long did it take?” That is one question with a factual answer.

A healthy provider answers in a day with a date, a description, and a duration. A struggling one sends a screenshot of a dashboard showing green checkmarks, which is not the same thing. A completed backup job tells you data was copied. It tells you nothing about whether that data can become a working business again. NIST’s National Cybersecurity Center of Excellence guidance for managed service providers is explicit that organizations need to test backup processes to verify backup file integrity and confirm the effectiveness of recovery.

If you cannot get a straight answer to that question, stop reading the rest of this list. That one is enough.

The Red Flags That Are Really About Trust

  • They hold your documentation and passwords hostage. Your network diagram, account inventory, domain registrar login, administrator credentials. These are yours. A provider who will not hand them over has confused a service relationship with leverage. The polite version is “our documentation is proprietary.” It is not.
  • Every conversation ends in a quote. Some things genuinely are projects and should be quoted. But if mentioning a problem reliably produces a proposal rather than an answer, you are not being served, you are being farmed. Notice whether anyone ever tells you something is not worth doing.
  • You have no idea what you are paying for. Ask what your monthly fee covers, line by line, and what falls outside it. If the answer is vague, that vagueness is doing work for somebody, and it is not you. You should be able to name every recurring charge and say why it exists.
  • Everything is the vendor’s fault. Sometimes it genuinely is the internet provider or the software company. But if every unresolved issue ends in “we are waiting on them,” with no ticket number, no escalation, and no follow-up, that is not vendor management. That is a shrug with a monthly invoice attached.

The Red Flags That Are About Competence

  • Nothing is ever fixed before you notice it. If every piece of work starts with you reporting a problem, you are paying for a help desk and calling it managed services. A provider watching your systems should occasionally tell you about something they already handled. If that never happens, nothing is being watched or nobody is reading it.
  • The same problem keeps coming back. Recurring tickets with the same symptom mean somebody is treating the symptom. Ask for a root cause explanation on anything you have reported three times. A blank stare is your answer.
  • The security basics still are not done. Multi-factor authentication on every account that reaches company data. Former employees disabled the week they leave. Patches on a schedule you can see. Administrator accounts separated from daily-use accounts. Their absence after a year of paying somebody is not an oversight, it is a choice.
  • Nobody ever tells you no. A provider who agrees with every request is either not thinking or not listening. Part of the job is saying “that will cost more than it saves” out loud.

That last cluster carries real risk, and not only to you. The Verizon 2026 Data Breach Investigations Report found third-party involvement in 48 percent of the breaches it analyzed, a 60 percent increase year over year, and that only 23 percent of third-party organizations had fully remediated missing or improperly secured multi-factor authentication. Your IT provider is a third party with deep access to everything you own. Their hygiene is your exposure. We wrote more about that shift in why cybersecurity is no longer optional for mid-sized businesses.

Before You Fire Anyone, Check the Agreement

Here is the fair counterpoint. Some of these failures are contractual, not personal. Plenty of businesses buy a low-cost reactive agreement and then feel let down when nobody is proactive. If nobody monitors your systems because monitoring was never in scope, that is a scoping failure, and a conversation may fix it faster than a switch.

The joint advisory on managed service providers issued by CISA and its partner agencies in May 2022 lands on the same point from the security side, recommending that MSP and customer contracts transparently identify ownership of security roles and responsibilities. When nobody has written down who owns patching, backups, or account removal, both sides assume the other has it. So before you move, read what you actually bought. If the agreement covers it and it is not happening, that is a performance problem. If the agreement never covered it, that is a different conversation, and possibly a cheaper one.

How to Switch Cleanly

Leaving badly is expensive and occasionally catastrophic. Leaving well is mostly a matter of sequence.

  1. Get your documentation first, before you announce anything. Request a full inventory: devices, servers, network equipment, licenses, subscriptions, domain registrar, DNS records, and a list of every account with administrative access. Ask as a routine records request, not as a warning shot.
  2. Verify you control the crown jewels. Domain registrar, DNS, email tenant, and primary cloud accounts should each have an owner-level login held by you, not only by them. If any are registered to your provider’s email address, fix that now whether or not you are leaving.
  3. Read the exit terms. Notice period, data return obligations, offboarding fees, and what happens to any equipment or licenses purchased through them. Surprises here are common and expensive.
  4. Choose the incoming provider before you give notice. Overlap is your friend. A transition planned across four to six weeks is calm. A transition that starts the day after a blow-up is not.
  5. Do not burn the bridge before the handoff. The outgoing team knows things written down nowhere, and you want them answering the phone during cutover week. Be professional, pay the final invoice, keep it boring. Satisfaction is not worth a two-day outage.
  6. Rotate every credential after the handoff. Not because your old provider is malicious, but because good hygiene says access ends when the relationship does.

The Bottom Line

The test is not whether your provider is perfect. Everyone has a bad ticket. The test is whether you can get a straight answer about your own systems, whether you know what you are paying for, and whether anything ever gets fixed before you notice it. If those three are yes, small frustrations are worth working through. If any one of them is a firm no, the relationship is not going to improve on its own.

Harrison Ward Technology works with small and mid-sized businesses across Denton County, and we would rather you use this list on us than not have it. If you are weighing a change, the most useful thing we can do is give you an honest read on your current setup, including the parts your existing agreement covers well. If you are earlier in the process, we laid out what to look for in why more businesses are outsourcing IT and what to look for in a partner. Contact us today


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).