Red flags when hiring an IT support company
Most IT support problems are visible in the sales meeting. Ten warning signs to look for before you sign, and in the first months after.

The proposal reads well. Response is "fast", security is "built in", and the price sits on page one. Twelve months later you have a shared admin login the provider owns, a separate security quote on top of the fee, no monthly report, and the same printer fault logged for the fourth time. Every one of those was visible in the sales meeting.
Why the sales process gives the game away
A provider that is vague with a prospect it wants to win will be vaguer still with a client it already has. The security points below are not only our opinion. The NCSC's guidance on choosing an MSP sets out what a good provider should offer as standard, and its blog on using MSPs to administer your cloud services is blunt about how provider access should be set up. Falling short of either is a red flag however good the lunch was.
This article covers what to watch for. The list to take into a meeting is in questions to ask an IT support company, and the fuller selection method is in how to choose an IT support provider.
What are the red flags during the sales process?
Response time is "fast", not a number
"Fast" means nothing in a dispute. A response time is a number of minutes, in writing, with a definition of what counts. A human picking up the ticket counts. An automated email does not.
For a 25-person firm, the gap between 2-hour and 20-minute fixes came to roughly £27,000 a year in what a slow IT response costs. Ask for the number and last quarter's actual figures. If they cannot give you both, they do not measure it.
They won't say who answers the phone
Ask who picks up when you call at 9am on a Tuesday, and how many engineers are on the desk. Hesitation usually means an outsourced first line reading from a script, or two engineers stretched across far too many clients. A provider proud of its desk will tell you who is on it.
Security is a priced add-on
If backups, patching, multi-factor authentication and security monitoring appear as optional extras on the quote, the base service is not a managed service. The NCSC guidance treats these as things to expect from an MSP as a matter of course. We cover what should be included in cyber security from your IT provider.
Admin accounts in the provider's name, or one shared login
Ask how their engineers will access your systems. The right answer is a named account for each engineer, each protected by multi-factor authentication, with the top-level admin accounts kept as break-glass accounts that belong to you. The wrong answers are a single shared "support" login, or admin accounts registered to the provider that you cannot see or revoke.
The NCSC's cloud blog is explicit on this. Shared admin accounts mean you cannot tell which person did what, and a compromised provider is a route into every one of its clients. If the provider owns the admin accounts, it effectively owns your business. Some providers prefer it that way.
A long auto-renewing term before you've seen the contract
A 36-month term with automatic renewal and 90 days' notice is a common shape. It is not wrong in itself, but a provider that pushes you to sign before you have read the full terms is relying on the term rather than the service to keep you.
Pressure tactics belong here too: a discount that expires on Friday, or an onboarding "slot" that will otherwise go to someone else. Reluctance to put service levels in the contract itself, rather than a brochure, is the same flag in a different coat. What should be in an IT support contract sets out what to check.
No references from businesses your size
Logos on a website are not references. Ask to speak to two current clients of roughly your size, with similar stakes when systems fail. A provider that has been trading for years and cannot produce two has clients who would rather not be asked. When you do speak to them, ask about the worst day, not the average one.
Vague answers about backups and restore tests
"Everything is backed up to the cloud" is the vague answer. The specific answer covers what is backed up, how often, where it is held, and the date and duration of the last test restore.
The NCSC guidance expects backups to be restored regularly as a test. An untested backup is only a hope.
No written onboarding plan
Switching providers is the riskiest moment in the relationship. A provider who cannot show you a written plan for the first 30 days, covering access handover, documentation, an account audit and what happens to the old provider's logins, is going to improvise it on you. Our guide to switching IT provider without downtime shows what a proper handover looks like.
What are the red flags once you are a client?
No monthly report
If you cannot see tickets logged, tickets closed, response times against target, patch status and backup results each month, you are paying on trust. The NCSC guidance names regular reporting and reviews as things the contract should require. If one has to be chased, and arrives with suspiciously tidy numbers, that is the second red flag.
The same faults keep recurring
A good service desk fixes the fault, then fixes the cause. If the same user has the same printer or sign-in problem every fortnight, the provider is closing tickets rather than solving problems. Over 12 months those repeat faults cost more than the contract does. Our one-hour invoice checklist shows whether that is happening to you.
What we do
Systemwork has supported businesses across Leeds and Yorkshire since 2005. Our managed IT support is a fixed monthly price per user, with a service desk staffed by engineers and proactive monitoring included. Site visits are included too, except for project work.
We will tell you if we are not the right fit. Every new client starts with a free IT audit: we look at how your current setup handles access, backups, patching and reporting, and tell you plainly what we find, whether you move to us or not.
Book a free IT audit. Call 0113 898 0565 or use the button below.
Frequently asked questions
What is the biggest red flag when hiring an IT support company?
Admin access held in the provider's name or through a shared login. You cannot see who did what in your systems, and you cannot easily remove the provider if the relationship fails. The NCSC advises named accounts for every engineer, with the top-level accounts kept under your control.
Is a three-year IT support contract a red flag?
Not on its own. Long terms with automatic renewal are common and can come with a better price. The red flag is being pressed to sign before you have read the full terms, or service levels that never make it into the contract.
Should security be included in managed IT support?
Yes. Backups, patching, multi-factor authentication and security monitoring are the basics of managing an IT estate, and NCSC guidance treats them as standard. If they appear as paid extras, the base service is incomplete.
What should I do if my current IT provider shows these signs?
Raise the specific issue in writing, referring to the contract, and ask for a date by which it will be fixed. Check your notice period at the same time. If the response is vague, start comparing alternatives before the renewal date.
