Frontrow Technology

Free tool · 5 minutes · Managed IT providers

MANAGED IT PROVIDER —
SCORECARD.

Most Australian businesses can't tell whether their current IT provider is actually doing the job, or just answering the phone. Score your arrangement across responsiveness, security, backup, patching and strategy in five minutes.

20 questions · 5 domains

Managed IT Provider Scorecard

Score your current IT provider against what a competent managed service should actually deliver — responsiveness, security, backup, patching and strategy. Pick the option closest to how your arrangement runs today.

Domain 1

Responsiveness and service levels

Documented response and resolution targets, whether performance against them is measured and reported, after-hours cover, and a defined escalation path when something isn't fixed in time.

  • Does your IT provider have documented response-time targets for support tickets?

    Source: ITIL 4 — Service Level Management practice.

  • How are ticket resolution times tracked and reported to you?

    Source: ITIL 4 — Continual Improvement practice.

  • Is after-hours or emergency cover included in your agreement, and has it ever actually been tested?

    Source: AS ISO/IEC 20000 — IT service management, availability management.

  • When a ticket isn't resolved within the target time, is there a defined escalation path?

    Source: ITIL 4 — Incident Management practice.

Domain 2

Security baseline

Multi-factor authentication coverage, control over administrator accounts, centrally monitored endpoint protection, and whether security is genuinely built into the service or sold as a separate extra.

  • Is multi-factor authentication enforced across all user accounts?

    Source: ASD Essential Eight — Multi-Factor Authentication.

  • How are administrator accounts controlled in your environment?

    Source: ASD Essential Eight — Restrict Administrative Privileges.

  • Is endpoint protection deployed and centrally monitored across all your devices?

    Source: Australian Signals Directorate — general guidance on endpoint detection and response.

  • Is cyber security explicitly included in your agreement, or billed as a separate extra?

    Source: ASD Essential Eight Maturity Model — general framework reference.

Domain 3

Backup and recovery

What is actually backed up, whether a real restore has ever been tested, whether backups are protected from the same event that could take out live systems, and who owns the recovery plan.

  • Do you know exactly what systems and data are included in your backup, in writing?

    Source: ASD Essential Eight — Regular Backups.

  • Has a real restore ever been tested — not just a backup job logged as 'completed successfully'?

    Source: ASD Essential Eight Strategy 8 — Regular Backups (restore testing).

  • Are your backups protected from the same event that could take out your live systems?

    Source: ASD Annual Cyber Threat Report — ransomware resilience guidance.

  • Who owns the backup and recovery plan, and are there documented recovery targets?

    Source: ISO 27031 — ICT readiness for business continuity.

Domain 4

Patching and lifecycle management

Operating system and application patching cadence, whether hardware and software approaching end-of-support are tracked and flagged, and whether a current asset register exists at all.

  • How frequently are operating system security patches applied across your devices and servers?

    Source: ASD Essential Eight — Patch Operating Systems.

  • Are business applications, not just the operating system, kept on a patching schedule?

    Source: ASD Essential Eight — Patch Applications.

  • Does your provider maintain a current asset register of every device, server and licence in your environment?

    Source: ASD Essential Eight Maturity Model — asset inventory as a maturity precondition.

  • Is hardware and software nearing or past end-of-support tracked and flagged to you proactively?

    Source: Microsoft Lifecycle Policy — end-of-support tracking, Microsoft Learn.

Domain 5

Strategy and reporting

Regular reporting beyond the invoice, a forward-looking roadmap and budget, a named account contact who knows your business, and whether the arrangement itself has ever been reviewed.

  • Do you receive regular reporting on the state of your IT environment, beyond the invoice?

    Source: General managed services industry practice — technology business review reporting.

  • Is there a forward-looking technology roadmap and budget plan, or is support purely reactive?

    Source: General managed services industry practice — technology business review reporting.

  • Do you have a named account contact who understands your business, not just whoever answers the ticket queue?

    Source: General managed services industry practice — account management standard.

  • Has anyone — you or an independent party — formally reviewed whether this arrangement is still fit for purpose?

    Source: General governance practice — periodic vendor and service review.

This is an indicative self-assessment based on your own knowledge of the arrangement. It is not a substitute for a formal review of your provider's actual configuration and documentation. For a verified result Frontrow Technology offers an independent review of your current IT arrangement.

What the scorecard covers

Five domains. One evidence-based view.

Domain 1

Responsiveness and service levels

Most businesses only discover their provider has no real service level agreement when something urgent doesn't get fixed. 'We're usually pretty quick' is not a service level. A competent managed service documents its targets, measures itself against them, and tells you when it misses.

Domain 2

Security baseline

Security is either built into how a provider runs your environment, or it's an upsell conversation that happens after an incident. The baseline questions here — MFA, admin account discipline, monitored endpoints — separate a provider doing IT from a provider doing IT securely.

Domain 3

Backup and recovery

A backup that has never been restored is a hypothesis, not a control. Plenty of providers can point to a green tick in a backup console that has never once been proven to bring a system back.

Domain 4

Patching and lifecycle management

Unpatched systems and unsupported software are among the most common ways Australian businesses get breached, and the least glamorous thing for a provider to stay on top of. An asset register is the precondition for doing any of this properly — you can't patch or track the end-of-support date of something you don't know you have.

Domain 5

Strategy and reporting

A good IT provider operates like a business partner: reporting on trends, planning ahead, and inviting scrutiny of its own performance. A provider that only shows up when something breaks and sends an invoice every month is running a helpdesk, not a managed service.

Frequently asked questions

What Australian business owners ask about judging an IT provider.

How do I know if my IT provider is any good?

The honest answer is most businesses can't, because judging a technical service requires technical knowledge you may not have, and your provider controls most of what you see day to day. The reliable proxy is documentation: does your provider have written service level targets, a documented backup scope, a current asset register, and regular reporting that goes beyond the invoice? A provider confident in their own practice will hand these over without hesitation. A provider that goes quiet, gets defensive, or can only offer verbal reassurance is telling you something important.

My provider seems responsive on the phone — isn't that enough?

Answering the phone quickly is necessary but not sufficient. Responsiveness tells you the provider is available; it says nothing about whether tickets are actually resolved within a documented target, whether security fundamentals like multi-factor authentication and administrator account control are in place, or whether your backups have ever been restore-tested. A provider can be friendly and prompt on the phone while running an environment with no tested backup and no patching cadence. This scorecard is built to surface exactly that gap between how a provider feels and what it actually delivers.

What is a reasonable response-time target for IT support?

There's no single number that applies to every business, because it depends on ticket priority and what's agreed in your service level agreement. What matters more than the specific number is whether a target exists in writing at all, whether it's tiered by priority (a server outage should not queue behind a printer issue), and whether your provider reports its actual performance against that target. A provider with no documented target cannot, by definition, be held to one, no matter how quick they seem in the moment.

Is Microsoft 365 retention the same as a backup from my provider?

No. Microsoft 365's built-in retention, recycle bins and version history are recovery features with defined limits, not a backup. If your provider is relying solely on Microsoft's native retention as your backup strategy for mailboxes, OneDrive, SharePoint or Teams, that is a meaningful gap. A properly protected environment layers a genuine backup, ideally with immutable or offline storage, on top of Microsoft's native retention settings, with restores tested on a regular schedule rather than assumed to work.

Should security be included in my managed IT contract, or is it reasonable to pay extra?

Reasonable providers vary in exactly where they draw this line, and there's no single correct answer. What matters is that the line is explicit. A provider should be able to tell you in writing exactly which security controls — multi-factor authentication, administrator account restrictions, endpoint monitoring — are included in your base fee, and which are optional additions. The problem isn't a provider charging separately for advanced security; it's a provider who has never had that conversation with you at all.

How often should IT patching happen?

Operating system security patches should be applied on a defined, regular cadence, with more urgent patches applied faster based on the severity of the vulnerability they close. Application patching, not just Windows or macOS, should follow a similar defined schedule rather than happening ad hoc. The Essential Eight framework treats patch timing as a maturity measure precisely because delayed patching is one of the most common ways Australian businesses are breached. If your provider can't tell you the current cadence, it likely isn't being tracked.

What should I ask my provider if this scorecard comes back red or amber?

Start with the specific questions you scored lowest on, rather than raising the whole assessment at once — a provider is more likely to engage constructively with a request to see the documented backup scope and the last restore test result than with a claim that an online quiz says they're failing. A competent provider will treat the request as reasonable and produce the documentation. A provider that resists, delays, or can't produce it after a reasonable period is giving you useful information about the arrangement, independent of the score itself.

Is switching IT providers as disruptive as it sounds?

A properly managed transition, with a documented asset register and credentials handed over cleanly, can happen with minimal disruption to day-to-day operations. The disruption most businesses fear usually stems from a poorly documented incumbent environment — exactly the kind of gap this scorecard is designed to surface before it becomes a problem during a transition, not after. Reviewing the current arrangement first, whether or not you end up switching, generally makes any future transition faster and lower-risk.

How is this scorecard's methodology validated?

Each scoring threshold reflects an established reference point: the Essential Eight for patching, multi-factor authentication and backups; ITIL 4 service management practices for response and escalation; ISO 27031 for recovery planning; and general managed services industry practice for reporting, roadmap and account management standards. The methodology is authored by Daniel Brown (5x Microsoft MVP), Graeme Lodge (Managing Director) and Sam Williams (Investor & Executive Consultant), drawing on Frontrow's managed IT engagements across Queensland and South Australia.