How do I know if my IT provider is any good?
The honest answer is most businesses can't, because judging a technical service requires technical knowledge you may not have, and your provider controls most of what you see day to day. The reliable proxy is documentation: does your provider have written service level targets, a documented backup scope, a current asset register, and regular reporting that goes beyond the invoice? A provider confident in their own practice will hand these over without hesitation. A provider that goes quiet, gets defensive, or can only offer verbal reassurance is telling you something important.
My provider seems responsive on the phone — isn't that enough?
Answering the phone quickly is necessary but not sufficient. Responsiveness tells you the provider is available; it says nothing about whether tickets are actually resolved within a documented target, whether security fundamentals like multi-factor authentication and administrator account control are in place, or whether your backups have ever been restore-tested. A provider can be friendly and prompt on the phone while running an environment with no tested backup and no patching cadence. This scorecard is built to surface exactly that gap between how a provider feels and what it actually delivers.
What is a reasonable response-time target for IT support?
There's no single number that applies to every business, because it depends on ticket priority and what's agreed in your service level agreement. What matters more than the specific number is whether a target exists in writing at all, whether it's tiered by priority (a server outage should not queue behind a printer issue), and whether your provider reports its actual performance against that target. A provider with no documented target cannot, by definition, be held to one, no matter how quick they seem in the moment.
Is Microsoft 365 retention the same as a backup from my provider?
No. Microsoft 365's built-in retention, recycle bins and version history are recovery features with defined limits, not a backup. If your provider is relying solely on Microsoft's native retention as your backup strategy for mailboxes, OneDrive, SharePoint or Teams, that is a meaningful gap. A properly protected environment layers a genuine backup, ideally with immutable or offline storage, on top of Microsoft's native retention settings, with restores tested on a regular schedule rather than assumed to work.
Should security be included in my managed IT contract, or is it reasonable to pay extra?
Reasonable providers vary in exactly where they draw this line, and there's no single correct answer. What matters is that the line is explicit. A provider should be able to tell you in writing exactly which security controls — multi-factor authentication, administrator account restrictions, endpoint monitoring — are included in your base fee, and which are optional additions. The problem isn't a provider charging separately for advanced security; it's a provider who has never had that conversation with you at all.
How often should IT patching happen?
Operating system security patches should be applied on a defined, regular cadence, with more urgent patches applied faster based on the severity of the vulnerability they close. Application patching, not just Windows or macOS, should follow a similar defined schedule rather than happening ad hoc. The Essential Eight framework treats patch timing as a maturity measure precisely because delayed patching is one of the most common ways Australian businesses are breached. If your provider can't tell you the current cadence, it likely isn't being tracked.
What should I ask my provider if this scorecard comes back red or amber?
Start with the specific questions you scored lowest on, rather than raising the whole assessment at once — a provider is more likely to engage constructively with a request to see the documented backup scope and the last restore test result than with a claim that an online quiz says they're failing. A competent provider will treat the request as reasonable and produce the documentation. A provider that resists, delays, or can't produce it after a reasonable period is giving you useful information about the arrangement, independent of the score itself.
Is switching IT providers as disruptive as it sounds?
A properly managed transition, with a documented asset register and credentials handed over cleanly, can happen with minimal disruption to day-to-day operations. The disruption most businesses fear usually stems from a poorly documented incumbent environment — exactly the kind of gap this scorecard is designed to surface before it becomes a problem during a transition, not after. Reviewing the current arrangement first, whether or not you end up switching, generally makes any future transition faster and lower-risk.
How is this scorecard's methodology validated?
Each scoring threshold reflects an established reference point: the Essential Eight for patching, multi-factor authentication and backups; ITIL 4 service management practices for response and escalation; ISO 27031 for recovery planning; and general managed services industry practice for reporting, roadmap and account management standards. The methodology is authored by Daniel Brown (5x Microsoft MVP), Graeme Lodge (Managing Director) and Sam Williams (Investor & Executive Consultant), drawing on Frontrow's managed IT engagements across Queensland and South Australia.