Signing with an IT company means handing over deep access to your systems, often for years. Here's what to actually evaluate before you do — technical fit, security, proof of results, and what happens if it doesn't work out.
Choosing an IT company is a bigger decision than it often gets treated as. You’re handing a third party ongoing access to your systems, your data, and often your team’s day-to-day productivity — usually for a multi-year relationship. Most businesses spend more time comparing quotes than they do actually evaluating whether a provider can deliver what they’re promising.
Evaluating an IT company means assessing a prospective provider’s technical fit, security practices, track record, and contract terms before signing — not just comparing pricing or a single sales conversation.
“I don’t want to give you a quote based on a headcount and a device list. Give me a week to actually look.”
— Adam Bowles, Partner & CEO, ACT360
The businesses that end up frustrated with an IT provider usually aren’t frustrated by bad luck. They’re frustrated by questions they didn’t ask before signing. Here’s what to ask instead.
Technical Fit: Can They Actually Support What You Run?
Before anything else, confirm the provider can genuinely support your specific environment, not just IT in general.
- What industries and business sizes do you typically work with?
- Do you support our specific software and systems, including anything industry-specific?
- What’s your typical ratio of technicians to client devices or users?
- Do you have in-house expertise for our platform, or does that get outsourced to a subcontractor?
A provider who’s vague about the last question — outsourcing specialized work without disclosing it — can create a coordination problem later, when it’s unclear who’s actually responsible for a given issue.
Security & Risk: What Happens With Access to Your Systems?
An IT provider typically has some of the deepest access to your business of any vendor you work with. The Canadian Centre for Cyber Security’s guidance on cyber supply chain security for small and medium organizations recommends treating critical vendors — a category that includes IT providers by definition — with the same scrutiny you’d apply to your own internal security posture, not just trusting that “they’re the IT people, they must have it covered.”
Questions worth asking directly:
- What security certifications or frameworks do you follow internally?
- How do you secure your own remote access tools, since those have deep access to our systems?
- What’s your incident response process if something goes wrong on your end?
- Do you carry cyber liability insurance, and at what coverage level?
A provider who bristles at these questions, rather than answering them plainly, is worth a second look.
Proof: Can They Show You, Not Just Tell You?

Every IT company says they’re proactive, responsive, and experienced. That’s meaningless without evidence attached to it.
- Can you provide case studies or references from businesses similar in size and industry to ours?
- What’s your average client tenure, and do you know why clients who’ve left, left?
- Can I speak directly with a current client, not just read a testimonial?
- What third-party reviews or recognitions can you point to?
References matter less for what they say and more for whether the provider is willing to offer them without hesitation. A provider confident in its own track record makes this easy.
The Exit: What Happens If It Doesn’t Work Out?

This is the question most businesses skip, and it’s arguably the most important one. A relationship that starts well can still go sideways, and the contract terms determine how expensive that turns out to be.
- What’s the length of the initial contract term, and what happens at renewal?
- Is there a defined exit clause, or are we locked in regardless of performance?
- Who owns our data, licenses, and documentation if we switch providers?
- What’s the transition process if we decide to leave?
A provider that requires a long lock-in with no meaningful exit option is betting that inertia, not performance, will keep you as a client. That’s worth noticing before you sign, not after a year of frustration.
The Full Checklist
Pulling it together, here’s what a thorough evaluation covers before signing:
- Technical fit confirmed for your specific systems and industry
- Security certifications, remote-access safeguards, and incident response process disclosed
- Cyber liability insurance coverage confirmed
- References or case studies from comparable businesses provided willingly
- Average client tenure and reasons for past departures discussed openly
- Contract term length and renewal terms clearly explained
- Exit clause or lack of one clearly stated
- Data, license, and documentation ownership confirmed in writing
- Transition process for leaving described in specific terms
- SLA response and resolution commitments defined by severity, not a single blended number
Signs You’re Being Sold, Not Assessed
A few patterns during the sales process itself are worth paying attention to:
A quote before a real conversation. If a provider can price a contract from a headcount and a device list without ever asking about how your business actually operates, that quote is a guess, not an assessment.
Pressure to sign quickly. Urgency tactics (“this pricing is only good this week”) have more to do with sales targets than your business’s actual timeline.
Vague answers that circle back to reassurance. “We’re very proactive” isn’t an answer to “what’s your average response time by severity.” If a specific question keeps getting a general answer, that’s the pattern to notice.
What This Looks Like at ACT360
Every ACT360 engagement starts with Assess — the first step in our ACTION methodology — specifically because a real quote can’t come from a headcount and a device list. We’d rather spend a week actually looking at how a business runs than hand over a generic proposal on day one.
That’s also why every ACT360 managed IT contract includes a 90-day exit clause. If a provider is confident in what they deliver, a client shouldn’t need to be locked in to stay. It’s a concrete answer to the “what happens if it doesn’t work out” question above, rather than a vague reassurance.
Final Thought
The businesses that end up satisfied with their IT provider a year later usually asked harder questions before signing, not after something went wrong. None of the questions above are unreasonable to ask, and a provider worth working with should be comfortable answering all of them directly.
T: 705-739-2281 E: [email protected]