To choose a managed IT provider, judge on criteria rather than marketing: a written response target, month-to-month terms rather than a lock-in contract, a documented security position, technicians who actually attend your premises, transparent pricing, and a clean exit process. Several capable MSPs operate on the Gold Coast — ask each the eight questions below and compare the written answers.
1–4: what they'll do for you
1. What's your response target, in writing?
Not "we're very responsive". An actual commitment, by priority, with different answers for a critical fault and a password reset. If it isn't written down before you sign, it isn't a commitment. Ours is published — priority matrix and all.
2. What happens outside business hours?
Who answers, what they can actually do, and whether after-hours attendance is included or extra. Many providers advertise 24/7 and mean an answering service. We are open 8am to 5pm Monday to Friday; after hours it's an AI operator that takes details and escalates, and it says so.
3. Is it month-to-month, or locked in?
A three-year term protects the provider, not you. If they're good you'll stay anyway. Ours is month-to-month with no exit fee.
4. What exactly is included, and what's extra?
Get the boundary in writing — particularly around projects, hardware, after-hours work and per-ticket charges. "Unlimited support" with a per-ticket fee isn't unlimited.
5–8: what happens when things go wrong
5. When did you last test a restore for a client?
The single best question on this list. Almost every provider does backups. Far fewer test that they restore. If the answer is vague, or "the software reports success", that is your answer.
6. What's your own security position?
They'll hold keys to your systems. Ask about individually named access rather than shared logins, MFA on their own tools, what they're aligned to, and whether they carry cyber liability insurance. Ours is published in full, including what we're not certified to.
7. Who actually attends, and are they screened?
Whether it's their staff or subcontractors, and whether the person entering your premises holds a police check. For healthcare, education and childcare sites this is usually a hard requirement.
8. What happens if we leave?
Ask before you join. Documentation, credentials, licences and asset register handed over — or held as leverage. A provider confident in their service answers this easily. We treat a clean exit as part of the service.
Three answers that should end the conversation
- "We'll get to it when we can." No response target means no commitment, and you'll find out where you sit in the queue at the worst possible moment.
- "You'll need to sign a three-year agreement." Occasionally justified where significant hardware is bundled. Usually it's protecting the provider from their own service quality.
- "We hold the domain and licences in our name." Your domain, your Microsoft 365 tenancy and your software licences should be registered to your business. This is the most common thing we find wrong when taking over, and it's much easier to fix while everyone's still on good terms.
A note on this guide
We wrote this knowing it might cost us work, because a business that asks these questions and picks someone else was probably a better fit for them anyway. What we would rather avoid is being chosen for the wrong reasons and parting company in eight months.
Our own answers are published rather than given on request, which is the only way a comparison like this is worth doing. Take this list to whoever else you're considering.
What makes this decision hard
Six things that obscure the comparison, and the questions that cut through each.
“They all say the same things”
Usually marketing language that is identical across the industry. Proactive, trusted, partner and 24/7 appear on nearly every provider’s website including, in places, ours.
What we do Ask for the specifics behind each claim in writing. A provider that publishes its response targets, its hours and its exit terms is making a commitment; one that describes itself as proactive is not.
“They advertise 24/7 support”
Usually frequently an answering service or a voicemail box. It is a claim worth testing rather than accepting.
What we do Ring the number at nine on a Sunday evening before you sign anything. We do not advertise 24/7 for general enquiries, because we are open eight to five weekdays and would rather say so.
“The quote is much cheaper than the others”
Usually usually a different scope rather than a better price. What has been excluded is rarely visible in the headline number.
What we do Normalise the quotes to one scope before comparing. Most of the price difference between providers turns out to be inclusions, and the cheapest quote frequently is not.
“They want a three-year term”
Usually an arrangement that protects the provider. Long terms with exit fees are common in this industry and are not a requirement of doing the work well.
What we do Read the term and the exit clause before anything else. Ask what happens to your documentation and credentials if you leave — the answer to that question is revealing.
“How do we know they’re any good?”
Usually the hardest thing to assess from outside, since every provider produces satisfied references.
What we do Ask for something specific: their response targets in writing, an example of documentation they hand over, and what they will do that the incumbent is not. Vague answers to specific questions are the signal.
“What happens to our passwords if we leave?”
Usually the question that separates providers most sharply, and the one businesses ask least often.
What we do Ask it in the first meeting. Credentials, asset registers, network documentation and licence details should be yours on request at any time, not only on the way out.
What this looks like in practice
Representative engagements, drawn from real work with identifying detail removed — we don’t name clients without written permission.
Ringing the shortlist at nine on a Sunday
The situation
A business was choosing between three providers. Two advertised 24/7 support prominently and the third published business hours only, which had initially counted against it. The proposals were otherwise difficult to separate.
What we found
We suggested testing the claim rather than weighing it. Rung on a Sunday evening, the first reached an answering service that took a message which was never passed on — the business followed up on the Monday and no record of the call existed. The second reached a voicemail box that was full and would not accept a message. The third, which had never claimed after-hours availability, answered with a recorded message stating its hours and a callback commitment, and rang back at four minutes past eight on the Monday morning.
What we did
Reported what each call had actually produced and let the business weigh it. The exercise took about ten minutes and cost nothing.
The outcome
The business chose the provider that had not made the claim. Two of the three had advertised something they did not do, which is not dishonesty so much as an industry habit — and it is trivially testable before signing rather than discoverable during an outage.
An assessment that recommended keeping the incumbent
The situation
A business of forty staff had used the same provider for six years and had begun to wonder whether it was still getting value. It commissioned an independent review with a half-expectation of being told to move.
What we found
The provider was doing a competent job. Patching was current, backups had been restored from within the year, multi-factor authentication was enforced, and documentation existed and was accurate — which is more than we find most of the time. Two genuine gaps existed: no formal restore testing schedule, and firewall rules nobody could account for.
What we did
Reported exactly that, including the parts that reflected well on the incumbent, set out the two gaps and what closing each would take, and gave the report to the business to hand to its provider.
The outcome
The business kept its provider, who closed both gaps within a month. We did not win the account and were not trying to — a review that always concludes the incumbent is failing is not a review, it is a sales process.
Questions Gold Coast businesses ask us
How do you choose a managed IT provider?
Judge on criteria rather than marketing. Ask for a written response target by priority, month-to-month terms rather than a lock-in contract, evidence that client restores are actually tested, the provider's own security position and insurance, whether attending technicians are screened, and what happens to your documentation if you leave. Ask every provider the same questions and compare the answers in writing.
What's the single most revealing question?
"When did you last test a restore for a client, and what happened?" Almost every provider runs backups. Far fewer verify they restore. A vague answer, or one that relies on the backup software reporting success, tells you what you need to know.
Should we avoid long contracts?
Generally, yes. A multi-year term protects the provider rather than you, and a good provider doesn't need one. There are exceptions where significant hardware is bundled into the monthly fee, but ask specifically what the term is buying you.
How much should managed IT cost?
There is no single figure, and anyone quoting one before understanding your environment is guessing. Cost is driven by whether you run a server, hardware age, number of sites, what has to stay available and what compliance applies. What you should expect is a quote after a proper review, and full transparency about what's included versus extra.
Does the provider's size matter?
It's a trade-off rather than a ranking. A larger provider gives deeper cover through leave and more specialists; a smaller one gives people who know your environment without reading notes and an escalation that reaches a decision-maker. Ask specifically about cover during simultaneous leave if that's a concern.
Should we check their own security?
Yes, and few businesses do. Your provider holds administrative access to your systems, which makes them part of your risk. Ask about individually named access, MFA on their own tooling, what frameworks they work to, and whether they carry cyber liability insurance.
Ask us the eight questions
Most of our answers are already published. If one isn't, ask and we'll put it in writing.