Picking information technology (IT) support is more than a technology question. It is a business decision. The right partner keeps people productive, protects your data, and helps you plan with confidence. This checklist gives you clear questions to ask and proof to request before you commit.
Start With Your Business Situation
Begin by mapping your business as it currently stands.
- How many people do you support
- Where they work
- Which systems keep the lights on
- Note any compliance needs
- Capture hours of operation and peak periods
- Record pain points that slow teams down
- Set goals for uptime protection and the user experience
- Decide if you want a fully managed partner or co-managed support that backs up your IT staff
- Define what is non-negotiable versus nice to have
Write it down and share it with vendors. A clear picture leads to a better fit and fewer surprises.
Security Baselines
Make a security routine. These checks keep data safe and teams working.
- Turn on multi-factor authentication (MFA) for admins and key apps
- Patch operating systems (OS), apps, and firmware on a set cadence with reports
- Keep a written incident response plan guided by the National Institute of Standards and Technology (NIST)
- Apply least privilege and review access regularly
- Monitor endpoints, email, and identities around the clock
- Track backup results, patch status, and confirm MFA coverage
- Run quarterly tabletop drills
Get proof. Ask for sample reports and recent test results.
Reliability And Service Level Agreements (SLAs)
Know how service is measured and reported. You should see it in writing.
- SLAs that set the first response and time to resolve
- Uptime targets and maintenance windows
- Severity levels with clear escalation steps
- Coverage hours documented, including after-hours
- Status updates during incidents on a set cadence
- Root cause reports after major issues
- Quarterly reviews with metrics and actions
- Access to a portal with live ticket status
If they cannot show this, keep looking.
Compliance, Attestations, and Insurance
Keep compliance tight. Request proof that stands up in an audit.
- Documented experience with the Health Insurance Portability and Accountability Act (HIPAA), the Payment Card Industry Data Security Standard (PCI DSS), or other rules that apply
- Current System and Organization Controls 2 (SOC 2) or precise control mapping
- Data handling and retention policy you can review
- Security awareness training and background checks on staff
- Vendor risk process and third-party oversight
- Cyber liability coverage with stated limits
- Incident and breach notification commitments in the master services agreement (MSA)
- Signed business associate agreements (BAAs) when needed
If they will not share reports or policies, move on.
People, Process, and Partnerships
You need a steady team and clear working methods.
- Named account lead with a backup
- Information Technology Infrastructure Library (ITIL) based ticket change and problem workflows
- Documented standard operating procedures (SOPs) and runbooks you can review
- Background checks and security training for staff
- Vendor coordination and defined escalation paths
- Quarterly reviews tied to your goals
Meet the team before you sign. Fit and follow through matter.
Transparency
You should always be aware of what is happening. Make status easy to see and share.
- Client portal with live tickets and service level agreement (SLA) timers
- Asset inventory and warranty data
- Monitoring with clear alerts and runbooks
- Patch and backup reports with pass or fail
- MFA and privileged access reviews
- Documentation hub with SOPs and site notes
- User self-service for resets and onboarding
- Monthly scorecard and quarterly business review (QBR) deck
Ask for a sample portal or report pack. Seeing it first prevents surprises.
Pricing and Contracts
Know what you pay and what you get. Keep surprises off the invoice.
- Clear scope of services with in and out of scope
- Pricing model per user per device or fixed, written down
- Term length renewal rules and notice window
- Project rates and change order process
- Onboarding costs and early termination fees
- Third-party pass-throughs listed by the vendor
- SLA credits and how they apply
- Data ownership and access during and after service
Ask for a sample invoice and MSA. Review it with your team.
Onboarding Plan
Map access document systems and show quick wins.
- 30 60 90 plan with owners and dates
- Discovery of users’ devices, apps, and vendors
- Credential cleanup and admin account review
- MFA rollout and patch catch-up in week one
- Backup validation and a test restore
- Build the asset inventory and SOPs
- User communications and training for key changes
- Early wins list with timelines
Ask for the plan in writing and a sample calendar. Clarity upfront saves time.
Exit Plan and Data Portability
Plan the handoff before you start. Make it easy to switch or scale.
- Notice period and transition timeline in writing
- Admin credentials documented and verified
- Full export of configs, logs, and documentation
- Data exports in open, readable formats
- Final backup snapshots with retention dates
- Cooperation clause with duties and points of contact
- Access removed on cutover and keys returned
A clear exit keeps leverage on your side. It also protects uptime and data.
Red Flags
Spot warning signs early. They point to pain later.
- Vague SLAs or no sample reports
- No written incident response plan
- Backups without recent restore tests
- Thin documentation and missing runbooks
- Slow or unclear escalation during outages
- No references in your industry
- One-person shop with no coverage plan
- Hesitation to share portal access or metrics
If two or more show up, keep looking.
Make the Right IT Call
Choosing IT support should feel straightforward. Use this checklist to compare partners based on outcomes that are visible and measurable. Ask for proof at every step.
At cb20, we build predictable, data-driven IT systems that keep operations stable and ready for what’s next. Reach out to our experts today to discover how cb20 can support your organization.
