Twelve Questions to Ask Your IT Provider Before You Renew

A finance director holds up a list of twelve questions across the desk from her IT provider, with the renewal date circled on the calendar behind them

Most managed IT agreements get renewed without anyone reading them. The invoice arrives on time, the tickets got answered, nothing burned down this year, so the contract rolls over for another twelve months. Then the audit finds something, a quote arrives to fix it, and you find out what your monthly fee was actually buying. You pay for it somewhere.

Across the 1,500 or more cyber audits inSUPPORT has run for Australian businesses, the questions that decide whether a provider deserves another year are rarely technical. They are commercial. What does the fee cover. What can they prove. Who owns the problem at four o'clock on a Friday. Below are the twelve worth asking at your next renewal, and what a straight answer sounds like, because you will hear some comfortable ones.

TL;DR: What to remember

  • ✅ Twelve questions, three groups: four about money, four about proof, four about the day something breaks. All of them answerable in plain English.
  • ✅ Ask them of the provider you already have. It costs nothing, and a renewal is the one time of year straight answers are owed.
  • ✅ A straight answer is a list, a date or a document. An adjective is a warning.
  • ✅ If your provider bills the audit and then bills the fix, every problem they find is a new project for them. Know which model you are on before you sign.

Contents

What your monthly fee actually covers

Start with the money, because everything else is downstream of it. Plenty of managed IT agreements separate monitoring and helpdesk from security remediation and project work. The monthly fee buys the first lot, and the second lot arrives later as a quote. That is a legitimate way to sell IT. The problem is being on that model without ever having agreed to it, and the second invoice is a lousy way to find out.

1. What exactly does the monthly fee cover, and what gets quoted separately?

A straight answer is a list, not an adjective. If the reply is "everything is included", ask which line items showed up on your quotes last year. inSUPPORT built its support pricing so the remediation an audit finds is included in the support fee, with insurance, backup and security awareness quoted separately and named. Whichever way your provider structures it, you are entitled to see the boundary drawn in writing.

2. When your audit finds a problem, who pays to fix it?

This is the question that exposes the incentive. If your provider bills the audit and then bills the fix, every problem they find is a new project for them. Ask them to say which model they run and to point at the clause that says so. The boundary belongs in the contract, not in the sales conversation.

3. What did we spend with you outside the monthly fee last financial year?

One number, and they already have it, because they invoiced it. If producing that figure takes a fortnight, your provider does not know what your account costs you, and that tells you something about how the account is run. Put it next to the monthly fee and you will see what your agreement actually costs, rather than what it says on the front page.

4. What happens to the fee when we add or remove staff?

Growth should not need a renegotiation. The answer you want is a per-user rate you can forecast against, in both directions, because businesses shrink too. If seats only ever get added and never come off the bill, raise it now, while the renewal is still unsigned and the decision is still yours.

What your provider can prove today

Anyone can tell you your environment is in good shape. The whole question is whether they can show you, today, from records that already exist. The Australian Signals Directorate's (ASD) guidance for businesses engaging a managed service provider takes the same line: it asks whether the provider implements the Essential Eight themselves, administers systems securely, monitors activity, assesses their own practices and can respond to an incident. Ask to see the artefact, not the assurance.

5. Which framework are you aligning us to, and what is in scope?

"You're compliant" is an adjective, not an answer. A real one names the framework, the systems it covers, who assessed it and when. Be precise about what alignment means, too: ASD is explicit that the Essential Eight is a baseline with three maturity levels, not a certificate, and that no set of mitigations is guaranteed to stop every threat. Anything bigger than that is comfort, and comfort is not a control.

6. Can you show me our documentation right now, without preparing it first?

A link, not a promise to send something through. Network diagrams, asset registers, the backup configuration, who has admin access. Documentation that has to be written after you ask for it is homework, and homework arrives late. And if you ever leave, that folder is the difference between a handover and a hostage negotiation.

7. When did you last test a restore, and what did it prove?

A backup job that reports success proves the software ran. A restore that actually brought a system back proves you can recover. Those are different things, and the gap between them is where businesses die. Ask for the date of the last test restore and what came back. If the answer is a monitoring screenshot, ask again.

8. What do you monitor, and who actually reads it?

Logs nobody reads are just storage. The answer you want names a person or a roster and what wakes them up. Alerts that go to an inbox nobody owns are how an incident runs for three weeks before anyone notices.

What happens when something breaks

The group people skip, because it deals with a day nobody wants to picture. It is also where the cost lives. ASD recorded more than 84,700 cybercrime reports in 2024 to 2025, around one every six minutes, and the average self-reported cost for a small business was $56,600 per report, up 14 per cent on the year before. Those numbers are the reason these four questions are not optional extras.

9. What are your real support hours, and what happens outside them?

Not the hours on the website. The hours a human answers. Then the harder half: when the till goes down at 7pm on a Friday, what number do you ring, who escalates it, and what does after-hours cost. If the honest answer is a voicemail, you have just found the price of the cheaper contract.

10. Who makes the call in an incident, and what do they do first?

The first move in a real incident is preserving the evidence, because a poorly controlled recovery can overwrite the very records that show what happened and what it touched. Then services come back in business priority order, not in the order they are easiest to restore. If your provider's incident plan starts with "rebuild everything", the plan was written for their convenience. inSUPPORT designs incident response during onboarding, not on the day, and that ordering is the reason why.

11. Can you help us assess and report inside the statutory timeframes?

An entity covered by the Notifiable Data Breaches scheme that suspects an eligible breach must take all reasonable steps to complete its assessment within 30 calendar days, and once it forms the view that a breach is notifiable, it must give a statement to the Commissioner as soon as practicable. You cannot contract those duties out to a provider, though a provider may carry obligations of its own. What your provider changes is speed: whether the investigation starts within the hour or after the weekend. A good answer here shows they know the clock exists.

12. If we left tomorrow, what would you hand over?

The most revealing question of the twelve, asked at the exact moment it is easiest to ask. A documented handover, credentials, licences in your name, your data in a usable form. A provider confident in their work will answer it without flinching. A vague one has just shown you how the relationship is really structured: your environment is being held, not run.

Questions owners ask about running this conversation

What if my provider cannot answer some of these?

One awkward answer is not a reason to leave. Documentation slips, people get busy. What matters is the pattern and the response: a provider who commits to a date and meets it has given you a useful answer, and so has one who treats the questions themselves as an insult. Write down what came back and read the whole list, not any single reply.

Do I need technical knowledge to judge the answers?

No, and that is the point. Every one of the twelve can be answered in plain English, and a provider who cannot explain their own service to the person paying for it has answered a bigger question than the one you asked.

When should I start, and how long does it take?

Allow an hour for the conversation and a week for the documents to come back. Start before your contract's notice deadline, which is often weeks before the renewal date itself, so check the termination clause first. How long the evidence takes to arrive is part of the evidence.

What if the answers are not good enough?

Get an independent read of where you actually stand before you make a decision about people. A gap analysis turns a suspicion into a list, and a list is something you can put in front of your current provider or a new one.

Ready to see where you actually stand?

Run the twelve on your current provider first. If the answers leave you with more questions than you started with, the next step is an independent look at the environment itself. A Cyber Strength Audit examines what is actually configured, identity and access, patching, backup and recovery, email and endpoint security, and gives you a plain English risk assessment ranked by business impact, with a costed path to closing the gaps. Kane Nawrocki has spent more than 25 years in IT, and the twelve questions above came out of the 1,500 or more cyber audits inSUPPORT has run, and the conversations that started them, with people who were not sure what they were paying for. We do not run an audit, hand you a report and disappear.

Book a Cyber Strength Audit →

Citations

  • Questions to ask managed service providers, Australian Signals Directorate. ASD's own questions for organisations engaging a managed service provider, covering Essential Eight implementation, secure administration, monitoring, assessment and incident response. Last updated 6 October 2021. cyber.gov.au
  • Annual Cyber Threat Report 2024 to 2025, Australian Signals Directorate. Records more than 84,700 cybercrime reports, an average of one every six minutes, and an average self-reported cost per report for small business of $56,600, up 14 per cent. Published 14 October 2025. cyber.gov.au
  • Quick reference guide for responding to data breaches, Office of the Australian Information Commissioner. Sets out the contain, assess, notify and review steps, the 30 calendar day assessment requirement, and the duty to give a statement to the OAIC as soon as practicable. Dated 29 June 2026. oaic.gov.au
Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE