Unhappy With Your Current IT Provider? It Might Be Time for Better IT Support
Changing IT providers can feel risky.
Even when support has become frustrating, businesses often stay because moving sounds worse.
You may worry that:
passwords will not be handed over
Microsoft 365 access will be disrupted
nobody knows how the network is configured
backups will be affected
employees will lose support during the transition
the new provider might turn out to be no better
Those are legitimate concerns.
But there is another risk worth considering:
What is staying with poor IT support already costing the business?
Recurring faults, slow responses, weak security, poor communication and a lack of forward planning can quietly cost far more than an organised provider change.
Good IT support should make technology easier to operate.
If you have reached the point where employees expect tickets to be ignored or managers spend their time chasing the IT company, the relationship probably deserves reviewing.
What Does Poor IT Support Actually Look Like?
Bad IT support is not always a catastrophic server failure.
More often, confidence disappears gradually.
You begin noticing patterns such as:
the same faults keep returning
support tickets need repeated chasing
nobody takes ownership
different engineers provide different temporary fixes
security recommendations never become actions
documentation is poor
backups exist, but nobody can tell you when they were last restored
Microsoft 365 has evolved without anybody reviewing its configuration
every project feels harder than it should
Eventually, the business adapts to poor service.
Employees create workarounds.
Managers stop reporting smaller problems.
People say:
“There’s no point contacting IT because they won’t fix it properly.”
That should never become normal.
Response Time Matters — but It Is Not Everything
One of the first frustrations businesses notice is usually slow response.
Someone cannot work.
They log a ticket.
Hours pass.
Nothing happens.
Response time matters because technical downtime becomes employee downtime.
But there is an important distinction between:
response time
and:
resolution time.
The NCSC’s current MSP guidance specifically recommends having clear Service Level Agreements setting expectations around service delivery and response.
A provider acknowledging a ticket quickly but leaving the problem unresolved for days is not necessarily providing good service.
At Hamilton Group, we aim to make first contact on IT support requests within 15 minutes.
But the more important objective is:
take ownership → investigate properly → communicate → resolve → prevent recurrence where possible.
Your IT Provider Should Take Ownership
Employees should not need to diagnose infrastructure before asking for help.
Imagine an employee cannot access a cloud application.
The cause could be:
laptop
Wi-Fi
firewall
broadband
DNS
Microsoft 365 identity
the software supplier
The user should not have to determine which company to call.
A good IT provider should investigate and, where necessary, coordinate with:
internet providers
software suppliers
hardware manufacturers
Microsoft
telecoms providers
until ownership of the actual fault is clear.
Constantly saying:
“That isn’t us”
without helping determine whose problem it actually is provides very little value.
Repeated Problems Are a Major Warning Sign
A recurring issue is often more important than an isolated fault.
Suppose an employee’s Outlook profile breaks every three weeks.
Fixing it once is support.
Fixing it six times without asking why is poor problem management.
The same applies to:
Wi-Fi regularly disconnecting
printers repeatedly falling offline
servers filling their disks
backups repeatedly failing
VPN connections dropping
Managed IT should use:
ticket history
monitoring
logs
recurring-problem analysis
to identify patterns.
The objective should be to reduce how often employees need support—not simply process an increasing number of tickets efficiently.
Your Provider Should Understand the Business
Technology only matters because the business depends on it.
Your provider should understand things such as:
which applications are critical
which employees cannot tolerate extended downtime
where sensitive information is stored
which systems have regulatory implications
how staff work remotely
what the organisation plans to change or grow
A recruitment company may have very different priorities from:
solicitor
manufacturer
school
property company
creative agency
Good managed IT support should reflect those differences.
Security Is Now Part of the MSP Decision
Choosing an IT provider is also a cyber-security decision.
An MSP may have extensive access to:
Microsoft 365
employee devices
firewalls
servers
backups
cloud infrastructure
That makes the MSP itself part of your security boundary.
The NCSC’s November 2025 guidance for SMEs specifically recommends checking an MSP’s security arrangements, including recognised certifications, MFA/2SV, least-privilege access, backups, incident response and contractual responsibilities.
Its newer 2026 cloud-MSP guidance goes even further: providers should not simply be given permanent root or Global Administrator privileges when those privileges are unnecessary, and customer organisations should be able to identify which individual performed administrative actions.
That means you should ask your IT provider:
How do your engineers access our systems?
Is MFA mandatory?
Do they use named accounts?
Who has Global Administrator access?
Is privileged access restricted?
Those are no longer specialist security questions.
They are basic supplier-management questions.
Your Business Should Not Be Held Hostage by Its Own IT
One of the biggest fears when changing provider is:
“What if the old IT company has all the passwords?”
A healthy IT relationship should not rely on one supplier being the only organisation capable of understanding your environment.
The business should have appropriate visibility over critical assets such as:
Microsoft 365 tenant
domain names
DNS
internet accounts
firewall
backups
administrator access
licences
major cloud services
That does not mean distributing administrator passwords throughout the company.
It means ownership and recovery arrangements should be clear.
The business should know:
what it owns
who controls it
and:
how control can be transferred securely.
Before Switching, Check Your Contract
Do not begin by telling the existing provider you are leaving and hoping everything works itself out.
Read the agreement first.
The NCSC specifically recommends ensuring MSP contracts define areas such as:
responsibilities
response expectations
security incidents
liabilities
third parties
reviews
termination.
Check:
Notice period
How much notice must you give?
Termination provisions
What happens at the end?
Data
Where is your information stored and how is it returned?
Licensing
Which subscriptions belong to you and which are bundled through the provider?
Hardware
Do you own the firewall, switches and backup appliances?
Documentation
What must the provider hand over?
Support during transition
When does their responsibility actually finish?
Never assume.
Read the agreement.
What Should Be Collected During the Handover?
A good handover should account for all important administrative dependencies.
That normally includes areas such as:
Microsoft 365
Confirm:
tenant ownership
Global Administrator access
licensing
domains
security configuration
Domain and DNS
Know:
registrar
DNS provider
renewal ownership
administrative credentials
Losing control of the company domain is considerably more serious than losing a printer password.
Networking
Document:
firewall
switches
access points
VLANs
broadband
VPN
configuration backups
Servers
Record:
roles
applications
storage
virtualisation
administrator access
backup coverage
Endpoints
Understand:
device inventory
RMM/management software
endpoint protection
encryption
local administrator arrangements
Backups
Establish:
what is backed up
where it is stored
retention
access
latest successful job
restore capability
The NCSC explicitly recommends asking MSPs where backups are stored, how often they are made, who can access them and how often recovery is tested.
The New Provider Should Audit Before Changing Everything
The first week with a new provider should not involve ripping out everything the previous company installed.
That creates unnecessary risk.
A better transition is:
discover → document → secure → stabilise → improve.
Start by understanding:
users
devices
licences
Microsoft 365
servers
network
backups
security
suppliers
Then identify issues by priority.
For example:
Immediate
Unknown administrator accounts.
No MFA.
Failed backups.
Unsupported exposed server.
Important
Inconsistent patching.
Poor documentation.
Old network equipment.
Excessive licensing.
Longer term
Cloud migration.
Laptop replacement.
Network redesign.
Automation.
This makes switching controlled rather than disruptive.
Provider Changes Often Reveal Security Problems
A handover is one of the best opportunities to review accumulated technical debt.
Common discoveries include:
former employees still licensed and enabled
excessive Global Administrators
shared administrator accounts
MFA inconsistently configured
local administrator rights everywhere
unsupported software
untested backups
forgotten firewall rules
unused remote-access tools
These may not mean the previous provider was negligent.
Environments change over time.
But the new provider should identify them.
The objective should not be merely:
take over the existing setup.
It should be:
understand it and improve it safely.
Revoke the Previous Provider’s Access Properly
Once responsibility has transferred, the old provider should no longer have unnecessary administrative access.
Review:
Microsoft 365 administrator accounts
delegated administration
RMM agents
remote-access software
VPN accounts
firewall accounts
backup access
cloud accounts
password-vault access
service accounts
The NCSC recommends that supplier access be limited, controlled, monitored and removed when it is no longer required.
Do this methodically.
Do not simply change one administrator password and assume the transition is complete.
Find Out Whether Your MSP Outsources Your Support
This is another excellent current NCSC point.
Some MSPs use:
outsourced helpdesks
third-party NOCs
external SOCs
subcontracted cloud administrators
There is nothing automatically wrong with that.
But the customer should understand who has access to its systems.
The NCSC’s 2026 guidance recommends checking whether the organisation named in your contract is actually administering your cloud services or whether another supplier is involved—and ensuring security obligations extend to those subcontractors.
Ask:
Who can access our environment?
That deserves a clear answer.
Don't Judge the Next Provider on Price Alone
Suppose:
Provider A = £X per month
and:
Provider B = £X + £500
The cheaper provider is not automatically better value.
Compare what is actually included:
helpdesk
monitoring
endpoint security
Microsoft 365 administration
backups
patching
onsite support
security monitoring
strategic reviews
Then compare how much poor IT currently costs in:
employee downtime
repeated issues
management escalation
security exposure
delayed projects
The cheapest monthly invoice can become the most expensive IT arrangement.
Ask the New Provider Difficult Questions
Before signing, ask:
1. What exactly is included?
2. What are your response expectations?
3. How do you prevent recurring faults?
4. What do you proactively monitor?
5. How do your engineers access our environment securely?
6. How are backups monitored and tested?
7. What happens during a cyber incident?
8. Do you outsource any elements of support?
9. What happens when we eventually leave you?
10. Who owns our documentation, licences and configuration?
That last question is especially useful.
A confident provider should not need to trap customers technically to retain them.
Communication Should Be Clear
One of the most frustrating aspects of poor IT support is uncertainty.
During a serious issue, the business should understand:
What happened?
What is affected?
What is being done?
What should staff do?
When will we hear more?
Nobody expects every fault to be resolved instantly.
But:
“We're looking into it.”
repeated indefinitely is not useful incident communication.
A good MSP translates technical problems into information the business can actually act upon.
Your Employees' Opinion Matters
Senior leadership may speak to IT once per month.
Employees may speak to them every week.
Ask staff:
Do you get responses?
Are recurring problems fixed?
Do you understand what engineers tell you?
Do you feel comfortable asking for help?
Do tickets disappear without explanation?
If employees avoid the helpdesk, you have lost something important:
visibility.
Unreported technical problems cannot be managed properly.
Users should not feel that requesting IT support is an inconvenience to the IT company.
The Buff IT Guy Approach: Fix the Cause
There is a simple comparison with training.
If the same movement repeatedly causes trouble, repeatedly masking the symptom is not a long-term solution.
You identify the underlying cause.
IT should operate the same way.
If the same issue returns every month:
don't just close another ticket.
Look at:
logs
monitoring history
configuration
hardware
dependencies
Find out why.
Fix the cause where possible.
Then use monitoring or management to identify it earlier if it ever returns.
Switching IT Provider: A Sensible Transition
A good provider change should broadly look like this:
1. Review the contract and notice period.
2. Choose the replacement provider before ending existing support.
3. Create an asset and access handover plan.
4. Audit Microsoft 365, devices, networks, servers and backups.
5. Securely obtain administrative access and documentation.
6. Deploy the replacement provider’s management/security tooling.
7. Verify backups and recovery.
8. Give employees the new support details.
9. Remove the previous provider’s access after handover.
10. Produce an improvement roadmap.
That is much safer than:
Cancel old provider on Friday → hope new provider works everything out on Monday.
When Is It Probably Time to Move?
I would seriously consider changing provider if several of these are true:
employees constantly chase tickets
the same faults keep returning
security concerns remain unresolved
there is little proactive monitoring
nobody can explain your backups
documentation is poor
communication breaks down during incidents
you have no idea what the IT roadmap is
management has lost confidence
employees have stopped bothering to report issues
One isolated mistake does not necessarily justify replacing a provider.
Every IT company will occasionally get something wrong.
The real warning sign is:
a persistent pattern with no evidence that the provider is improving it.
How Hamilton Group Can Help
Hamilton Group works with businesses that have reached the point where their existing IT relationship no longer works.
Our approach is to:
audit the environment
secure the handover
stabilise what already exists
fix recurring problems
improve security
and:
build a clearer IT roadmap.
We support areas including:
managed IT support
Microsoft 365
endpoint and workstation management
networks and servers
cloud infrastructure
backups
cyber security
strategic IT planning
We aim to make first contact on IT support requests within 15 minutes, but responsive support is only one part of the service. The bigger objective is to take ownership and reduce the number of recurring problems your employees have to report in the first place.
If you are unhappy with your current IT provider, changing does not have to mean disruption.
It should mean finally getting control of the environment.
Visit hgmssp.com or call 0330 043 0069 to talk to Hamilton Group about changing IT provider.