Five questions worth asking your IT provider this week.

Fair questions any good provider answers instantly. The answers tell you whether you have a managed service or a repair shop on speed dial.

26 August 20266 minute readLANTEK Computers

None of these are trick questions. A provider running a real managed service answers all five without checking, because the answers are things they already track. A provider running a repair shop with a monthly invoice attached will need to come back to you, and that delay is itself the answer.

1. What is your current accreditation list, and what tier is each one?

Accreditation is not decoration. Each one represents assessments passed, engineers certified and kept current, and a direct line into vendor engineering when something goes wrong at your premises at eleven at night.

The length of the answer matters less than how quickly it arrives. A provider who has to go and look does not have a live relationship with those vendors. Ask for the tier as well as the name, because there is a real difference between a registered partner and a gold one, and both are accurate descriptions that mean very different things.

2. When did somebody last restore from our backup?

Not when did it last run. When did somebody last restore from it, to a usable state, and open a file afterwards.

A backup job can report success every night for a year while quietly writing files that cannot be read back. Nobody discovers this on an ordinary Tuesday. They discover it on the worst day of the year. A restore should be rehearsed at least quarterly and the result recorded, because the only evidence a backup works is a file somebody has opened after restoring it.

Ask the follow-up too: is one copy immutable? Modern ransomware looks for backups and destroys them before encrypting anything, so a backup an administrator account can delete is a backup an attacker can delete.

3. Who is looking at our systems at eleven on a Saturday night?

Nobody gets breached at two in the afternoon on a Tuesday. Attacks land on a Friday evening, over a long weekend, on Christmas Eve, and not by coincidence. That is when nobody is looking.

A working week is 168 hours. A business open nine to six, Monday to Friday, is watched for 45 of them. The other 123 are the window. Ask what happens in that window, and specifically whether an alert is acted on or queued for Monday. Those are different services at similar prices.

4. Are we charged per device or per user, and what is inside the pool?

Charging per device penalises a business for giving somebody a laptop and a phone. Charging per user reflects what is actually being supported, which is a person.

The more useful half of the question is what the fee covers. Proactive work, meaning monitoring, patching and automated remediation, should never be billed against a reactive pool, because the moment it is, the provider's incentive is to attend problems rather than prevent them. Ask where the line sits and get it in writing.

5. If a regulator asked tomorrow, what would you hand them?

Section 19 of POPIA requires appropriate technical and organisational measures to secure personal information, and the maximum administrative fine is R10 million. The question a regulator asks after an incident is not whether you meant well. It is what was in place beforehand, and what evidence exists that it was.

That evidence is a set of documents: security and acceptable use policies, an asset register, a risk register with review dates, data processing agreements with every vendor that touches your data, and an incident response plan somebody has actually tested. If your provider cannot say where those live, they do not exist.

What the answers tell you

A provider who answers all five immediately is running a managed service. One who answers two and promises to check on the others is running support with a subscription attached. Both are legitimate businesses. Only one of them is what most people think they are buying.

If you would rather see the answers for your own environment than ask for them, the free health check starts with a dark web scan and thirty minutes of plain language. You keep the report either way.

A free dark web scan
and thirty minutes.

We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.

Worried about what it takes to move?

Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.