Better managing your IT provider requires no technical skill: it requires a routine. Reading the monthly report, holding a structured quarterly review, checking two or three factual indicators (response times, state of backups) and arbitrating recommendations knowingly. One hour a month is enough — and that hour changes everything, because a steered provider works better than a provider left to itself. Here is the method.
Why a good provider, poorly managed, delivers poor results
A managed IT relationship erodes by default. Without a contact person on the client side, recommendations pile up unanswered, reports are no longer read (then no longer sent), urgent decisions wait for months, and the provider drifts towards minimum service — not out of malice, but because nothing and nobody maintains the standard. This mechanism is one of the failure causes we detail in why managed IT fails in SMEs.
Steering reverses the dynamic: a client who reads the reports, asks questions and decides quickly mechanically obtains more attention and quality. It is the best-yield investment of the whole relationship.
The monthly ritual: actually read the report
The monthly report is your dashboard. Three things to check in ten minutes: do the actual response times meet the contract SLA? Are the backups green, with documented restoration tests? Do the same incidents come back month after month — the sign of a problem treated at the surface? Note your questions and send them: a provider that knows its reports are read takes care of them.
The quarterly ritual: the steering meeting
Four times a year, one hour, with a fixed agenda: review of the quarter's incidents and SLAs, state of security and backups, review of pending recommendations (accept, schedule or decline — but decide), and upcoming projects and changes on the company side (office move, hiring, new software). The last point is crucial: your provider can only anticipate what it knows about.
Arbitrating recommendations without being a technician
For each investment recommendation, three questions suffice: what risk does it cover? What does inaction cost if the risk materialises? How urgent is it really — this year or this month? The answers let you prioritise without expertise: replacing an end-of-life firewall covers a documented intrusion risk; the bigger screen can wait. Declining a recommendation is legitimate — ignoring it without a decision is not, because you carry the risk, as our cybersecurity guide reminds.
Maintaining the contractual fundamentals
Once a year, check that the contract still matches reality: does the scope cover the new workstations and services? Is the provider's access still justified and named? Is your infrastructure documentation up to date and in your possession — not just in the technician's head? These checks overlap with the grid of our managed IT contract guide; they also prepare a drama-free exit if it ever comes to that. And if you juggle several providers, our article on multi-provider governance completes the method.
What a good provider expects from you
The relationship works both ways: a designated contact who responds quickly, clear decisions (even negative ones), advance notice of changes, and respect for the agreed procedures (going through the helpdesk rather than calling "the nice technician" directly). At AlpenData, this steering framework — a readable monthly report, measured response times, regular reviews — is part of the standard operation of AlpenCare: we prefer demanding clients who read our reports.
Frequently asked questions
How often should you review progress with your IT provider?
A quarterly steering meeting is enough for most SMEs: review of the quarter's incidents, state of backups and security, pending recommendations and upcoming projects. Add a broader annual review of the contract, prices and strategy. In between, the monthly report is the guiding thread.
What should an IT provider's monthly report contain?
At minimum: the tickets handled with actual response times compared to the SLA, the state of backups and restoration tests, the updates applied, the security incidents blocked, and recommendations. A report readable by a non-IT person in ten minutes — if you need a dictionary to read it, ask for another format.
How do you verify the SLA is met without technical expertise?
The SLA is verified in the monthly report: actual response times per criticality level, compared with the contract commitments. Cross-check with your teams' perception — an internal three-question annual survey is enough. If the provider does not publish its SLA figures, that is an answer in itself.
Should you follow your provider's investment recommendations?
Not blindly, but do not ignore them systematically: obsolete hardware and end-of-life systems are the leading causes of incidents. For each recommendation, ask what risk it covers, what inaction would cost and how urgent it really is. A good provider prioritises its recommendations and accepts that some can wait — a salesperson pushes everything, immediately.
What should you do when the relationship with the provider deteriorates?
First objectify: recurring incidents, missed SLAs and absent reports are measurable facts. Then have a frank discussion based on those facts, with a recovery deadline (one quarter). If nothing changes, prepare a clean exit: reversibility clause, successor chosen before termination, coordinated transition.
Written by
David Cunha
Co-founder · Technical director, AlpenData
A computer engineer with over 10 years of experience managing systems, networks and infrastructure, David helps Swiss SMEs with their IT, security and compliance.
More about AlpenData →