Managed IT

How to manage several IT providers in an SME

Managed IT, telephony, business software, website: how to coordinate several IT providers without an internal IT manager, without conflicts or grey areas.

David Cunha

David Cunha

Published on May 20, 2026 8 min read
MANAGED IT

Managing several IT providers in an SME takes three things: a written map of who is responsible for what, a main provider that carries overall responsibility for the infrastructure, and a regular review of access and contracts. Without these three elements, every incident becomes a blame game, and nobody has the full picture of your information system. Here is how to structure that governance, even without an internal IT person.

Why SMEs end up with several providers

Few SMEs deliberately chose to have five IT providers. The situation builds up by accumulation: the business software vendor dates from the company's creation, the phone installer arrived with the office move, the web agency runs the site, a freelancer has looked after the workstations "forever", and a reseller sold the server with its maintenance contract.

Each one may be competent in its own field. The problem is not competence, it is the lack of an overall view: nobody knows the complete infrastructure, nobody checks that the backups cover everything, and nobody feels responsible when a problem sits at the border between two scopes.

3–5 providers
on average in a Swiss SME of 10 to 50 people
1 owner
of overall operations: the golden rule of governance
1×/year min.
review of every provider’s access and contract

The three risks of unmanaged multi-provider IT

Responsibility ping-pong

The business software is slow. The software vendor blames the network, the IT person blames the server, the server reseller blames the software. Meanwhile, your teams wait. Without written scopes and a designated arbiter, this scenario repeats at every cross-domain incident — and cross-domain incidents are precisely the ones that last longest.

Coverage gaps

Each provider assumes someone else handles whatever is not in its contract. Typical result: nobody backs up the accounting workstation, nobody updates the firewall installed five years ago, nobody deactivates the accounts of departed employees. These gaps are invisible day to day; they are discovered on the day of the incident.

Access sprawl

Every provider accumulates access: VPN, administrator accounts, passwords shared by email. Over the years, nobody knows anymore who can get into what. That is a major security risk — our SME cybersecurity guide ranks unmanaged access among the top intrusion vectors — and a data protection problem, since these providers are your processors within the meaning of the Swiss Data Protection Act.

The governance method in four practices

1. Map: who is responsible for what

Draw up a simple document listing each domain (workstations, server, network, email, business software, telephony, website, backups) with, for each: the responsible provider, the covering contract, the contact, and the agreed response time. One page is enough. This document is the basis for everything else — and merely writing it usually reveals two or three coverage gaps.

2. Appoint a main provider

One provider must carry responsibility for the overall infrastructure: it monitors, detects problems, coordinates the other providers during cross-domain incidents and advises you on trade-offs. That is exactly the role of a managed IT contract such as AlpenCare: your specialised providers stay in place, but a single contact answers for the whole. Our article on managed IT services details what that role covers.

3. Control access

Named accounts for every provider, least privilege, mandatory MFA, a password vault instead of emails, and an annual review of all external access. At the end of a contract, revoking access is part of the exit procedure, just like handing back documentation.

4. Institutionalise the annual review

Once a year, review each contract: does the scope still match reality? Are response times being met? Is the price aligned with the market? This review is the right moment to renegotiate or consolidate. To evaluate a managed IT contract specifically, our contract comparison guide provides the full checklist.

Consolidate or coordinate?

Should you reduce the number of providers? Not necessarily. The business software vendor and the web agency are often irreplaceable in their specialty. On the other hand, day-to-day operations — workstations, server, network, email, backups, security — almost always benefit from consolidation with a single provider: fewer interfaces, fewer grey areas, one SLA.

The right model for most SMEs: one main provider responsible for operations and coordination, plus the business specialists staying within their scope. If you are starting from scratch in choosing that main provider, our guide on how to choose your IT provider lists the criteria that matter.

Frequently asked questions

How many IT providers should an SME have?

As few as possible, and ideally a single one responsible for day-to-day operations. An SME of 10 to 50 people often works with 3 to 5 providers (managed IT, telephony, business software, website, printers): that is manageable as long as one of them carries overall responsibility for the infrastructure and coordinates the others.

Who should coordinate IT providers when there is no internal IT manager?

Either a member of management takes on the role with dedicated time, or you delegate it contractually to your main managed IT provider. The second option is usually more effective: the main provider speaks the same technical language as the other providers and can arbitrate questions of responsibility.

How do you prevent providers from passing the blame for an incident?

By documenting in writing who is responsible for what: an up-to-date infrastructure diagram, a responsibility matrix per domain (network, workstations, server, business software, telephony) and a single point of contact for your employees. Without that documentation, every incident at the border between two scopes becomes ping-pong.

Should all providers get administrator access?

No. Each provider should only receive the access needed for its scope (least privilege), with named, non-shared accounts. Access must be inventoried, reviewed at least once a year and revoked immediately at the end of a contract. Former providers' accounts left active are a classic entry point for attackers.

What if two providers give contradictory recommendations?

It happens often, and it is the symptom of a missing technical arbiter. Appoint a referee (main provider or independent adviser) who decides based on your interest, not the vendor's. An independent infrastructure audit also objectifies the debate with a factual assessment.

David Cunha

Written by

David Cunha

Co-founder · Technical director, AlpenData

A computer engineer with over 10 years of experience managing systems, networks and infrastructure, David helps Swiss SMEs with their IT, security and compliance.

More about AlpenData →

First IT recommendations

Want to know where your SME is exposed?

Request a 30-minute conversation with an AlpenData engineer. You walk away with first recommendations on your security, your backups and your IT priorities, with no commitment.