Seven questions to ask a managed IT provider in Australia

Seven that turn specifically on Australian obligations and on who is awake at 2am. Ask them verbally, and pay as much attention to how fast the answer arrives as to what it contains.

There is a longer list on this site already — twelve questions to ask an MSP before you sign — which covers the general vetting of any provider anywhere. These seven are narrower and more local. They are the ones where the answer depends on Australian law, Australian staffing and Australian time zones, and where an offshore-delivered or product-led provider tends to come apart.

We are one of the managed IT service providers you could be asking. Our answers to all seven are at the foot of this page, which is more than most providers will give you before a second meeting — and it is a fair test of the rest.

1. Who answers at 2am, where are they, and what are they allowed to do?

Three parts, and providers frequently answer the first and skip the other two. 24/7 IT support covers everything from a rostered onshore team to a single engineer with call diversion, and the two cost very different amounts to run.

The third part is the one that matters most and gets asked least: is the person who answers authorised to isolate a machine or disable an account without waking somebody up first? In an incident the delay is almost never technical. It is somebody waiting for permission.

A real answer sounds like: “Rostered, in Australia, two engineers overnight. They can isolate an endpoint and disable an account under a standing authorisation you sign at onboarding, and they call you afterwards.”

2. Where does our data sit, and which of your staff can reach it?

Two separate questions bundled together on purpose, because the second is the one people have not thought about.

Data location is straightforward: which regions your tenant, backups and monitoring data are held in. Ask about backups specifically — they are frequently in a different place from production, and the provider may not have chosen it deliberately.

Provider access is the harder one. Ask how many of their people can reach your environment, whether that access is standing or requested, whether it is individually named or a shared account, and what happens to it when one of their engineers leaves. A provider's own privileged access is a real part of your attack surface and it is almost never in the proposal.

A real answer sounds like: a number, a named region, and a description of time-bound elevation. “Only our senior engineers” is not a number.

3. What is your position on the Essential Eight, now that it is changing?

In June 2026 ASD announced that the Essential Eight will be retired and replaced by a broader body of guidance called the Essentials, beginning with a chapter for enterprise IT. The underlying controls carry over; the maturity model may not survive in its current form. We covered the detail in The Essential Eight is becoming the Essentials.

The question is a test of two things. Whether they follow the guidance they claim to specialise in, and whether they can hold a nuanced position — “keep going, here is what we would not commit to in writing right now” — rather than either panicking or not knowing.

Follow it with: can you show us an Essential Eight assessment you have produced for a client, redacted? A provider doing this work has one.

4. If we have a notifiable breach, what exactly do you do — and what stays ours?

The correct answer includes a limit. A provider should investigate, establish what was accessed, produce the timeline and help draft the material. A provider should not be offering to own the notification decision, because it is not theirs to make and they cannot carry the consequence.

Listen for whether they know which clocks apply to you. Notifiable Data Breaches assessment under the Privacy Act. Contractual notice periods to clients. And, if your turnover is over $3 million, the 72-hour ransomware payment report to ASD, which has been law since May 2025 and actively enforced since January 2026 — including where the payment is made on your behalf by an insurer or an incident response firm. We have set out who that catches.

A provider who has never mentioned any of this to a client has not been in the room for one.

5. Show us a real restore test result and a real monthly report

Two artefacts, both redacted, both from an actual client.

The restore test tells you whether recovery is measured or aspirational. Ask for the date, the system, and the elapsed time. If what comes back is a recovery time objective rather than a measured result, it has never been tested — and backup success reports are not restore tests.

The monthly report tells you what they measure, whether anything is ever red, and who the document is written for. A report where everything has been green for six months is not a report; it is reassurance with a chart on it.

6. What is explicitly excluded, and what is your margin on hardware and licences?

Every managed service has boundaries. Ask for them verbally, then check they match the schedule in the agreement — the two are not always the same document's worth of honesty. A provider describing their service as fully inclusive without naming exclusions has exclusions you will meet on an invoice.

The margin question is not about the number. Everyone has one and it is entirely legitimate. It is a transparency test, and the speed of the answer is the result. A provider who states a percentage without hesitating is telling you something useful about how the rest of the relationship will go.

7. What does it cost to leave, and whose name are the tenants in?

Read the exit terms before the technical sections. Notice period, exit assistance rate, and exactly what is handed over: documentation, tenant administrative access, asset register, credentials.

Then ask the yes-or-no question. Are our Microsoft, security and backup licences held in our own tenant and our own name? Some providers resell seats from their own agreement, which makes leaving considerably harder and occasionally makes it difficult to take your data with you in a usable form. The answer should be immediate.

If exit assistance is not priced in the agreement, it will be priced at your least convenient moment.

One more question, depending on what you do

The seven above apply to any buyer of Australian SMB IT support. Add one.

Healthcare and allied health
“How do you coordinate patching with our practice software vendor, and what is the agreed window?” Clinical systems cannot be offline mid-session and the vendor usually controls the update. Genuine healthcare IT services are distinguished by that relationship, not by endpoint counts. Follow up by asking whether they have a written breach assessment procedure for a practice — health records are sensitive information under the Privacy Act.
Startups and scale-ups
“What happens to pricing and licensing if we double headcount in six months, and what do you hand over if we bring IT in-house?” The answer separates IT services for startups from a small-business contract with a growth clause attached.
Mid-sized businesses with internal IT
“Where exactly is the boundary between your team and ours, function by function?” Co-sourcing works when the split is written down and fails when it is assumed. Ask for it as a table, not a paragraph — it is the core of any workable mid-sized business IT solution.

How to run the meeting

Three practical notes.

  • Ask verbally, not in writing. A written response is a marketing document with a deadline. A verbal answer has a pause in it, and the pause is data.
  • Have the person who will run the account in the room. The senior people in a sales meeting are frequently not the ones who will do the work. That is normal, and you should know it before you sign.
  • Take notes on the follow-through. Every provider will promise to send two or three artefacts. Whether they arrive, and how quickly, is the most reliable predictor in the entire process.

Questions

Is seven questions enough?

For a first meeting, yes — you are filtering, not auditing. Once you have a shortlist of two, work through the longer twelve-question list and the comparison process in how to choose managed IT services in Australia.

What if we do not have anyone technical to assess the answers?

You do not need to. Six of the seven are answered with a number, a name, a document or a yes. What you are assessing is specificity and speed, and a business manager or a finance director is perfectly well equipped to judge both.

Where you do want independent help, get an assessment from somebody who is not bidding for the contract.

Should we ask our current provider these?

Yes, and it is often more useful than asking a prospect. You will get honest answers from a relationship that already exists, and you will find out whether the gaps you suspected are real before you go to market.

Occasionally it fixes the problem without a tender, which is a cheaper outcome for everyone.

Does it matter if a provider only has offshore engineers overnight?

It is a trade rather than a disqualifier. Follow-the-sun coverage is a legitimate model and often produces faster overnight response than an on-call roster.

What should be explicit is where those people are, what data they can access, what law governs that access, and whether they can act or only triage. The problem is never the model. It is the model being implied rather than stated.

Why Next Cyber

We answer all seven in the first meeting

Most providers need a second meeting to come back on margin, provider access and exit costs. Answering them on the spot is what separates a partner from a reseller.

  • Onshore, rostered, authorised. Australian owned and Australian staffed, with security cleared personnel where an engagement needs them.
  • Data held onshore. Named regions for tenant, backups and monitoring — and a number for how many of our people can reach you.
  • Essential Eight, current. We track the ASD transition to the Essentials, and will show you a redacted client assessment.
  • Breach support, with a limit. We investigate, build the timeline and draft the material. The notification decision stays yours.
  • Evidence, the same week. A real restore test result and a real monthly report, including the months that were red.
  • Named exclusions. In the agreement before you sign, not on an invoice in month four.
  • Exit priced upfront. Notice, handover and assistance rate agreed at the start, while everyone is still friendly.

Ask us all seven

Including the ones about margin, provider access and exit costs. We will answer them in the first meeting and send the artefacts the same week. Bring the list.