The Questions the
Brochures Skip.
Written for business owners evaluating managed IT providers — including us. These are the questions that separate a provider you'll keep for a decade from one you'll spend a year escaping, and we answer every one of them about Sidestreet at the end.
If a question on this list makes a provider uncomfortable, that reaction is your answer.
Why Every MSP Brochure Sounds the Same
Read five managed IT websites in a row and you'll notice something: they're the same website. Proactive monitoring, peace of mind, fast response times, a photo of someone smiling at a server rack. The service lists are nearly identical because the underlying tools mostly are — the difference between a great MSP and a frustrating one lives in the details no brochure advertises.
Those details come out when you ask specific questions and listen to how the answers land. A confident provider answers directly. An evasive one changes the subject, and that evasion is data.
These are the questions we'd want you to ask us — and every other provider you're evaluating. We answer them about ourselves at the end, because a guide like this is worthless if the author won't take its own test.
Questions About Who Actually Supports You
"When my office manager calls with a problem, who picks up?" This is the single most predictive question. Many providers route everything through a tier-one desk that reads from scripts and escalates anything hard, which means your team retells the same problem three times to three people. Ask about the experience level of the first responder, and ask how many accounts each technician covers. Support quality is mostly a staffing model, and staffing models don't lie.
"How do you track issues, and can we see the queue?" Every serious provider runs on tickets — that's how nothing falls through the cracks and how you get a paper trail of what broke and how it was fixed. The question is transparency: can you see your open tickets, their status, and the history? A provider who tracks everything but shows you nothing is asking for trust they haven't earned yet.
"How does support work if we're not local to you?" Most day-to-day support is remote now, and speed matters more than address. But get specific about the exceptions: what happens when hardware fails, who coordinates on-site hands, and what's covered. A provider should be able to explain exactly how they support a client two time zones away — and exactly what changes when they can put a person in your building.
"Will the same people stay on our account?" Familiarity is half the value of managed IT. A technician who knows your environment solves problems in minutes that would take a stranger an hour of orientation. Ask about turnover, account assignment, and documentation practices — because when people do change, the documentation is what keeps you from starting over.
Questions About Security and Backups
"What specifically is in your security stack?" "Advanced cybersecurity" is a phrase, not an answer. Ask for the list: endpoint protection, email filtering, multi-factor authentication enforcement, patch management, monitoring coverage and hours, security awareness training. Then ask which of those are included in the monthly fee and which cost extra — this is where thin quotes hide.
"When did you last actually restore a backup for a client?" Everyone backs up. Almost nobody tests. A backup that has never been restored is a hope, not a plan, and the difference only becomes visible on the worst day of your business year. A good provider has a recent, specific answer and a testing schedule. A great one brings it up before you ask.
"What happens at 9pm on a Saturday?" Get the honest shape of after-hours coverage: what's monitored around the clock, what triggers a human response, what's billed differently. Automated monitoring genuinely does watch all night — the question is what happens when it finds something. There are legitimate answers at different price points; what you're screening for is a provider who's vague about it.
"Can you support our compliance requirements?" If you're in healthcare, legal, financial services, or government, your provider inherits your rules. Ask how they support frameworks like HIPAA or CJIS, whether they'll sign a Business Associate Agreement where protected health information is involved, and how they document what auditors will eventually ask about. A provider who hasn't heard these acronyms before shouldn't be learning on your account.
Questions About the Contract and the Exit
"What exactly does the monthly fee cover, and what triggers a separate invoice?" The flat fee is only flat if the boundaries are clear. Projects, hardware, after-hours emergencies, new-employee setups, software licenses — every provider draws these lines differently, and the drawing matters more than the headline number. Get the boundaries in writing before you compare prices.
"What does onboarding look like, and what does it cost?" The first sixty days set the tone: environment audit, documentation, monitoring deployment, security baseline. Some providers charge an onboarding fee, some fold it in — either is fine, but surprise is not. Ask for the onboarding plan as a document, not a promise.
"What's the term, and what does leaving look like?" A confident provider doesn't need a three-year trap with a painful exit clause, because they plan to keep you by being good. And ask the uncomfortable one: if we leave, what do we get? Documentation, credentials, configurations, and license ownership belong to you. A provider who gets cagey about offboarding is telling you exactly how the relationship ends.
Red Flags We See in the Managed IT Market
Fear as a sales strategy. Cybersecurity risk is real, but a pitch built entirely on breach statistics and worst-case scenarios is manipulating you toward a signature, not informing a decision. Good providers explain risk in proportion and tell you which defenses matter most for a business your size.
Prices that seem too good. Managed IT has real costs — tooling, licensing, senior labor. A quote dramatically below market usually means a thin security stack, junior-only support, or a fee structure designed to make it back in project invoices. Cheap managed IT is the most expensive kind; you just pay for it later, in downtime.
A hardware quota in disguise. Some providers make real margin reselling equipment, which quietly biases every recommendation toward buying something. Ask how they make money on hardware. The right answer includes the sentence "sometimes the answer is don't buy anything."
Vague response promises. "Fast response" means nothing without definitions: response to what, measured how, covered when. Providers serious about service levels write them down with specifics. Providers who aren't, adjective.
No curiosity about your business. An MSP that quotes you without asking what your business does, what downtime costs you, and what you're worried about is selling a package, not a service. The technology only matters in proportion to what it protects.
How Sidestreet Answers These Questions
Taking our own test, directly:
Who picks up? A senior technician — that's the staffing model, not a marketing line. Every issue is logged as a ticket so nothing falls through the cracks and you have the full history, and the same people stay on your account long enough to actually know it.
How do we support non-local clients? Remote-first, nationwide — that's how most of our support works for everyone. In-person service is available across Spartanburg, Greenville, and the Upstate of South Carolina when hands need to touch hardware, and for clients elsewhere we design the environment so hands-on needs are rare and coordinated when they happen.
What's in the fee? A flat monthly agreement scoped to your users, devices, and complexity, with the boundaries in writing: what's covered, what's a project, and what response expectations we're committing to. Project work is quoted separately and approved before it starts. Our managed IT services page covers the full scope, and our cost guide explains the pricing math most providers keep behind the quote form.
Backups and security? Tested backups on a schedule, layered security included in the base agreement rather than sold as fear-priced add-ons, and AI-assisted monitoring watching around the clock with senior engineers judging what it finds. For regulated clients, we support compliance obligations under frameworks like HIPAA and CJIS, and we execute a Business Associate Agreement before any access where protected health information is involved.
The exit? Your documentation, credentials, configurations, and licenses are yours — during the engagement and after it. We'd rather keep clients by being good than by being hard to leave.