Most managed IT providers send monthly reports. Many of them are thick with charts, such as tickets opened, tickets closed and a pie chart of categories, but light on meaning. As an owner or operations leader, you do not need dozens of numbers. You need a few that answer a simple question: is IT helping our people work, and is it keeping us safe?
Here are the metrics worth watching, how to read them and what they might be hiding.
Response and resolution
Time to first response
How long until a person acknowledges a request? Fast responses reassure users, particularly field crews who may be waiting on a blocked device. Ask for the measure by priority level, since a quick reply to a minor request does not offset a slow answer on an outage.
Time to resolution
How long until the problem is fixed? Look at the typical value and also the slow tail. A few tickets that take weeks to close matter more than the average suggests.
Priority definitions
Understand how your provider classifies urgency. An outage affecting a jobsite should not sit in the same queue as a request for a new mouse. Make sure the definitions match your business, and that your agreement specifies targets for each level.
Quality of support
First-contact resolution
What share of issues are solved on the first interaction? A higher rate usually means skilled staff and good documentation. A low rate can mean frequent handoffs and frustration.
Reopened tickets
If tickets are frequently reopened, the fix may not have worked, or the ticket was closed too early. Watch for a pattern.
User satisfaction
Short surveys after ticket closure are useful when you read the comments, not just the score. Field and office staff often have different experiences, so look at both.
Patterns and trends
Recurring problems
Repeated tickets about the same issue point to a root cause that should be fixed. Ask your provider to identify the top recurring issues each quarter and describe what is being done about them.
Ticket volume trends
A rising volume might signal a new problem, a rollout or growing pains. A falling volume might mean improvement, or that people have stopped asking because they are frustrated. Check with users before assuming.
Tickets by location or team
Breaking out tickets by jobsite, department or device type can expose weak spots, such as a trailer with unreliable connectivity or an aging group of laptops.
Security and maintenance metrics
Support is not only break-fix. Ask for a few indicators of preventive health:
- Patch compliance: the share of devices that are current on updates, and how long critical patches take to deploy.
- Endpoint coverage: devices with active protection and management compared to total devices.
- MFA coverage: the share of accounts protected by multi-factor authentication.
- Backup success and restore tests: the rate of successful backups and the date of the last tested restore.
- Open security findings: known risks with owners and due dates.
- Onboarding and offboarding time: how quickly accounts are created and removed.
What to ask for in a report
- A one-page summary in plain language, with trends over several months
- Performance against the response targets in your agreement
- The top recurring issues and the plan to fix them
- Security health indicators
- Upcoming projects and risks needing your decision
Beware of vanity metrics
- Tickets closed: may reward closing quickly rather than fixing properly
- Uptime claims without definitions: ask what is measured and what is excluded
- Averages: can hide long delays; ask for percentiles or the longest cases
- Metrics without context: a number means little without targets and history
Compare reports to reality
Numbers are only part of the picture. Talk to supervisors, field crews and office staff. Ask what frustrates them, and what improved. If the report says everything is fine and staff say otherwise, trust the people and investigate.
A hypothetical example
Consider a hypothetical contractor whose monthly report shows a fast average resolution time. A closer look reveals that routine requests close within hours, while jobsite connectivity problems often take days and are counted in a different category. The owner asks for a breakout by priority and location, and finds the real problem hidden in the averages.
Hold regular reviews
Meet your provider at least quarterly to go through the data, discuss trends and set improvement goals. A good provider welcomes the scrutiny.
Working together
Ironfield Cyber reports on the measures that matter to contractors and energy companies, in plain English, and reviews them with our clients regularly. If you want to know whether your current support is delivering, we can help you build a scorecard and interpret your existing reports.