Hiring a managed IT provider is not the finish line. The first two months set the pattern for the whole relationship. A disciplined onboarding finds hidden risks, documents your environment and builds trust with your staff. A sloppy one leaves you with the same problems under a new logo.
This guide describes what a well-run onboarding should include, so you can hold your provider to a standard and know what to expect.
Before day one: agree on the plan
A good provider will walk you through the schedule before work starts. Expect to agree on:
- A named onboarding lead on both sides
- Priorities, such as security gaps, field connectivity or specific pain points
- A transition plan with the outgoing provider, including how credentials and documentation will be handed over
- Communication norms, such as who gets updates and how often
- The scope of service, response times and what is billed separately
Days 1 to 15: discovery and stabilization
Take inventory
The provider should document devices, servers, network equipment, cloud services, software licenses, user accounts and vendors. For contractors, this should include jobsite routers, trailers, rugged tablets, project software and any systems that hold sensitive contract data.
Secure administrative access
Make sure you hold the keys. That means company-owned administrator accounts for Microsoft 365, domain registrations, firewall and router consoles, backup systems and software portals. Rotate credentials that the previous provider knew, and remove their access once the transition completes.
Install monitoring and management tools
Endpoint management, patching and monitoring should begin early so the provider can see the environment and respond to problems.
Address urgent risks
Expect a short list of high-priority fixes: missing MFA, unsupported systems, dead backups, exposed remote access. Ask for the list in plain language, ranked by risk, with proposed timelines.
Days 16 to 30: baseline and documentation
Assess security posture
The provider should evaluate settings and gaps against a recognized framework such as the NIST Cybersecurity Framework, or against specific requirements you face, such as CMMC. The result should be a written baseline with findings and recommendations.
Verify backups
Confirm what is backed up, where copies live and that a restore actually works. Request evidence of a test.
Document the environment
Network diagrams, system lists, standard configurations and runbooks should be written down and stored where you can access them. Documentation is your protection against dependence on one vendor or one technician.
Meet your people
Good onboarding includes introducing the help desk to your staff, explaining how to request support and setting expectations for response times. Field crews should know exactly who to call and how.
Days 31 to 45: standardize and improve
- Roll out consistent device configurations and update policies
- Strengthen email security and enforce MFA where it is missing
- Tidy user accounts, permissions and shared mailboxes
- Review software licensing to cut waste and close gaps
- Plan upgrades for old equipment, with costs and timelines
Days 46 to 60: review and roadmap
Deliver a roadmap
Expect a prioritized plan covering the next twelve months, with budget estimates and the business reason for each item. A roadmap lets you plan spending instead of reacting to emergencies.
Review service performance
Look at early data: ticket volume, response and resolution times, recurring problems. Discuss what is working and what is not.
Schedule recurring reviews
Set a regular cadence, quarterly at minimum, to review performance, risks and projects with your provider's leadership, not only the technicians.
What to ask for at the 60-day mark
- A current asset and account inventory
- A written security baseline with a remediation plan
- Evidence of a successful backup restore test
- Documentation of key systems and processes
- A roadmap and budget outline
- Service performance reporting
Red flags during onboarding
- No clear plan or schedule
- Reluctance to give you administrator access or documentation
- Reports full of jargon with no priorities
- Slow response to your early requests
- Pressure to buy products before assessing needs
A hypothetical example
Consider a hypothetical energy services company that changes providers. In week two, the new provider finds that a former technician still has global administrator rights, that backups have not completed in months and that two field routers use default passwords. Because onboarding included discovery and a ranked fix list, those issues are closed by day 30 instead of discovered during an incident.
What to do on your side
Assign a point person, make staff available for questions, and share vendor contracts and prior documentation. The more openly you share, the faster the provider can help.
Working with Ironfield Cyber
Ironfield Cyber uses a structured onboarding built for contractors and energy companies, covering inventory, security baseline, field connectivity and a clear roadmap. If you are considering a change in providers, we are happy to explain how we would approach your first 60 days.