Many owners receive a monthly report from their IT provider and have no idea whether it is good news. Charts of tickets closed and uptime percentages look impressive, but they do not tell you whether your crews are productive, your data is protected, or your money is well spent.
Useful measurement focuses on a small number of metrics that reflect real outcomes. This guide describes what to ask for, how to read it, and what to be skeptical about.
Service responsiveness
Time to first response and time to resolution
Ask for both. A quick acknowledgment means little if problems linger for days. Look at averages and also at the slow tail, since a handful of long-running tickets often explain staff frustration. Compare results against the targets in your agreement, and ask for breakdowns by priority.
Repeat issues
If the same problem keeps appearing, such as a jobsite router that drops weekly or a laptop that keeps failing, the provider should be fixing root causes. A good report highlights recurring issues and shows plans to eliminate them.
User satisfaction
Short surveys after ticket closure give a view that numbers alone cannot. Read the comments, especially from field staff. Watch for patterns, such as complaints from one site or one department.
Security health
Security results should be reported in plain terms, not just tool counts. Ask for:
- Multifactor authentication coverage: the percentage of users and admin accounts protected, with a goal of all.
- Patch status: how many devices are current on critical security updates, how many are behind, and for how long.
- Endpoint protection coverage: devices protected and any that are unprotected or not reporting.
- Backup success and restore tests: recent results and the date of the last test restore.
- Phishing and training results: participation rates and how many people report suspicious email.
- Account hygiene: stale accounts, accounts for departed staff, and unused administrator rights.
- Open critical findings: the number of unresolved high-risk items and how long they have been open.
Trends matter more than a single snapshot. Is the risk list shrinking?
Business value
Downtime and impact
Ask about incidents that affected work, how long they lasted, and what was done to prevent a repeat. Ask crews and project managers for their view as well. A report showing 99 percent uptime can hide the one afternoon your estimators could not work.
Project and roadmap progress
IT should not be only reactive. Review progress on planned improvements: device refreshes, security upgrades, site network projects. Are they on schedule and on budget?
Costs
Review spending against the budget, including licenses, hardware, and additional project work. Check for unused licenses and unexplained add-ons.
Questions for quarterly reviews
- What were the biggest risks you found this quarter, and what did you do about them?
- Which items are overdue, and why?
- What changed in our environment that affects risk?
- What should we budget for in the next 12 months?
- What is the one thing you would fix first if you had more time or money?
A provider that welcomes these questions is likely a good partner. One that avoids them deserves scrutiny.
Be wary of vanity metrics
- Large numbers of tickets closed, which may reflect poor underlying stability.
- Uptime figures for a single service that ignore everything else.
- Counts of blocked threats with no context.
- Reports that never change from month to month.
- Scorecards that measure only the provider's own activity, not your outcomes.
Keep your own view
Do not rely only on the provider's reporting. Occasionally check a few things yourself or through an independent party: confirm that an ex-employee's account was disabled, ask for a restore of a random file, or review administrator accounts in your own tenant. Verification builds confidence and keeps everyone honest.
Set expectations in writing
Metrics are easier to track if they appear in the service agreement or a service review charter. Define what will be reported, how often, and what happens when targets are missed.
Where Ironfield Cyber fits
Ironfield Cyber provides plain-language reporting built around outcomes for contractors and energy companies, with a quarterly review focused on risk and budget. If you want a second opinion on the reports you receive today, we are happy to take a look.