Many companies sign with a managed IT provider and then rarely talk about strategy. Tickets get closed, invoices get paid, and the relationship stays transactional until something breaks. A regular quarterly business review changes that. It is a scheduled conversation between your leadership and the provider about how technology supports the business, where risks are rising, and what to do next.
For a contractor or energy company with growing projects, shifting crews, and increasing customer security demands, an hour each quarter is a good investment. Here is a practical agenda and some tips for making the meeting worthwhile.
Who Should Attend
- An owner, president, or CFO who can make decisions
- The operations or project leader who understands field needs
- The person who manages IT day to day
- The provider's account manager and a technical lead
Include someone from the field periodically so the conversation stays grounded.
Suggested Agenda
1. Business update (10 minutes)
Start with your side. Share upcoming projects, new offices or sites, hiring plans, acquisitions, and any customer or contract requirements involving security. The provider cannot plan for changes they do not know about.
2. Service performance (10 minutes)
Review the simple measures that matter: response and resolution times by priority, repeat issues, and user feedback. Ask the provider to explain trends, not just present numbers. Discuss any incidents from the quarter and what was learned.
3. Security posture (15 minutes)
Look at the basics and their trends:
- Patch and update status
- Multi-factor authentication coverage
- Backup results and the date of the last restore test
- Endpoint protection health
- Email threats blocked and reported by staff
- Any security incidents or near misses
- Outstanding recommendations from earlier reviews
Ask which risks have changed since last quarter and what the provider recommends. Agree on priorities and owners.
4. Projects and roadmap (10 minutes)
Review work in progress and planned projects such as hardware replacements, software upgrades, site network builds, or migration to cloud services. Confirm timelines, budgets, and dependencies. Make sure the roadmap lines up with the business calendar, avoiding busy bid periods or payroll deadlines.
5. Budget and licensing (5 minutes)
Check for unused licenses, upcoming renewals, and expected hardware costs. Ask whether any services could be consolidated or are no longer needed. Look at spending against the plan.
6. Compliance and customer requirements (5 minutes)
Discuss insurance questionnaires, customer security requests, and any frameworks that apply to you, such as CMMC for defense work. Ask what evidence the provider can supply and what gaps exist.
7. Action items (5 minutes)
Close with a written list of decisions, owners, and dates. Send it out after the meeting and open the next review by going through it.
Preparing Beforehand
Ask the provider to send a concise report three or four days ahead. Review it and collect questions from managers and field staff. If you know of recurring complaints, bring examples.
Questions to Keep Asking
- What are the top three risks to our business right now?
- What would you do first if we had a ransomware incident tomorrow, and have we practiced it?
- Which of our systems are near end of support?
- What are we paying for that we don't use?
- Where are we depending on one person or one device?
- What should we be doing that we are not?
Signs of a Healthy Relationship
- The provider raises problems before you do.
- Recommendations come with reasons and options, not only quotes.
- Reports include bad news as well as good.
- Follow-up items actually get done.
- Your staff say the help desk is helpful.
Warning Signs
- Meetings that are cancelled repeatedly
- Reports that never change
- Vague answers about security
- Pressure to buy without explanation
- No documentation of your environment
If you see these signs, address them directly and consider whether the provider is the right fit.
Keep It Practical
A review should lead to decisions. Avoid long technical tours unless they inform a choice. Keep notes, track progress over time, and share highlights with your leadership team.
An Offer
Ironfield Cyber conducts quarterly reviews with its managed clients and is glad to share a sample agenda and report format. If you are working with another provider and want a second opinion on your current setup, we can sit in on a review and help you ask sharper questions.