Quarterly Business Reviews With Your IT Provider: What to Ask

A regular review turns a managed IT contract into a partnership. Use this agenda to check security, costs, risks and the projects that matter to your business.

3 min readBy Ironfield Cyber Team

Many contractors sign a managed IT agreement, receive monthly invoices, and rarely sit down with their provider except when something breaks. That is a missed opportunity. A short, structured review each quarter keeps IT aligned with the business, surfaces risks before they cause damage, and holds the provider accountable for results.

Here is how to run a useful quarterly review, with an agenda and the questions that matter.

Who should attend

Include people who can make decisions.

  • An owner or executive who understands business priorities
  • The controller or CFO, who sees cost and fraud exposure
  • An operations or project leader who represents field needs
  • The IT lead or office manager, if you have one
  • The provider's account manager and a senior technical person

Keep the meeting to an hour and send an agenda in advance.

Agenda item 1: Service performance

Ask the provider to show data, not impressions.

  • Tickets opened and closed
  • Average response and resolution times against targets
  • Recurring issues and the plan to remove their causes
  • User satisfaction feedback
  • Any outages and what was learned

If a particular site or team has recurring problems, discuss a permanent fix.

Agenda item 2: Security posture

This is where the review pays off. Ask:

  1. Are MFA and email security protections active for every user?
  2. How many security alerts occurred, and how were they handled?
  3. What is the patch status of workstations, servers, and network equipment?
  4. Are any accounts or devices out of policy?
  5. What threats are currently targeting our industry?
  6. Were there any incidents or near misses?

Request a short list of open risks, with owners and target dates.

Agenda item 3: Backups and recovery

Ask for evidence of backup success, the date of the last restore test, and the result. Confirm whether recovery time and data loss targets are still realistic given business changes, such as new projects or systems. If it has been more than a few months since a test, schedule one.

Agenda item 4: Users and access

Review changes in staffing.

  • New hires and departures in the quarter and how quickly access was changed
  • Accounts that have not been used recently
  • Administrator accounts and who holds them
  • Third-party and vendor access

Agenda item 5: Assets and lifecycle

Look at the device and equipment inventory. Which laptops, phones, servers, and network devices are nearing the end of their warranty or support life? What replacements should be budgeted in the next year?

Agenda item 6: Costs and budget

Review spending against the plan.

  • Are there licenses you pay for but do not use?
  • Are there services that overlap?
  • Which upcoming renewals are due?
  • What projects should be budgeted for the next quarter or year?

Ask the provider to flag savings opportunities, not only additions.

Agenda item 7: Business changes

Tell the provider what is coming: new offices, major projects, acquisitions, new software, changes in contract requirements, or insurance renewals. IT is easier and cheaper when planned ahead. If a prime or customer is asking about security requirements, raise it here.

Agenda item 8: Roadmap

Agree on three to five priorities for the next quarter, assign owners, and set dates. Keep the list short enough to complete.

Make the review useful

  • Ask for a written summary with action items after every meeting.
  • Track items from one review to the next.
  • Be candid about what is and is not working.
  • Do not accept vague answers. Ask for specifics and dates.
  • Bring field voices into the room, since problems are often invisible from the office.

A hypothetical example

Consider a hypothetical contractor whose provider reports that response times meet targets, but the operations manager says foremen on two jobsites complain of slow internet every afternoon. Without the review, those two facts would never meet. In the meeting, they discover a camera upload is saturating the connection, and a schedule change solves it at no cost.

When to worry

Warning signs include a provider who avoids reviews, reports that never change, security questions answered with generalities, and recurring issues with no root cause analysis. Those are reasons to open a frank discussion, or to consider alternatives.

Where Ironfield Cyber fits

Ironfield Cyber includes regular reviews for our managed IT clients, focused on security, reliability, and cost. If you would like a sample agenda or a second opinion on what your current provider reports, we can share what we cover.