Your First 30 Days With a New Managed IT Provider

A good managed IT onboarding is structured and visible. Here is what should happen in the first 30 days, and what to ask your provider if it does not.

3 min readBy Ironfield Cyber Team

Signing a managed IT agreement is the easy part. The first month is where you find out whether the provider actually knows how to run a contractor or energy company. A good onboarding is organized, documented and sometimes a little uncomfortable, because it surfaces problems that have been quietly accumulating.

Here is what a healthy first 30 days looks like, so you can hold your provider to it.

Week One: Discovery and Access

The first week should be about learning your environment, not changing it.

  • Inventory: every computer, phone, tablet, server, network device and cloud account, with owners and ages.
  • Administrative access: the provider should gain administrative access in a documented, controlled way, and you should keep at least one emergency administrator account that you hold.
  • Contacts and escalation: who to call, who approves spending, and how after-hours emergencies work.
  • Current pain points: a conversation with project managers, superintendents and the office team about what frustrates them daily.

If the provider arrives with no questions about your software, such as Procore, Sage, Viewpoint or Autodesk, that is a warning sign.

Week Two: Baseline and Quick Wins

With the inventory complete, the provider should assess where you stand and fix the safest, highest-value items.

Security baseline

Look for a review of multi-factor authentication coverage, email security settings, backup status, patch levels and administrator accounts. The result should be a written list of gaps, ranked by risk.

Quick wins

These are changes that reduce risk quickly with little disruption:

  1. Turn on multi-factor authentication for email and remote access if it is not already.
  2. Remove accounts for people who no longer work for you.
  3. Confirm that backups are running and that at least one copy is out of reach of an attacker.
  4. Install endpoint protection and monitoring on devices that lack it.

Tell your staff what is coming. Surprise prompts and password resets generate more help desk calls than the changes themselves.

Week Three: Standardize and Document

Now the provider starts organizing.

  • Standard configurations for new laptops and phones.
  • A documented onboarding and offboarding process for employees, including seasonal crews.
  • A help desk process with a clear way to submit tickets from the field, not just from the office.
  • Documentation of your network, passwords stored in a managed vault, and software licenses.

Ask to see the documentation. If everything lives only in a technician's head, you have traded one dependency for another.

Week Four: Roadmap and Review

By the end of the month, expect a review meeting that covers:

  1. What was found, in plain English.
  2. What has been fixed.
  3. What remains, with estimated costs and recommended timing.
  4. A twelve-month roadmap that matches your budget and your growth plans, such as new offices, new jobsites or compliance requirements like CMMC.
  5. How service will be measured, such as response times and ticket satisfaction.

Be wary of a roadmap that is only a list of products to buy. A good roadmap ties each item to a risk or a business goal.

Questions to Ask Along the Way

  • Who is my primary contact, and who backs them up?
  • How do field employees get help, and what are the hours?
  • How do you handle a security incident, and what is included in the price?
  • What do I own if we part ways, including documentation, credentials and licenses?
  • What will I see monthly, and in what format?

What You Owe the Provider

Onboarding is a two-way process. Give your provider timely access to people, systems and decision makers. Name an internal point person who can approve changes. Share your plans for growth, new software and major projects. Providers can only plan around what they know.

Warning Signs

  • No written inventory by the end of week two.
  • Changes made without notice to staff.
  • Administrative credentials known only to the provider.
  • No mention of backups until you ask.
  • A roadmap that arrives with a price tag but no explanation.

Starting on the Right Foot

If you are comparing providers or want a second opinion on an onboarding already underway, Ironfield Cyber is happy to share how we structure the first 30 days for construction and energy clients and to review what your current provider has delivered.