Your New IT Provider's First 60 Days, Phase by Phase

A good managed IT provider does more than answer tickets. Here is what the first 60 days should include so you know the relationship is on track.

3 min readBy Ironfield Cyber Team

Switching to a managed IT provider is a big change, and the first two months set the tone for everything after. Some providers hand over a welcome email and start answering tickets. Better ones follow a structured onboarding that discovers what you have, fixes urgent problems, and builds a foundation for security.

If you are hiring a provider, or wondering whether your current one did it properly, this outline describes what a solid first 60 days looks like for a contractor or energy company.

Days 1 to 15: Discover and stabilize

Kickoff and contacts

The provider should meet with leadership and key staff to understand how the business works: where crews are, which systems are critical, what the busy seasons are, and what downtime costs. Agree on contacts, escalation paths, and how emergencies are handled after hours.

Inventory everything

Expect a thorough discovery of:

  • Computers, phones, tablets, servers, and network equipment
  • Cloud services and software subscriptions
  • User accounts and administrator accounts
  • Jobsite routers, trailers, cameras, and any field technology
  • Backup systems and what they actually protect
  • Domain names, licenses, warranties, and vendor contacts

This inventory is the foundation for everything else. If a provider does not do it, they are guessing.

Address urgent risks

During discovery, the provider will usually find issues that cannot wait. Examples include accounts without multifactor authentication, unsupported operating systems, missing backups, shared administrator passwords, or exposed remote access. A good provider should flag critical items quickly and fix the most severe ones in the first two weeks, while explaining the rest.

Days 16 to 30: Standardize and protect

Deploy core tools

This is when management and security software typically goes on devices: patching, endpoint protection, monitoring, and remote support. The provider should coordinate rollout with your staff, especially field users, so no one loses a day of work.

Establish identity and access basics

Expect work on multifactor authentication, cleanup of old accounts, review of administrator rights, and a standard process for adding and removing users. Hiring and offboarding checklists should be written and tested.

Confirm backups

The provider should verify what is backed up, confirm recovery targets with you, and run a test restore. Any gaps found should be documented with a plan.

Days 31 to 45: Document and train

Documentation

By now, you should receive clear documentation of your environment, including network diagrams, system lists, and standard procedures. You should know where it is stored and who can access it. Documentation that lives only in the provider's head is not documentation.

Staff communication and training

Staff should know how to request help, what to expect, and what changed. Security awareness training should be scheduled, ideally with content relevant to construction and energy roles.

Review email and cloud security

Expect a review of Microsoft 365 or Google settings, including filtering, sharing, and logging, with changes proposed and made.

Days 46 to 60: Plan and report

Initial assessment and roadmap

The provider should present a findings report with priorities, rough budgets, and timelines. It should separate must-do items from nice-to-have ones. You should leave the meeting knowing the top five risks and the plan to address them.

Service review

Review how ticket handling has gone: response times, satisfaction, recurring issues. Agree on the metrics you will receive going forward and how often you will meet.

Warning signs during onboarding

  • Little curiosity about how your business operates
  • No written inventory or documentation after several weeks
  • Pressure to buy products before assessing needs
  • Vague answers about who responds after hours
  • Admin credentials that you cannot access or that are not documented
  • Refusal to explain what they are installing and why

What you should own

Throughout the process, confirm that you hold the keys: administrator accounts for your domain and cloud tenant, your domain registrations, and your software licenses should be in your name, with documented access for you. A provider should make exit possible, not difficult.

Where Ironfield Cyber fits

Ironfield Cyber follows a structured onboarding built for contractors and energy companies, with security fixes up front and clear documentation at each step. If you want to see our onboarding plan before committing to anything, we are happy to walk through it.