Questions to Ask Before Hiring a Managed IT Provider
Choosing a Canadian MSP is a multi-year decision. The right 10 questions surface the difference between a real partner and a ticket queue before you sign. Here are the ones that matter, and why.
Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
KEY TAKEAWAYS
- The Canadian Centre for Cyber Security publishes 10 assessment areas for buyers of managed services in ITSM.50.030 (October 2020).
- 47% of Canadian businesses without cyber security staff rely on consultants or contractors instead (Statistics Canada, 2024).
- Ask for a redacted sample quarterly report. It is the only artifact you can verify before signing.
- Get named ownership, response targets, and offboarding terms in writing rather than in the pitch deck.
How to use these questions
According to the Canadian Centre for Cyber Security, ITSM.50.030 (October 2020) sets out 10 areas a buyer should assess a managed service provider against. The questions below map onto those 10 areas in plain language.
Bring this list to every MSP conversation. The goal is to surface how a provider actually operates before you are locked into a multi-year contract. Vague answers to specific questions are the clearest warning sign I know of. Group the questions into 5 areas: accountability, security, service model, pricing, and AI readiness.
Question zero: ask for the name and certification number behind any “CISSP-led” marketing claim. Our guide to verifying an MSP’s CISSP claim shows the 2-minute directory check that settles it.
What is a managed IT provider, explained in plain English
According to Statistics Canada (2024), 47% of Canadian businesses without cyber security employees said they rely on consultants or contractors to monitor cyber security. Outsourced IT is the majority position rather than the exception.
A managed IT provider takes ongoing operational responsibility for a defined slice of your technology, for 1 recurring fee. That normally covers 5 things: monitoring, help desk, patching, backup, and security. The word that matters in the definition is responsibility. A vendor who only sells you licences and hourly labour is a reseller.
Provider or reseller: the working test
The distinction shows up on a bad day. When a server fails at 4pm on a Friday, a managed provider already owns the outcome and has the runbook. A reseller opens a ticket and quotes you. I have watched Canadian firms discover which one they bought during the incident rather than during the sales process.
Accountability and relationship
According to Statistics Canada (2024), 16% of Canadian businesses were impacted by a cyber security incident in 2023, and large firms were the most likely to be hit at 30%. Smaller firms face the same threats with thinner internal coverage, which is what makes the accountability question decisive.
The single biggest difference between Canadian MSPs is whether you get an accountable relationship or a shared queue. Ask who owns your account, how escalations work, and what happens when your main contact is away for 2 weeks. A provider who cannot name your engineer of record is selling ticket coverage.
Ask 1 more question here: does the provider belong to a peer community that benchmarks its numbers against other Canadian MSPs? Fusion answers that question in detail, because a provider who only compares itself to itself has no way to know it is drifting.
The criteria that separate a partner from a ticket queue
Five criteria do most of the sorting, and each one is answerable in a first meeting. I score prospective Canadian providers against all 5 on a single page, because a scoring sheet forces a comparison that pleasant conversations never will.
- Named ownership. A person and a documented backup, written into the agreement rather than promised verbally.
- Written response commitments. A 1-hour priority response target belongs in the contract, with the measurement window stated.
- Evidence over assertion. Ask for a redacted sample report showing patch compliance and tested restores, not a dashboard screenshot.
- Documented offboarding. What you receive, in what format, and within how many days if you leave.
- Framework alignment. Reporting mapped to CIS Controls v8.1, which defines 18 controls and 153 safeguards across 3 implementation groups.
| Signal | Real partner | Ticket queue |
|---|---|---|
| Ownership | Named engineer plus a documented backup | A shared inbox and a rota. |
| Response | Written 1-hour priority target with a stated window | Best-effort language only. |
| Evidence | Quarterly report with tested restores and owner names | A dashboard screenshot. |
| Offboarding | Documented handover inside a stated number of days | Undefined, negotiated on exit. |
| Frameworks | Reporting mapped to CIS Controls v8.1 | Tool names in place of controls. |
A provider that clears all 5 is rare. One that clears 3 and is honest about the other 2 is usually a better bet than one claiming all 5 without evidence. My rule of thumb is to weight the sample report heaviest, because it is the only artifact you can verify before signing.
Security and compliance
According to the Canadian Centre for Cyber Security, its 13 baseline controls are scoped to organisations under 499 employees and cover patching, strong user authentication, encrypted backups, and an incident response plan. Ask a prospective provider to walk you through all 13.
Security is the hardest capability to evaluate from outside, so ask direct questions. Does the provider hold CISSP or CISM credentials at the executive level? Where is your data stored, and is it in Canada? How does incident response actually run? For regulated businesses, ask specifically about PHIPA, PIPEDA, FIPPA, or CIRO obligations relevant to you.
Breach notification: what the statute actually says
Get the breach-notification answer in writing. PIPEDA s.10.1 requires reporting a breach of security safeguards to the Privacy Commissioner “as soon as feasible”, and it sets no 72-hour clock. The Office of the Privacy Commissioner publishes the reporting guidance.
A provider quoting a 72-hour PIPEDA deadline is repeating a myth, which tells you how carefully they read the statute. Ask about attack priorities too: the Verizon Data Breach Investigations Report (2026) puts vulnerability exploitation at 31% of breaches, ahead of stolen credentials at 13%.
“We asked all 9 questions to 3 providers. Two of them answered the offboarding question with a pause. That pause told us more than the whole proposal did.”
Managing partner, 35-person professional services firm, Greater Toronto Area. Anonymized at the client’s request; quote shared with permission.
Service model and scope
According to Statistics Canada (2024), Canadian businesses spent CA$1.9 billion on consultants and contractors for cyber security prevention in 2023, the third-largest prevention cost line. Scope decides whether that money buys coverage or gaps.
Confirm exactly what is included and what costs extra. Ask whether the Canadian provider offers co-managed arrangements if you already have internal IT, what the response commitments are in writing, and how onboarding runs across the first 4 weeks. Get the boundaries of the agreement clear before signing rather than after the first surprise invoice.
Ask how the provider measures itself. Uptime by service, first-contact resolution, mean time to repair, patch compliance, and tested restores are the 5 numbers worth seeing every quarter. Our guide to the IT metrics you should be tracking covers what good looks like in each, and what a defensible measurement window is.
Pricing and contracts
Understand the pricing model and the exit terms. Per-user monthly pricing is standard in Canada, so confirm what a user includes and what triggers add-on charges. Fusion Computing’s managed IT services start at CA$180 per user per month and typically run around CA$230, with cybersecurity services in the CA$180 to CA$250+ range.
Exit terms and documentation
Ask about contract length, what happens to your data if you leave, and whether the provider will document your environment so you are never held hostage by missing knowledge. If you are buying at around 50 users, managed IT services for a 50-employee business shows what the per-user fee should cover at that size.
Ask the provider to show the fee behaving over 12 months rather than in month one. Predictable, scalable IT costs is our own answer to that question, and it is the format I would ask any competitor to match.
What a managed IT contract requires you to check
Four clauses decide how a Canadian agreement behaves under stress, and each one is easy to miss in a first read. I mark these 4 in the margin before any client signs, because every one of them is cheap to negotiate before the contract starts and expensive afterwards.
- Data residency and portability. Where data and backups live, and in what format they come back to you.
- Incident response obligations. Who declares an incident, who notifies whom, and inside what window.
- Scope change mechanics. What counts as in-scope work, and how a change gets priced before it is performed.
- Documentation handover. Network diagrams, credentials, and runbooks delivered on exit within a stated number of days.
How the clauses map to CCCS guidance
Those 4 map directly onto ITSM.50.030 areas covering data portability, incident response, legal compliance, and data destruction. A provider familiar with that document will recognise the questions immediately, which is itself a useful signal about how they think.
AI readiness
AI is now part of the IT conversation for Canadian SMBs. Ask how the provider handles Microsoft 365 Copilot oversharing, where the assistant surfaces files a user technically has access to but was never meant to read. A provider who cannot explain their permissions remediation approach is not ready to guide an AI rollout.
One of the most revealing answers is the tool list itself. Fusion publishes all of its own in the software and tools behind our managed IT, so any Canadian buyer can compare like for like. Ask any provider to do the same, and note whether the list arrives with a shrug or with documentation.
The full question list
These are the 10 questions in the order I would ask them. Each one has a follow-up that separates a rehearsed answer from a real one, and the follow-up is where most of the information is. Take notes on the pauses as well as the answers.
Who specifically will be my engineer of record?
You want a named person or a small pod of 2 or 3 who know your environment, rather than an anonymous shared queue. If the provider cannot name who owns your account, you are buying ticket coverage. Ask for the backup name too, and get both written into the agreement.
Do you have CISSP or CISM credentials at the executive level?
Security tooling is not security strategy. A CISSP or CISM at the leadership level signals the provider can own your security posture rather than reselling software. Ask for the certification number and check it in the issuing body’s public directory, which takes about 2 minutes.
Where is my data stored, and is it in Canada?
Data residency matters for PIPEDA, PHIPA, FIPPA, and CIRO obligations. Get a clear written answer about where your production data and your backups live, which can be 2 different answers. Data residency is 1 of the 10 areas in the Canadian Centre for Cyber Security guidance ITSM.50.030.
What is your incident response process and time commitment?
Ask for the response-time target in writing, along with a description of what happens in the first 4 hours of a security incident. A 1-hour priority response commitment means little without a stated measurement window. A breach is not the moment to discover the provider has no plan.
Do you offer co-managed IT if we have internal staff?
With an internal IT person or team you need augmentation rather than replacement. Many providers only do full takeovers. Confirm they are comfortable working alongside your team, and get the split of responsibilities written down before day 1 rather than negotiated during the first incident.
How do you handle Microsoft 365 Copilot oversharing?
Copilot can surface files a user technically has permission to open but was never meant to read. Ask what the provider does about it: a permissions audit, sensitivity labelling in Microsoft Purview, and a remediation plan before rollout. A provider without those 3 steps is not ready to guide an AI deployment.
What exactly is included in the monthly price, and what costs extra?
Per-user monthly pricing is standard in Canada, but the definition of a user and the add-on list vary widely. Confirm whether project work, after-hours work, hardware procurement, and licensing sit inside or outside the fee. Get the inclusions and the exclusions in writing to avoid surprise invoices.
What happens to our data and documentation if we leave?
A good provider documents your environment and hands it over cleanly. Ask what you receive, in what format, and within how many days. Data and service portability plus data destruction are 2 of the 10 areas the Canadian Centre for Cyber Security tells buyers to assess before engaging a provider.
Can you provide references from businesses like ours?
Ask for 2 or 3 references from organisations of similar size and sector, and ask to speak with the person who deals with the provider weekly rather than the person who signed. A confident provider connects you with clients who describe the actual experience, including a bad week.
Can I see a redacted sample of your quarterly report?
This is the question most providers are least prepared for, and the single most useful of the 10. Look for a stated measurement window, named owners, patch compliance against a published window, and tested restore evidence with timestamps. A dashboard screenshot is not a report.
Related reading. Early-stage founders should read the startup-specific version first. See managed IT for Canadian startups for the day-one stack, the CA$180 per user baseline, and the security questionnaire enterprise buyers send.
Compare providers by your specific situation
Once you know the right questions, compare providers by the category that matches your need. Our national shortlist and the 4 situational guides below cover most Canadian SMB buying scenarios, and each one names the criteria that matter for that segment rather than repeating a generic list.
Start with our comparison of the top MSPs in Canada, which names providers worth evaluating by region and situation. If the staffing question is still open, read outsourcing IT versus hiring in-house first. For the leadership layer specifically, compare virtual CIO vs traditional CIO.
For security-led buying decisions, see our guide to cybersecurity-focused MSPs in the GTA, and ask any shortlisted provider how they run a network vulnerability assessment. Regulated firms should also read IT providers for law firms in Ontario.
Talk to Fusion
Fusion Computing provides answers to all 10 questions in writing, from Canadian offices in Toronto, Hamilton, and Metro Vancouver. We recommend asking every shortlisted provider for the same, and talk to our team when you want a sample quarterly report to compare against.

