How to Choose a Managed IT Provider: Questions Boards and Family Offices Should Ask

August 29, 2026 Mark O'Malley

How to Choose a Managed IT Provider: Questions Boards and Family Offices Should Ask

Choosing a managed IT provider is not only a procurement decision. The provider may receive privileged access to systems, identities, devices, cloud platforms, backups and highly sensitive information. In many organisations, it also becomes part of the incident-response and business-continuity model.

For Family Offices, the decision is even more important because the provider may need to support principals, executives and family members across offices, residences, travel and personal technology environments.

The right question is therefore not simply: “How much does support cost?” It is: “Can this provider safely carry the level of trust and accountability we are about to give it?”

Key takeaways

  • Evaluate security, governance and accountability as carefully as technical capability.
  • Understand exactly who will hold privileged access and how that access is controlled.
  • Check whether the provider can support incident response, recovery and after-hours events.
  • Family Offices should test whether the operating model genuinely fits family members, travel, residences and adviser ecosystems.
  • AI governance and third-party risk now belong in the MSP selection process.

1. Who is accountable for the outcome?

Technology environments often involve multiple vendors: Microsoft, telecommunications providers, security platforms, line-of-business applications, backup providers and specialist advisers.

A managed IT provider should be clear about whether it merely supports its own services or will coordinate the wider environment.

Ask:

  • Who owns an issue that spans several suppliers?
  • Will you manage escalation with third-party vendors?
  • Who is accountable when responsibility is unclear?
  • Do we have one practical escalation point?

A mature provider should reduce finger-pointing rather than add another layer to it.

2. How do you protect privileged access?

An MSP can become a high-value target because its administrative systems may provide access to multiple customers.

Ask specifically:

  • How are administrator accounts protected?
  • Is multi-factor authentication enforced?
  • Are individual administrator accounts used rather than shared credentials?
  • How are privileged sessions logged?
  • How are service accounts, API keys and secrets managed?
  • How quickly is access removed when an employee leaves?
  • How is customer access separated?

3. What does 24×7 actually mean?

Many providers advertise 24×7 services, but the operating model can vary considerably.

Clarify whether 24×7 means:

  • security alerts are monitored around the clock;
  • someone can actively respond to an incident;
  • end users can obtain support after hours;
  • senior technical escalation is available;
  • critical suppliers can be contacted and coordinated.

For internationally active Family Offices, support hours need to reflect the reality of travel and time zones.

4. How do you manage cybersecurity?

Managed IT and cybersecurity are now deeply connected. A provider managing identities, devices and cloud platforms directly influences the organisation’s security posture.

Ask how the provider approaches:

  • identity and access management;
  • endpoint protection and monitoring;
  • patching and vulnerability management;
  • Microsoft 365 security;
  • backup and recovery;
  • security awareness;
  • incident response;
  • configuration standards;
  • third-party risk.

Be cautious if the answer is primarily a list of products. Security is an operating model, not a shopping list.

5. How do you prove backups and recovery work?

Ask what is backed up, where copies are stored, how backups are protected and how often restoration is tested.

Important questions include:

  • Is Microsoft 365 included?
  • Are backups isolated from production credentials?
  • When was the last test restore?
  • What are the expected recovery times for critical systems?
  • Who coordinates recovery during a major incident?

6. Can the provider support the Family Office operating model?

Family Offices often need a different service model from mainstream corporate IT.

Ask whether the provider can support:

  • family members who are not employees;
  • personal and business devices;
  • executives who expect low-friction support;
  • international travel;
  • home and holiday-property technology;
  • trusted advisers and external partners;
  • highly confidential information;
  • next-generation family members.

A provider may be excellent at standard corporate IT and still be a poor fit for a Family Office.

7. How do you handle third-party providers?

Ask whether the MSP maintains a supplier register, understands which vendors handle sensitive information and can assist with vendor security reviews.

Useful areas to assess include:

  • contractual responsibilities;
  • security and privacy commitments;
  • incident-notification requirements;
  • data location and retention;
  • business continuity;
  • exit and data-return arrangements.

8. What is your approach to AI?

AI now affects both productivity and risk. An MSP supporting modern organisations should be able to discuss:

  • approved versus unapproved AI;
  • Shadow AI;
  • Microsoft Copilot and other enterprise AI services;
  • data protection;
  • identity and permissions;
  • AI vendor assessment;
  • agentic AI and non-human identities;
  • monitoring and governance.

If the provider’s AI strategy is simply to resell licences, the organisation may still be left to manage the real governance questions itself.

9. How transparent is the commercial model?

Boards and executives should understand what is included, what is variable and which costs may rise as the environment changes.

Ask:

  • What is included in the managed service?
  • Which projects or changes cost extra?
  • How are user, device and licence changes handled?
  • Are third-party security services separately charged?
  • How are cloud and AI consumption costs governed?

10. Can we speak to comparable clients?

References remain valuable, particularly where the environment requires discretion, regulatory sensitivity or unusual service expectations.

Ask for clients with similar:

  • size and complexity;
  • industry or stakeholder sensitivity;
  • support requirements;
  • cybersecurity expectations;
  • length of relationship.

Questions for the board or executive team

  1. What level of access are we giving this provider?
  2. Who remains accountable internally for technology risk?
  3. Could we change provider without losing access to our data, configurations and documentation?
  4. How will we know whether security and service quality are improving?
  5. Does the provider understand our operating model or are we being fitted into theirs?

Choose for stewardship, not only support

The strongest managed-service relationships extend beyond ticket resolution. They provide visibility, coordination, practical judgement and accountability across the technology environment.

DSC has supported high-trust organisations since 1997 and has developed a specialist Family Office Managed IT model spanning managed technology, cybersecurity and Secure AI Governance.

Sources and further reading