Most businesses end up with their MSP by accident. Someone made a recommendation. A contract is auto-renewed. A sales call came at the right moment. Very few UK businesses have ever sat down and asked: what does good IT support actually look like, and do we have it?
That question is worth asking, whether you are reviewing your current provider or starting the process from scratch. This guide gives you the framework to answer it honestly, and the specific questions to ask before you sign anything.
What Managed IT Support Is Actually Supposed to Do
Proactive vs Reactive: The Distinction That Matters Most
The single most important question to ask about any IT support arrangement is whether it is proactive or reactive. Most businesses are paying for reactive support and calling it managed. The two are not the same.
A managed service monitors your environment continuously. Issues are identified and resolved before users notice them. A device showing early signs of storage failure gets flagged, the drive is replaced, and the employee carries on working. Nobody loses anything.
Reactive support, often sold as break-fix or ad hoc support, waits for something to go wrong. The same failing drive triggers a call to the helpdesk, an engineer is dispatched or connected remotely, data recovery is attempted, and the employee loses half a day. The outcome depends on whether a backup was current. Often it is not.
The cost difference between proactive and reactive is not just in the IT budget. It is in the working time lost, the stress absorbed by staff, and the accumulated risk of a fleet that nobody is watching continuously.
What a Managed Service Includes That Break-Fix Does Not
A genuine managed service includes continuous device monitoring, automated patch management, security policy enforcement, regular reporting, and a named account relationship with scheduled reviews. Break-fix provides none of these. It provides a number to call when something stops working.
If your current provider does not deliver a written report of what they have monitored, resolved, and recommended in the last quarter, ask why. If the answer is that they only act on what you report to them, you have break-fix with a managed service label on it.
The Apple Specialist Question
What a Generalist MSP Typically Misses on a Mac Fleet
A generalist MSP supporting a mixed Windows and Mac estate typically has Windows-certified engineers applying Windows thinking to Mac problems. This sounds like a minor distinction. In practice, it produces a pattern of workarounds, incorrect configurations, and MDM policies that underperform because the engineer building them has not been trained on Apple’s platform specifically.
Common examples: DMS (MDM) configurations that technically enrol devices but do not apply the correct supervision profiles; Cyber Essentials compliance configurations based on Windows security benchmarks that do not translate cleanly to macOS; onboarding workflows that work for the Windows users but require a separate manual process for Mac users. Each of these is a friction cost that accumulates invisibly until something goes wrong.
What Apple Technical Partner Status Actually Means
Apple’s Technical Partner status requires demonstrated competency across Apple’s platform, assessed by Apple directly. It is not a self-declaration or a marketing claim. A business holding Apple Technical Partner status has engineers who have been trained and assessed on Apple device management, deployment, and support. Dr Logic holds Apple Technical Partner status, the highest tier in Apple’s restructured partner programme.
For a client, this means the engineers working on their Mac fleet have been trained on the platform they are managing, not working around the gaps in their knowledge.
Why It Matters for Device Management, Deployment, and Support Quality
The practical impact of Apple-specific expertise shows up in three areas. First, deployment: an Apple-specialist MSP will set up Apple Business zero-touch enrolment correctly from the start, meaning new devices arrive at employees’ desks pre-configured without IT involvement. Second, DMS configuration: policies are built to Apple’s own security frameworks, not adapted from Windows equivalents. Third, support resolution time: an engineer who understands macOS natively resolves Mac-specific issues faster than one who treats it as a less familiar platform.
For a business running 20 or more Mac devices, the difference in annual IT overhead between a specialist and a generalist MSP is measurable. In Dr Logic’s experience, the hidden cost of Apple support delivered by a generalist provider is most visible at onboarding, at Cyber Essentials audit time, and whenever a macOS update changes platform behaviour in ways that require configuration updates.
The Certification and Compliance Checks
What Cyber Essentials Plus Tells You About a Provider
Cyber Essentials Plus means the MSP has been externally assessed against the UK government’s baseline cyber security standard by an independent certification body. It is not self-declared. The assessment covers five technical controls: firewalls, secure configuration, access control, malware protection, and patch management.
For a client, Cyber Essentials Plus certification means two things. First, the provider has demonstrated that their own environment meets the UK’s minimum cyber security standard. A provider that cannot achieve Cyber Essentials Plus for themselves is in a poor position to help you achieve it. Second, they understand the standard well enough to have implemented it correctly under external scrutiny, which is directly relevant if Cyber Essentials is a requirement for your business.
The NCSC’s official guidance on choosing an MSP for SMEs specifically recommends that businesses use providers with Cyber Essentials Plus certification. You can verify a provider’s current certification status at the Cyber Essentials website.If you want an honest assessment of whether your business is prepared for Cyber Essentials certification, Dr Logic is here to help.
What ISO 27001 Certification Means for Your Data
ISO 27001 is an internationally recognised standard for information security management. Achieving certification requires an organisation to implement and maintain a documented information security management system, then pass an independent audit against the standard. It is substantially more comprehensive than Cyber Essentials and covers the processes, policies, and controls that govern how information is handled across the organisation.
For a client handing over access to their infrastructure, ISO 27001 certification provides evidence that the MSP has carefully considered data handling, access controls, incident response, and risk management, and that an independent auditor has verified these claims. Dr Logic holds ISO 27001 certification alongside Cyber Essentials Plus.
Why These Certifications Matter When You Are Handing Over Control of Your Infrastructure
When you engage an MSP, you are giving them privileged access to your systems, your data, and, in many cases, your users’ credentials. A provider without external certification has made no verifiable commitment to securing that access appropriately. In the current threat environment, where MSPs are an increasingly targeted attack vector precisely because compromising one provider gives access to multiple clients, certification is not a nice-to-have. It is the minimum standard of due diligence.
The Questions to Ask Before You Sign Anything
Response Time SLAa: What to Ask For and What to Check
Every MSP will present a service-level agreement with response-time commitments. The contractual target is not the metric that matters. Ask for the actual average response time over the last 12 months across their client base. Ask specifically for the average resolution time, not just the initial response time. The two are very different: a ticket can be acknowledged in five minutes and sit unresolved for three days.
Ask whether SLAs differ between critical, high, and standard priority issues, and ask for the criteria they use to assign priority. A provider who cannot give you a clear answer to how priority is determined has not thought carefully about the client experience under pressure.
What a Quarterly IT Review Should Include
A quarterly review is the mechanism through which a managed service remains proactive rather than reactive over time. Ask what is on the agenda, who attends from the provider’s side, and what decisions typically come out of it.
A good quarterly review covers: a summary of issues resolved in the period and any patterns emerging from them; the current security and compliance posture of the fleet; upcoming changes to software, operating systems, or hardware that require planning; and a forward look at the business’s technology needs in the next quarter. If the provider’s answer to this question is vague or if they do not currently offer a structured quarterly review, that is a signal worth noting.
How Escalation Works When Something Goes Seriously Wrong
Every managed service will have a process for routine tickets. The question that separates providers who have thought about client outcomes from those who have not is: What happens when something goes seriously wrong outside business hours?
Ask for the name of the senior contact who would be available in the event of a critical incident on a Sunday evening. Ask how that contact is reached and what the response commitment is. A provider who cannot answer this question specifically is one whose escalation process has not been documented, which means it will be improvised when you need it most.
What the Exit Process Looks Like
This question is worth asking before you are in a position where it matters. What happens to your data when you leave? What happens to your DMS configuration and your device enrolment records? How long does the transition process take, and who owns the work of migrating your environment to a new provider?
A provider who becomes evasive at this question, or who builds contractual barriers to a clean exit, is telling you something important about how they think about the client relationship. A good provider should be able to describe a clean, documented exit process without hesitation, because they have one.
Red Flags: What Poor IT Support Looks Like Before You Have Committed
These are patterns Dr Logic’s team encounters regularly when businesses arrive having left a previous provider. They are easier to spot before you sign than after.
No named account manager means nobody owns the relationship on the provider’s side. Tickets go into a pool, and whoever picks them up has no context about your business.
SLAs written in jargon that obscures actual commitments. “Best efforts” response times, priority levels defined by the provider at their discretion, and resolution windows that reset on any update to the ticket are all mechanisms that make performance harder to measure.
Reluctance to provide reference clients in a similar sector or of a similar size. A provider confident in their delivery should be able to connect you with two or three clients willing to speak honestly about their experience.
No proactive monitoring capability. If the provider cannot show you the dashboard they use to monitor your fleet, or cannot describe the alerting process that catches issues before users report them, they are running a reactive service.
Inability to describe their Apple methodology specifically. Ask directly: how do you configure DMS for a Mac-first fleet? How do you handle Cyber Essentials compliance on macOS? How do you manage Apple Business enrolment? If the answers are vague or generic, the Apple expertise is not there.
If you want an honest assessment of whether your current IT support is serving your business, Dr Logic offers a no-obligation IT review.
Related Articles
- Switching to an Apple-Dedicated MSP: What the Transition Looks Like
- Is Outsourced IT Support Right for Your Business?
- Cyber Essentials for Mac Offices: What UK Businesses Need to Know
FAQs
What is the difference between a managed service and break-fix IT support?
A managed service monitors your IT environment continuously and resolves issues proactively, before users are affected. Break-fix support waits for something to fail and responds when you report it. Most businesses paying for a managed service are actually receiving break-fix with a managed label. The clearest test: does your provider send you a regular report of what they have monitored and resolved, or do they only act on what you report to them?
What should I look for in an MSP if my business runs Macs?
Look for Apple Technical Partner status, which requires demonstrated competency assessed by Apple directly, not a self-declared claim. Ask specifically how the provider configures DMS for a Mac fleet, how they handle Cyber Essesntials compliance on macOS, and how they manage Apple Business enrolment. A generalist MSP applying Windows thinking to Mac problems produces workarounds and misconfigured policies that accumulate as invisible friction costs over time.
What certifications should a managed IT provider hold?
At a minimum, Cyber Essentials Plus requires an external assessment against the UK government’s baseline cyber security standard. ISO 27001 is the next level up, covering the information security management processes that govern how your data is handled. The NCSC’s official guidance for SMEs on choosing an MSP specifically recommends Cyber Essentials Plus as a minimum requirement. You can verify a provider’s certification status directly at the Cyber Essentials website.
What questions should I ask an MSP before signing a contract?
Ask for actual average response and resolution times over the last 12 months, not just the contractual SLA target. Ask what a quarterly IT review includes and who attends. Ask for the name of the senior contact available during a critical out-of-hours incident. Ask what the exit process looks like. A provider who answers these questions specifically and confidently has thought carefully about client outcomes. A provider who becomes vague or evasive on any of them has not.



















































