7 Insider Secrets Your IT Provider Won't Tell You

I run an MSP in Sarasota, which means I know exactly where the bodies are buried in this industry. Seven things providers do that are perfectly legal, rarely disclosed, and worth knowing before your next contract renewal.

There's a version of this article every industry writes about itself and then buries. I've been in managed IT here on the Gulf Coast for years, I've inherited dozens of clients from other providers and seen what actually happens behind their invoices. Almost everything I'll describe is legal. Some of it is even defensible business practice. All of it is stuff your provider has no incentive to explain, and all of it changes how you should evaluate your current setup. If you haven't read what managed IT should cost, start there; this is the deeper cut.

1. "We monitor your systems" sometimes means software watches, humans don't

Monitoring platforms generate alerts constantly. The difference between real monitoring and monitoring theater is whether a person triages those alerts or whether they pile up until something breaks and someone goes looking. Ask your provider for last quarter's alert volume and mean time to acknowledge. A shop with genuine 24x7 eyes can answer instantly; theater can't.

What to do: ask for one concrete example of a problem their monitoring caught before anyone at your office noticed, from the last month. Real shops have these stories because they happen weekly.

2. The vendor ecosystem pays providers to recommend specific tools

Most MSPs get margin on software they resell, antivirus, email security, password managers, documentation platforms. That's normal and mostly fine; distribution margins fund real services. But it shapes recommendations in ways you'll never hear about. When your provider recommends switching from a tool that works to one that "integrates better," there is sometimes a revenue reason wearing a technical costume.

What to do: ask directly: "Do you receive partner margin on anything you've recommended to us?" A good provider answers yes without flinching and explains why the recommendation stands anyway.

3. Your backups probably pass checks but wouldn't restore

Backup software reports job success, data was copied. Nobody verifies the copy opens, decrypts, and rebuilds into a working machine except during an actual disaster, when discovering the truth costs a week of downtime. We restore-test client backups on a rotating schedule precisely because green checkmarks lie by omission.

What to do: ask when your provider last performed a full test restore of your critical systems, and ask to see the report. If the answer is "we've never needed to," that's the answer that should worry you.

4. Per-device contracts quietly become per-profit contracts

Under per-device billing, every new laptop, tablet, phone, and printer becomes monthly recurring revenue, and nobody audits the device count. I've audited incoming clients billed for 60 devices who actively used 31. Over three years, that drift quietly funds somebody's vacation home.

What to do: request a current device inventory from your provider today, compare against reality, and if you're on per-device billing, ask for per-user instead. See our hiring checklist for the full set of contract questions.

5. Security assessments are often sales documents wearing lab coats

A proper risk assessment takes days: interviews, network scanning, policy review, a written report mapped to a framework (CIS, NIST, HIPAA Safeguards). Many free "security assessments" are 45 minutes of scanning software followed by a report engineered to sell you the assessor's own products, complete with scary red graphics calibrated to produce signature anxiety.

That doesn't mean paid assessments are worthless, ours find real gaps every time. It means you should ask what framework the findings map to, whether severity ratings follow any published methodology, and for heaven's sake get a second opinion before buying anything priced like a car because of a PDF.

6. The renewal trap is deliberate

The most common lock-in isn't a penalty, it's a 90-day non-renewal notice window buried on page four, paired with auto-renewal. Providers know most businesses decide to switch within two weeks of a bad incident, then discover the notice deadline passed months ago. Missing it means paying another full year to a company you're leaving.

What to do: tonight, find your contract and calendar the notice deadline with three reminders. This single step saves more local businesses more money than any other advice in this entire post.

7. The best thing an MSP sells is saying no

Here's the uncomfortable secret on our side of the desk: the profitable move is almost always to say yes to whatever the client wants, new servers, fancy software, office-wide hardware refreshes, because projects bill hourly. The discipline to say "you don't need that yet, spend the money on backups and training instead" costs us revenue every single time we do it.

So invert the trust test. The provider who talks you out of purchases is managing your technology. The provider who agrees with every idea is managing your budget. Watch for which one shows up at your quarterly review.

Action Plan for This Week

  1. Calendar your contract's non-renewal window (Secret #6). Do it now; this post will still be here.
  2. Email your provider the backup-restore question (#3) and the monitoring example question (#1). Response quality tells you more than any sales meeting.
  3. Request a device inventory if you're billed per device (#4).
  4. Bring one "no" candidate to your next IT conversation, a purchase you're unsure about, and watch how they handle it (#7).

If you'd rather have an outside pair of eyes on your current setup, that's literally the business I run. Book a free 30-minute review or see what we handle for Sarasota and Bradenton businesses. Even if you never hire us, execute the action plan above, the calendar reminder alone might be the highest-value five minutes you spend on IT this year.