How to Choose an IT Support Company

An IT support company should be chosen on objective criteria: the team’s competencies, international certifications (ISO 27001, ISO 20000), professional indemnity insurance, response times committed to in the contract, the level of automation in day-to-day support, regular reporting and references from real clients. Price is only one factor — the cheapest proposal often means a narrower scope of services, a slower response or less competence, which ultimately costs more than the difference you saved.

The decision matters all the more because an IT support partnership typically lasts for years: the provider gains access to your systems, data and processes, so the cost of a wrong choice is high — and, equally, greater competence brings real benefits and pays for itself. The good news is that the right questions and a few clear criteria let you tell a mature service provider apart from a firefighter — before you sign anything.

Below you will find concrete evaluation criteria, a list of questions for a prospective provider, the warning signs to watch for, and a comparison table that helps you assess several proposals in a structured way.

The key evaluation criteria

Competencies and team maturity

Assess whether the provider’s team includes experienced specialists covering every area that matters to you: workstations, servers, networking, security, cloud, IT management and consulting. Ask which methodologies their work is organised around — mature providers follow global ITSM, ITIL or COBIT practices rather than improvising and learning only from their own experience. It also matters whether you will be assigned a responsible person who genuinely has IT competencies and knows the technologies in your infrastructure, or whether you will speak to a different specialist every time — or, worse, only to a friendly account manager.

Certifications and partnerships

An ISO 27001 certificate shows that the company manages information security systematically; ISO 20000 shows that its IT service management processes meet the international standard. These are not formalities: certified companies are audited by independent assessors every year. Vendor partnership statuses (for example with Microsoft or security solution vendors) are an additional signal of verified technical competence.

Insurance and accountability

Professional indemnity and cyber risk insurance shows that the provider takes real responsibility for its work, and insurers assess the maturity of every company they insure. Ask not only whether the insurance exists but also about the amount — it should be adequate to the potential damage to your business.

Response times and SLA

A serious provider puts its commitments in the contract: which channels requests are logged through, how quickly the provider responds depending on incident severity, how quickly the issue is resolved, and how performance is measured. What level of commitment to require for your type of business is covered on the page What SLA does your company need, and what the contract itself should define on the page What should an IT support contract include.

Automation, proactivity and prevention

What separates a mature provider from a firefighter is automated system monitoring and response: problems are spotted and resolved before users ever notice them. Ask which tools are used for monitoring, patch deployment and backup verification. Ask, too, whether there is a problem management process and how it works — so that the provider tackles causes rather than consequences, and identifies and prioritises them continuously, without you having to ask.

Reporting and transparency

Regular reports on completed work, incidents and system health let you see what you are paying for and make informed decisions about IT investments. If a provider does not report, you are effectively buying a black box — and you may end up spending a great deal of time on explanations or disputes.

Client references

Ask to speak with existing clients whose size and line of business resemble yours. The most valuable question to put to them is not whether everything is fine, but how the provider behaved in one specific situation or another, and when something went wrong. It is also worth reviewing publicly available success stories.

Questions worth asking a prospective provider

  1. How many clients do you currently support, and how large are their infrastructures?
  2. Which certifications do you hold, and when was your last independent audit?
  3. Do you carry professional indemnity and cyber risk insurance? For what amount?
  4. Which response and resolution times are fixed in the contract, by incident severity?
  5. How are user requests logged and prioritised — is there a single point of contact?
  6. Which tools do you use to automate monitoring, updates and backup verification?
  7. Which reports will we receive, and how often?
  8. Who will be responsible for our company — will we have a dedicated IT manager, or a general helpdesk line?
  9. Do you also manage third-party vendors (internet, telephony, business systems), or does that remain with us? Is it handled through the same single point of contact?
  10. What does the takeover process from our current provider or in-house specialist look like?
  11. How do you ensure information security, and do you help with NIS2 compliance?
  12. What is included in the monthly fee, and what is billed separately?
  13. What are the contract term and termination conditions — are we being locked in?
  14. How do you document our infrastructure, and will the documentation belong to us? Do you audit the IT estate when the service starts, will we receive the results, and is the audit charged for?
  15. Can you provide at least two existing clients as references?

The answers will reveal not only the substance of the service but also the provider’s culture: whether they answer specifically, or in generalities.

Red flags to be concerned about

  • A price is quoted immediately, without a single question about your infrastructure — the scope will be adjusted later, and not in your favour.
  • No written SLA commitments — a promise to respond quickly is not a commitment. Some providers commit only to a response time and not to a resolution time, which leads to situations where the issue was acknowledged in 15 minutes and fixed five days later.
  • A long fixed-term contract with heavy termination penalties — a provider confident in its service does not tie clients down with long terms or exit penalties.
  • No documentation practice — if all knowledge about your systems stays in the head or on the computer of a single person at the provider, you become dependent.
  • Reluctance to provide references or concrete examples of existing clients.
  • No security certifications and no insurance, even though the provider will gain access to your data.
  • Purely reactive work: no monitoring, no proactivity, no preventive maintenance, no reporting — you are paying for firefighting, not fire prevention.

A comparison table for evaluating several proposals

When assessing several providers, score each criterion on facts, not impressions. You can use this table as a template:

Criterion What to ask / look for Provider A Provider B
Certifications ISO 27001, ISO 20000, vendor partnerships
Insurance Professional indemnity and cyber risk insurance amount
SLA Written response and resolution times by severity
Automation Tools and commitments for monitoring, updates and backup verification
Reporting Content, frequency, a sample report
Dedicated contact Assigned IT manager, single point of contact
References At least two existing clients you have spoken to
Contract terms Scope for each service, extra charges, termination procedure
Price Pricing model and what it includes

Deliberately leave price for last — first make sure you are comparing an identical scope of services. What makes up the price and which hidden costs to ask about is covered in detail on the page How much does IT support cost for a business.

Why size does not necessarily mean quality

A big provider name is no guarantee of a better service: in very large organisations, a smaller client is often served from a general queue with no personal attention, while a very small provider may lack the specialists for cover and for different competence areas. Large providers usually offer standardised services with a predefined scope that cannot be adapted or changed to fit your needs, so the question is whether that will suit you and whether it will be enough. What matters more than size is process maturity, the level of automation, the team’s experience — and whether your company will actually matter to the provider. A practical test: how much attention and specificity you get at the sales stage. It will certainly not increase after the contract is signed.

If you are currently weighing not just which provider to pick but the model itself — hiring an in-house specialist versus choosing a partner — you will find the comparison on the page In-house IT specialist or outsourced IT partner. And if you are replacing an existing provider, how to do it smoothly is described on the page Changing your IT support provider without risk.

Why Altic IT

Altic IT meets every criterion listed above — the same criteria we suggest you apply to any IT support provider, ourselves included:

  • ISO 27001 (information security), ISO 20000 (IT service management) and ISO 14001 certifications;
  • professional indemnity and cyber risk insurance of EUR 2 million;
  • 180+ clients served, around 3,500 computers and mobile devices and around 350 servers under management;
  • Microsoft Solutions Partner for Data & AI and Sophos Gold Partner statuses;
  • work organised around ITSM, ITIL and COBIT practices, an experienced external IT manager assigned to every client, and a single point of contact for users — including third-party vendor management;
  • a team made up mostly of experienced senior-level specialists;
  • within the first three months, the number of incidents our clients experience is reduced by up to five times;
  • open-ended contracts — we stay with you for as long as you are happy — and the vast majority of our clients come through referrals. They include the Bank of Lithuania, the State Tax Inspectorate, Bite Lietuva, Tele2, CityBee and others (more on the about us page).

Frequently asked questions

  • How do I choose an IT support company?

    Start by defining your own needs: the number of workstations and servers, the systems that will need support, the service hours you require and your security requirements. Then shortlist several providers — at least three — based on referrals, experience, competencies and certifications, ask each of them the same questions and compare the answers in a structured way, for example using the table on this page.

  • Do ISO 27001 and ISO 20000 certifications really matter?

    Yes, because they are independently audited evidence that a provider’s security and service management processes actually work. The provider will gain broad access to your systems and data, so declarations about security in a contract are certainly not enough on their own.

  • How do I verify a provider’s references?

    Ask for the contacts of at least two existing clients and speak to them directly. Ask about real situations: how the provider responded to incidents, whether it keeps its commitments, and how service quality has changed over time.

  • Is it worth choosing the cheapest proposal?

    The cheapest proposal often means a narrower scope, less competence delivered, a slower response, or extra charges for work that is already included in the price elsewhere. First align the scope and the pricing model of the proposals you are comparing, and only then compare the price.

  • How long does switching to a new IT support provider take?

    The duration depends on the size of the infrastructure and the state of the documentation, and can range from a week to a month or a few. A mature provider has a clear takeover process: an infrastructure audit, an inventory, access handover, documentation and a smooth service start with no downtime for users.

Discuss your IT support needs

Want to measure us against every criterion on this page? Ask us all fifteen questions — we will answer them specifically. Get in touch via our contacts page or by phone at +370 5 2032018, and let us discuss your company’s IT support needs with no obligation.

Contact Altic IT

IT paslaugos verslui - Altic.lt
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Read more information about our Privacy policy