The short answer: choose on the criteria the National Cyber Security Centre actually recommends - Cyber Essentials Plus you can verify, response and resolution times in the contract, least-privilege access, a breach-notification clause and a clean exit that returns your data - plus proof they answer the phone. Grade a provider against the lot in five minutes.
- Judge providers on the NCSC's control set - certifications, SLAs, access control, incident notification and a clean exit.
- Most UK providers can't even evidence the security baseline, so a few verifiable checks narrow a shortlist fast.
- The scorecard grades any provider against the standard in about five minutes.
Written for UK owners and directors choosing an IT support company - and tired of checklists written to sell one.
There are 12k+ IT support companies - or managed service providers - in the UK, and almost every guide telling you how to choose between them was written by one of them. So the criteria are conveniently whatever that provider happens to be good at, and the awkward questions - about their own security, their contract, how you'd leave - never make the list.
In November 2025 the National Cyber Security Centre - GCHQ's cyber arm - published its own guidance on choosing a provider. It's short, vendor-neutral and refreshingly specific about what to look for.
This guide turns that guidance into a working checklist, adds the commercial questions the NCSC leaves out and gives you a scorecard to grade any provider against it. It's written by a provider too. The difference is that we'll show you the bar, and stand on the wrong side of it if we don't clear it.
First: do you even need to outsource?
Before you choose a provider, it's worth being sure you need one - and at what shape. If you're under about 50 staff, outsourcing almost always beats hiring on cost and coverage; between 50 and 100, co-managed support is often the sweet spot; past 100 it becomes a genuine choice.
We've done that maths in full in in-house versus outsourced IT support, and what a provider actually does day to day is covered in what is managed IT support.
This guide assumes you've decided to buy support and now need to pick the right company. That decision matters more than the price you pay for it - a cheap provider that fails on security or holds your data hostage on exit costs far more than it saves. So let's start where the National Cyber Security Centre starts.
What does the NCSC actually say about choosing a provider?
In November 2025 the NCSC published Choosing a managed service provider (MSP) - a plain-English guide aimed squarely at small and medium businesses. It matters because it's the one document in this whole field with nothing to sell.
It breaks the decision into four parts: how to choose a provider, the security issues to discuss, the details to check in the contract and a due-diligence checklist.
Underneath, the NCSC's blunt point is this: your IT provider will hold privileged access to your systems and data, so its own security is your problem too. That isn't caution for its own sake.
In 2021 the Kaseya attack spread ransomware through managed service providers to as many as 1,500 downstream businesses; in 2025 the DragonForce group hit a provider's remote-management tool to reach its clients; and in 2026 a single compromised remote-support tool isolated dozens of downstream firms in a matter of days.
When you let a provider in, you inherit its security posture. Choosing well is partly about making sure that posture is sound.
Here's the whole of the NCSC's guidance, plus the commercial criteria it doesn't cover, as one checklist. Skim it, then read the sections that follow for how to actually verify each one - and what a good answer versus a dodge sounds like.
| What to check | What good looks like | The red flag |
|---|---|---|
| Cyber Essentials Plus | A live CE Plus certificate you can find on the IASME register | "We follow the principles", with nothing to verify |
| Named security stack | Names its tools - endpoint detection and response, managed detection and response, email security - and enforces multi-factor authentication everywhere | "Advanced protection" with no product named; MFA treated as optional |
| Service level agreements (SLAs) | Numeric response and resolution times by priority, in the contract, with service credits | "Best endeavours", or a response time that's really an auto-acknowledgement |
| Incident notification | A clause stating when and how they'll tell you about a breach on your systems | Silence, or "we'll let you know" with no timeframe |
| Access and privilege | Least-privilege access, two-step verification on admin accounts, secured connections | Standing domain-admin access and shared passwords |
| Patching | Critical and high-risk vulnerabilities fixed within 14 days | No patch policy, or "when we get round to it" |
| Backups | Automated off-site backups with restores that are actually tested | Backups that exist but have never been restored |
| Monitoring and logging | Round-the-clock monitoring and alerting, with logs you can access | "Monitoring" that nobody watches out of hours |
| Reviews and reporting | Regular health reports - uptime, patch compliance, backup success | No reports; you find out how it's going at renewal |
| Exit terms | A clear termination process that returns your data, documentation and credentials | Notice measured in years, and data held hostage |
| End-of-life responsibility | Someone named to flag kit before it drops out of support | Nasty surprises when a server stops getting patches |
| Roles and liability | A written split of who owns what, including liability for incidents | Everything "shared", nothing actually owned |
| Supply chain | Can name its own suppliers and tools and vouch for their security | No idea who its own sub-processors are |
| Tested IR, DR and training | Rehearsed incident-response and recovery plans, plus staff security-awareness training | A plan on paper that's never been tested |
| References and transparency | Contactable clients your size, plain answers, published pricing | Logos on a wall, jargon and a price only after a "discovery call" |
The first fourteen rows are the NCSC's own recommendations from Choosing a managed service provider (November 2025); the last folds in the commercial checks the NCSC assumes you'll make anyway. The three sections below expand the ones that decide most contracts.
Security you can verify
Security is where the field is weakest and where the NCSC is most specific, so start here. The good news is that most of it is checkable rather than a matter of trust.
Cyber Essentials Plus - and check the register
The NCSC names Cyber Essentials Plus as the baseline: the UK government's minimum standard, independently assessed. The word that matters is Plus - the basic tier is a self-assessment; Plus is verified by a real assessor.
And you don't have to take a provider's word for it, because every certificate is listed on the public IASME register (IASME runs Cyber Essentials for the NCSC). Ask for the certificate, then look it up.
This one criterion filters hard. Government research found that only about 14% of UK IT providers even mention Cyber Essentials, and across all UK businesses only around 5% report meeting it.
A provider that holds CE Plus has already done more than most. One that answers "we follow the principles" but can't show a certificate has told you where it really sits. ISO 27001 or SOC 2 on top is a genuine plus; neither replaces CE Plus as the baseline.
A security stack they'll name
"Advanced threat protection" is marketing. Ask what the tools actually are. A serious provider will name them without flinching: endpoint detection and response on every device, managed detection and response with a team watching around the clock, email security, multi-factor authentication enforced everywhere.
If a provider won't name its stack, it usually means antivirus with a better adjective - and you'll only discover the gap during an incident. The named stack also matters because it's what you're really paying for; two quotes at the same price can hide very different protection.
How they get in - and whether that's locked down
This is the criterion buyers skip and the NCSC puts front and centre. Your provider needs access to your systems to do the job; the question is how much, and how well guarded.
The NCSC's standard is least privilege - the provider takes only the permissions each task needs, not standing administrator rights over everything - with two-step verification enforced on every account, especially admin ones, and connections secured over VPNs or restricted addresses. Ask specifically how they protect administrative credentials. A provider offended by that question has answered it.
Why this is not paranoia. An IT provider holds the keys to dozens or hundreds of businesses, which makes it a prize target. The Kaseya attack in 2021 reached up to 1,500 firms through their providers; in 2026 one compromised remote-support tool isolated dozens of downstream businesses within days.
Regulation is catching up: the Cyber Security and Resilience Bill, before Parliament through 2026, will bring medium and large providers under the Information Commissioner with a duty to report incidents within 24 hours. Picking a provider that already meets that bar is picking one that's ahead of the law.
Patching, backups and monitoring - the boring three that save you
Three quieter checks decide whether you ever have a bad week. The NCSC's benchmark for patching is fixing critical and high-risk vulnerabilities within 14 days - ask for the policy in writing.
On backups, the word to listen for is tested: a backup nobody has ever restored is only a hope until it's proven, so ask when they last restored one. And "monitoring" only counts if someone is actually watching - round-the-clock alerting with logs you can see, watched out of hours as well as in.
A provider that has all three to hand is proactive; one that has to go and check is reactive with a nicer brochure.
There's a bonus, too: multi-factor authentication, tested backups and endpoint protection are exactly what a cyber insurer now asks for - so a provider that runs them properly helps keep your premium down as well as your systems up.
Want a provider that already clears the security bar? Every Red Eagle Tech package names its stack and includes 24/7 CrowdStrike managed detection and response, from our entry tier up. See what's in each tier.
Service you can measure
Everyone promises to be responsive. The difference between providers is whether that promise is a number in a contract or a feeling in a sales meeting.
Response and resolution are two different clocks
Most buyers ask about "response time" and stop. There are two clocks, and you want both in writing. Response is how long until someone starts working on your problem; the NCSC's rule of thumb is within one business day for routine issues and under an hour for urgent ones.
Resolution is how long until it's fixed - a couple of business days for routine, medium-priority issues is a sensible starting point. A provider that guarantees a fast response but says nothing about resolution has promised to pick up the phone quickly and nothing else.
Both should vary by priority and both should be in the contract; missing them should cost the provider something - service credits you can point to.
The one question nobody else tells you to ask. Every provider will quote you its SLA targets. Almost none volunteer their actual performance. So ask: "What was your real average response time last quarter, against that target?"
A provider that measures its own service will have the number to hand and be glad you asked. One that mumbles has just told you the SLA is a marketing figure rather than a managed one. An automated "we've received your ticket" email, by the way, doesn't count as a response.
Who actually answers the phone?
When something breaks, you want a UK-based engineer who can act on it there and then, rather than a first-line script in another time zone reading from a flowchart. Ask where the helpdesk sits, who staffs it and whether you'll have a named contact who knows your setup.
"UK-based" on the website isn't the same as a UK team answering at 9am on a Monday - some providers front an offshore queue with a British phone number. This isn't about geography for its own sake; it's about whether the person who answers can fix the problem or only log it. Remote is fine - most good support is remote - but remote and offshore-first are different things.
Will they tell you when it goes wrong?
The NCSC wants a contract clause on incident notification: when and how the provider tells you if it - or you - suffers a breach, with timeframes set by severity. It sounds obvious until you realise how many contracts are silent on it.
You want to hear about a breach from your provider, quickly and in plain terms, before a customer or a regulator does. Pair it with regular reporting - health reports covering uptime, patching and backup success - so you're never finding out how the relationship is going only at renewal.
Beyond fixing: will they help you plan?
One thing the NCSC leaves out, worth weighing: does the provider only fix what breaks, or help you plan? A good one reviews your setup, flags what's ageing before it fails and gives you a roadmap - the job a virtual IT director, or vCIO, does. If technology drives your growth, that's worth as much as the helpdesk.
The contract, and how easy it is to leave
The commercial terms are where a provider's real confidence shows. A company sure of its service doesn't need to trap you; one that isn't relies on the contract to do what the service can't.
Length, notice and the auto-renewal trap
Three-year terms with automatic renewal are still common, and they exist for the provider rather than you. The NCSC tells buyers to check for flexibility to terminate, renew or renegotiate as needs change. Rolling monthly is the strongest signal a provider will keep earning your business; a 12-month term with a fair, clearly stated notice period is acceptable.
Watch for the evergreen clause that renews you for another year unless you cancel in a narrow window nobody remembers - and for annual price rises pegged to inflation with no cap. The length of contract a provider needs is inversely proportional to how good it thinks its service is.
What you get back when you leave
Ask the exit question while nobody wants to leave, because that's when you'll get a straight answer. What exactly comes back to you, and how fast: your data in a usable format, your documentation and configurations, along with every administrative credential and licence. Your Microsoft tenant, your domain and your data are yours to keep.
A confident provider makes leaving easy and says so in writing; one that goes vague on offboarding is telling you that the relationship is held together by friction rather than by value. The best exit terms are the ones you negotiate before you sign and hope never to use.
Pricing you can actually see
Most UK providers won't publish a price - you get a figure only after a "discovery call". That's a choice rather than a necessity, and the direction of travel is against it: the Competition and Markets Authority finalised guidance in November 2025 making hidden and drip pricing a live consumer-fairness issue. That's consumer law rather than a duty on business contracts, but it signals where expectations are heading.
A provider that publishes its per-user pricing and a written list of what's included versus billed extra respects your time. Get the inclusions in writing and check for the classics billed on the side - call-outs, after-hours work, onboarding fees, new-starter setups - because that's where a cheap headline price gets expensive.
See a full price list before you talk to anyone. Our per-user pricing is public - every package, ex VAT, monthly rolling, with the security stack named in each tier. Compare our packages against this checklist before you book a single call with anyone.
Score a provider against the standard
Tick what a provider you're considering can actually prove - not what its brochure says - and this scores it against the checklist above, non-negotiables first. It grades one provider at a time, so run it once per shortlist company and compare the results. No email address, no discovery call.
Non-negotiable the six the NCSC treats as essential · Quality signal the six that separate good from adequate. Tick only what the provider can evidence.
Tick what your provider can prove above, and its verdict appears here.
Where the gaps are:
Every box ticked. On this evidence the provider meets the NCSC's bar in full - now get the important ones written into the contract.
How we scored this
The 12 checks are the checklist above, distilled to the ones you can verify with a yes or a no. The six non-negotiables are the NCSC's essentials - miss two and no amount of nice-to-haves makes a provider a safe bet, so the verdict turns red; miss even one and the best it can be is amber. Green needs all six non-negotiables plus most of the quality signals. It's editorial guidance to focus your questions, not a certified risk score - and the written checklist above is the real standard.
The questions to ask on the call
A provider's answers on a first call tell you more than any brochure. The NCSC suggests five questions; we've added three commercial ones it leaves out. Ask them, and listen for a plain answer given without hesitation. The NCSC's benchmark is that a reputable provider should clearly articulate the services, policies and responsibilities it offers - and a good one does exactly that, without dodging.
- How do you secure admin access into our systems? Good answer: least privilege, two-step verification on every admin account, secured connections. Dodge: "our engineers are all vetted", which answers a different question.
- What does your monitoring and alerting look like? Good answer: named tools, round-the-clock, with someone actually watching and logs you can see. Dodge: "we monitor everything", with no detail on who or when.
- How quickly do you respond, and how will you tell us there's been an incident? Good answer: numbers by priority, plus a notification timeframe. Dodge: "very quickly" and a promise to "keep you in the loop".
- What's your vulnerability-management process? Good answer: critical and high-risk patches inside 14 days, with reporting. Dodge: "everything's kept up to date".
- How do you handle a breach in your own environment? Good answer: a tested plan, and a straight account of their own security. Dodge: visible discomfort at being asked.
- What was your actual average response time last quarter? Good answer: a number, offered without defensiveness. Dodge: a return to quoting the SLA target.
- What isn't included in the monthly fee? Good answer: a clear list - projects, hardware, maybe onsite visits - given upfront. Dodge: "it's all included", which is never quite true.
- What does leaving you look like? Good answer: notice period, what's returned and in what format, offboarding help. Dodge: a pivot to how happy their clients are.
Red flags to watch for
Some signals are worth more than any positive. If you see these, keep looking - a provider on its best behaviour, during the sale, is already showing you its ceiling.
- Pressure and expiring discounts. A price that drops if you sign by Friday is a sales tactic dressed up as a deal. Good providers know the decision takes weeks and don't rush it.
- No SLA in writing. Or a "response time" that turns out to be an automated acknowledgement. If the numbers aren't in the contract, they aren't real.
- Won't name the security stack. "Enterprise-grade protection" with no product behind it usually means antivirus and optimism.
- Charges extra for the basics. Multi-factor authentication, backup and patching are part of the core job. Billing them separately is a tell.
- Three-year lock-ins with auto-renewal. Especially with inflation-linked rises and a narrow cancellation window. Confidence doesn't need a cage.
- Vague on exit and data ownership. A provider that won't put in writing what you get back is telling you how leaving would go.
- A price only after a discovery call. Sometimes genuine, often a filter to get you into a sales process. Ask for a ballpark; a straight answer is a good sign.
- Suspiciously cheap. Below about £40 to £45 per user, something is missing - the security tooling alone costs a provider £20 to £25 per user, so the maths only works if scope or protection has been stripped out. Our guide to IT support costs shows what a fair price includes.
What good looks like
It's fair to ask whether the company writing the checklist passes it. So here's where Red Eagle Tech stands against its own standard, plainly, including where the answer is still a work in progress.
- The security stack is named, and the same in every tier. Every package includes CrowdStrike Falcon Complete - endpoint detection and response plus 24/7 managed detection and response, run by CrowdStrike's own threat-hunting team - on every device we manage, from our entry tier up. Naming it is the point.
- The SLAs are published up front. Priority-1 response targets sit on the pricing page for every package, with monitoring and detection running around the clock and the helpdesk staffed Monday to Friday. The numbers are public, so you can hold us to them.
- Rolling monthly, with a clean exit. No minimum term - cancel any time and your service runs to the end of the billing period. Onboarding is free, offboarding is free and your documentation, credentials and data come with you. There's a 90-day satisfaction promise on top.
- The prices are on the website. Every package, every per-user price, ex VAT, with what's included in each. We couldn't find another UK provider you can review in full and buy online without a call - which is exactly the transparency this guide argues for.
- A UK team, and a Microsoft Partner. Real UK engineers answer the phone, and we're a certified Microsoft Partner. On the certifications front we'll be straight: hold us to the same register check we tell you to run on anyone - ask us where we are on Cyber Essentials Plus, and we'll give you a straight answer rather than a marketing line.
That last point is the tell we'd want you to look for in anyone. A provider that meets every bar will say so and show you; one that meets most will tell you which and by when. The dodge is the diagnosis.
Run the checklist against us. Our packages start at £69 per user per month ex VAT, monthly rolling, with the stack named and the SLAs published. See the full price list, or talk to a UK engineer and put us on the spot.
Frequently asked questions
Judge every provider against the criteria the National Cyber Security Centre published in November 2025: Cyber Essentials Plus certification you can verify, response and resolution times written into the contract, least-privilege access with two-step verification, a breach-notification clause, tested off-site backups and a clean exit that returns your data. Then check the things the NCSC assumes - a UK team that actually answers, published pricing and references your own size. Our scorecard grades any provider against the lot in about five minutes.
The same six non-negotiables every time: a Cyber Essentials Plus certificate on the register, written response and resolution SLAs with service credits, a contract clause on how fast they tell you about a breach, tested off-site backups, a named security stack with managed detection and response, plus an exit that hands back your data, documentation and credentials. Everything else - who answers the phone, how transparent the pricing is, whether references match your sector - separates a good provider from a merely adequate one.
The NCSC suggests five: how do you secure admin access into our systems, what does your monitoring and alerting look like, how quickly do you respond to incidents and how will you tell us there's been one, what's your vulnerability-management process and how do you handle breaches in your own environment. Add three of our own: what was your actual average response time last quarter, what's not included in the monthly fee, and what does leaving you look like. A good provider answers all eight plainly, without dodging.
It's a floor to clear, then you keep looking. The NCSC names Cyber Essentials Plus as the baseline standard and tells buyers to prefer providers that hold it - you can check any company on the IASME register. But only around 14% of UK IT providers even mention Cyber Essentials, so it's a useful filter on its own. Treat CE Plus as the price of entry, then judge the provider on SLAs, incident notification, exit terms and how it secures its own access to your systems.
UK managed IT support runs roughly £30 to £150 per user per month in 2026, with £45 to £85 the realistic mid-market band; be wary below £40 to £45, because the security tooling alone costs a provider £20 to £25 per user. Price should never be the first filter, though - a cheap provider that fails the security and exit criteria costs far more the day something breaks. Our cost guide breaks down the bands, the drivers and the hidden extras in full.
Rarely, in 2026. Monitoring, patching, managed detection and response and most helpdesk work are done remotely, so a UK-based provider serves you just as well from the next county as the next street. What matters is that the team is UK-based and answers quickly from a UK helpdesk, and that someone can be on site when the problem is genuinely physical. Judge on response times and who picks up the phone rather than the postcode.
Short enough that the provider has to keep earning it. Three-year terms with automatic renewal exist for the provider's benefit rather than yours - the NCSC specifically tells buyers to check for flexible termination. Rolling monthly is the gold standard; a 12-month term with a fair notice period is acceptable. What you're really testing is confidence: a provider certain of its own service doesn't need to trap you in a long contract to keep you.
Ask for contactable clients of your own size and in your own sector, then set the questions yourself so the provider can't hand you its three happiest logos. Ask those references how the provider handled a real incident or dispute, rather than whether they're generally happy. The NCSC frames this as speaking to current clients in similar industries to understand real-world performance - a provider proud of its service will make the introductions without hesitating.
Sales pressure and discounts that expire on Friday; no written SLA, or a response time that's really an automated acknowledgement; refusal to name the security tools they use; three-year lock-ins with automatic renewal; charging separately for basics like multi-factor authentication or backup; and hidden call-out, after-hours or onboarding fees. Any provider that won't put data ownership and exit terms in writing before you sign is telling you exactly how leaving would go.
Yes, and it's less risky than it feels. A proper move runs in three overlapping stages over two to eight weeks - discovery, parallel running and cutover - and your team keeps working throughout because nothing is switched off until its replacement is proven. The real variable is the state of your documentation rather than your size. A good incoming provider handles the handover, including taking over a mid-contract mess, and a good outgoing one returns your data and credentials cleanly. Where either resists, that's the exit clause earning its place.
In UK practice they're the same thing. "IT support company" is what most businesses search for; "managed service provider", or MSP, is the industry term for a company that runs your IT for a monthly fee - helpdesk, devices, patching, backup, security and monitoring. The NCSC's guidance is written about MSPs and applies equally however the provider labels itself. What matters is the service model and the criteria in this checklist, whatever the label over the door.
Because your IT provider holds privileged access to your systems, which makes it a high-value target and, if it's breached, a direct route into your business. It isn't theoretical: the 2021 Kaseya attack reached up to 1,500 downstream businesses through their providers, and in 2026 a single compromised remote-management tool isolated dozens more. The NCSC's guidance is blunt about it - ask how a provider secures admin access, enforces two-step verification and handles breaches in its own environment before you let it into yours.
Sources
- NCSC, Choosing a managed service provider (MSP), version 1.0, published 24th November 2025 - ncsc.gov.uk
- NCSC, Annual Review 2025 - Cyber Essentials certificate figures
- DSIT and Frontier Economics, Research on the managed service providers market 2025 (12k+ active UK MSPs, £51bn revenue), published November 2025 - gov.uk
- DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, published 30th April 2026 - 43% of businesses breached; supplier cyber-risk review; Cyber Essentials adherence
- gov.uk, Cyber Essentials scheme overview and management information, updated 13th March 2026
- IASME, Cyber Essentials pricing and the certificate register - iasme.co.uk
- gov.uk, Cyber Security and Resilience Bill factsheets: relevant managed service providers, 2025 to 2026
- Competition and Markets Authority, finalised price transparency guidance, published 18th November 2025 - gov.uk
- NCSC, CISA and allied agencies, joint advisory: Protecting Against Cyber Threats to Managed Service Providers and their Customers, May 2022
- Sophos and Huntress, incident reporting on the Kaseya (2021) and remote-management-tool (2025 to 2026) supply-chain attacks