Most business owners judge their IT provider on gut feeling - are tickets getting answered, does the person on the phone seem competent. That's a reasonable starting point, but it misses the things that actually matter most: whether your systems are genuinely secure, patched, and backed up, which you'll only find out the hard way if nobody's actually checking.
Why Gut Feeling Isn't Enough
A provider can be pleasant, responsive on the phone, and still be failing at the less visible parts of the job - proactive patching, backup verification, security monitoring. These are exactly the things that don't show up as a problem until something goes wrong, at which point it's too late to have measured it. Concrete metrics catch this gap before an incident does.
The Metrics That Actually Matter
Response and Resolution Times
Compare actual performance against the SLA in your agreement, not just anecdotal impressions. Ask for a report showing average response time by priority level over the past quarter. See our guide on managed IT response times and SLAs for realistic benchmarks to compare against.
Patch Compliance Rate
The percentage of devices fully up to date on security patches at any point in time. This is one of the most reliable indicators of whether proactive maintenance is genuinely happening, since patching rarely generates a support ticket on its own - it's invisible unless someone reports on it.
Backup Success and Test Restore Rate
Ask specifically whether backups have been test-restored recently, not just whether the backup job "completed successfully." A completed backup job and a genuinely restorable backup are not the same thing.
Ticket Volume and Recurrence
A high volume of repeat tickets for the same underlying issue suggests root causes aren't being addressed, just symptoms. A declining trend in overall ticket volume, alongside stable or improving satisfaction, is a good sign of proactive work paying off.
Security Findings and Remediation Time
How quickly are identified vulnerabilities or security gaps actually closed, not just flagged? A provider that reports issues but takes months to fix them isn't providing much protective value.
How to Get This Information
Most reputable managed IT providers offer this as standard quarterly or monthly reporting, without you needing to request it. If your provider has never proactively shared this kind of data, ask directly - and treat reluctance to share it as a signal worth taking seriously.
Putting It in Context: The Quarterly Review
These metrics are most useful as a running conversation, not a one-off audit. See our guide on what happens in a quarterly business review with your MSP for how to structure this as an ongoing check-in rather than a one-time report card.
What to Do If the Numbers Are Bad
A single missed target isn't necessarily a reason to switch - ask what happened and what's changing. A consistent pattern of missed SLAs, unpatched systems, or untested backups over multiple quarters, with no improvement plan offered, is a different situation entirely. See our guide on switching managed IT providers without disruption if that's where you land.
Frequently Asked Questions
How often should I formally review my IT provider's performance?
Quarterly is a reasonable cadence for most small businesses - frequent enough to catch a decline before it becomes serious, but not so often that it becomes an administrative burden on both sides. See our guide on quarterly business reviews for what that conversation should cover.
What if my provider refuses to share performance data?
This should be treated as a warning sign in itself. A provider confident in their service has no reason to withhold ticket volumes, response times, or patch compliance figures - most reputable providers offer this as standard reporting without being asked.
Is a low number of support tickets a good sign or a bad one?
It depends on the reason. Genuinely stable, well-maintained systems generating few tickets is a good sign. Low ticket volume because staff have given up reporting issues, or because the provider discourages contact, is a bad sign disguised as a good one - worth checking with staff directly.
What's the single most telling metric if I can only track one?
Patch compliance - the percentage of devices fully up to date on security patches at any given time. It's a reliable proxy for whether proactive maintenance is actually happening behind the scenes, rather than just responsive support when something visibly breaks.
Every client gets regular reporting on response times, patch compliance, and backup health - not just a friendly voice on the phone.
Managed IT Services →Want an outside read on how your current provider is really doing?
Call 0433 087 091 - our free IT health check benchmarks your current setup against what good actually looks like.
Book a Free IT Health CheckFor related reading, see our guides to managed IT response times and SLAs and what an IT security audit covers.