Onboarding a new client starts with a question, not a technical task: what do you have? Which computers, which logins, which vendor accounts, who has admin rights to what. More often than our team would like, no one has an answer. Not because the business is careless — because their previous IT company never handed any of it over.
No asset list. No password vault. No diagram of how the network fits together. Just a folder of invoices and logins that may or may not still work.
Why that’s a bigger problem than you think
An accurate inventory of your own systems isn’t a nice-to-have. It’s the first control in the CIS Critical Security Controls, because you can’t protect what you don’t know you have. A business that’s never seen its own asset list has been missing that first step the entire time it was paying someone to manage it.
It usually doesn’t show up until something forces the issue — a provider becomes unresponsive, a contract renewal gets awkward, or the business wants a second opinion. That’s when it becomes obvious, and by then it’s a scramble, not a simple conversation.
What to ask before you sign
These aren’t sales questions. They’re the ones that matter once the contract’s signed and the relationship is three years old.
Who owns the documentation? Passwords, network diagrams and asset lists should be somewhere you control, not locked inside a provider’s system. If the answer is vague, that’s not an answer — it’s a problem.
What’s the response time, in writing? “We’ll get to it quickly” isn’t a commitment. A number in the contract is.
What happens if you want to leave? A provider confident in their work will have an offboarding process already spelled out. One who dodges the question is telling you something too.
What’s not included in the flat rate? Most of the regret comes from the difference between what was quoted and what shows up on the invoice six months in.
The Canadian Centre for Cyber Security’s own guidance on contracting with managed service providers makes the same point from the security side: outsourcing your IT doesn’t outsource the responsibility for it. You’re still the one accountable for what happens to your systems — which only works if you have visibility into them.
What we do differently
Every system our team touches gets documented as we go — not reconstructed later, not held back as leverage. If a client ever wants to leave, they walk out with everything they came in with, plus everything we added. That’s not a courtesy. It’s the first control on the list, done properly.
If you’re not sure what your current provider has on file for your business, that’s worth finding out before it becomes a problem. Book a free 15-minute discovery call — we’ll help you figure out what questions to ask.