
10 Questions to Ask Before Signing an IT Contract
Most IT contracts get signed on trust, not on specifics. Here are ten real questions to ask any provider — including us — before you sign, and what a straight answer to each one actually sounds like.
Most businesses don't switch IT providers because a specific thing went wrong. They switch because a slow accumulation of small things — a surprise line item, a question that got a shrug instead of an answer, a feeling that nobody could explain what they were actually paying for — finally added up.
The contract itself rarely catches any of that. It's written to protect the provider, not to help you evaluate one. So before you sign anything — a new agreement, a renewal, or your very first one — these are ten questions worth asking out loud, on a call, before you look at a single price sheet.
We run an IT company for businesses whose work happens away from a desk — fleets, warehouses, field crews, engineering and survey firms. We wrote this list because we'd rather you ask hard questions and switch to someone else with your eyes open than sign anything, anywhere, on a hunch. If a couple of these questions make a provider visibly uncomfortable, that's useful information too.
1. What exactly is included in the price — and what happens when something isn't?
This is the single most common source of IT billing disputes: a "flat monthly fee" that turns out to cover routine support but not the new server, the after-hours emergency, or the extra line item nobody mentioned at signing. Ask the provider to name, specifically, what triggers an additional charge — and ask what happens if they forget to tell you about one in advance.
Where we land: every line item a client pays gets flagged before it's billed, not after — if something shows up on an invoice that wasn't discussed first, that line is free. It's a specific, enforceable commitment, not a vague promise of "transparency."
2. Can they show you what's actually running on your network — or only tell you?
Any provider can describe your IT environment in a sales conversation. Fewer can put in front of you, in writing, in language you don't need a technical background to read, exactly what software and remote-access tools are installed on your systems right now. If the answer to "can I see that" is a shrug or a promise to "circle back," that's worth noting before you sign anything.
3. How do they watch for remote-access tools that shouldn't be there?
This one matters more than it sounds like it should. Remote monitoring and management (RMM) software — the tool a legitimate IT provider uses to fix your computers from anywhere — is also the tool criminals use once they've gotten in. The FBI's Internet Crime Complaint Center (IC3) put out an advisory in April 2026 tying a 60% year-over-year jump in cargo theft losses directly to unauthorized RMM software installed through phishing. If you run a fleet or a warehouse, this isn't a hypothetical: it's the current, named method.
The uncomfortable part is that an unauthorized RMM connection looks exactly like an authorized one to a standard security tool. Antivirus doesn't catch it. A firewall doesn't catch it. It looks like tech support, because functionally, it is — just not tech support you approved.
Ask directly whether auditing for unauthorized remote-access software is something they actually do, and how often. A provider who treats it as a specialty add-on rather than routine hygiene is telling you something.
4. Do you get a second opinion before a vendor sells you something new?
A lot of IT spend gets locked in by momentum, not need — a renewal that auto-approves, a "recommended upgrade" nobody outside IT can evaluate, a vendor quote that arrives with no real basis for comparison. Ask whether your provider will look at a quote from someone else — even a competitor's — and tell you honestly whether it's worth it.
Where we land: bring it to a free 15-minute call and we'll give you a written second opinion on any vendor quote or existing contract — whether or not you're a client. If the quote is fair, we'll say so.
5. How do they prove your backups actually work — not just that they ran?
A backup job completing successfully and a backup you can actually restore from are two different things, and the gap between them is where a lot of businesses get an unpleasant surprise, usually at the worst possible moment. Ask specifically: when was the last time someone actually restored a test file from your backup, not just checked that the job status said "success"?
If the honest answer is "we've never actually tested it," that's not unusual — but it's worth fixing before you need it, not after.
6. Do they have a plan for your technology, or just a ticket queue?
There's a real difference between a provider who reacts to what breaks and one who can tell you, in a document you could hand to a lender or an insurer, what your technology environment looks like today, what it costs, and where it needs to go over the next year or two. Ask to see one — not a sales deck, an actual written roadmap tied to your business and your budget.
7. Do they actually understand how your team works — at a desk, or away from one?
A lot of IT providers are built around office-based businesses: one location, everyone at a desk, standard hours. If your people are in trucks, on job sites, or spread across multiple locations most of the day, ask how that changes their approach — to licensing (are you paying full desktop-software rates for people who barely touch a keyboard?), to device management, to how quickly someone can actually reach a technician in the field. A generic answer here is a real signal.
8. How long have they been in business, and can you talk to a real client?
This is a fair question to ask anyone, and it deserves a straight answer, not a dodge.
We've been doing this as Boximity for seven years. We've kept it to four anchor clients that whole time, by design, not by accident — we'd rather go deep on a small number of relationships than spread thin across a lot of them, and we're happy to walk you through that track record in detail, honestly, including what we've gotten wrong. Our founder also brings a separate track record managing technology spend for organizations, including bringing it in below market rate — happy to talk through that too. What's changing now is we're building out a broader package specifically so that same depth of attention can extend to more businesses than it has so far. Any provider who won't tell you plainly how long they've actually been doing this, or dodges a reference request, is worth a second look regardless of the answer.
9. What do you actually find out about your own environment on an ongoing basis?
Response-time promises are easy to say and hard to verify after the fact. A more useful question is: what does the provider actually measure and show you, regularly, about your own systems? Ask to see a sample report before you sign — not a marketing one-pager, the real thing a client gets.
Where we land: we report on two things we can actually measure and stand behind — how consistently your monitored devices are checking in and online during business hours, and whether the specific security findings on your own risk register are going down, quarter over quarter, shown to you as the same one-page scorecard each time so you can see the trend yourself. We'd rather commit to something real and narrow than a punchier number we couldn't defend.
10. What does it actually take to leave, and how are you protected if you do?
Before you sign anything, ask what happens on the way out — not because you're planning to leave, but because a provider's answer to this question tells you a lot about how they think about the relationship. What's the notice period? Who owns your data, your documentation, your passwords, once the contract ends? Is there a penalty for leaving early, and if so, what is it actually for?
A provider confident in the value they deliver should be able to answer this plainly, without getting defensive. If the honest answer sounds more like a trap than a business relationship, that's worth knowing before you sign, not after.
Where we land: either of us can end the relationship with ninety (90) days' written notice — no cause required, and that goes both ways, not just for us to invoke. The one exception: if you leave during your first committed term, you cover what we spent getting you set up, capped at three months of fees — never the full remaining contract. Once that initial term is behind you, there's no exit penalty at all, just the notice. Getting your data, documentation, and access back is billed at our normal hourly rate, same as any other work we do for you.
The point of this list
None of these questions are designed to make any provider — including us — look bad. They're designed to make the invisible parts of an IT relationship visible before you're contractually stuck with them. A provider worth signing with should be able to answer all ten plainly, on the spot, without a follow-up call to "check with the team."
If you want to run this list against your current provider, or you're evaluating IT support for the first time, get a free Business-First IT Assessment — a 30-minute session that covers a lot of the same ground from the other direction — what's actually running on your network, what's protected, and what isn't. No obligation either way.
Source: FBI IC3 Public Service Announcement PSA 260430, April 30, 2026.