Contact

BlogManaged IT

Managed IT

How to Choose a Managed IT Provider in South Africa: 10 Questions That Matter

Ten questions that separate a real managed IT provider from a slow help desk with an invoice — SLAs, security, ownership, POPIA, load-shedding, and who actually does the work.

Derick PayneDerick PayneFounder and lead developer

Published 16 June 2026Read 3 min

On this page
  1. 1. What exactly is included — and what is billed extra?
  2. 2. What are your SLA response times — response or resolution?
  3. 3. What are the coverage hours, and what does after-hours cost?
  4. 4. Are backups monitored, and are restores actually tested?
  5. 5. How is security handled — is it baseline or an upsell?
  6. 6. Who owns the keys — Microsoft 365, DNS, and admin access?
  7. 7. Is there a written POPIA operator agreement?
  8. 8. How do you handle load-shedding and connectivity?
  9. 9. Will I get a report I can actually read?
  10. 10. Who actually does the work?
  11. The practical next step

Choosing a managed IT provider is one of those decisions that feels similar across vendors until something goes wrong — and then the differences are suddenly very clear. A good provider is a quiet operating layer that keeps your business running. A weak one is a monthly invoice that buys you a slow help desk. These are the questions that separate the two, before you sign.

We provide managed IT ourselves, so consider this the list we would want a client to hold us to.

1. What exactly is included — and what is billed extra?

“Managed IT” is not a defined term. Get the scope in writing: help desk, monitoring, patching, endpoint security, backups, Microsoft 365 administration, and a regular review should all be named. Anything vague will become a surprise invoice later.

2. What are your SLA response times — response or resolution?

A service-level agreement is where promises become commitments. Ask for the response targets by priority — a critical, business-down issue should be measured in a couple of hours, not “we’ll get to it.” And clarify whether the number is a promise to respond or to resolve. They are very different.

3. What are the coverage hours, and what does after-hours cost?

Standard cover is usually business hours. If your business runs into the evening or over weekends, confirm whether after-hours support exists and what it costs. The time to discover there is no after-hours cover is not at 7pm on month-end.

4. Are backups monitored, and are restores actually tested?

Almost everyone “does backups.” Far fewer test that the backups can actually be restored. Ask when they last performed a test restore. A backup that has never been restored is a hope, not a safeguard — and in a ransomware event, hope is expensive.

5. How is security handled — is it baseline or an upsell?

South Africa is a real target — it recorded the highest ransomware detections in Africa in 2024. Endpoint protection, multi-factor authentication, email security, and patching should be part of the baseline, not features sold to you after an incident. Ask what is included by default.

6. Who owns the keys — Microsoft 365, DNS, and admin access?

You should own your Microsoft 365 tenant, your domain, and your admin accounts — with the provider given access, not control. A provider who holds your keys hostage is a provider you cannot leave. Confirm ownership before you hand anything over.

7. Is there a written POPIA operator agreement?

When a provider handles your data, POPIA treats them as an “operator” — and you, the business, remain accountable. The law expects a written agreement obliging them to keep your data secure and to tell you promptly if it is breached. A provider who has never heard of this is a red flag.

8. How do you handle load-shedding and connectivity?

This is the South African question a generic checklist misses. Power loss corrupts data and interrupts backups. A provider who works here should have a view on UPS-backed safe shutdowns, hybrid on-site and cloud backup, and keeping you reachable when the lights go out.

9. Will I get a report I can actually read?

If you cannot see what was done, you cannot tell whether you are paying for anything. A plain-language monthly report — updates applied, threats blocked, backups taken, issues handled — turns an invisible service into an accountable one.

10. Who actually does the work?

Ask who is accountable when something hard happens. A named, technical owner who understands your business beats an anonymous ticket queue every time. This is exactly why we are founder-led: the person responsible for your environment is the person who designed it.

The practical next step

Take these questions to any provider you are considering — including us. The answers will tell you more than any sales deck. If you want a sense of what good looks like, our guide to what managed IT should include and cost lays it out, our whitepaper on what ‘managed’ should actually mean sets the SLA standard to hold any provider to, and a short conversation will tell you honestly whether we are the right fit.

Published 16 June 2026. Last updated 16 June 2026.

Get your IT looked after

Tell us what keeps going wrong, or what worries you. We'll tell you plainly what it takes to fix, before any work starts.