The first ninety days set the pattern for the whole relationship. A provider who spends it firefighting will still be firefighting in year three, because nobody ever stops to fix causes once the pattern is established.
Here is what a good first ninety days actually contains, from both sides.
Weeks 1 and 2: discovery before anything changes
A provider making changes before documenting what exists is guessing, and the first thing that breaks will be something nobody knew depended on the thing they changed.
What should be produced:
- An asset register. Every device, its age, its operating system, its warranty end date. This is what makes replacement a budget line rather than a crisis, as covered in the Windows 10 article.
- A systems inventory. Every application, who uses it, who supports it, when the contract renews.
- Network documentation. What connects to what, and what is exposed to the internet.
- Account ownership. Whose name is your domain in? Your Microsoft tenancy? Your hosting? This one matters enormously and is rarely checked.
- Licence position. What you are paying for and whether anyone is using it.
Every one of these should be visible to you, not held privately by them.
Weeks 3 and 4: stabilise
Now the immediate risks, in a deliberate order.
- Monitoring. So problems are found before users report them.
- Patching. Automated, scheduled, reported.
- Backups verified. Not "backups are configured" — a restore performed and timed. If the answer to when did you last restore something is vague, that is the first job.
- The obvious security gaps. Multi-factor authentication everywhere, exposed remote access closed, administrator accounts separated from daily-use ones. The list in ten settings to turn on covers most of it.
You should expect a report at the end of the first month saying what was found and what was fixed. Including the uncomfortable findings — a provider who reports only good news is not reporting.
Weeks 5 to 8: fix causes
The stage that distinguishes a good provider from a competent one.
By now there is a month of ticket data. It will show patterns: one machine generating a quarter of the calls, one application everybody struggles with, one process that goes wrong every month.
A good provider brings you that analysis unprompted and proposes fixing the causes. A poor one keeps handling the tickets, because handling tickets is what they are paid for and fixing causes reduces the work.
Ask to see your ticket volume by category at week eight. If nobody has looked at it, nobody is going to.
Weeks 9 to 12: plan
The end of the first quarter should produce a written plan for the next twelve months, with costs.
It should cover:
- Device replacement, by quarter, with figures.
- Renewals — licences, certificates, contracts, warranties — with dates.
- Security improvements, prioritised, with what each addresses.
- Projects worth doing and roughly what they cost.
- Risks you are currently carrying, stated plainly.
That last section is the test. A provider willing to write down the risks you are running — including the ones you have declined to spend money on — is a provider you can trust. One who presents everything as fine is either not looking or not telling you.
What you should be able to see by day 90
- A complete inventory of what you own
- Monitoring and patching running, reported
- A tested restore, with a date
- The obvious security gaps closed
- A costed plan for the next year
- Ticket volume starting to fall
Warning signs
Silence between incidents. A good provider contacts you about things you did not ask about — a certificate expiring, a licence you no longer need, a machine approaching end of support.
You cannot see what they are doing. No reporting, or reporting that is technical rather than useful. A report you cannot understand is not a report.
Accounts in their name. Your domain, your tenancy, your hosting. If they hold ownership rather than delegated access, you cannot leave without their cooperation.
Recurring problems. The same issue every month, handled every month, cause never addressed.
Everything is extra. A managed contract where each request generates a quote is a break-fix arrangement with a retainer attached.
Your side of it
Three things make the relationship work, and they are your responsibility.
Give them access properly. Half-access produces half-service, and a provider working around missing permissions cannot be held to a standard.
Tell them what the business is doing. New office, new staff, a big contract, a system change. Technology decisions made without that context are guesses.
Have one voice. A named person on your side who makes decisions. Providers taking instructions from six people build something incoherent.
If you would like to know how your current arrangement compares, our technical support team is happy to give an honest second opinion with no obligation to move. Get in touch.








