Every MSP sales call in New York covers the same ground: responsiveness, proactive support, security focus. The calls are rehearsed and largely interchangeable. Agreements are where providers actually differ, and the way to see the differences before you sign is to ask questions the rehearsal did not prepare for. Here are twelve, with the reason each one matters and the answer that should worry you. They apply whether you are buying fully managed IT or adding a provider around an internal team.
Scope and money
1. What exactly is out of scope, and what does each item cost?
Published benchmark guides report that out-of-scope charges commonly add 30 to 50 percent over the headline rate, which makes this the most expensive question on the list. Ask for the out-of-scope schedule in writing. The answer that should worry you: “everything’s included,” with no written schedule behind it — that usually means the categories will be decided later, by them.
2. What does a security incident cost under this agreement?
Some agreements treat incident response as covered work; others treat it as a billable emergency at premium rates, which means your worst day is also your most expensive invoice. Worry if: the answer is “we’ve never had to deal with that.”
3. What happens at renewal, and does the agreement auto-renew?
Auto-renewal with a generous notice window is common and defensible. Auto-renewal with a price escalator and a narrow exit window you were not told about is a trap. Read the term clause together, aloud. Worry if: the salesperson has to look it up.
4. What does onboarding involve, week by week?
Competent onboarding is a checklist: inventory, credential custody, monitoring deployment, backup verification, documentation. It has dates and deliverables. Worry if: the answer is a mood — “we’ll hit the ground running” — rather than a plan you can hold them to.
Security and compliance
5. Who reads the security alerts, and what happens at 2 a.m.?
Tooling that watches continuously is table stakes; the question is what happens when it fires. Ask them to walk one real alert from detection to human action, including who gets woken up. Worry if: the answer claims a staffed around-the-clock SOC but cannot describe the shift structure, or conflates “the software is always on” with “someone is watching.” Precision here predicts honesty everywhere else.
6. What does NYDFS Part 500 — or HIPAA, or the FTC Safeguards Rule — require of a firm like mine?
If you are regulated, your provider is part of your compliance posture. A provider serving New York financial firms should know without notes that Part 500 requires an annual certification filed by April 15, and that the small-business MFA exemption ended on November 1, 2025. One serving CPA firms should be able to name the Safeguards Rule’s nine required elements. Worry if: the answer is “we handle compliance” with no specifics — the regimes are public documents, and fluency is checkable.
7. What will you hand my insurer, auditor, or client questionnaire?
Renewal applications and client security questionnaires ask for evidence: MFA enforcement, endpoint detection coverage, backup test results. Ask to see a sample report, and ask whether producing it is in scope. Worry if: reporting is an upsell, or the sample is a screenshot of a dashboard.
8. When was my backup last restored — and who watched it succeed?
A backup that has never been through a restore is a hypothesis. A provider should verify restores on a schedule and be able to show you the record; this is the core of how we treat business continuity. Worry if: the answer describes the backup software rather than the last successful restore.
Operations and exit
9. Who owns my documentation, credentials, and configurations?
The correct answer: you do, at all times, with the provider acting as custodian. Worry if: documentation is described as proprietary, or administrative credentials live only in their vault.
10. How do you work with an internal IT team?
If you have internal IT, you are buying reinforcement, not replacement. A real co-managed practice has defined duty splits, shared ticket visibility, and escalation paths in writing. Worry if: co-managed is treated as a stepping stone toward taking over the account.
11. Which parts of the service are subcontracted?
Help-desk overflow, after-hours coverage, and security monitoring are commonly outsourced downstream. That can be fine — but you should know who answers, and the agreement should say who is accountable. Worry if: the question causes visible discomfort.
12. What does leaving look like?
Ask for the offboarding process before you onboard: what is handed over, in what format, at what cost, on what timeline. A provider confident in its service makes leaving boring. Worry if: exit terms are vague, or exit assistance is billed at a rate designed to discourage the question.
What to do with the answers
Take notes, then do two things. First, get the material answers — the out-of-scope schedule, incident pricing, exit terms, reporting samples — appended to the agreement, because a sales answer that cannot survive being written down was not an answer. Second, weigh precision over polish: the provider who says “our tooling monitors continuously and pages an engineer” is telling you more truth than the one who promises everything, instantly, forever.
If you want a baseline to negotiate from, a scoped IT and security assessment documents your current environment first — which also makes every quote you receive afterward easier to check.