- The most common source of dispute with managed IT providers isn't a technical failure — it's a disagreement about what was actually included.
- An MSP with access to your network typically has access to a great deal of sensitive information — employee records, customer data, financial systems.
- Confirm, in writing, that your business data always remains your property, and that the agreement sets out exactly how you get it back — in what format, through what process — if you…
Outsourcing your IT support to a managed services provider (MSP) can save a growing business the cost and hassle of building an internal IT department. But you're also handing a third party access to your systems, your data, and — often — your ability to keep operating if something goes wrong. The contract you sign before onboarding an MSP deserves more scrutiny than most businesses give it.
Start With a Clear Scope of Services
The most common source of dispute with managed IT providers isn't a technical failure — it's a disagreement about what was actually included. A vague scope, such as simply "IT support services," leaves room for the provider to treat anything beyond routine maintenance as extra, billable work. Before signing, get a detailed description of:
- Which systems, devices, and software are covered
- What counts as included support versus a chargeable project
- Response and resolution expectations, often set out in a service level agreement attached to the main contract
- Whether the provider proactively monitors your systems or only responds when you report a problem
Data Security and Confidentiality
An MSP with access to your network typically has access to a great deal of sensitive information — employee records, customer data, financial systems. The agreement should address:
- Confidentiality obligations covering everything the provider sees or accesses
- Security standards the provider commits to maintaining
- A defined obligation to notify you promptly if the provider discovers or causes a security incident affecting your data
- How the provider's handling of any personal information fits with your own obligations under federal privacy law (PIPEDA), since you may remain responsible to your own customers and employees even if a breach originates with your provider
Data Ownership and Return on Termination
Confirm, in writing, that your business data always remains your property, and that the agreement sets out exactly how you get it back — in what format, through what process — if you switch providers or the relationship ends. A provider with no obligation to cooperate on transition can effectively hold your data hostage during a difficult exit.
Subcontracting
Many MSPs subcontract parts of their service — hosting, backup, help-desk overflow — to other vendors. Ask whether the agreement permits subcontracting, whether you'll be told who the subcontractors are, and whether the MSP remains fully responsible to you regardless of who actually performs the work.
Pricing Structure
Managed IT pricing typically follows one of a few common models:
- Flat monthly fee — predictable cost, usually per user or per device, covering defined services
- Tiered packages — different service levels at different price points, with clearly defined upgrades
- Time and materials — billed for actual hours worked, which can create unpredictable costs without a cap or estimate process
Whichever model applies, make sure the contract clearly states what triggers additional charges beyond the base fee.
Liability, Insurance, and Termination
- Liability caps. Most MSP agreements cap the provider's liability, often at a modest multiple of fees paid — consider whether that's adequate given how dependent your business is on the systems they manage.
- Insurance. For a business with significant IT dependency, consider requiring the provider to carry appropriate liability and cyber insurance.
- Termination and transition. Look for a defined transition-out period and the provider's obligation to cooperate with an orderly handoff to a new provider, rather than a clause that lets them walk away immediately.
Frequently asked questions
What should I do before signing with a new MSP?
Get the scope of services, pricing structure, data ownership terms, and liability provisions in writing and reviewed before you sign, not after onboarding has already started and switching becomes disruptive.
Who is liable if our MSP causes a data breach?
This depends heavily on what the contract says. Well-drafted agreements allocate responsibility for breaches caused by the provider's negligence, but you may still owe notification and other obligations to your own customers and employees under federal privacy law regardless of whose systems failed.
Can we switch providers mid-contract if the service is poor?
Only according to whatever termination rights the contract gives you — for cause, for convenience, or not at all before the term ends. This is why termination and transition terms deserve attention before you sign, not once you're unhappy.
Is a verbal understanding with our IT provider enforceable?
Most commercial agreements don't strictly need to be in writing to be enforceable, but an unwritten understanding is very difficult to prove and rarely covers the details — liability caps, data ownership, response times — that actually matter when something goes wrong. Get it in writing.
This is a corporate question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.