7 Signs Your MSP Is Underperforming (How to Check)
How to Tell If Your MSP Is Underperforming
The honest answer: you usually cannot tell from frustration alone. A bad week of tickets can happen to a good provider, and a quiet month can hide real gaps in security and backups. What separates a genuinely underperforming managed service provider from a temporarily busy one is evidence, and almost all of it is evidence you can pull yourself in an afternoon: SLA reports, patch compliance, MFA coverage, backup test results, invoice history, and documentation.
This article walks through seven concrete signs, how to verify each one without taking anyone’s word for it, and what to do with the results. Some findings justify a direct conversation with your current provider. Some justify a switch. Getting the order right matters, because switching MSPs is disruptive enough that you want to do it once, for the right reasons, with your data and credentials intact. If you are still deciding what a managed relationship should even include, start with our plain-English guide to managed IT services and come back.
The Seven Signs, and How to Verify Each One
| Sign | What good looks like | What to ask for |
|---|---|---|
| Slow or opaque response | Written SLA with times by severity, reported monthly | SLA document + last quarter’s response-time report |
| Recurring problems | Root-cause fixes; repeat tickets trend down | Ticket export grouped by category over 6 months |
| No roadmap or reviews | Quarterly business reviews with a 12 to 24 month plan | Date and notes of your last review |
| Security basics missing | MFA on every account, patch cadence, tested backups | MFA coverage, patch compliance, restore test reports |
| Surprise invoices | Flat fee with named exclusions; projects quoted first | 12 months of invoices vs. the contract’s scope |
| Account team turnover | Stable named contacts who know your environment | Who owns your account, and for how long |
| No documentation | Current network, asset, and credential documentation | A copy of your environment documentation, this week |
1. Slow or opaque response times
The baseline is a written SLA with specific commitments by severity. A good service contract should require the MSP to meet defined standards, such as responding to any critical ticket within 30 minutes. Vague language (“we prioritize urgent issues”) is not an SLA, and an SLA nobody reports against might as well not exist. For calibration: Prevvi publishes a 15-minute median response time and reports performance to clients, and that transparency is the part worth demanding from any provider, whoever you use.
How to verify: ask for the SLA document and the last quarter’s actual response-time report. If the provider cannot produce measured performance against their own SLA within a few days, that is the finding.
2. The same problems keep coming back
A printer that fails weekly, a VPN that drops every Monday, a shared mailbox that detaches itself monthly: individually small, collectively a signal. Recurring tickets mean symptoms are being closed while root causes are not being fixed. The cost side is real: in ITIC’s 2024 survey, over 90% of mid-size and large enterprises put the cost of a single hour of downtime above $300,000. Your number is smaller, but it is not zero, and recurring issues are downtime paid in installments.
How to verify: request a ticket export for the last six months grouped by category or affected system. Three or more tickets for the same root issue without a documented permanent fix is the pattern to look for.
3. No proactive roadmap or business reviews
Managed IT that is purely reactive is break-fix with a subscription price. A functioning MSP relationship includes a recurring business review: ticket trends, security posture, hardware approaching end of life, license renewals, and a forward plan with budget estimates. This is the strategic layer that separates what managed IT services actually cover from a help desk contract.
How to verify: find the date of your last business review and reread the notes. If there was no review in the past six months, or the review was a ticket-count recap with no 12 to 24 month roadmap, the strategic layer of your agreement is not being delivered.
4. Security basics are missing
This is the sign that outranks all the others, because the consequences are not gradual. Three checks, all fast:
- MFA coverage. According to Microsoft’s research, MFA reduces the risk of account compromise by 99.22%. Ask for the report showing which accounts have it enforced. “Most users” is not an answer; the accounts attackers want are the exceptions.
- Patching cadence. VulnCheck found that 28.3% of exploited vulnerabilities were exploited within one day of CVE disclosure in early 2025. A monthly patch cycle with no expedited path for critical vulnerabilities is a decade out of date; for calibration, CISA’s binding directive gives federal agencies two weeks for known exploited vulnerabilities.
- Backup testing. Backups that have never been restore-tested are a hypothesis. Veeam’s 2024 Ransomware Trends Report found victims were unable to recover 43% of the data affected by an attack. Ask for the date and result of the last test restore.
The stakes for small businesses specifically: Verizon’s 2025 Data Breach Investigations Report found 88% of SMB breaches involved ransomware. If any of the three checks comes back empty, treat it as urgent regardless of how well the help desk performs.
5. Surprise invoices and scope disputes
A managed agreement exists to make IT costs predictable. If invoices regularly arrive with line items you did not expect, or routine requests keep getting classified as billable “out of scope” work, either the contract scope no longer matches how your business operates or the provider is monetizing ambiguity. Both are fixable; neither should be tolerated silently.
How to verify: pull 12 months of invoices and compare every non-recurring line item against the contract’s inclusion and exclusion lists. Legitimate extras (projects, hardware) should have been quoted and approved before the work, not discovered on the invoice.
6. Constant turnover on your account
Every time your account changes hands, institutional knowledge of your environment resets, and you pay for the re-learning in slower fixes and repeated questions. Some rotation is normal in any service business. A new face every quarter is not.
How to verify: write down who has worked your tickets over the past year and who currently owns your account. If you cannot name your primary contact, or the answer has changed three times in twelve months, ask the provider directly what is happening on their side.
7. No documentation of your environment
Your MSP should maintain current documentation: network diagrams, asset inventory, license records, admin credential storage, and configuration notes. This is not bureaucracy. It is what makes you portable. A provider that keeps your environment undocumented, or treats documentation as their proprietary property, has made leaving expensive by design.
How to verify: ask for a copy of your environment documentation this week. A mature provider exports it quickly and the contract confirms you own it. Hesitation, or an admission that it lives in one engineer’s head, is one of the clearest underperformance signals there is.
Want a second opinion on what you find? Prevvi runs independent IT environment assessments from our Cambridge, MA headquarters: we document your MFA coverage, patching, backups, and SLA reality in writing, and you keep the report whoever you work with next. Book an assessment.
Some of These Signs Have Innocent Explanations
Honesty requires saying this plainly: not every symptom above means your MSP is failing you. A slow month can be a genuine capacity crunch during a security incident affecting other clients. Recurring tickets sometimes trace to aging hardware you declined to replace, or a line-of-business application the MSP explicitly does not cover. Surprise invoices are sometimes accurate billing for scope you agreed to but forgot. And if your business has doubled headcount since signing, you may have outgrown your service tier rather than your provider.
That is why the verification steps matter more than the feelings. One weak answer is a conversation. A pattern of missing evidence across several categories, especially the security basics, is a different situation.
Have the Fair-Warning Conversation First
If your checks surface real gaps, the right first move is usually not a switch. It is a direct, documented conversation with your provider:
- Bring evidence, not adjectives. Specific tickets, specific invoice lines, the missing reports. “We feel neglected” gets a discount offer; “critical tickets averaged 9 hours against a 1 hour SLA last quarter” gets an action plan.
- Ask for a written remediation plan with owners and dates: SLA reporting turned on, MFA gap closed, a restore test scheduled, a business review on the calendar.
- Set a review window. Sixty to ninety days is fair. Improvement that only lasts while you are watching is its own answer.
This step is worth taking seriously because a provider who responds well saves you a genuinely disruptive transition, and because it builds the paper trail you will want if you do leave. It is also worth asking whether the underlying problem is the outsourcing model itself; our comparison of in-house IT vs. a managed service provider covers when each one actually fits.
How to Switch Cleanly If You Have To
If the window closes without change, switch deliberately rather than angrily. The sequence:
- Reread your contract before saying anything. Note the termination notice period, any early-exit fees, and what the offboarding clause promises.
- Secure admin access first. Before giving notice, confirm you (not only the MSP) hold working global administrator credentials for Microsoft 365 or Google Workspace, your domain registrar and DNS, firewalls, and the backup platform. Recovering access is far easier while the relationship is intact.
- Take ownership of documentation and data. Environment documentation, asset and license inventories, ticket history exports, and confirmation of where backup data lives and how it will be handed over or retained.
- Select the replacement before you resign the incumbent. Vet candidates against the same evidence standards from this article; our list of questions to ask a managed IT provider is built for exactly this, and our managed IT services page shows what a fully specified scope looks like as a reference point.
- Run a short overlap. A two to four week window where the new provider onboards while the old one still answers tickets prevents the gap where nobody owns a live issue.
A professional MSP offboards professionally; most transitions are uneventful. The failure mode to avoid is giving notice first and discovering afterward that you never held your own keys.
The Bottom Line
Underperformance is measurable. Response times, recurring tickets, review cadence, MFA coverage, patch compliance, restore tests, invoice accuracy, and documentation are all things you can check this week, and a provider worth keeping will hand over the evidence without friction. Run the checks, have the honest conversation, and only then decide.
If you want the checks run for you, Prevvi offers an independent IT environment assessment: a written, evidence-based review of your current setup and your current provider’s delivery against it. We run our own operations on multi-agent AI automation, so the assessment work is fast and the findings arrive as a document you own, with no obligation attached. Book your assessment and go into your next provider conversation with the facts already in hand.
Sources
- Microsoft Research: How Effective Is Multifactor Authentication at Deterring Cyberattacks?
- VulnCheck: 2025 Q1 Trends in Vulnerability Exploitation
- Veeam: 2024 Ransomware Trends Report Press Release
- CISA: Binding Operational Directive 22-01
- ITIC: 2024 Hourly Cost of Downtime Report
- Spacelift: Small Business Cybersecurity Statistics (Verizon 2025 DBIR)
- Net Friends: Five Questions to Answer Before You Sign a Managed Services Contract
Frequently asked questions
A written SLA should commit to specific times by severity: critical issues acknowledged within 15 to 30 minutes with immediate triage, standard requests within a few business hours. The key word is written. A provider that will not put response times in the contract, or will not report actual performance against them, is asking you to take service quality on faith.
Pull the evidence rather than relying on impressions: a ticket report showing response and resolution times against the SLA, a patch compliance report, MFA coverage across all accounts, the date and result of the last backup restore test, and notes from your last business review. A healthy MSP produces all five quickly. Gaps in the evidence are themselves the finding.
Usually, yes. Many underperformance patterns trace to a mismatched service tier, an outdated scope, or an account team change the provider can fix once it is named. A direct conversation with specific evidence and a 60 to 90 day window to show improvement is faster and cheaper than switching, and it tells you quickly whether the relationship is fixable.
Full administrator credentials for every system (Microsoft 365 or Google Workspace, firewalls, DNS registrar, backup platform), your complete environment documentation, license and warranty records, and exports of ticket history. Your contract's offboarding clause should already grant these; if it does not, negotiate that before you need it.
Quarterly is the common standard for a strategic review covering ticket trends, security posture, upcoming renewals, and a 12 to 24 month roadmap. Smaller environments sometimes run twice a year. If you cannot remember your last review, or the reviews are just ticket-count recaps with no forward plan, that layer of the service is missing.
Written by
Andrew Wienen Founder & CEO, Prevvi
Andrew is the founder and CEO of Prevvi, a Cambridge, Massachusetts managed IT and AI solutions provider. He is Claude Certified by Anthropic and built the multi-agent AI operation Prevvi runs on, after leading enterprise AI, automation, and Workday Financials programs.
Want this handled for you?
Talk to a real engineer about your environment: no sales script, just straight answers.
