Skip to main content
Dig IT Solutions logo

Managed IT Support

Signs of bad IT support: 15 red flags, the response-time benchmarks that expose them, and what to do

The signs of bad IT support: slow response, recurring faults, no patching reports, no documentation, hidden fees. With SLA benchmarks and what to do about it.

By Dig IT SolutionsUpdated 8 September 20267 min read

Short answer

The clearest signs of bad IT support are response times measured in days rather than hours, the same faults recurring without a root-cause fix, no reports on patching or backups, no documentation of your systems, hidden charges, and a provider you only hear from when something breaks. Benchmark them against a written SLA, and if several persist, plan a change.

Bad IT support rarely announces itself. It shows up as a slow drift: tickets take a little longer, the same problems come back, nobody mentions security, and one day the backup that "was running" turns out not to have been. This guide lists the signs, gives you benchmarks to measure your provider against, explains why the cost is larger than the annoyance, and sets out what to do if you conclude the provider is the problem.

The 15 red flags

1. Slow response has become normal. Urgent issues wait hours for a human and days for a fix. You chase as routine.

2. Recurring faults are never fixed at the root. Wi-Fi drops, printers disappear, Outlook keeps asking for a password. Each time it is patched, never investigated.

3. Nothing is proactive. You have never seen a patching report, a backup test result or a note about hardware going out of warranty. The provider only appears when something breaks.

4. Security is not on the agenda. No MFA rollout, no EDR, no email filtering, no awareness training, no discussion of Cyber Essentials. If you have to ask, that is the answer.

5. Communication is poor. Jargon instead of explanation, vague updates, silence during incidents, and no post-incident summary.

6. Hidden charges. Invoices for things you thought were included, with no rate card and no prior approval.

7. No documentation. Ask for a network diagram, a device inventory or a list of admin accounts and nothing arrives.

8. No performance metrics. The provider cannot tell you its response times, ticket volumes or SLA performance for your account.

9. Your staff are the helpdesk. People fix their own problems, or ask the office manager, because it is faster than logging a ticket.

10. A different engineer every time. High turnover means your systems are relearned from scratch on each call.

11. Blame instead of accountability. Problems are the ISP's fault, the software vendor's fault, your users' fault. Never the provider's.

12. Limited availability with no emergency route. The phone goes to voicemail at 5.31pm and there is no defined process for a genuine emergency.

13. Outdated knowledge. Resistance to cloud, Microsoft 365, modern security tooling or remote working, and a preference for the way things were set up in 2015.

14. No strategy. No account reviews, no plan for hardware refresh, no advice on what to change as you grow.

15. You feel like an account, not a client. No named contact, no understanding of your business, no interest in it.

Two or three of these and the service needs a formal conversation. Five or more and you are paying for break-fix at managed prices.

Benchmarks: what to measure against

The most useful thing you can do is stop relying on impressions and measure.

Response and resolution

Pull the last three months of tickets. For each, note the priority, how long until a human responded, and how long until it was resolved. Compare with the SLA in your contract. If there is no SLA table in the contract, compare with the targets commonly seen in UK business-hours managed contracts:

PriorityDefinitionCommonly seen response target
P1Whole business or critical system downWithin 1 hour
P2A team or key function stoppedWithin 2 to 4 hours
P3One user affected, or a workaround existsWithin 1 working day
P4Request or questionWithin 2 working days

These are market observations, not a promise about any provider, and faster is available at a price. The point is the gap between your data and any reasonable target. A P1 that waited four hours for a callback is a failure under any SLA worth signing. The mechanics are explained in what an IT support SLA is.

Proactive work

Ask for three documents: the last patching report for your devices, the last backup restore test result, and the current device inventory with warranty dates. A managed provider produces all three from its tools in minutes. If any of them cannot be produced, the work is not being done.

Security posture

Ask five questions drawn from the NCSC's Cyber Essentials controls: Is MFA enforced on every Microsoft 365 account? Is EDR or managed antivirus on every device? Are updates applied within a defined period of release? Have leavers' accounts been disabled? Is the firewall on supported firmware? Five yeses is a managed environment. Five "I'll check" is not.

Recurrence

Count how many tickets in the last three months were the same problem for the same user or system. More than two repeats of anything means nobody is doing root-cause analysis.

Why bad support costs more than it annoys

The frustration is visible. The cost is not, which is why businesses tolerate it.

Downtime lands on your payroll. Twenty people waiting two hours for a fix is 40 staff hours, whatever the IT bill says. The arithmetic is in why unresolved IT issues become expensive.

Unmanaged systems are exposed systems. Reactive support usually means unpatched devices, no MFA, untested backups and no monitoring. That is the environment in which a phishing email, which the GOV.UK Cyber Security Breaches Survey consistently finds to be the most common attack on UK businesses, becomes a compromised mailbox or a ransomware event.

Data loss is permanent. A backup that was never tested is a backup that may not restore. Nobody finds out until the day it matters.

Compliance is undocumented. When a client, insurer or the ICO asks where your data is, who has access and when backups were tested, a provider with no documentation cannot help you answer.

Emergency spend. Hardware bought the day it fails, engineers called out at premium rates, and rebuilds under pressure.

Staff morale and turnover. People who fight their tools every day leave.

Missed improvements. A provider with no strategy never suggests the cloud migration, the network refresh or the phone system change that would save you money.

Spotting it early: questions for a prospective provider

The cheapest time to spot bad support is before you sign. Ask these at the consultation and listen for specifics.

  • What is your SLA by priority, and is it in the contract? Vague answers mean no SLA.
  • Show me a patching report and a backup test result for an existing client, anonymised. If they cannot, they do not produce them.
  • Who will I speak to when I call, and how many clients does that person look after? An overloaded helpdesk is slow by design.
  • What documentation do you hand over on exit, and at what cost? Hesitation here predicts trouble later.
  • What did you find in your last three onboardings? A provider that finds nothing is not looking.
  • How do you handle a problem that recurs three times? The answer should involve root-cause analysis, not "we'll fix it again".

The full list of questions is in how to choose an IT support company.

Is it the provider, or is it your systems?

Sometimes the systems are genuinely old and the provider is doing its best. Three tests separate the two.

Has the provider told you? A good provider on a poor estate will have written to you, more than once, about what needs replacing and why. If the first you hear of ageing hardware is when it fails, the provider was not managing it.

Are the failures explained? Old systems fail in explicable ways. A provider who can tell you the root cause of each incident is managing. One who shrugs is not.

Is there a plan? A refresh schedule, a budget, a priority order. If not, the age of the systems is a symptom of the support, not an excuse for it.

What to do if your IT support is the problem

  1. Gather evidence. Ticket history, response times, recurring issues, missing reports, invoices for unexpected charges.
  2. Raise it formally. In writing, with reference to the contract and SLA, listing the specific failures and asking for a written response and a plan within a defined period.
  3. Get an independent view. An IT health check from another provider will tell you what is and is not being done, without obligation.
  4. Read your contract. Notice period, renewal window, exit terms, termination-for-breach. Details in what to look for in an IT support contract.
  5. Choose the replacement before serving notice. The order matters. See how to switch IT support provider.
  6. Run an overlap. Keep both providers under contract for a short period while credentials, documentation and monitoring move across. The changeover itself typically takes up to 2 days.

Businesses that go through this usually say the handover was less disruptive than they feared. The harder part was deciding.

What to do next

If several of the red flags apply and you would like an independent check before you act, an IT health check reviews monitoring, patching, security, backups and documentation and tells you plainly what a managed service should already be doing. It gives you evidence for the conversation with your current provider, or for the decision to move.

Frequently asked questions

How do I know if my IT support company is bad?
Measure them against their own contract. Pull the last three months of tickets and note how long each waited for a human response and for a fix, by priority. Ask for the latest patching report and backup test result. Ask for your network documentation. If response is routinely slower than the SLA, the reports do not exist and the documentation is missing, the service is not being managed, whatever the invoice says.
What is a reasonable response time for IT support?
For a UK business-hours managed contract, commonly seen targets are an engineer starting on a whole-business outage within an hour, a team-level issue within two to four hours, a single-user problem within a working day and a request within two. The number matters less than whether it is in the contract, measured and reported. A provider with no SLA table has nothing to be measured against.
Is it normal for IT problems to keep coming back?
No. Occasional faults are normal. The same Wi-Fi dropout, printer disappearance or Outlook password prompt recurring every few weeks means the symptom is being patched and the cause is not being found. A managed provider should notice the pattern in its ticket history and investigate. If you are the one noticing the pattern, nobody is managing your systems.
Can bad IT support be dangerous, or just annoying?
Dangerous. Slow, reactive support usually goes with unpatched systems, no MFA, untested backups and no monitoring, which is the environment in which a phishing click becomes a ransomware event and a failed disk becomes permanent data loss. The annoyance is visible. The risk is not, until it lands, and by then the cost is a multiple of years of support fees.
What should I do if I think my IT provider is the problem?
Gather evidence: tickets, response times, unresolved issues, missing reports. Raise it formally in writing with reference to the contract and SLA, and give a defined period for improvement. Ask an independent provider for a health check to confirm what is and is not being done. If the formal conversation changes nothing, read your notice and exit terms and start choosing a replacement before serving notice.
Why do businesses stay with bad IT support for so long?
Because the problems feel tolerable individually, switching feels risky, and the true cost sits in staff time and unrealised risk rather than on an invoice. Loyalty to a provider who was good years ago also plays a part. The businesses that switch usually say the same thing afterwards: the handover was easier than they feared and they should have done it a year earlier.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us