Business IT Assurance
Don't Take Our Word for It: How to Check Whether Your IT Provider Is Competent
A practical, evidence-led way to assess the people responsible for your systems — including us.
10 min read — Altitude IT Support
Choosing an IT Provider Involves a Lot of Claims
Choosing a qualified IT support provider can feel like comparing a wall of logos. Microsoft expertise. Cyber security knowledge. Years of experience. Vendor partnerships. Accreditations. Specialist capability. Every provider has a story to tell.
But a claim is not the same thing as evidence. A company can display a technology logo without showing who will work on your systems. A reseller relationship can help with licensing without proving that the people administering your Microsoft 365 tenant understand identity, permissions or security configuration. A qualification can show useful knowledge without proving experience in the work you are considering.
A sensible customer should ask for evidence and decide whether it is relevant to the job. That is how to check an IT company without getting distracted by badge collecting or marketing language.
A wall of technology logos is not evidence of competence. Ask who will actually work on your systems, what they can prove and how current that knowledge is.
Altitude IT encourages customers and prospects to apply exactly the same standard to us. You should be able to ask what we know, what we have done, what we can show and where our competence ends.
The “Show Me” Test
The IT Club’s independent framework is a useful starting point for any business assessing an IT provider:
- Claim — What is the provider saying they can do? Define the proposed work rather than accepting a broad phrase such as “we do everything”.
- Evidence — What can they actually show? This might include current certificates, anonymised project examples, a sample report, references or an explanation of their working process.
- Relevance — Does the evidence relate to the work being proposed? A networking qualification is not automatically evidence of Microsoft 365 identity experience, and a sales partnership is not proof of secure administration.
- Recency — Is the knowledge current? Cloud platforms, attack methods, licensing and security controls change continually.
- Experience — Have the people involved delivered this in real environments, with the constraints and unexpected problems that real businesses bring?
- Assurance — What wider safeguards exist? Look for documentation, access controls, change records, backup and recovery practices, escalation routes and a clear handover process.
For the fuller independent explanation of this framework, read the IT Club guide to checking whether an IT provider is qualified and competent. This Altitude IT article applies the same test to the practical questions a customer can ask us or any other provider.
Apply the Same Test to Us
Altitude IT should be judged on the same basis as any other competent IT support company. The useful question is not whether we can produce the biggest list of logos. It is whether the people doing the work have relevant knowledge, practical experience, current understanding and a process that leaves the customer in control.
Microsoft Knowledge Is More Than a Logo
For Microsoft 365 IT support, ask who will actually administer the tenant and what they can show. Where relevant, Altitude IT should be able to discuss current individual Microsoft certifications, practical Microsoft 365 work and the specific experience behind the proposed service.
These are different things:
- An individual holding a current Microsoft certification;
- A company using a Microsoft logo on its website;
- A reseller or vendor relationship that helps supply licences or products; and
- Technical competence in the Microsoft 365 work your business actually needs.
One certification does not prove expertise in everything Microsoft makes. Equally, the absence of a logo does not settle the question. Ask which person’s knowledge is relevant, how it is kept current and what practical work supports the claim.
Cyber Security Needs Precise Language
A cyber security IT provider should be able to explain the relevant qualifications, practical work and current understanding behind its recommendations. It should also be clear about what a particular standard or service does and does not prove.
Cyber Essentials is a useful UK government-backed baseline for common technical controls. Preparing for certification can expose gaps in supported software, access control, secure configuration and malware protection. Passing Cyber Essentials does not prove that a business has solved every cyber security risk, nor does it by itself prove that a provider can design or operate every security control.
Altitude IT can help businesses prepare for Cyber Essentials and improve the surrounding controls. That is different from claiming to be the independent certification body or assessor. The distinction matters because customers deserve to know who is advising them and who is making the certification decision.
Microsoft 365 and Identity Experience
Technical competence should connect to the systems your people use every day. A provider offering Microsoft 365 support should be comfortable explaining its practical experience with areas such as:
- Microsoft 365 administration and licensing;
- Microsoft Entra ID and identity lifecycle;
- multi-factor authentication and recovery;
- Conditional Access policy design;
- Microsoft Defender and security configuration;
- endpoint and device management;
- SharePoint, Teams and OneDrive permissions;
- privileged access and administrator accounts; and
- documentation, change control and access review.
You do not need a provider to recite every product feature. You do need a provider that can explain what is configured, what is not, what the risk is and what the next sensible action would be. A Microsoft 365 support provider in Manchester should be able to relate its advice to how your organisation actually works.
Practical Experience Matters
Certifications matter, but real-world delivery matters too. Ask whether the provider has worked through the messy parts: incomplete documentation, old devices, conflicting permissions, unreliable backups, unclear ownership, a difficult migration window or a supplier who has stopped responding.
Altitude IT’s published case studies show the kind of evidence customers can inspect:
- A review that found duplication in a small business IT bill, rather than accepting every product as necessary;
- Cyber Essentials remediation where apparently updated devices still needed targeted investigation;
- Domain recovery and business continuity work after administrative control was lost; and
- Comparative troubleshooting that isolated a telecoms firewall problem and provided the evidence needed to resolve it.
These examples do not prove that any provider can solve every future problem. They show the kind of practical reasoning, evidence and communication a customer should ask to see.
Current Knowledge Has a Time Dimension
IT knowledge expires. Microsoft changes its identity and security controls. Attackers change their methods. Products are retired, renamed or bundled into different licences. A qualification from many years ago may show valuable background knowledge, but it does not answer what the provider is learning and working with now.
Ask what the people supporting your business have renewed, studied, tested or delivered recently. Ask how they track changes that could affect your tenant, devices, backups or security posture. Technical credibility is not a one-time event; it has a time dimension.
A Competent Provider Knows Where Its Competence Ends
No provider is expert in every technology. A provider that claims otherwise is giving you a reason to ask more questions, not fewer.
Sometimes specialist knowledge, additional resources or boots-on-the-ground support are appropriate. Altitude IT may work with trusted specialist partners where that is the safest way to deliver the required outcome. The important questions are whether the partner’s role is clear, who remains accountable, how access is controlled and what documentation the customer receives.
Knowing when to bring in another specialist is not a weakness. It is risk management. The weakness is pretending to have capability that is not there and discovering the boundary during an incident.
Customer Control Is Part of Competence
A technically capable provider can still create unnecessary risk if the customer cannot see or control the environment. Before appointing an IT provider, or while reviewing an existing relationship, ask:
- Who has administrator access today?
- Which accounts, licences and domains belong to the business?
- Are there secured customer-owned administrator accounts with MFA and documented recovery?
- Who controls the Microsoft tenant, domain, DNS and backups?
- Is documentation available if the provider changes?
- What happens to privileged access, licences and data when the relationship ends?
- Can another competent provider take over without starting from zero?
The customer should retain appropriate ownership and visibility of core systems. Provider access may be necessary; provider-held exclusive control is a dependency worth examining. A Microsoft 365 Tenant Ownership Review can help establish who controls the tenant, licensing and administrative access before a change is attempted.
Our Evidence
Here is the standard we believe customers should apply to Altitude IT. We should be able to explain the relevant evidence for the work proposed, and we should be equally clear when a question needs a specialist partner or a different type of review.
| What we claim | What customers should be able to see |
|---|---|
| Microsoft knowledge | Current relevant individual certifications where held, plus practical Microsoft 365 experience. |
| Cyber security capability | Relevant qualifications, clear Cyber Essentials boundaries and examples of real security work. |
| Microsoft 365 experience | Practical tenant, identity, security, permission and endpoint work related to the proposed service. |
| Business IT experience | Long-term practical delivery, references where appropriate and relevant case studies. |
| Current technical knowledge | Current certifications, renewals, training and active work with changing platforms and threats. |
| Specialist capability | Clear use of specialist partners where appropriate, with roles, accountability and handover explained. |
| Customer outcomes | Real case studies, evidence of work completed and improvements that can be explained rather than vague promises. |
Questions to Ask Before You Choose
If you are comparing providers, ask each one the same questions. Consistency makes the answers easier to compare.
- Who will actually work on our systems, and who checks their work?
- Which qualifications and certifications are current and relevant to this proposal?
- Can you show an anonymised example of a similar project and its deliverables?
- How do you keep knowledge current as Microsoft, security threats and licensing change?
- What will you document, and can we access it if we change provider?
- Which accounts and systems remain owned and controlled by us?
- Which parts of this work would you refer to a specialist partner?
- What would you say you do not know or do not provide?
The answers do not need to be perfect on the first call. They should be specific, proportionate and open to checking. Evasion, unexplained jargon or a refusal to distinguish a partner relationship from technical delivery are useful signals too.
Don’t Just Ask Us
Don’t just ask us. Ask your current IT provider the same questions.
A good IT relationship should survive reasonable scrutiny. You should know who is responsible for your systems, what they can prove, how current their knowledge is, what happens when something falls outside their competence and how you retain control of your business technology.
That standard is not anti-provider. It is a sensible way to protect the business and make sure the service you are paying for is relevant, accountable and based on more than a collection of logos.
If you are reviewing Manchester IT support, Stockport IT support or a provider serving your wider business, start with the evidence. Ask what is being done, who is doing it and what you will receive to show it happened.
Altitude IT provides business IT support in Manchester and the North West, alongside cyber security services and practical Microsoft 365 reviews. The right starting point depends on the evidence your business needs to establish.
Frequently Asked Questions
How do I check whether an IT provider is competent?
Start with the claim, then ask for evidence. Check whether it is relevant to your proposed work, current, based on real experience and supported by sensible assurance such as documentation, access controls and a clear handover process.
What qualifications should an IT support provider have?
There is no single qualification that proves competence in every area of IT. Ask for current, relevant individual qualifications and certifications, then compare them with the practical work, systems and risks involved in your business.
Does a Microsoft partner logo prove technical competence?
No. A logo may indicate a commercial or reseller relationship, but it does not identify who will administer your systems or prove their technical competence. Ask for the relevant person’s current knowledge and practical Microsoft 365 experience.
Does Cyber Essentials prove that an IT provider is a cyber security expert?
No. Cyber Essentials is a baseline for common technical controls and a certification decision is separate from general cyber security expertise. Ask what relevant security work, qualifications and current understanding sit behind the provider’s recommendations.
Why does the recency of IT qualifications matter?
Cloud platforms, licensing, vulnerabilities and attack methods change quickly. Older qualifications can show useful foundations, but they should be combined with evidence of current learning, renewals, practical work and awareness of recent changes.
Should my IT provider have administrator access?
Provider access may be necessary to deliver support, but the customer should understand who has it and retain appropriate ownership and visibility. Your business should have secured customer-owned access, MFA, recovery information and documentation rather than relying on a provider-held exclusive account.
Is it a problem if an IT provider uses specialist partners?
Not necessarily. Specialist partners can be the safest option when a requirement falls outside the provider’s core competence. Ask who is accountable, what access the partner receives, how the work is documented and how the result is handed back to you.
What should a competent IT provider be willing to show?
They should be willing to discuss relevant current qualifications, practical examples, proposed deliverables, working processes, customer ownership, documentation, security arrangements and the boundaries of their competence. Evidence should relate to your actual needs rather than just a general capability list.
Can Altitude IT review my current IT provider or setup?
Altitude IT can review the practical technology, security, access, ownership and provider arrangements around your business. We will distinguish between evidence that can be checked, questions that need more information and specialist work that should be referred rather than overstated.