Short answer
To choose an IT service provider, start with your own needs: workstations, systems, sensitive data and how much downtime you can live with. Then insist on a written scope, measurable service levels, proven security practices, a contract that meets Quebec's Law 25 and a clear exit clause. The right provider answers each point precisely, in writing.
This guide is for information only and is not legal advice.
When you hand your IT over to an outside company, you give it the keys to your systems and, very often, to the personal information of your customers and employees. The Canadian Centre for Cyber Security puts it plainly in its guidance for managed services customers: "Your organization is the data owner and is legally responsible for data security." You can delegate the work, but not the accountability. The steps below will help you make a sound, well-documented decision.
Before you start: describe your environment and needs
A provider can only commit to what it understands. Gather a few basics first, and the quote you receive will be far more precise.
- Your inventory: workstations, mobile devices, servers, business-critical software, cloud services and network equipment.
- Your sensitive data: personal information about customers or employees, financial records and trade secrets. Note where this data lives today and who needs access to it. The Cyber Centre recommends identifying which data the provider will be able to access, and how sensitive it is, before you sign anything.
- Your hours and locations: business hours, evening or weekend work, remote staff, number of sites and employees on the road.
- Your tolerance for outages: for each key system, how long can the business run without it, and how much data could you afford to lose? Those two answers drive your backup schedule and the service levels you should ask for.
If someone on your team already looks after IT, write down what that person will keep doing. Clear roles prevent grey areas later.
The criteria that matter most
A written scope: what is in and what is out
The scope spells out what the provider takes on: user support, monitoring, updates, backups, security, accounts and licences, and the network. It should also name what is excluded or billed separately, such as projects, hardware purchases or on-site visits. A vague scope is a frequent source of misunderstandings. For ongoing support, you can get a quote for managed IT and IT support based on your description.
Measurable service levels: response or resolution, priorities, coverage hours
A service level agreement (SLA) turns your expectations into commitments you can measure. The Cyber Centre is specific: "Your service level agreement with the service provider should specify the expected turnaround times, communication media, escalation processes, metrics for assessing performance, and penalties for not meeting turnaround times."
Make the distinction between response time, when someone starts working on your request, and resolution time, when the service is working again. Both should vary by priority level, defined in writing, and apply to coverage hours that match the way your business actually runs.
Security: least privilege, two-factor authentication and logging
A provider that manages your IT often holds the keys to every system you have. ITSM.50.030 sets out the basic principle: "Access control should be based on the principle of least privilege, meaning that individuals should only have the privileges that they need to perform their work functions."
In practice, ask that each technician use a named administrator account, separate from their everyday account and protected by two-factor authentication, and that administrator actions be logged. The Cyber Centre's baseline controls for small and medium organizations also call for two-factor authentication on cloud administrative accounts, with passwords that differ from those used on your internal network. If security is the heart of your project, see our cybersecurity page.
Backup and disaster recovery: frequency, tested restores, where copies live
A backup is only worth something if you can restore it. Set the backup frequency according to how much data you can afford to lose, decide how long copies are kept and how often restores are tested, and ask for a written report of each test. The Cyber Centre is clear on location: "Best practice is that back-ups should not be stored in the same place as operational data." Your disaster recovery plan should also state who does what when a major system goes down.
Data location and Quebec's Law 25 (sections 17 and 18.3)
Ask where your data, backups and logs are hosted, and where the administrators work from. The Cyber Centre's baseline controls list both of these locations among the points to consider.
Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, adds legal requirements. Under section 17, "Before communicating personal information outside Québec, a person carrying on an enterprise must conduct a privacy impact assessment." The information may be communicated if the assessment shows it would receive adequate protection, and the communication must be the subject of a written agreement. The same rule applies when you entrust a person or body outside Quebec with keeping that information on your behalf. Under section 18.3, a service contract involving personal information must be in writing and set out the required safeguards. The Commission d'accès à l'information also reminds businesses that when they entrust personal information to a third party for safekeeping, they remain responsible for all of their obligations if a confidentiality incident occurs. If you are considering cloud hosting, our cloud services page describes that type of project.
Security attestations: SOC 2, SOC 3 and ISO 27001
Some providers can show attestations produced by an independent third party. A SOC 2 report evaluates an organization's information systems with respect to security, availability, processing integrity, confidentiality or privacy. A SOC 3 report confirms compliance without giving details on the controls used, which is why providers are more willing to hand it out. ISO/IEC 27001, for its part, is a standard for information security management.
These documents are useful, but they are not a must for a small business engagement. If a provider has none, ask it to describe its security practices in writing.
Data portability and exiting the contract
The Cyber Centre's advice is simple: "Your organization should consider an exit strategy, in case the need arises, when entering a service contract." The contract should confirm that you keep ownership of your data, specify the formats in which it will be returned, describe the help you get during the transition and require the provider to destroy its copies when the contract ends.
Reporting and a named contact
Ask for regular reports in plain language: requests handled, service levels met, status of updates and backups, incidents and recommendations. Insist on a named contact person who knows your business. For one-off work such as an office move or a server replacement, see our IT projects page.
Questions to ask before you sign
These questions are adapted from the checklists in ITSM.50.030. Ask for the answers in writing.
- Which services are included in the agreement, and which are billed separately?
- What are your response and resolution times for each priority level, and what penalties apply if they are missed?
- What hours do you cover, and how do we reach your team in an emergency?
- What access to our networks, systems and data do you need to deliver your services?
- Do your technicians use named administrator accounts, separate from their regular accounts and protected by two-factor authentication?
- Can you provide an audit trail of every action your administrators take in our systems?
- Where will our data, backups and logs be stored, and where do your administrators work from?
- How often is our data backed up, and how are restores tested?
- How, and how quickly, will you notify us of a security incident that affects our data?
- Would you be willing to run an incident or disaster recovery exercise with us?
- Do you use subcontractors for any part of the service, and how do you control their access?
- Has an independent third party assessed your organization, for example through a SOC 2 or SOC 3 report or ISO/IEC 27001 certification?
- Do we keep ownership of our data, and in what formats will it be returned when the contract ends?
- Could you put us in touch with current clients we can speak with about your service?
Red flags
Some warning signs call for a pause before you sign:
- A vague scope, along the lines of "everything is included", with no written list of services or exclusions.
- No written service level agreement, or commitments that say nothing about priorities or coverage hours.
- Shared administrator accounts among technicians, or passwords sent by email.
- No restore testing, or backups kept in the same place as the original data.
- No exit clause and no process for returning your data.
- Evasive answers about where your data is stored or how you will be told about an incident.
What the contract should include (checklist)
Before you sign, make sure the contract covers at least the following:
- The scope of services, with inclusions and exclusions.
- Service levels: priorities, response and resolution times, coverage hours and penalties.
- Security measures: least privilege, named accounts, two-factor authentication and logging.
- Backups: frequency, retention, location of copies and restore testing.
- The hosting region for your data, backups and logs.
- The clauses required by section 18.3 of the Act: safeguards, use limited to the contract, no retention after it expires, and notice without delay of any violation.
- The privacy impact assessment and written agreement required by section 17, if personal information is communicated or kept outside Quebec.
- Incident notification, regular reporting and a named contact.
- The exit: data ownership, return formats, transition help, destruction of copies, term and termination.
Frequently asked questions
What criteria matter most when choosing an IT service provider?
Start with your own needs: workstations, critical systems, sensitive data and how much downtime you can tolerate. Then assess the written scope, the service levels, security practices, backups, data location, a contract that meets Law 25 and a clear exit clause.
What should a service level agreement (SLA) include?
According to the Canadian Centre for Cyber Security, it "should specify the expected turnaround times, communication media, escalation processes, metrics for assessing performance, and penalties for not meeting turnaround times." Add priority levels, coverage hours and how results will be reported to you.
Does my data have to stay in Canada or in Quebec?
For organizations outside the Government of Canada, the Canadian Centre for Cyber Security writes: "If your organization is a non-GC organization, we recommend that you ensure all sensitive data (M/M/M or above) is stored only in data centres located within the geographical boundaries of Canada." (ITSM.50.030, section 2.2). The hosting region is therefore a point to specify in your request and in the contract. Before communicating personal information outside Quebec, or entrusting someone outside Quebec with keeping it, section 17 of Quebec's private sector privacy act requires a privacy impact assessment and a written agreement. No hosting region is promised in advance: it is specified in the quote.
What is a SOC 2 or SOC 3 report?
These are reports produced by an independent third party after auditing a service provider's controls. A SOC 2 Type 1 report assesses how controls are designed at a single point in time, while a Type 2 report assesses how well they work over time. A SOC 2 report is often shared only under a non-disclosure agreement. A SOC 3 report confirms compliance without detailing the controls.
How can I switch providers without losing my data?
Plan your exit when you sign: data ownership, return formats, transition help and destruction of copies by the outgoing provider. Also keep your own administrator access, up-to-date documentation and a backup that you control.
What should the contract include to comply with Law 25?
When a provider receives personal information to perform a service contract, section 18.3 of Quebec's private sector privacy act requires a written contract. It must set out the measures that protect the confidentiality of the information, limit its use to performing the contract and prevent the provider from keeping it after the contract expires. The provider must also notify your person in charge of the protection of personal information without delay of any violation or attempted violation.
Sources
- Canadian Centre for Cyber Security, Cyber security considerations for consumers of managed services (ITSM.50.030), sections 1, 2.1, 2.2, 2.3, 2.4, 2.6, 2.7.2 and 2.9
- Canadian Centre for Cyber Security, Baseline cyber security controls for small and medium organizations, section 3.10
- LégisQuébec, Act respecting the protection of personal information in the private sector (CQLR, c. P-39.1), sections 17 and 18.3
- Commission d'accès à l'information du Québec, Incidents de confidentialité et mesures de sécurité (businesses, in French)