What we keep finding when we audit IT providers

These aren't hypotheticals. Every case below came from an actual audit.

The IT provider that never tested backups

The problem

A 12-person accounting firm had been paying their IT provider for managed backups for over two years. Nobody at the firm had ever seen a restore test or backup verification report. The provider sent monthly invoices but no documentation proving backups actually worked. The failure went unnoticed for 18 months until a server drive started throwing SMART errors.

What we found

The backup agent was installed but misconfigured. It pointed at a NAS share that ran out of space 18 months earlier. Every nightly job had been failing with a disk-full error since then, but the provider had no alerting for failed jobs. The dashboard showed 547 consecutive failures. No one had logged in. The firm had 3.2 terabytes of client financial records, tax filings, and payroll data on a single server with no valid copy anywhere.

How our service prevents this

Our Professional and Complete plans include monthly verified restores. We pull data from a backup and confirm it opens, reads correctly, and matches the source. Results go in your monthly report with timestamps and file counts. We run automated backup monitoring with failure alerts that trigger within 15 minutes. If a job fails twice in a row, we investigate the same day. Verified restores are built into the service because an untested backup is not a backup.

Impact

3.2 TB of client financial records at risk of permanent loss.

The $12,000 ransomware bill

The problem

A 10-person insurance agency in central Mississippi got hit by ransomware on a Tuesday morning. Every workstation and their file server were encrypted within 40 minutes. Their IT provider had installed antivirus on most machines but had no way to detect the attack as it spread. The agency was down for 6 business days. Between the ransom payment, emergency IT labor, and lost billable hours, the total cost exceeded $12,000.

What we found

The provider had deployed a free consumer-grade antivirus product. It caught known malware signatures but had no behavioral detection, so it could not identify ransomware actively encrypting files. No endpoint detection and response. No 24/7 monitoring. No network segmentation. The attacker entered through a phishing email and moved laterally because all workstations shared the same local admin password. The antivirus flagged nothing because the variant was 11 days old and not in the signature database.

How our service prevents this

Our Professional and Complete plans include managed endpoint detection and response with 24/7 threat monitoring. EDR watches for suspicious behavior, not just known signatures, so it catches ransomware that traditional antivirus misses. Foundation includes active Defender management with policy enforcement and alert review. All tiers enforce unique local admin passwords and basic network segmentation. The phishing email might still arrive, but lateral movement gets blocked and encryption stops on the first machine.

Impact

$12,000 in direct costs plus 6 days of lost revenue for a 10-person firm.

The vendor runaround

The problem

The owner of a 7-person real estate office spent 6 hours on the phone trying to fix an email delivery problem. Her ISP said it was the email host. The email host said it was the DNS provider. The DNS provider said it was the IT company. The IT company said they only covered hardware. She lost an entire workday cycling between four vendors. A client contract nearly fell through because the emails never arrived.

What we found

The IT provider's contract excluded third-party vendor coordination. Any problem crossing a vendor boundary became the owner's responsibility. The root cause took 20 minutes to fix: an SPF record overwritten during a DNS migration three weeks prior. But finding that required checking DNS records, email headers, and mail server logs across three vendor dashboards. The owner had no access to two of them and no idea what an SPF record was.

How our service prevents this

Our Professional and Complete plans include full vendor coordination. When something breaks and involves your ISP, email host, or software vendor, you call us once. We handle the back-and-forth, join three-way calls if needed, and track the ticket to resolution. You do not become the project manager for your own IT problems. Foundation covers vendor coordination for the core tools we manage. One point of contact, one number to call.

Impact

6 billable hours lost and a client contract nearly lost over a 20-minute DNS fix.

Ready to stop worrying about IT?

15 minutes on the phone. You tell us what's broken; we tell you what we'd do about it. If it makes sense, we move forward.

Free call. No obligations. Worst case, you learn something.

Book a free discovery call