When organizations contact us for the first time, it’s usually because they’re feeling a certain way about the people who currently provide their IT support, cybersecurity protection, and AI and automation services.
One prospect described their current MSP relationship in four words that have stuck with us ever since:
“Comfortable, but not right.”
That’s a succinct and polite way to say the relationship is broken and it’s time to look for a different kind of partnership. Maybe it’s an IT guy everyone likes who hasn’t touched a new technology in six years. Maybe it’s an MSP that has never once brought you a new cybersecurity defense while the criminals attacking you upgrade every quarter. Maybe it’s an IT company so locked in tradition that it treats cloud, automation, and AI like the hula hoop, a fad worth waiting out, while your competitors quietly get faster and reduce their operating expenses.
Here’s the uncomfortable part. Nobody leaves a provider because of a feeling. They leave because of an incident. So the feeling sits there for two, three, five years, getting renewed automatically every January, until something expensive finally forces the issue.
The purpose of this article is to give you a way to act on the feeling before the incident shows up. Below are the five places to look, and the specific questions to ask, when you suspect your IT relationship is comfortable but not right.
Why “comfortable” is such an effective trap
Comfortable measures familiarity, and familiarity does three things to a buying decision.
It hides the baseline. If your servers have always taken four hours to fix, four hours feels normal. You have no way of knowing that a peer down the road is at 30 minutes, because nobody publishes their downtime.
It converts problems into personalities. “That’s just how Dave is.” When a service failure gets attached to a likable human being, complaining about it starts to feel like a personal attack. So you stop complaining.
It makes the switch feel bigger than the problem. The pain of migrating is concrete and immediate. The pain of standing still is spread across a hundred small Tuesdays. Human beings are terrible at that math. We wrote about the specific fears involved in Common Myths About Switching MSP Providers, and almost every one of them turns out to be smaller than it looks from the inside.
None of that means you should switch. It does mean you owe yourself an honest look before you renew.
1. Responsiveness: measure it, don’t remember it
Most business owners evaluate response time from memory, and memory is heavily weighted toward the last bad thing that happened. Pull the actual data instead.
Ask your provider for a ticket report covering the last 90 days, and look for four numbers:
- Time to first human response, not the auto-reply that says a ticket was created
- Time to resolution, measured separately for critical issues and routine ones
- Reopen rate, meaning tickets closed and then reopened within a week
- Ticket volume by user and by device, which tells you whether you’re paying to nurse one dying asset
If they can’t produce that report, that’s the finding. A provider without measurement is a provider without accountability. For context on what these numbers can look like when someone is actually managing them, see our own response and resolution times, where 99 percent of critical issues are resolved within 30 minutes.
The question to ask: “What percentage of our critical tickets were resolved within an hour last quarter?”
2. Reoccurrence: the same problem is the whole problem
Fixing the same issue eleven times is one unsolved root cause, billed eleven times.
Go through your ticket history and cluster it. If the same printer, the same VPN, the same login, or the same user shows up over and over, you’re paying for a reactive relationship dressed up as a responsive one. A proactive provider watches for that pattern and eliminates the source, which reduces their own ticket count on purpose.
The question to ask: “What are our top three reoccurring issues, and what is the plan to make each one permanently go away?”
A good partner answers this without preparation, because they already track it.
3. Security posture: has anything changed since you signed?
This is where “comfortable but not right” gets expensive.
Pull out whatever your provider proposed the day you signed. Compare it to what you have today. If the stack is identical, you have a problem, because the threat landscape is nowhere near identical. Attackers moved to phishing-as-a-service, identity attacks, and business email compromise while a lot of MSPs were still selling antivirus and a nightly backup.
Run this checklist against your current protection:
- Managed detection and response with humans watching around the clock, rather than software firing alerts into an inbox nobody reads at 2 a.m.
- Multifactor authentication enforced on email, VPN, and administrative accounts, with no standing exceptions for executives
- Advanced email security that catches impersonation and payment fraud on top of ordinary spam
- Backups that have been restored, in a test, in the last twelve months, with a documented recovery time
- Patching evidence, meaning a report showing what got patched last month and what did not
- Offboarding discipline, so accounts for departed employees actually disable on the last day
Two of these deserve special attention. An unrestored backup is a theory with a filename. And if your provider has never described what happens in the first 60 minutes of a ransomware event at your company, they haven’t planned for one.
If you’d rather have this checked by someone other than the people being graded, a penetration test and a cyber security audit will settle the question with evidence. If you handle federal contracts or sit in a supply chain that does, add CMMC compliance to the list, since that clock is real and it’s running.
The question to ask: “What did you add to our defenses in the last 12 months, and what did you recommend that we declined?”
That second half matters. A partner who has been pushing while you have been deferring is a very different situation from a vendor who never brought it up.
4. Strategy: is anyone thinking about next year?
Support keeps you running. Strategy keeps you competitive. Plenty of providers deliver the first and quietly skip the second, and it takes years to notice because nothing appears to be broken.
The tells are easy to spot once you look:
- No technology roadmap, or one that hasn’t been updated since it was created
- No budget forecast, so every hardware refresh arrives as a surprise
- No lifecycle tracking, so you find out a server is out of warranty when it dies
- No point of view on automation or AI, or worse, a dismissive one
That last item is the newest and the widest gap. Automation and AI have moved past the demo phase into ordinary operational savings, and the organizations capturing that savings started with an honest assessment of where their manual work actually lives. We laid out what’s realistic in From Hype to ROI: What Automation and AI Can Actually Do for Your Business.
The question to ask: “What should we be doing in the next 12 months that we’re not doing today?”
Silence is an answer. So is a quote for more of the same.
5. Contract terms: read your own agreement
Most companies haven’t read their IT agreement since the day they signed it. Go find it, and confirm four things:
- Your renewal date, along with whether it renews automatically
- Your termination window, which is often 60 or 90 days before renewal
- Early termination fees, if any
- What is actually included, specifically onsite visits, emergency and after-hours rates, project work, and per-incident charges
Knowing these four numbers is basic vendor management, and the useful part is that it converts a vague feeling into a calendar date. If your termination window closes in November, then your evaluation happens in September, and now the decision has a deadline instead of drifting for another year.
While you’re in there, compare your plan against what a base level of service should include. Our breakdown of the top issues to consider when switching IT providers covers where the gaps usually hide, particularly the difference between flat-rate coverage and hourly billing, which quietly determines whether your provider profits when things break.
Score your relationship
Give your current provider a 1 to 5 on each line, where 1 means never and 5 means consistently.
| Area | What a 5 looks like |
|---|---|
| Responsiveness | Documented response and resolution times, reported without being asked |
| Reoccurrence | Root causes eliminated, ticket volume trending down |
| Security | Defenses upgraded in the last 12 months, backups tested, MFA enforced |
| Strategy | Living roadmap, budget forecast, a clear position on automation and AI |
| Contract terms | Transparent pricing, no surprise invoices, you know your renewal terms |
| Partnership | They know your business as well as they know your network |
- 26 to 30: You have a partner. Keep them.
- 20 to 25: You have a decent vendor with real gaps. Bring this list to your next review and set a 90-day expectation.
- Below 20: Comfortable, but not right. Find your termination window, then start your evaluation now, so you’re ready to make a decision about your partner before an incident or an automatic renewal forces one for you.

A partner shows up with a plan you didn’t ask for. A vendor shows up when you call. The difference between those two is worth more than the line item on your invoice, and we made the full case for that in If IT Isn’t a Partner, It’s a Problem.
A low-risk way to find out where you stand
You don’t have to switch anything to get an honest answer.
Even if you aren’t sure a change is in order, Pegasus can run a cybersecurity audit, a penetration test, an infrastructure analysis, and an AI preparation session to see whether you’re using technology in ways consistent with comparable organizations. There is no ongoing commitment attached to any of it.
One of two things happens. Either it confirms you’re exactly where you should be, which is genuinely good news and worth knowing, or it surfaces deficiencies while they’re still cheap to correct and gives you a corrective plan you can execute at your own pace, with your current provider or with us.
If you want a faster starting point, take the Match-IT quiz or browse the full Right Fit IT Resource Center, where we’ve collected everything we know about choosing and evaluating an IT partner.
Pegasus has the depth, breadth, and personality to be your strategic IT partner. If your current relationship is comfortable, but not right, let’s have a conversation.
Contact Pegasus today or call 610-444-8256 to schedule your no-commitment analysis.