Choosing an IT Partner

How to Choose an IT Company in Tulsa: 12 Questions to Ask Before You Sign

Every IT company’s website says “proactive”, “responsive”, and “partner”. The proposals look alike, the monthly numbers are close, and you are being asked to trust a company with the systems your business runs on. You are not an IT expert and you shouldn’t have to become one to make this call. What you need is a short list of questions that separate the providers who will show up from the ones who will show up on the invoice.

Who this guide is for

Owners, presidents, and office managers of Tulsa-metro businesses choosing an IT company for the first time, replacing one that has stopped answering, or checking whether the one they have is still the right fit. It is written for organizations of roughly 10 to 100 people — big enough that IT matters every day, not big enough for a department.

Before the questions: decide what you are buying

Most businesses this size are choosing between three shapes of support: break-fix (pay by the hour when something breaks), managed IT (a flat monthly fee for monitoring, help desk, security, and planning), and co-managed IT (an outside team working alongside one or two internal IT people). If you have not settled that yet, read managed IT vs break-fix first. The questions below assume you are talking to a managed IT provider.

The 12 questions to ask an IT company in Tulsa

1. What exactly is included in the monthly fee — and what isn’t?

Ask for the inclusions and exclusions in writing. Projects, after-hours work, new-hire setups, hardware, licensing, and “onsite visits beyond X per month” are the usual places a flat fee stops being flat. A good answer is a one-page list you can understand; a bad answer is “it’s all covered” with nothing on paper.

2. What is your written response standard, and how do you report against it?

Not “we respond fast” — the actual targets by priority (a down office versus a printer question), and the report you will see each month showing whether they were met. If there is no report, there is no standard.

3. Who answers the phone when we call, and where are they?

You are asking whether the help desk is a local team that knows your environment or a call centre working from a script. Ask what a normal call sounds like, whether you can reach a real technician directly, and how many people on the team would recognize your company name.

4. What is monitored, and what happens when an alert fires at 2 a.m.?

“We monitor everything” is not an answer. Ask which systems are watched, who sees the alerts, and what they do about a failing backup or a server running out of disk before you arrive in the morning.

5. What security controls are part of the standard service?

At minimum you should hear multi-factor authentication, endpoint detection and response (not just antivirus), email filtering, patching on a schedule, and security awareness training. The FBI’s Internet Crime Complaint Center recorded more than $16 billion in reported losses in 2024; a provider who treats security as an optional add-on is leaving you exposed. Our SMB cybersecurity checklist is a useful thing to hand across the table.

6. How are our backups tested, and when did you last restore one for a client?

The answer should include a schedule for restore tests and a plain description of the last one. Follow up: where do the backups live, and could ransomware on our network reach them?

7. What does onboarding look like, and how long until you know our environment?

A good provider starts with an assessment and documentation of what you have — accounts, devices, network, vendors — before changing anything. Ask for the plan for the first 30, 60, and 90 days and what you will be asked to do during it.

  1. Days 1–30

    Assess and baseline

    Discovery, documentation, and a baseline review of risk and performance.

  2. Days 31–60

    Stabilize and secure

    Critical issues handled first; standards rolled out for endpoints, identity, email, patching, and backup.

  3. Days 61–90

    Optimize and plan

    Optimization plan, priority projects, and a quarterly roadmap.

  4. Ongoing

    Steady state

    Support, report, and review — help desk, monitoring, monthly reporting, strategy sessions

8. Who will we meet with, and how often, to plan ahead?

Look for a scheduled review — quarterly is common — with someone senior enough to talk about budget, risk, and where the business is going, not just ticket counts. This is where IT stops being a cost you react to and becomes something you plan.

9. What happens if we outgrow you — or want to leave?

Ask about contract length, notice period, and what you get on the way out: documentation, passwords, admin access, and cooperation with the next provider. A confident provider will describe an orderly handover. Hesitation here tells you a lot.

10. Can you give us three clients our size, in a similar industry, that we can call?

Then call them. Ask how long a real problem took to fix, whether the same problems keep coming back, and whether they feel like a priority or a ticket number. Also look at public reviews — a long run of recent, specific, five-star reviews from named local businesses is hard to fake.

11. Do you understand our industry’s software and obligations?

An engineering firm needs someone who has sized workstations for Revit; a CPA firm needs someone who knows the FTC Safeguards Rule; a contractor needs phones and files that work from a truck. Ask for specific examples of work in your industry, not a general assurance.

12. Who owns the company, and how long have you been in Tulsa?

Not because local is a virtue in itself, but because ownership and tenure predict behaviour: a locally owned company with a decade of Tulsa clients has a reputation to protect in the same rooms you are in. Ask who you would escalate to if something went badly wrong, and whether that person’s name is on the door.

How to compare the proposals

Put the answers side by side rather than the prices. Two proposals at similar monthly fees can differ enormously in what is monitored, what security is standard, whether backups are tested, and whether anyone will meet with you to plan. Score each provider on the twelve questions and note where the answers came with paper and where they came with reassurance. Then weigh price. If the cheapest proposal is thin on questions 2, 5, and 6, the saving is borrowed against your bad week.

Common mistakes when choosing an IT company

  • Choosing on the monthly number. The variance in what is included is larger than the variance in price.
  • Not asking for the reports. Response standards and backup tests only exist if you can see them.
  • Skipping reference calls. Twenty minutes with a peer tells you more than any proposal.
  • Deciding during an outage. If you are choosing while email is down, choose someone to stabilise things — and run this process properly afterwards.
  • Signing a long contract without an exit clause. A good provider expects to earn the renewal.

Choosing an IT company in Tulsa

The Tulsa metro has plenty of capable providers, and the right one for a 40-person accounting firm in Broken Arrow is not necessarily the right one for a 15-person electrical contractor in Sand Springs. Take the twelve questions to at least two conversations, insist on the written answers, and call the references. You will know quickly who treats you as a priority.

NSN Management is one of the companies you might ask. We are Tulsa-owned and have supported businesses across the metro since 2012, and we will answer all twelve questions in writing before you decide anything. Book a Discovery Call to start — bring the list.

Questions Tulsa businesses ask about this

What should a managed IT agreement include?

A written list of inclusions and exclusions, response targets by priority with a monthly report, the security controls that are standard, backup and restore-testing commitments, an onboarding plan, a scheduled planning review, and clear exit terms including documentation handover.

How much does managed IT cost in Tulsa?

Most Tulsa managed IT providers price per person or per device per month, and the number varies with what is included — particularly security, backup, and planning. Compare what is covered before comparing prices; two similar fees can buy very different services.

Should we choose a local IT company or a national one?

Choose on the answers to the twelve questions. Local ownership tends to predict accountability and faster onsite response, and a Tulsa-based team is easier to meet and to call references on — but hold every provider to the same written standards.

How long does it take to switch IT companies?

Typically 30 to 90 days from signing to a stable handover, depending on the state of documentation. A good incoming provider assesses and documents first, fixes obvious risks, then moves you onto monitoring and support — with as little disruption to your team as possible.

What are red flags when choosing an IT provider?

No written response standard, no monthly reporting, security sold as an add-on, vague answers about where backups live and when they were last restored, reluctance to provide references, and long contracts with no clear exit.

· Founder, NSN Management

Sean founded NSN Management in Tulsa in 2012 after running eMonarch, the managed IT company he started in 1999, and still leads the team. He co-wrote Special Edition Using Microsoft Active Directory (Que, 2001), was named to the Tulsa Business Journal’s 40 Under 40, and led NSN Management to Kaseya/Datto MSP of the Year 2025.

Published · Updated

Choosing an IT PartnerManaged IT Strategy