Is your business exposed? Run a free domain security audit in 60 seconds
CyberBITS
Managed IT Support 4 July 2026 · 4 min read

What I Find When I Take Over From Another IT Supplier

Every time we onboard a client from another IT supplier, I look under the bonnet — and almost every time I find something that makes me wince. Three real examples from the last six months: phantom 'DNS protection', an £85/user setup with no security switched on, and backups going nowhere.

An IT engineer inspecting a server cabinet, illustrating what gets discovered when onboarding a client from another IT supplier

Every time we take on a client who's coming from another IT supplier, the first thing I do is look under the bonnet. Not the tidy overview the previous provider handed over — the actual setup. And almost every time, I find something that makes me wince. Sometimes it's just sloppy. Sometimes it's something the client has been paying good money for that doesn't actually exist.

Here are three real examples from the last six months. I've left the names out, but the details are exactly as I found them.

"Advanced DNS protection" that wasn't protecting anything

One client was being billed every month for "advanced DNS protection." It sounds reassuring. It sounds like there's a proper security product sitting between them and the internet, filtering out dodgy domains before anyone can click them.

When I went looking for it, there was nothing there. No filtering service, no threat feed, no product at all. What they were actually paying for was someone occasionally logging into GoDaddy to manage their DNS records — the basic plumbing that points a domain at the right place. That's not protection. That's routine admin, dressed up in a frightening-sounding label and billed monthly.

The client had no idea, and why would they? They're not supposed to know what a DNS record is. That's exactly what they were paying a supplier to handle for them.

£85 a user, and the security was switched off

Another client came to us because we were cheaper. They'd been paying north of £85 per user per month and, fair enough, assumed that kind of money bought proper security.

First thing I checked was their Microsoft 365 tenant. They were on Business Premium — which is a genuinely good licence. It includes a serious stack of security tools: multi-factor authentication, conditional access, Defender, the lot. Not one of them was switched on. Their Microsoft Secure Score — Microsoft's own measure of how well your protection is configured — was sitting at 24%.

The previous MSP had installed ESET antivirus and called it a day. So the client was paying Business Premium prices and getting the security of a basic antivirus. The tools were there, bought and paid for, just never turned on. That one stung, because the fix cost nothing extra. They already owned everything they needed — somebody just had to bother configuring it.

A backup sitting right next to the thing it was backing up

The third was a client on Business Basic running on-site servers. They had backups, which is more than some, so on paper that box was ticked.

Then I traced where the backups were actually going. A NAS box — sitting in the same cabinet as the servers it was backing up. No offsite copy, nothing in the cloud, nothing off the premises at all. So the moment you get a fire, a flood, a theft, or ransomware that walks across the network, you lose the servers and the backup in the same instant.

A backup that lives next to the thing it's protecting isn't really a backup, it's a copy. The whole point is resilience — somewhere separate to fall back to when the worst happens — and that was the one thing missing.

What ties all three together

None of these clients were careless. None of them were skimping. In two of the three cases they were paying well over the odds. The problem each time was the same: they'd trusted a supplier to handle something they couldn't see, and the supplier had cut a corner where it didn't show.

That's the thing about IT. When it's done badly, everything looks fine — right up until the day it really, really doesn't. The phantom DNS product never causes a problem until there's a breach. The unconfigured security never matters until someone's account gets taken over. The backup next to the server is perfect until the day you actually need it.

Find out where you really stand

I'm not writing this to have a go at other providers. I'm writing it because if you've got an IT supplier and you've never actually checked what you're getting for your money, you're taking it on trust — and trust is exactly where these gaps hide.

If you want to know where you really stand, we built a free CyberBITS Health Check. It flags the obvious holes in a few minutes, with no salesperson attached. Run it, and at the very least you'll know what's actually under your own bonnet.

This article is general guidance for UK SMEs based on real onboarding cases and is not formal security advice. Specific products, licences and configurations change over time — check your own setup before relying on any single detail.

Tagged

  • switching IT provider
  • managed IT support
  • Microsoft 365 security
  • backup and disaster recovery
  • MSP West Midlands

Share this post

Ready to talk?

Let's see if we can help.

A short, no-pressure conversation about whatever IT problem is bugging you most.