How do I evaluate whether my IT department or provider is doing a good job?
Evaluate your IT department or provider on five things: service quality employees actually experience, security outcomes measured against a recognized framework, alignment of projects with business goals, cost transparency, and whether systems and decisions are documented and owned. Use evidence such as ticket data, a framework-based assessment and tested backups, not impressions, and ideally get an independent view.
Why executives struggle to judge IT
When IT works, it is invisible; when it fails, the failure is visible but the cause is not. Leaders often rely on how responsive IT staff seem, which says little about security, resilience or strategic value. A structured review replaces impressions with evidence.
What to look at
- Service: response and resolution times, repeat tickets, user satisfaction, after-hours coverage
- Security: MFA coverage, patch levels, admin account control, logging, incident response readiness
- Resilience: backup coverage and the date of the last successful test restore
- Alignment: whether current projects map to business priorities and a roadmap
- Cost: a clear view of IT spend, contracts and renewals
- Documentation: network diagrams, asset inventory, system owners, vendor list and passwords held by the company
- Ownership: who decides on risk, spending and vendor selection
Use a framework for security
NIST's Cybersecurity Framework 2.0 gives a vendor-neutral structure. Its six functions, Govern, Identify, Protect, Detect, Respond and Recover, let you check for blind spots, and its Tiers, from Partial through Risk Informed and Repeatable to Adaptive, describe how rigorous your risk management practices are. Comparing a Current Profile to a Target Profile turns the evaluation into an action plan.
For a lighter starting point, CISA's Cross-Sector Cybersecurity Performance Goals are voluntary practices that CISA aligns to CSF 2.0 and positions partly for small and medium-sized organizations.
Get an independent view
Asking your IT team or provider to grade itself has an obvious limit. An independent assessment by someone without a stake in the outcome, such as a fractional CIO or outside reviewer, gives leadership a clearer picture and gives the IT team a fair hearing.
CISA's guidance for MSP customers reinforces why: outsourcing operations does not absolve your organization of its risk management responsibilities, so leadership needs its own basis for judging the provider.
Turn findings into action
Rank gaps by business risk, agree owners and dates, and review progress quarterly. Distinguish between problems of resources, skills and process. Many issues blamed on people are really missing funding or unclear authority.
Share a summary of the results with the IT team or provider and agree a remediation plan together. Re-run the same assessment a year later using the same criteria, so leadership can see measurable progress rather than a new set of impressions.
Common follow-up questions
How often should we evaluate our IT function?
A full assessment annually is a reasonable rhythm, with lighter quarterly reviews of service metrics, security status and roadmap progress. Also reassess after major changes such as an acquisition, a new regulation, a security incident or a change of provider.
What documents should we ask IT to produce?
Ask for an asset inventory, network diagram, list of systems with owners, vendor and renewal list, backup test results, admin account list, security policies and an incident response plan. Gaps in these documents are often the most revealing findings.
Is this an evaluation of people?
It should be framed as an evaluation of the IT function and its results. Findings often trace back to funding, scope or authority rather than individual performance. Treating it as a systems review makes staff and providers more forthcoming.
LAN Service Group conducts IT assessments for small and mid-size businesses as part of its IT strategy and fractional CIO-style leadership, covering service, security, documentation and spend.
Talk to LAN Service Group (888) 281-7243