How should a Walnut Creek business choose a managed IT provider?

Short answer

A Walnut Creek business should choose a managed IT provider that offers responsive remote support, scheduled and urgent on-site work, and a security baseline for Microsoft 365, email and backups. Office-based firms handling client money or confidential files should press hardest on email-fraud defenses, phishing-resistant MFA for admins, written service levels, and whether the provider runs all of IT or co-manages with your staff.

The Walnut Creek context

Walnut Creek, incorporated in 1914, is a Contra Costa County city with its own BART station on Ygnacio Valley Road. BART describes the city as the business and arts center of Contra Costa County. For IT planning, that usually means office-based teams, often in multi-tenant buildings, with staff who split time between the office, home and client sites.

That pattern puts the risk in identity and email more than in on-premises servers. Most incidents an office firm faces start with a stolen password or a convincing invoice email, so your provider's security work should start there.

What good managed IT covers

  • Help desk with clear hours, escalation paths and a ticket history you can review
  • Microsoft 365 administration: MFA, Conditional Access, mailbox rules monitoring and admin-account control
  • Endpoint protection, patching and device management for laptops that leave the office
  • Backups of Microsoft 365 data and any servers, with periodic restore tests
  • Network, Wi-Fi and conference-room support, on site when needed
  • A security and budget review with leadership at least each quarter

Defend the inbox and the wire transfer

CISA recommends phishing-resistant MFA, such as FIDO2 security keys or passkeys, as the gold standard, and app-based codes or push with number matching as the best interim option for small and mid-size businesses. Ask the provider which method they will use for administrators first, and how quickly everyone else will follow.

Pair technical controls with a payment rule: any change to bank details or an unusual payment request is confirmed by phone to a number already on file. That process control costs nothing and closes the gap MFA alone does not.

Fully outsourced or co-managed

Firms without IT staff typically outsource the whole function. Firms with an IT manager often choose co-managed IT, where the provider adds security tooling, monitoring, after-hours coverage and project help while internal staff keep business applications. CISA's guidance for MSP customers is clear that outsourcing does not transfer your risk, so the contract should spell out who owns hardening, detection, incident response and notification.

The choice usually comes down to three questions: can one IT person realistically cover help desk, security and projects; can anyone internal review security alerts after hours; and does leadership want IT knowledge to stay inside the company? If the answers are no, no and yes, co-managed IT tends to fit. If nobody internal owns IT today, full outsourcing is usually simpler.

Questions to ask a provider

  • How is on-site work in Walnut Creek scheduled and charged, and what is the written response commitment?
  • Which MFA method will protect our admins, and when will all users be on it?
  • Do you require MFA on every technician account that reaches our systems?
  • Who owns our Microsoft 365 Global Administrator accounts and domain registrations?
  • What happens to our data, accounts and documentation if we end the contract?

Common follow-up questions

Is a provider in another Bay Area city good enough for Walnut Creek?

Often, yes. Remote support handles most issues. Confirm the on-site terms in writing, including how visits to Walnut Creek are scheduled and what counts as urgent, and judge the provider by those commitments rather than by distance on a map.

What should a small professional-services firm prioritize first?

Start with identity and email: MFA for everyone, phishing-resistant MFA for administrators, blocking legacy authentication, alerting on suspicious mailbox rules, and a phone-verification rule for payment changes. Then confirm backups restore and laptops are encrypted and patched.

Can we keep our IT person and still use an MSP?

Yes. That is co-managed IT. Your IT person keeps ownership of business systems and user relationships, while the provider adds monitoring, security tools, after-hours coverage and project capacity. Write down who owns each task so nothing falls between you.

Need help with this?

LAN Service Group, founded in 1992 and based in San Ramon, provides managed IT for Walnut Creek and East Bay small and mid-size businesses, either as the full outsourced IT department or co-managed alongside an in-house IT team.

Talk to LAN Service Group (888) 281-7243

Sources