By the time most companies realize their IT provider isn't working out, the damage is already done: a missed security patch, a botched migration, a client who noticed the outage before anyone internally did. Chris McGlasson, fractional CIO and founder of ClearStack Advisory, has walked into dozens of $10M-$20M companies mid-crisis with an IT provider that should have been replaced a year earlier. The signs are usually visible well before the crisis. Here's what to watch for.

You can't get a straight answer on security

Ask your provider for the current patch compliance rate across all endpoints, or the results of the last security assessment, and see what happens. A confident, specific answer is a good sign. A vague reassurance that "everything's covered" is not an answer, it's a deflection. Providers that can't produce hard numbers on security posture usually aren't tracking it closely enough to catch a problem before it becomes an incident.

Tickets get slower to close, and nobody explains why

A gradual increase in resolution time is easy to miss month to month, but it compounds. If simple issues that used to close in hours now take days, and the provider has no explanation beyond generic apologies, that's usually a staffing or prioritization problem on their end, not an isolated bad week.

The roadmap hasn't changed in two years

A provider that's still recommending the same three initiatives from 18 months ago either isn't paying attention to how the business has changed, or has stopped investing time in genuinely understanding it. Technology priorities should shift as the company grows, adds headcount, or changes what it sells. A static roadmap is a sign of a static relationship.

Billing is confusing on purpose

Overage charges that show up without warning, licenses billed that nobody remembers approving, and invoices that take a phone call to decode are common signs of a provider protecting margin at the client's expense. Chris McGlasson notes that cost transparency is one of the fastest signals of relationship health. Providers doing right by a client can explain every line item without hesitation.

Every conversation starts with an upsell

There's a difference between a provider recommending investment because the business genuinely needs it, and a provider recommending investment because the contract's up for renewal. If every quarterly check-in ends with a new product pitch that happens to align with the provider's margin rather than a documented business need, that's worth questioning directly.

You've never met the team actually doing the work

At $10M-$20M in revenue, a company should have real relationships with the specific engineers and account managers handling its account, not a rotating cast of unfamiliar names on every ticket. High turnover on the vendor side, or a total lack of continuity, usually means the client relationship isn't a priority internally.

Nobody proactively flags risk

A provider that only shows up when something breaks is managing tickets, not managing risk. A provider actually doing the job flags outdated software, expiring certificates, and emerging vulnerabilities before they become incidents, without being asked. Silence between problems isn't a sign that everything's fine. It's often a sign nobody's watching.

The annual review is a status update, not a strategy session

If the yearly check-in is a slide deck of uptime percentages and closed ticket counts with no hard questions asked or answered, the relationship has drifted into maintenance mode. A real review surfaces where the provider is falling short, not just where they're succeeding.

What to do if you're seeing these signs

One or two of these on their own might just mean a tough quarter. A pattern across three or more, especially security transparency and proactive risk management, is a strong signal the relationship needs a hard conversation or a replacement search. Companies at this revenue range rarely have someone whose full-time job is to evaluate the provider objectively, which is exactly why problems tend to go unnoticed until they're expensive.


Not sure where your IT really stands? Start with a Clarity Audit: a focused assessment of your backups, security, vendors, and AI readiness. It's the first step in every engagement I take on.


About the author: Chris McGlasson is a fractional CIO and the founder of ClearStack Advisory, where he helps mid-market companies build AI governance, IT strategy, and technology roadmaps without the overhead of a full-time CIO. He previously built and sold LANPRO Systems, an IT services firm serving 350+ enterprise clients.