Vendor Management

managed it services sla what to include a filing cabinet three drawers

What Should Be Included in a Managed IT Services SLA?

A clause-by-clause inventory of what a managed IT support agreement has to contain before it is worth relying on: scope counted rather than described, coverage windows converted into their real share of the 168-hour week, availability targets translated into allowed minutes per month, priority definitions and clock stops, service credits measured against the loss they are supposed to answer for, and the statutory floor underneath all of it — reasonable care and skill under the Supply of Goods and Services Act 1982, the reasonableness test in the Unfair Contract Terms Act 1977, six or twelve years under the Limitation Act 1980, and the eight processor terms UK GDPR Article 28(3) makes compulsory. Ends with a weighted hundred-point scorecard and a pass mark of 75.

Read more
managed it services onboarding checklist first 30 days a backpack upright body two straps

Managed IT Services Onboarding Checklist: What Happens in the First 30 Days?

What should actually happen in the first thirty days with a new managed IT provider, day by day and with the clocks that run whether or not anyone is watching them: the 90-day GDAP request window, the two-year cap on delegated access, Microsoft’s 30-day Expired and 90-day Disabled subscription states, the 30-day Entra ID recovery window for a deleted user, and the 14-day critical-patch rule that is an automatic Cyber Essentials failure under the Danzell question set. It models the provider’s own effort at 123 hours — £10,455, or 3.1682 months of a £3,300 monthly fee — shows the discovery gap between a declared and a discovered estate, and ends with a weighted day-30 scorecard with a pass mark of 80.

Read more
switch it support providers without business disruption a bridge flat deck two piers

How to Switch IT Support Providers Without Business Disruption

Switching IT support providers goes wrong for administrative reasons, not technical ones — a licence that lapsed, a firewall nobody had the password for, a backup chain that ended with the old contract. This guide sets out the sequence that keeps a move invisible to the business: the contract clock and the cost of missing a notice date, the exact Microsoft CSP transfer rules (30-day request expiry, 72-hour completion, 25 line items per billing plan), what happens if the outgoing provider cancels instead of transferring, a 90-day phased plan with exit criteria, the cutover weekend hour by hour, and a modelled £17,500 switching cost for a 60-user firm that takes 3.04 years to pay back on price alone.

Read more
change seo agencies without losing rankings a three ascending rounded pillars

Change SEO Agencies: Proven Steps to Avoid Losing Rankings

Switching supplier is almost never what costs a business its organic visibility — the unmanaged fortnight in between is. This guide sets out the full transition plan: the baselines to export before notice is served, the nine access items that must sit in your own name, the five contract clauses that decide whether you get a handover or a shrug, and why paying two agencies for one overlapping month is the cheapest insurance available. It includes a model transition clause to put in your next agreement, a week-by-week handover timeline, the arithmetic showing a planned overlap costs 39% of a badly handled switch on a £3,000 retainer, and the 30, 90 and 180-day questions that tell you whether the change actually worked.

Read more
cloud exit strategy a blank signpost two arms

Cloud Exit Strategy: Proven Guide to Avoid Lock-In Risk

Almost every organisation agrees a cloud exit strategy is sensible and almost none holds a tested one. This guide sets out where lock-in genuinely comes from, what the four realistic exit routes cost in money and elapsed time, how egress charges and the new switching rules actually work, which architecture decisions keep the door open cheaply, what exit rights belong in the contract, and how to rehearse the plan so it becomes a capability rather than a filing-cabinet artefact. The point is rarely to leave. It is to be credibly able to leave.

Read more
AI vendor lock-in - ai vendor lock in exit strategy a featured upright key

AI Vendor Lock-In: Essential Exit Plan to Avoid Risk

AI vendor lock-in is the bill that arrives eighteen months after a successful pilot. This guide breaks dependency into five distinct types — model, data, workflow, integration and commercial — explains why AI switching costs behave differently from classic software migrations, sets out the contract clauses that cap your exposure at signature, covers the architecture decisions that keep switching cheap, and gives you a four-page exit plan you can write in a day and rehearse once a year.

Read more
supplier contract security requirements a shield emblem on hexagonal plinth

Supplier Contract Security: Essential Clauses to Avoid Risk

Most contracts dispose of security in a single sentence promising “appropriate technical and organisational measures”, which gives you no notification deadline, no evidence rights and no route to terminate when the supplier is breached. This guide sets out the cybersecurity requirements worth writing into supplier agreements: the standards and certification scope to specify, the core control clauses, the UK GDPR processor terms that are statutory rather than optional, incident notification and cooperation, audit and evidence rights, subcontractor flow-down, exit and data return, liability and insurance, and the three-tier model that keeps the whole programme proportionate across a real supplier base.

Read more
cyber due diligence mergers acquisitions a magnifying glass on plinth

Cyber Due Diligence in M&A: Essential Guide to Avoid Risk

Financial diligence values the earnings and legal diligence values the contracts, but neither tells a buyer whether the target has been quietly compromised for eight months. This guide sets out proportionate cyber due diligence on a real transaction: what the exercise actually covers, the four ways weak review destroys deal value, the five phases from scoping to costed reporting, the data room evidence list and what its absence proves, the red flags that justify repricing, how deal size and sector change the scope, the mapping from findings to price adjustments, warranties, indemnities and conditions, the first hundred days after completion, who should run the exercise and what it costs, and the mistakes that keep repeating.

Read more
supplier cyber-risk assessment - supplier cyber risk assessment checklist a concentric cube rings plinth

Supplier Cyber-Risk Assessment: Essential Safe Checklist

Most supplier assurance programmes send a spreadsheet, receive a spreadsheet and file it — producing documentation rather than assessment. This guide sets out a working supplier cyber-risk assessment checklist as a seven-step programme: building an honest supplier inventory from four independent sources, scoring inherent risk before you contact anyone, tiering the base so effort follows exposure, the ten control domains the checklist must cover, choosing an assessment method that matches the tier, demanding the evidence artefact behind every claim, converting answers into residual risk and a dated decision, handling concentration and fourth-party risk, turning findings into remediation with deadlines and consequences, monitoring continuously between reviews, and closing the loop properly at offboarding.

Read more
third-party cybersecurity questionnaire - third party cybersecurity questionnaire template a central hub six satellite nodes plinth

Third-Party Cybersecurity Questionnaire: Proven Risk Guide

Most supplier security questionnaires are inherited spreadsheets that produce documented false assurance rather than real risk reduction. This guide provides a working third-party cybersecurity questionnaire template: the eight domains it must cover, the full 47-question Tier 1 set written as closed questions, a three-tier model so you stop sending 180 rows to low-risk suppliers, a four-outcome scoring rubric that produces decisions instead of percentages, the evidence artefact to demand behind every claim, the red flags that separate a filed document from a real finding, a mapping to Cyber Essentials, ISO 27001 and NIS2 Article 21, and the contract clauses that turn questionnaire answers into enforceable obligations.

Read more
CHAT