What happens if your IT support company goes bust?

Six steps to protect your business

Your IT provider probably has more control over your business than you think. Not just laptops and helpdesk tickets, but your Microsoft 365 environment, your backups, your cyber security tools, your internet services, your domains, and the passwords that sit behind all of it.

So, when that provider suddenly stops trading, you’re not looking at a procurement headache. You’re looking at a business continuity event, and the clock starts the moment you find out.

The National Cyber Security Centre has been blunt about this risk. Suppliers with extensive access to essential systems, or who hold important company data, or who rely on subcontractors you’ve never heard of, can create serious disruption when things go wrong. Its guidance for SMEs is to understand exactly what your MSP manages, what access it holds, and how you could end the relationship safely if you had to. Most businesses only ask that question once it’s too late to matter.

Here’s what we’d tell any MD or FD facing this right now.

1. Find out what's actually happened

Rumour spreads faster than fact in situations like this, so don’t act on either until you know which one you’re dealing with. Has the provider entered administration or liquidation? Stopped answering support requests? Lost key staff? Been quietly acquired? Had its own suppliers pull the plug on services it resells to you? Get a named contact, get written confirmation, and find out who, if anyone, has been appointed to manage the business.

While you’re chasing that answer, activate your own continuity plan anyway. Don’t assume everything’s fine just because your systems are still working this morning. They might not be by this afternoon.

2. Secure control of your critical accounts

Access is the first thing that matters here, before anything else. Confirm your business holds its own authorised administrator accounts for Microsoft 365, Azure and any other cloud platforms, your domain names and DNS, your internet and telecoms portals, your backups, your cyber security systems, and your line-of-business applications.

Microsoft’s partner model allows an MSP to administer your tenant through delegated permissions. Those permissions sit separately from your tenant itself, and they can be replaced or removed, but only if you’ve retained proper administrative control of your own. Microsoft also allows an existing tenant to move to a new reseller without starting from scratch, which matters more than most business owners realise until they need it.

Your provider should have access to your systems. It should never be the only party with that access. And resist the urge to lock everything down in one go without understanding what depends on it first. Cutting off a supplier account blind can trigger a second outage on top of the first. Secure control, then remove access methodically.

3. Protect your backups before you touch anything else

Find out where your backups actually live, who owns the backup account, whether the payments behind it are up to date, whether the outgoing provider can still delete or alter them, and when someone last successfully tested a restore. A dashboard full of green ticks tells you nothing useful in a crisis. You need proof the data exists and can be recovered without relying on the provider that just let you down.

Where you can, create or verify a recovery copy the outgoing MSP has no ability to touch.

4. Map every service and contract you actually have

Most SMEs discover, usually at the worst possible moment, that their IT contract is only one layer of a much bigger relationship. Your provider may also be reselling Microsoft licences, broadband and leased lines, telephone systems, cloud hosting, endpoint security, backup services, or hardware leases.

Work out which of these contracts sit directly between you and the underlying supplier, and which exist entirely through the MSP. The NCSC recommends keeping an up-to-date map of suppliers and dependencies precisely so you know where the risk sits and can do proper due diligence when you need to, not when you’re forced to. For each service, note the renewal date, the notice period, who owns the account, how it’s paid for, and who to call.

5. Get your documentation and evidence out now

Download copies of network diagrams, asset registers, licence records, backup reports, support history, supplier contracts, security policies, configuration records, and data-processing agreements while you still can. A good supplier should have furnished you with this stuff anyway.

Under UK GDPR, your business will usually remain the controller of its personal data, with the MSP acting as a processor working to your instructions.

That relationship has to be governed by a written contract covering security, instructions, and what happens to your data when the arrangement ends. If you can’t work out where your data lives, or you can’t get hold of it without the provider’s cooperation, that’s not a technicality. That’s a governance failure you didn’t know you had.

6. Bring in a replacement provider quickly, but don't rush blindly

The job right now is stabilisation, not a full transformation project dressed up as an emergency fix. A good replacement provider will start by verifying administrative control, assessing the immediate security risks, protecting your backups, checking your licences are still valid, identifying anything undocumented, monitoring the systems that matter most, and setting up an emergency support route. Longer-term recommendations come after that, not instead of it.

Be wary of anyone who tries to use the chaos as an opening to sell you a full rebuild before they’ve properly understood what you’ve got.

The leadership takeaway

Outsourcing your IT was never the same as outsourcing accountability for it. Your Managed Services Provider runs the technology your business operates upon. But, your business still owns the risk, the disruption, and every commercial consequence if control slips away from you.

The right time to check whether you could switch provider safely is before you’re forced to find out the hard way. And don’t forget, always try and stay in touch with the risks your supplier base presents.

Unsure where you stand, want to assess your risks? Book a no obligation IT review.

Newsletter

Subscribe for monthly IT advice and a chance to get Co-Op Live tickets.

Follow Us