
Most businesses choose an IT company in Las Vegas the same way they choose any other vendor: compare a few quotes, ask how quickly someone will answer the phone, and pick the one that feels right. Price and responsiveness matter. They are also the two things every provider will tell you they're good at.
What gets less attention is how much access you are handing over. Within a few weeks of signing, your IT provider will typically hold administrative access to your:
- Computers and servers
- Microsoft 365 tenant and email
- Firewalls and network equipment
- Backups
- Cloud systems
- Sensitive business, customer and employee data
That makes an IT provider two things at once: a technology partner and a security-critical vendor. If their own accounts are compromised, or their processes are loose, your environment is exposed along with theirs. The questions below are the ones we would ask any provider of managed IT services in Las Vegas, including us, before signing a contract.
15 questions to ask an IT company before you sign
1. What exactly is included in your monthly price?
A per-user price means little until you know what it covers. Ask the provider to list, in writing, which of these are included and which are billed separately:
- Help desk and remote support
- 24/7 monitoring and alerting
- Patching for operating systems and third-party applications
- Security tools (endpoint protection, EDR/MDR, email security, filtering)
- Backup software, storage and restore testing
- Projects such as migrations, new offices or network redesigns
- On-site visits
- After-hours and weekend work
- Software licensing, including Microsoft 365
Two quotes with the same monthly number can describe very different services. Our 2026 pricing guide walks through how to compare them, and our own rates are published on the Managed IT Services page.
2. What cybersecurity protections are included?
"We install antivirus" is not an adequate description of a modern security program. A credible answer should cover:
- Endpoint security and EDR/MDR: detection and response on every computer and server, not just signature-based antivirus, and who reviews the alerts.
- Email security: filtering for phishing, malicious attachments and impersonation.
- Multi-factor authentication (MFA): where it is enforced and whether any accounts are exempt.
- DNS or web filtering: blocking known-malicious sites before a connection is made.
- Vulnerability management: finding and fixing weaknesses on a schedule, not only when something breaks.
- Security monitoring: who is watching, at what hours, and what happens when an alert fires at 2 a.m.
- Incident response: what the provider does, and does not do, when something gets through.
Ask which of these are in the base price and which are add-ons. Our cybersecurity services page describes how we approach this.
3. How do you secure your own administrative accounts?
An MSP's technician accounts are among the most valuable targets in your environment, because one compromised account can reach many customers. Ask:
- Is MFA required on every administrative account and remote access tool, with no exceptions?
- Do technicians use separate admin accounts, distinct from their everyday email accounts?
- Are passwords stored in a managed password vault rather than spreadsheets or shared documents?
- Is access granted on least privilege, meaning only the access each role needs?
- Is administrative activity logged, and who reviews the logs?
4. Who has administrative access to our systems?
You should know which people at the provider can administer your systems, how they get that access, and how it is removed when a technician leaves the company. Ask whether access is individual (named accounts you can audit) or shared (one login many people use). Shared credentials make it impossible to tell who did what, and hard to cut off one person's access.
5. How do you handle backups, and how do you know they can actually be restored?
Backup monitoring tells you a job finished. Restore testing tells you the data comes back. They are not the same thing, and many businesses discover the difference during an outage.
Terms worth knowing:
- Off-site backups: a copy stored somewhere other than your office, so a fire, flood or theft doesn't take the backup with the original.
- Immutable backups: copies that cannot be changed or deleted for a set period, even by an administrator. This matters because ransomware often targets backups first.
- Recovery testing: actually restoring files, or whole systems, on a schedule to prove it works.
- RPO (recovery point objective): how much data you can afford to lose, measured in time. An RPO of four hours means backups run at least every four hours.
- RTO (recovery time objective): how long you can afford to be down while systems are restored.
Ask the provider what RPO and RTO their plan supports, how often restores are tested, and whether you receive the results. Our disaster recovery page covers planning in more detail.
6. What happens when we have a cybersecurity incident?
Ask the provider to walk you through their process:
- Escalation: who is notified, and how quickly, when a serious alert fires.
- Containment: isolating affected devices or accounts to stop the spread.
- Communication: who contacts you, and how they keep leadership informed.
- Forensic support: whether they perform investigation themselves or bring in a specialist firm.
- Cyber insurance coordination: many policies require you to use approved incident response firms and notify the insurer early. Your provider should know to ask.
- Recovery: restoring systems, resetting credentials and confirming the attacker is gone.
A provider that has never thought through this sequence will be improvising when it matters most.
Dominant-IT can handle incident response from start to finish. For larger organizations, we also work alongside the incident response vendors assigned by a cyber insurance carrier.
7. How do you handle employee onboarding and offboarding?
Most access problems start with a new hire set up in a hurry or a departing employee who was never fully removed. A good process covers:
- Onboarding: account creation, correct group permissions, MFA enrollment and a device configured to a standard.
- Offboarding: disabling accounts on the last day, revoking active sessions and tokens (so a signed-in phone doesn't keep working), recovering devices, and transferring mailbox or file ownership.
- Access reviews: checking periodically that permissions still match people's roles.
Ask how offboarding requests are submitted and how quickly they are completed.
8. How do you manage Microsoft 365?
For most small and mid-sized businesses, Microsoft 365 holds email, files and identity. Ask about:
- MFA for every user, not just administrators.
- Conditional Access: rules that decide when sign-ins are allowed, for example blocking sign-ins from unmanaged devices or unexpected countries.
- Administrative roles: how many Global Administrators exist and whether day-to-day work uses lower-privilege roles.
- Email security settings and anti-phishing policies.
- SharePoint and OneDrive permissions: who can see what.
- External sharing: whether users can share files with anyone on the internet.
- Logging: whether audit logs are enabled and retained.
- Secure configuration: whether the tenant is checked against a baseline, rather than left on defaults.
9. How do you patch computers and servers?
Patching should be monitored and verified, not simply configured and assumed. Ask how the provider confirms that updates actually installed, what happens to devices that fail or stay offline, and whether they patch third-party applications (browsers, PDF readers, Java, line-of-business software) as well as Windows and macOS. Unpatched third-party software is a common way in.
10. How do you monitor our network?
Your network includes more than computers. Ask how the provider monitors and maintains:
- Firewalls
- Switches
- Wireless access points
- Internet connectivity and failover
- Firmware versions on network devices
- Configuration backups and change tracking
Ask what triggers an alert, who receives it, and what happens next.
11. How do you help with compliance requirements?
If your business handles patient information, card payments or sensitive client data, ask how the provider supports the frameworks you are subject to, such as:
- HIPAA for healthcare organizations and their business associates
- PCI DSS for businesses that store, process or transmit cardholder data
- Cyber insurance security requirements, which increasingly ask about MFA, EDR and backups
- SOC 2, where your own customers require it
Using an MSP does not make a business compliant. Compliance depends on your policies, your people and your processes as well as your technology. A provider can help you implement controls and produce documentation, but you remain responsible. Dominant-IT works with HIPAA, PCI DSS, SOC 2 readiness and NIST 800-53; our HIPAA guide and PCI guide explain what each involves.
12. What happens if our primary technician is unavailable?
Many small businesses depend on one technician who knows everything about their environment. When that person is sick, on vacation or leaves, the knowledge goes with them. Ask about:
- Documentation of your network, systems and procedures
- Credential management in a shared, access-controlled vault
- Standardized configurations, so any technician can work on any system
- Ticket history that records what was done and why
- Cross-training, so more than one person knows your environment
13. Who owns our accounts, domains, licenses and documentation?
This is one of the most important questions on the list. There is a difference between allowing an MSP to administer an account and allowing the MSP to own it. Your business should keep ownership and control of:
- Domain registration (your website and email depend on it)
- Your Microsoft 365 tenant
- Cloud accounts such as Azure, AWS or Google Workspace
- Firewall administrative access
- Backup data
- Software licensing
The provider should have administrative access through named accounts you can remove. If a relationship ends badly and the provider owns your domain or tenant, recovering them can be slow and expensive.
14. What happens if we decide to leave?
Understand the exit process before you sign, while everyone is on good terms. Ask about:
- Contract termination: notice period and any early termination fees
- Documentation transfer: network diagrams, configurations and procedures
- Credential transfer: all administrative passwords and MFA methods
- Data export: backups and any data held in the provider's systems
- Licensing: which licenses are yours and which are the provider's
- Equipment ownership: leased versus purchased hardware
- Cooperation with your next provider during the handover
15. Can you explain your recommendations without hiding behind technical jargon?
A good IT provider should be able to explain a recommendation in business terms: the risk it addresses, what it costs, what the alternatives are, and what happens if you do nothing. "It's best practice" is not an explanation. If a provider can't explain why something matters to your business, you can't make an informed decision about it.
Red flags when choosing a Las Vegas IT company
None of these automatically means a provider is incompetent. Each one deserves a follow-up question and a clear answer before you sign.
- No MFA on administrative access. This is the single most common gap in provider security.
- Shared administrator accounts. You can't audit who did what.
- No documented backup testing. Monitoring alone doesn't prove restores work.
- Vague cybersecurity answers. "We've got you covered" instead of specifics.
- No clear onboarding and offboarding process.
- Extremely low pricing without explaining exclusions. The difference usually shows up later as project fees or hourly bills.
- The provider owns your domain or critical cloud accounts.
- No documented process for ending the relationship.
- No clear escalation process for urgent issues or incidents.
- The provider can't explain what its security tools actually do.
What should a good MSP be able to show you?
Anyone can describe a process. Ask to see evidence of it, with sample or redacted data if needed:
- Sample reports they provide to clients
- Patch status across devices, including failures
- Backup status and restore test results
- Asset inventory of computers, servers and network devices
- Security alerts and how they were handled
- Documentation practices, such as a redacted example of client documentation
- Ticket metrics, such as volume and resolution times
- Network documentation, including diagrams
A provider that is confident in its work should be comfortable showing you what it looks like.
Dominant-IT can supply any of these reports on request, or on a regular schedule.
15-question MSP interview checklist
Print this list and take it into each provider meeting. Write down each answer, and ask for anything important in writing.
| # | Question | Provider A | Provider B | Provider C |
|---|---|---|---|---|
| 1 | What exactly is included in the monthly price? | |||
| 2 | What cybersecurity protections are included? | |||
| 3 | How do you secure your own admin accounts? | |||
| 4 | Who has admin access to our systems, and how is it removed? | |||
| 5 | How are backups tested? What are the RPO and RTO? | |||
| 6 | What is your incident response process? | |||
| 7 | How do you handle onboarding and offboarding? | |||
| 8 | How do you secure and manage Microsoft 365? | |||
| 9 | How do you verify patching, including third-party apps? | |||
| 10 | How do you monitor our network equipment? | |||
| 11 | How do you support our compliance requirements? | |||
| 12 | What if our primary technician is unavailable? | |||
| 13 | Do we own our domain, tenant, cloud accounts and backups? | |||
| 14 | What is the exit process and what does it cost? | |||
| 15 | Can you explain recommendations in business terms? |
Choosing an IT company in Las Vegas: what matters most
Price matters, and so does responsiveness. But the provider you choose will hold the keys to your systems and data, so choose based on transparency, technical capability, security practices, communication, documentation and business fit. The best answers to these questions are specific, written down and consistent from one meeting to the next.
Frequently asked questions
How do I choose an IT company in Las Vegas?
Compare providers on what their monthly price includes, how they secure your systems and their own accounts, how they test backups, who owns your accounts and data, and how the relationship ends. Ask each provider the same questions and get key answers in writing.
What should be included in a managed IT services contract?
A written scope of services, response times, support hours, security services, backup responsibilities, exclusions, contract length, termination terms, and how documentation and credentials are handed over if you leave.
Should my IT company own my domain or Microsoft 365 account?
No. Your business should own its domain registration, Microsoft 365 tenant, cloud accounts, backup data and licensing. The provider should have administrative access through named accounts you can remove.
Does hiring an MSP make my business HIPAA or PCI compliant?
No. An MSP can help implement technical controls and documentation, but compliance also depends on your policies, training and processes. Your business remains responsible.
What is the difference between backup monitoring and restore testing?
Monitoring confirms that backup jobs ran. Restore testing proves the data can actually be recovered. A reliable backup program includes both.
What are RPO and RTO?
RPO (recovery point objective) is how much data you can afford to lose, measured in time. RTO (recovery time objective) is how long you can afford to be down while systems are restored.
What are red flags when hiring an IT company?
No MFA on administrative accounts, shared admin logins, no backup testing, vague security answers, very low pricing without clear exclusions, a provider that owns your domain or cloud accounts, and no defined exit process.
Bring us the list
If you're evaluating IT providers in Las Vegas, bring us this list. We're happy to answer these 15 questions about how Dominant-IT would manage and secure your environment, and to talk through what you have in place today. No pressure and no obligation. Contact us, call (702) 514-0583, or email contact@dominant-it.com.
Further reading
- CISA: More than a Password (Multi-Factor Authentication)
- NIST: Cybersecurity Framework
- Microsoft Learn: What is Conditional Access?
- U.S. Department of Health and Human Services: HIPAA Security Rule
- PCI Security Standards Council: Document Library