What Should Business Leaders Ask During an MSP Review Meeting?

Many businesses have regular review meetings with their Managed Service Provider (MSP).

Unfortunately, too many of these meetings focus on technical updates, ticket numbers, and discussions that have little connection to business objectives.

A successful MSP relationship should be about far more than resolving support issues.

It should help your organisation:

  • Improve cybersecurity
  • Reduce downtime
  • Control costs
  • Support business growth
  • Improve productivity
  • Plan for the future

Whether you're a managing director, finance director, CEO, trustee, operations manager, or business owner, asking the right questions can help ensure you're receiving genuine strategic value from your IT partner.

In this guide, we'll explore the most important questions business leaders should ask during an MSP review meeting and explain why each one matters.

Why MSP Review Meetings Matter

Many organisations only engage with their MSP when something goes wrong.

However, the most successful businesses take a proactive approach.

Regular review meetings create an opportunity to:

  • Assess performance
  • Identify risks
  • Review cybersecurity
  • Discuss future plans
  • Improve budgeting
  • Align technology with business goals

A good MSP review should focus as much on the future as it does on the past.

The 10 Questions Every Business Leader Should Ask

1. What Are Our Biggest Technology Risks Right Now?

Every organisation has technology risks.

The question is whether those risks are understood and being managed effectively.

Examples may include:

  • Cybersecurity vulnerabilities
  • Ageing infrastructure
  • Unsupported software
  • Backup concerns
  • Compliance issues

Why This Matters

Business leaders need visibility into the risks that could affect operations, finances, or reputation.

What Good Looks Like

Your MSP should provide clear, business-focused answers rather than technical jargon.

2. What Cybersecurity Improvements Should We Prioritise?

Cybersecurity should be a standing agenda item in every review meeting.

Ask:

  • What are our biggest security gaps?
  • What improvements should we prioritise?
  • How do we compare to industry best practice?

Why This Matters

Threats evolve constantly.

Businesses need a clear improvement plan rather than reacting after an incident.

What Good Looks Like

Your MSP should provide practical recommendations linked to risk reduction.

3. Are We Making Full Use of Microsoft 365?

Many organisations invest heavily in Microsoft 365 but only use a fraction of its capabilities.

Ask:

  • Are we using Microsoft 365 effectively?
  • Are there features we're paying for but not using?
  • Could we improve collaboration or security?

Areas Often Overlooked

  • Microsoft Teams
  • SharePoint
  • OneDrive
  • Microsoft Defender
  • Intune
  • Automation tools

Why This Matters

Optimising existing investments often delivers more value than purchasing new technology.

4. What Technology Investments Should We Budget for Over the Next 12–36 Months?

Unexpected IT costs create challenges for every organisation.

Ask:

  • Which devices require replacement?
  • Are any systems approaching end-of-life?
  • What major projects should we plan for?

Why This Matters

Strategic budgeting reduces surprises and supports better financial planning.

What Good Looks Like

A technology roadmap covering:

  • Hardware replacement
  • Cybersecurity investments
  • Cloud initiatives
  • Business improvement projects

5. How Are We Performing Against Industry Standards?

Many organisations have no benchmark for evaluating their technology environment.

Ask:

  • How does our cybersecurity compare?
  • Are we behind industry best practice?
  • Where should we improve?

Why This Matters

External benchmarking helps prioritise investments and identify weaknesses.

6. What Is Causing the Most Support Requests?

Support tickets often reveal recurring issues.

Ask:

  • What are the most common support problems?
  • Are there recurring patterns?
  • How can we eliminate them?

Why This Matters

The goal is not simply resolving tickets.

The goal is reducing the need for tickets.

What Good Looks Like

Your MSP should identify root causes and propose permanent solutions.

7. How Prepared Are We for a Cyber Incident?

Every organisation should assume that one day a cyber incident may occur.

Ask:

  • Could we recover from ransomware?
  • Have backups been tested?
  • Do we have an incident response plan?

Why This Matters

Recovery readiness is just as important as prevention.

What Good Looks Like

Clear answers supported by documented processes and testing.

8. Are We Meeting Compliance and Governance Requirements?

Compliance expectations continue to increase.

Depending on your sector, this may include:

  • Cyber Essentials
  • Data protection requirements
  • Governance obligations
  • Customer security requirements

Why This Matters

Non-compliance can create operational and reputational risks.

What Good Looks Like

Regular reviews and documented improvement plans.

9. Is Technology Helping or Hindering Business Growth?

Technology should support growth.

Ask:

  • Are our systems scalable?
  • Will our current infrastructure support future plans?
  • Are there bottlenecks we should address?

Why This Matters

Technology should enable growth rather than become a constraint.

What Good Looks Like

Strategic recommendations aligned with business objectives.

10. If You Were Running Our Business, What Would You Change?

This is often the most revealing question.

It encourages your MSP to think strategically rather than operationally.

Why This Matters

An experienced MSP sees many businesses and often identifies opportunities that internal teams overlook.

What Good Looks Like

Honest, practical recommendations linked to business outcomes.

What Topics Should Be Included in Every MSP Review?

A productive review meeting should typically cover:

Service Performance

  • Support metrics
  • Response times
  • Recurring issues

Cybersecurity

  • Risks
  • Improvements
  • Training
  • Compliance

Infrastructure

  • Device lifecycle planning
  • Capacity reviews
  • Reliability concerns

Microsoft 365

  • Security
  • Collaboration
  • Licensing optimisation

Strategic Planning

  • Technology roadmap
  • Business objectives
  • Future projects

The discussion should focus on outcomes rather than technical detail.

Warning Signs Your MSP Review Meetings Lack Value

If your meetings only discuss:

  • Ticket numbers
  • Technical terminology
  • Minor issues

You may not be receiving the strategic guidance your organisation needs.

Common Red Flags

  • No discussion of cybersecurity
  • No technology roadmap
  • No budgeting conversations
  • No business alignment
  • No future planning

Review meetings should help leadership make informed decisions.

MSP Review Meeting Scorecard

Use this checklist during your next review meeting.

Question Discussed?
Technology Risks Reviewed
Cybersecurity Reviewed
Microsoft 365 Optimisation Discussed
Future Budget Requirements Discussed
Hardware Lifecycle Reviewed
Compliance Requirements Reviewed
Backup Testing Confirmed
Business Growth Plans Discussed
Technology Roadmap Updated
Strategic Recommendations Provided

Results

If fewer than seven of these areas are covered regularly, your review meetings may be too operational and not strategic enough.

How Stratiis Helped A Growing Scottish Charity

Their Situation

A 40-person charity held quarterly MSP review meetings focused almost entirely on support tickets.

Their Challenges

  • No cybersecurity roadmap
  • No budgeting visibility
  • No strategic planning
  • Limited awareness of technology risks

The New Review Structure

Meetings began covering:

  • Cybersecurity
  • Technology planning
  • Device replacement
  • Microsoft 365 optimisation
  • Business continuity

The Outcomes

Benefits included:

  • Better budgeting
  • Reduced risk
  • Improved planning
  • Greater trustee confidence
  • Clearer technology priorities

The value of the meetings increased significantly because they focused on business outcomes rather than technical issues.

Why Businesses Across Scotland Choose Stratiis

At Stratiis, we believe MSP review meetings should help organisations make better business decisions.

Our strategic review process includes:

  • Cybersecurity assessments
  • Technology roadmaps
  • Budget forecasting
  • Microsoft 365 optimisation
  • Business continuity planning
  • Risk reviews
  • Strategic vCIO guidance

We support charities, nonprofits, law firms, manufacturers, engineering companies, housing associations, construction businesses, accountants, and other organisations throughout Scotland.

Our goal is to ensure technology supports your business objectives—not simply maintain your infrastructure.

Final Thoughts

The most valuable MSP review meetings focus on more than support tickets.

They help business leaders understand:

  • Technology risks
  • Cybersecurity priorities
  • Budget requirements
  • Future opportunities
  • Business continuity
  • Strategic investments

The right questions lead to better conversations.

And better conversations lead to better technology decisions.

If your MSP review meetings are not helping you plan, improve, and reduce risk, it may be time to rethink what you expect from your technology partner.

Related Articles

What Does a Strategic vCIO Do for a Growing Business and Is It Worth It?

What Are the Warning Signs That We've Outgrown Our Current MSP?

How Much Downtime Does Unmanaged IT Typically Cost a Business?

How Much Should Managed IT Support Cost for a 10–100 Employee Business in Scotland?