12 Crucial Questions to Ask Before Hiring an IT Company in Kenya
Every managed service provider Kenya pitch sounds the same: “24/7 support,” “proactive monitoring,” “we’ve got you covered.” Yet the difference between a provider that genuinely protects your business and one that leaves you exposed rarely shows up in the sales call. Instead, it shows up three months in, when a server goes down on a Friday afternoon, or a phishing email locks up your files.
Kenya’s threat environment makes this decision higher-stakes than it used to be. In fact, the Communications Authority of Kenya‘s National KE-CIRT/CC detected 3.37 billion cyber threat events in the first quarter of 2026 alone. Moreover, roughly 37% of Kenyan organisations reported a cyber incident in the past year mostly phishing and ransomware. On top of that, the Data Protection Act, 2019 now carries real enforcement teeth, with the ODPC issuing penalty notices and pushing for structured accountability rather than warnings.
This guide gives you 12 direct questions to ask any IT company Nairobi businesses are considering organised around the five areas that actually predict whether a partnership will work: SLAs, cybersecurity, backup, pricing, and red flags.
Want a copy to bring into your vendor meetings? Message us on WhatsApp for our free, printable MSP evaluation scorecard – all 12 questions laid out with space to score each provider you’re comparing.
The 12 Questions at a Glance
Use this as your scorecard. If a provider hesitates, deflects, or can’t answer in specifics on any of these, treat it as data.
| # | Question | Category |
|---|---|---|
| 1 | What are your guaranteed response and resolution times for critical issues in writing? | SLA |
| 2 | Is your 24/7 support a staffed help desk, or an answering service that escalates the next morning? | SLA |
| 3 | What happens if you miss your own SLA – service credits, or just an apology? | SLA |
| 4 | Are you monitoring my systems proactively, or only reacting when I report a problem? | Cybersecurity |
| 5 | How do you support my Data Protection Act compliance, including ODPC registration and breach notification? | Cybersecurity |
| 6 | Walk me through the first 24 hours of your ransomware incident response plan. | Cybersecurity |
| 7 | Are backups tested with real restores, or just marked “completed” on a dashboard? | Backup |
| 8 | What are your Recovery Time Objective and Recovery Point Objective for my business? | Backup |
| 9 | Is pricing per user, per device, or a flat retainer and what’s excluded? | Pricing |
| 10 | Can I see a sample itemised invoice before I sign? | Pricing |
| 11 | Can I speak to two or three current clients of a similar size to my business? | Red Flags |
| 12 | What’s the exit process, and do I keep full ownership of my data and accounts if I leave? | Red Flags |
SLA: The Questions That Reveal Whether Support Promises Are Real
A Service Level Agreement is the one document that turns “we’ll take care of you” into something enforceable. Industry benchmarks for a well-run MSP typically look like this: critical (P1) issues acknowledged within 15 minutes with resolution in 1-4 hours. High-priority (P2) issues acknowledged within 30-60 minutes. Routine (P3/P4) requests handled within a business day or two. Furthermore, P1 and P2 coverage should run 24×7, not just during office hours.
1. What are your guaranteed response and resolution times for critical issues in writing? Verbal promises about “fast support” mean nothing without a documented SLA. Request the actual document, not a summary, and verify that response times differ meaningfully by priority level. A provider unwilling to put numbers on paper is telling you they can’t consistently hit them.
2. Is your 24/7 support a staffed help desk, or an answering service that escalates the next morning? Many providers advertise round-the-clock coverage that’s really an on-call technician or a call centre that logs the ticket and does nothing until business hours. Specifically, you should ask who answers a 2am critical alert and how quickly they can actually act on it.
3. What happens if you miss your own SLA service credits, or just an apology? An SLA without a consequence for missing it is a marketing document, not a contract. Look for language around service credits or fee reductions tied to missed response or resolution targets. Additionally, ask how often (if ever) they’ve had to pay out.
Cybersecurity: The Questions That Matter Most in 2026
This is arguably the most important category on this list. Kenya’s cyber threat volume has grown sharply. According to KE-CIRT/CC reporting, roughly 90% of attacks still begin with a phishing email. Meanwhile, identity-based attacks – phishing, credential theft, business email compromise now account for close to half of all recorded incidents in Africa. Consequently, an IT company Nairobi businesses hire today needs to be a security partner first, not just a help desk.
4. Are you monitoring my systems proactively, or only reacting when I report a problem?
A reactive provider fixes things after they break. A proactive one watches for the warning signs – failed logins, unpatched systems, unusual network activity before they become an incident. Specifically, ask what tools they use for monitoring and how quickly an alert reaches a human.
5. How do you support my Data Protection Act compliance, including ODPC registration and breach notification?
Under the Data Protection Act, 2019, most businesses handling personal data need to register with the Office of the Data Protection Commissioner. Breaches generally must be reported within 72 hours. Penalties can reach KES 5 million or 1% of annual turnover for data controllers. A provider that shrugs at this question, or doesn’t know the ODPC exists, isn’t equipped to protect you legally, not just technically.
6. Walk me through the first 24 hours of your ransomware incident response plan.
Every provider claims to “take security seriously.” Few can actually describe, step by step, what happens if your files get encrypted tomorrow morning, who gets called, how systems get isolated, how backups get verified before restoring, and how the breach notification clock gets managed. If they can’t answer this in specifics, they haven’t rehearsed it, and neither have you.
Backup: The Questions Most Businesses Forget to Ask
A backup that has never been tested is a hope, not a plan. In fact, this is the single most common gap between what an IT provider promises and what actually works when it’s needed.
7. Are backups tested with real restores, or just marked “completed” on a dashboard?
A backup job can report “success” every night for a year and still fail to restore usable data when you actually need it corrupted files, incomplete snapshots, or a missed folder are common culprits. Therefore, ask how often they perform an actual test restore, not just a status check, and request evidence of the last one.
8. What are your Recovery Time Objective and Recovery Point Objective for my business?
Recovery Time Objective (RTO) is how long it takes to get you back up and running after an outage. Recovery Point Objective (RPO) is how much data you could lose the gap since the last successful backup. A provider should be able to state both in hours, tailored to your business, not a generic “we back up daily.”
Pricing: The Questions That Prevent Surprise Invoices
Managed IT pricing in Kenya varies widely. Smaller support retainers in the Nairobi market can start from around KES 10,000 per month for basic plans. Pricing scales up with user count, device count, and included hours. Extra support hours or on-site visits are typically billed separately, often in the KES 2,500-4,500 range per visit or hour beyond the plan. Moreover, full managed services with proactive cybersecurity monitoring and backup management generally cost meaningfully more than a bare-bones “break-fix” retainer.
The number on the quote matters less than what’s actually included in it. This is where a lot of Kenyan SMEs get caught out – a low headline price that excludes security monitoring, backup testing, or after-hours support, with those items appearing later as add-ons.
9. Is pricing per user, per device, or a flat retainer and what’s excluded?
Ask for a plain-language list of what’s covered under the monthly fee and what triggers an additional charge: after-hours emergencies, on-site visits, new device setup, security incident response, project work. Get this in writing before you sign.
10. Can I see a sample itemised invoice before I sign?
A real invoice from an existing client (with identifying details removed) tells you far more than a proposal document. It shows you exactly how extra charges get itemised in practice, not just in theory.
Red Flags: What Weak Providers Have in Common
11. Can I speak to two or three current clients of a similar size to my business? A provider confident in their service will connect you with references without hesitation. Hesitation, excuses, or only offering testimonials from their website is a signal worth taking seriously.
12. What’s the exit process, and do I keep full ownership of my data and accounts if I leave? Ask this before you sign, not when you’re trying to leave. You should retain full ownership and administrative access to your domain, email accounts, licences, and data regardless of who supports it. A provider that holds your accounts hostage as leverage is a provider to avoid entirely.
Beyond the two questions above, watch for these patterns during the sales process itself:
• No written SLA, or a vague one that avoids specific numbers for response and resolution times.
• Can’t explain how they support Data Protection Act compliance or hasn’t heard of the ODPC.
• Reporting only happens when something goes wrong, with no regular monthly reports or reviews.
• Long-term contracts with heavy early-termination penalties and no clear exit process.
• Pressure to sign quickly, paired with a price that seems unusually low for the scope described.
The Bottom Line
Choosing an IT company Nairobi businesses can rely on isn’t about finding the provider with the slickest pitch deck. It’s about finding one that answers these 12 questions with specifics documented SLAs, a real security posture, tested backups, transparent pricing, and a clean exit process rather than reassurance. With Kenya’s cyber threat volume and Data Protection Act enforcement both rising through 2026, the cost of getting this decision wrong is no longer just downtime. It’s regulatory exposure too.
Take the Guesswork Out of Choosing an MSP
Comparing providers on gut feel is how businesses end up with weak SLAs, untested backups, and unclear pricing. Sapiens IT Lab’s managed IT services team is happy to walk you through our own answers to all 12 questions – SLA, security posture, backup testing, and pricing with no obligation.
Want the printable scorecard to use with any provider you’re evaluating, including us? Message us on WhatsApp and we’ll send it straight over, along with a free assessment of your current IT setup.
Get the Free Scorecard on WhatsApp



