What Your IT Provider Is Responsible For — And What They Are Not 

it provider responsibilities

Table of Contents

Most professional services firms operate under a quiet assumption: that their IT provider is handling it. Handling what, exactly, is rarely defined. The contract covers the technology. The relationship covers the rest. And somewhere in that gap, responsibility goes unassigned. 

This matters because professional services firms carry a different kind of risk. You hold client data. You operate under regulatory frameworks. You have duties of confidentiality that pre-date the internet. When something goes wrong — a data breach, a ransomware incident, a failed ICO audit — the question of who was responsible for what becomes consequential very quickly. 

The problem is rarely bad intent on either side. IT providers assume their clients understand what a managed service does and does not include. Firms assume their provider is watching everything. Nobody writes down where one ends and the other begins. This article maps that boundary clearly. 

What is my IT provider responsible for?

A managed IT provider takes ownership of the technology they manage. That usually means devices are patched and updated, core software is maintained, backups are running and checked, and security tools such as antivirus, endpoint detection, and email filtering are configured and monitored. 

On the security side, a competent provider will manage the firewall and network perimeter, configure multi-factor authentication, and respond to alerts from the tools they operate. If email is compromised or ransomware hits a managed device, they are responsible for the technical response. 

They are also responsible for advice. If the setup has gaps, they should say so in plain language, not bury it in a technical report. A good provider does not just maintain what exists. They explain what needs attention before something breaks. 

What they are not responsible for is how the firm uses what they build. They can lock a door. They cannot stop someone propping it open. 

What is my firm responsible for? 

Firms carry more responsibility than most realise, and that does not transfer when a managed service agreement is signed. The clearest example is data governance. What data the firm holds, how long it keeps it, and where it is stored are decisions that belong to the firm. 

User behaviour sits with the firm too. An IT provider can train staff and reduce risk through configuration. They cannot stop a fee-earner forwarding sensitive documents to a personal email address or clicking a phishing link late on a Friday. Policy, training, and culture are still management responsibilities. 

Access approvals are another area firms often underestimate. When someone joins and needs access to a matter management system, the firm decides whether that access is appropriate. When someone leaves, the firm must trigger removal. The provider can carry out the task, but not make the decision. 

The same applies to policy choices. Whether to allow personal devices to access firm email, whether to enable sharing with external parties, and whether to permit access from overseas are governance decisions with legal and regulatory weight. The provider should advise. The firm decides. 

What Sits Between Your Business and Your IT Provider? 

This is where most of the friction lives. Not in what the provider clearly owns or what the firm clearly owns, but in the territory nobody claimed at the start of the relationship. 

Cyber insurance declarations are a common flashpoint. When an insurer asks about MFA coverage, patching, or endpoint detection, who completes the declaration? If the provider fills it in, they rely on the firm to confirm the answers are accurate. If the firm fills it in, it may be guessing what the provider has actually implemented. 

Either way, a mismatch between what the policy says and what is in place can be used to decline a claim. That conversation needs to happen before renewal, not after an incident. 

Software licensing sits in a similar space. The provider may manage Microsoft licences, but who tracks the specialist tools the teams use every day? If nobody owns that audit, gaps stay hidden until they become a cost or a legal problem. 

Shadow IT is another grey area. When a team starts using a file-sharing tool, an AI assistant, or a communication app that was never approved, it may never appear on the provider’s radar. The data moving through those tools is still the firm’s data. The risk is still the firm’s risk. 

Leavers and joiners deserve separate attention. Providers can disable accounts and revoke device access, but only when they are told. The trigger sits with HR, operations, or firm leadership. Without a formal process that includes IT, former employees can keep access for weeks. 

Clear ownership does not require a complex document. It requires a direct conversation, ideally at the start of the relationship and at least once a year thereafter. Put in writing what the provider monitors and responds to, what the firm owns, and which areas need a defined process between you. Review it when staff numbers change, when regulations shift, or when something nearly went wrong. The firms that handle incidents well are almost always the ones that had this conversation before they needed it. 

Not sure where the line sits in your firm?

The IT Ownership Scorecard takes 5 minutes.

02890 025 435

hello@innosec.co.uk

Unlock the Future of Work with Microsoft Copilot!

microsoft ebook cover ebook cover

50 Reasons Why Your Business Should Be Using Microsoft Copilot

💼 Supercharge Productivity
🛡️ Boost Security
📊 Empower Data-Driven Decisions

This website uses cookies

We use cookies to personalise content, provide social media features, and analyse our traffic. We also share information about your use of our site with our analytics partners. You can change your preferences at any time. For more information, please see our Privacy Policy and Cookie Policy.

02890 025 435

hello@innosec.co.uk