What happens in the first 90 days with a new IT provider?
In a competent changeover, the first 90 days run in three phases: discovery, where everything is documented and credentials transfer; stabilisation, where monitoring, patching and backups are brought to standard; then improvement, where the plan you actually bought starts delivering. Your old provider is needed for weeks one and two; your patience for about six.
Most businesses that should switch providers delay for a year or more, and the reason is rarely satisfaction; it is the hostage feeling. Nobody is sure what the passwords are, what is documented, or what breaks if the relationship ends, and that uncertainty is read as a reason to stay. Read it the other way: if your business cannot see its own IT without the incumbent's goodwill, that is the strongest argument for a changeover to a provider who documents, because the fear is describing the current arrangement, not the switch.
Phase one is discovery, roughly the first fortnight. The incoming provider collects and verifies administrative credentials, domain and licensing details, and backup access from the outgoing one, then documents what actually exists: every device, account, application and vendor, checked rather than assumed. Expect an access audit with awkward findings, ex-staff who still have accounts, admin rights nobody remembers granting. This is also the only phase where the old provider is truly needed, so the handover checklist, credentials, documentation, licence ownership, backup custody, is agreed in writing before notice runs out. Nothing in this phase should change how staff work; it is archaeology, not construction.
Phase two is stabilisation. Monitoring and management tooling is deployed across your systems, patching is brought to a baseline, backups are configured to standard and, critically, test-restored, and the security controls of the tier you purchased are implemented against the Essential Eight. Expect noise in this phase, and treat it as a good sign: things are being found, because someone is finally looking. A findings report at the end of it, what was discovered, what was fixed, what is recommended, is the deliverable that tells you the phase actually happened. It is also when the security tier you chose becomes real: controls implemented and evidenced, not promised.
Phase three is improvement. With the environment documented, watched and stable, the service you bought starts operating as designed: the desk answering, maintenance running quietly, and the first proper review meeting, where recommendations from the findings report become a roadmap with owners and rough timing. Quick wins land here; larger projects get scoped rather than smuggled into the monthly fee. This is the phase where you learn whether you bought a service or a subscription, because improvement requires initiative, and initiative is visible.
You have a role in each phase, and it is small but real. Name one internal owner for decisions so approvals do not scatter. Tell staff plainly how to get help from day one, because the fastest way to sour a transition is a team still emailing the old provider out of habit. And judge the transition on evidence rather than speed alone: the earliest work is administrative by design, and the visible improvements come once the environment is documented. A short weekly note from the provider, what happened and what is next, costs them little and tells you everything about how the relationship will run.
What good looks like by the end, checkably: a documented environment your business owns and could hand to anyone; a backup that has been restored, not just scheduled; monitoring quiet because things are healthy, not because nothing is watched; staff who know exactly who to ring; and a written roadmap you have discussed. What bad looks like: you are still chasing passwords, nothing has been tested, and the new provider communicates like the old one did.
The honest caveat: ninety days is the industry's rough shape, not a law, and a good changeover beats it. Ours is deliberately tighter, a PRINCE2-managed four-week onboarding with weekly updates on what has been done and what is next, because a documented method compresses the timeline that guesswork stretches. A clean environment transitions faster; a neglected one runs slower; and a provider who quotes a fixed glorious timeline before seeing your systems is guessing. What should not vary is the structure, discover, stabilise, improve, with evidence at each step, because a changeover without phases is just a new logo on the invoice.
See our changeover mapped out
Our onboarding is a PRINCE2-managed four-week programme with weekly updates, so you always know what has been done, what is next and when.
Frequently asked questions
Questions? Let's talk.
Call 1800 456 567 or fill out the form.
- 30-minute discovery — no jargon, no pressure
- Plain-English Essential Eight Cyber Security Scorecard
- A clear plan tailored to your business