Bad IT support rarely announces itself. Nobody calls a meeting to say the arrangement isn't working. Instead it shows up as small, tolerated frictions: a ticket that takes three days to close, a licence nobody remembers signing up for, a risk that only becomes visible once it's already caused a problem.

Individually, none of these feel serious enough to act on. Together, they usually mean you're paying for a service that's quietly costing you more than it's saving. Here are five signs worth paying attention to.

1. You Can't Get a Straight Answer on Response Times

Ask your IT provider what happens when something breaks, and you should get a clear answer: how quickly they respond, how they prioritise urgent issues versus minor ones, and what "resolved" actually means. If the answer is vague, or changes depending on who you ask, you don't have a service level. You have a hope.

This matters because response time is the thing you actually feel when something goes wrong. A vague promise is fine right up until a member of staff can't log in, a system goes down mid-morning, and you're left waiting with no idea whether that means ten minutes or the rest of the day.

2. The Same Issues Keep Recurring

A support desk that fixes the same problem week after week isn't managing your IT. It's responding to it. Recurring issues are almost always a symptom of something upstream: an underlying configuration problem, an ageing piece of hardware, a setting that keeps reverting. Fixing the symptom each time a user reports it is easy. Finding and closing the actual cause takes more effort, and it's the difference between IT support and IT firefighting.

If your team has a running joke about "just restart it and it'll be fine for a bit," that's usually a sign the root cause has never actually been addressed.

3. Nobody's Proactively Telling You About Risk

If the only time you hear from your IT provider is when something's already broken, they're not monitoring anything. They're waiting. Proper proactive monitoring should surface warning signs before they become outages: a server running low on disk space, a backup that's silently been failing, a device that's fallen out of date on patches. None of that is visible to you day to day, which is exactly why it's supposed to be someone else's job to watch it.

A provider who only ever contacts you reactively is, in effect, asking you to discover your own risks through downtime.

4. You're Paying for Licences Nobody's Auditing

Microsoft 365 and similar platforms are notorious for quiet licence creep. Someone leaves the business and their licence doesn't get reassigned or cancelled. A trial tier gets upgraded and never gets reviewed. A department ends up with a premium plan nobody uses the premium features of. None of this shows up as a single alarming bill. It shows up as a subscription total that's crept up over eighteen months without a clear reason why.

If nobody is actively reviewing what you're licensed for against what you're actually using, you are very likely overpaying, and it's the kind of overspend that never gets noticed unless someone goes looking for it.

5. Compliance and IT Are Handled by Two People Who Don't Talk

For healthcare providers especially, this is where real risk hides. Compliance obligations and technical setup aren't separate concerns. They're two descriptions of the same system, and gaps appear exactly at the handoff between them: a policy that says data must be encrypted, sitting next to a technical setup nobody has actually checked against it; an access control requirement that exists on paper but was never implemented in practice.

When the person responsible for your compliance position and the person responsible for your technical infrastructure aren't in regular contact, nobody is actually checking that the two line up. That gap tends to stay invisible right up until an audit, an incident, or a DSPT submission forces the question.

The Real Cost of Reactive IT

None of these five signs are dramatic on their own. That's exactly why they persist. Vague response times, recurring tickets, silent monitoring gaps, licence creep, and a disconnect between compliance and IT don't show up as a single bad month. They show up as a slow, steady cost that's easy to underestimate until you actually add it up: the hours lost to repeat problems, the licences paid for and unused, the risk sitting unmanaged until it isn't.

If any of this sounds familiar, it's worth getting an honest, no-obligation view of where you actually stand. A proper review looks at your response times, your recurring issues, your licensing, and how your compliance and IT setup line up in practice, and tells you plainly what it finds.