Part one was how the shortlist gets written. Part two was what got built off the back of it. This part is the morning it stops working, and everything that follows from there.
Who is contractually on the hook, and for how much. What gets said in the room when the answer is nobody. What a provider worth keeping does instead. And what it takes to leave one that is not, which turns out to be the part nobody plans for until they need it that week.
What Did The Premium Actually Buy
The evidence is in part two and I am not walking you back through it. Take it as read that the expensive option did not buy competence, did not finish the basics, and did not get you a box that was any harder to break into.
So what is the money attached to?
Not the silicon, which gets cheaper every year. Not the addresses. Not the engineering hours, in a sector that cut its training spend by nearly a third in two years. The premium is attached to the channel — a vendor big enough to run tiers, rebates, deal registration and a distributor network, which means a queue of people who all get paid before anything is built, and every one of them on your invoice.
That is the seller’s half, and on its own it does not explain much. Plenty of buyers are perfectly capable and sign anyway. So here is the other half, and it is the more uncomfortable one.
The premium buys cover. Not for the company. For the person who signs.
Putting the well-known badge in is defensible in a way that choosing the open one never is. If the market-leading firewall gets breached, so did everybody else’s, and you were unlucky. If the thing you assembled yourself gets breached, you chose it, and you will be asked why. The outcome for the business is the same. The consequence for the individual is not, and every buyer above a certain grade understands that without anybody having to say it out loud.
As such, the ring closes. The seller is paid more for recommending the expensive option. The buyer is personally safer for accepting it. Neither of them is acting against their own interests at any point — and the only party carrying the cost of that arrangement is the business they both work for.
That is the answer to the question this series started with, and it is worse than lying. A liar knows what the truth is. This arrangement does not need anybody to know. It just needs the shortlist to keep coming out the same way, and it does.
The Reports You Never Get
Every recurring line on a managed service invoice ought to produce a document. Most of them produce nothing, and almost nobody asks.
Take infrastructure patching, the line that sits above the desktop one. The honest way to update a fleet is a playbook — Ansible or whatever else — kept somewhere you can see it, run on a schedule, leaving output behind. So ask to see the playbook, and ask to see the run log. On a great many contracts neither exists. The updates are manual when they happen, they happen when somebody remembers, and the line is billed every month either way. What you were sold as automation is a note in a calendar.
Then backups. This is the worst of them, because it is the line people believe in most.
You will get a backup report. Green ticks, jobs completed, bytes written, all of it arriving weekly and none of it read. That report is not the one that matters. A backup nobody has restored is not a backup. It is a hypothesis about a backup.
The document you want is a restore test. What was restored, onto what hardware, how long it took end to end, and who opened the data afterwards and confirmed it was the data. Ask for the most recent one.
Then ask the same thing again about the offline copy, because it is a separate claim and it needs separate proof. Everybody says they hold one. Ask them to show it to you — the media, where it lives, the last write date, who has the credentials — and ask when a restore was last performed from that copy rather than from the live backup system. Those are different media in different formats, and testing one proves nothing whatever about the other. The offline copy is the one that survives a bad week, and it is the one least likely ever to have been read back. Ask how often they are done, and against which systems, and whether anybody from your side has ever seen the result. On a lot of contracts it has never been done at all, because doing it costs a day of somebody’s time and nobody bills for it.
There is a prior question to all of this, and it decides whether any of the rest means anything. Do these reports come to you, or only to them?
Most of the time the tooling generates them, they land in the provider’s inbox, somebody reads them if there is time, and you get told when there is a problem. That is not accountability. It is self-assessment with an invoice attached, and it asks you to take their word for the exact thing you are paying them to do.
So ask for the reports to come to you as well. Directly from the system, on a schedule, in whatever form the tooling spits out — not a slide assembled by the person being measured, and not a green dashboard curated for the monthly meeting. Backup successes and, more importantly, failures. The patch run and what it skipped. Alert volumes and response times against target. The restore test when it happens, and the exceptions list as it stands.
You do not have to read every one. You have to be able to, and they have to know you can. That is the entire mechanism, and it is the difference between trusting somebody and being in a position to check.
And if it turns out to be difficult, ask why. Every report on that list already exists and is already being sent somewhere. Adding a second recipient is a line in a distribution list, not a project. Reluctance here is not a technical problem, and it is worth more than the answer would have been.
There is a bigger version of the same question, and it is the one that decides whether you can ever check anything for yourself. Where does the documentation live?
Ask whether they will record your estate in your systems — your IPAM, your asset database, your wiki — or in theirs. Most will say theirs, and it will be presented as efficiency. Their tooling, their templates, their process, nothing for you to run.
Look at what that arrangement does. The addressing plan, the network diagram, the asset register, the runbooks and the licence keys are all records of your business, created with your money, describing kit you own. Held somewhere you cannot see them. You cannot audit what you cannot read, so you have no way of knowing whether the documentation matches the estate — and documentation drifts from reality constantly, which is normal and forgivable, but invisible drift is how you find out during an incident instead of during a review.
Then there is what happens at the end, which the section on leaving comes back to. Documentation in your own systems is already yours, already current, already in a format you use. Documentation in theirs is an export, on their timetable, in whatever shape their tool offers, usually a PDF of something that was a database.
So ask the question plainly, and ask for read access today rather than in principle. A provider working in your systems has made a decision that costs them a little and gives you a lot, and they will tell you so. One that insists on keeping the picture in their own tooling has made the opposite decision, and it is worth asking which part of it they found attractive.
That gap is not academic. Every incident in part two lands on it. The Kaseya customers, the eighty conveyancing firms, the pension schemes behind Capita — for each of them the only question that mattered on the day was whether the restore worked. That is when a report nobody asked for becomes the only document in the building worth having.
If your provider cannot produce a restore test, you are not buying backup. You are buying copying, and you will find out which on the worst morning of the year.
Nobody Is On The Hook
Buying somewhere to put the blame deserves more than the clause it got in part one, because accountability is the thing this whole arrangement is built to route around. Not morally. Contractually.
Start with the service level agreement, and read what it actually promises. Almost always it is a response time. Four hours to acknowledge, eight to attend, that sort of thing. Responding is entirely within their control, so it can safely be promised. Fixing is not, so it is not. Look for a line committing them to an outcome — the service works, the data comes back, the site trades — and on most contracts there is not one anywhere.
Then find the liability cap. It will be there, and it is usually the fees you have paid over the preceding twelve months, sometimes less. So the worst thing that can happen to them is refunding what you already gave them. The worst thing that can happen to you is the business. Those two numbers are not in the same universe, and the gap between them is the actual risk position you are in.
Resale moves the rest of it upstream. If the hyperscaler is down it is the hyperscaler’s fault. If the firewall ships a ten it is the vendor’s fault. If a trojanised installer arrives signed and shipped as an ordinary update, that is the vendor as well. Every one of those is true, and none of them is any use to you, because you never had a relationship with any of those companies. You had one with the firm that chose them on your behalf and took a rebate for it.
And underneath all of that sits the quietest mechanism of the lot. You cannot fail to deliver a requirement that was never written down. The requirements document nobody wrote in part one is not only sloppiness — it is protection. No captured requirement, no measurable promise. No measurable promise, no breach. A design nobody signed off cannot be departed from.
Look at what happened when accountability finally did arrive somewhere. Capita was fined £14 million, and it came from the Information Commissioner under data protection law, over an alert nobody actioned for fifty-eight hours. Not from a customer, and not under a service contract. The money went to the state. The 6.6 million people whose data went out of the door, and the 325 pension schemes carrying the consequences, were not the ones who brought it and were not the ones paid.
So the arrangement, end to end. The vendor sells a product under a licence disclaiming fitness for anything in particular. The provider sells hours against a capped liability and a response-time promise. The insurer prices whatever is left. And the loss settles on the business that cannot move, which is the only party in the chain that never got to disclaim anything.
There is a simpler test in all of that, and it needs no lawyer.
If a firm believes in what it has recommended, it should be willing to stand behind it. That is what a recommendation is. You did not buy the box — anybody with a website can sell you a box. You bought somebody’s judgement that this was the right box for you, and they were paid for that judgement, and paid again by the vendor whose box it turned out to be.
So when it fails and the answer comes back that the vendor let everyone down, look at what has just happened. The part you actually purchased has been disclaimed. The judgement evaporates at the exact moment it is tested, and what is left is a firm that passed a product through and took a margin on the way past.
Nobody is asking an MSP to underwrite Microsoft. But there is a wide gap between underwriting a hyperscaler and standing behind your own advice, and every other trade lives somewhere in it. An electrician who fits a consumer unit does not get to blame the manufacturer for having chosen it. A structural engineer who specifies a beam owns the specification. They carry their judgement, because the judgement was the service.
So ask what your provider is prepared to carry. Not the vendor’s product — their own recommendation. The answer, or the length of the pause before it, tells you what they privately think of it.
And Then It Is Your Fault
The contract is the quiet half of this. The loud half turns up on the day something actually breaks, and it gets there before the fix does.
Watch which way responsibility travels. Outward, in every direction that is available, and roughly in this order. The vendor shipped a bad patch. The circuit was the carrier’s. It is a known issue and everyone is seeing it. Nobody could have foreseen it, said about a flaw that had been on the exploited list long enough to have grown a beard. The previous provider left it like that, which is a fair answer for six months and is still being given in year three. Then the outward directions run out, and there is one left. You never approved the upgrade. That was out of scope, your staff clicked the link, and you never raised a ticket.
Here is the uncomfortable bit. Some of those are true. A customer who has turned down the same replacement three years running does own that decision, and a provider who says so is being straight with you. So the question is not whether the excuse is accurate. It is when it was first said. A risk put to you in writing before the outage, with what it would cost to fix and what it would cost not to, is a provider managing your estate. The same sentence sent the week after is a defence being assembled. Same words, different date, opposite meaning.
“You never raised a ticket” is the one worth stopping on, because it is not an excuse at all. It is the operating model said out loud. Nothing is anybody’s job until you notice it, which makes you the monitoring, and you are paying a monthly fee to a firm whose detection layer is a customer ringing up. Once you have heard that answer once, you know what the service is.
There is a more active version of this, and it works far better than it should. You call a review to ask why the last six months have gone the way they have, and the agenda that comes back is about something else entirely: an urgent security matter, a licensing deadline nobody had mentioned, an end-of-life notice on a box that has been end-of-life for two years and has suddenly become pressing this fortnight. It is presented with real concern and a quote attached, and it eats the hour. You leave having agreed to spend money, and the thing you called the meeting for never got said out loud at all.
Notice what the manufactured crisis always has in common. It needs a purchase, it needs it this quarter, and it requires nobody in the room to admit anything. Real urgency looks different, because it comes with an identifier, a date it was published, the specific machines in your estate that have it, and what they have already done about it while waiting to tell you. The invented sort arrives as a vendor deadline and a rounded figure. Ask when it first appeared on their radar. If the answer is the same week you started asking awkward questions, that is not a coincidence and it was never meant to be one.
So keep your own file, and start it before you need it. Every time you are told a thing is fine, ask for that in an email. Every time you decline something, write down what you were shown and what it was quoted at. It takes a minute and it means that on the day it becomes your fault, you can ask for the date, and the answer either exists or it does not. A firm doing this job properly gets there first anyway. They open with we missed this, here is what we are changing, and they say it before you have finished asking. It costs them one sentence, which is precisely why so few of them will spend it.
And when you get the invented crisis, or the blame lands on you for something nobody ever put to you, say it in the room. Not as a complaint afterwards and not as a note for the file. Ask them whether they consider that professional, whether it is the answer they would accept if it were given to them, and where the integrity is in it. Somebody will be uncomfortable, and that is the entire purpose of asking. A firm with any self-respect left takes it, says fair enough, and comes back different next month. You will know inside a minute which sort is sat across from you.
Then start looking anyway. That week. One bad meeting does not decide it, but the deflection was never a bad day. It was a decision about you: that managing how you feel is cheaper than fixing what you bought, and that you will put up with it. Firms do not un-make that calculation because a customer pulled a face. Replacing a provider properly takes months you have not begun to spend, and the time to be doing it is while you are still calm enough to choose well, rather than in the fortnight after the outage that finally makes your mind up for you.
Ask These In The Next Meeting
None of this costs you owt, and you do not need to be an engineer to ask any of it.
I have put the questions in a spreadsheet rather than down the page — 120 of them across fifteen areas, each with what a competent answer sounds like set against what a deflection sounds like, and a column to record which one you got.
Supplier questions, the long versionTreat it as a prompt sheet, not a script. Read down it, mark the dozen that actually bear on your contract, and ask those. Nobody sits through a hundred questions in an hour and you would learn less if they tried. Send it across before the meeting rather than producing it in one — a provider doing the job properly will be glad of the notice, and how they take the notice is itself an answer.
One question in there asks which of their recommendations earn them a rebate, a credit, a margin or a target from the vendor. That is the one that changes the temperature in a room, and it should not. A provider with nothing to hide answers it straight, because they were going to recommend the same thing anyway and would rather you knew. Watch what happens when you ask. The answer matters less than the reaction.
A provider doing the job properly has all of this to hand. Already, today, without preparing. The requirements written down, the options costed, the open source line on the comparison, the address plan dual-stacked, the remote management tool patched and the risks in the register where they belong. Ask, and you find out inside one meeting which sort you are paying for.
And if it is the asking itself that upsets them, you have found out everything you needed to.
Every Account Goes Quiet
All of this assumes you can leave if you need to. That is worth testing before you need to, because leaving is where a managed service contract stops being about technology.
Assume you will need it eventually. Every one of these arrangements drifts the same way, whoever you sign with. The attention you got while they were winning the work thins out once the direct debit is running, and you settle into their books as a monthly figure rather than an estate somebody is thinking about. Nobody sits down and decides to stop caring. The best engineer goes where the noise is, the reviews quietly stop happening, and your kit sits on whatever was the right answer the year you signed while the rest of the trade moves on without you.
Understand what a quiet account actually is, because the phrase sounds like a compliment and is not one. A quiet account is one nobody has checked. The backups run green every night and nobody has restored one to a spare machine and watched it come up. The failover pair has never been failed over, because doing it means booking an outage and somebody would have to be there. The firmware is whatever shipped, the certificate has been renewed by whoever remembered, and the documentation describes a network that was decommissioned two moves ago. The licence count has not been looked at since the year you had eleven more staff. None of that generates a ticket, so none of it reaches anybody’s screen, and the account sails through every internal review because the only thing being measured is whether you rang.
Then you find out. Not at a review, because there was not one. You find out on the morning the restore is needed, or when the auditor asks for the diagram, or when a thing that has run untouched for six years stops and nobody left in the building knows what it was doing. A quiet account pays the same as a busy one and costs far less to serve. That is the whole of the incentive, and it points away from anybody ever opening the lid.
The Advice That Costs Them Money
Set the test the other way up, and ask what you are actually meant to be buying. It is not the absence of trouble. Anybody can be absent. What you are paying for is somebody who knows the business well enough to arrive with things you did not ask for: a way of doing the month end that stops falling over, a licence you are paying for and nobody has opened since the year before last, a cheaper way to hold the data, a plan for the box everyone has quietly agreed not to reboot. Some of that costs them revenue to tell you, which is exactly why it is the honest signal. Ask yourself when your provider last put a recommendation in front of you that made their own invoice smaller.
The commonest form that takes is not a discount. It is somebody going through what you already run. Most outfits are not short of software, they are short of anybody who has ever sat down properly with the software they have got: the licence tier that already includes the feature being quoted for, the module paid for in the original project and never rolled out, the workflow in the finance system that would end the re-keying if somebody gave it two days, the second subscription bought because nobody asked the first supplier whether their product did that as well, the reporting nobody ever built so the whole company exports to a spreadsheet and does the work there instead. A genuine provider starts in that pile. What you own, what it can be made to do, what it will never do, and how much of the problem goes away if the thing you are already paying for is configured the way it was meant to be, all of that before anybody opens a price list.
Which tells you how they intend to earn from you, because that work is the awkward sort. It means reading somebody else’s documentation, learning a system they do not resell and get nothing for knowing, and sitting with the people who use it all day to find out what actually happens at four o’clock on a Friday. No rebate arrives on the back of any of it. It is also the whole of what you thought you were buying. And sometimes the answer at the end really is a new system, in which case buy the new system. Spending is not the problem. The order is: what you run, what it will still do, where it genuinely falls short, and only then what to go out and get. A recommendation that skips the first three was never an assessment. It was a catalogue with your name typed at the top of it.
And a provider who has never sat down and learned what the business does cannot do any of it. There is a difference between knowing you have ninety mailboxes and knowing which hour of which day it would genuinely hurt to lose the system that takes the orders. One is inventory, the other is understanding, and only the second produces advice worth the money. A firm that has proposed nothing in three years, that cannot say what you sell or when your busy season falls, that keeps the lights on and raises the invoice on the same day every month, is not a partner and has stopped pretending to be. It is a subscription with a phone number on it. Not one to keep.
The opposite failure turns up in a better suit. That is the provider who is never quiet at all, who has something for you every quarter, and whose answer to every question you have ever asked came back with a part number attached to it. It looks like attention. What separates advice from selling is not the volume of it, and it is not how good the slides are either — it is whether the recommendation is capable of coming back as leave it alone, you do not need anything this year, and that money is better spent on the thing in the corner nobody has budgeted for. If not one recommendation in the whole relationship has ever cost them a sale, you are not being advised. You are being worked through a list, and part one is about where those lists come from. A partner talks you out of spending sometimes. To everybody else you are an account that buys what it is shown, which is a cash cow with a service desk attached, and nobody involved has to be dishonest about it for that to be exactly what is happening.
Getting Rid Of A Bad One
Work through what actually has to happen. All of it. Administrative credentials handed over for every system. Documentation that describes how the estate is built, assuming it exists. Control of the domain names, and of whatever account the DNS lives in. Certificate private keys. Subscriptions moved out of the provider’s partner agreement and into a tenancy that is yours. Their agent removed from every machine, by them. And the incumbent cooperating with their replacement, in detail, for weeks, while being paid nothing to do it and having just been told they are finished.
Now the part that ought to worry you most. The worse a provider is, the harder that exit gets, because the failings are the same failings. A firm that never wrote your requirements down did not write the handover pack either. A firm that kept the credentials in a shared vault has no clean way to give them to somebody else. A firm with no playbook and no restore test has nothing to hand over but access and good luck. The mess is the moat. Nobody sat down and designed it that way, and it works better than if they had.
So assume the documentation line does not hold. Documentation is the first thing to go unwritten and the last thing anybody checks, and what arrives on the way out will describe an estate that moved on without it. That is the good case. The bad one is a pack that looks complete and is wrong: a diagram with a switch on it that went to the tip two years ago, a runbook for a server that has been rebuilt since, a credentials sheet full of accounts nobody can log in as. Wrong documentation is worse than none, because you act on it. None at least sends you to go and look.
Price the exit as though nothing survives it. Somebody walks the racks, reads the configuration off the live kit, exports the firewall rules and the DHCP scopes and the zone files, and writes down what is actually running. That is weeks of work, and in an exit it is weeks you are spending under notice, while the only people who know the answers have already been told they are finished. Do it now instead. Ask for the pack today, then take one page of it and check it against a live machine. If it holds, you have learned something worth knowing. If it is not worth the bits used to store it, you have learned that as well, and you have learned it with a year to put it right rather than a fortnight.
That cooperation line is the one that will actually hurt, and it is the one nobody prices. Read it back as a request: a firm that has just lost the account is being asked to spend weeks explaining it to the people who took it off them. Nobody has to refuse. The account moves to the leavers’ pile, the engineer who knew your estate goes on a job that still pays, and your questions land with whoever is left. Replies come back in days instead of hours. The handover call gets booked three weeks out. Half of what you ask for turns out to be chargeable, and the one person who built the thing left in March. None of it is sabotage. All of it costs you exactly what sabotage would.
Your replacement carries it, and then you carry it again. Their first month goes on working out what they have inherited. That is discovery they have nothing to show you for, so they either price it honestly and look dear against the incumbent’s renewal, or they swallow it and start the job already behind. You pay either way. So buy the cooperation before you need it. Put it in the contract on the way in rather than on the way out: a defined handover period, a named person doing it, a day rate agreed while they still want your signature, and access that stays live until the incoming firm says it can go. Pay for an overlap and count it cheap. And never arrive at the switchover with the outgoing provider holding the only key to something you own.
The paperwork does its share too. Notice periods measured in months rather than weeks, auto-renewal dates that pass while you are still deciding, and a handover priced as professional services at a day rate somebody sets after you have already given notice. None of that is unusual, and none of it breaks any rule.
So test the exit while the relationship is fine and nobody is upset. Ask for the handover pack now, in writing, as a deliverable rather than a promise. Ask who the registrant of your domains actually is. Ask whether your licences sit in your own tenancy or under their partner agreement, and what moving them involves. A provider doing the job properly will answer all three off the top of their head, because a firm confident in its work has no reason to make leaving difficult.
And if the answers are vague, remember what the next section says about who you complain to.
There Is No Regulator For The Selling
Something should have been nagging by now. Every failure in this series that came with a formal finding attached is a security failure. The ICO on Advanced. The ICO on Capita. CISA on the tooling. On the selling — the shortlist, the rebate, the single option, the renewal — there is nothing. Not one enforcement action against a British MSP.
That is not because the selling is clean. It is because nobody has the job of looking at it.
Consumer law stops at your front door. The Consumer Rights Act 2015 protects consumers, and a limited company buying a managed service is not one. The Digital Markets, Competition and Consumers Act 2024 handed the CMA direct enforcement powers in April 2025, pointed squarely at aggressive sales practices, misleading information and contract terms that are plainly unbalanced. They are consumer powers. The CMA’s own account of the first year is worth reading for the wording as much as the numbers: fourteen investigations, two settlements, £760,000 “refunded to consumers”, £4.7 million in fines, 157 advisory and warning letters. Consumers, every time. Not the thirty-person manufacturer who signed five years of managed service last spring.
Telecoms is the one corner a British regulator has been anywhere near. It shows what enforcement looks like when somebody holds the brief. In July 2015 Ofcom fined a small business telecoms provider £200,000 for mis-selling landline services to a base of “around 100,000 small businesses”, and made it compensate the customers affected and rewrite its sales materials. Right behaviour, right size of customer, wrong industry, and eleven years ago.
There is no equivalent for IT services. Add it up from where you are sitting. No cooling-off period. No ombudsman to escalate to. No regulator with jurisdiction. No duty on anybody to tell you what the vendor pays them. No published findings to learn from, because there is nowhere for a finding to come from. The contract was drafted by the supplier, and the only remedy in it is to sue — which means costs, years, and a legal budget a small business has not got, as the supplier is well aware.
Financial advice had this exact problem and dealt with it. The fix was not complicated — say who pays the adviser, and stop the product provider being the answer.
There will not be an RDR for IT. Nobody is coming to make your MSP declare what the vendor pays them, and the Cyber Security and Resilience Bill currently going through Parliament, which would pull managed service providers inside the NIS Regulations, is about detection and reporting rather than about who is paying for the advice.
So when somebody tells you there is no evidence of a problem in how technology gets sold in this country, they are right. It means nothing at all. There is no evidence because there is no inspector, no complaint route that ends in a public document, and no register of what happened to anybody else who signed the same contract. In a market nobody supervises, absence of evidence is just absence of anybody looking.
What It Says About The Trade
Strip the invoices away and look at who is actually stood in this arrangement.
At one end, businesses that make and do things. A firm machining parts. A garage. A kitchen feeding people. Solicitors moving somebody into a house on a Friday. Every one of them produces something you can point at, and every one of them is carrying the risk in this post, because they are the only party in the chain who cannot disclaim anything.
At the other end, several layers that produce nothing at all. A vendor whose licence disclaims fitness for any particular purpose. A distributor moving a box between warehouses and taking a cut. A partner programme paying somebody to prefer one badge to another. A provider selling hours against a capped liability. Each takes its margin and passes the consequence down, and the consequence keeps travelling until it reaches the only person who has to open the doors on Monday.
A trade is a body of people who know how to do something, who are paid for knowing it, and who stand behind what they say because their name is on it. Held against that, most of this industry is a distribution channel with certifications.
Look at what has been given away to get there. Skill first, because you cannot cut a third out of what you spend on training and still sell expertise with a straight face. Then judgement, sold at the front of the engagement and disclaimed the moment it is tested. And last the plain willingness to say “that is not the right answer for you” when the right answer pays less — which is the only thing separating advice from selling, and costs nothing but nerve.
The way out of it is unglamorous and entirely available. Own the kit you can own. Hold your own keys. Keep the documentation somewhere you can reach without ringing anybody. Learn enough about your own systems to know when you are being told something daft — not to run them yourself, just to recognise an adjective arriving where a number was asked for. That is not nostalgia for everyone having a server in a cupboard. It is the only leverage on offer, and it is cheap.
There are people in this trade who never stopped doing the job properly, and they are not hard to spot once you know what to look for. They quote the boring option. They tell you what a thing costs rather than what it is priced at. They put the risk in writing before you ask, and they are relieved when somebody finally checks.
The rest have arranged matters so that nobody ever does. You are allowed to ask what it costs, who is paying whom, and what happens when it breaks. Nobody in this arrangement is going to volunteer it, and that is not the same thing as you not being owed it.
Sources
Retrieved 28 August 2026.
Law and policy.
- Cyber Security and Resilience (Network and Information Systems) Bill 2024-26 — House of Commons Library briefing on bringing managed service providers into the NIS Regulations.
Who is allowed to complain.
- Consumer Rights Act 2015 and the Digital Markets, Competition and Consumers Act 2024 — the protections, and who they are for.
- CMA, direct consumer enforcement one year on — April 2025 to April 2026: 14 investigations, GBP 760,000 refunded to consumers, GBP 4.7 million in fines.
- Ofcom fines Unicom, 31 July 2015 — GBP 200,000 for mis-selling to small businesses, the nearest thing to an enforcement precedent, in telecoms rather than IT.