Infogérance & Cloud

Changing IT Provider: The Real Risk Isn’t What You Think

September 15, 2026 · By Jérémy Laurensis

Who holds the administrator passwords? What happens to Microsoft 365? Will the backups keep running? Will the outgoing provider cooperate? And your users — will they face downtime?

These questions are legitimate. But they miss the real risk.

The real risk isn’t changing provider. It’s changing without knowing exactly what you’re taking over.

A poorly prepared transition usually comes down to the same mistake: unplugging one provider on Friday evening and plugging in another on Monday morning, without having understood the environment first. A successful transition does exactly the opposite. It’s gradual, and it starts by understanding what’s already there before changing anything.

Start by mapping what already exists

The first step isn’t to replace tools. It’s to know, precisely, what’s in place: users and workstations, physical and virtual servers, network, firewalls, VPN and Wi-Fi, the Microsoft 365 and Azure environment, backups, domains, DNS and certificates, licences, line-of-business applications, administrator access, and every associated supplier and contract.

The value of an initial audit isn’t the visible inventory — anyone can find that. It’s spotting the invisible dependencies. A business application that relies on one specific server. A VPN to a supplier no one talks about any more. A service account created five years ago that nobody dares touch. These are the dependencies that bring an infrastructure down at the worst possible moment. Mapping them beforehand is how you avoid nasty surprises afterwards.

Take over access and documentation, gradually

Once the environment is mapped, you recover the access needed to administer it: Microsoft 365 and Entra ID, Azure, servers and hypervisors, firewalls and network equipment, backups, security tools, domain registrars and DNS, supplier portals, local administrator accounts, monitoring.

In parallel, you collect the existing documentation where it exists: network diagrams, procedures, inventories, contracts, specific configurations, contacts.

In an ideal world, the outgoing provider hands over a clean, documented environment. In real life, quality varies enormously — and sometimes there’s almost nothing. That’s not a blocker. A good part of the work is precisely rebuilding what’s missing and documenting as you go. Missing documentation is a problem to solve, not a wall.

Changing provider doesn’t mean replacing everything

This is the most common confusion, and it needs to be clear: taking over the management of an IT environment does not mean replacing the firewalls, servers, workstations, backups and licences all at once. Doing so on day one would be a mistake, not a sign of seriousness.

Equipment that’s still fit for purpose stays in place. A properly designed architecture has no reason to be replaced simply because the provider has changed. The priority is to regain control of what exists and check that it works. Changes come afterwards, when they’re justified — not because a new provider fancies redoing everything their own way.

That said, anything that presents a real risk is identified and prioritised immediately. An important nuance: not changing everything is no excuse for looking at nothing.

Securing while you regain control

A change of provider is also an excellent opportunity to cleanly regain control of access. Concretely, you check who actually holds administrator rights, you review and strengthen multi-factor authentication, you remove access that’s no longer needed, you change sensitive passwords and secrets, you review remote-access rules.

On the data side, you don’t just note that “the backups are running”. You check their state and you test the restore — a backup that’s never been restored is an assumption, not a guarantee. Finally, you check the protection of workstations and servers, the pending patches, and you put proper monitoring back in place.

The goal isn’t to overhaul the infrastructure. It’s to make sure the right people have the right access — and that old permissions that no longer belong are removed.

For users, the best transition is almost invisible

For your staff, a successful transition is barely noticeable. Their only real change should fit in one sentence: knowing who to contact when they need help.

So you clearly communicate the new support contact point, how to raise a request, the response arrangements and, where relevant, the new security rules to follow. The rest — the way they work — has no reason to change on day one. Bigger changes are planned afterwards, with the communication that goes with them.

What if the outgoing provider doesn’t cooperate?

This is one of the most common worries. In practice, a professional transition generally goes smoothly: a date is agreed, access and information are handed over, and responsibilities pass across gradually.

But you don’t bet on it. Before the switch, the company needs to know which services, licences and contracts are held in its own name, which access it holds directly, and which services still depend on the outgoing supplier. That’s what makes you independent of their goodwill.

The rule is simple: the more strained the relationship with the outgoing provider, the more structured and documented the handover must be. A delicate situation is never a reason to improvise — quite the opposite.

A typical case

The scenario we come across most often among SMEs in the region looks like this. A company with twenty to thirty workstations, an outgoing provider who has become hard to reach, near-non-existent documentation, and administrator access held “somewhere” without anyone knowing exactly where.

The handover isn’t about breaking everything. It’s about mapping the environment, recovering and securing access, actually testing the backups, removing obsolete permissions — then giving the company a clear picture of its IT and a budgeted roadmap. Gradually, you move from an IT environment that’s endured to one that’s under control — often without users ever feeling that anything was happening at all.

When is the transition really complete?

A handover is finished the day the new provider no longer depends on knowledge held only by the old one.

At that point, the company has a clear view of its infrastructure, its equipment, its users, its access, its licences, its backups, its suppliers, its security, its documentation — and of the actions to take in the short and medium term. Only from there can an environment truly be managed over time, rather than endured from one incident to the next.

Regain control, don’t break everything

At Mensialis, this is the starting point of our managed-services approach for SMEs in Luxembourg and Belgium: understanding the existing environment before recommending anything. The goal is never to replace everything. It’s to regain control of your IT, document what exists, fix what needs fixing and clearly define the priorities that follow.

Thinking about changing provider — or simply want to know the real state of your IT environment?

Let’s start with an initial audit. It gives you a clear picture of your infrastructure, with no commitment to what comes next.

A question about your IT?

Our articles point you in the right direction — our experts give concrete answers, tailored to your business.

Talk to an expert