IT outsourcing · 8 min

How to switch IT providers safely — a step-by-step takeover plan

Fear of migration keeps companies with weak providers for years. A well-planned takeover takes 3–4 weeks and doesn't require an hour of downtime.

1 July 2026

"We know it's bad, but we're afraid to touch anything" — that's the sentence we hear most often from companies stuck for years with an IT provider that responds after two days. The fear is understandable: the provider holds the passwords, knows the environment, and nobody in-house knows exactly what is configured where. The good news: a properly planned takeover takes 3–4 weeks and doesn't require an hour of downtime.

Below is the full plan: what to prepare before you give notice, what the transfer looks like step by step, and how to neutralise the scenario where the previous provider refuses to cooperate.

Signs it's time to switch

  • Response times measured in days, no ticketing system — everything works "by calling John".
  • No documentation: nobody except the provider knows how the network works or where the backups are.
  • No reports and no proactivity — you learn about problems when something stops working, not before.
  • Invoices grow while the scope stays vague; every extra task is a separate, surprising line item.
  • The provider is falling behind technologically: no cloud or security competence, no MFA "because it makes work harder".
Everyone has a single bad week. But if three or more items on this list have described your company for months — the problem is structural and won't fix itself.

Before you give notice — preparation

  1. Read the contract: notice period, the provider's end-of-contract obligations (handover of documentation and passwords should be a contractual duty), ownership clauses.
  2. Establish what belongs to whom: who is the registered owner of the company domain, the Microsoft 365 subscription, licences, network hardware? If it's the provider — fix that BEFORE giving notice.
  3. Inventory the access: a list of systems with admin accounts (servers, firewall, cloud, DNS, backup). You don't need to know the passwords — you need to know they exist and who holds them.
  4. Secure an independent backup: at least one current copy of critical data the provider cannot touch.
  5. Choose the new partner before giving notice — the takeover should start during the notice period, in parallel.

The transfer step by step (3–4 weeks)

  1. Week 1 — initial audit: the new provider inventories the environment (often in parallel with the old one still working), records configurations, identifies single points of failure and documentation gaps.
  2. Week 2 — formal handover: a handover protocol covering documentation, password lists and licences from the incumbent. A three-way meeting if possible — civilised partings happen more often than you'd think.
  3. Weeks 2–3 — secret rotation: immediate change of ALL administrative passwords, revocation of the old provider's VPN access and accounts, MFA re-enrolment, review of service accounts and remote-access rules.
  4. Week 3 — operational takeover: monitoring and backup under the new team's control, ticketing system live, message to employees: from today, report here.
  5. Week 4 — stabilisation: a remediation plan from the audit (what's urgent, what can wait), the first report, a review cadence agreed.

What if the old provider won't cooperate

Rarer than fear suggests, but possible. The key facts: the company's data and system configuration belong to the company, not the provider — withholding passwords is grounds for legal claims. In practice, this sequence works: a formal demand (e-mail + letter) with a deadline, citing the contract and GDPR (the provider is usually a data processor), and only then legal steps.

In parallel, the technical side: an experienced team can regain control of the environment without the predecessor's cooperation — through physical access to servers, vendor account-recovery procedures (Microsoft, domain registrars) and reconfiguration of network devices. It extends the takeover by 1–2 weeks, but it is doable — we've done it many times.

The best protection for the future: top-level admin accounts (M365 tenant, domain registrar, firewall) always registered to the company, with passwords in the company's password vault — the provider gets named accounts of their own that can be revoked with one click.

The first 30 days — how you'll know you chose well

  • You receive documentation of your environment as your property — network map, system list, procedures. That's your insurance for any future switch.
  • A ticketing system with visible status works — not "I sent an e-mail and silence".
  • After the audit you get a remediation plan with priorities and pricing — not scare tactics and upselling.
  • The backup has been tested with an actual restore, not just "configured".
  • The first monthly report arrives without you chasing it.

Key takeaways

  • An IT takeover is 3–4 weeks of overlapping work with the old provider — no downtime; choose the new partner before you give notice.
  • Before giving notice: check who owns the domain, licences and subscriptions, and secure an independent copy of critical data.
  • Data and configuration belong to your company — and an experienced team can regain control of the environment even without the predecessor's cooperation.

Frequently asked questions

Considering a change of IT provider?

Let's talk — we'll review your current contract and situation free of charge and show you a takeover plan tailored to your company. An NDA before the first conversation is our standard.