If you run a small business, your managed service provider probably knows more about your operations than almost anyone outside your own staff. They hold the keys to your email, your files, your backups and your client records. So when news arrives that your provider has been acquired, it is reasonable to feel a flicker of unease. You did not choose the new owner. You chose the old one.
The good news is that acquisitions in the managed service provider sector are common, and most are handled with continuity in mind. The trick is knowing what to ask, and asking it early rather than waiting for something to go wrong.
A Real Example: First Focus and Resolve Technology
In 2026, Australian IT services company First Focus acquired Wellington-based Resolve Technology. Resolve had operated since 2007, building a client base among law firms, health providers and community organisations. First Focus already employed more than 100 staff across Auckland, Nelson, Dunedin and Christchurch, and described Wellington as an important next location.
Two details from that deal are worth noting. First, First Focus said continuity was the priority: existing relationships and support would remain in place while clients progressively gained access to broader services. Second, Resolve founder Simon Falconer stayed on in a vCAIO role, working with clients across New Zealand.
Ross Sardi, managing director at First Focus, said the fit was partly about Falconer staying on and about demand from clients wanting practical help with AI. Falconer said the decision came down to finding the right long-term home for clients and team.
That deal is one example, not a guarantee of how every acquisition unfolds. But it shows the kinds of commitments worth asking about in writing.
Continuity Questions to Ask First
Continuity is the thing most likely to affect your day-to-day operations. Ask these before any transition date is announced.
- Will the same technicians and account manager keep supporting us, or will our tickets move to a new team?
- Will our current pricing and contract terms carry over, or will we be asked to sign something new?
- What is the notice period if we decide the new arrangement is not working for us?
- Who is our named contact for escalations during the transition?
- Will support hours, response times or after-hours arrangements change?
Get answers in writing. A verbal reassurance over the phone is worth something, but a short email confirming the details is worth more.
Security and Capability Questions
Acquisitions often bring access to more tools and expertise, which can be a genuine improvement. They can also bring changes to how your systems are configured. Both possibilities deserve a direct question or two.
- Will our security tools, backups and monitoring stay the same, or will they be replaced?
- If systems are being migrated, what is the timeline and what happens if something breaks?
- Who at the new organisation will have access to our systems, and how is that access controlled?
- Does the combined business hold relevant certifications or insurance, and can they show you?
- How will they handle any security incident during the transition period?
Client security compliance matters here. If you work in law, accounting, health or any regulated field, you may have obligations around who can access client data and how it is protected. The Notifiable Data Breaches scheme under the Privacy Act applies to many small businesses, and a change of provider does not pause those obligations.
The Human Side: Training and Awareness
One area that often slips through the cracks during an acquisition is cyber security training for small business. Your staff may have been partway through an awareness program, or your provider may have been running phishing simulations on your behalf. Ask whether that continues, and whether the reporting you relied on will still be available.
It is also worth remembering that your IT provider, however good, cannot stop a staff member from clicking a convincing link. That is a human problem, and it needs a human solution. Regular, realistic testing is how you find out where your team is vulnerable before a real attacker does. If you want to understand the gap your provider cannot fill, this piece on automated phishing testing for non-technical managers covers it plainly.
Voice-based attacks are also on the rise. If your team handles payments or sensitive requests over the phone, it is worth adding AI voice cloning fraud to your awareness program alongside email phishing.
Regulatory and Supplier Questions
If you operate in a regulated sector, or you simply want to be careful, these questions are worth raising.
- Will the new entity be the contracted supplier, or will we be dealing with a subsidiary?
- Where will our data be stored, and does that location change?
- How do we request an audit or a copy of our data if we leave?
- What happens to our data if the combined business is itself acquired or restructured?
The research on managed service providers published in the UK gives a sense of how large and interconnected this sector has become. Consolidation is normal, and it is not automatically bad news for clients. But it does mean you should know what you are signing up for.
What Good Looks Like
A well-handled acquisition feels boring from the client side. Your invoices stay the same. Your tickets get answered by people who know your setup. Your security tools keep working. If something is going to change, you hear about it before it happens, not after.
If you are not getting that, ask harder questions. You are not being difficult. You are being a responsible business owner looking after client data and staff.
A Simple Step You Can Take Today
While you are sorting out provider questions, it is a good moment to check how your team handles a suspicious email. Phishing Training Australia runs automated phishing simulations that test your staff, track who clicks, and deliver short training to anyone who needs it. Setup takes minutes, and you do not need any IT background to use it.
You can start a free trial and send yourself a test email to see exactly what your team would receive. It is a small, low-effort way to find out where you stand, no matter what is happening with your IT provider.