Insights · Choosing a provider

How to choose an IT company in Dubai: 10 questions to ask before you sign

There are a lot of IT companies in Dubai. Some are brilliant. Some are one man, a van and a very confident LinkedIn profile. Here are the 10 questions we’d ask if we were hiring one ourselves.
The short answer

Ask every IT company the same 10 questions: who answers at 2am and what the SLA says, who has admin access, when they last tested a backup restore, whether they are independently certified, whether they understand your regulations, who covers holidays, what costs extra, how you can see their performance, what they would change first, and how you would leave. A good provider answers without flinching. A bad one suddenly needs to “check with the team”.

Key points
  • Get response and fix times in a written SLA, by priority.
  • Ask for a customer portal where you can see tickets and SLA performance.
  • Ask when a backup restore was last tested, not whether backups exist.
  • Make sure you own your accounts, passwords and documentation if you leave.

The honest version

From the outside, every IT company looks the same: a logo, a stock photo of a server room and the words “end-to-end solutions”. We should know. We’re one of them.

So here’s the honest version. These are the 10 questions we’d ask if we were hiring an IT company ourselves. A good provider will answer them without flinching. A bad one will suddenly need to “check with the team”.

1. Who actually picks up the phone at 2am?

Every proposal says “24/7 support”. Ask what that means. Is it a person, a ticket that waits until Monday, or a voicemail in a time zone you’ve never heard of? Ask for the name of the team and where they’re based.

Good answer: a named team, an emergency number that isn’t someone’s personal mobile, and a proper SLA (service level agreement).

An SLA is the bit of the contract that turns “we’ll get back to you ASAP” into an actual number. It should set out how quickly they’ll respond and how quickly they’ll fix things, by priority. For example, a critical issue (nobody can work) gets a response within 15 minutes, while a request for a new mouse can wait until after lunch. Ask what happens when they miss it. If the answer is “we never miss it”, ask to see the figures.

2. Who has admin access to our systems right now?

If they’re taking over from another provider, they should want to find this out on day one. Ex-employees, old suppliers and that one freelancer from 2019 often still hold the keys. If your new IT company doesn’t ask, they’re not going to check.

3. When did you last test restoring a backup?

Not “do you do backups”. Everyone says yes. The question is whether anyone has actually restored one and watched it work. A backup that’s never been tested is less of a backup and more of a hope.

Good answer: a date, what was restored and how long it took. More on this in our page on data backup and recovery.

4. Are you independently certified?

Anyone can write “secure” on a website. Certifications such as ISO 27001 (information security) and ISO 9001 (quality) mean an outside auditor has checked how the company actually works. It’s not a guarantee, but it does mean someone other than their marketing team has looked.

5. Do you understand the rules we have to follow?

A retailer in Al Quoz and a wealth manager in DIFC have very different obligations. If you’re in a free zone or a regulated industry, ask whether they’ve worked with firms like yours and which regulations they deal with. If the answer is “we’re very flexible”, that’s a no.

Regulated in DIFC or ADGM? See our guide to IT vendor management for DFSA and FSRA firms.

6. What happens when your best engineer goes on holiday?

Smaller providers often rely on one person who knows everything. That’s fine until they’re on a beach with no signal. Ask how knowledge is documented and who covers your account when the usual person is away.

7. What’s included, and what costs extra?

The monthly fee looks lovely until the first invoice for “out of scope works”. Ask for a plain list: what’s covered (support hours, number of users, devices, site visits), and what’s billed on top (projects, new starters, hardware, after-hours call-outs).

Our guide to managed IT services costs in Dubai goes through the usual inclusions and extras in detail.

8. How will we know you’re doing a good job?

Ask what they’ll report and how often, and whether you can see it yourself without having to ask.

The best providers give you a customer portal where you can log tickets, see who’s working on them, and check in real time whether they’re hitting their SLAs. You should be able to see open and closed tickets, response and fix times against the SLA, and recurring problems that keep coming back. It’s the difference between “trust us, it’s fine” and “here’s the dashboard”.

On top of that, expect a regular review covering security updates applied and risks they’ve spotted. If the only report you get is the invoice, you’ll only hear from them when something breaks.

9. What would you change first?

Ask them to look at your set-up before you sign and tell you the three things that worry them most. A good IT company will find something. One that says everything looks perfect either hasn’t looked or wants to keep you happy until the contract is signed.

10. If we leave, how do we get everything back?

Nobody likes talking about the break-up on the first date, but you should. Ask who owns your accounts, passwords and documentation, and how handover works. If leaving sounds difficult, staying will be too.

Red flags to watch for

  • They say you’re “too small to be a target”. Attackers love small businesses because small businesses believe this.
  • One person knows all the passwords.
  • No one has tested a backup restore in the last 90 days.
  • There’s no written SLA, or no way to see your own tickets.
  • Pricing is vague until after you sign.
  • They can’t name a client in your industry.

Where Cre8 IT fits

Cre8 IT has supported businesses in the UAE since 2012, with engineers in Dubai, Riyadh and the UK. We’re ISO 27001 and ISO 9001 certified, and every client gets a baseline level of cyber security whether they asked for it or not. Some of them grumbled. None of them have asked us to remove it.

If you’d like us to answer these 10 questions about your business, book a free 30-minute consultation. We’ll tell you what we’d change first, even if you don’t hire us.

Sources and further reading

Last reviewed 7 October 2026. This guide is general information, not legal or contractual advice.

Written by
CEO, Cre8 IT
Rob Crossley is CEO of Cre8 IT, a Dubai-born managed IT and cyber security company that has supported businesses across the UAE, Saudi Arabia and the UK since 2012. Cre8 IT is certified to ISO 27001:2022 and ISO 9001 and is a certified Microsoft Partner.
FAQ

Frequently asked questions

What is an SLA in IT support?

A service level agreement is the part of your IT contract that sets out, in numbers, how quickly the provider will respond to and fix issues at each priority level, and what happens if they miss those targets.

What response time should I expect from an IT company in Dubai?

It depends on the support level you pay for. What matters is that response and fix times are written into the SLA for each priority, with critical issues handled fastest, and that you can see how they perform against it.

Should my IT provider give me a customer portal?

Yes, ideally. A portal lets you log tickets, track progress and see SLA performance without chasing anyone, which makes it much easier to judge whether you are getting what you pay for.

How do I switch IT company?

Plan the handover. Ask your current provider for documentation, admin passwords and licence details, check you own your accounts, and give the new provider time to review your set-up before the old contract ends.

Related guides

Keep reading

Each guide links to the regulator’s own text and shows when it was last reviewed.
Managed IT

Managed IT services in Dubai: what’s included and what drives the cost

What a good managed IT contract covers, how pricing is structured, what is usually extra and how to compare providers.
4 min read · Reviewed 6 October 2026
Cyber security

What is a penetration test, what does it cost in the UAE, and do you need one?

What a pen test involves, how it differs from a vulnerability scan, typical UAE costs and when you need one.
6 min read · Reviewed 7 October 2026
Audit readiness

IT audit readiness for DIFC and ADGM firms: an evidence-first checklist

How to be ready when a regulator, auditor or client asks for proof of your IT and security controls.
3 min read · Reviewed 19 September 2026

Want us to answer these 10 questions?

Book a free 30-minute consultation. We’ll look at your set-up and tell you the three things we’d change first, even if you don’t hire us.