Blog
There's a Higher Bar to Drive a Zamboni Than to Run Your Company's IT
A conversation with Josh Hohbein of centrexIT on 3rd Element Live surfaced an uncomfortable truth: almost anyone can start an MSP tomorrow and be responsible for your entire IT environment by next week. Here are the two questions that actually separate a mature provider from someone learning on your business.
The Zamboni Test
When I sat down with Josh Hohbein of centrexIT on a recent episode of 3rd Element Live, he made a comment that immediately stuck with me: "There are more requirements to drive a Zamboni than there are to start an MSP." It's funny because it's true.
Josh's son started playing hockey last year, and like most youth hockey families, they volunteered at the local rink. Josh thought driving the Zamboni looked like a great way to earn his volunteer hours. It wasn't. Before he could even get behind the wheel, he had to be added to the rink's insurance. Before that, he had to complete an ice maintenance course. Before that, he had to pass a certification. There was a legitimate barrier to entry.
Josh's comment resonated with me because of a conversation I'd had just a few weeks earlier at an industry event. Someone proudly told me they were starting a Managed Service Provider. That's great. Our industry needs good people. The problem wasn't the ambition. It was that this person had zero IT experience and planned to learn on their first client.
Someone can decide to become a Managed Service Provider tomorrow, sign their first client next week, and immediately become responsible for that company's Microsoft 365 environment, cybersecurity, backups, servers, and sensitive business data without any meaningful experience or industry-required qualifications.
That's not an indictment of every new MSP. Plenty of outstanding providers started small and built excellent businesses through experience, mentorship, and continuous learning. The problem is that there's no standard preventing someone from learning on your business.
The Two Questions Every Business Owner Should Ask Before Hiring an MSP
One of the best takeaways from my conversation with Josh was that business owners don't need to become technology experts to evaluate an IT provider. They simply need to ask better questions.
How Are You Keeping My Data Safe?
Not the marketing version. Not, "We use enterprise-grade security." Ask them to explain what they actually do:
- How do you protect identities?
- How are endpoints monitored?
- What happens when suspicious activity is detected?
- How are backups protected?
- How do you reduce ransomware risk?
A mature provider won't struggle to answer those questions because they're describing processes they follow every day. If they have to pause, think about it, or fall back on buzzwords, that tells you something too.
What Happens If Something Goes Wrong?
Every IT provider will eventually deal with an incident. The difference is whether they already have a documented plan before it happens. Ask questions like:
- Who gets notified?
- Who makes decisions?
- How quickly are clients contacted?
- How is the incident contained?
- What does recovery actually look like?
If the answer is vague or improvised, that's worth paying attention to. Hope is not an incident response strategy. Incidents are inevitable. Preparation is optional.
Why This Matters
When an accounting firm hires a bad accountant, one business has a problem. When dozens or hundreds of businesses rely on an MSP that lacks mature security practices, documentation, or operational discipline, the consequences spread much further.
Your IT provider is part of your supply chain. Their operational maturity directly affects your organization's risk. That's why evaluating an MSP should go beyond price, response times, or how friendly the technicians are. Ask about their:
- Security governance
- Incident response plan
- Security framework
- Documentation standards
- Backup testing
- Business continuity planning
The answers tell you far more than a polished sales presentation ever will.
How We Approach IT at 3rd Element
At 3rd Element, we've intentionally built our business around repeatable systems instead of tribal knowledge. Our incident response procedures are documented. Our security recommendations are aligned with recognized industry frameworks. Our operational processes are documented, reviewed, and continually improved.
Every client also has a designated security owner within their own organization because cybersecurity works best when both the provider and the client understand their responsibilities. That's not because documentation is exciting. It's because businesses deserve to know their technology is being managed by proven processes instead of memory, assumptions, or good intentions.
The Real Lesson Behind Josh's Zamboni Story
Josh wasn't arguing that every MSP should need a government-issued license to operate. His point was much simpler: business owners shouldn't assume competence simply because someone has a website, a logo, and calls themselves an IT provider.
Ask questions. Expect documentation. Verify the answers. A mature Managed Service Provider should be able to explain how they secure your business, respond to incidents, and manage risk without hesitation. If they can't, that's valuable information before you trust them with your business.
Not Sure Where Your Current MSP Stands?
If you're evaluating your current IT provider, don't start by asking what tools they use. Start by asking how they protect your business when things don't go according to plan.
If you'd like an objective second opinion, that's exactly what our IT Environment Review is designed to provide. We'll review your current IT environment, cybersecurity posture, documentation, backup strategy, incident response readiness, and operational maturity, then identify gaps and opportunities for improvement. Whether you continue working with your current provider or choose someone else, you'll walk away with a clearer understanding of the risks and where your business stands.
Common questions
Questions leadership usually asks first.
Continue reading
Related reading.
Questions to Ask Before Choosing a Managed IT Provider
The fuller list this post's two questions are drawn from.
Read more: Questions to Ask Before Choosing a Managed IT ProviderGovernance, Risk & Compliance
The documentation and framework alignment behind a mature provider's answers.
Read more: Governance, Risk & ComplianceTemplates and Checklists
Grab the Cyber Insurance Renewal Checklist and Incident Response Plan template referenced in this post.
Read more: Templates and ChecklistsNext step
Get a clearer view of your IT environment.
Find out what is working, where the risks are, and what needs attention next.
