Buyer guide

How to choose a managed service provider in Nigeria

Choose a managed service provider by defining what you need them to own, then testing how they deliver it: the service agreement, their own security, where your data goes and how you would leave. Price only makes sense once those are comparable.

The short answer

A managed service provider (MSP) takes ongoing responsibility for some or all of your IT: support, monitoring, maintenance, security and planning. To choose well:

  1. Define the scope you want them to own, and what stays with you.
  2. Compare service agreements, not marketing: hours, response targets, escalation and reporting.
  3. Check the provider's own security. An MSP has privileged access to your systems, so its weaknesses become yours.
  4. Ask where your data goes, including the provider's tools and subcontractors.
  5. Read the exit terms before you sign.

Only then compare price, because proposals with different scope and service levels are not comparable.

Step 1: decide what you want managed

Write down what you need before you talk to providers. Typical components:

ComponentExamples
Service deskUser support by phone, email, portal; hours of coverage
Monitoring and maintenanceServers, network, endpoints, cloud services, patching, internet links and failover
Security operationsEndpoint detection and response, email security, alert monitoring
Backup and recoveryBackup management, restore testing, disaster recovery planning, and resilience to power cuts (UPS, inverter or generator cover for critical equipment)
Identity and Microsoft 365 or Google WorkspaceAccounts, licences, access, configuration
ProjectsMigrations, office moves, new systems (usually quoted separately)
PlanningTechnology roadmap, budgeting, vendor management

Also decide the model. Fully managed suits organisations without internal IT staff. Co-managed suits organisations with an IT lead or team who want extra capacity, after-hours coverage or specialist skills. See co-managed IT.

Step 2: compare service agreements

The service agreement is where promises become obligations. Look for:

  • Coverage hours for support and for monitoring. 24/7 monitoring is different from 24/7 help desk staffing; ask which you are getting.
  • Response and resolution targets by priority, and how priority is decided.
  • Escalation paths and named contacts.
  • What is included and what is billable: after-hours work, onsite visits, projects, new-user setup.
  • Reporting: ticket volumes, targets met, patch status, backup results, security alerts.
  • Remedies if targets are consistently missed.

As a matter of good practice, a service agreement with a managed provider should define expected turnaround times, communication methods, escalation processes, performance metrics and what happens when targets are missed. If a proposal leaves these out, ask for them in writing.

Step 3: test the provider's own security

MSPs use remote management tools with administrative access to many clients at once, which makes them attractive targets. Ask:

  • Is multi-factor authentication enforced on every tool that can reach your environment?
  • Do technicians use named accounts with least-privilege access, or shared administrator logins?
  • How are your credentials stored, and who can see them?
  • How are their staff screened, and how is access removed when someone leaves?
  • How and when will they notify you of a security incident that affects your data?
  • Which security framework do they align their own operations with, and can they show evidence?

Least privilege, multi-factor authentication and prompt incident notification are standard expectations for any provider with access to your systems. A provider should also be able to help you meet baseline controls such as patching, strong authentication, backups and security awareness training, using a reference like the NIST Cybersecurity Framework as a common language. For local threat advisories and incident guidance, ngCERT is the national point of reference.

Step 4: data location, data protection and subcontractors

Your provider will see personal data: staff records, customer emails, files. Under the Nigeria Data Protection Act 2023 (NDPA) your organisation stays responsible for personal data it asks a service provider to process for it, so use a written contract that sets out what the provider may do and what safeguards it must apply. The Nigeria Data Protection Commission (NDPC) publishes the Act and its General Application and Implementation Directive (GAID) 2025. Ask:

  • Where are the provider's tools, logs, ticketing system and backups hosted?
  • Which subcontractors or offshore staff may access your systems or data?
  • Will they sign a data processing agreement and confidentiality terms?
  • Can they support the sector rules that apply to you, such as the NDPA's requirements for health data, which is sensitive personal data, or the rules of your financial or other regulator?
  • If data leaves Nigeria, how do the NDPA's transfer rules apply, and will they notify you promptly of a breach so you can meet the 72-hour notification duty to the NDPC where it applies?

Banks, payment service providers, insurers, pension operators and capital-market operators should also assess providers against the outsourcing and third-party risk requirements of their own regulator (the Central Bank of Nigeria, SEC Nigeria, NAICOM or PenCom). This is general information, not legal advice.

Step 5: onboarding and exit

Good onboarding is a project: discovery, documentation, access handover, security fixes and agreed baselines. Ask to see a sample onboarding plan and a sample of the documentation you will receive.

Plan the exit before you enter:

  • Who owns the documentation, configurations and scripts?
  • How will administrator credentials, licences and domain registrations be handed back?
  • What notice period and transition help are included, and at what cost?
  • Are any tools licensed in the provider's name that you would lose?

Pricing models

Common models are per user, per device, tiered bundles and blocks of hours. Per-user pricing is simple to budget but may not suit organisations with many shared devices. Ask for all costs as estimates in naira (or US dollars where a licence or service is priced in dollars), including onboarding, licences resold by the provider and typical project work, so you can compare total annual cost. Ask how dollar-priced items are adjusted if the exchange rate moves.

Red flags

  • Vague answers about who can access your systems.
  • No written service agreement, or targets that are not measured.
  • Reluctance to put administrator accounts and domain registrations in your name.
  • Pressure to sign long terms before discovery.
  • Security claims without evidence.

Comparison checklist

Scope

  • Components to be managed listed, with what stays in-house
  • Fully managed or co-managed model chosen

Service

  • Coverage hours for support and monitoring confirmed in writing
  • Response targets, escalation and reporting defined
  • Included and billable work clearly separated

Security

  • Multi-factor authentication on all provider tools confirmed
  • Named, least-privilege technician accounts
  • Incident notification process and timing agreed

Data and data protection

  • Hosting location of tools, logs and backups documented
  • Subcontractors and offshore access disclosed
  • Data processing and confidentiality terms signed

Exit

  • Ownership of documentation and configurations stated
  • Credential, licence and domain handover process defined
  • Transition assistance and notice period agreed

Limitations

No checklist replaces references and a trial of how a provider communicates. Ask to speak with clients of a similar size and sector, and start with a clear onboarding period. If you are reviewing options, our managed IT services page explains how we scope, onboard and report.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. Nigeria Data Protection Act 2023 and GAID 2025, Nigeria Data Protection Commission
  2. Cybersecurity advisories and incident guidance, ngCERT
  3. NIST Cybersecurity Framework, National Institute of Standards and Technology

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Get a straight answer for your situation

General advice only goes so far. Tell us about your environment and we will tell you what we would do, what it would cost and what to watch out for.

  • A named specialist who owns the outcome, not a chat window
  • Advice checked against your actual systems, contracts and risks
  • Written scope and costs in NGN before any work starts