Search "best managed IT company in Kenya", or "top MSP in Nairobi", and the first page belongs to directories. Listing sites, a couple of ranked roundups nobody at the ranked companies has heard of, a sponsored result or two. None of them has seen a single provider's monitoring console. A ranking assembled from listing fees and self-submitted profiles tells you who filled in a form, and choosing a managed IT provider on that basis is choosing at random with extra steps.
We are one of the companies that gets evaluated. CloudSpinx provides managed IT support to organizations in Kenya and the wider East African region, so we sit through these meetings from the supplier's chair, and we have watched buyers spend the hour on the slide deck and the price and never once ask to see anything. That is the mistake. Every claim a provider makes about monitoring, patching, backups and inventory has a physical artifact behind it if the claim is true, and no artifact if it is not. Ask for the artifact. The meeting gets shorter and a great deal more useful.
Monitoring you can watch, not a monitoring slide
Ask the engineer in the room to share a screen and show the alert that fired most recently on their own estate. Not a demo tenant, not a screenshot in the deck: the live console, the timestamp, who it paged and what happened next.
A provider that runs monitoring for a living can do this in under a minute, because somebody on their side is looking at that screen anyway. A provider that resells a monitoring license and installs the agent will find a reason the console is not available today. Watch for the second thing too, which is where the alert went. An alert that lands in a shared mailbox is a log, not monitoring. It has to page a person on a rota, and you want to see the rota.
The last patch report they sent anyone
Every IT support company in Kenya says it patches. Ask for the most recent monthly patch report they sent to a client, with the client's name blacked out. You are reading for three things: the cadence, whether a test ring takes a Windows cumulative update before the rest of the estate does, and whether exceptions are listed by machine with a reason.
A real report has exceptions in it. Something is always excluded, a legacy application server that breaks on a particular update, a laptop that has not touched the network in a month. A report showing full compliance and no exceptions was generated from a template rather than from an estate, and the provider has probably never had to produce one for anybody.
When the backup was last restored, and how long it took
A backup that has never been restored is a hypothesis. Ask for the date of the provider's last restore test on a client system, what was restored, how long it took from the decision to a usable system, and what did not work the first time.
The honest answer has a failure in it: a restore that ran for hours because the copy was offsite, a database that came back inconsistent and had to be replayed from logs. Restore testing is how those get found, and a provider who has found none has not tested. Where they run recovery drills as a service, ask for the drill log. The duration matters more than the outcome, because the duration is your outage.

What the inventory says about a laptop that went missing on Friday
Pose one scenario and time the answer. A sales laptop was left in a matatu on Friday evening and the user noticed on Monday. Can the provider say, from their own records rather than the user's memory, whether the disk was encrypted, which accounts were signed in and when the device was last seen, and can they revoke all of it from one console?
If the answer arrives in a minute from an asset inventory and a device-management console, they run one. If it arrives as a description of the process they would follow, they do not, and you have just watched a rehearsal of your own breach notification. The Data Protection Act gives you 72 hours to tell the Data Commissioner about a breach that carries a real risk of harm, counted from the moment you become aware, and a provider who cannot answer the laptop question cannot help you meet it. Who carries that notification under the contract is its own reading.
The registration check nobody runs on a managed IT provider
A provider holding your staff records and your customer database is a data processor under Kenyan law, and unless it has fewer than ten employees and turnover under KES 5 million it must be registered with the Office of the Data Protection Commissioner. That is regulation 13 of the registration regulations, and the exemption falls away entirely for anyone processing data for the purposes in the Third Schedule, which include financial services, health, education and telecommunications. A certificate runs for 24 months.
Ask for the certificate number and check it against the ODPC's published register of data handlers, a public table listing each entity, whether it registered as a processor or a controller, the registration number and whether the status is active or expired. Two minutes. A provider who is not on it is either small enough to be exempt, which tells you something about the on-call rota, or has not done for itself the compliance work it is proposing to do for you. Neither is disqualifying by itself. Both are worth knowing before the price is on the table.
While the register is open, look up your own organization. The same thresholds bind controllers, and the schedule's list includes hospitality and property management alongside the obvious sectors.
Which shape of provider you actually need
The five checks above tell you whether a provider is real. They do not tell you whether you need one, or in what shape, and the shape is where most bad contracts get signed. Three questions sort it.
- an honest fit
- no contract needed
- extra check
The regulation 26 gate is about the sub-processor, not you: the backup target is where a Kenyan estate most often turns out to be in Frankfurt without anybody having decided that.
The shape you land on decides what you ask them to quote. Co-managed support behind an existing IT manager normally costs less than the full outsource, and a provider who quotes the outsource anyway is quoting what they would like to sell. A per-seat rate is honest for an office of laptops on a hosted suite and stops being honest the moment there is a server, because a server costs the same to look after at twenty staff as at sixty. Whether outsourcing beats a hire at all is a separate question, and it comes after this one rather than before.
Whichever shape it is, ask us for the five artifacts too. Our monitoring console, our last patch report with the client removed, our last restore log, the inventory answer to the laptop question and our ODPC registration number are all available in the first meeting, and the monthly figure arrives with the exclusions written down before you see the price. Describe the estate and you get that figure with nothing owed, or WhatsApp +254 713 403 044 if it is quicker to talk it through.