Home · Blog
GRC

IT supplier management in an SME: what leaving costs

5 October 2026 · 8 min read · ODCUS
A business owner at a desk reviewing a thick service contract while cables and a bundle of keys lead out of the room to the IT provider in the building opposite

The contract renewal with your IT service provider is on the table, dearer again than last year, and nobody questions it. The service is not particularly good. It is just that everyone in the room suspects a switch would hardly be realistic. This is exactly where IT supplier management is decided: on the question of whether you could replace the provider at all. The completed questionnaire in your folder says nothing about that.

In most SMEs the topic runs as a procurement task. Compare prices, pin down the SLA, file the certificate. None of that is wrong, it just works on the wrong thing. You become dependent in operations, over years. The contract ends up doing little more than describing it.

TLDR

IT supplier management is decided on your ability to exit, not on the questionnaire. Vendor lock-in grows out of admin accounts in somebody else's name, documentation sitting in the provider's ticket system and knowledge held by people on his payroll. If you cannot switch, you cannot negotiate either. A second supplier is rarely the answer to that. Disentangling is.

What is IT supplier management, and where does procurement end?

IT supplier management is the leadership of the dependencies you take on with IT contracts: who delivers which service, which rights he holds in your systems to do it, what his failure costs you in operations and how quickly you could replace him. Procurement negotiates the price. Supplier management negotiates your ability to exit. Only the two together give you negotiating power.

The distinction sounds academic until it hurts. Procurement has done its job when the hourly rate is right and the paper is signed. Whether the company still has an alternative in two years sits in no procurement policy. In companies with 50 to 500 employees there is usually no role for that question, and accordingly no answer.

Which suppliers are critical in the first place, and what you can demand from them, is the other half of the topic and sits in Supplier risk in an SME. This piece is about the relationship after that: what happens when you want to get rid of one of them.

Vendor lock-in does not come from the contract, it comes from operations

Nobody signs a clause forbidding a switch. The company slides into it, over years, through a series of sensible individual decisions.

None of this is bad faith. Every single point is convenient, and convenience is the route by which dependency enters the building. That a provider runs your security without leading it is a topic of its own, which we took apart in Security and your IT provider.

FINMA, the Swiss financial market supervisory authority, observes the same mechanism in a regulated industry and describes it unusually plainly: financial institutions are becoming increasingly dependent on service providers for important functions, and the supervisor sees an elevated concentration among individual providers, because the same firms deliver critical functions for many institutions (FINMA on cyber risks and outsourcing). Most SMEs are not supervised. The mechanism does not know the difference.

The usual answer to dependency is called second source: two providers for everything that matters. In a company of this size that doubles the contracts and the coordination effort, and halves the attention paid to either side. What makes you independent is not a second supplier, it is the ability to take on a new one within a reasonable time. More protection, fewer contracts, lower cost.

Two routes out of supplier dependency compared: on the left two parallel service providers with duplicated contracts, on the right one provider and the keyring in your own hand
Two routes out of dependency. The right-hand one is cheaper and works in the negotiation itself.

How do you know you can no longer switch?

Three questions are enough. Who in your company can create an administrator today without the provider? How long does it take to obtain the complete system documentation if he does not cooperate? And how many weeks would a change of provider weigh on operations? If the answers are nobody, unclear and no idea, the price is no longer negotiable.

The most honest indicator is already sitting in your accounts. If the last price increase went through without discussion, the company has already given up its position, whatever the contract allows for. That is not a question of blame. It is a status report.

Let us be honest: in many companies the answer to all three questions is uncomfortable. That is the normal case and not the exception. All that counts is that somebody in the company asks them before the provider does.

What exit capability looks like day to day

Exit capability has no end date. It is a condition a company either holds or loses, and four things carry it. All four are organisational, none of them technical.

What stays in houseWhy it gives you back negotiating power
Identities and contracts The provider works with rights you delegated to him and can withdraw again. This is the only point at which a termination becomes technically enforceable. Everything else is wording.
Current documentation If the state of the environment regularly lands with you, nobody holds knowledge as collateral. The side effect is immediate: anyone who has to document works more cleanly.
Readable data formats Whether you get your data out depends on the format and not on goodwill. What only opens with his software effectively belongs to him.
The switching cost as a number A rough estimate in months and francs is enough, as long as your management team knows it and it is not from 2019.

The benefit shows up long before any switch, namely in the conversation about it. An SLA you cannot enforce is a statement of intent. It becomes enforceable the moment both sides know that a switch would be possible. That is the whole lever, and it has nothing to do with security technology.

BACS, the Swiss federal office for cyber security, is very clear at one point in its recommendations for working with IT providers: accountability cannot be outsourced or delegated. Alongside that, the recommendations name liability in the event of damage, tested restores and periodic security audits as points to settle contractually. Many SME contracts do not contain this, rarely out of negligence, mostly because the contracts date from a time when the IT estate was smaller and the provider was not yet half inside operations.

When does a second supplier pay off?

Rarely, and only where standstill costs more than running two tracks for a year. The sum is unspectacular: what two days without this service cost, how likely a failure is within a year, and what the second contract charges for it. For internet connectivity and links between sites it often adds up. For the IT service provider itself, almost never.

The reason is not only money. Two providers for the same environment mean two levels of knowledge, two escalation paths and a new favourite answer when something breaks: that was the other one. In our experience that costs companies of this size more than the outage it is meant to prevent.

What holds up is a split. For the two or three services where standstill costs revenue directly, you need a named plan B that does not hang off the same provider. For everything else, exit capability is enough. It is the same sizing question as with tools: what do you need twice, and what do you only need to have under control?

From practice: the tender that never went out

A machine builder in north west Switzerland, 270 employees, wanted to put its IT service out to tender again. The trigger was support that got noticeably worse over two years. Security was on none of the slides. The tender never went out.

Preparing it showed where the problem sat. The Microsoft tenant ran through the provider's contract, the current firewall configuration existed only in his backup, and the two people who knew the setup in detail were employed there. The estimated duration of a migration came to nine months alongside running operations. The management team decided against the switch. The right decision, from the wrong position.

Instead of switching, twelve months of disentangling followed: the tenant moved onto the company's own contract, administrator rights onto its own identities with delegation outwards, network and configuration documentation written into the contract as a deliverable. None of it was a security project, and the security posture was better afterwards anyway, because for the first time somebody in the company knew what was actually running. At the next negotiation there was also a number on the table for what a switch would cost. That changes a conversation more reliably than any escalation email.

Common questions

Do we need a dedicated tool for IT supplier management?

In our experience, rarely. With ten to twenty relevant contracts, a maintained list covering the service, access rights, notice period and estimated switching cost carries more than a platform does. A tool pays off once the list is bigger than what one person can hold in their head. Before that it mostly administers itself.

What if the provider does not cooperate with the disentangling?

Then you know more about the relationship than any questionnaire could show you. Reputable providers have no problem supplying documentation and holding administrator rights by delegation rather than by possession, because it does not threaten their business. Resistance at this point is itself the answer to the question of whether a switch should be examined.

Does this apply to the large cloud providers too?

Partly. With a hyperscaler the issue is less the outage than the move: data sits in formats and services that make a switch expensive, and an SME has little negotiating power there. So the question belongs in the decision on the platform and not in the renewal. With a regional provider it is the other way round. There a switch is possible, it is just that nobody ever prepared one.

What stays open is who takes this on inside the company. Procurement wants prices, IT wants quiet, and exit capability belongs to neither. In our mandates this point lands on the table early, because it touches money and freedom of action at the same time. Which form of security leadership fits that, and what it costs, is set out under packages and pricing.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call