Free IT consultant interview questions for small business owners: 6 sets on discovery, security, scope, and pricing, plus a scorecard. Download as DOCX.
Six question sets for hiring an IT consultant: discovery, technical depth, cybersecurity, communication, scope and pricing, plus a scorecard with red flags and reference-call questions. Built for small businesses without an IT or HR department. Download as DOCX.
The first IT consultant I ever hired arrived with a proposal before he had asked a single question about the business. It was a good proposal for somebody. Six weeks later we owned equipment we did not need and still had the problem we called about. The lesson stuck: the interview for this role is not a test of technology, it is a test of whether the person diagnoses before they prescribe.
That is harder to run than it sounds, because you are hiring expertise you do not have, which is the whole reason you are hiring. Confidence gets mistaken for competence, and the most fluent explanation wins. Writing the questions down in advance, and knowing what a strong answer contains, is what levels the field. If you are still defining the role, the IT consultant job description covers the scope side.
At FirstHR, we build for owners and office managers who make this call themselves, without an IT department and usually without an HR one either. These six question sets cover discovery, technical depth, cybersecurity, communication, and commercial terms, and the sixth is a scorecard with a red-flag checklist and reference-call questions.
TL;DR
Interview an IT consultant on five things: business discovery, technical method, security, communication, and commercial terms. The single most useful signal is whether they diagnose before they prescribe, so open with discovery questions and be skeptical of any recommendation that arrives before a question about your business. Score each area from 1 to 5 and call two references. Download six question sets and a scorecard as DOCX.
What an IT Consultant Does for a Small Business
An IT consultant is hired to diagnose and advise: to assess the systems you already run, recommend changes, plan a migration or a security uplift, and usually deliver a defined project with a start and an end. That is different from day-to-day support, which answers tickets and fixes what broke this morning.
The distinction matters in the interview because the two roles reward different answers. A consultant is judged on judgment: how they prioritize, how they weigh cost against risk, how they explain a trade-off. Support is judged on responsiveness and throughput. Many small businesses need both, and many providers sell both under one retainer, which is exactly why the scope questions in this kit exist.
Titles blur here more than in most fields. Roles sold as consulting overlap with an IT manager on the strategy side and with an IT support role on the hands-on side. Decide which half of the work you actually need before you write the questions, because interviewing for the wrong one is the most expensive mistake available here.
What to Assess in an IT Consultant
Assess five things: business discovery, technical method, security and access hygiene, communication, and commercial clarity. Technical depth is only one of the five, and it is rarely where these engagements fail. They fail on scope nobody wrote down, on advice nobody could act on, and on a consultant who could not be reached the week it mattered.
The most reliable way to test all five is a structured interview, where every candidate answers the same core questions scored against the same rubric. That matters more here than in most hiring, because you are comparing people whose sales polish varies far more than their quality, and a consistent question set is what keeps polish from deciding it.
Consulting signals
Asks about the business before proposing
Ranks work by impact and risk
Right-sizes advice to a small budget
Technical signals
A repeatable diagnostic method
Tests restores instead of assuming
Names the edge of their expertise
Working-relationship signals
A defined update cadence and response time
Explains trade-offs in plain language
Documents so a successor could take over
Red flags
Leads with a product before a diagnosis
Hides vendor commissions or margins
Registers your accounts in their own name
Which Question Set Should You Use?
Use all six for a significant engagement, and pick three or four for a small project. The discovery set and the scorecard belong in every interview regardless of size, because they are the two that catch the failures you cannot see coming.
Discovery and Business Needs
Diagnose, not sell
Whether they start with your business, budget, and risk or with the technology they already like selling. Ask this set before any technical question.
Technical Depth
Method over jargon
How they reason through an unfamiliar outage, choose cloud or on-premise, run a migration, and prove a backup actually restores.
Cybersecurity and Data
Service and risk
The security basics they would fix first, plus how they handle their own administrator access to your systems and what happens to it at the end.
Communication and Fit
Where engagements fail
Update cadence, response times, plain-language explanations, and documentation, so you are not locked in to what one person happens to remember.
Scope and Pricing
Terms are part of it
Pricing model, what is out of scope, change requests, disclosed vendor margins, account ownership, and how either side exits cleanly.
Scorecard and Red Flags
Score, do not guess
A 1-to-5 rubric, a red-flag checklist, and five reference-call questions, so the decision rests on evidence rather than on who sounded most confident.
Weight the Sets to the Engagement
A one-time project, such as a migration or a security uplift: lean on discovery, technical depth, and scope and pricing. An ongoing monthly retainer: weight communication, response times, security, and the exit terms far more heavily, because those are what you live with every month. Comparing a solo contractor against a firm: ask both the same core questions, then add two more for the firm: who your day-to-day engineer is, and what happens when that person is away.
6 Free Question Sets to Download
Download all six as a single Word document or copy individual sets. Each follows the same structure: when to use it, the questions with notes on what a strong answer contains, what to listen for, and space for notes. More hiring kits sit in the hiring templates library.
Download All 6 IT Consultant Question Sets
Discovery, technical depth, cybersecurity, communication, scope and pricing, and a scorecard with red flags. All in one DOCX.
Set 1: Discovery and Business Needs
Whether they start with your business, budget, and risk or with the technology they already like selling. Ask this set before any technical question, because the order changes the answers you get.
Discovery and Business-Needs Questions
IT CONSULTANT INTERVIEW: DISCOVERY AND BUSINESS NEEDS
Candidate / Firm: __
Business: __
Interviewer: __
Date: _
WHY THIS SET COMES FIRST
An IT consultant is hired to diagnose, not just to fix. The first thing you are
testing is whether they start with your business and your budget, or with the
technology they already like selling. Ask these before any technical questions.
QUESTIONS TO ASK
1. Walk me through how you would assess a business like ours in the first week.
(Good answer: interviews people, inventories the systems and licenses, looks
at what actually breaks, asks about budget and growth plans before proposing.)
2. What do you need from us before you can recommend anything?
3. How do you decide what to fix first when everything looks broken?
(Good answer: ranks by business impact and risk, not by what is easiest or
most interesting to work on.)
4. Tell me about a project where the client asked for one thing and you
recommended something different. What happened?
5. How do you avoid recommending more technology than a business our size needs?
6. What questions do you have about how our business makes money?
(Good answer: they ask several. A consultant who has no business questions is
selling parts, not advice.)
7. Describe an engagement that did not go well. What would you do differently?
WHAT TO LISTEN FOR
•Starts with business goals, constraints, and budget, not with a product
•Ranks work by business impact and risk
•Asks you real questions during the interview itself
•Honest about a project that went badly
NOTES
__
__
Set 2: Technical Depth and Troubleshooting
How they reason through an unfamiliar outage, choose between cloud and on-premise, run a migration, and prove a backup actually restores. You are grading method, not vocabulary.
Technical Depth and Troubleshooting Questions
IT CONSULTANT INTERVIEW: TECHNICAL DEPTH AND TROUBLESHOOTING
Candidate / Firm: __
Business: __
Interviewer: __
HOW TO USE THIS SET
You do not have to grade the technology. You are listening for a method: how the
candidate reasons through an unfamiliar problem and whether they can explain it
to you. Each question has a note on what a strong answer contains.
QUESTIONS TO ASK
1. Our email and shared files stopped working this morning. Walk me through your
first hour.
(Good answer: confirms scope and impact, checks whether it is one user or
everyone, isolates the layer, communicates status before it is solved.)
2. How do you decide between cloud, on-premise, and a mix for a business our size?
(Good answer: weighs cost, staff, compliance, and internet reliability rather
than declaring one option always correct.)
3. What is your experience migrating a small business to a new system? Walk me
through one migration end to end.
4. How do you handle backups, and how do you know a backup actually works?
(Good answer: mentions testing restores, not just that backups are scheduled.)
5. Explain a technical problem you solved to me as if I were the office manager.
(Good answer: plain language, no jargon, checks that you followed.)
6. What do you do when a problem is outside your expertise?
(Good answer: names the boundary and the specialist they bring in. Nobody
covers networks, security, telephony, and line-of-business software equally.)
7. Which parts of our stack would you want a second opinion on?
WHAT TO LISTEN FOR
•A repeatable diagnostic method, not a list of certifications
•Tests restores rather than assuming backups work
•Explains clearly to a non-technical listener
•Knows and names the edge of their own expertise
NOTES
__
Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
The security basics they would fix first, how they would respond to an incident, and how they handle their own administrator access to your systems, including what happens to it at the end.
Cybersecurity and Data Protection Questions
IT CONSULTANT INTERVIEW: CYBERSECURITY AND DATA PROTECTION
Candidate / Firm: __
Business: __
Interviewer: __
WHY THIS SET MATTERS FOR A SMALL BUSINESS
An IT consultant will hold administrator access to your email, files, and
possibly your financial systems. Security is therefore both a service they
provide and a risk they introduce. Ask both halves.
QUESTIONS TO ASK
1. What are the first three security changes you would make at a business our
size, and why those three?
(Good answer: usually multi-factor authentication, tested backups, and patch
or update discipline. Cheap, high impact, boring. Be skeptical of an answer
that leads with an expensive product.)
2. How do you handle your own access to our systems?
(Good answer: named individual accounts, not a shared login, multi-factor on
admin accounts, access removed when the engagement ends.)
3. What happens to our data and credentials when we stop working together?
4. Walk me through how you would respond if we were hit by ransomware tomorrow.
(Good answer: isolate, assess, restore from tested backups, notify, then fix
the root cause. A consultant who only talks about paying or about prevention
has not thought it through.)
5. How do you keep our passwords and documentation? Who else can see it?
6. What is your own cyber liability insurance, and what does it cover?
7. How would you train our team on the basics, and how often?
WHAT TO LISTEN FOR
•Leads with cheap, high-impact basics before products
•Individual named accounts and multi-factor on their own access
•A real, ordered incident response, not just prevention talk
•A clean offboarding plan for credentials and data
NOTES
__
Set 4: Communication and Client Fit
Update cadence, response times, plain-language explanations, and documentation good enough that a successor could pick it up. This is where most small-business IT engagements actually fail.
Communication and Client Fit Questions
IT CONSULTANT INTERVIEW: COMMUNICATION AND CLIENT FIT
Candidate / Firm: __
Business: __
Interviewer: __
WHEN TO USE THIS SET
Technical skill is easy to overweight. Most failed IT engagements at a small
business fail on communication: nobody knew what was happening, the consultant
was unreachable, or the advice arrived in language nobody could act on.
QUESTIONS TO ASK
1. How do you keep a client updated during a project that runs several weeks?
(Good answer: a named cadence and format, for example a short weekly written
update, plus a rule for when they call instead of write.)
2. What is your response time for something urgent, and how is urgent defined?
3. Tell me about a time a client disagreed with your recommendation. How did you
handle it?
(Good answer: presented the trade-off and the cost of each path, then
respected the decision. Not a story about being proved right.)
4. How do you work alongside a non-technical owner who has to approve spending?
5. Who is our day-to-day contact, and what happens when that person is away?
(Ask this of any firm. A single point of failure is a real risk.)
6. How do you document what you have built so someone else could pick it up?
7. What would make you tell us that we are not a good fit for your firm?
WHAT TO LISTEN FOR
•A specific update cadence and a defined response time
•Explains trade-offs and cost, then respects your decision
•Real documentation, so you are not locked in to one person
•Willing to say when an engagement is a poor fit
NOTES
__
Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
Pricing model, what sits out of scope, how change requests are approved, whether they take vendor margins, who owns the accounts and licenses, and how either side exits cleanly.
Scope, Pricing, and Engagement Terms Questions
IT CONSULTANT INTERVIEW: SCOPE, PRICING, AND ENGAGEMENT TERMS
Candidate / Firm: __
Business: __
Interviewer: __
WHEN TO USE THIS SET
Most IT consultants are engaged as independent contractors or through a firm,
not hired as employees, so the commercial terms are part of the interview. Ask
these before you get attached to a candidate.
QUESTIONS TO ASK
1. How do you price: hourly, project fee, or a monthly retainer? What is included
in each and what is billed separately?
2. What is explicitly out of scope, and how do change requests get approved?
(Good answer: a written change process with a price attached, so surprises
arrive as a quote rather than as an invoice.)
3. If we buy hardware, software, or cloud services through you, do you receive a
commission or a partner margin?
(Good answer: discloses it without hesitation. Undisclosed vendor incentives
are the most common conflict of interest in this field.)
4. Who owns the documentation, scripts, licenses, and accounts you create for us?
(Good answer: you do, and every account is registered in your business name.)
5. How much notice does either side give to end the engagement, and what is the
handover?
6. How many other clients do you serve, and how do we get priority when something
is on fire?
7. Will you sign a confidentiality agreement covering our data and our clients?
WHAT TO LISTEN FOR
•Clear pricing with a written scope and a change process
•Discloses vendor commissions and partner margins up front
•Accounts and licenses registered in your business name
•A defined exit and handover, agreed before you start
NOTES
__
Set 6: Scorecard and Red Flags
A 1-to-5 rubric across all five areas, a red-flag checklist, and five reference-call questions. Use it with any of the sets above, and score right after each conversation while it is fresh.
IT Consultant Scorecard and Red Flags
IT CONSULTANT SCORECARD AND RED-FLAG CHECKLIST
Candidate / Firm: __
Business: __
Interviewer: __
Date: _
HOW TO SCORE
Score each area from 1 to 5 immediately after the interview, while it is fresh,
and anchor every score to something the candidate actually said. If more than one
person interviews, each scores independently first, then compare. Use the same
areas for every candidate so you compare evidence rather than impressions.
Rating scale:
5 = Strong, specific evidence 4 = Solid evidence 3 = Some evidence
2 = Weak or mixed evidence 1 = No evidence or red flags
SCORING AREAS
Business discovery: starts with your goals, budget, and risk, not a product
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Technical method: reasons through unfamiliar problems, tests instead of assuming
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Security and access hygiene: basics first, clean handling of their own access
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Communication: plain language, defined cadence, defined response time
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Commercial clarity: written scope, disclosed margins, you own the accounts
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
Fit for our size: right-sized advice for a small business, no gold plating
Score [ 1 ] [ 2 ] [ 3 ] [ 4 ] [ 5 ]
Evidence: ______
RED FLAGS (WEIGH CAREFULLY)
[ ] Recommends a purchase before asking what the business needs
[ ] Will not disclose vendor commissions or partner margins
[ ] Wants accounts and licenses registered in their own name
[ ] Cannot explain a technical decision in plain language
[ ] Vague on response times, scope, or what is billed extra
[ ] No plan for handover if the engagement ends
[ ] Talks only about prevention and has no incident response
[ ] Refuses a confidentiality agreement or reference calls
REFERENCE CALL QUESTIONS (DO NOT SKIP)
1. Did the work land on the budget and timeline you agreed?
2. Were you ever surprised by an invoice?
3. How quickly did they respond when something urgent broke?
4. If they left tomorrow, could someone else pick up their documentation?
You do not need to grade the technology; you need to hear the difference between a method and a sales pitch. Strong answers are ordered, specific, and tested. Weak answers are confident, general, and arrive before any diagnosis. Those patterns are audible to anyone.
Walk me through how you would assess a business like ours in the first week.
Strong answer: Interviews the people who use the systems, inventories hardware, licenses, and accounts, looks at what actually breaks and how often, and asks about budget and growth before recommending anything. A strong answer treats the first week as diagnosis and produces a written, prioritized list you can act on.
Weak answer: A weak answer jumps straight to a recommendation, usually a platform or a device the candidate already sells, before asking a single question about how your business runs.
How do you know a backup actually works?
Strong answer: Tests a restore on a schedule, documents how long a full restore takes, and keeps at least one copy that ransomware on your network cannot reach. A strong answer distinguishes between a backup that runs and a backup that has been proven to come back.
Weak answer: A weak answer describes the backup schedule and stops there. Backups that have never been restored are the most common unpleasant surprise in a small-business incident.
Do you receive a commission or partner margin on what we buy through you?
Strong answer: Answers directly, names the vendors involved, and explains how they keep the advice independent, for example by presenting options at different price points and letting you buy direct if you prefer. Disclosure without hesitation is the signal.
Weak answer: A weak answer deflects, changes the subject, or insists the question does not apply. Undisclosed vendor incentives are the most common conflict of interest in IT consulting.
Two follow-ups do most of the remaining work. The first is why those three, asked after any list of recommendations, which forces the candidate to connect their advice to your business rather than to a standard checklist. The second is how would you know it worked, which separates people who ship changes from people who verify them.
Ask
What a strong answer includes
How would you assess us in the first week?
Interviews, inventory, what breaks, budget and growth, then a written priority list
What would you fix first, and why that?
Ranks by business impact and risk, not by what is easiest or most interesting
How do you know a backup works?
Tested restores on a schedule, with a documented restore time
Explain this to me as a non-technical owner
Plain language, no jargon, checks that you followed
What is outside your expertise?
Names the boundary and the specialist they bring in
Do you earn a margin on what we buy?
Direct disclosure, options at different price points, no hesitation
Run the same six prompts past every candidate. When two firms give the same recommendation but only one of them arrived at it by asking about your business, you have learned something a proposal document will never tell you. Then verify with a reference check before you commit.
Security Questions Worth Asking Twice
Ask about security twice: once about what they will do for you, and once about the risk their own access creates. Most interview kits cover the first half and skip the second, which is the half that has actually cost small businesses money.
On what they will do for you, listen for cheap and boring before expensive and impressive. Multi-factor authentication, tested backups, and update discipline close most of the gap at a small business, and the federal NIST Small Business Cybersecurity Corner is a reasonable yardstick for whether a proposal is right-sized. A consultant who leads with a product rather than the basics is answering a different question than the one you asked.
Named accounts, never shared logins
The consultant works under their own named administrator account with multi-factor authentication, so every action is attributable and can be switched off in one step.
You own the tenant and the licenses
Cloud tenants, domain registration, and software licenses are registered to your business, with the owner holding a global administrator account of their own.
Offboarding agreed before onboarding
Write down what happens to credentials, documentation, and data when the engagement ends, before it begins. Ask the question in the interview.
Reference calls about surprises
Ask past clients about invoices, response times, and whether documentation was good enough for someone else to pick up. Reluctance to give references is itself an answer.
On the second half, an IT consultant typically holds administrator access to email, files, the domain, and sometimes financial systems. Named individual accounts, multi-factor authentication on those accounts, and an offboarding plan agreed before the engagement starts are all reasonable to require. A good consultant expects to be asked. Resistance to any of it is a warning sign worth weighing heavily.
Scope, Pricing, and Contractor Status
Commercial terms belong inside the interview, not after it. Ask about the pricing model, what sits outside scope, how change requests are approved and priced, and whether the consultant earns a commission or partner margin on anything you buy through them. Disclosure without hesitation is the signal you want.
Pricing model
Fits when
Ask specifically
Hourly
Small, unpredictable work
Minimum billing increment, travel time, after-hours rate
Project fee
A defined migration or uplift
What is out of scope, and how change requests are priced
Monthly retainer
Ongoing advice and support
Included hours, what rolls over, response times, notice to end
Blended firm rate
A firm with mixed seniority
Who actually does the work, and at which rate
Most IT consultants are engaged as independent contractors or through a firm rather than hired as employees, which suits project-shaped work. Classification is not a preference, though: the IRS weighs behavioral control, financial control, and the type of relationship, not the label on the agreement. If the engagement drifts toward set hours and daily direction, read up on employee versus contractor status and talk to your accountant.
Whichever way it goes, get a confidentiality agreement signed before the first login, since the consultant will see customer data and staff records. If the arrangement later converts to an employee role, the paperwork and onboarding side is where FirstHR fits, with e-signature, document management, and a structured first-week workflow. Applicant tracking is coming soon to FirstHR.
Fair, Legal, and Structured Interviewing
Fair, legal, and structured reinforce each other. Asking the same job-related questions of everyone keeps you compliant, reduces the pull of a strong first impression, and produces a better decision at the same time. It also leaves you a record of why you chose one firm over another.
Ask about the work, not the person
Federal anti-discrimination law, enforced by the EEOC, prohibits basing hiring decisions on protected characteristics, and questions that touch them create risk even when they are asked as small talk. Skip age, race, religion, national origin, sex, pregnancy or family plans, disability, and genetic information. In an IT consultant interview the usual traps are casual: guessing how long someone has been in the field as a proxy for age, asking where an accent is from, or asking about family commitments when you really mean weekend availability. Ask about availability directly instead. Every question in these sets is written to stay on the work. This is general information, not legal advice.
Use the same core questions for everyone
Ask each candidate or firm the same core questions and score them against the same rubric. A structured interview predicts on-the-job performance far better than a free-flowing conversation, and it protects you from the specific failure mode of technical hiring, where the most confident vocabulary wins rather than the best method. This matters even more when you are comparing an independent contractor against a managed services firm, because the sales polish differs wildly while the underlying quality may not. Write the questions in advance, ask them in the same order, and score right after each conversation. This is general information, not legal advice.
Score independently, then discuss
If your office manager sits in alongside you, have both people score the rubric on their own before anyone talks. This stops the more senior or more technical voice from anchoring the decision, which is exactly how a small business ends up buying the solution that was explained most fluently rather than the one it needed. Compare written evidence first, then discuss the gaps. A 1-to-5 rubric filled in separately turns a subjective debate into a structured decision, and it leaves you with a record of why you chose one firm over another.
Weight the sets to your actual situation
A consultant brought in for a one-time migration and one you want on a monthly retainer are different decisions, so weight the questions accordingly. For a project, lean on discovery, technical depth, and scope and pricing. For an ongoing relationship, weight communication, response times, security, and the exit and handover terms far more heavily, because those are what you will live with every month. If the engagement touches regulated data such as health or payment records, add your own compliance questions before you start, and put the answers in writing.
Same Questions, Same Rubric, Better Decision
A structured interview, where every candidate answers the same questions scored against a consistent rubric, predicts on-the-job performance more reliably than an unstructured conversation, and asking the same job-related questions of everyone also keeps you inside the EEOC rules against basing decisions on protected characteristics. Structure is both the fairer approach and the more effective one.
Keep every question tied to the work, and watch the casual traps: years in the field used as a proxy for age, questions about where an accent is from, or family commitments raised when you really mean weekend availability. The list of questions employers cannot ask is worth a read before the first call. This is general information, not legal advice.
What an IT Consultant Costs
There is no separate federal occupation called IT consultant, so use the nearest classification as a floor. Computer systems analysts is the closest match, and its reported job titles include computer systems consultant and IT analyst. Consulting rates sit above employee wages because they cover overhead, insurance, and unbilled time.
Median $105,850 a Year (BLS, May 2025)
Computer systems analysts had a median annual wage of $105,850, about $50.89 an hour, with the lowest 10 percent under $67,340 and the highest 10 percent over $167,710, according to the Bureau of Labor Statistics Occupational Employment and Wage Statistics survey (May 2025). Employment in the occupation is projected to grow 9 percent from 2024 to 2034, with about 34,200 openings a year on average (U.S. Bureau of Labor Statistics).
Compare quotes on scope rather than on rate. A higher hourly rate attached to a written scope, a change process, and a named engineer is usually cheaper over a year than a low rate with everything billed as an extra. Ask each candidate to price the same defined piece of work, which is the only way to make the numbers comparable at all.
Hiring Without an IT or HR Department
A large company runs this through a procurement team, a security review, and a legal read of the contract. A small business runs it through one owner, between everything else, with no in-house technical opinion to check the advice against. That reality shapes where the avoidable mistakes cluster.
You are buying expertise you do not have, which is the whole problem
Every other hire can be judged against something you already know. An IT consultant cannot, which is why owners fall back on confidence as a proxy for competence. The way out is to stop grading the technology and start grading the method. Did they ask about the business before recommending anything? Do they test restores or just schedule backups? Can they explain a decision in language your office manager can act on? Those three signals are visible to anyone, and each of the question sets on this page pairs its questions with a note on what a strong answer contains, so you can hear the difference without being technical yourself.
The consultant will hold the keys to everything
An IT consultant typically ends up with administrator access to your email, your files, your domain, and sometimes your financial systems, which makes access hygiene part of the evaluation rather than a detail to sort out later. Insist on named individual accounts with multi-factor authentication instead of a shared login, keep a global administrator account of your own, and register every cloud tenant, domain, and license in your business name. Agree what happens to credentials and documentation at the end of the engagement before it starts. A good consultant expects all of this. Resistance to any of it is a meaningful warning sign.
You are comparing a solo contractor against a firm, and the sales polish differs more than the quality
A managed services firm will usually present better than an independent contractor, with a slide deck, a service catalog, and a salesperson who never touches your systems. That difference in polish tells you very little about the work. Ask both the same core questions, and add two for the firm: who is our day-to-day engineer, and what happens when that person is away. Once you choose, the commercial and people side is where a small business gets caught out, so put scope, pricing, and access in writing before anyone logs in. FirstHR handles the people half of that: e-signature for a confidentiality agreement, document management for signed paperwork, and onboarding workflows when the engagement turns into an employee hire. Applicant tracking is coming soon to FirstHR.
What you get
Independent consultant
Managed services firm
One named person who knows your setup
Coverage when your contact is unavailable
Breadth across networks, security, and software
Direct line to the person doing the work
Formal documentation and process by default
Neither column is the right answer on its own. The comparison is only useful once you know which gaps you can live with, which is why the questions about coverage, documentation, and handover matter more than the org chart. Ask both the same core set, then judge on the answers.
From Interview to Engagement
The interview is step one. Once you choose, the work shifts to getting the commercial and access side right before anyone logs in: a written scope, a signed confidentiality agreement, named administrator accounts, and a documented handover plan. Doing this at the start is far easier than reconstructing it later.
Put the scope in writing
Confirm the deliverables, the pricing model, what sits outside scope, and how change requests are approved and priced, before any work starts.
Sign the confidentiality agreement
The consultant will see customer data, financial systems, and staff records, so a signed confidentiality agreement belongs before the first login, not after.
Grant access with controls
Named administrator accounts with multi-factor authentication, the owner keeping a global administrator account, and every license in your business name.
Store the records
Keep the signed agreement, the scope, the access list, and the documentation together, so a handover to a successor is a file transfer rather than an archaeology project.
If the engagement eventually converts into a permanent hire, the process becomes ordinary hiring again: an offer letter, the new hire paperwork, and a structured first month. FirstHR connects the offer, e-signatures, document management, and the onboarding workflow in one place, and keeps the signed records on the employee profile. FirstHR is an onboarding and HR platform, not IT management or security software, so pair it with those. Applicant tracking is coming soon to FirstHR.
Key Takeaways
Judge an IT consultant on five areas: business discovery, technical method, security, communication, and commercial terms.
The strongest single signal is diagnosis before prescription; be skeptical of advice that arrives before a question about your business.
Ask about security twice: what they will fix for you, and how they handle their own administrator access and offboarding.
Settle scope, pricing, vendor margins, and account ownership inside the interview, not after it.
Register every cloud tenant, domain, and license in your business name, and keep an owner administrator account of your own.
Score each area from 1 to 5 with evidence, then call two references about invoices, response times, and documentation.
Frequently Asked Questions
What questions should I ask when hiring an IT consultant?
Ask questions across five areas: business discovery, technical method, security, communication, and commercial terms. Strong openers include how they would assess a business like yours in the first week, how they decide what to fix first, how they know a backup actually works, what the first three security changes would be at your size, and whether they receive a commission on anything you buy through them. Then ask about update cadence, response times, what is out of scope, who owns the accounts and licenses they create, and what the handover looks like if the engagement ends. The pattern that matters is diagnosis before prescription: a consultant who recommends a purchase before asking how your business runs is selling, not advising. This page includes six ready-to-use question sets plus a scorecard, with notes on what a strong answer contains.
What is the difference between an IT consultant and IT support?
An IT consultant is hired to diagnose and advise, while IT support is hired to keep things running day to day. A consultant assesses your existing systems, recommends changes, plans migrations, and often runs a defined project with a start and an end. IT support answers tickets, fixes broken laptops, resets passwords, and handles the steady stream of small problems. Many small businesses need both, and many providers sell both under a single monthly retainer, which is why the scope questions matter so much: get in writing which of the two you are buying and what is billed separately. In interviews, test consulting skill with discovery and prioritization questions, and test support quality with response times, escalation paths, and what happens when your named contact is away.
How do I evaluate an IT consultant if I am not technical?
Stop grading the technology and start grading the method, which is visible to anyone. Three signals do most of the work. First, do they ask about your business, budget, and growth before recommending anything, or do they lead with a product. Second, do they test rather than assume, for example by restoring a backup instead of only scheduling one. Third, can they explain a technical decision in language your office manager could act on, without jargon. Add a fourth check outside the interview: call two references and ask whether invoices ever came as a surprise, how fast the consultant responded to something urgent, and whether the documentation was good enough for someone else to pick up. Each question set on this page pairs its questions with a note on what a strong answer contains.
Should I hire an IT consultant as a contractor or an employee?
Most small businesses engage IT consultants as independent contractors or through a firm, because the work is project-shaped and the expertise is needed occasionally rather than daily. Classification is not a matter of preference, though: it depends on the degree of control and independence in the actual relationship, and the IRS looks at behavioral control, financial control, and the type of relationship rather than at what the contract calls the arrangement. If you find yourself setting someone's hours, directing how the work is done day to day, and treating them as part of the team indefinitely, that pattern points toward employment. Talk to your accountant or an employment attorney before deciding. This is general information, not legal or tax advice.
What security questions should I ask an IT consultant?
Ask two categories: the security they will provide, and the risk their own access creates. On the first, ask what the first three changes would be at a business your size and why those three; strong answers usually lead with multi-factor authentication, tested backups, and update discipline rather than an expensive product. Ask how they would respond to ransomware, and listen for an ordered plan that includes isolating, restoring from tested backups, and fixing the root cause. On the second, ask whether they work from named individual accounts with multi-factor authentication rather than a shared login, where they store your passwords and documentation, what cyber liability insurance they carry, and exactly what happens to credentials and data when the engagement ends. A good consultant expects every one of these questions.
How much does an IT consultant cost?
Cost depends on scope, location, and whether you engage an individual or a firm, and there is no separate federal occupation called IT consultant. The closest classification is computer systems analysts, whose reported job titles include computer systems consultant and IT analyst. According to the Bureau of Labor Statistics Occupational Employment and Wage Statistics survey (May 2025), that occupation had a median annual wage of $105,850, about $50.89 an hour, with the lowest 10 percent under $67,340 and the highest 10 percent over $167,710. Consulting rates run above employee wages because they cover overhead, insurance, and unbilled time, and most small businesses pay hourly, by project fee, or on a monthly retainer. Use the federal figures as a floor for what the skill costs, then compare quotes on scope rather than on rate alone.
What are red flags in an IT consultant interview?
The clearest red flag is a recommendation that arrives before a diagnosis, especially when it happens to be a product the consultant resells. Others worth weighing: refusing to disclose vendor commissions or partner margins, wanting cloud tenants, domains, or licenses registered in their own name rather than yours, being vague about response times or what is billed extra, having no plan for handover if the engagement ends, and talking only about prevention with no incident response. Add two soft signals: an inability to explain a technical decision in plain language, and reluctance to provide references. None of these is disqualifying on its own, but two or three together usually predict the kind of engagement that ends badly. The downloadable scorecard includes the full red-flag checklist.
Are these IT consultant interview questions legal to ask?
Yes. Questions about technical experience, method, security practices, response times, pricing, and references are job-related and permitted. The legal caution is general to all interviewing: avoid questions that touch characteristics protected under federal law, which the EEOC enforces, including age, race, religion, national origin, sex, pregnancy or family plans, disability, and genetic information. In practice that means asking about availability directly rather than about family commitments, and not using years in the field as a proxy for age. Asking the same core job-related questions of every candidate and scoring them on the same rubric is the simplest way to stay both fair and consistent, and it leaves you with a record of why you chose one firm over another. This is general information, not legal advice.