What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
When an IT vendor repeatedly misses commitments, obscures security information, or makes it hard to retrieve your data, treat the behavior as a business risk—not just a frustrating service problem. Record what happened, rank the potential harm, compare performance with your agreement, and ask for a corrective plan with named owners and verifiable milestones. If the risk remains unacceptable, prepare a controlled transition rather than making a rushed exit.
Which vendor problems deserve attention first?
“Worst bad habits” is a conversational label, not a formal industry taxonomy. Focus on observable patterns rather than assuming every vendor behaves badly. A missed call is different from a recurring failure to report a security incident or provide records your business needs.
Prioritize by potential impact and urgency. CISA advises leaders to focus on the “critical few” risks instead of trying to remediate everything at once. That is a useful way to organize your response, not a universal ranking of vendor problems. See CISA’s guidance on bad practices.
- Security or privacy exposure: unexplained access, unresolved vulnerabilities, missing incident information, or uncertainty about how sensitive data is handled.
- Service continuity: outages, repeated missed service commitments, or a failure that could interrupt essential operations.
- Loss of visibility or control: inaccessible records, unclear responsibility for a task, or missing information about subcontractors and system access.
- Exit barriers: data, credentials, integrations, or essential processes that cannot readily be moved or maintained elsewhere.
For each concern, note dates, commitments, outcomes, and business effects. A short record of repeated missed deadlines is more actionable than a general complaint that a vendor is “unresponsive.”
#1 Best Overall
How should you assess the vendor’s performance?
Start with the agreement and the evidence
Compare what happened with the service description and commitments already agreed. Check the relevant terms for scope, response and escalation processes, security commitments, reporting, subcontractors, and transition duties. These are review prompts, not a universal list of contractual requirements or legal advice.
Separate facts you can verify from assumptions. For example, record the date you requested an incident update and what information was supplied; do not conclude that a vendor concealed an incident unless evidence supports that claim.
Use repeatable questions
A consistent assessment makes it easier to identify gaps and compare vendors. CISA’s small- and medium-sized business supplier-assessment fact sheet offers sample topics including security and privacy policies, asset management, network access, contractual obligations, incident detection, and recovery. Use its supplier assessment fact sheet to shape questions appropriate to your service and risk.
For a managed service provider (MSP), ask what security requirements apply, how subcontractors are vetted, and whether you can access relevant security logs and telemetry. CISA identifies these as visibility areas for MSP customers in its guidance on risks for MSP customers.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
Ask security questions across the software lifecycle
Software risk does not end at purchase. Ask how the vendor handles vulnerabilities and patches, what incident-notification process applies, and whether it can provide relevant information about software components. NIST’s guidance discusses acquisition, use, and maintenance of third-party software, including component inventories, vendor assessments, and vulnerability management. Its stated audience and scope are federal agencies; it is not a universal legal mandate for all buyers. Read NIST’s software supply-chain guidance.
What should a corrective plan include?
Describe the gap in concrete terms, refer to the applicable commitment where relevant, and ask the vendor to respond in writing. A workable plan should make responsibility and progress checkable.
- Issue and impact: the specific missed deliverable, unresolved concern, or information gap, with dates and business consequences.
- Owner: a named person on each side who is responsible for next steps.
- Actions and milestones: what will change and when, including interim safeguards if needed.
- Evidence: how completion will be demonstrated, such as a report, updated procedure, or agreed service record.
- Review date: when both sides will assess progress and decide whether further escalation is necessary.
For a security issue, tailor the requested evidence to the risk: vulnerability handling, patch progress, incident updates, or relevant component information. Avoid asking for sensitive records without considering how they can be shared and protected.
How can you reduce dependence on a difficult vendor?
Integration can improve agility, productivity, operations, and management, but it can also make a service harder to replace. Gartner’s public abstract on cloud lock-in frames this as a risk to assess alongside those benefits; it does not prescribe specific contract terms. See Gartner’s cloud lock-in abstract.
Best Value
Map the practical dependencies before a dispute becomes urgent:
- Which systems, business processes, and integrations rely on the vendor?
- Where is your data, and what export formats and access methods are available?
- Who controls administrator credentials, encryption keys, and service accounts?
- Which proprietary components or subcontractors could complicate a replacement?
- What would operations need to continue during an outage or transition?
Review any existing data-portability, access, and transition provisions, and identify what would need to be arranged if service ends. The goal is to understand the effort and continuity risks of a change; integration alone does not mean a service is harmful.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When and how should you escalate or switch?
Escalate in proportion to the risk. Use the agreement’s escalation process and involve the people responsible for security, procurement, operations, or legal review as appropriate. Keep a dated record of communications, decisions, and promised actions.
If the vendor does not remediate the issue or the remaining risk is unacceptable, evaluate a managed transition. Confirm what data and records must be retrieved, who will maintain critical operations, and how access will be handled during the change. Do not terminate unilaterally without reviewing the agreement and applicable law; a qualified adviser can assess legal remedies and notice requirements.
How to compare a replacement vendor
Use the same practical criteria for each candidate, tailored to the service and the consequences of failure. These dimensions synthesize the cited guidance; they are not a universal scoring model.
Quick Recap
| Dimension | Questions to ask |
|---|---|
| Security evidence | Can the vendor explain its vulnerability disclosure and patch process, incident handling, relevant audit evidence, and availability of software component information? |
| Operational accountability | Is the service scope clear? Are commitments measurable, escalation contacts identified, reporting cadence defined, and responsibility boundaries understood? |
| Dependency and exit | Can you export data in a usable form? What proprietary components or integrations could complicate a move, and what transition support is available? |
| Supplier visibility | Will the vendor disclose relevant subcontractors and provide access to records or telemetry needed to oversee the service? |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




