IT Support Contract Mistakes San Antonio SMBs Keep Making

San Antonio owners rarely get burned by one exotic clause. They get burned by 7 habits around the agreement, from counting seats the way payroll counts them to answering a cyber insurance application the contract never backed up. Every one of them is fixable before the next renewal, and most take an afternoon. For what the service itself should cover, start with our managed IT services in San Antonio page.

The most common IT support contract mistakes in San Antonio are miscounting billable seats, assuming the provider inherits your compliance duty, attesting to security controls the agreement never required, and buying monitoring while believing it’s coverage. None of those are clause problems. They are habits.

I’ve signed a lot of these agreements from the other side of the table. Hundreds, probably.

Running Uprite means I’ve also watched what happens 14 months later, when the honeymoon is over and somebody pulls the PDF out of an email thread to settle an argument. The clause is almost never the villain. Nine times out of ten the contract said exactly what it was going to say, in plain enough English, and nobody on the client side had read it since the day it was signed, which is a very different problem than a predatory provider and needs a very different fix. Different problem. Different fix.

This piece is about the buyer side of the table. Not the fine print. If you want the clause by clause read, the Texas MSP contract guide covers the document stack and the statutory layer, and response time contract mechanics covers what an SLA number actually commits anyone to. Still comparing providers? Go read the San Antonio provider selection guide first and come back here once you have a shortlist.

What separates a contract mistake from a bad deal?

A contract mistake is something you did, or failed to do, that the agreement already told you about. A bad deal is a term you would reject if you understood it. The first kind is yours to fix and costs nothing but attention. The second needs a negotiation. Sometimes a different provider.

Worth separating them early, because owners tend to blame the provider for both.

The 7 below are all the first kind. They show up in San Antonio more than they should, and 3 of them bite harder here than they would in Dallas or Houston for reasons that have nothing to do with the providers and everything to do with what this city’s economy looks like. Geography matters. Not the way people expect.

Mistake 1. Why does the seat count on your invoice keep growing?

Your contract does not count people. It counts whatever the order form says it counts, which is usually managed endpoints, licensed mailboxes, or named users, and those 3 numbers are almost never the same number in a business that runs shifts. Check yours. Right now.

San Antonio makes this worse than the state average. Leisure and hospitality employment here ran 149,500 jobs in August 2026 against 1,191,700 total nonfarm, which is 12.5% of the metro workforce. Statewide the same ratio is 10.9%. Add the seasonal construction and event staffing that comes with it and you get a payroll number that moves every quarter while your managed seat count sits frozen on an annual order form.

Here is where it actually bites. A 40 person company hires 9 seasonal staff in March, the provider provisions 9 mailboxes and 9 endpoints, the true up clause catches it at the next billing cycle, and in October those 9 people are gone but the seats are not, because Microsoft’s own rules say an annual term subscription cannot shed licenses mid term outside a short window after purchase or renewal. You pay for 49 until the anniversary.

That is not your provider being greedy. That is Microsoft licensing, passed through.

Counting basisWhat it actually countsWhere it goes wrong in San Antonio
Per managed endpointDevices with an agent installedShared floor terminals and kiosks get double counted
Per named userHumans with a login, active or notSeasonal staff stay on the list after the season
Per licensed mailboxMicrosoft 365 assignmentsShared and resource mailboxes get billed as people
Per sitePhysical locations coveredA second warehouse opens and nobody amends the order form

Ask for the counting basis in writing, ask what triggers a recount, and ask whether the count can go down mid term or only up. Three questions. Providers who bill honestly answer all 3 in a sentence each. Our San Antonio managed IT cost breakdown walks the per user math, including the $30 to $50 per user per month of licensing that usually sits on top of the managed fee and moves on its own schedule.

Shift change in a San Antonio hospitality business as a supervisor counts staff on a tablet

Mistake 2. Does the contract inherit your compliance duty?

It does not. A managed services agreement can move work to your provider. It cannot move the legal obligation, because the statute and the prime contract both name you, not them.

San Antonio feels this harder than the rest of Texas. Government employment here is 181,800 jobs, 15.3% of everything, and the defense supply chain attached to it reaches into shops that do not think of themselves as defense companies at all. A machine shop. A caterer with base access. A firm drafting plans for a subcontractor two tiers up. The DFARS acquisition rule that carries CMMC into live contracts has been effective since November 10, 2025, and primes flow the clause down whether or not the sub was expecting it.

We have the same conversation 3 or 4 times a year. An owner forwards a flow down request and asks whether their IT contract covers it.

Usually it doesn’t. Managed IT and a CMMC assessment are different products with different scopes, and an agreement written for the first will say nothing about the second. That’s a gap to close deliberately, which is what our CMMC compliance work in San Antonio exists for, not something to assume away. Assume nothing here.

State law has the same shape. Texas SB 2610 created Chapter 542 of the Business and Commerce Code and gives businesses with fewer than 250 employees a shield against exemplary damages, but only if the business itself implemented and maintained a qualifying program. Tiers scale by headcount.

HeadcountWhat Chapter 542 expectsWhat your provider can doWhat stays yours
Under 20Simplified controls, password policy, employee trainingDeliver and document bothProving it was maintained at the time of the breach
20 to 99Moderate requirements against a recognized standardRun the controls, produce the evidenceChoosing the standard and funding the gaps
100 to 249Conformance to a framework such as NIST CSF or CIS ControlsOperate most of itGovernance, policy approval, risk acceptance
250 and upChapter 542 does not applySame services, no statutory shieldEverything

Read the right hand column twice. CISA makes the same point in its joint advisory on managed service provider risk, which is blunt about the fact that outsourcing the work never outsources the accountability.

Mistake 3. What if your insurance answers don’t match your contract?

This is the one that keeps me up. An owner answers 30 underwriting questions about MFA, endpoint detection, offline backups and privileged access, ticks yes to most of them because that’s what the provider pitched, and files the policy. Nobody checks those answers against the service schedule. Nobody ever does.

Then a claim happens and the carrier reads both documents side by side.

International Control Services, a 150 employee manufacturer, told Travelers it required multifactor authentication for privileged access. It didn’t. Not at application, and not at the time of the ransomware attack. Travelers sued to rescind the policy from inception and, as Lockton documented, the parties stipulated to a judgment voiding it. The MFA gap didn’t cause the breach. The answer on the form was enough.

Run your application answers against your contract before you sign either one. If the application says continuous monitoring with 24×7 response, the service schedule should say the same words, and if it says you maintain immutable offsite backups, someone needs to point at the line that obliges anybody to do that. Where the two disagree, fix the contract or change the answer. Our managed security services in San Antonio page lists what a baseline actually includes, which is a reasonable starting point for that comparison.

IBM puts the global average breach at $4.99 million with a 247 day lifecycle. A rescinded policy means you carry all of it. Every dollar.

Business owner reviewing a cyber insurance application late at night under a desk lamp

Mistake 4. Is 24×7 monitoring the same thing as coverage?

Monitoring is watching. Coverage is someone getting out of bed. Plenty of agreements promise the first in large type and the second in small type, and buyers read the large type. Read the small type.

The question to ask is narrow. When an alert fires at 2 a.m. on a Saturday, who is contractually obligated to touch it, how fast, and does that obligation change if it happens to be a Saturday in December? A 24×7 monitoring line and a business hours remediation window can sit in the same agreement without contradicting each other. They frequently do.

Line in the agreementWhat it usually meansThe follow up question
24×7 monitoringTooling watches around the clockDoes a human see the alert at 2 a.m.?
24×7 supportSomeone answers the phoneAnswers, or works the ticket?
After hours coverageOften billable at a separate rateWhat is the rate and who authorizes it?
Onsite responseTravel to your addressWithin what window, and is it included?

We average 5 minutes on first response across all priority levels, and that number is only worth quoting because it’s measured the same way at 2 a.m. as it is at 2 p.m. Same clock. Ask any provider how theirs is measured before you compare it to anyone else’s. The San Antonio response time benchmarks post has the local comparison.

Mistake 5. When did anyone last prove your restore works?

Backups are in every managed IT contract written in the last decade. Tested restores are in far fewer. That gap is where companies die.

Veeam surveyed more than 900 IT, security and risk leaders for its 2026 report and found that 90% were confident they could recover while only 28% of ransomware victims actually got all their data back. 44% recovered less than three quarters of it. The average was 72%.

Confidence and capability are not the same asset. Only one restores files.

Put 3 things in the agreement. A recovery time objective in hours, a recovery point objective in minutes or hours, and a scheduled restore test with a written result you receive. Our own baseline includes tested backup and recovery rather than backup alone, and the test result goes into the quarterly review packet. If your current provider has never handed you a restore report, you don’t have an opinion about your backups. You have a feeling. The San Antonio backup and disaster recovery page covers what a real test looks like.

Mistake 6. Who is actually booking your strategy hours?

Plenty of mid market agreements include quarterly business reviews or a virtual CIO allotment. Plenty of those hours expire unused. Every year.

The owner is busy. A calendar invite goes out, it gets moved twice, then it quietly stops being sent. Eighteen months later the same company is buying hardware reactively and wondering why the roadmap never materialized, and the honest answer is that the roadmap was a contractual deliverable both sides let lapse.

Book them. Every quarter we review ticket volumes, average response times, security posture score, roadmap completion percentage, and open risk items with client leadership, and that meeting is where the next year’s budget gets built. It’s also the cheapest thing in the contract. You already paid for it.

There’s a second reason to keep the meeting. Hiring the equivalent in house is not cheap in this market. San Antonio had 1,350 information security analysts employed metro wide in 2025 at an annual mean wage of $125,830, and loaded with benefits at the federal 1.43 multiplier that’s roughly $180,000 for one person who takes vacations. Your strategy hours cost a fraction of that. And you are throwing them away.

Small business leadership team in a quarterly technology review meeting with their IT provider

Mistake 7. Who owns your IT contract right now?

Ask who owns your IT agreement. If the answer is the person who signed it, and that person left in 2024, you have this problem.

Three things go wrong when nobody owns it. A renewal notice window passes unnoticed, which quietly buys you another full term. Out of scope work gets approved by whoever picks up the phone, because the agreement names an authorized approver and nobody told the front desk. And when the relationship does need to end, the exit clock starts from a date nobody has in a calendar, which is exactly the scenario our guide to exiting an MSP contract was written for.

Name an owner. Put the renewal date and the notice deadline in a shared calendar with a 120 day warning. Write down who can authorize billable work. Twenty minutes, total. It survives staff turnover, and it’s the highest return item on this whole list.

What each mistake costs, and the line that prevents it

Here is the whole list in one place, with the specific contract language that shuts each one down. Take it to your next renewal conversation. Print it.

MistakeWhat it costsThe line that prevents it
Counting seats wrongMonths of billing for people who leftCounting basis, recount trigger, and whether the count can decrease mid term
Assuming compliance transfersA failed flow down or a lost safe harborA named framework, a responsibility matrix, and who produces evidence
Guessing on the insurance formA rescinded policy and an uninsured breachControl obligations written in the same words the application uses
Monitoring mistaken for coverageAn alert that sits until MondayRemediation hours stated separately from monitoring hours
Untested restoresPartial recovery during the worst week of your yearRTO, RPO, and a scheduled restore test with a written result
Unused strategy hoursReactive spending and no roadmapA quarterly review cadence with named attendees and required metrics
No internal ownerAn unwanted auto renewalNotice window, renewal date, and a named authorized approver

A 30 minute contract review you can do this week

You don’t need counsel for this pass. You need the PDF and a highlighter. That is all.

  1. Find the order form and write down the counting basis and the current count.
  2. Find the renewal date, subtract the notice period, and put both in a shared calendar.
  3. Search the document for the word excluded. Read every hit.
  4. Open your cyber insurance application next to the service schedule and compare the security answers line by line. This is the step people skip and it’s the most valuable one in the list, because a mismatch here can void a policy you are otherwise paying for correctly every single month.
  5. Look for RTO and RPO. If neither appears, that is your first redline.
  6. Find the clause naming who may authorize out of scope work, then go tell that person.

Six steps. Under half an hour for most agreements. Anything you can’t answer becomes a question for your provider, and a provider who won’t answer plainly has told you something useful.

When none of this is worth your time

Bias disclosed up front, since we sell the thing I am writing about.

If you run 8 people on laptops and Microsoft 365, hold no regulated data, take no government work and carry no cyber policy, most of this list is overhead. Fix the renewal calendar, confirm someone has actually restored a file once, and get on with your business. A break fix arrangement may genuinely fit you, and the break fix versus managed IT comparison for San Antonio is honest about where that line sits.

Around 20 people it starts earning its keep. Or the first day somebody sends you a security questionnaire.

How Uprite handles these 7

Uprite Services is a managed IT and cybersecurity provider for small and mid sized businesses across Texas, with a San Antonio office on Radium Street and teams in Houston, Dallas and Fort Worth. We exist because companies under 250 employees need real security and a technology roadmap without carrying enterprise payroll to get them. What makes our agreements different is not clever drafting. It’s that the counting basis, the remediation hours, the restore test and the quarterly review are written down as obligations rather than implied by a sales deck. No asterisks.

Our baseline covers endpoint detection and response, email filtering, multifactor authentication, patch management, conditional access, security awareness training, and tested backup and recovery. Those are the same controls a cyber insurance application asks about. That is deliberate. If you’d rather keep your internal IT lead and add depth around them, co-managed IT in San Antonio works the same way on a smaller scope.

Send us your current IT agreement and we will mark up the 7 items above against it, in writing, whether or not you end up switching providers.

Get a Contract Review

What San Antonio owners ask about IT support agreements

Can I reduce my seat count mid contract if we shrink?

Usually not, and the block often comes from Microsoft rather than your provider. Annual term subscriptions only allow license reductions in a short window after purchase or renewal, so a headcount drop in month 4 typically waits for the anniversary. Ask for monthly term licensing on the roles you know will fluctuate. It prices higher per seat.

Does my MSP contract make them responsible for CMMC?

No. The contract can assign the work, never the obligation. Your prime contract names your company, and the DFARS clause flows down to you. A provider can implement controls, keep the evidence and support an assessment, but the certification and the liability stay on your side of the table. Get a written responsibility matrix instead of a verbal assurance.

My provider says backups are included. Isn’t that enough?

Included backups and proven recovery are different products. Only 28% of ransomware victims in Veeam’s 2026 survey fully recovered their data. Ask for a recovery time objective, a recovery point objective, and a restore test on a schedule with a report you actually receive. No test result from last quarter? Then you have an untested backup.

Is a San Antonio provider better than a national one for a company like mine?

It depends far more on the contract than the zip code. Local matters when you need hands on site inside a stated window, when base adjacent work requires people who can pass a screening, and when you want the quarterly review to happen in a room rather than on a call. National providers win on scale and sometimes on price. Compare the onsite response language, not the marketing.

How much notice do I have to give before renewal?

Commonly 60 to 90 days, and Texas does not cap it for business to business agreements. Read your own document, because the window is measured back from the renewal date. Calendar the deadline, not the renewal.

What if I already signed something with all 7 of these problems?

Start with the 2 that cost money immediately, which are the seat count and the unused strategy hours, because both can be fixed by email this week without renegotiating anything. Take the rest to the renewal conversation as a redline list. Most providers move on restore testing and remediation windows long before they move on price. Push there first. Timing decides how hard you get to push, so if your renewal sits more than 120 days out you have room to open all 7 at once, and if it is already inside 30 days, send the notice first to preserve your options and negotiate afterward.

About Author

Learn More