Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

WEBIT Learning Hub

Inherited Networks: What a New MSP Finds and What Happens Next

Every new managed IT relationship starts with an inherited network: years of decisions made by people who may no longer be around. What a new provider finds in the first few weeks shapes everything that follows. Here is what we typically uncover, how we decide what to fix first, and what you should receive along the way.

Why every inherited network has surprises

Nobody builds a network from a single plan. Instead, it grows one urgent fix at a time. A new office opens, a vendor installs a system, or an employee sets up a shortcut that becomes permanent.

None of that makes the previous provider bad. However, it does mean the documentation rarely matches reality. In my experience, the gap between what a client believes they have and what is actually running is the single biggest onboarding risk.

So a good provider starts by assuming nothing. The team verifies every device, account, and rule before anyone changes it.

The first 30 days: discover before you change

The instinct is to start fixing things right away. Resist it. Changes made without full context are how onboarding causes outages.

Instead, the first weeks focus on discovery. A disciplined team scans the network, reviews admin consoles, collects credentials, and interviews the people who use each system. Then it compares what it finds against any existing documentation.

Only urgent security problems, such as an actively exploited vulnerability, justify immediate changes during this phase. Everything else goes on a prioritized list.

This phase also includes the business side.

For example, the team learns who approves spending and which systems cannot go down during busy seasons. It also learns which vendors need notice before changes. Those answers shape the remediation schedule as much as any technical finding.

What a new provider usually finds

Every inherited network is different. Still, certain findings appear again and again.

Admin accounts nobody can explain

Former employees, former vendors, and generic “admin” logins often still have full rights. Some have sat unused for years. Each one is an open door until someone confirms it and removes it.

Hardware and software past support

Microsoft ended Windows 10 support on October 14, 2025. So any machine still running it without Extended Security Updates no longer receives security fixes. Old firewalls, switches, and servers often have the same problem, just less visibly.

Backups that have never been tested

A backup job that reports “success” is not the same as a restore that works. Often, nobody has tried to recover a full system in years.

Firewall rules with no owner

Open ports and remote access rules pile up over time. Someone opened many of them for a project that ended long ago. Now nobody remembers why they exist.

Cloud services nobody tracks

Departments often sign up for file sharing, scheduling, or marketing tools on their own. As a result, company data ends up in places IT has never seen. Discovery should surface those accounts so someone can decide which to keep and secure.

Licenses and subscriptions out of alignment

Organizations frequently pay for accounts assigned to departed staff. Meanwhile, active users sometimes lack the security features their license tier should include.

Triage: what gets fixed first

A long finding list can feel overwhelming. So the order matters more than the length.

First, close active exposure. Anything on CISA’s Known Exploited Vulnerabilities Catalog goes to the top, because attackers are already using those flaws. Unexplained admin accounts come next.

Second, protect recovery. Test a real restore, and confirm that at least one backup copy sits isolated from the network.

Third, stabilize. Replace failing or unsupported equipment on a planned schedule rather than all at once.

Finally, standardize. Bring configurations, naming, and documentation into a consistent baseline so future support is predictable.

What you should receive during onboarding

You should not have to guess what your new provider found. By the end of onboarding, expect clear deliverables.

  • A complete inventory of devices, users, and cloud services.
  • A written summary of findings, ranked by risk, in plain language.
  • Confirmation that the provider has documented every admin credential and stored it securely.
  • Results of a real backup restore test, not just job reports.
  • A roadmap that separates urgent fixes from planned improvements, with rough costs.
  • A named contact who owns your account and walks you through the results.

If a provider cannot produce these, ask why. Also ask how they will keep the documentation current after onboarding ends.

Where new providers fall short

I have seen onboarding go wrong in two opposite ways. Some providers change too much, too fast, and break things the business depends on. Others change too little and simply take over support of an inherited network, risks and all.

A third failure is quieter. The provider does thorough discovery, then never shares it. As a result, the client pays for an assessment they never see and cannot use.

The fix for all three is the same: a written plan that the client reviews before work begins. That plan should say what will change, when, and who will notice.

Good onboarding sits in the middle. It is careful about change, honest about findings, and transparent with the client throughout.

How WEBIT approaches this

Our onboarding runs 30 days, and we take on no more than two new managed clients per month so each one gets full attention. We baseline every client to the CIS Controls. In addition, Security Essentials runs on every managed device, covering EDR, application allowlisting, DNS filtering, and vulnerability management.

You also get a named Client Success Manager and a dedicated Field Engineer from day one, and you can read how that rhythm works in the WEBIT Way. Because our managed IT services run month-to-month with 90 days’ written notice, we have to keep earning the relationship long after onboarding ends.

Key takeaways

  • Every inherited network hides undocumented accounts, gear, and rules.
  • Discovery should come before changes, except for urgent security exposure.
  • Fix active exposure first, then recovery, then stability, then standards.
  • You should receive an inventory, a ranked findings list, and a roadmap.
  • Watch for providers who change too much, too little, or share nothing.

Switching providers and want to know what you will find? Talk to an owner.

Talk to an owner

Want help applying this to your business? A 30-minute discovery call gets you honest advice.

Schedule a discovery call

Industry whitepapers

In-depth guides for 13 industries, from medical to manufacturing.

Browse whitepapers →

Estimate your IT cost

Real per-unit pricing, updated as you go.

Open the calculator →

Keep reading

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.