
Most MSP prospect lists are built from what a company is. The lists that produce conversations are built from what a company is doing. This page covers the first group in our guide to the 18 buying signals that show a company is about to change IT providers: the three signals that show a firm is changing its systems. Each one puts a decision about outside IT help on an owner's desk before the firm starts calling providers, and each is slow to spot by hand.
Systems-change signals are public traces that a company is altering how its technology works, and they predict a decision about outside IT support. Three matter most for a managed service provider. First, an AI rollout: a firm moves from staff using AI tools on personal accounts to a company account. That week it needs single sign-on, data retention settings, an acceptable-use policy, and someone to run the rollout. Second, an email or security vendor change: when a firm's email filtering or public sender records change, an IT provider change or a migration is usually under way. Third, an IT project before launch: new remote-access, client-portal, or AI systems often appear in public records before they go live. Each signal is slow to find by hand because the trace is spread across sources that no one person reads. An outbound system can watch for these signals and put the firms showing them at the top of a list built to the provider's ideal-client definition.
1. AI rollout: personal accounts become a company account
An AI rollout is a firm's move from personal chatbot use to a company account, and this event predicts an outside IT decision because sign-on, retention, and policy controls must exist before the account goes live. Once the account is official, someone must connect the tool to the login system, set retention on prompts and files, write an acceptable-use policy, and train staff on what may go into the tool. Few firms of 10 to 60 people have done this before.
Regulators have noticed. The Securities and Exchange Commission (SEC) examination priorities for fiscal year 2026 say examiners will assess whether firms have adequate policies to monitor AI use. The American Bar Association's Formal Opinion 512 ties a lawyer's competence and confidentiality duties to generative AI tools. An owner who opened a company account this week owns controls that did not exist last week.
A company standardizing on an AI tool leaves a trace in job postings that name the platform, in vendor-published case studies, and in press mentions. The trace is small and spread across every firm in a territory, so a salesperson cannot check it by hand.
2. Email or security vendor change
An email or security vendor change is a shift in a company's published SPF, DKIM, DMARC, or MX records, and this shift predicts an active migration or a recent IT-provider change because those records rarely move without a reason. Those records are the public settings that tell other mail servers who may send and filter email for the company. Every company that sends email publishes a small set of these records, telling other mail servers who may send on its behalf. A change means something real happened: a new email platform, a new filtering service, or a new IT provider.
For an MSP this means one of two things: either a competitor just won the account, which means the firm buys outside IT help and roughly when its agreement renews, or the firm is doing the migration itself and the hard parts are still ahead.
Financial firms have a regulatory reason too. The SEC's 2024 amendments to Regulation S-P require written policies for oversight of service providers that handle customer information. An adviser that just changed vendors has a new provider to document. The firm now needs a review of what moved, what did not, and who owns the pieces nobody claimed after the switch.
3. An IT project before launch
An IT project before launch is a client portal, remote-access system, or AI assistant seen in press releases or job posts before the go-live date, and this early visibility predicts the support decision because that choice is made before launch. Those filings and announcements are scattered across many sources and nobody reads them for a whole territory, so by the time a salesperson hears about the project it is usually live.
The value of this signal is timing. Once a system is live, the firm has already chosen who supports it. Before launch, the questions are still open: security review, identity and access, and who is on call the first week.
One related need sits on the calendar rather than in a filing, and it often becomes the project that surfaces before launch. Microsoft's Extended Security Updates for Windows 10 are priced per device and the price rises each year for up to three years, so a firm that bought updates instead of replacing machines has a device refresh ahead, and the project that appears before launch is often that refresh.
4. What an MSP sells into these signals
Each signal opens a different project, with its own buyer and its own worry.
AI rollout. The service model is a small, fixed-scope setup that often becomes a support retainer: sign-on, retention, a use policy, and short training. The owner or compliance officer usually decides. That person fears being asked to show controls that do not yet exist. The same rollout usually surfaces a second gap: file-sharing permissions and device rules written for email and documents, not for a tool that can read and summarize both, so the first engagement often grows past the four items above once the review starts.
Vendor change. The service model is a fixed-scope migration review when the firm manages the switch alone, or a managed-services agreement when a competitor was just hired. The owner or vendor lead decides, and that person fears downtime visible to every client. The first project is usually small, a review of what moved and what did not, and the managed agreement follows when the review turns up mail rules, backups, or devices that nobody owns after the switch.
Project before launch. The service model is a fixed-scope pre-launch review that tends to lead into an ongoing agreement: a security review, access setup, and first-week coverage. Whoever sponsors the project, usually the owner or a partner, decides, and that person fears a security gap surfacing right after go-live. The first project is scoped to the launch date: who can reach the new system, from which devices, with what logging, and who answers the phone in the first week when something the vendor did not test breaks.
| Signal | What changes at the firm | What it needs | Service model | Who decides |
|---|---|---|---|---|
| AI rollout | AI use becomes a company account | Sign-on, retention, use policy, training | Fixed-scope setup, often a retainer | Owner or compliance officer |
| Vendor change | Sender and filtering records change | Migration review or second opinion | Migration review or managed-services agreement | Owner or vendor lead |
| Project before launch | A system is built ahead of go-live | Security review, access setup, first-week coverage | Pre-launch review into a support agreement | Whoever sponsors the project |
5. Two honest caveats
First, nobody buys the day the event happens. The decision sits on the owner's desk for weeks before a provider is chosen.
Second, the sharpest signals are low volume. Only a small share of firms in a territory shows one of these signals at a given time. They belong at the top of a list built to the MSP's ideal-client definition. They are not the whole list.
Questions owners ask
How do we know a client's AI use just became official?
The clearest sign is a company account replacing personal accounts, paired with a new sign-on setup. That switch creates the sign-on, retention, and policy work.
Does a vendor change always mean the firm is unhappy with its IT provider?
No. The firm may be managing a self-directed migration without outside help at all. Both cases are worth a conversation, but a different one.
Why does a project matter before it has even launched?
Because the support decision is usually made before launch. Once live, the firm has already chosen who is on call, so arriving early is the only way to be considered.
Is Regulation S-P only a concern for large financial firms?
No. It applies to covered institutions of any size, so a small advisory firm that changes vendors still has documentation duties.
Does one of these signals mean a firm is ready to switch providers today?
Not by itself. A signal shows a decision is on the table, not that it has already been made.
Where to go from here
The next group is people and hiring: a new chief operating officer (COO) or compliance officer, and job posts that show one person carries the whole IT load. Read People and Hiring Signals: New Leaders and Telltale Job Posts. For the full list, see 18 buying signals that show a company is about to change IT providers. For the system that turns this list into conversations, see our guide to building an MSP outbound system.
Sources and editorial note
SiteSmith builds target lists for managed service providers around signals like these, and this article cites external sources for every factual industry and security claim. This article is not legal, regulatory, or cybersecurity advice.
- SEC Division of Examinations, Fiscal Year 2026 Examination Priorities
- SEC, adoption of amendments to Regulation S-P (May 2024)
- SEC fact sheet, Enhancements to Regulation S-P (service provider oversight)
- American Bar Association, Formal Opinion 512 on generative AI tools
- Microsoft Learn, Extended Security Updates program for Windows 10