If you only hear from your IT provider when something breaks, a council meeting is coming up, or it is time to renew a contract, you are not getting enough value.

Technology is not a one time setup. Your staff changes. Your systems change. Public expectations change. Cybersecurity risks change too.

That is why a quarterly IT review matters for municipalities, public agencies, utility districts, public works departments, libraries, parks departments, and economic development organizations across the Greater St. Louis region.

Most city administrators, department heads, and public sector leaders know they should be checking in, but they are not always sure what to ask. That is normal. You run public services. You should not have to speak IT for a living.

Here are six simple questions your IT provider should be able to answer every quarter, in plain English.

1. What security problems need attention right now?

Every organization has weak spots. That includes cities, villages, townships, utilities, and public agencies. The goal is not to pretend they do not exist. The goal is to find them early and deal with them before they turn into downtime, fraud, data loss, service disruption, or a public trust problem.

Ask your provider:

Are any systems missing security patches?

Have there been unusual login attempts?

Are any users, devices, or processes creating extra risk?

Are there security alerts we should know about?

Are public facing systems, payment portals, or citizen service platforms being monitored properly?

You do not want a vague answer like everything looks good. You want specifics.

A good IT partner should be able to tell you where your top risks are, what has already been fixed, and what still needs attention.

That matters whether you are supporting residents in Chesterfield, handling permits in St. Charles, managing public works in O’Fallon, or protecting administrative systems in Clayton.

2. Have our backups been tested recently?

A backup only matters if it works when you need it.

Plenty of public organizations think they are covered because a backup system exists. Then a server fails, ransomware hits, a file share gets corrupted, or someone deletes the wrong folder, and everyone finds out the recovery plan was never tested.

That is not the time to figure it out.

Ask:

When was the last full recovery test?

How long would it really take to restore our systems?

Are backups stored separately from our main network?

Are Microsoft 365, Google Workspace, and other cloud apps included?

Who is responsible for restoring what during an outage?

What services must come back first if we have limited time or resources?

You need a tested plan, not hope.

For local government, this is bigger than convenience. It affects payroll, utility billing, police and fire administration, permitting, records access, inspections, public meetings, citizen communications, and continuity of services.

3. Where is technology slowing our staff down?

Not every IT problem feels like an emergency. Some problems just drain time all day long.

A computer takes too long to start. A records system freezes. A GIS workstation struggles. A video call drops during a board meeting. A staff member stops using a system because it is too painful.

Those issues cost taxpayer resources, even if nobody opens a ticket.

Ask your provider:

Are we seeing repeat performance issues?

Are any computers or servers aging out?

Which systems get the most complaints?

Are we outgrowing any software or hardware?

What should be optimized before it becomes a bigger problem?

Are there manual processes that could be simplified with better use of Microsoft 365 or existing tools?

Technology should help your team serve the public faster and more reliably. It should not train people to work around problems.

This is especially important for lean departments. A small parks department, library district, or public works office in Maryland Heights, Edwardsville, Collinsville, or Belleville may not have extra staff to absorb wasted time.

4. Are we still meeting compliance, records, and insurance requirements?

Compliance is not something you check once and forget.

Public agencies deal with retention rules, open records obligations, cyber insurance requirements, payment security, vendor contracts, grant requirements, and internal policies. Some departments may also touch health, financial, law enforcement, or utility customer data.

A city or district that was in good shape last year can fall behind without realizing it.

Ask:

Have any requirements changed recently?

Do our policies and documentation still line up?

Do employees need updated security training?

Are there controls we need to strengthen?

Would we be ready if an auditor, insurer, board, council, or state agency asked for proof?

Are we protecting citizen data the way the public expects us to?

The cost of falling behind is not just a fine or an audit finding. It can affect cyber insurance claims, legal exposure, public confidence, staff credibility, and your ability to keep essential services running.

Public trust is hard to earn and easy to damage. Technology decisions play a bigger role in that than many people realize.

5. What should we budget for next quarter?

Good IT planning keeps surprises off your desk.

Your provider should be tracking what is coming, not just reacting to what broke this morning.

That includes:

Aging computers and servers

Expiring warranties

Software renewals

License changes

Network upgrades

Security improvements

Microsoft 365 licensing and configuration changes

Upcoming vendor price increases

Public meeting technology

Backup and disaster recovery needs

Quarterly planning gives you time to make smart decisions. It helps you spread costs out, avoid rush purchases, and align technology with the budget cycle.

No city administrator, finance director, library director, utility manager, or parks leader likes surprise IT expenses. Most of them can be prevented with better planning.

For public agencies in St. Louis and the Metro East, this also helps with board approvals, council packets, grant planning, procurement timelines, and responsible use of taxpayer dollars.

6. Where are we falling behind?

This is the question that separates a basic IT vendor from a real partner.

You need someone who can look at your organization and say, here is what is changing, here is what matters, and here is what we recommend next.

Ask:

Are there tools or automations we should consider?

Are we behind on security best practices?

Are similar public agencies doing something we are not?

Have cyber threats changed in a way that affects us?

Are we using our current systems as well as we could?

Are there Microsoft 365 features we already pay for but are not using well?

Are our departments sharing information securely and efficiently?

Technology moves fast. Cybercriminals move faster. Your IT provider should help you keep up without burying you in technical talk.

That does not mean chasing every new tool. It means making practical decisions that protect citizen data, support staff, reduce risk, and keep public services available.

If these conversations are not happening, that is a red flag.

If your IT provider cannot answer these questions clearly, or if they are not asking to meet with you quarterly, you may not be getting the support your organization needs.

You need more than someone who shows up after something breaks.

You need a partner who helps prevent the break in the first place.

At Tigerhawk, we believe public sector leaders deserve clear answers, practical planning, and local support that understands how government operations actually work. IT should protect your organization, support your team, preserve public trust, and help you make better decisions with the resources you have.

If you want a second set of eyes on your current setup, we can help.

For more information, schedule time with Tigerhawk.