Help centre
Frequently asked questions Page 2 of 10
Practical answers for assessing IT services, scope, security and operations.
Questions 101–200 / 996
Frequently asked questions — page 2
-
What installation height do you recommend for good detail and reduced risk of tampering?
The height is adjusted to the objective: a balance is typically sought between facial detail and area coverage, taking into account framing and the height of the surroundings. The design should validate the actual field of view, not just the theoretical height. -
What legal requirements must I comply with if the installation may record areas near third parties?
You must apply privacy principles: inform through signage where applicable, limit the field of view to minimize unnecessary recording, and define a retention policy suited to the purpose. It is advisable to document the compliance approach. -
What’s the difference between installing an IP, analog and hybrid video surveillance system?
IP systems typically use network connections and support modern features like centralised management and easier remote access. Analog systems rely on DVRs and traditional cabling, while hybrid systems combine both to support upgrades without replacing everything at once. -
Do I need an NVR or DVR for my cameras, and how do I connect them?
Yes, you usually need a recording device: NVR for IP cameras and DVR for analog cameras. The connection flow is camera power/data to the recorder, then viewing via TV, web or mobile apps. -
Is wireless video surveillance truly easier to install, and what power options does it require?
Wireless can reduce drilling, but it still needs careful placement to maintain stable signal quality. Power may be battery-based or hardwired, and you must plan for charging or reliable power delivery. -
When should I hire a professional installer for video surveillance systems?
Hire a professional when you need multi-site coverage, complex cabling routes, secure remote access, or a system that must be operational from day one. Professionals also help avoid coverage gaps and ensure correct configuration for recording and alerts. -
What monitoring options are available after installation (self-monitoring vs professional monitoring, alerts, remote access)?
You can self-monitor via mobile apps and notifications, or use professional monitoring for faster incident handling. Many systems support alerts for motion, events, and offline cameras, plus remote viewing for verification. -
What system is best for measuring PM1, and how is its performance validated during installation?
For PM1, a monitor with an appropriate size fraction and performance specifications aligned with the project objective is recommended. During installation, validation is carried out through commissioning tests, configuration verification, stability checks, and data quality controls in accordance with the QA/QC plan. -
Is it recommended to combine continuous monitoring with passive sampling during the initial phase?
Yes, this is usually an efficient strategy: continuous monitoring provides time series and alerts, while passive sampling helps characterize zones and prioritize points. The key is to define comparability criteria and a validation schedule so that results are interpretable. -
Which gaseous pollutants are typically included first, and in what cases are VOCs added?
CO, NOx, SO2, and O3 are frequently prioritized based on emission sources and applicable regulations. VOCs are added when the objective includes indoor air quality, odor control, or the assessment of compounds associated with processes, ventilation, or materials. -
How is quality assurance and quality control (QA/QC) organized, and how often are audits and calibrations performed?
It is organized in phases: requirements definition, initial calibrations, periodic verifications, audits, and data validation. The frequency depends on the sensor type, criticality of use, and the agreed plan, but a documented and traceable cycle must always be in place. -
What is needed to publish real-time data, such as an air quality index (AQI), with review and validation?
A data management platform is required, along with validation rules (cleaning, consistency, and quality control) and an AQI calculation model based on the available variables. In addition, alert thresholds and a review workflow are defined to ensure that the published data is reliable. -
What installation works are typically included in an air quality control system project?
Most projects include mechanical works (mounting and ducting), electrical works (power and cabling), ductwork components (including dampers where applicable), and controls/monitoring integration. A good proposal also lists commissioning and handover documentation. -
Do you provide commissioning and verification to confirm the system is installed correctly?
Yes—commissioning should include functional checks, performance verification against the agreed requirements, and evidence for acceptance. You should receive a documentation pack that supports ongoing operation and audits. -
Can you support regulatory compliance, including testing, reporting, and submissions?
Installation partners typically support compliance by aligning the system design with relevant standards, providing test evidence, and preparing the documentation required for reporting. Confirm the exact scope during planning. -
What maintenance and cleaning approach should be planned after installation?
Plan maintenance around filter/ductwork inspection, cleaning schedules, and responsibility split between your team and the installer. Installation should include labelling, access routes, and operational guidance to keep downtime low. -
Do you handle upgrades or retrofits of existing air pollution or air quality control equipment?
Many projects include retrofit planning: assessing existing ducting, power/network constraints, and integration points. A strong retrofit scope includes minimal disruption measures and a clear commissioning plan for the upgraded system. -
What’s the difference between access control software-only and a complete access control system with hardware and monitoring?
Software-only solutions manage permissions, but they still require door-side hardware (readers, controllers, locks) to enforce access. A complete system also includes integration, audit trails, and often monitoring and support to respond to incidents. -
Can access control be integrated with visitor management and time tracking?
Yes. A well-designed integration links visitor registration to temporary access credentials and connects staff access events to time and attendance workflows. This reduces manual checks and improves reporting accuracy. -
Do I need biometrics, or are smartcards sufficient for sensitive areas?
Smartcards can be sufficient for many areas, especially when combined with strong access policies and anti-tailgating controls. Biometrics are typically considered for higher-risk zones where identity assurance needs to be stronger. -
What options exist for temporary access for contractors, visitors, and events?
Temporary access is usually handled through time-bound permissions, visitor management integration, and automated revocation. You can also use mobile credentials or short-lived access codes depending on your security model. -
Do you offer remote management and ongoing support after installation?
Managed services typically include remote administration, proactive maintenance, and SLA-based support. This helps keep integrations stable and ensures faster assistance when operational issues arise. -
What support services does IT outsourcing in Madrid cover (users, incidents, networks, or software)?
It typically includes user support, incident management, access administration, and systems, network, and application tasks according to scope. The goal is to ensure daily operations do not depend on hiring additional staff. -
Can you cover sick leave and vacations without the company needing to hire additional staff?
Yes. The on-demand reinforcement model allows you to cover absences and demand peaks with technical profiles ready to integrate into your operations. This way you maintain continuity without growing your headcount. -
How do you guarantee fast response times in the Community of Madrid?
A scope with SLAs and an attention workflow (remote and, where applicable, on-site) is defined. In addition, operational capacity and experience in ticket management help respond with agility. -
Do you offer one-off collaboration models for projects as well as recurring support?
Yes. You can engage by days, weeks, or months for specific needs, or opt for a recurring team to stabilize operations. The choice depends on criticality, incident volume, and objectives. -
What does computer outsourcing typically include for Madrid businesses?
It usually covers endpoint support (PCs and laptops), helpdesk ticket handling, incident resolution and preventive maintenance. Depending on the agreement, it can also include software support and troubleshooting for related services. -
Do you offer on-site support, off-site support, or both?
Both are possible. On-site is used for desk-side hardware interventions, while off-site handles remote troubleshooting and ticket management. Many companies choose a hybrid model for balanced coverage. -
How quickly can you respond to incidents and how do SLAs work?
SLAs should define ticket intake, response and resolution targets, escalation rules and reporting cadence. A good provider will align targets to your business hours and incident severity levels. -
Can you manage both hardware and software issues for company PCs?
Yes, the scope commonly includes both hardware and software troubleshooting for endpoints. You should confirm what is covered for peripherals, OS issues, applications and user access problems. -
What information do you need from us to start an outsourcing onboarding?
You typically share an inventory of endpoints, current support processes, access requirements, documentation and key contacts. The provider then performs an assessment and defines the transition plan and acceptance criteria. -
What is the difference between IaaS, PaaS, and SaaS, and which is right for my company?
IaaS offers partially managed infrastructure; PaaS provides a platform for developing and deploying; SaaS delivers ready-to-use applications. The right fit depends on your team: if you want less management overhead, SaaS usually works best; if you need infrastructure control, IaaS or PaaS may be more suitable. -
What cloud services do I need if my priority is business continuity (backup and recovery)?
Look for a combination of Backup as a Service (BaaS) and Disaster Recovery as a Service (DRaaS), with restoration tests and defined RTO/RPO objectives. Complement this with monitoring and an incident response plan. -
Can I contract security and management for environments like Microsoft 365 without having an internal team?
Yes. You can outsource management with managed cloud services and operational security, including hardening, access control, monitoring, and response. The key is to define SLAs and the scope of support. -
How do you plan a phased cloud migration to minimize risks?
Start with a limited pilot, validate performance and security, define success criteria, and then scale in waves. Ensure interoperability, training, and a rollback plan to reduce impact. -
What should I review to control costs in cloud services (pay-per-use, scalability, and variable costs)?
Review consumption variables (storage, network, compute, licenses), define limits and alerts, and establish a forecasting model. Ensure scalability is governed to avoid spending spikes. -
What are the main types of cloud services businesses need to run operations end-to-end?
Most businesses need a mix of cloud storage, compute, business applications, and data/analytics. Integration services and identity/security controls are also essential to connect systems and protect users and data. -
How do I evaluate cloud security for sensitive and regulated business data?
Check security controls end-to-end: identity and access management, encryption, logging, vulnerability management, and backup/recovery. Confirm compliance alignment (e.g., GDPR) and review the provider’s operational security processes and incident handling. -
What hidden costs should SMBs watch for when migrating to cloud services?
Look beyond subscription fees: data transfer, storage growth, integration work, training, and ongoing support. Also estimate operational overhead for monitoring, patching, and recovery testing. -
How should we plan integration between legacy systems and cloud services?
Start with a dependency map and data-flow design, then choose integration patterns (APIs, connectors, or middleware). Plan phased migration to reduce risk, and define cutover criteria and rollback options. -
What should we include in a cloud cost estimate before choosing a provider?
Include expected usage (compute/storage), data transfer, backup and recovery requirements, support/SLA costs, and integration effort. Build a forecast that reflects growth and seasonal peaks, not just current workloads. -
What are the most cost-effective cloud backup options for automatic nightly copies?
They are usually those that combine real automation, flexible retention, and integrity verification. Compare total cost (storage, bandwidth, restoration, and support) and demand SLA and recovery tests. -
Can I easily recover and download my backups if I am out of the office?
Yes, if the service offers remote access with controlled permissions and a clear restoration/download flow. Ask for recovery times (RTO) and options for granular restoration. -
What should I consider to back up large video files (DV/ProRes) without driving up costs?
Evaluate size, change rate, and format compatibility, as well as retention policies and compression/deduplication if applicable. Ensure that the provider allows efficient restoration and tests with real data. -
How can I configure backups from external storage to the internet securely?
Define the source (folders/devices), enable encryption in transit and at rest, and configure overnight automation. Then validate with a restoration test and monitor failure alerts. -
How do I know if my backup can actually be restored and is not just 'being saved'?
Request evidence of periodic restoration tests and success metrics. A good service verifies integrity and allows granular restoration to confirm that the data is recoverable. -
What should I look for to ensure an online backup service has real versioning and restore protection?
Look for explicit retention/versioning terms (how many restore points and for how long) and confirm that restores can recover previous file states after deletion or corruption. Also check whether the service supports system-level recovery or only file-level recovery. -
Are “cheap” cloud storage plans suitable for offsite backup, or do I need dedicated backup features?
Cheap storage alone is usually not enough for reliable recovery because it may not include versioning, retention policies, or ransomware-resilient restore points. Dedicated backup features typically provide versioning, scheduling, and restore workflows. -
How do I compare affordability across services when pricing is per device, per account, or per terabyte?
Normalise the total cost for your endpoint count and expected retention period, then compare what is included (encryption, restore options, add-ons, and limits). Price-per-terabyte can mislead if retention is short or restores are restricted. -
Which online backup services are best for backing up multiple PCs and mobile devices under one account?
Choose services that support multi-device management under one admin console and clearly state device limits, mobile coverage, and retention behaviour. Confirm that all endpoints receive the same protection policy, not just “best effort” backups. -
How can I test that my backups will restore successfully before relying on them for business continuity?
Run a restore test that mirrors your real recovery needs: restore a sample of critical files and, if required, perform a system restore to a test environment. Document success criteria (time to restore, completeness, and usability) and repeat on a defined cadence. -
What security does cloud storage offer for businesses (encryption and authentication)?
Look for encryption in transit and at rest, as well as strong authentication like 2FA. Role-based access control and the ability to audit access and changes are also key. -
Can I access my files from web, mobile, and desktop without losing synchronization?
Most enterprise solutions offer multi-device access and synchronization. Check availability, performance, and how version conflicts between devices are managed. -
Does it include backup, recovery of deleted files, and version control?
It should include backups (ideally automatic and scheduled), recovery from deletions, and version control. The greater the granularity, the less work is lost during restoration. -
Can I share with password-protected and expiring links?
Yes, many platforms allow sharing with protected links and expiration dates. Also confirm permissions, revocation, and limits to reduce data exposure. -
How does storage scalability work when the company grows?
Scalability depends on the plan, the ability to expand space, and policy management. Assess user growth, data volume, and the impact on backups and restorations. -
Which cloud storage option is best for businesses that already use Microsoft 365?
Look for tight integration with Microsoft identity, SSO, and collaboration workflows. Prioritise permission controls, retention features, and compatibility with your existing governance model. -
How do I verify that a cloud storage provider supports compliance requirements like GDPR or ISO 27001?
Request current audit reports and security documentation, then map controls to your obligations (data processing, access, retention, and audit logs). Confirm how evidence is provided and how incidents are handled. -
What should I ask about encryption: at-rest/in-transit, key management, and access controls?
Ask what is encrypted, how keys are managed (including customer-managed options), and how access is enforced (MFA, least privilege, role-based permissions). Ensure audit trails cover access and sharing events. -
How can businesses reduce recovery time (RTO) and ensure data availability after deletion or outage?
Define RTO/RPO targets, confirm replication and recovery mechanisms, and require restore testing. Ensure soft delete/versioning and recovery windows match your operational needs. -
Do cloud storage services support real-time collaboration and team permissions for multiple users?
Most business-focused platforms support real-time editing and granular sharing controls. Validate permission models, external sharing rules, and how conflicts and version history are handled. -
What IT services do companies that hire IT outsourcing usually outsource first?
Typically, they start with technical support and help desk, and basic infrastructure management. Then it expands to security, cloud, preventive maintenance, and continuity based on maturity and criticality. -
How is the scope defined and who manages incidents?
The scope is defined by areas, systems, and service levels. The provider manages incidents with a support flow, escalations, and defined responsibilities, according to the agreed model. -
Does the provider include cybersecurity, backups, and disaster recovery?
This should be reflected in the contract: endpoint and network protection, backup policies, restoration tests, and recovery procedures. The important thing is to have evidence and periodic reviews. -
What hiring model exists: full outsourcing, phased, or partial support?
You can hire full outsourcing, phased (for example, first support and then infrastructure/security), or with partial support to the internal team. The key is to align responsibilities and SLAs from the start. -
How is service performance measured (SLA/response times and reporting)?
SLAs and OLAs are defined with response times, resolution, and availability. Additionally, KPIs and periodic reporting with trends, recurring incidents, and improvement actions are established. -
Which IT services are most suitable to outsource first for a growing business?
Start with functions that are repeatable and measurable, such as help desk, network management, and IT asset/account management. These typically deliver quick wins in response times, uptime and cost predictability. -
How do we reduce security risks when an outsourcing partner handles sensitive data?
Require documented data handling, access controls, audit rights and security SLAs. Align patching, vulnerability management, secure remote access and backup/compliance tooling with your risk profile. -
What should we define in advance to ensure outsourcing delivers expected outcomes?
Define goals, scope, responsibilities (RACI), escalation paths and service levels (SLAs). Agree on reporting cadence and the documentation needed for smooth operations and change management. -
When is it better to keep IT in-house instead of outsourcing?
Keep highly strategic or tightly regulated activities in-house if you cannot define clear responsibilities or if response needs are extremely bespoke. A hybrid model often works best. -
How can we avoid dependency on a single IT outsourcing vendor?
Use clear exit clauses, maintain operational documentation, and consider multi-vendor or phased transitions. Ensure knowledge transfer and keep critical processes and credentials governed. -
What storage destinations are compatible for Remote Backups (S3, Wasabi, Dropbox, Google Drive, SFTP)?
In general, you can use cloud destinations like S3 and Wasabi, services like Dropbox and Google Drive, and also off-site repositories via SFTP. The exact compatibility depends on the backup tool and the connection method. -
How are exclusions configured to avoid backing up directories like logs or tmp?
Rules are defined by paths and patterns (for example, log folders, temporary or cache folders) to reduce size and transfer time. The important thing is to validate that the exclusions do not affect necessary data for restoration. -
What is the difference between restoring from a file manager type panel and restoring via SFTP/SSH?
The panel method is usually faster for small and operational restorations. SFTP/SSH is useful for larger volumes or more controlled restorations, but it requires extraction and management of the recovery flow. -
Do Remote Backups allow restoring folder permissions (for example, NTFS permissions)?
It depends on the solution and the type of backup. In enterprise approaches, it is possible to preserve metadata and permissions (including NTFS permissions) so that the restoration is functional, not just 'copy files'. -
How is the risk of ransomware mitigated in a Remote Backup strategy with snapshots?
It is mitigated by combining off-site copies, version control, and snapshots with history. Additionally, access is reinforced with encryption and authentication, and integrity is validated to detect corruption or malicious encryption. -
Should I use managed remote backup storage or self-hosted remote backup software?
Choose managed offsite storage when you want operational reliability, monitoring, and support included. Choose self-hosted software when you need deeper control over deployment and integration, but be prepared to run monitoring, updates, and restore testing. -
Do Remote Backups include client-side encryption so only I can access the data?
Not all solutions provide client-side encryption. Look for encryption where keys are controlled by you (or your organisation) and where the provider cannot decrypt backup contents by default. -
Can I restore to a specific point in time (versioning) and how does it work?
Yes, if the platform supports versioning and restore-to-point-in-time. You should verify retention windows, how incremental chains are rebuilt, and how quickly restores complete for your key workloads. -
What anti-ransomware options are available with Remote Backups?
Common options include immutable backups, separate retention for backup copies, and controls that prevent deletions from propagating. Confirm how immutability is enforced and whether it survives compromised credentials. -
How do Remote Backups handle geographic resilience and faster transfers over high-latency links?
Look for geo-replication across regions and transfer strategies such as seeding, scheduling, and edge transfer. Ask how the system behaves during network interruptions and how it prioritises critical data. -
What steps do you follow to plan a migration to cloud services in IT Consulting companies?
It starts with objectives and success criteria, evaluates the inventory (applications, data, identities, and networks), and defines the scope by waves. Then, the architecture, transition plan, and operational model are designed with security and continuity. -
How do you define the scope (what to move first) and how long does each phase take?
The scope is prioritized by criticality, dependencies, change windows, and risk. The time varies based on complexity but is usually structured into pilot, controlled migration, stabilization, and optimization with metrics for each phase. -
What success metrics do you recommend to justify the business case?
It is recommended to measure costs (TCO and variation), productivity (provisioning and resolution time), resilience (RTO/RPO), and availability. Service quality is also evaluated with operational and experience indicators. -
How do you manage security, operational continuity, and risks during the transition?
Change governance, hardening, identity control, and encryption are applied, along with backups and recovery tests. For risks, rollback plans and acceptance criteria are defined before moving to the next wave. -
What criteria do you use to select a cloud platform and implementation partner?
Fit with security requirements, continuity, compatibility with the existing stack, and operational capability are valued. Methodology, experience in phased migrations, and the support model with SLA are also important. -
What approach should we choose if we need both cost control and better agility?
Start with a workload-by-workload assessment and classify dependencies, risk, and time-to-value. Many organisations use lift-and-shift for low-risk workloads, then modernise the highest-impact services to improve agility without losing cost control. -
How do we measure migration success—what KPIs should be tracked from day one?
Define KPIs before migration: cost (unit economics and spend variance), performance (latency/throughput), security/compliance evidence, and continuity targets (RPO/RTO). Track them with a baseline, targets, and a reporting cadence that matches release phases. -
How can we migrate without unexpected costs (governance, IaC coverage, and optimisation)?
Use governance with cost guardrails, tagging standards, and infrastructure-as-code coverage to prevent configuration drift. Optimise after validation, not during firefighting, and enforce approval gates for scaling and new services. -
What security and compliance steps are typically required for SOC 2 during migration?
Align controls to your SOC 2 scope: encryption, access management, audit logging, change control, and evidence collection. Plan for audit readiness early so security controls are validated during build and migration, not after go-live. -
Can a migration partner reduce timelines and implementation effort compared with hiring internally?
A partner can accelerate delivery by bringing repeatable playbooks, governance templates, and operational readiness practices. The biggest gains come when the partner also provides managed services support to stabilise operations during and after the move. -
What IT services should I outsource first if I have a small internal team?
It usually starts with technical support, preventive maintenance, and management of basic infrastructure to stabilize operations. It is also common to delegate managed cybersecurity and backup to reduce risks without expanding the workforce. -
How do I calculate cost savings compared to hiring and training staff?
Compare total costs: salaries, recruitment, training, turnover, tools, licenses, and unproductive time. Add the impact of incidents and downtime to assess the return on managed service with SLA. -
What should I demand in security and compliance from the provider (networks, recovery, cybersecurity)?
Demand access policies, patch management, backups with restoration tests, monitoring, and incident response. Align the scope with compliance requirements and define evidence, reporting, and recovery times. -
What practical differences are there between onshore and nearshore for my project?
Onshore prioritises coordination and proximity; nearshore offers a balance between cost and effective communication. The choice depends on criticality, support windows, language, and the need for presence. -
How do I plan the transition to avoid interrupting operations or losing quality?
Define measurable goals, an inventory of systems, responsible parties, and a phased handover plan. Execute a pilot with acceptance criteria, establish SLAs from the start, and track incidents, changes, and quality. -
What does the Microsoft 365 service include?
It can include licences, Exchange, Teams, SharePoint, OneDrive, migration, security, identity and support. Components and support coverage are defined in the accepted proposal. -
Does Microsoft 365 back up my data?
Microsoft 365 includes availability, retention and recovery options that vary by service and configuration; Microsoft 365 Backup also provides configurable protection. The strategy should start from required RPO, RTO and restore scenarios and may add another backup where needed. -
Can you migrate our email without disrupting work?
We plan migration in phases to reduce disruption. The cutover window, risks, tests, acceptance criteria and rollback plan are agreed before the change. -
What does IT consulting do and what does it include?
We assess your current technology, identify risks and opportunities, and design a plan aligned with your business goals: infrastructure, security, cloud, processes and budget.
Let's talk
Still have a question?
Share the context and we will review the most suitable scope with you.