In this exclusive CanadianSME Small Business Magazine interview, Shawn Bedard, President & Founder of JIG Technologies, shares insights from more than 25 years of helping organizations turn complex technology into practical business solutions. A University of Waterloo engineering graduate, Shawn founded JIG Technologies in 2001 after gaining experience with organizations including CIBC, Sun Life, and IBM.
Today, JIG Technologies helps small and mid-sized businesses, nonprofits, and healthcare organizations strengthen their IT strategy, cybersecurity, and technology infrastructure. A strong advocate for putting business objectives before technology, Shawn helps leaders make smarter decisions around IT and AI while also mentoring entrepreneurs through Entrepreneurs’ Organization Toronto.
How can a business owner tell if their IT provider is genuinely doing a good job—not just closing support tickets?
While responding to and resolving tickets is an important measure, a business owner should look beyond how quickly tickets are closed. The focus should be on whether IT is becoming more reliable, secure and aligned with the business over time.
A strong IT provider should be reducing recurring problems, identifying risks before they become incidents, maintaining accurate documentation, planning for aging systems, testing backups, and providing a clear technology roadmap. Support should feel increasingly proactive, not like an endless cycle of fixing the same issues.
Good providers should also understand where the organization is going and communicate clearly with leadership. Leaders should receive explanations of risks, priorities and upcoming investments in business language, with enough context to understand why something matters and what outcome is expected. Technology recommendations should connect to business goals, not exist in isolation.
A warning sign is when the relationship is almost entirely ticket-driven, recurring issues remain unresolved, surprises are common, or leadership has little visibility into risks and future needs.
Ultimately, good IT support should create confidence that someone is actively looking after the technology environment—not simply waiting for the next problem to occur.
When an IT provider gives a long list of recommendations, how should a business decide what is urgent and what can wait?
When an IT provider gives a long list of recommendations, good advice should already come with clear prioritization.
A strong provider should distinguish between immediate risks, items that should be planned and budgeted for, and improvements that would be beneficial but are not urgent. Recommendations should be tied to business impact, security risk, compliance requirements, system reliability, and the organization’s goals—not simply presented as a technical wish list.
The timing should also make sense. Some items may need attention immediately, while others belong in a 12-, 24-, or even 36-month roadmap. Costs, dependencies and trade-offs should be clear enough that leadership can make informed decisions.
A warning sign is when everything is presented as critical, recommendations continually appear without a broader plan, or the provider cannot clearly connect the investment to a business outcome or meaningful reduction in risk.
Ultimately, a good IT provider should help leadership turn technology needs into a practical, prioritized roadmap—not overwhelm them with a list of things to buy.
How can leaders know their backups will actually work when a cyberattack, system failure, or disaster happens?
The most important answer is simple: test them.
Seeing a dashboard that says “backup successful” does not prove that the organization can actually recover. A successful restore test does. Leaders should know when the last restore test was performed, what was restored, whether it was successful and how long recovery took.
It is also important to understand what is actually being backed up. Is it a complete system that can be restored, or only selected files and data? Business owners often assume everything important is protected when, in reality, critical systems or information may have been overlooked.
Backup resilience matters as well. An on-site copy can provide faster recovery, while at least one protected off-site copy should be isolated from the production environment so the same ransomware attack or disaster cannot affect both.
Finally, leaders should understand the backup frequency and be comfortable with how much data could be lost between backups.
The goal is not to understand every technical detail. It is to have evidence that the organization can recover within a timeframe—and with an acceptable amount of data loss—that the business can live with.
Cybersecurity can feel like a bottomless expense. What does “good enough” protection look like for a small or midsized business?
“Good enough” does not mean eliminating all risk. That is neither realistic nor affordable. It means reducing the most significant risks to a level the business understands and accepts.
For most small and midsized organizations, I would start with strong fundamentals: multifactor authentication, timely patching, endpoint protection, secure backups, limited administrative access, employee security awareness, email protection and a documented incident response plan.
From there, security investments should be based on the organization’s actual risk. A healthcare organization holding sensitive personal information may need significantly stronger controls than a small business with limited confidential data.
The important part is having a framework rather than continually buying the newest security product.
Leadership should be able to answer: What are our biggest risks? Which controls reduce them? What gaps remain? And have we consciously accepted those gaps?
Cybersecurity spending becomes much easier to manage when it is connected to risk and business impact rather than fear.
How can a business tell whether its IT provider is recommending something because it is genuinely needed rather than because the provider profits from selling it?
This is a fair question, and every IT provider should be able to explain the value of a recommendation in terms that make sense to the business.
To get past the technical jargon, ask questions such as: What problem does this solve? What risk does it reduce? What happens if we do nothing? Are there less expensive alternatives?
Providers should also be transparent about where financial incentives exist. It is reasonable for an IT company to earn a margin on the products and services it provides, but clients should understand how recommendations are being made.
One of the best indicators of a trusted advisor is a willingness to sometimes recommend a less expensive option—or even recommend doing nothing when an investment is not yet necessary.
Trust develops when recommendations consistently reflect the client’s needs, budget and objectives rather than maximizing technology spend. If a provider cannot clearly explain why something is needed and how it provides value to the business, leadership should feel comfortable challenging the recommendation.
How can a nontechnical business leader effectively oversee IT without becoming an IT expert?
You do not need to become an IT expert any more than a business owner needs to become an accountant to oversee finance.
The starting point is being clear about the business strategy and communicating it to your IT provider. Leaders should be asking questions such as: Where are we trying to grow? What processes are holding us back? Where do we need greater efficiency? What risks could significantly disrupt the business? And what capabilities will our people need over the next few years?
From there, the technology questions become much easier: How is technology supporting those objectives? What are our biggest technology risks? What investments will we need over the next 12 to 24 months?
I also recommend maintaining a simple technology roadmap showing major risks, upcoming projects, expected costs and priorities.
A good IT advisor should translate technology into business impact. If overseeing IT requires you to understand every technical detail yourself, the relationship is not working properly.
If a business is unhappy with its IT provider, what should it know before deciding to switch?
Usually, the first step before switching is to be clear with the current provider about what is not working. It may be a misunderstanding around expectations or service needs. However, if it is clear the provider is no longer a good fit, changing IT providers should not be frightening when properly managed.
Start by reviewing the existing contract and understanding the termination terms. Also determine who owns and controls critical technology assets such as domains, Microsoft 365 accounts, administrative credentials, software licences, network equipment, backups, internet services, cloud systems and documentation. These should ultimately remain under the organization’s control.
The incoming provider should create a transition plan that covers documentation and credentials, security, backups, systems, immediate risks and knowledge transfer.
Where possible, avoid cancelling the existing provider too early and allow a short overlap between providers.
Most importantly, do not remain in a poor relationship simply because switching feels risky. A well-managed transition is less risky than continuing with a provider you no longer trust.
Good providers should make both onboarding and offboarding professional and orderly.
Disclaimer:
The views and opinions expressed in this interview are those of the interviewee and do not necessarily reflect the official policy or position of CanadianSME Small Business Magazine. Our platform is dedicated to fostering dialogue and sharing insights that inspire and empower small and medium-sized businesses across Canada.

