Emergency Call Protocol for IT Companies
When an “IT emergency” call comes in, you need to make a fast, repeatable decision: is this truly urgent, who owns it, and what’s the next action in the next 5–15 minutes. This protocol gives you a clear definition of an IT emergency, a triage decision tree, after-hours handling, dispatch steps, scripts, pricing, documentation, and ways to prevent “everything is urgent” callers from burning your team out.
1) What Counts as an IT Emergency (and What Doesn’t)
Key takeaway: Treat it as an emergency only when operations stop, security is actively threatened, or data loss is happening right now.
2) Triage Decision Tree (5-Minute Intake You Can Run on Every Call)
Key takeaway: A consistent 5-minute triage prevents panic decisions and gets the right tech on the right problem fast.
3) After-Hours Emergency Response (Nights, Weekends, Patch Nights)
Key takeaway: After-hours success is fast callback + immediate remote triage, with a clear escalation path when remote fixes aren’t enough.
4) Dispatch Procedures (Remote First, On-Site When It’s Truly Needed)
Key takeaway: Start remote to stabilize fast, then send the right specialist on-site only when physical access is truly required.
5) Communicating Wait Times (Scripts That Reduce Panic and Repeat Calls)
Key takeaway: A calm script with exact time commitments and clear next steps prevents churn and stops callers from shopping around mid-incident.
6) Emergency Pricing (Clear Rates, No Surprises, Still Profitable)
Key takeaway: Simple emergency rates + minimums protect your calendar and profit while staying fair during high-stress outages.
7) Documenting Emergencies (So You Can Bill Correctly and Prevent Repeat Outages)
Key takeaway: Good emergency notes let you bill confidently, prove value, and reduce the chance the same outage happens again.
8) Preventing False Emergencies (Reduce Noise Without Missing Real Crises)
Key takeaway: A few simple scope questions and clear rules cut “fake emergencies” while keeping you responsive to real outages.
Step-by-Step Process
Answer + tag the call
Classify the call immediately as: Emergency, Urgent, or Scheduled. Capture company name, site address (if relevant), best callback number, and the on-site contact.
Run the 5-minute triage
Ask scope, what system is down, and whether there are security signs. Write the caller’s exact words (they help later with billing and incident reports).
Decide: remote-first vs dispatch
Start remote triage for almost everything. Dispatch on-site only for power/hardware/ISP handoff issues or when no one can follow remote steps.
Confirm emergency pricing + approval
State the rate and minimum clearly (especially after-hours). Get a clear “yes” from an authorized person before you start billable emergency work.
Alert the right on-call tech
Route network outages to a network engineer, server crashes to a systems engineer, and security events to your security lead. Include all triage notes so they don’t re-ask the same questions.
Stabilize first, then fix
Your first goal is to restore operations: bring WAN up, fail over, restore a service, or isolate infected machines. Permanent fixes and cleanup come after the fire is out.
Send timed updates
During active incidents, send a short update every 30–60 minutes: what’s confirmed, what’s being done, and the next update time. This reduces repeat calls and panic.
Close the loop with a post-incident summary
Document timeline, root cause, and prevention steps. Offer a scheduled project if needed (backup redesign, firewall replacement, security audit).
Pro Tips
- 1.Keep a printed “Core Services Check” in your go-bag: ISP status, firewall uptime, DNS/DHCP, AD login, M365 status, VPN tunnels, storage capacity, backups.
- 2.Create three ticket templates in your PSA: Network Down, Server Down, Security Incident—each with required fields so techs don’t miss key evidence.
- 3.For ransomware-suspected calls, your first action is containment: isolate the endpoint/VLAN, disable suspicious accounts, and preserve logs before cleanup.
- 4.Set one public promise: “Emergency callback within 10 minutes.” If you can’t staff that, use a 24/7 answering workflow to capture details and route instantly.
- 5.Add a “recent changes” question to every intake: patching, firewall rule changes, new switch/AP, password policy/MFA changes—most emergencies correlate with changes.
Frequently Asked Questions
What’s the difference between “urgent” and “emergency” for IT support?
Emergency means business-down, active security risk, or ongoing/likely data loss. Urgent means important but limited scope (one user, one device) or there’s a workable workaround until business hours.
Should you always dispatch on-site for a server or network outage?
No. Start remote first to confirm what’s actually down (ISP vs firewall vs DNS vs a single switch). Dispatch on-site when hardware/power/ISP handoff requires hands or remote steps aren’t possible.
How do you handle callers who refuse emergency pricing?
Stay calm and give two options: after-hours emergency at the emergency rate, or schedule the first available business-hours slot at the normal $100–$200/hour rate. Document their choice in the ticket.
What questions catch most “false emergencies” fast?
Ask: “How many users are affected?” and “What system is down?” Then ask: “Can anyone else log in/send email/take payments?” If it’s one person and others work, it’s usually not an emergency.
What should you do first if ransomware is suspected?
Containment before cleanup: isolate the affected machine/network segment, disable suspicious accounts, block outbound traffic if needed, and preserve logs/screenshots. Then start incident response triage and confirm backups/restore options.
How do you keep from missing after-hours emergency calls when you’re already on another job?
Use an on-call rotation with a 10-minute callback standard and a clear escalation list. If you can’t answer phones consistently, use a 24/7 answering layer that collects triage info and instantly routes emergencies to the on-call tech.
Stop losing IT emergency calls when you’re busy in a server room
If you run an IT support company or MSP, missed “network down” and “we got hacked” calls go to the next provider fast. Use a 24/7 AI receptionist like SkipCalls to capture the right triage details, filter spam, and route true emergencies to your on-call tech—so you respond first and win the job.
More Resources for IT Companies
After-Hours Guide
Handle calls outside business hours effectively
Business Hours Optimization
Optimize when and how you answer calls
Call Handling Best Practices
Handle every call like a pro from ring to close
Client Retention Scripts
Keep customers coming back with follow-up calls
Communication Checklists
Step-by-step customer communication guides
Complaint Handling Scripts
Turn complaints into loyalty with the right words
Lead Response Templates
Follow-up templates that close more jobs
Missed Call Cost Analysis
Calculate the real cost of every missed call
No-Show Follow-Up Templates
Recover missed appointments professionally
Customer Onboarding Checklist
Step-by-step new customer onboarding process
Phone Etiquette
Make great first impressions on every call
Phone Scripts
Ready-to-use call scripts for every scenario
Phone Setup Guide
Configure your business phone system right
Pricing Inquiry Scripts
Handle price questions without losing leads
Review & Referral Scripts
Get more 5-star reviews and referrals
Scheduling Tips
Smart appointment scheduling strategies
Seasonal Call Guide
Plan for peak and slow call seasons
Upselling & Cross-Selling Guide
Increase revenue naturally during service calls
Voicemail Greetings
Professional voicemail scripts that set expectations