Smaller companies rarely need enterprise complexity, but they do need clear ownership and a few dependable controls. These are the gaps I find most often.
- No tested recovery: a backup exists, but nobody has restored from it.
- Shared administrator accounts: nobody can prove who changed what.
- Incomplete offboarding: former staff retain access to email, files or cloud tools.
- Unmanaged Microsoft 365: security defaults, MFA and recovery methods are inconsistent.
- One-person knowledge: critical credentials and configurations exist only in someone’s memory.
- Consumer-grade network design: business, guest and device traffic share the same trust boundary.
- No incident plan: staff do not know who to call or what to disconnect during an attack.
A practical first step
Create a one-page inventory: systems, owners, administrators, backups and recovery contacts. Then test one important restore and one employee offboarding. These two exercises reveal more than a long policy document.
Remote assessment
Most of this review can be completed securely and remotely. The objective is a prioritized plan in plain language—not a catalogue of products.
Want a practical IT health review?
Get a prioritized view of the risks that matter to your business.
Request a remote review →