Your IT setup needs an annual review, not just attention when something breaks. An hour of honest assessment once a year can prevent problems that cost far more to fix than to find.
Your IT setup is not something you configure once and forget about. Businesses change, threats evolve, software gets updated and hardware ages. What worked perfectly a year ago may have gaps today that you do not know about until something goes wrong.
An annual IT review does not need to take long. An hour of honest assessment once a year can save your business from expensive surprises. Here is what to look at.
Are your backups actually working?
This is the most important question on the list and the one most businesses get wrong. Having a backup running is not the same as having a backup that works. When was the last time someone tested a restore? Do your backups cover your email, your cloud data and your local files? Are they stored somewhere that ransomware cannot reach?
If you cannot answer all of these with confidence, your backup strategy needs attention before anything else.
Is every account protected with multi-factor authentication?
MFA should be enabled on every business account, not just email. Microsoft 365, your accounting software, banking portals, cloud storage, remote access tools. Any account without MFA is an open door for an attacker who gets hold of the password.
Check whether any new accounts have been created during the year without MFA being set up. It is easy for this to slip through when onboarding new staff or adding new tools.
Are all your devices up to date?
Check that every laptop, desktop and phone used for work is running the latest operating system and has all security patches installed. Devices that are behind on updates are vulnerable to known exploits that attackers actively scan for.
This includes your router, your firewall and any other network equipment. Firmware updates for these devices are often overlooked but just as important.
Do you know who has access to what?
Review who has access to your business systems. Are there former employees or contractors who still have active accounts? Are there shared passwords that have not been changed in over a year? Does every staff member have the right level of access for their current role or do some people have admin rights they no longer need?
Access that is not actively managed accumulates risk over time. An annual review is the minimum frequency for cleaning this up.
Is your hardware still fit for purpose?
Check the age and condition of your devices. Laptops and desktops over four years old are approaching the end of their useful life. Devices that are out of warranty carry a higher risk of unexpected failure with no coverage for repair costs.
Look at whether any staff members are regularly complaining about slow machines. Performance problems that get worked around rather than fixed cost your business productivity every single day.
Are your software licences correct?
Review what software your business is paying for and whether it matches what you are actually using. Are there licences for staff who have left? Are you on the right Microsoft 365 plan for your current team size? Are there tools you signed up for and stopped using but are still being billed for?
Licence waste is one of the easiest costs to trim and most businesses find something when they look.
Is your internet setup resilient?
Does your business have a failover connection for when your primary internet goes down? Is your networking equipment on a UPS so it stays online during load shedding? Has your bandwidth kept up with your team's needs or are video calls and cloud apps slower than they should be?
If your entire business goes offline every time the fibre drops or the power goes out, that is a gap worth addressing.
Do you have a plan for when things go wrong?
Not a detailed disaster recovery document, just the basics. Does your team know who to call when something breaks? Do you have your IT provider's emergency contact number somewhere that does not require a working computer to access? Is there a documented process for what happens when a staff member leaves?
The businesses that handle incidents well are the ones that thought about them before they happened.
Are you meeting your POPIA obligations?
Review how your business handles personal information. Are client records stored securely? Is access to sensitive data restricted to the people who need it? Do you have a process for handling a data breach if one occurs? Has anything changed in the past year that affects your compliance?
POPIA is not a once-off exercise. It is an ongoing responsibility that should be reviewed at least annually.
The bottom line
None of these checks are complicated. Most business owners can work through this list in an hour and come away with a clear picture of where they stand and what needs attention. The cost of doing this review is negligible. The cost of skipping it and discovering problems the hard way is not.
At Recloud we conduct annual IT reviews for our managed clients as standard practice. If you would like a professional assessment of where your business stands, get in touch and we will walk through it with you.