The IT Jobs Small Businesses Forget Until Something Breaks

The IT Jobs Small Businesses Forget Until Something Breaks

Most IT problems in small businesses aren’t dramatic. They’re the result of something ordinary that nobody got round to.

A backup that ran for two years and turned out not to be restorable. A domain name that expired because the renewal went to someone who left. An account belonging to a departed employee that stayed active for eighteen months.

None of these are technically difficult to prevent. They get missed because they’re nobody’s specific job, they’re invisible when they’re working, and they only announce themselves at the worst possible moment.

Here are twelve worth checking, whether you have an IT provider or not.

1. Backups Nobody Has Ever Tested

A backup that runs successfully is not the same as a backup you can restore from. Files can be silently excluded, permissions can break, and backup jobs can report success while capturing nothing useful.

The check: pick a file, ask for it to be restored, and time how long it takes. If nobody can do that quickly and confidently, you don’t currently have a backup you can rely on, you have a backup you hope works.

Worth doing at least annually. A full restore test is better still.

2. Domain Name and SSL Certificate Renewals

Domains and certificates expire. When a domain lapses, your website and email stop, sometimes for days while it’s recovered. When an SSL certificate lapses, visitors see a browser security warning telling them your site isn’t safe.

Both are entirely preventable, and both happen regularly, usually because the renewal notice goes to an old email address or an individual who has left.

The check: know your domain expiry date, know which account controls it, and make sure the contact address is a role-based address that outlives any individual, not someone’s personal inbox.

3. Accounts Belonging to People Who Left

This is the most common finding in almost any audit. Disabling someone’s email is the obvious step, but people accumulate access to far more than email: cloud services, shared drives, VPN, third-party platforms, admin panels.

Offboarding is usually done in a hurry, and the things nobody remembers are the things nobody documented.

The check: list your systems, then list everyone with access to each. If any name on those lists no longer works for you, that’s your answer.

4. Software Past Its End of Support

Operating systems and applications eventually stop receiving security updates. They keep working, which is exactly why they get overlooked. A machine that runs fine feels like a machine that’s fine.

Unsupported software doesn’t get patched when a vulnerability is found, so the risk increases steadily over time rather than appearing suddenly.

The check: know what operating system versions you’re running and whether they’re still supported. Include phones and tablets used for work email, which are frequently forgotten.

5. Everyone Being an Administrator

Local administrator rights get granted for a genuine reason, someone needed to install something, and then they stay. Over time, most people end up with more access than their job requires.

It’s convenient, and it means any malware that runs on a machine inherits those same rights.

The check: how many of your staff can install software on their own machine? If the answer is most of them, that’s worth revisiting.

6. Shared Logins

A single login used by several people appears in nearly every small business, usually for a system that charges per user, or a shared mailbox, or something set up years ago.

The problem isn’t only security. It’s that you lose any ability to know who did what, and when someone leaves, the credential has to be changed and redistributed to everyone, which usually means it isn’t.

The check: identify any credential more than one person knows. Each one is a small ongoing liability.

7. Multi-Factor Authentication That Isn’t On Everything

Most businesses have enabled MFA somewhere by now, commonly on email. Fewer have it consistently across every system holding company data.

Attackers go where MFA isn’t. A protected email account is worth much less if the same password also opens an unprotected system containing the same information.

The check: list every system with company data in it, then confirm which have MFA enforced. Look particularly at admin accounts, which are the highest value and sometimes the least protected.

8. Router and Firewall Firmware

Network hardware runs software that needs updating like anything else, and it rarely gets it. Many small businesses have never updated their router firmware, and a meaningful number still have the default administrator password.

This is the device sitting between your business and the internet, so it’s a poor place to leave defaults in place.

The check: confirm the admin password has been changed from the factory default, and that firmware has been updated within the last year.

9. Email Authentication

SPF, DKIM and DMARC are DNS records that tell receiving mail servers your email is legitimate. Without them properly configured, two things happen: your genuine email is more likely to be filtered as spam, and it’s easier for someone to send email that appears to come from your domain.

The failure mode is quiet. Nobody tells you your emails are landing in junk. You just get fewer replies.

The check: if you send meaningful volumes of email, particularly outbound sales or recruitment email, this is worth verifying properly. Free online tools will show whether the records exist, though interpreting whether they’re correctly configured takes a bit more.

10. Subscriptions and Licences Nobody Tracks

Software subscriptions auto-renew, often annually, often to a card belonging to whoever set them up. Businesses commonly pay for licences for people who left, tools nobody uses, and duplicate products doing the same job.

The reverse also happens: a licence lapses unnoticed and something stops working.

The check: an annual list of every software subscription, what it costs, who uses it, and when it renews. This one frequently pays for itself.

11. Old Devices Still Holding Data

Laptops and phones get replaced, and the old ones go in a drawer. They still contain company data, and unless they were properly wiped, that data is still recoverable.

The same applies to devices being sold, donated, or given to staff personally.

The check: know where your retired devices are and whether they were securely wiped. If a device has genuinely gone missing, treat that as a potential data incident rather than an inventory problem.

12. Everything Living in One Person’s Head

In most small businesses, one person knows how things are set up. Where the backups go, which account controls the domain, who the internet provider is, what the admin password is.

That works until they’re on holiday, off sick, or leave.

The check: if the person who knows your IT best was unreachable for two weeks, could someone else find the essential information? If not, writing it down is a genuinely valuable afternoon’s work.

The Pattern Worth Noticing

Almost everything on this list shares a shape. It’s invisible while it’s working, it’s nobody’s specific responsibility, and it only becomes urgent once it’s already a problem.

That’s the real argument for having someone whose job includes checking these things routinely, whether that’s an internal person with the time to do it or an external provider. Not because any single item is difficult, but because in a busy business, tasks with no deadline and no owner reliably don’t happen.

If you work through this list and find several gaps, that’s normal. Most businesses do.

Getting Help

CCSW provides IT support to businesses across Cardiff and South Wales, including the routine maintenance that keeps this kind of thing from accumulating. If you’d like a conversation about your setup, get in touch or call 0333 014 4544.