Close-up of a digital checklist being marked off on a tablet with a stylus pen.

Small Business IT Checklist: 12 Things to Review Before Something Breaks

Technology problems rarely begin when something finally stops working.

The warning signs often appear much earlier: an account nobody remembers creating, a backup that has never been tested, an employee who still has access after leaving or a server that everyone depends on but nobody fully understands.

Small businesses do not necessarily need an enormous IT department or an expensive collection of enterprise tools. They need clear ownership, sensible protections and a plan for handling problems before those problems interrupt the business.

This checklist will help you find the areas that deserve attention.

1. Identify who controls your important accounts

Make a list of the accounts your organization depends on, including:

  • Domain registrations
  • Website hosting
  • Business email
  • Microsoft 365 or Google Workspace
  • Accounting and payroll platforms
  • E-commerce accounts
  • Payment processors
  • Inventory and order-management systems
  • Social media and advertising accounts
  • Cloud storage and backup services

For each one, determine who owns the account, which email address receives recovery messages, who has access to 2FA (two factor authentication) and whether the business can access it without relying on a former employee or outside vendor.

Your organization should maintain control of its own accounts, even when another company manages them for you.

2. Review administrative access

Most employees do not need administrator access to every system.

Review who can:

  • Add or remove users
  • Change billing information
  • View financial or customer data
  • Install software
  • Modify security settings
  • Access backups
  • Change website or domain settings

Remove unnecessary permissions and establish at least one documented backup administrator for critical systems.

Shared administrator accounts should be replaced with individual accounts whenever the platform supports them. This creates clearer accountability and makes access easier to revoke.

3. Turn on multifactor authentication

Passwords alone are not enough for important business accounts.

Enable multifactor authentication for email, financial systems, remote access, cloud platforms, website administration and any account containing sensitive information.

Authenticator applications (authy, google authenticator, roboform, etc) or hardware security keys are generally stronger than text-message codes. However, using almost any form of multifactor authentication is better than relying on a password alone.

Recovery codes should be stored securely somewhere the business can access during an emergency.

4. Check whether backups are actually working

Having backup software installed does not guarantee that usable backups exist.

Verify:

  • What information is being backed up
  • How frequently backups run
  • Where the backup is stored
  • How long previous versions are retained
  • Whether failures generate notifications
  • Who reviews those notifications
  • How the data would be restored

At least one backup should be isolated from the primary computer, server or network. This helps protect it from hardware failure, theft, accidental deletion and ransomware. Make sure you keep at least one recent backup offsite.

Most importantly, test a restoration. A backup should not be considered reliable until you have successfully recovered something from it.

5. Establish an employee offboarding process

When an employee or contractor leaves, their access should be removed promptly and consistently.

A basic offboarding checklist might include:

  • Disable the user’s email account
  • Revoke active sessions
  • Reset shared credentials
  • Remove remote-access permissions
  • Recover company computers and mobile devices
  • Transfer ownership of important files
  • Redirect necessary email
  • Remove access to vendors and cloud platforms
  • Preserve required business records

Do not rely on someone remembering every system each time. Maintain a reusable checklist that can be followed even when a departure happens unexpectedly.

6. Keep computers and applications updated

Security patches and software updates address known problems that attackers and malware may exploit.

Review whether your organization has a consistent method for updating:

  • Windows and macOS
  • Web browsers
  • Microsoft Office and other productivity applications
  • Accounting and payroll software
  • Website platforms and plugins
  • Firewalls and network equipment
  • Servers and storage devices

Updates should be managed carefully, but repeatedly postponing them creates unnecessary risk.

Older computers and unsupported software should be identified so replacement or migration can be planned rather than handled during a crisis.

7. Review endpoint protection and monitoring

Every business computer should have active security protection that is centrally monitored whenever possible.

Confirm that:

  • Protection is running
  • Definitions and detection tools are current
  • Alerts are reviewed
  • Devices have not silently stopped reporting
  • Former computers have been removed
  • New computers are added during setup

Security software is most effective when someone is responsible for reviewing alerts and responding to suspicious activity. Installing it and forgetting about it is not a complete security plan.

8. Document your network and equipment

You do not need a complicated diagram, but you should know what equipment exists and what each device does.

Record important information about:

  • Internet providers and account numbers
  • Modems and firewalls
  • Wi-Fi access points
  • Managed switches
  • Servers
  • Network-attached storage devices
  • Battery backups
  • Security cameras
  • VoIP and telephone equipment
  • Printers and shared devices

Include model numbers, locations, purchase dates and administrative access information.

This documentation makes troubleshooting faster and reduces dependence on one person’s memory.

9. Identify the systems that would stop your business

Ask a simple question:

If this system stopped working tomorrow morning, what would our team be unable to do?

The answer may include email, internet access, payroll, order processing, inventory, shipping, phones, a shared drive, a website or an e-commerce marketplace.

For every critical system, identify:

  • Who supports it
  • How support is contacted
  • Where login information is stored
  • Whether data is backed up
  • How long the business could operate without it
  • Whether a temporary workaround exists

This creates the beginning of a practical continuity plan.

10. Review vendor responsibilities

Small businesses often depend on several vendors, but responsibility can become unclear when a problem involves more than one system.

For example, an email problem could involve the domain registrar, DNS provider, hosting company, email platform, security service or local network.

Document what each vendor manages and how to reach them. Keep contracts, account numbers and support details somewhere accessible to the business.

When possible, designate one person or technology partner to coordinate problems that cross between vendors.

11. Create sensible technology policies

Policies do not need to be lengthy or written like legal documents.

Begin with a few clear expectations covering:

  • Passwords and multifactor authentication
  • Use of company computers
  • Installation of unauthorized software
  • Storage of company information
  • Remote work and public Wi-Fi
  • Reporting suspicious messages
  • Use of personal email for business
  • Approval of new applications
  • Appropriate use of AI tools

Employees should understand both what the policy requires and why it matters.

Short, practical training is often more effective than sending employees a document they will never read.

12. Build a technology roadmap

Technology planning does not require predicting every future need. It means identifying likely expenses and improvements before they become emergencies.

Your roadmap might include:

  • Replacing aging computers
  • Upgrading network equipment
  • Improving wireless coverage
  • Moving away from unsupported software
  • Consolidating duplicate services
  • Improving backup protection
  • Rebuilding an outdated website
  • Connecting inventory and order systems
  • Introducing useful automation
  • Training employees to use AI responsibly
  • Preparing for business growth or an office move

Prioritize projects based on business impact, risk and cost. Not everything needs to happen immediately.

Start with what matters most

You do not have to correct every issue at once.

Begin with account ownership, administrative access, multifactor authentication and reliable backups. Those four areas can prevent many common problems from becoming serious business disruptions.

From there, document what you have and make improvements in a sensible order.

The goal is not to add more technology. It is to make the technology you already depend on more secure, understandable and reliable.

Not sure where to begin?

Info Hazard Solutions helps small businesses assess their technology, identify practical priorities and resolve the problems getting in the way of their work.

Whether you need ongoing support, a focused technical review or help with one persistent problem, we can start with the situation you have today.