5 Things Your IT Setup Is Probably Getting Wrong (And How to Check Each One in 15 Minutes)

Table of Contents

Most IT problems don’t start with dramatic failures or headline‑grabbing cyberattacks. They usually begin with small assumptions: something that was meant to be temporary, a task everyone thought someone else had handled, or a system that’s been “working fine” for years.

This article isn’t about worst‑case scenarios or technical deep dives. It’s about the everyday oversights we encounter when reviewing real-world business IT environments. Each section includes a simple sense‑check you can do yourself. No technical background required. If nothing else, it should help you ask better questions before small issues turn into expensive ones.

Former Staff Still Have Access (A Common IT Security Risk)

Why it Matters.

When someone leaves, most businesses disable their email and move on. But access rarely ends there. Shared folders, cloud systems, historical links, and third‑party tools are often overlooked, not through negligence, but because they’re easy to forget.

Quick self‑check

Could you confidently explain what happens to someone’s access on their last day? Not just email, but files, shared drives, systems, and cloud services.

If your answer includes phrases like “usually”, “I think”, or “IT handles that”, it’s worth digging deeper.

What good looks like

A clear, repeatable leavers process that’s followed every time. Access is removed on the day someone leaves, shared links are reviewed or time‑limited, and responsibility for the process is clearly defined.

Early warning signs checklist

  • Reliance on memory rather than process
  • No record of who had access to what
  • Shared links with no expiry date

 

Multi‑Factor Authentication Isn’t Fully Switched On

Why it Matters.

Passwords alone no longer provide meaningful protection. Most account compromises don’t involve advanced techniques; they rely on phishing emails, reused passwords, or leaked credentials.

Independent research from Microsoft Research found that enabling multi‑factor authentication reduces the likelihood of account compromise by more than 99% compared to password‑only access, making it one of the most effective security measures available

Quick self‑check

Do all users, including directors and senior staff, use a second verification step when signing in? Are there any long‑standing “temporary” exemptions still in place?

If you’re not sure, that uncertainty is important.

What good looks like

MFA is enabled for everyone, without exception. Sign‑ins from new devices or unusual locations require confirmation, and security settings are reviewed periodically rather than forgotten once configured.

Early warning signs checklist

  • “We’ll roll MFA out properly later”
  • MFA is enabled for staff but not leadership
  • Security decisions delayed for convenience

 

Business Data Is Sitting on Personal Devices

Why it Matters.

Work no longer happens neatly within office walls. Files move across laptops, mobiles, tablets, and home computers. Without clear controls, company data often ends up stored on personal devices that the business can’t protect or manage.

In the UK, the Information Commissioner’s Office (ICO) notes that many reportable data breaches arise from loss, misdirection, or unauthorised access rather than targeted attacks, including lost or unsecured devices

Quick self‑check

If an employee lost their phone today, could you remove company access without touching their personal data? And do staff know what’s allowed when it comes to storing or sharing business files?.

What good looks like

Business data is clearly separated from personal use. Access can be removed remotely if required, without affecting private apps or photos. Expectations are documented, understood, and technically enforced.

Early warning signs checklist

  • Policies based entirely on trust
  • No visibility of where the company data is stored
  • Personal devices accessing sensitive systems with no controls

 

Backups Exist… But No One Has Tested Them

Why it Matters.

Most organisations believe they’re backed up. Fewer have actually tested what restoring that data looks like under pressure. Backups can run and fail silently for months without anyone noticing.

Quick self‑check

When was the last successful restore test? Not confirmation that a backup was completed, but proof that data was restored and usable.

If the answer is “we’ve never needed to”, that’s a gap worth addressing.

What good looks like

Regular restore testing, clear ownership of the process, and documentation that explains what happens if something needs to be recovered quickly.

Early warning signs checklist

  • Confidence based on assumptions
  • Reliance on a single person who “knows how it works”
  • No record of restore tests

 

Too Many People Can Make Big Security Changes

Why it Matters.

Administrative access allows changes that affect security, systems, and data. Over time, these permissions tend to spread, often for convenience, until many more people have full control than necessary.

Most problems here aren’t malicious. They’re accidental.

Quick self‑check

How many people have full administrative access to your systems? And do they need that level of access permanently, or only occasionally?

If you don’t know the answer straight away, that’s telling.

What good looks like

A small number of administrators, with elevated access granted only when required. Changes are deliberate, logged, and reversible.

Early warning signs checklist

  • “Everyone in IT has full access, just in case”
  • Admin rights granted permanently for convenience
  • No regular review of permissions

 

What This Article Is, and Isn’t

This isn’t a technical audit, and it’s not designed to replace one. It’s a practical sense‑check that highlights areas where uncertainty often hides bigger risks.

If any section made you pause or feel unsure, that’s useful insight. IT problems rarely arrive without warning; they usually start as unanswered questions.

Good IT Starts With Better Questions

The most effective IT environments aren’t built on complex tools or expensive systems. They’re built on clarity: clear responsibilities, clear processes, and a clear understanding of what’s really happening behind the scenes.

Addressing small gaps early is far less disruptive than dealing with incidents later. Sometimes, knowing what to ask is the most valuable first step.

If you’d like a second pair of eyes on any of this, an independent review can often spot issues before they turn into problems. Reach out to us for a no-obligation chat.

Simon

LinkedIn
Facebook
X

Enjoyed This Article?

Discover more articles to keep your business ahead of the curve
Chichester