Skip to main content
Cost & Provider Decisions7 min read

The IT health check: 10 questions every business owner should ask before year-end

"You review your finances, your team, and your sales pipeline at year-end. Your IT stack rarely gets the same treatment. These are the 10 questions that surface the problems before they become incidents - no technical knowledge required."

Author

Lior Refael

Published

Aug 15, 2026

Back to Articles

The review most businesses actually skip

Year-end is when business owners review everything: financials, team performance, sales pipeline, vendor contracts, strategic goals. One thing almost never gets the same treatment: the IT running underneath all of it.

That's not because IT is unimportant. It's because the questions feel like they need a technical person to answer them. They don't. The right questions are business questions, about cost, risk and readiness, and a non-technical owner can ask and understand every one of them.

A meaningful share of what small businesses spend on IT each year goes on tools nobody uses, security nobody configured, and backups nobody has tested. A 30-minute review once a year catches most of it.

These 10 questions are that review. Ask them of yourself, or ask them of whoever manages your IT. The answers tell you whether your setup is healthy, or quietly heading toward a problem. They are also the questions behind the baselines national authorities publish for small organisations - CISA's Cyber Essentials[1][2], the UK NCSC's small business guide[3], and for businesses operating in Israel, the INCD's organisational cyber defence methodology[4][5][6].

1. Is multi-factor authentication actually on every single account, or just the ones you remember?

This is the single most important question on the list. Microsoft's own research found MFA cuts the risk of account compromise by 99.22%, and by 98.56% even on accounts whose password had already leaked[7].

The question isn't "do we have MFA." It's "is it on every mailbox, every admin account, and every remote access path." One unsecured account is the gap an attacker walks through. Check the admin accounts specifically - they're the ones most commonly missed.

2. When did you last actually test a backup restore?

A backup you've never tested is not a backup. It's a hope. The only way to know a restore will work when you need it is to have already done it once when you didn't have to. Sophos' annual ransomware research is blunt about the consequence: recovery is what a tested backup buys, and paying is what an untested one costs[8].

Ask for the date of the last restore test. If the answer is "we haven't done one" or "we're not sure," that's the finding. A tested restore should happen at least quarterly. Anything less is a gap [your insurer may care about too](/articles/why-small-businesses-fail-cyber-insurance-assessment).

3. Do you actually know what every recurring IT charge on your card is for?

Most small businesses carry a handful of tools that are redundant, overlapping, or still billing for someone who left months ago. It is not a local problem: across more than 40 million licences under management, organisations leave an average of 36% of their SaaS licences unused[9].

Print the last three months of IT-related card and bank charges. Question every line. If nobody can explain what a tool does or who uses it, cancel it. In the audits we've run for clients, this typically saves €400-800 a month for a small business - money that goes straight to the bottom line.

4. If your most technically capable person left tomorrow, who actually has the passwords?

This is the bus-factor question. If one person holds the admin credentials for your domain, your email, your cloud accounts and your backup system, and those credentials live in their head or their personal password manager, that's a business risk, not an IT risk.

Every business should keep its admin credentials in a shared, company-owned password vault. Access is controlled, audited and transferable. No single person is the only one who can get you back in.

5. Are you actually paying for Microsoft 365 licences you're not using?

Microsoft's list prices for Business plans move periodically - Business Basic currently lists at $7 a user a month[10] - and licence drift, users sitting on a higher plan than they need, or former employees still licensed, is one of the most common wasted costs in small businesses.

Review the admin centre. Check: is every licensed user still at the company, is each person on the plan that matches what they actually do, and are unused add-ons still billing. A 10-person business can often save €50-150 a month just by cleaning this up.

6. When did someone last actually review who has access to what?

In many small businesses, everyone has access to everything: the HR folder, the finance folder, the client contracts folder, all open to all employees by default. That's convenient until it isn't.

Ask for a list of who has access to sensitive folders. If the answer is "everyone," that's a finding. Permissions should be role-based: finance sees finance, leadership sees strategy, new hires see what they need for their job. It's a couple of hours' work for a 10-person business, and it matters more than ever if you're considering AI tools like Copilot, which surface information based on whatever permissions already exist rather than a separate check of their own[11].

7. Do you actually have a written incident response plan, or do you improvise when something goes wrong?

When an incident happens, a phishing click, a lost laptop, a suspicious login, the time to figure out what to do is not during the incident. A written plan means anyone on the team can take the first step without waiting for the owner to decide.

It doesn't need to be elaborate. It needs to answer three questions: who do we call, what do we shut down, and how do we communicate. If that doesn't exist, it's a gap, and [insurers now ask about it too](/articles/why-small-businesses-fail-cyber-insurance-assessment).

8. Is every company device actually encrypted, updated, and remotely wipeable?

If a laptop is lost or stolen, can you wipe it remotely? "I think so" or "I'm not sure" is a finding. Microsoft Intune, included in Business Premium, is built to handle device compliance, encryption and update management across a fleet[12] - but only for devices that are actually enrolled.

Ask for a device inventory. If the list is incomplete, or devices aren't enrolled in management, that's the finding. A lost laptop with company email on it and no way to wipe it remotely is a data breach.

9. Are your employees actually trained, or was it a one-time video at onboarding?

Security awareness training that happens once, during onboarding, and never again doesn't hold up. Attackers change their methods; your team needs to encounter realistic phishing attempts often enough that spotting a fake becomes reflex rather than a guess.

Ask: when was the last phishing simulation, and what were the results. If the answer is "we don't do that," the team is your weakest control, and your strongest one if you train them. Regular training with simulation results is also something insurers increasingly want to see.

10. If you switched IT providers tomorrow, could you actually do it?

This is the question most owners don't want to ask. The answer tells you whether you're in control of your own IT or trapped by whoever currently runs it.

You should own your domain, your Microsoft 365 or Google Workspace tenant, and every business account, in your company's name, with admin credentials you can access. A provider administers these; they shouldn't own them. If your domain is registered in your provider's name, or your tenant is on their billing, that's a structural problem worth fixing before you ever need to switch. [We've written about exactly how to make that move without losing anything.](/articles/switching-it-providers-without-losing-data)

How to actually use this review

These questions aren't a pass/fail test. They're a map. Every "no" or "I'm not sure" is a finding, something to address before it becomes an incident, a denied insurance claim, or an unexpected cost.

The review takes 30 minutes if the answers are available. If they're not, that itself is the finding: your IT isn't documented well enough for you to know where you stand. That's fixable.

For a 10-person business, closing the gaps this review surfaces typically costs €150-350 a month on top of existing Microsoft 365 licensing, mostly backup and security training. The cost of not closing them is the incident you can't recover from.

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. Cyber Essentials for Small Businesses (opens in a new tab)

    CISA (US Cybersecurity & Infrastructure Security Agency) · 2025

    Government baseline control set for small organisations: identity, devices, data recovery.

  2. Cross-Sector Cybersecurity Performance Goals (opens in a new tab)

    CISA · 2026

    A prioritised, product-agnostic list of the controls that remove the most risk first - useful for deciding what to fix after the health check.

  3. Small Business Guide: Cyber Security (opens in a new tab)

    UK National Cyber Security Centre · 2025

    The baseline control set a small organisation should implement first, from a national authority.

  4. Cyber Defense Methodology for an Organization (opens in a new tab)

    Israel National Cyber Directorate (INCD) · 2025

    Israeli national guidance on layered organisational cyber defence for smaller organisations.

  5. NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide (SP 1300) (opens in a new tab)

    NIST · 2024

    The vendor-neutral baseline behind the health-check questions: identify, protect, detect, respond and recover, scaled for a business without an IT department.

  6. Cybersecurity Guide for SMEs (opens in a new tab)

    ENISA (European Union Agency for Cybersecurity) · 2021

    EU-level, non-vendor guidance for small businesses - directly relevant for clients operating in Greece and Spain.

  7. How effective is multifactor authentication at deterring cyberattacks? (opens in a new tab)

    Microsoft Research · May 2023

    MFA reduces the risk of account compromise by 99.22% overall and 98.56% even on accounts with a previously leaked password.

  8. The State of Ransomware 2026 (opens in a new tab)

    Sophos · 2026

    Malicious email and phishing drive roughly half of ransomware incidents; mean recovery cost of USD 1.7M excluding ransom.

  9. 2026 SaaS Management Index (opens in a new tab)

    Zylo · 2026

    36% of SaaS licences left unused; median SaaS spend per employee, from 40M+ licences under management.

  10. Compare All Microsoft 365 Business Plans (opens in a new tab)

    Microsoft · 2026

    Current Microsoft 365 Business plan list pricing, including Business Basic, used in the licence-drift question.

  11. Secure and Govern Microsoft 365 Copilot (opens in a new tab)

    Microsoft Security · 2026

    Microsoft's own framing of oversharing as a named governance risk, relevant to why a permissions review matters more once AI tools are involved.

  12. Microsoft Intune (opens in a new tab)

    Microsoft Security · 2026

    What Intune does for device compliance, encryption enforcement and update management across a fleet.

Figures last checked 2 August 2026

Not sure how your IT would score on this checklist?

Book a free 30-minute call. We'll walk through all 10 questions with you and tell you exactly where the gaps are.