The review most businesses actually skip
Year-end is when business owners review everything: financials, team performance, sales pipeline, vendor contracts, strategic goals. One thing almost never gets the same treatment: the IT running underneath all of it.
That's not because IT is unimportant. It's because the questions feel like they need a technical person to answer them. They don't. The right questions are business questions, about cost, risk and readiness, and a non-technical owner can ask and understand every one of them.
A meaningful share of what small businesses spend on IT each year goes on tools nobody uses, security nobody configured, and backups nobody has tested. A 30-minute review once a year catches most of it.
These 10 questions are that review. Ask them of yourself, or ask them of whoever manages your IT. The answers tell you whether your setup is healthy, or quietly heading toward a problem. They are also the questions behind the baselines national authorities publish for small organisations - CISA's Cyber Essentials[1][2], the UK NCSC's small business guide[3], and for businesses operating in Israel, the INCD's organisational cyber defence methodology[4][5][6].
1. Is multi-factor authentication actually on every single account, or just the ones you remember?
This is the single most important question on the list. Microsoft's own research found MFA cuts the risk of account compromise by 99.22%, and by 98.56% even on accounts whose password had already leaked[7].
The question isn't "do we have MFA." It's "is it on every mailbox, every admin account, and every remote access path." One unsecured account is the gap an attacker walks through. Check the admin accounts specifically - they're the ones most commonly missed.
2. When did you last actually test a backup restore?
A backup you've never tested is not a backup. It's a hope. The only way to know a restore will work when you need it is to have already done it once when you didn't have to. Sophos' annual ransomware research is blunt about the consequence: recovery is what a tested backup buys, and paying is what an untested one costs[8].
Ask for the date of the last restore test. If the answer is "we haven't done one" or "we're not sure," that's the finding. A tested restore should happen at least quarterly. Anything less is a gap [your insurer may care about too](/articles/why-small-businesses-fail-cyber-insurance-assessment).
3. Do you actually know what every recurring IT charge on your card is for?
Most small businesses carry a handful of tools that are redundant, overlapping, or still billing for someone who left months ago. It is not a local problem: across more than 40 million licences under management, organisations leave an average of 36% of their SaaS licences unused[9].
Print the last three months of IT-related card and bank charges. Question every line. If nobody can explain what a tool does or who uses it, cancel it. In the audits we've run for clients, this typically saves €400-800 a month for a small business - money that goes straight to the bottom line.
4. If your most technically capable person left tomorrow, who actually has the passwords?
This is the bus-factor question. If one person holds the admin credentials for your domain, your email, your cloud accounts and your backup system, and those credentials live in their head or their personal password manager, that's a business risk, not an IT risk.
Every business should keep its admin credentials in a shared, company-owned password vault. Access is controlled, audited and transferable. No single person is the only one who can get you back in.
5. Are you actually paying for Microsoft 365 licences you're not using?
Microsoft's list prices for Business plans move periodically - Business Basic currently lists at $7 a user a month[10] - and licence drift, users sitting on a higher plan than they need, or former employees still licensed, is one of the most common wasted costs in small businesses.
Review the admin centre. Check: is every licensed user still at the company, is each person on the plan that matches what they actually do, and are unused add-ons still billing. A 10-person business can often save €50-150 a month just by cleaning this up.
6. When did someone last actually review who has access to what?
In many small businesses, everyone has access to everything: the HR folder, the finance folder, the client contracts folder, all open to all employees by default. That's convenient until it isn't.
Ask for a list of who has access to sensitive folders. If the answer is "everyone," that's a finding. Permissions should be role-based: finance sees finance, leadership sees strategy, new hires see what they need for their job. It's a couple of hours' work for a 10-person business, and it matters more than ever if you're considering AI tools like Copilot, which surface information based on whatever permissions already exist rather than a separate check of their own[11].
7. Do you actually have a written incident response plan, or do you improvise when something goes wrong?
When an incident happens, a phishing click, a lost laptop, a suspicious login, the time to figure out what to do is not during the incident. A written plan means anyone on the team can take the first step without waiting for the owner to decide.
It doesn't need to be elaborate. It needs to answer three questions: who do we call, what do we shut down, and how do we communicate. If that doesn't exist, it's a gap, and [insurers now ask about it too](/articles/why-small-businesses-fail-cyber-insurance-assessment).
8. Is every company device actually encrypted, updated, and remotely wipeable?
If a laptop is lost or stolen, can you wipe it remotely? "I think so" or "I'm not sure" is a finding. Microsoft Intune, included in Business Premium, is built to handle device compliance, encryption and update management across a fleet[12] - but only for devices that are actually enrolled.
Ask for a device inventory. If the list is incomplete, or devices aren't enrolled in management, that's the finding. A lost laptop with company email on it and no way to wipe it remotely is a data breach.
9. Are your employees actually trained, or was it a one-time video at onboarding?
Security awareness training that happens once, during onboarding, and never again doesn't hold up. Attackers change their methods; your team needs to encounter realistic phishing attempts often enough that spotting a fake becomes reflex rather than a guess.
Ask: when was the last phishing simulation, and what were the results. If the answer is "we don't do that," the team is your weakest control, and your strongest one if you train them. Regular training with simulation results is also something insurers increasingly want to see.
10. If you switched IT providers tomorrow, could you actually do it?
This is the question most owners don't want to ask. The answer tells you whether you're in control of your own IT or trapped by whoever currently runs it.
You should own your domain, your Microsoft 365 or Google Workspace tenant, and every business account, in your company's name, with admin credentials you can access. A provider administers these; they shouldn't own them. If your domain is registered in your provider's name, or your tenant is on their billing, that's a structural problem worth fixing before you ever need to switch. [We've written about exactly how to make that move without losing anything.](/articles/switching-it-providers-without-losing-data)
How to actually use this review
These questions aren't a pass/fail test. They're a map. Every "no" or "I'm not sure" is a finding, something to address before it becomes an incident, a denied insurance claim, or an unexpected cost.
The review takes 30 minutes if the answers are available. If they're not, that itself is the finding: your IT isn't documented well enough for you to know where you stand. That's fixable.
For a 10-person business, closing the gaps this review surfaces typically costs €150-350 a month on top of existing Microsoft 365 licensing, mostly backup and security training. The cost of not closing them is the incident you can't recover from.
