In most small businesses, there are certain IT jobs that everybody assumes somebody else is doing.
Backups are probably working. Someone must be keeping an eye on licences. Presumably, somebody removed that former employee’s access. And there must be a person who knows the administrator password …
Most of the time, these things sit quietly in the background. Until something goes wrong.
Here are some of the IT responsibilities that are surprisingly easy to leave without a clear owner.
Many businesses have automatic backups, which is a good start. But who checks that they’re actually completing successfully?
More importantly, has anyone tested whether the data can be restored?
A backup isn’t much reassurance if the first time you discover there’s a problem is when you desperately need it.
When somebody leaves a business, there are plenty of things to organise – and IT access can easily become just another item on a long list.
Someone needs to make sure email accounts, cloud services, shared files, remote access and company devices are dealt with properly.
It’s worth having a standard leaver process rather than relying on somebody remembering everything each time.
Software subscriptions have a habit of accumulating.
An employee leaves, a new service is introduced or somebody signs up for an additional tool – and before long the business can be paying for licences nobody uses.
Someone should have oversight of what you’re paying for, who is using it and whether you still need it.
There’s often one computer in the office that everybody knows is on its last legs.
The temptation is to keep it going until it finally gives up. But replacing ageing equipment in a planned way is usually much less disruptive than dealing with an unexpected failure on a Monday morning.
Someone needs to know what equipment the business has, how old it is and when it is likely to need replacing.
Administrator accounts can make significant changes to systems, so they shouldn’t simply be handed out whenever somebody needs to install something.
Who knows which employees have administrator privileges? Are there old admin accounts still active? Are powerful accounts being used for ordinary day-to-day work?
If nobody owns the question, unnecessary access can gradually build up.
Updates aren’t just about getting the latest features. They frequently contain important security fixes.
Someone needs to know whether company computers, servers and other devices are being kept up to date – and whether any devices have stopped receiving the updates they need.
This can be one of the biggest hidden risks.
Perhaps there’s one employee who knows where the passwords are, how a particular system works or who to call when the broadband goes down.
What happens if they’re on holiday, off sick or leave the business?
Important IT knowledge shouldn’t exist solely in one person’s head. Key information should be documented and accessible to the appropriate people.
This is perhaps the most important question.
If your internet connection failed tomorrow, who would contact the provider? If you couldn’t access your files, who would check the backups? If an employee clicked on a suspicious link, would they know who to tell?
You don’t need an elaborate procedure for every possible IT problem. But people should know who is responsible for making decisions and getting help.
As businesses grow, IT often develops gradually. A few laptops become ten, then twenty. More software is introduced. People join and leave. More data is stored online.
The technology may keep working perfectly well, but the responsibilities surrounding it can become surprisingly unclear.
The answer isn’t necessarily to give one person a long list of additional jobs. It’s to make sure somebody has oversight – whether that’s an internal IT person, an external IT provider or a combination of the two.
Because the worst time to discover that nobody was responsible for something is usually just after it has gone wrong.