10 Technology Must-Dos and Must-Nots for a Growing Business

Most technology problems in a growing business are not exotic. They are the same handful of avoidable habits, repeated. These ten cover the ground that matters most, each with the thing to do and the thing that quietly costs you.

1. Backups — do test the restore. Do not assume it works.

A backup you have never restored is a belief, not a control. Test one restore this quarter and write down the date. And keep one copy somewhere ransomware cannot reach — if your backup is online and reachable from the network, it is in range.

2. Access — do give everyone their own account. Do not share logins.

Shared credentials mean you cannot tell who changed something, cannot revoke one person without disrupting others, and cannot answer a client’s question about who accessed their data. One account per person, always.

3. Passwords — do use a password manager and MFA. Do not reuse passwords.

Password reuse is how one breach at an unrelated website becomes a breach of your banking. Multi-factor authentication on email is the single highest-value control in a small business, because email resets everything else.

4. Updates — do patch on a schedule. Do not let one awkward app stop everything.

Patching removes more risk than any product you can buy. Run a monthly cycle, and when one business-critical application breaks on updates, treat it as a documented exception with compensating controls — not a reason to stop patching the rest. We go deeper in the monthly patching routine.

5. Email — do authenticate your domain. Do not treat delivery as luck.

SPF, DKIM and DMARC decide whether your invoices reach the inbox. Set them up, and update them every time you add a tool that sends on your behalf. Most “our emails go to spam” problems are one missing DNS entry.

6. Client data — do know where it lives. Do not let it sit in personal drives.

If you cannot say where a client’s files are, who can open them and what happens when someone leaves, you cannot answer the questions clients are increasingly asking. Centralise it, and make the location the obvious place to save.

7. Staff leaving — do run an offboarding checklist. Do not rely on memory.

The dangerous moment is not a hostile exit. It is the friendly one where nobody removed access to the shared drive, the mail forwarding rule, or the accounting platform. Use a written checklist, and have someone else verify it.

8. Software — do keep a subscription list. Do not let renewals go unseen.

Growing businesses accumulate overlapping tools one purchase at a time. Keep one list of what you pay for, who uses it and why. Review it quarterly and cancel what nobody has opened in three months.

9. AI — do write a rule before people experiment. Do not paste client data into consumer tools.

AI drafted text is genuinely useful, and staff will use it whether or not you approve. Decide which tools are allowed, what data must never go into them, and that anything going to a client gets read by a person who is accountable for it. See AI governance and guardrails and, for a starting point, a practical starting line for AI at work.

10. Documentation — do write it down. Do not keep it in one person’s head.

Every business has one person who knows how a critical thing works. That is a risk concentration, not a superpower. Write down the internet provider, the domain registrar, the wifi password, the backup schedule and who to call. Keep it where two people can find it.

If you only do five things this quarter

  1. Turn on multi-factor authentication for email.
  2. Test one restore from backup.
  3. Set up SPF, DKIM and DMARC.
  4. Write the offboarding checklist.
  5. Write down the ten systems the business runs on, and who owns each.
Photoa printed one-page business systems checklist on a desk beside a keyboard
Five items, all free, all higher value than most of what you could buy.

How to tell you are on top of it

You are in good shape when a new starter can be set up in an afternoon, someone leaving can be offboarded in an hour, and you could describe your backup and recovery to a client without checking first.

Most of this sits inside cybersecurity and IT lifecycle management. If you would like someone to run the list against your business and tell you where the gaps are, we will do that with you.

Photoa manager reviewing a simple dashboard on a monitor showing abstract status tiles
The goal is not perfection. It is knowing your own answers before you are asked.