The biggest IT system issues today are no longer just about hardware failures or viruses. The major risks are increasingly cybersecurity, complexity, human error, resilience, and keeping systems properly maintained.
- Cybersecurity and ransomware
Probably the biggest issue for businesses.
Ransomware and data theft
Phishing and compromised email accounts
Stolen passwords and credentials
Attacks through remote access and cloud services
Supply-chain attacks through third-party providers
Increasingly sophisticated AI-assisted attacks
The difficult part is that a business can have antivirus and a firewall and still be compromised.
- Backups that aren’t actually recoverable
This is an area I think is particularly important for IT providers.
Many businesses say “We have backups” when what they really mean is “Something is running that appears to be backing up.”
The real questions are:
Has the backup actually completed?
Can the data be restored?
How recently was it tested?
Are multiple backup copies available?
Is one copy isolated from ransomware?
Can the business continue operating if the main systems are destroyed?
A backup that has never been tested is not a proven backup.
- Outdated and unsupported systems
Businesses often continue using:
Old Windows versions
Unsupported servers
Old networking equipment
Unpatched applications
Legacy line-of-business software
Devices that can no longer receive security updates
Replacing something that still “works” is difficult to justify to a business owner—until it fails or becomes a security problem.
- Human error
People remain one of the biggest vulnerabilities.
Examples include:
Clicking malicious attachments
Reusing passwords
Sending confidential information to the wrong person
Approving fraudulent payments
Losing laptops or phones
Using unauthorised cloud applications
Technology can reduce these risks, but it cannot eliminate them.
- Cloud and Microsoft 365 dependency
Cloud services have enormous benefits, but businesses sometimes assume:
“It’s in Microsoft 365, therefore it is backed up.”
That’s not necessarily sufficient protection against accidental deletion, malicious deletion, compromised accounts or other incidents.
Businesses also need to understand what happens if their Microsoft/Google/cloud account becomes unavailable.
- Lack of documentation
This is a surprisingly serious problem.
A business may have perfectly good systems but nobody knows:
What equipment exists
What it does
Where passwords and credentials are held
How the network is configured
What licences exist
Who has administrative access
How backups work
How to recover the system after a major failure
This becomes particularly dangerous when the person who originally installed everything is no longer available.
- Network complexity
Modern businesses can have:
Internet → firewall → switches → Wi-Fi → servers → Microsoft 365 → cloud applications → VPN → remote workers → phones → printers → IoT devices
Every additional connection introduces another potential failure or security point.
- Poor disaster recovery
Businesses often plan for individual failures but not for a major incident.
For example:
“What happens if the server, firewall and backup equipment are all destroyed at the same time?”
Or:
“What happens if the office is unavailable for two weeks?”
A proper disaster-recovery plan needs to consider people, systems, data, communications and physical premises.
- Lack of monitoring
Many businesses don’t discover a problem until someone complains.
Good managed IT should identify problems before the customer notices them:
Disk failure
Backup failure
Storage running out
Security alerts
Expiring certificates
Unpatched devices
Network problems
Unusual login activity
- IT knowledge leaving the business
This is becoming increasingly important as experienced IT people retire or move on.
A business can become dependent on one person who understands its entire infrastructure.
That creates what I would call “key-person IT risk.”
Where I see an opportunity for an experienced IT professional
Given your background in infrastructure and networking, I think there is an interesting opportunity in moving away from being the person who simply fixes computers and towards being the person who assesses and improves IT resilience.
For example, you could offer businesses an independent:
IT Health & Resilience Assessment
You examine:
Cybersecurity
Backups and recovery
Network infrastructure
Microsoft 365/cloud security
Hardware and software lifecycle
Disaster recovery
Documentation
User security
Remote access
Business continuity
Then produce a simple report:
RED — Critical problem
AMBER — Needs attention
GREEN — Acceptable
That could be particularly valuable to small and medium businesses that don’t have an internal IT manager.
And importantly, it doesn’t require you to be the person doing every technical job yourself. You could perform the assessment and work with younger technical partners to implement the recommendations.
That could be a very good model for someone with substantial IT experience who wants a new challenge rather than simply doing traditional IT support.
