IT Systems Main Considerations

The biggest IT system issues today are no longer just about hardware failures or viruses. The major risks are increasingly cybersecurity, complexity, human error, resilience, and keeping systems properly maintained.

  1. Cybersecurity and ransomware

Probably the biggest issue for businesses.

Ransomware and data theft

Phishing and compromised email accounts

Stolen passwords and credentials

Attacks through remote access and cloud services

Supply-chain attacks through third-party providers

Increasingly sophisticated AI-assisted attacks

The difficult part is that a business can have antivirus and a firewall and still be compromised.

  1. Backups that aren’t actually recoverable

This is an area I think is particularly important for IT providers.

Many businesses say “We have backups” when what they really mean is “Something is running that appears to be backing up.”

The real questions are:

Has the backup actually completed?

Can the data be restored?

How recently was it tested?

Are multiple backup copies available?

Is one copy isolated from ransomware?

Can the business continue operating if the main systems are destroyed?

A backup that has never been tested is not a proven backup.

  1. Outdated and unsupported systems

Businesses often continue using:

Old Windows versions

Unsupported servers

Old networking equipment

Unpatched applications

Legacy line-of-business software

Devices that can no longer receive security updates

Replacing something that still “works” is difficult to justify to a business owner—until it fails or becomes a security problem.

  1. Human error

People remain one of the biggest vulnerabilities.

Examples include:

Clicking malicious attachments

Reusing passwords

Sending confidential information to the wrong person

Approving fraudulent payments

Losing laptops or phones

Using unauthorised cloud applications

Technology can reduce these risks, but it cannot eliminate them.

  1. Cloud and Microsoft 365 dependency

Cloud services have enormous benefits, but businesses sometimes assume:

“It’s in Microsoft 365, therefore it is backed up.”

That’s not necessarily sufficient protection against accidental deletion, malicious deletion, compromised accounts or other incidents.

Businesses also need to understand what happens if their Microsoft/Google/cloud account becomes unavailable.

  1. Lack of documentation

This is a surprisingly serious problem.

A business may have perfectly good systems but nobody knows:

What equipment exists

What it does

Where passwords and credentials are held

How the network is configured

What licences exist

Who has administrative access

How backups work

How to recover the system after a major failure

This becomes particularly dangerous when the person who originally installed everything is no longer available.

  1. Network complexity

Modern businesses can have:

Internet → firewall → switches → Wi-Fi → servers → Microsoft 365 → cloud applications → VPN → remote workers → phones → printers → IoT devices

Every additional connection introduces another potential failure or security point.

  1. Poor disaster recovery

Businesses often plan for individual failures but not for a major incident.

For example:

“What happens if the server, firewall and backup equipment are all destroyed at the same time?”

Or:

“What happens if the office is unavailable for two weeks?”

A proper disaster-recovery plan needs to consider people, systems, data, communications and physical premises.

  1. Lack of monitoring

Many businesses don’t discover a problem until someone complains.

Good managed IT should identify problems before the customer notices them:

Disk failure

Backup failure

Storage running out

Security alerts

Expiring certificates

Unpatched devices

Network problems

Unusual login activity

  1. IT knowledge leaving the business

This is becoming increasingly important as experienced IT people retire or move on.

A business can become dependent on one person who understands its entire infrastructure.

That creates what I would call “key-person IT risk.”

Where I see an opportunity for an experienced IT professional

Given your background in infrastructure and networking, I think there is an interesting opportunity in moving away from being the person who simply fixes computers and towards being the person who assesses and improves IT resilience.

For example, you could offer businesses an independent:

IT Health & Resilience Assessment

You examine:

Cybersecurity

Backups and recovery

Network infrastructure

Microsoft 365/cloud security

Hardware and software lifecycle

Disaster recovery

Documentation

User security

Remote access

Business continuity

Then produce a simple report:

RED — Critical problem

AMBER — Needs attention

GREEN — Acceptable

That could be particularly valuable to small and medium businesses that don’t have an internal IT manager.

And importantly, it doesn’t require you to be the person doing every technical job yourself. You could perform the assessment and work with younger technical partners to implement the recommendations.

That could be a very good model for someone with substantial IT experience who wants a new challenge rather than simply doing traditional IT support.

 

Computer Backups

The Importance Verifying your Backups

We were asked to supply a new computer and restore the data from user’s USB Drive.

Upon examining the contents of the USB Backup Drive, we could not find any useful data to restore.

The Backup was originally set up by a relative and it was apparently working over the last 2 years.

When I asked “how do you know that the backup was working”, the Answer was “There was a light on the USB Drive”.

Unfortunately, a light on a backup device does not confirm that your data is actually being backed up successfully or that the data can be restored when you need it

Backups need to be regularly checked and verified.

A proper backup strategy should include:

  • Regular checks that backups are completing successfully
  • Verification that the backed-up data is actually accessible
  • Periodic test restores to confirm that data can be recovered
  • More than one backup where appropriate, preferably including an off-site or cloud-based copy

Backups are essential for protecting your business and its valuable data. Don’t wait until you need a backup to discover that it isn’t working.

Backup Solutions for Small Business

Ransomware attack – don’t be exposed

How to recover from ransomware attack.

The best way to to recover from a Ransomware attack is to have a Recovery Plan.

  1. Isolate affected systems. Disconnect infected computers, servers, and storage from the network to prevent the ransomware from spreading.
  2. Preserve evidence. If the attack may require investigation, avoid deleting files or wiping systems before IT/security professionals have captured relevant evidence.
  3. Identify the ransomware. Determine which ransomware variant is involved and whether a legitimate decryptor is available.
  4. Remove the malware. Use trusted, up-to-date security software. For severely compromised systems, a clean OS installation or reimaging is generally safer than trying to remove every malicious component manually.
  5. Patch and secure systems. Before reconnecting restored machines, install current operating-system and application updates, change compromised credentials, and address the vulnerability that allowed the attack.
  6. Restore from clean backups. Use the most recent backup that you can verify was created before the ransomware infection. Don’t restore backups that may themselves be compromised.
  7. If necessary, restore a complete system image. A known-good image can be preferable when rebuilding a system manually would be impractical.
  8. Verify the recovery. Scan restored systems, check that applications and data work correctly, and monitor for signs of reinfection before returning them to normal operation.
  9. Investigate and improve defenses. Determine how the ransomware entered, document the incident, and strengthen backup, patching, authentication, network segmentation, and endpoint-security practices.

Important: Don’t assume that deleting the encrypted files will remove the ransomware. Also, avoid paying a ransom. Carefully consider the legal, operational, and security implications.