A practical business IT health checklist.

Use this owner-friendly review to expose unclear access, undocumented dependencies and recovery assumptions before they become urgent. It covers the technology, suppliers and working arrangements a small business relies on.

Gather evidence, not just reassuring answers.

Have recent supplier invoices, administrator details, Microsoft 365 information, backup reports, broadband and phone account records available. Ask the person responsible for day-to-day operations to join the review.

Use three labels: verified when you have seen evidence, assumed when somebody believes it is true, and unknown when ownership or evidence is missing.

Review the ten areas that keep daily work dependable.

Write down gaps as you go. Do not enter passwords, recovery codes or other secrets into the checklist.

1. Inventory and ownership

List the computers, servers, network equipment, cloud services, phone systems and business applications that matter. Record who owns each decision and who can administer each service.

  • Important equipment and services are recorded
  • A named person owns each business decision
  • Administrator and supplier access is known

2. Administrator access and 2-step verification

Identify every administrator account. Use named accounts where possible, protect important accounts with 2-step verification and make sure recovery methods belong to the business.

  • Important accounts use 2-step verification
  • Shared or former-staff administrator access is removed
  • Recovery details are current and business-controlled

3. Microsoft 365 and staff changes

Check active users, licences, shared mailboxes, forwarding, groups and external access. Make joiner and leaver actions repeatable rather than relying on memory.

  • Users and licences match the current team
  • Shared mailboxes and groups have owners
  • Joiner and leaver steps are documented

4. Devices, updates and encryption

Confirm that business laptops and desktops run supported software, receive updates and have appropriate protection. Record where business information is stored on portable devices.

  • Devices are supported and updated
  • Lost or stolen laptops can be dealt with
  • Business data on portable devices is protected

5. Network, Wi-Fi and broadband

Sketch how internet connections, firewalls, switches and wireless access points fit together. Record the broadband account owner, support details and what work stops if connectivity fails.

  • Key network equipment is identified
  • Business and guest Wi-Fi arrangements are understood
  • Broadband ownership and outage options are recorded

6. Backups and recovery evidence

Record what is backed up, where copies are held, how failures are reported and when somebody last restored important information. A successful dashboard is not the same as a proven recovery.

  • Critical information is included
  • Backup access is protected with 2-step verification
  • A recent restore has been completed or scheduled

7. Business phones and call continuity

Document main numbers, call routing, voicemail, handsets and the supplier portal. Check what callers experience when the office loses power, broadband or access to a building.

  • Main numbers and routing are recorded
  • More than one authorised contact can manage the service
  • Outage and diversion behaviour is understood

8. Suppliers, contracts and digital ownership

List the provider, account reference, renewal date and authorised contacts for each important service. Confirm that domains, websites and cloud tenants are controlled by the business rather than an individual or former supplier.

  • Renewals and notice periods are visible
  • Domains and core services are business-controlled
  • Supplier responsibilities do not overlap or leave gaps

9. Incidents and continuity

Name the people who make decisions during an outage or suspected compromise. Keep essential supplier contacts and safe alternative communication routes available when normal systems cannot be trusted.

  • Critical services and information are prioritised
  • Response contacts are available away from normal systems
  • Staff know who to contact and what not to do

10. A 30- and 90-day action plan

Turn gaps into a short list with an owner and target date. Fix exposed ownership and access issues first, then schedule resilience, documentation and replacement work in a sensible order.

  • Every action has an owner
  • Urgent access and recovery gaps come first
  • The plan is reviewed after 30 and 90 days

Red flags that should not wait for the next annual review.

  • A former employee or supplier still controls an important account
  • Only one person can access the domain, Microsoft 365, backups or phone portal
  • No recent restore has proved that important data can be recovered
  • Important accounts do not use 2-step verification
  • The business cannot explain what happens to calls or work during an outage
  • Renewals, notice periods or service ownership are unknown
Keep the evidence safe

Record account ownership, service references, dates and responsible people, but keep passwords and recovery codes in an appropriate password manager or other controlled system.

If you suspect an active compromise, do not rely on the potentially affected email or device for response communications.

Collect the information the business will need to retain control.

  • Current contracts, account references, renewal dates and notice periods
  • Domain registrar, DNS, website hosting and authorised contacts
  • Microsoft 365 tenant, licences, administrator roles and recovery ownership
  • Network layout, firewall, Wi-Fi, broadband and telephone service details
  • Backup locations, retention, recent results and restore evidence
  • Known faults, open projects, warranties and third-party dependencies

Use the complete provider-switching guide →

Keep the action plan short enough to finish.

Give every action one owner, a sensible target date and an explanation of the business consequence. Deal first with lost ownership, exposed access and unproven recovery. Group lower-risk documentation and replacement work into the next 30 and 90 days.

Use trusted guidance for the cybersecurity detail.

This broader operational checklist is informed by the UK National Cyber Security Centre’s current guidance for small organisations, including important account protection, device security, backups and incident preparation.

Read the NCSC small organisations guide →

Important boundary

This guide helps a business identify practical questions and ownership gaps. It is not a penetration test, certification, legal opinion, regulatory assessment, formal compliance audit or insurance review.

Use the checklist with clear boundaries.

How often should we use the checklist?

Use it at least annually and after a significant staff, supplier, premises or system change. Important access, backup and continuity actions may need more frequent checks.

Does this replace a penetration test or compliance audit?

No. This is a practical operational checklist, not a penetration test, certification, legal opinion, regulatory assessment or insurance review.

Can our current IT provider help complete it?

Yes. A capable provider should be able to supply evidence for the services it manages. The business should still understand ownership, dependencies and any areas handled by other suppliers.

What if information or access is unavailable?

Record the gap rather than guessing. Missing ownership, documentation or recovery access is itself a useful finding and should receive an owner and next action.

Ask Oblyx to carry out the full Health Review.

Oblyx can gather the evidence, document the complete picture and turn findings into a prioritised working plan.

Request a Health Review