Small Business IT Checklist: How Well Do You Know Your Technology?
- Shay

- Apr 9, 2025
- 19 min read
Updated: Aug 25

A small business owner does not need to know how to configure a firewall, create a VLAN, administer Microsoft Entra ID, troubleshoot a failed backup, or figure out why a computer stopped checking into an RMM platform. That is part of the reason businesses hire people like me. But I do think someone inside the business should have a clear understanding of the technology the company depends on, where important information lives, who owns the accounts, who has administrative access, what is being backed up, which devices are actually being managed, and what major technology expenses or renewals are coming.
I originally wrote this article from the perspective of cyber insurance and whether a small business could be too small to worry about cyber risk. Cyber insurance is still an important part of this conversation, but after working through more client environments, insurance questionnaires, Microsoft 365 reviews, security projects, AI implementations, hardware planning, and IT assessments, I think there is a bigger question that needs to come first.
How well do you actually know your business's IT environment?
If I asked you where your DNS is hosted, who has administrative access to Microsoft 365, which computers are currently under centralized management, what data is backed up, whether your guest WiFi can reach your internal network, when your firewall needs to be renewed or replaced, and which AI platforms employees are using for company work, could you answer?
If some of those answers are “I don't know,” that is useful information. It tells us where we need better visibility.
What IT Information Should a Small Business Owner Know?
There is an important difference between understanding your IT environment and personally managing it. I do not expect my clients to know how to change DNS records, build Conditional Access policies, configure inter VLAN firewall rules, deploy endpoint protection, or manage patch policies. I do want the business to understand what it owns, what it relies on, where its important information resides, and who is responsible for managing each part of the environment.
At a basic level, I think a business should be able to get clear answers to questions like these:
Where is our business email hosted?
Where are our important files and business data stored?
Who owns our domain, DNS, and website accounts?
What computers, servers, and other devices belong to the business?
Who has administrative access to our critical systems?
What is being backed up, and how would we recover it?
Are our computers centrally managed and monitored?
What security systems are in place?
How is our network segmented?
What software and cloud services does the company depend on?
Which equipment is owned and which is leased?
What subscriptions, contracts, warranties, and leases are coming up for renewal?
Which AI platforms are employees using for company work?
Where is our current IT documentation?
If our current IT provider became unavailable, could another qualified provider understand the environment and take over?
Those are business ownership and management questions. They do not require the owner to become the IT department.
If a business cannot answer many of them, that is one of the situations where an SNL-Tech Services IT Baseline Assessment may make sense. The assessment goes beyond this owner level checklist and looks at the actual technology environment so I can establish what is there, how the pieces fit together, what needs attention, and what should be prioritized.
Where Does Your Business Actually Live?
A small business is rarely contained inside one server closet anymore. Parts of the company may live in Microsoft 365, Google Workspace, SharePoint, OneDrive, accounting software, payroll platforms, CRM systems, websites, cloud storage, industry specific applications, local servers, NAS devices, employee laptops, and increasingly AI platforms.
That is why one of the first things I want to understand when looking at an environment is where the business actually operates from a technology perspective.
A basic systems inventory might start like this:
System or Service | What Do We Use It For? | Who Owns the Account? | Who Administers It? | Where Is the Data? | Backup or Recovery |
Microsoft 365 / Google Workspace | |||||
Website | |||||
Domain and DNS | |||||
Accounting | |||||
Payroll | |||||
CRM | |||||
File storage | |||||
Industry software | |||||
AI platforms | |||||
Other critical systems |
The first goal is not to document every technical setting. It is to understand what the business depends on.
That approach is consistent with current NIST Cybersecurity Framework guidance for small businesses. NIST recommends identifying and maintaining an inventory of the hardware, software, systems, services, and important data the business relies on. The Cybersecurity Framework is also intentionally risk based rather than a single technology prescription that every business must implement identically.
Do You Know Where Your Important Business Data Is Stored?
Knowing which applications the company uses is only part of the picture. I also want to know where the information that keeps the business running actually lives.
Depending on the company, that could include customer or client records, email, contracts, financial information, estimates, employee information, project files, accounting data, intellectual property, website files and databases, and regulated information such as PHI or CUI when applicable.
Then I want to understand what systems store that information, who can access it, how it is protected, and what the business expects to happen if the primary copy becomes unavailable.
This becomes particularly important when technology has accumulated over time. One application may store documents in the cloud while another still relies on a local server. Employees may save individual work in OneDrive while shared company information belongs in SharePoint. An older line of business application may still depend on traditional Active Directory even though much of the company has moved to cloud services.
I have encountered exactly that kind of dependency during assessment work. In one environment, understanding an ERP application's dependency on traditional Active Directory became important to larger infrastructure and compliance decisions. That is why I do not like starting with a predetermined solution and trying to make the environment fit it. I want to understand what depends on what first.
Who Owns and Controls Your Technology Accounts?
Ownership is one of the things I stress most with my clients. A business can hire an IT provider, web developer, marketing company, or another specialist to manage technology without giving up ownership and control of the underlying business assets.
I have worked with businesses that felt trapped because a previous provider controlled information or accounts they needed. That experience influenced a deliberate decision I made about how I wanted to run SNL-Tech Services. My clients should not need to be held hostage by me to keep operating their own business.
At a minimum, the business should understand these areas:
Asset | What the Business Should Know |
Domain | Registrar, ownership, renewal, and business controlled access |
DNS | Where DNS is hosted and who can make changes |
Website | Hosting, administrative access, files, database, and backups |
Microsoft 365 / Google Workspace | Tenant or organization ownership, administrators, and recovery access |
Cloud applications | Business owner, administrators, billing, and recovery |
Backups | Platform, administrative access, and recovery process |
Network equipment | Ownership, management access, leases, and configuration |
IT documentation | Where current documentation resides and whether the business can access it |
I go much deeper into this in When Everything Went Offline: Why IT Documentation and Ownership Matter.
My position is not that the business owner needs to personally administer all of these systems. Management and ownership are two different things.
Is Someone Actually Managing Microsoft 365 or Google Workspace?
Many small businesses know they use Microsoft 365 or Google Workspace but have very little visibility into what is happening behind Outlook, Teams, OneDrive, Gmail, or the other applications employees see every day.
Email working does not tell me whether administrative access is appropriate, MFA is configured properly, former employees have been fully removed, security settings are being reviewed, licensing still makes sense, external access is appropriate, or third party applications have accumulated access over time.
For Microsoft 365 specifically, I discuss that distinction in Microsoft 365 for Small Businesses: Is Anyone Actually Managing Your Environment?.
When I need to go deeper, an SNL-Tech Services Microsoft 365 Audit lets me look specifically at the tenant, including identities, authentication, administrative access, licensing, security controls, SharePoint and OneDrive, devices, external access, connected applications, and other areas that may need attention.
The same basic principle applies to Google Workspace. Owning the subscription is not the same as actively managing the environment.
Are All of Your Computers Actually Under Management?
This is an area I think more business owners should ask their IT provider about.
An RMM, which stands for Remote Monitoring and Management, Microsoft Intune, or another centralized management platform can give an IT provider visibility into business devices. Depending on the platform and configuration, centralized management can help with areas such as device inventory, patching, monitoring, security deployment, configuration, and identifying computers that have stopped checking in.
But I would not stop at asking, “Do we have an RMM?”
The more important question is whether everything that is supposed to be managed is actually in scope and reporting.
A business should be able to determine things such as:
How many computers and other managed endpoints it has
Which employee is assigned to each device
Whether those devices are currently checking into the management platform
Whether operating system and application updates are being managed or monitored
Whether endpoint protection is centrally deployed and reporting
Whether encryption is enabled where required or appropriate
Whether laptops and remote or field devices are included
Whether retired and replaced devices have been removed from management systems
Whether someone notices when a device stops checking in
Whether an accurate list of currently managed devices can be produced
If a company owns 35 computers but only 28 are appearing in the management platform, saying “we have centralized device management” does not tell the entire story. I want to understand what those other seven devices are and whether they should be managed.
This is one of the differences between having a technology and actually managing it.
What Does Your Network Depend On?
A network inventory should include more than the name of the internet provider and the model of the firewall.
Depending on the environment, I want to understand the firewall, switches, wireless access points, internet connections, VPN or remote access, servers, printers, phones, cameras, IoT devices, and other equipment connected to the network. I also want to know who manages that equipment, whether firmware and security updates are being addressed, whether the hardware is still supported, and whether the configuration is documented.
A current network diagram can be incredibly useful here. It does not need to be a work of art, but another qualified IT professional should be able to look at it and understand the important parts of the environment.
Is Your Network Segmented Appropriately?
Network segmentation deserves its own discussion because knowing which devices are connected is not the same as deciding which devices should be allowed to communicate with each other.
VLANs are one common way to create logical separation within a network, but a VLAN by itself is not the entire security control. Firewall rules and other access controls determine what traffic is actually permitted between network segments.
Depending on the business, it may make sense to separate employee computers, servers, guest WiFi, security cameras, VoIP phones, printers, building systems, IoT equipment, or other types of devices. I would not prescribe the same VLAN design to every small business because the appropriate architecture depends on the environment, risk, systems, and requirements involved.
From the business owner's perspective, I would want answers to questions such as:
Is guest WiFi separated from the internal business network?
Can guest devices access internal business systems?
Are servers or sensitive systems segmented where appropriate?
Are cameras, IoT equipment, phones, printers, or other specialized devices separated where appropriate?
What VLANs or network segments currently exist, and why?
Are firewall rules controlling communication between those networks?
When new equipment is installed, does someone determine which network it belongs on?
Are old or unnecessary firewall rules and network configurations reviewed?
Is the network architecture documented?
The owner does not need to know VLAN IDs or understand every firewall rule. The IT provider managing the environment should be able to explain why the network is designed the way it is and document that design.
Network segmentation is also not something I would describe as a universal requirement for every cyber insurance policy or every small business. Requirements vary. Where segmentation becomes relevant to insurance or compliance, I want to evaluate it against the actual requirement rather than turning my preferred network design into somebody else's mandate.
What Computers, Servers, and Network Equipment Do You Actually Own?
An IT inventory should not stop at employee laptops. Depending on the environment, it may need to account for desktop computers, laptops, mobile devices, servers, NAS devices, firewalls, switches, wireless access points, internet equipment, printers, and other technology the business depends on.
Then I want to know which equipment is owned, which is leased, how old it is, whether it is still supported, what warranty coverage exists, and what lifecycle dates are approaching.
This is where IT documentation starts becoming part of financial planning.
If a firewall lease expires in January, I do not want January to be the first time my client hears about it. If several computers are approaching replacement, I would rather start that conversation months ahead so the owner can plan for the expense and we can decide whether replacement is actually necessary.
I discuss that approach in When Should a Small Business Replace Its Computers? A Practical IT Hardware Lifecycle Guide.
Hardware lifecycle planning is not about throwing away perfectly good equipment because it reached an arbitrary birthday. Sometimes replacement is the right answer. Sometimes repairing, upgrading, or repurposing an existing computer makes more sense. The important part is knowing what is coming early enough to make that decision intentionally.
Do You Actually Know What Is Being Backed Up?
“We have backups” is not enough information for me.
I want to know what is included, what is not included, where the backup resides, who administers it, who receives alerts when something fails, how long data is retained, and what the recovery process actually looks like.
Useful questions include:
What systems and business data are being backed up?
What is not being backed up?
Where are the backups stored?
Who manages and monitors them?
Who receives failure alerts?
How long is backup data retained?
Are Microsoft 365, Google Workspace, servers, NAS devices, websites, and other important systems protected where appropriate?
Can individual files, mailboxes, or entire systems be restored?
When was a restore last tested?
What happens if the primary environment is unavailable?
A backup application reporting success is useful, but ultimately I care about whether the business can recover what it needs.
The FTC's current small business cybersecurity guidance likewise recommends regular backups of important files and emphasizes protecting business data as part of foundational cybersecurity.
What Business Applications and Cloud Services Are You Paying For?
Small businesses tend to accumulate applications gradually. Someone needed a scheduling application. Accounting moved to the cloud. A CRM was introduced. Another department purchased a specialty application. Someone subscribed to Dropbox. Employees started experimenting with AI.
Five years later, the business may have dozens of platforms and no single inventory showing what they do or who is responsible for them.
For each important application, I want to know:
What does the business use it for?
Who owns the account?
Who has administrative access?
What business information does it contain?
Does it integrate with Microsoft 365, Google Workspace, or another company system?
Can its data be exported?
What happens to access when an employee leaves?
Is there a backup or recovery method?
What does it cost?
When does it renew?
Who is responsible for managing it?
This also matters when evaluating vendors. The FTC specifically advises businesses to consider the cybersecurity risks associated with suppliers and other third parties and to establish processes for confirming that vendors follow the business's security expectations.
What AI Tools Are Employees Already Using?
AI now belongs on a basic business technology inventory.
A business does not have to formally purchase an AI platform for employees to begin using AI. Someone may already be using ChatGPT, Claude, Microsoft Copilot, Gemini, Perplexity, Grok, or another service through a personal account.
I want to understand:
Which AI platforms are being used for company work?
Are employees using personal accounts or company managed accounts?
What company information is being entered?
Are AI platforms connected to Microsoft 365, Google Workspace, or other business systems?
Who approves new AI tools?
Does the company have rules for acceptable AI use?
What happens to access when an employee leaves?
This has become a significant part of the assessment conversation for me because I have seen businesses where AI use began before anyone formally decided how AI should be used.
I cover that much more deeply in AI Governance for Small Business. If the business discovers that employees are already using multiple AI platforms, company information is going into personal accounts, or nobody knows what AI can access, an SNL-Tech Services AI Governance Assessment may make more sense than trying to solve those questions with a generic IT checklist.
What Contracts, Leases, Warranties, and Renewals Are Coming?
Technology management also means looking forward.
A useful IT inventory should identify dates involving hardware leases, firewall subscriptions, internet contracts, software renewals, domain registration, website hosting, warranties, cloud subscriptions, support agreements, and major equipment lifecycle events.
I start looking at some of those decisions well before the renewal date because I want my clients to have time to understand the options and budget appropriately. Waiting until something expires removes options and can turn a planned technology decision into an emergency purchase.
For me, documentation is not just a record of what happened yesterday. It should help us see what is coming tomorrow.
Can You Answer the Technical Questions on Your Cyber Insurance Application?
This is where the original purpose of this article still matters.
A cyber insurance application or renewal is often one of the moments when a business discovers how much it does or does not know about its IT environment. An application may ask about MFA, endpoint protection, encryption, backups, remote access, email security, patching, incident response, financial transaction procedures, or other technical controls.
The exact questions and underwriting requirements vary by insurer, policy, and business. I do not treat a generic online checklist as a substitute for the company's actual application.
What matters to me from the IT side is whether the business can accurately substantiate the answers it gives.
If an application asks whether endpoints are encrypted, for example, I do not want to guess. I want to know which devices are in scope and whether the required encryption is actually enabled. If the question asks about patching, I want to understand how patches are managed and whether all of the appropriate devices are reporting into that management process.
That is why the SNL-Tech Services Cyber Insurance Readiness Assessment is driven by the actual questionnaire. I focus on helping the business verify the technical controls it is being asked about. The insurance professional remains responsible for insurance advice, policy language, coverage, exclusions, and other insurance specific questions.
What Should Be Included in Small Business IT Documentation?
Once the business understands what it has, that information needs to live somewhere useful and stay reasonably current.
The exact documentation depends on the environment, but useful IT documentation may include:
Hardware and device inventories
Network diagrams
Important network and IP information
Internet provider information
Firewall, switch, and wireless information
VLANs and network segmentation
Domain and DNS information
Website and hosting information
Microsoft 365 or Google Workspace overview
Administrative and emergency access information
Business applications and cloud services
Vendor contacts
Backup and recovery systems
Security and management platforms
Important system dependencies
Licensing and subscriptions
Warranty, lease, and renewal dates
Hardware lifecycle planning
Recovery information
I do not think the only current copy of that documentation should be inaccessible to the business itself. For one of my managed IT clients, I maintain my documentation in my own environment, but I also maintain a shared documentation library in the client's SharePoint environment that is shared with the owners. It means I update information in two places, and I am fine with that. They maintain access to documentation about their own technology.
That is intentional.
It is also one of the reasons I describe SNL-Tech Services as an IT partner, not another vendor.
What Is the Difference Between an IT Baseline Assessment and the Other SNL-Tech Services Assessments?
These services overlap because the technology overlaps, but they do not answer the same question.
SNL-Tech Services Service | What I Am Trying to Answer |
IT Baseline Assessment | What technology does the business depend on, how does the environment fit together, what needs attention, and what should be prioritized? |
Microsoft 365 Audit | How is the Microsoft 365 tenant actually configured, managed, and secured? |
Google Workspace Audit | How is the Google Workspace environment actually configured, managed, and secured? |
Cyber Insurance Readiness Assessment | Can we accurately verify the technical answers being requested on the business's actual cyber insurance questionnaire? |
AI Governance Assessment | What AI is already being used, what can it access, what risks exist, and what governance or controls should be established? |
Managed IT Services | How will the environment be maintained, monitored, documented, supported, and planned for on an ongoing basis? |
I do not want to sell a business six assessments when one of them answers the question it actually has. Sometimes a Microsoft 365 Audit uncovers the issue. Sometimes an insurance questionnaire gives us a very specific scope. Sometimes the bigger problem is that nobody has looked at the entire environment in years.
That is where the IT Baseline Assessment becomes particularly useful.
What If You Answer “I Don't Know” a Lot?
That may be the most useful result of going through this article.
“I don't know” is a finding.
It does not automatically mean something is insecure, misconfigured, or broken. Maybe the company has grown quickly. Maybe several providers have worked on different pieces.
Maybe applications were added gradually. Maybe the person who understood the environment left. Maybe the technology works perfectly well, but nobody has stepped back recently and documented how everything fits together.
The next step is not automatically to replace a bunch of technology.
It is to figure out the answers.
That is the philosophy behind the SNL-Tech Services IT Baseline Assessment. I want to establish what is actually there before I start recommending what should change.
A Checklist Is a Starting Point, Not an IT Assessment
The downloadable Small Business IT Checklist & Systems Inventory that goes with this article is designed to help a business owner identify what they know, what they do not know, and what may need further review.
It will cover the major areas discussed here, including systems, data, ownership, Microsoft 365 or Google Workspace, devices, centralized management, network segmentation, backups, business applications, AI, vendors, lifecycle planning, documentation, and cyber insurance readiness.
The checklist will deliberately use:
Yes | No | I Don't Know | Needs Review
because those answers tell us different things.
What the checklist cannot tell you is whether every technical control is actually configured correctly. It cannot validate a Microsoft 365 tenant, confirm every computer is patched and encrypted, inspect firewall rules, test backup recovery, determine whether VLAN segmentation is appropriate, or substantiate the answers on a cyber insurance application.
Those require looking at the actual environment.
The checklist helps you understand what questions need to be asked.
An assessment helps us determine what the answers actually are.
Frequently Asked Questions About Small Business IT
What does a small business need for IT?
There is no single technology stack that every small business needs. The right environment depends on how the business operates, what information it handles, where employees work, what applications it relies on, its cybersecurity risks, and any contractual, insurance, or regulatory requirements that apply. I prefer to understand those things before recommending products or architecture.
Does a small business need an IT inventory?
I think every business should have enough of an inventory to identify the technology it relies on. Current NIST small business guidance recommends identifying and maintaining inventories of hardware, software, systems, services, and important data as part of understanding cybersecurity risk.
What should a small business keep in its IT documentation?
At minimum, the business should have visibility into its important systems, devices, cloud services, network, administrative ownership, backups, vendors, and major renewal or lifecycle dates. More complex environments will require more detailed technical documentation.
Who should have access to a small business's IT accounts?
The answer depends on the system and the roles involved, but I do not like critical business assets being accessible only through an outside provider's account. A provider may appropriately administer the system, while the business retains appropriate ownership, recovery access, and documentation.
How do I know whether my IT provider is actually managing our computers?
Ask how the provider centrally manages devices, how many business computers are currently in scope, whether those devices are checking in, how updates and endpoint security are monitored, and what happens when a device stops reporting. Having an RMM or management platform does not automatically prove that every appropriate device is enrolled and being managed.
What is an RMM?
RMM stands for Remote Monitoring and Management. IT providers commonly use RMM platforms to remotely monitor and manage business computers. Capabilities vary by product and configuration, but RMM can be used for areas such as device visibility, monitoring, patching, software management, and remote support.
Does a small business need VLANs?
Not every small business needs the same VLAN architecture. VLANs can be useful for separating different types of systems or users, but the appropriate design depends on the environment. VLANs also need appropriate firewall or access control rules if the goal is to restrict communication between network segments.
What IT information should I have if I change IT providers?
The incoming provider may need information about the network, devices, servers, Microsoft 365 or Google Workspace, domain and DNS, website, firewall, backups, business applications, licensing, vendors, administrative access, and existing documentation. The exact handoff depends on the environment, but the business should not have to rediscover its entire infrastructure simply because the provider changes.
What IT information might I need for cyber insurance?
Cyber insurance applications vary, but they may ask technical questions about areas such as MFA, endpoint protection, encryption, backups, patching, email security, remote access, incident response, and other cybersecurity controls. I recommend using the actual insurer questionnaire rather than assuming a generic checklist represents that insurer's requirements.
How do I know whether my business needs an IT assessment?
An IT assessment may be useful when the business cannot clearly identify its systems, devices, administrative access, backups, security controls, network architecture, or important technology dependencies. It can also make sense before major changes, after substantial growth, during a provider transition, when preparing for insurance or compliance requirements, or when the overall environment has not been comprehensively reviewed in a long time.
How often should a small business review its IT environment?
I do not think there is one interval that makes sense for every business. Significant growth, new offices, provider changes, major software changes, insurance renewals, compliance requirements, AI adoption, or security incidents can all create reasons to review the environment. For managed clients, I prefer ongoing documentation and lifecycle planning so we are not rediscovering the environment every few years.
Knowing What You Have Comes Before Deciding What to Change
A business owner should not need to become an IT administrator to know whether the company's technology is being managed properly. What the owner needs is visibility.
What does the business depend on? Where does important information live? Who controls the accounts? Which devices are under management? Is everything that should be in scope actually in scope? What is being backed up? How is the network separated? Which providers are involved? What is coming up for renewal or replacement? What is documented? What don't we know yet?
Once we have those answers, we can make better decisions.
Sometimes the next step is a Microsoft 365 Audit. Sometimes it is a Cyber Insurance Readiness Assessment. Sometimes AI use reveals a need for an AI Governance Assessment. Sometimes the bigger issue is that nobody has looked at the entire technology environment in years, which is where an IT Baseline Assessment makes more sense.
And sometimes an assessment confirms that a lot of things are already being done well.
That is useful information too.
The goal is not to perform an assessment and find technology to sell. The goal is to understand what the business has, identify what actually needs attention, document it, and help the owner plan for what comes next.
Download the Small Business IT Checklist & Systems Inventory
I created the SNL-Tech Services Small Business IT Checklist & Systems Inventory to help business owners work through the major areas covered in this article and start documenting the technology their business depends on.
The guide includes sections for:
Business systems and cloud services
Microsoft 365 and Google Workspace
Device inventory and centralized management
RMM and endpoint visibility
Network equipment, segmentation, and VLANs
Backups and recovery
Administrative access and ownership
AI tools and connected applications
Vendors, contracts, renewals, and lifecycle planning
Cyber insurance readiness
Systems, device, vendor, and network inventory worksheets
The checklist uses Yes, No, I Don't Know, and Needs Review because identifying what you do not know is part of establishing a useful IT baseline.
Download the Small Business IT Checklist & Systems Inventory
Additional Resources
NIST Cybersecurity Framework 2.0: Small Business Quick Start Guide
NIST's official guide is designed specifically to help small and medium businesses begin managing cybersecurity risk using the Cybersecurity Framework 2.0. NIST Small Business Quick Start Guide
NIST Cybersecurity Framework 2.0 Resources for Small Businesses
NIST maintains additional CSF 2.0 resources specifically for small businesses, and its small business resource page was updated in April 2026. NIST Cybersecurity Framework for Small Business
Federal Trade Commission Cybersecurity for Small Business
The FTC provides practical small business guidance covering data protection, backups, updates, remote access, vendors, cyber insurance, network security, and other foundational cybersecurity issues. FTC Cybersecurity for Small Business




Comments