Most advice about improving internal IT is written at a level of abstraction that makes it impossible to act on. “Align technology with business objectives” is not a task anyone can start on a Tuesday.
These ten are things you could begin this week. None of them require a big budget, and several require no budget at all.
1. Write down what you actually have
Every improvement downstream depends on this, and almost nobody has it accurately. Devices, who holds them, what software is installed, what subscriptions are being paid for, which systems hold customer data, and who has administrative access to each.
The surprises are usually in the licensing — software paid for and unused, or used and unpaid for — and in the accounts belonging to people who left two years ago.
2. Fix the thing people complain about most, first
Ask ten people what wastes the most of their time. You will hear the same three or four answers: logging in takes forever, the shared drive is slow, the file I need is impossible to find, the printer.
Fix the loudest one properly before starting anything strategic. It buys credibility for everything that follows, and the strategic project will go better for it.
3. Standardise how machines are built
If every laptop was configured by hand, every laptop is subtly different, and every support call starts with archaeology. One standard build — same operating system version, same core applications, same settings — turns most support from investigation into recognition.
It also means a replacement machine can be in someone’s hands in an hour rather than a day.
4. Get starters and leavers onto a written process
This is the single most common gap we find, and it has consequences in both directions. New people spend their first week unable to do their job, which is expensive and demoralising. People who have left keep working accounts, which is a security problem and occasionally a legal one.
The fix is a checklist and a named owner, not a system.
5. Turn on multi-factor authentication everywhere
Everywhere means everywhere: shared mailboxes, service accounts, the third-party CRM, and the senior person who asked to be exempted. Partial MFA mostly tells you where the attacker will go.
6. Restore something from backup this quarter
Backups fail silently and are usually discovered to have been failing at the worst possible moment. A backup that has never been restored from is a belief rather than a control.
Pick a file, restore it, time how long it took, and write the number down. Then do the same with something larger once a year.
7. Find out what unapproved software people are using
Somebody is using a personal Dropbox, a free PDF converter, or an AI tool nobody approved. Banning it does not work; it just moves the activity somewhere less visible.
Ask instead, without consequences attached. The answer tells you exactly where the approved tools are failing, and that is genuinely useful information.
8. Patch on a schedule everyone knows about
Not “we have automatic updates on”. A known window, applied consistently, with someone who would notice if a machine stopped reporting in. Under the current Cyber Essentials requirements, high-risk patches must land within fourteen days, which is only achievable as a process.
9. Measure one thing
Ticket volume grouped by cause is the most useful single number a business can start tracking. It turns “IT is frustrating” into “forty per cent of our tickets are password resets”, which is a problem with an obvious solution.
Without it, every improvement is chosen on instinct and no improvement can be shown to have worked.
10. Decide who owns IT decisions
Not who fixes things — who decides. What gets bought, what gets replaced, what risk is acceptable, what the budget is for.
Where this is unowned, IT drifts by default, and it drifts regardless of how capable the people supporting it are. This is the tip that costs nothing and changes the most.
The ten, as a checklist
Tick what is genuinely true today rather than what is planned. The unticked ones are your shortlist.
If the list is longer than the time available
Do one, two and six. An accurate inventory, one visible fix, and a tested restore will tell you more about the state of your IT — and buy you more goodwill — than any amount of planning.
If you would rather someone went through this with you, that assessment is how most of our client relationships start, and it comes with no obligation to do anything about what we find.





