Is your IT keeping up with your business? Four risks that emerge as SMEs grow…
The gap between business growth and IT maturity is often biggest in SMEs. Why? Because they typically go through periods of quick growth during which IT is retrofitted to support the expansion.
And because it tends to be done on the fly, a lot of the IT environment is pieced together without a clear strategy, which in turn means it doesn’t support the organisation as well as it might in the future. You can see how this reinforces over time.
Think that might be you? Here’s four things we’d recommend to set your IT straight.
Maintain an asset register
As your company grows, you may find that departments will acquire software, cloud services and devices independently. It means you’ll no longer know which department owns what, how it’s managed, and what data it contains. Crucially, you may not know what security risks those tools create either.
Industry best practice is to log hardware, software, removable media and third-party services in an asset and application register. Guidance from the NCSC, says that the log should show each asset’s purpose, location and owner, as well as the systems and business activities that depend on it. This makes it easier to identify obsolete devices, duplicated software and unapproved cloud applications.
Our advice is to maintain a single register that covers all software, hardware, apps, licences and suppliers, as well as the owner, renewal date and support status. Review it quarterly and cross-check it whenever anyone moves department or leaves the business.
Formalise the new starter, mover and leaver process
With the above point in mind, you need a formal means of connecting HR and IT processes. SMEs often grant access to IT assets informally, but as headcounts rise you run the risk of a) losing track of who can access what, and b) major security breaches.
Best practice guards against and ensures that:
- New employees receive only the access their role requires.
- Permissions are reviewed when somebody changes role.
- Accounts, sessions and third-party access are removed promptly when someone leaves.
- Administrative access is restricted and reviewed separately.
- Multi-factor authentication is applied to important systems.
As a minimum, you should review user and privileged accounts every month, removing those that are old, unused or unrecognised. Microsoft has some really useful guidance on getting this going.
Standardise and manage every business device
If you buy a lot of equipment during expansion, you’ll have a mixed bag of assets. You’ll have new and old laptops, personal phones, inconsistent software versions and devices configured by different people and different departments. This can make support costs skyrocket and makes patching/updates difficult too.
Best practice in this scenario is to establish a standard set of approved devices and configurations, and manage them centrally. Additionally, enable automatic security updates and define a replacement point for equipment that is no longer supported. You’ll also need a clear policy on use of personal devices for work activities.
Have a recovery plan…and test it
Not enough companies take recovery seriously. Most will suffer a security breach at some point in their lifetime, but very few have a decent recovery plan in place. Don’t be one of them. If you aren’t prepared for a breach, it can cause serious damage to all aspect of the business and your wider supply chain.
At a very basic level you should at least be able to identify your essential systems and their status, establish who is responsible for managing recovery, and have a plan of action to limit and contain any external threat. That plan needs to be documented, tested and reviewed at least quarterly (our forthcoming eBook documents this process). It also needs to grow and adapt with the company – don’t set and forget.
This isn’t something that should be left to chance. A growing company becomes more dependent on its systems, but its backups may not reflect that – don’t let that be you.
Generally speaking, growth introduces new devices, systems and users, but the controls around them don’t always follow. Regularly reviewing your IT environment is therefore essential to expose emerging risks before they become costly problems.
