1. Your 'IT person' is whoever is least scared of computers
Someone in the office has become the de facto IT department because they once fixed the printer. They're not trained for it, it's not their job, and every hour they spend on it is an hour off their actual role. When IT is a side-task for a staff member, nobody owns it — and the things that need owning (updates, backups, security) don't happen.
2. Nobody is sure whether backups are working
Ask three questions: Is there a backup? When did it last run? When did anyone last restore something from it? If any answer is 'I think so', 'not sure' or 'never', you don't have a backup — you have a hope. This is the single most common gap we find, and the one with the worst consequences.
3. Staff share passwords or use the same login for everything
Shared logins mean no accountability and no way to remove access when someone leaves. Reused passwords mean one breach anywhere becomes a breach everywhere. If you couldn't say with confidence that every staff member has their own login with multi-factor authentication, this is a sign.
4. Updates get postponed indefinitely
Windows wants to restart. Staff click 'remind me later'. Forever. Every unapplied update is a known vulnerability with a published fix that you haven't installed. Attackers scan for exactly these. Nobody in a break-fix arrangement is responsible for making updates happen.
5. You've had at least one scare
A phishing email that nearly worked. An account that got locked out. A laptop that went missing. Ransomware at a business you know. A scare is the universe giving you a free warning. Most businesses that suffer a serious incident had a scare first and did nothing.
6. Every IT problem becomes your problem
The owner as escalation point for every tech issue is unsustainable past a handful of staff. If you're being pulled out of meetings to look at someone's frozen Outlook, that's a business process failure, not a technology one.
7. Someone has asked about your security and you didn't have an answer
An insurer's renewal questionnaire. A larger client's supplier assessment. A government contract's Essential Eight requirement. If you've been asked about multi-factor authentication, endpoint protection or backup testing and had to say 'I'll find out', that's the market telling you what's expected now.
What to do about it
You don't have to fix all seven at once. Start with the ones that hurt most — usually backup and MFA — and build from there. A free IT health check will show you exactly where you stand. From there, managed IT is the way to make sure these things stay fixed rather than drifting back.
TechFix Pro Managed
Find out where your business actually stands.
Free 15-minute IT health check for Sydney businesses. One workstation, your Microsoft 365 tenant, a plain-English report. No obligation.
Frequently asked questions
How many of these signs mean I need managed IT?
Three or more, and it's worth a serious conversation. If sign 2 (backups) or sign 3 (shared passwords) applies, address those immediately regardless.
We're a small team — surely we're not a target?
Small businesses are targeted precisely because their security is assumed to be weak. Automated attacks don't care about your size; they care whether the door is open.
Related articles
