What Good Backup Actually Looks Like for a Small Business
A staff member deletes a shared client folder on Friday. Nobody notices until Monday.
Can you get it back? How far back? How long will it take?
Most businesses have never answered those questions. They assume "it's in the cloud" covers it.
Cloud sync helps with everyday mistakes. But it mirrors changes in both directions. If something gets deleted, encrypted, or corrupted, that change can travel to the synced copy too.
Good backup comes down to five things:
It covers what the business actually depends on. It creates a copy that is independent of the original. It keeps enough history to catch problems that are not found right away. It survives if something happens to the office. And someone has actually tested restoring from it.
That last one matters more than people expect. A backup that has never been used to restore anything is a hope, not a plan.
The first step is not buying a product. It is answering a few honest questions about the current setup.
When an Employee Leaves: What to Handle on the Technology Side
An employee leaves.
Do you know every system they can still log into?
In most small businesses, the answer is no. Not because anyone is careless, but because nobody owns the process.
Here's the thing most offboarding advice misses: removing access and preserving the business's information are two different tasks. A former employee's email might contain months of client correspondence your team still needs. Their files might hold the only copy of an ongoing project. Disabling everything without a plan creates one set of problems. Leaving everything active creates another.
The better approach starts with three questions:
Who inherits this person's work?
What access needs to stop today?
What business information needs to stay available?
A short, repeatable process built around those questions turns a stressful moment into a manageable one.
New post on the blog covers the three things to get right when someone leaves your team.
What to Set Up Before Your New Hire's First Day
Your new employee starts Monday.
Is everything they need actually ready?
In most small businesses, there's no single person whose job it is to think about technology setup for a new hire. So it gets improvised. Someone scrambles to create an email account. A shared login gets passed along "for now." Security steps get skipped because there's not enough time.
That's not a failure. It's what happens when nobody owns the process.
The fix isn't complicated. It's a short set of decisions made before day one:
Does this person have their own email and their own login to every system?
Is two-step verification set up before they start, not "whenever they get around to it"?
Does the device they're using meet a basic standard?
Is any of this written down?
The difference between a first day that works and one that doesn't isn't budget. It's whether someone thought through the steps ahead of time.
Password management and access control for small businesses.
Every browser asks the same question: "Save this password?"
Most people click yes. And for personal use, that is fine.
But in a business, that quiet habit creates problems nobody sees until something breaks.
The real issue is not whether your team uses Chrome, a spreadsheet, sticky notes, or the one person in the office who "knows all the logins."
The issue is that your business probably cannot answer three questions:
Who has access to what?
How do you revoke access when someone leaves?
How do you recover access if someone is unavailable?
A purpose-built password manager solves all three. But not every option is built for business use.
This week on the blog, I walk through what to look for, which options hold up under scrutiny, and the one provider with a track record that should disqualify it from consideration.
The Technology Conversation Every New Business Should Have (and Almost Nobody Does)
Nobody starts a business by mapping out their technology decisions.
You open the LLC, sign the first client, and work with whatever you have. A personal Gmail. A laptop from Best Buy. A password on a sticky note.
That works for a while. Then it doesn't.
Here's what I see most often when businesses come to me in year two or three:
Business email is tied to a personal Gmail account.
The domain is registered under a contractor's account nobody talks to anymore.
Files are scattered across personal Dropbox, email attachments, and USB drives.
Nobody's sure who has the master passwords to anything.
Backups don't exist.
None of these are hard to set up correctly from the start. All of them are painful to fix later.
The technology decisions you make in year one aren't dramatic. They're quiet. But they compound.
If you're in your first few years of business, it's worth pausing to ask one question: does the business actually own its technology, or is it borrowing access from individuals?
What Actually Happens When a Laptop Gets Stolen
A laptop disappears from your business tomorrow. What happens in the next 24 hours?
Not the dramatic version. The real one.
The first 15 minutes: Can anyone confirm what was on it? Was it encrypted? Were passwords saved in the browser? Can someone open your email without logging in again?
The next hour: Who is changing passwords, and in what order? Were files backed up, or did critical documents live only on that device? Does your industry require you to notify clients?
The next day: Can you document what protections were in place when you file the insurance claim? Can you tell the employee who lost it that the data was secure?
Every one of those questions has a clear, calm answer when a few basics are already configured. Encryption. Cloud storage. A password manager. Remote device management.
The hard part is not the tools. It is making sure they are set up on every device, verified regularly, and documented well enough to hold up when it matters.
Why I Left Enterprise IT to Work With Small Businesses
Nobody at a big tech company ever decided to ignore small businesses.
Nobody had to. It just happens.
I spent 25 years inside Dell, Microsoft, Unisys, and Apple. Great companies, great training, and the same pattern everywhere I looked:
Big vendors often assume a small business wants a shrunken enterprise product. It doesn't. A 10-person firm doesn't need less enterprise. It needs different.
Success gets measured in survey scores averaged across millions of customers. At that scale, one small firm's frustration rounds to zero.
Meanwhile, the best parts of my career were the opposite of that. Sitting next to someone at their desk, learning how they actually use technology day to day. That is where the real work is.
Here's the part that surprised me most: even the local IT providers who say "small business" often mean 50+ employees. Many have minimums a 6-person firm falls below.
So the true small business fends for itself. The office manager becomes the accidental IT person. And honestly? Those office managers are heroes. They keep businesses running with no training, no budget, and no backup. They deserve backup.
I left enterprise IT to work for exactly those businesses. I wrote about why, including the Apple story that first made the problem impossible for me to unsee.
Are You Using the AI You Already Pay For?
Most businesses are already paying for AI they have never turned on.
Not a separate subscription. Not a new tool. Features sitting inside software they already use every month.
Microsoft 365. Google Workspace. QuickBooks. Zoom. Canva. HubSpot.
All of them have added AI features in the last year or two. Many of those features are included in the plan you are already on.
The problem? They ship quietly. No walk-through. No popup. Just a feature buried in settings that nobody told you about.
Before you go buy another AI subscription, take an hour and check what you already have.
I put together a full walk-through of common business tools with built-in AI, what is included versus what costs extra, and what to watch out for before connecting AI to your live business data.
What Changes When You Stop Waiting for Things to Break
Most small businesses handle IT the same way.
Something breaks. Someone fixes it. Everyone moves on.
There is nothing wrong with that approach. It is how almost every business starts.
But as the team grows, a few things start to shift:
Every time you call for help, the person on the other end is starting from scratch. No history. No context. No idea what changed since last time.
Nobody is watching for the small issues that quietly build into big ones.
And IT costs become impossible to predict. A quiet month costs nothing. A bad month is three emergency invoices plus a lost afternoon.
The core difference with managed support is not more technology. It is that someone is paying attention between the emergencies.
The five-minute security check every small business should do today
Most small businesses are not one catastrophic mistake away from a security incident.
They are one overlooked detail away.
A former employee whose account was never closed. A router that has not been updated since it was installed. A password manager that everyone agreed to use and nobody has opened since.
Three things worth checking today, no technical background required:
1. Are your accounts actually protected?
Not just "do you have a password manager" but are you using the audit feature? Most people have never run it. It is usually eye-opening.
2. Do you know who still has access?
Changing a password does not remove someone's login. Former employees, old contractors, file storage tools like Dropbox that nobody manages anymore. Access tends to outlive the relationships it was created for.
3. Are your devices still getting security updates?
Windows 10 support ended in October 2025. A lot of small business machines are currently running an unsupported operating system with no patches coming. Most owners have not been told that in plain terms.
None of these require a consultant. They just require an honest look.
The Solid Footing Self-Assessment
A question worth sitting with:
If the most important laptop in your business disappeared tonight, what would tomorrow look like?
A few more in the same spirit:
If someone left your company today, could you remove their access to every business account before end of day?
Does every person on your team have their own login, or are some accounts shared?
Is your business data stored somewhere other than individual devices?
Do you have a backup? Have you ever tested whether it actually works?
If your internet went out this morning, how long before your team could not do their jobs?
Most business owners have a gut sense that things could be tighter. Very few have ever looked at it all in one place.
If you answered no to more of those than you expected, that is actually useful information. You now know where to start looking.