If a work laptop is left in a car, the questions go beyond replacing the equipment. You need to consider what business information is on it and which accounts someone could reach through it. Thinking through a familiar situation gives you a concrete way to ask about the protection your business has.
If your policy says only certain employees can open customer files, ask to see who can open them today. If it says work computers must receive updates, ask which computers have received them and which still need attention.
Check the controls in use.
Choose a file your business needs, such as the customer list or payroll spreadsheet, and ask who can open or change it. Does anyone who no longer needs it still have access, and who must approve folder access for a new employee?
If your policy says only the bookkeeper and owner can open payroll files, ask whether anyone else can get into that folder. For computer updates, ask whether every work laptop is managed, including the one an employee uses at home, and which machines still need updates.
Use these questions during the review:
- Who can open important business files or sign in to key accounts, and when was that access last reviewed?
- Which work computers receive updates, including laptops used at home, and who checks for missing updates?
- Are our invoices, customer files, and business applications backed up, and what would we need to get them back after data loss?
- If security software flags a suspicious sign-in or file, who looks into it, and how do we find out what happened?
For backups, ask where your invoices, customer records, and other essential files are saved, then check whether each location is backed up. A file on someone’s laptop may need different backup arrangements from a shared folder, so ask what you’d need to get either one back after data loss.
If nobody can answer one of these questions, write it down and ask for an answer. Keep it on the list until someone can explain the account settings or show which folders the backup includes.
Know who handles security alerts.
If your security software flags an unusual sign-in, ask who sees the warning and looks into it. You need to know whether someone checks what happened, rather than assuming the software takes care of everything once it raises an alert.
Ask how an employee should report a password reset they didn’t request or an email asking them to enter their password. What should they send or describe so the person looking into it can understand what they saw?
Could an employee find the number or request form when a suspicious email arrives? Ask whether they can report it even if they haven’t clicked anything and aren’t sure it’s dangerous, so they don’t have to diagnose the problem before asking for help.
Prioritize the gaps.
If nobody knows whether a folder is backed up, find out what’s in it and whether losing it would stop billing or other work. If an account belongs to someone who no longer needs it, ask about removing that access. Use those answers to decide which problems need attention first.
The basics deserve attention because Geekland IT has found gaps in those areas during real reviews. Ask whether every account uses multi-factor authentication and whether anyone, including the owner, uses an account with full administrator rights for everyday work. Check whether passwords are kept in a text file on someone’s desktop or several people share a login with a weak password.
When Geekland IT recommends turning on multi-factor authentication or changing administrator access, we explain what problem the change would address and why it should come first. You can also ask us which accounts it would affect and what else you would still need to check afterward.
Agree who will make each change, such as removing an old login or turning on multi-factor authentication, and when you’ll check progress. Keep the list and the answers so you can ask which changes are finished and which still need work.
Back to resources