Is IT Governance Necessary for Companies with 10 or Fewer Employees? An Introduction to IT Management for SMEs
"Isn't IT governance something for large corporations?"
"I don't feel like such an elaborate system is necessary when we don't even have 10 employees."
"We haven't had any particular trouble so far, so I'm putting it off."
For business owners who think this way, that very mindset is actually the most dangerous state for IT management in a small company.
The term IT governance sounds difficult, but
in short, it means "deciding who manages the company's IT and how." is what it is.
Even with 10 or fewer employees, as long as you are using PCs or cloud services, a minimum level of management is necessary. This article provides a simple explanation of the basics of IT management that small and medium-sized enterprises should establish first.
1. What is IT Governance?
There is no need to think of IT governance as difficult.
It is sufficient if the following three points are in place.
Knowing who is using which IT tools
Having rules in place for how information is managed
Deciding who will respond when a problem occurs
A state where these three are not in place is a "state without IT governance."
In companies with fewer employees, the impact of each individual is greater, so basic management is even more important for SMEs.
2. Why "We haven't had any trouble" is the most dangerous reason
Even if IT governance is not in place, problems usually do not surface in daily operations.
However, when "something happens" like the following, problems will erupt all at once.
When an employee resigns
If you do not know who has access to which systems, you will fail to delete the accounts of departing employees. There is a risk that former employees will continue to have access to company systems even after they leave.
When a data breach occurs
If you do not know "which data is stored where" or "who has access to what," you cannot identify the scope of the damage. Response will be delayed, and the damage will spread.
When a person in charge is suddenly absent
In a situation where "only Mr. Yamada knows the password for that system," operations will stop the moment that person is absent.
When the company grows
As the number of employees increases, you will no longer be able to manage things if you are just "using them somehow." If you try to build a system later, it will take a huge amount of time to organize.
3. IT Management Essentials for Companies with 10 or Fewer Employees: 5 Basics
Basic 1: Create an Inventory of IT Tools and Services in Use
First, list all the IT tools and cloud services used by the company. Not knowing what is being used is the biggest blind spot in IT management.
Items to include in the list:
Service name
Employees/departments using it
Account administrator
Monthly cost
Cancellation/renewal dates
Simply reviewing this list once a year can prevent wasteful payments for unused services and prevent oversight in managing accounts for departed employees.
Basic 2: Manage Passwords at the Organizational Level
The practice of "everyone manages their own passwords" carries higher risks for SMEs. If a person in charge leaves or takes sudden leave, a situation arises where no one can log in.
What to do:
Introduce a password management tool (such as 1Password or Bitwarden)
Centralize the management of IDs and passwords for services used by the company
Ensure that multiple administrators can access the system
End the practice of managing passwords in personal notebooks, Excel files, or sticky notes today.
Basic 3: Standardize Data Storage Locations
Having data scattered across individual PCs, personal USB drives, and various cloud services is a breeding ground for information leakage risks and dependency on specific individuals.
What to do:
Standardize on company-approved cloud storage (e.g., OneDrive, Google Drive)
Prohibit local storage and USB drive storage as a general rule
Organize the folder structure so that anyone can find what they need
A simple rule like "place data in the cloud where everyone can access it" solves many problems.
Basic 4: Keep access permissions to the minimum necessary
A state where "everyone can access all data" may seem convenient, but it is actually highly risky. The ideal state is one where only the people who need the data can access it.
To-do:
Grant access permissions only to folders and systems necessary for work
Review access permissions upon resignation or transfer
Prepare folders that only management or supervisors can access
Simply moving from a state where "anyone can see everything" to one where "only necessary people can see it" significantly reduces the risk of information leakage.
Basic 5: Determine contact points and response flows for IT troubles
In companies with 10 or fewer employees, there is almost never a dedicated IT staff member. That is why it is important to decide in advance "who to report to, what to report, and how" when a problem occurs.
Things to decide:
Designate an internal IT person (or someone who handles it as a secondary duty)
Determine external contact points (such as IT support companies) for troubles that cannot be handled internally
Summarize the reporting flow for "emergency troubles" and "normal troubles" on a single sheet
"Just call the president if you have a problem" not only increases the burden on management but also slows down the response.
4. How to solve the problem of "having no IT staff"
The most common concern in companies with 10 or fewer employees is the problem of "having no IT staff".
Option 1: Appoint an employee who is knowledgeable about IT as the person in charge
Specialized knowledge is not required. Simply entrusting basic IT management to an employee who is more comfortable with IT than others can lead to significant improvements. Supplementing their knowledge with external training or online learning is also effective.
Option 2: Contract with an external IT support company
You can utilize an "IT consultant" service that acts as an external IT representative for a monthly fee. By having an external partner you can consult only when you have trouble, you can create a secure system even without a dedicated staff member.
Summary: It is too late to manage IT after something happens
The fewer employees you have, the greater the damage when IT management is not in place.The state of "not having any trouble right now" might just mean that problems are not yet visible.
Start today by creating a list of the IT tools used in your company. Just doing that will give you an overview of your IT management and naturally reveal what needs to be done next.
📖 Recommended Reading
💬 Contact Us Here
At IT Work Lab, we provide support for SMEs, including:
Diagnosis and improvement support for current IT management systems
Ongoing support as an external IT representative (IT consultant)
Review and development of overall internal IT rules
If your company does not have an IT staff member, please feel free to consult with us.
The initial consultation is free.
いいなと思ったら応援しよう!
いつも読んでいただき、ありがとうございます。
役に立った!と感じていただけたら、チップで応援していただけるとうれしいです。今後の記事づくりに活用させていただきます。