The 3 Things Companies Without an IT Department Should Do First: How to Reliably Reduce Your Company's IT Risks Starting Today
*At the end of this article, we also introduce a video that summarizes the content in 30 seconds.
"We don't have an IT person... I don't know where to start."
There are many small and medium-sized enterprises that are somehow managing their daily operations while harboring such anxieties.
Actually, this is not a special case, but "a daily problem occurring in every company." However, it is also a concern that is difficult to bring to the surface.
But don't worry.
Even without an IT person, there are only three things you should do first to protect your company.
No difficult technology is required, and I have summarized the content that you can start working on today as clearly as possible.
1. Organizing Accounts
Visualize "who is using what"
The first step is very simple, but it is neglected in many companies.
What cloud services are employees using?
Are accounts for email, attendance, accounting, and file management organized?
Are there any accounts left behind by former employees?
If accounts are not organized, a dangerous situation where former employees can still log in happens normally.
First, paper or Excel is fine.
Start by creating a list of services and users used by the company.
2. Reviewing Access Rights
Eliminate "people who shouldn't see it being able to see it"
The following situations are common in small and medium-sized enterprises.
Personal information folders are visible to all employees
President folders can be opened by general employees for some reason
Shared folders are not organized and are full of lost files
This may seem like a small problem, but it can actually become a gateway to information leaks. At a minimum, let's set up at least the following three things.
Separate "viewing" and "editing" for each employee
Personal information and payroll files are inaccessible to anyone other than those involved
Always set an expiration date for external sharing links
You don't need any special knowledge.
Simply drawing a line between "who can see it" and "who cannot" will significantly reduce your risk.
3. Establishing a backup system
Always protect the things you can't afford to lose
Backups are often thought to be difficult, but the concept is very simple.
Always save data you can't afford to lose in two places.
The recommended combination is the following two:
Cloud (OneDrive / Google Drive)
External HDD (a reliable one)
Conversely, USB flash drives are absolutely a no-go.
They carry a high risk of loss, damage, and viruses, and recovery is difficult.
◆ In companies without an IT department, protect with "systems" rather than "individuals"
In companies without an IT department, management tends to be left to individuals.
But in reality,
protecting with systems = IT management that can continue even without a dedicated person
This is the optimal method for small and medium-sized enterprises.
For example,
Manage accounts in Excel → Review them once a month
Always separate folder permissions into "view" and "edit"
Automate backups to create a "state of being protected automatically"
Just by getting these three things in order, you can prevent 90% of accidents.
Summary: Just these first three things will dramatically lower your company's IT risk
Organize accounts
Review access rights
Perform backups
These three things can definitely be implemented even in companies without an IT department.
And with just this, your company's IT environment will be one step closer to being in a 'protected state'.
IT is not something 'difficult'.
By accumulating small improvements, you can create an environment where you can work with peace of mind.
◆ For those who want to know only the main points in 30 seconds
I have summarized the content of this article into a 30-second short video.
If you don't have time to read, or if you just want to know the big picture first, please take a look here.
📖 Recommended Reading
💬 Click here for consultations
At IT Work Lab, we provide comprehensive support for
account organization
permission design
backup maintenance
establishing operational rules for PCs and cloud services
and other aspects of building a foundation for companies without an in-house IT person.
On-site support is also available for the Hachioji and Tama areas.
Please feel free to consult with us, even if you are at the stage of asking, 'Where should I start?'
いいなと思ったら応援しよう!
いつも読んでいただき、ありがとうございます。
役に立った!と感じていただけたら、チップで応援していただけるとうれしいです。今後の記事づくりに活用させていただきます。