When we walk into a new company, it is hardly ever because everything is on fire. It is usually because somebody in management has spent months with the feeling that IT “isn’t quite right” and cannot put a name to it.
These five signs are usually that name.
1. Nobody can tell you what you have
If you ask how many servers you have, which operating system version they run or which licences you are paying for, and the answer takes more than a day, you do not have an inventory problem: you have a control problem.
2. Everything depends on one person
There is one person — in-house or external — who is the only one who knows how it is all put together. It works fine until the day they go on holiday, change jobs or fall out with you. Documentation is not bureaucracy, it is the way to stop the knowledge walking out of the door.
3. The same incidents keep coming back
The same machine that freezes every week, the same printer that vanishes from the network, the same folder that loses its permissions. If an incident keeps repeating, it is not being resolved: it is being papered over. Somebody has to go after the cause.
4. Buying happens in a panic
If your criterion for buying a server is “the other one broke”, you are always paying the price of haste: worse negotiation, worse technical choice and zero planning. A three-year refresh plan costs the same and hurts far less.
5. Nobody has looked at security from the outside
Plenty of small businesses have ports open that they do not know are open, remote desktops exposed to the internet, or accounts belonging to people who left two years ago and are still active. None of it shows its face until it shows it all at once.
What an audit does, specifically
- A real inventory of machines, servers, licences and contracted services.
- A configuration review: network, permissions, backups, updates.
- Detection of single points of failure and of the surface exposed to the internet.
- A report that management can understand, with prioritised risks and the cost of fixing them.
The important thing is not the report: it is that somebody then carries out the plan. A report filed away in a drawer has never protected anybody.



