An IT baseline is the practical minimum that keeps a small business supportable. It defines what should be watched, patched, backed up, documented, and owned before the business is forced to figure it out during an outage or security incident.
Start with ownership
The first question is not which tool to buy. The first question is who owns the condition of the environment. Someone should know which systems matter, who has admin access, where documentation lives, which vendors are involved, and what needs attention next.
Without ownership, small problems become permanent background noise. Passwords stay shared, old accounts remain active, backups go untested, and nobody is fully sure what changed.
Identity and access
For most small businesses, identity is the front door. Microsoft 365, email, file access, business applications, VPNs, and administrator accounts should be reviewed regularly.
- Multi-factor authentication for important accounts
- Named user accounts instead of shared logins where practical
- Admin access limited to people who actually need it
- Old employee and vendor accounts removed promptly
- Recovery email and phone settings reviewed before they are needed
Endpoints and patching
Laptops, desktops, and servers drift over time. A baseline should include visibility into devices, patch status, security software, disk health, and obvious failure signs.
Patching does not need to be dramatic, but it does need a rhythm. Updates should be applied, failed updates should be noticed, and business-critical systems should be handled with enough care that maintenance does not create avoidable downtime.
Backups and recovery
Backup status alone is not enough. A business needs to know what is backed up, how often it is backed up, who receives alerts, how long data is retained, and what a realistic recovery path looks like.
The key question is simple: if something important failed today, would recovery be a known process or a guess? A baseline should include restore validation, not just a green dashboard.
Microsoft 365 and email hygiene
Microsoft 365 often becomes the center of a small business. Email, calendars, file sharing, Teams, identity, licensing, and device access all need routine review.
- Licensing matched to actual users and needs
- Mailbox and forwarding rules reviewed for risk
- External sharing understood and controlled
- Security defaults or equivalent protections enabled where appropriate
- Tenant admin access documented and limited
Documentation
Documentation is not busywork. It is what keeps the business from being trapped when a vendor changes, an employee leaves, or a system fails.
At minimum, documentation should cover vendors, domains, DNS, internet service, network equipment, core applications, backup systems, admin access ownership, support contacts, and recurring procedures.
Security basics
A small-business security baseline should focus on the controls that reduce common risk without overwhelming the business. That usually means identity protection, patching, endpoint protection, backups, least-privilege access, and clear response steps if something suspicious happens.
The goal is not to make security complicated. The goal is to make the obvious risks harder to ignore.
Vendor and account control
Domains, hosting, phone systems, internet accounts, software subscriptions, and line-of-business applications should not be mysteries. The business should understand who owns each account, how billing works, who can make changes, and what happens if a vendor relationship ends.
What the baseline should produce
A working IT baseline should produce fewer surprises. It should make support easier, reduce repeated issues, and give the business a clearer view of what is stable, what is fragile, and what should be planned next.
For RhubArx, this is the purpose of managed IT oversight: maintain the baseline, reduce recurring problems, and keep the environment supportable over time.