Managed IT Support
The most common IT problems small businesses face, and how to prevent each one
The IT problems UK small businesses hit most often: weak security, untested backups, ageing hardware, patchy Wi-Fi, one-person dependency and more, with fixes.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
The IT problems small businesses hit most often are weak security (no MFA, no EDR, no training), backups that have never been restore-tested, ageing hardware and unsupported software, unreliable Wi-Fi and networks, no documentation, dependence on one person, sprawling access permissions and no recovery plan. Every one is preventable with monitoring, patching, testing and someone accountable.
Most small business IT problems are the same ten problems, and all ten are preventable. This guide lists them in roughly the order we find them when auditing a new client, explains why each happens, and gives the fix. If you recognise more than three, the IT health check is the practical next step.
Security and backup
1. Weak security
The problem. No multi-factor authentication on Microsoft 365, antivirus rather than managed endpoint detection, no email filtering, no awareness training, and updates postponed because they are inconvenient. Attackers do not need to be clever in this environment.
Why it happens. The belief that a small firm is not a target. The GOV.UK Cyber Security Breaches Survey consistently finds phishing the most common attack on UK businesses of every size, because it is sent to everyone.
The fix. Enforce MFA on every account. Put managed EDR on every device. Filter email. Train staff twice a year and test them with simulated phishing. Patch on a schedule. The NCSC's Cyber Essentials five controls are the baseline, and our cyber security service is built around them.
2. Backups that have never been tested
The problem. A backup job that "runs" but has never been restored. Or a single copy on a drive in the same room as the server. Or the assumption that OneDrive is a backup.
Why it happens. Backups are set up once and forgotten. Cloud storage is mistaken for backup, when Microsoft's own shared responsibility model makes your data your responsibility.
The fix. Three copies, two media, one off site. Daily as a minimum. Monitor every job. Restore a file monthly and a system annually, and write down how long it took. Back up Microsoft 365 separately. Our backup and disaster recovery page covers the arrangement.
Hardware, software and networks
3. Ageing hardware and unsupported software
The problem. Laptops past warranty, a server on borrowed time, an operating system no longer receiving security updates, an application version the vendor stopped supporting years ago.
Why it happens. "It still works." No inventory, no warranty tracking, no refresh budget.
The fix. An inventory with purchase and warranty dates. A refresh cycle: four to five years for laptops, five to seven for servers. A budget line for it every year, so replacements are planned, not emergencies. Unsupported software is either upgraded, replaced or isolated.
4. Unreliable Wi-Fi and networks
The problem. Wi-Fi that drops in the afternoon, dead spots in the far office, a consumer router from the ISP doing a business's job, an unmanaged switch someone bought at a supermarket, and no idea what is plugged into what.
Why it happens. The network was built incrementally as the business grew, by whoever was available.
The fix. A site survey. Business-grade access points placed for coverage, a managed switch, a proper firewall, guest Wi-Fi separated from business systems, and firmware kept current. Our office Wi-Fi page describes the approach. Metre-thick walls at the Hertfordshire Golf & Country Club needed a mesh design. Most offices need less, but they need it designed.
Documentation, people and access
5. No documentation
The problem. Nobody can produce a network diagram, a device list, the admin password for the firewall or the login for the domain registrar.
Why it happens. Documentation is nobody's job, and the person who set things up knows where everything is, until they leave.
The fix. A managed provider has to document to support you, and that documentation is yours. If you manage in-house, a password manager the business controls, a device inventory and a one-page network diagram are the minimum.
6. Dependence on one person
The problem. IT works because one director, office manager or employee keeps it working. They go on leave, fall ill or resign, and the business discovers it does not know how anything works.
Why it happens. Small teams delegate IT to whoever is willing, and it becomes permanent.
The fix. Document now. Then add a second holder of the knowledge, either a provider or a colleague. This is one of the tasks that should not sit with non-IT staff, as why business owners should not be managing IT explains.
7. Sprawling access and weak passwords
The problem. Leavers with live accounts. Shared logins. Everyone with access to everything on the shared drive. Passwords on sticky notes, or the same one everywhere.
Why it happens. Access is granted to avoid friction and never reviewed.
The fix. Role-based permissions. A joiners and leavers process that removes access the day someone goes. Quarterly access reviews. MFA everywhere. A password manager. Our onboarding and offboarding service exists because this is the control that most often fails.
Patching, recovery and the support model
8. Unpatched systems
The problem. Windows updates deferred for months, browsers out of date, firewall firmware never touched, because updates are inconvenient and nobody owns them.
Why it happens. Fear of disruption, and no schedule.
The fix. Scheduled patching out of hours, tested, reported. Third-party applications included. Firewalls and switches included. This is the single most effective control against known vulnerabilities, and it is dull, which is why it needs to be someone's job.
9. No recovery plan
The problem. Nobody has written down what to do if the server dies, the office floods, or ransomware encrypts everything. When it happens, decisions are made under pressure with incomplete information.
Why it happens. Rare events feel hypothetical.
The fix. A one-page plan: critical systems, who does what, how to restore, who to call, how to tell customers. Test it once a year. Our business continuity planning service produces exactly this.
10. Reactive support and technical debt
The problem. IT is dealt with only when it breaks. Quick fixes pile up. Systems work as long as nobody touches them. Every change is frightening.
Why it happens. Break-fix arrangements, no monitoring, no reviews.
The fix. Monitoring so problems are seen early. Root-cause fixes rather than workarounds. A review a few times a year to plan what to replace. In other words, managed IT support rather than emergency calls.
The ten at a glance
| Problem | First sign | Prevention |
|---|---|---|
| Weak security | Phishing emails reaching staff, no MFA prompts | MFA, EDR, filtering, training, patching |
| Untested backups | Nobody can name the last restore | 3-2-1, monitored, restore-tested |
| Ageing hardware | Slow machines, out of warranty | Inventory and refresh cycle |
| Unreliable network | Afternoon Wi-Fi drops | Site survey, business-grade kit |
| No documentation | Nobody knows the firewall password | Documented environment, owned by you |
| One-person dependency | "Ask Dave" | Second knowledge holder |
| Access sprawl | Leavers still in the address book | Joiners and leavers process, reviews |
| Unpatched systems | Update reminders dismissed | Scheduled, reported patching |
| No recovery plan | "We'd work it out" | One-page plan, tested annually |
| Reactive support | Same faults recurring | Monitoring, root-cause fixes, reviews |
What to do next
If three or more of these apply, an IT health check will confirm which, rank them by risk, and give you a prioritised plan that starts with security and backup. It is the same assessment a new provider runs in the first weeks, without the commitment.

