Skip to main content
Dig IT Solutions logo

Managed IT Support

The most common IT problems small businesses face, and how to prevent each one

The IT problems UK small businesses hit most often: weak security, untested backups, ageing hardware, patchy Wi-Fi, one-person dependency and more, with fixes.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

The IT problems small businesses hit most often are weak security (no MFA, no EDR, no training), backups that have never been restore-tested, ageing hardware and unsupported software, unreliable Wi-Fi and networks, no documentation, dependence on one person, sprawling access permissions and no recovery plan. Every one is preventable with monitoring, patching, testing and someone accountable.

Most small business IT problems are the same ten problems, and all ten are preventable. This guide lists them in roughly the order we find them when auditing a new client, explains why each happens, and gives the fix. If you recognise more than three, the IT health check is the practical next step.

Security and backup

1. Weak security

The problem. No multi-factor authentication on Microsoft 365, antivirus rather than managed endpoint detection, no email filtering, no awareness training, and updates postponed because they are inconvenient. Attackers do not need to be clever in this environment.

Why it happens. The belief that a small firm is not a target. The GOV.UK Cyber Security Breaches Survey consistently finds phishing the most common attack on UK businesses of every size, because it is sent to everyone.

The fix. Enforce MFA on every account. Put managed EDR on every device. Filter email. Train staff twice a year and test them with simulated phishing. Patch on a schedule. The NCSC's Cyber Essentials five controls are the baseline, and our cyber security service is built around them.

2. Backups that have never been tested

The problem. A backup job that "runs" but has never been restored. Or a single copy on a drive in the same room as the server. Or the assumption that OneDrive is a backup.

Why it happens. Backups are set up once and forgotten. Cloud storage is mistaken for backup, when Microsoft's own shared responsibility model makes your data your responsibility.

The fix. Three copies, two media, one off site. Daily as a minimum. Monitor every job. Restore a file monthly and a system annually, and write down how long it took. Back up Microsoft 365 separately. Our backup and disaster recovery page covers the arrangement.

Hardware, software and networks

3. Ageing hardware and unsupported software

The problem. Laptops past warranty, a server on borrowed time, an operating system no longer receiving security updates, an application version the vendor stopped supporting years ago.

Why it happens. "It still works." No inventory, no warranty tracking, no refresh budget.

The fix. An inventory with purchase and warranty dates. A refresh cycle: four to five years for laptops, five to seven for servers. A budget line for it every year, so replacements are planned, not emergencies. Unsupported software is either upgraded, replaced or isolated.

4. Unreliable Wi-Fi and networks

The problem. Wi-Fi that drops in the afternoon, dead spots in the far office, a consumer router from the ISP doing a business's job, an unmanaged switch someone bought at a supermarket, and no idea what is plugged into what.

Why it happens. The network was built incrementally as the business grew, by whoever was available.

The fix. A site survey. Business-grade access points placed for coverage, a managed switch, a proper firewall, guest Wi-Fi separated from business systems, and firmware kept current. Our office Wi-Fi page describes the approach. Metre-thick walls at the Hertfordshire Golf & Country Club needed a mesh design. Most offices need less, but they need it designed.

Documentation, people and access

5. No documentation

The problem. Nobody can produce a network diagram, a device list, the admin password for the firewall or the login for the domain registrar.

Why it happens. Documentation is nobody's job, and the person who set things up knows where everything is, until they leave.

The fix. A managed provider has to document to support you, and that documentation is yours. If you manage in-house, a password manager the business controls, a device inventory and a one-page network diagram are the minimum.

6. Dependence on one person

The problem. IT works because one director, office manager or employee keeps it working. They go on leave, fall ill or resign, and the business discovers it does not know how anything works.

Why it happens. Small teams delegate IT to whoever is willing, and it becomes permanent.

The fix. Document now. Then add a second holder of the knowledge, either a provider or a colleague. This is one of the tasks that should not sit with non-IT staff, as why business owners should not be managing IT explains.

7. Sprawling access and weak passwords

The problem. Leavers with live accounts. Shared logins. Everyone with access to everything on the shared drive. Passwords on sticky notes, or the same one everywhere.

Why it happens. Access is granted to avoid friction and never reviewed.

The fix. Role-based permissions. A joiners and leavers process that removes access the day someone goes. Quarterly access reviews. MFA everywhere. A password manager. Our onboarding and offboarding service exists because this is the control that most often fails.

Patching, recovery and the support model

8. Unpatched systems

The problem. Windows updates deferred for months, browsers out of date, firewall firmware never touched, because updates are inconvenient and nobody owns them.

Why it happens. Fear of disruption, and no schedule.

The fix. Scheduled patching out of hours, tested, reported. Third-party applications included. Firewalls and switches included. This is the single most effective control against known vulnerabilities, and it is dull, which is why it needs to be someone's job.

9. No recovery plan

The problem. Nobody has written down what to do if the server dies, the office floods, or ransomware encrypts everything. When it happens, decisions are made under pressure with incomplete information.

Why it happens. Rare events feel hypothetical.

The fix. A one-page plan: critical systems, who does what, how to restore, who to call, how to tell customers. Test it once a year. Our business continuity planning service produces exactly this.

10. Reactive support and technical debt

The problem. IT is dealt with only when it breaks. Quick fixes pile up. Systems work as long as nobody touches them. Every change is frightening.

Why it happens. Break-fix arrangements, no monitoring, no reviews.

The fix. Monitoring so problems are seen early. Root-cause fixes rather than workarounds. A review a few times a year to plan what to replace. In other words, managed IT support rather than emergency calls.

The ten at a glance

ProblemFirst signPrevention
Weak securityPhishing emails reaching staff, no MFA promptsMFA, EDR, filtering, training, patching
Untested backupsNobody can name the last restore3-2-1, monitored, restore-tested
Ageing hardwareSlow machines, out of warrantyInventory and refresh cycle
Unreliable networkAfternoon Wi-Fi dropsSite survey, business-grade kit
No documentationNobody knows the firewall passwordDocumented environment, owned by you
One-person dependency"Ask Dave"Second knowledge holder
Access sprawlLeavers still in the address bookJoiners and leavers process, reviews
Unpatched systemsUpdate reminders dismissedScheduled, reported patching
No recovery plan"We'd work it out"One-page plan, tested annually
Reactive supportSame faults recurringMonitoring, root-cause fixes, reviews

What to do next

If three or more of these apply, an IT health check will confirm which, rank them by risk, and give you a prioritised plan that starts with security and backup. It is the same assessment a new provider runs in the first weeks, without the commitment.

Frequently asked questions

What is the biggest IT mistake small businesses make?
Assuming they are too small to be attacked. The GOV.UK Cyber Security Breaches Survey consistently finds phishing the most common attack on UK businesses, and attackers send the same email to everyone. Small firms are hit because they are easier, not because they are chosen. The practical consequence is no MFA, no managed endpoint security, no training and no tested backup, which is the environment in which one click becomes a crisis.
How often should a small business back up its data?
Daily at minimum for business data, with more frequent backups for anything that changes constantly. Follow the 3-2-1 pattern: three copies, on two different media, one off site or in the cloud. The schedule matters less than the test. A backup that has never been restored is an assumption, so restore a file every month and a whole system at least once a year.
Do we need to replace computers that still work?
Working is not the same as supported. A computer past its warranty, on an operating system that no longer receives security updates, or too slow to run current software costs you in lost time and security risk before it fails. Plan a refresh cycle of four to five years for laptops and five to seven for servers, track warranty dates, and replace on a schedule rather than in a panic.
Why does our office Wi-Fi keep dropping?
Usually because it is a consumer router or a single access point doing a job that needs business-grade equipment: several access points placed for coverage, a managed switch, and a firewall with the connection properly configured. Interference from neighbouring networks, too many devices on one channel and old firmware are common. A site survey and a UniFi or Meraki deployment sized for the building fixes most of it.
What should we do if only one person understands our IT?
Document everything now, while they are still there: network diagram, device inventory, admin credentials in a password manager the business controls, licence logins, backup locations and how to restore. Then remove the dependency by bringing in a provider or a second person who holds the same knowledge. The risk is not that the person is bad at the job. It is that they are one resignation or one illness from being unavailable.
Should we move everything to the cloud to avoid these problems?
Cloud removes some problems and changes others. It retires the server and the hardware refresh, but accounts, MFA, permissions, licences, backup of your own data and the office network still need managing, and phishing targets cloud accounts directly. Many small businesses land on Microsoft 365 for email and files with a hybrid arrangement for anything that must stay on site. Either way, someone has to be accountable.

Next step

Talk to an engineer, not a sales script

Tell us what is not working, or what you are planning, and we will give you a straight view on what it would take to fix.

WhatsApp us