Picture an ordinary small business on an ordinary morning. The internet is up. Email opens. The billing computer starts the way it always does. Someone takes a backup occasionally, or believes someone does. A local vendor knows the administrator password, which has always felt convenient rather than concerning. Nothing appears broken, so the IT setup is assumed to be healthy.
That assumption holds right up to the moment it is tested. A laptop fails, a former employee's account turns out to still be active, the vendor stops answering the phone, or a backup that has existed for three years turns out never to have been restored. None of these are exotic events. They are ordinary, and so is the discovery that follows them: the business was never as resilient as it looked.
Working today is not the same as being recoverable tomorrow. Most small-business IT trouble lives in the gap between those two states.
The technology usually looks healthier than it is
Visible availability hides invisible dependencies. A small office can run smoothly for years on top of arrangements that would not survive a single bad week: one internet connection with no known fallback, one person holding all the administrative knowledge, cloud file sync quietly mistaken for backup, a handful of shared passwords, antivirus software standing in for an overall security model, devices whose ownership nobody can quite state, and a vendor account the business itself does not control.
None of these things announces itself as a problem. Each one works, in the narrow sense that the system it supports is currently available. The fragility only becomes visible when something changes — a departure, a dispute, a hardware failure, a credential in the wrong hands — and the business discovers that what it thought was a setup was actually a set of unexamined dependencies.
The point is not that every small company needs enterprise-grade infrastructure. It clearly does not, and pretending otherwise is how owners end up buying things they will never operate. The point is more modest and more useful: a business should understand what it depends on, who controls each dependency, and what would happen if one of them stopped working.
Small-business IT risk is a connected system
The second thing that makes this hard is that the dependencies cannot be examined one at a time. They behave as a connected system, and a weakness in one place quietly undermines strength in another.
Backup is weakened if identity is compromised, because whoever controls the accounts can often reach the copies too. Disaster recovery is theoretical if nobody knows where the assets and data actually are. Moving to the cloud does not reduce risk if the ownership of access remains unclear; it relocates the same ambiguity to a new platform. A perfectly reliable network still creates business risk if only an external vendor can administer it. And no amount of endpoint protection compensates for privileged access that nobody is tracking.
This connectedness has a practical consequence for anyone trying to assess the situation honestly: an overall judgement must not allow several moderate strengths to conceal one critical weakness. Resilience is not an average. It behaves more like a chain, and a chain is judged by its weakest link, not by the polish of the others.
Why I built the SMB IT Health Score
This gap between looking healthy and being recoverable is what led me to build the SMB IT Health Score — an independent, educational self-assessment for small-business owners and operational leaders, published under Simple Infrastructure Thinking, a small personal label I use for this kind of practical material. It takes roughly fifteen minutes, requires no login to begin, and states clearly that responses are private.
I built it because most of the assessments available to a small business sit at one of two unhelpful extremes. Some are too technical for an owner to answer honestly, written in the vocabulary of people who already work in infrastructure. Some are too shallow to reveal anything, a handful of yes-or-no questions that confirm whatever the respondent already believed. Many are designed primarily to sell a service, which shapes both the questions and the conclusions. And a few are enterprise audit questionnaires in disguise, built for organisations with compliance teams rather than for an office of twelve people and one part-time vendor.
The design goal was different: a calm, structured way for a business owner to pause, walk through the environment one area at a time, and come away knowing what deserves attention first. The tool is not intended to diagnose every technical issue. It is intended to improve the quality of the next decision, or the next conversation with whoever supports the systems.
What the assessment examines
The assessment asks 45 questions across ten categories, each answered on a simple one-to-five scale with guidance at every level, and the categories are deliberately ordinary. They fall into four natural groups.
The first group covers everyday access and productivity: the internet and Wi-Fi the business runs on, the identities and access rights that determine who can reach what, and the email and collaboration tools where most of the day actually happens. The second covers protection and control: endpoint security on the devices, network security around them, and the backup and recovery arrangements underneath everything. The third is about operational knowledge and ownership, which is where small businesses are most often surprised: whether anyone holds an inventory of assets, and how dependent the business is on its vendors. The fourth looks forward, at cloud readiness and disaster recovery — the questions that only feel urgent after it is too late to ask them calmly.
In full, the ten categories are:
- Internet and Wi-Fi
- Identity and Access
- Email and Collaboration
- Backup and Recovery
- Endpoint Security
- Network Security
- Cloud Readiness
- Asset Inventory
- Vendor Management
- Disaster Recovery
The result is an overall weighted health score, a per-category breakdown, prioritised recommendations, and a 30/60/90-day roadmap. There is also a printable report, because the most useful place for this kind of output is often a table with two people sitting at it. At the end, you can save your details to receive the printable report. Reports available to you can be accessed through My Reports.
Why the score includes red-flag caps
One scoring decision deserves an explanation, because it is the part of the tool that behaves least like a school examination. Serious red flags can cap the overall score, so that strong answers in less critical areas cannot conceal a fundamental risk.
The reasoning is straightforward. A business should not receive a reassuring score merely because its Wi-Fi is good, its devices are new, and its collaboration tools work, when nobody has ever tested a restore, former staff still hold administrator access, or the only privileged account belongs to an external vendor. In a simple average, those everyday strengths would dilute the critical weakness into a respectable-looking number. In reality, the weakness does not get diluted. It sits there, fully intact, waiting.
Resilience behaves like a dependency chain, not like an examination average. The cap exists to keep the score honest about that.
A score is useful only if it changes sequencing
A number on its own changes nothing. The reason the assessment ends with prioritised recommendations and a 30/60/90-day roadmap is that the real value of an honest result is what it does to the order of work.
The shape of that sequencing tends to be consistent, even though the specifics depend entirely on the answers given. The first thirty days are usually about ownership and the obvious access risks: establishing who controls what, removing accounts that should no longer exist, confirming that backups actually run, and writing down the critical dependencies somewhere other than one person's head. The next sixty days strengthen the controls around devices, the network, and administrative access, and close the operational gaps that keep recurring. The ninety days after that are for the harder, slower work: testing recovery rather than assuming it, reducing avoidable dependence on any single vendor, and planning improvements that need budget or time.
These are illustrative, not guaranteed. The generated plan depends on the answers, and two businesses with the same overall score can have very different first months. That is rather the point — the sequencing is where the score becomes a decision rather than a grade.
Some questions need more than a score
A self-assessment can show where attention is needed. It cannot understand everything about a particular business: the constraints behind a vendor proposal, the history of an existing technical arrangement, the budget realities of a migration decision, or the trade-offs that only make sense from inside the company. A score points at the area. It does not always settle the decision.
Sometimes the situation after the assessment is exactly this: the owner understands the risk well enough, but remains unsure about the next step. A vendor has proposed something, and it is unclear whether the proposal is proportionate to the actual problem. The backup arrangement looks reasonable on paper, but is it sufficient? Two weaknesses have been identified, and it is not obvious which should be addressed first. A cloud migration is on the table, but will it resolve the underlying operational risk or simply relocate it? The business suspects it has become too dependent on one vendor or one administrator and would value a second view. Or a proposed solution feels heavier than the business it is meant to serve.
For that narrow situation, the tool includes an Ask an Infrastructure Architect option. You submit one focused infrastructure question, with enough business and technical context to make it answerable, and receive a calm written second opinion after review. The response is meant to be taken back to your own IT team or existing vendor and discussed. It is a contribution to the decision, not a replacement for the people who run your systems.
It is worth being equally plain about what this is not. It is not emergency support, not a formal security audit, not implementation work, and not a disguised sales conversation. It is a written answer to a written question, nothing more. If an unresolved decision needs that kind of help, you can ask an Infrastructure Architect about one specific decision.
What the tool deliberately does not do
It is worth being plain about the limits, because they are part of the design rather than an apology for it.
The SMB IT Health Score does not certify security. It does not perform a vulnerability scan or inspect any system. It does not replace professional judgement, and it provides no legal or regulatory assurance. It does not promise that a business is safe, and it does not collect confidential technical information — users should never enter passwords, secrets, employer data, client data, contracts, or sensitive personal information into it. It is an educational self-assessment, and it does not replace a formal audit, a cybersecurity certification, a legal review, or a proper conversation with the people who run the systems. The same boundaries apply to the architect-question option: neither provides emergency technical support or implementation work, and neither is a substitute for an organisation's own IT team or vendor.
That restraint is deliberate. The tool exists to create awareness and decision clarity. Anything that claimed more would be exactly the kind of overconfident instrument it was built in reaction to. The same logic runs through some of the other writing here, from why reactive IT support is dangerous to the five things a small office actually needs: the useful move is rarely buying more, and almost always understanding more.
Knowing what you depend on
A small business does not need an enterprise architecture department. But it does need to know who controls its systems, what would happen if one of them stopped working, and whether it could recover without improvising under pressure. Those three questions can be answered in an afternoon, and most businesses never sit down to answer them.
If you run a small business, or carry operational responsibility for one, the assessment is a practical way to start. Forty-five questions, ten categories, about fifteen minutes, and at the end of it a clearer sense of whether the setup is fragile, stable, or ready to grow — and what deserves attention first. Keep the report, work through the priorities at your own pace, and if one decision still feels unresolved afterwards, a single well-framed question is a reasonable next step.
Check your SMB IT Health Score →
A private, approximately 15-minute educational self-assessment. No login required.