Summer is the Time
Assuming your business isn't summer seasonal, this time of the year is typically slow for most owners. The phone rings less, vendors are harder to reach, employees take long weekends, and hopefully even you’re looking at a few days off!
That can be frustrating when you’re trying to close work, collect money, or get answers from people who are “currently checking email periodically.” But things just don’t seem to move as fast in July and August. If that’s the case for you right now, that may not be a bad thing, assuming you’re able to capitalize on the well-deserved quiet time.
According to this recent article How to Conduct a Mid-Year Business Review by SCORE (a nonprofit organization and resource partner of the U.S. Small Business Administration), “summer is a smart time to make strategic moves while your competitors are taking it easy.”
The summer slowdown gives you an opportunity to take advantage of something most business owners rarely get - a little space. And if IT security has been sitting on your to-do list, this may be a great time to look into a few things. You don’t need to solve every issue. But you can defiantly use the summer slowdown to knock out a few things that materially lower your IT risk before business picks back up.
5 Basics to Tackle During the Summer Slowdown
1. Put that password manager in place
If your team is still saving passwords in browsers, notebooks, spreadsheets, text messages, or “that one document everyone uses,” deploying a company password manager is a quick and inexpensive place to start
Nothing fancy needed, any business-grade password manager works. Set it up for key employees. Move the important accounts first: email, banking, payroll, accounting, website, CRM, payment processing, and anything with customer data. Make a list, and work through it.
2. Turn on Multi-Factor (MFA)
Multi-factor authentication, or MFA, is another simple and affordable security improvement.
At minimum, it should be turned on for email, banking, payroll, accounting, remote access, cloud file storage, and administrator accounts. If someone gets a password, MFA can be the thing that keeps that password from becoming a full-blown incident.
And don’t just turn it on for the team. Make sure the owner’s covered as well.
3. Check your licensing
A lot of small businesses are paying for tools they’re not really using — or using tools that don’t give them the protection they think they have.
Summer is a great time to review your Microsoft 365, Google Workspace, backup, antivirus, email security, accounting, CRM, and file-sharing licenses.
Ask a few basic questions:
- Are we on business-grade licensing?
- Are we paying for security features we haven’t turned on?
- Do former employees still have active accounts?
- Are users sharing logins and do we own enough licenses?
- Are personal email accounts being used for business?
This is not just about saving money. It’s about knowing whether the tools you already have are actually protecting the business.
4. Inventory your equipment
Look under desks, in draws, and of course hit the top shelf of every closet! Make a list of laptops, desktops, tablets, phones, printers, routers, and even external hard drives that contain business information.
For each item, capture the basics: who has it, what it is, serial number if available, approximate age, whether it is still being used, and whether it may contain company or customer data.
This may sound boring, but that's because it is boring. It’s also important! You can’t protect what you don’t know you have. And you definitely can’t retire it properly if it’s sitting in a closet with old client files, tax records, contracts, passwords, or saved browser sessions still on it.
5. Clean out, wipe, and properly dispose of old equipment
Old machines are easy to ignore. They sit in a closet, garage, basement, or back office because nobody wants to deal with them. Now's the time to deal with them!
If a device is no longer needed, wipe it properly before it leaves your control. If it contains sensitive data, customer records, financial information, employee files, medical information, legal documents, tax records, or anything regulated, don’t guess. Use a qualified provider and get a certificate of destruction if your business, industry, insurance policy, or compliance obligations require one.
Staples offers Retail Recycling which can be very useful for the small business owner. But don’t confuse recycling with certified data destruction and if you need proof that data was destroyed, make sure you use a service that provides the right documentation.
The rule is simple: Before technology leaves your business, wipe it clean and make sure you can prove it if you need to. Then update your inventory list above with removal/destruction date.
Overall, The Point Is Progress
None of this is flashy. None of it is crazy expensive. These are the kinds of basic steps that make a small business harder to compromise, easier to manage, and less dependent on memory, guesswork, and good luck.
Password manager. MFA. License review. Equipment inventory. Proper disposal. Put them all in place and you’re not only more secure, you’re also starting to shift the culture and generate an awareness that security is important.
Know your risk. Protect what you've built. You don’t need to spend the summer buried in IT. But if the phone is ringing a little less or the calendar has a little more breathing room, use the time. Get the basics handled now, and fill out the form below if we can be a resource.
