Dallas, TX · serving Dallas–Fort Worth · remote across Texas Remote support 24/7/365, including US holidays [email protected]

Dallas business IT

The annual IT check-up: what to review every year

Most small-office IT problems are not sudden. They build quietly over a year: a lapsed license, a five-year-old laptop, a backup nobody has tested. Here is a once-a-year agenda an office manager in Dallas can run in an afternoon.

Written and reviewed by Anthony Omini, Cross River Tech·12 min read·Published · Updated

What should we review in our IT every year?

Once a year, sit down for two hours and review eight things: software licenses and who has them, how old every computer is, a real restore from your backup, firewall firmware and rules, who still holds administrator access, whether your documentation is still true, every contract and renewal date, and what needs replacing next year. An office manager in Dallas can run this without me.

Answered by Anthony Omini, Cross River Tech, Dallas

Open notebook, pens and reading glasses on a desk

Key takeaways

  • An annual review catches the slow problems, the ones that never trigger a support call until the day they become expensive.
  • The single most valuable item on the list is a real restore from a real backup, because a backup nobody has tested is only a hope.
  • Most of this agenda can be run by an office manager with a spreadsheet; the technical items are few and can be handed to whoever supports your systems.
  • Renewal dates and administrator access are the two things that drift fastest and cause the most trouble when nobody is watching.
  • Finish the review with a written replacement and budget plan for the coming year, so hardware is bought on a schedule rather than in an emergency.

What should you review in your IT every year?

Eight things. I am Anthony Omini, the owner of Cross River Tech in Dallas, and this is the agenda I run with the offices my team and I look after. It is deliberately written so that an office manager can run it alone, hand two or three technical items to whoever supports the systems, and finish in an afternoon.

#What you reviewWho can do it
1Software licenses and subscriptions: what you pay for, who uses itOffice manager
2Every computer: age, warranty, condition, who has itOffice manager
3Backups: a real file restored from a real backup, while you watchWhoever supports your systems
4Firewall and network: firmware currency, rules, Wi-Fi and guest networkWhoever supports your systems
5Administrator accounts and access: who has the keys, who should notOffice manager, with technical help
6Documentation: is it still true, and can two people reach itOffice manager
7Contracts and renewal dates: internet, phones, software, support, leasesOffice manager
8Next year's replacement and budget planOffice manager and owner

Nothing on this list is dramatic, and that is the point. Every one of them is a slow problem. A license lapses quietly. A laptop gets older quietly. A backup fails quietly, sometimes for a year. None of them generates a support call until the day it turns into a bad morning, which is why they need a scheduled review rather than a reaction.

The rest of this page is the detail for each item, written so you can work straight down it. If you would rather have someone run it with you, get in touch and I will do it with your office manager.

How often should IT be reviewed, and who should run it?

A full review once a year, a short check every quarter, and a few things watched continuously. The annual review is the sit-down with the whole list. The quarterly check is fifteen minutes on the items that drift fastest. Everything security-related should be monitored all the time rather than reviewed occasionally, which is one of the things a monthly plan is for.

  • Continuously, by whoever supports your systems: update status on computers and servers, endpoint protection health, backup success or failure, unusual sign-ins, and whether the internet and firewall are up.
  • Every quarter, fifteen minutes: user accounts against the current staff list, admin access, guest and contractor access, license counts against actual seats in use, and anything renewing in the next ninety days.
  • Once a year, the full agenda: everything on this page, including the restore test and the replacement plan.
  • Whenever something changes: a person leaves, an office moves, a new system arrives, or a customer sends a security questionnaire.

Who runs it matters less than that somebody owns it. In most small offices the right person is the office manager, because they already hold the vendor relationships, the invoices and the staff list. The technical items get handed over; the rest is organizational. Pick a month and keep it, ideally not your busiest one, and put next year's date in the calendar before you close this year's review.

One caution: an annual review is not a substitute for someone watching in between. It catches drift, not incidents. If nobody is monitoring backups and security day to day, the annual review will find problems that were fixable months earlier.

Which software licenses and subscriptions should you check?

All of them, against the list of people who actually work there. Subscription creep is the most reliably wasted money in a small office. Seats stay assigned to people who left, trials quietly become paid plans, and two tools end up doing the same job because different people bought them.

Build or update one spreadsheet with a row per service:

  • What it is and what it is for, in plain words, so the list still makes sense next year.
  • How many seats you pay for and how many are actually in use. Compare to your current staff list, name by name.
  • Who administers it inside the business, and who the backup administrator is.
  • What it costs, how it is billed and on which card, since an expiring card takes services down without warning.
  • The renewal date, and whether it renews automatically.
  • Whether it is still needed at all. Ask the team; there is usually at least one tool nobody has opened in months.

Three checks catch the most common problems. First, look for duplicate capability: two file-sharing services, two password tools, two meeting platforms. Second, check the plan tier you are on, because most offices are either paying for features they never use or missing a security feature that sits one tier up. Third, look for anything still billed to a personal card or a former employee's account, which is a problem to fix immediately rather than at renewal.

The identity platform deserves particular attention, since it usually costs the most and has the widest range of tiers. Microsoft 365 security for a small business explains which protections come with which plan, so you can tell whether you are on the right one.

How old are the computers, and what needs replacing?

Walk the office with a list and record every machine's age, warranty status and condition. Hardware age is the single best predictor of support calls, and a five-year-old laptop that everyone jokes about is costing you more in lost time than a new one would cost to buy.

Record for every computer:

  • Who uses it, the model and the serial number.
  • Purchase date, or manufacture date from the serial number if nobody remembers.
  • Warranty status and end date.
  • Memory and storage, and how full the drive is.
  • Whether it is still receiving operating system updates.
  • Battery condition on laptops, since a laptop tethered to a desk by a dead battery has stopped being a laptop.
  • Anything the user complains about, in their words.

A rough guide I use for planning, not a rule:

AgeWhat it usually means
Year 1 to 3Under warranty, low risk. Nothing to do.
Year 4Warranty ending. Decide now whether it is a replacement this year or next, and budget for it.
Year 5 and beyondReplace, or accept that a failure will happen at a bad moment and there will be no warranty behind it.
No longer receiving updatesReplace regardless of age. An unpatched machine is a security problem, not just a slow one.

Do the same for the network equipment and any server, and include the printers and the uninterruptible power supplies. Power supply batteries in particular wear out in about three to five years and then quietly provide no protection at all, which North Texas storm season eventually exposes. The hardware choices themselves are covered in buying and supporting Dell and Lenovo business computers.

How do you test that the backups actually work?

Ask for a specific file from a specific date to be restored while you watch, and time it. This is the most important item on the whole agenda and the one most often skipped, because the backup dashboard is green and everyone assumes green means recoverable. Green means the job ran. It does not mean the data comes back.

The test, step by step:

  1. Pick a file yourself, without warning, ideally something from a few months ago rather than yesterday.
  2. Ask for it to be restored to a separate location, not over the original.
  3. Open it and confirm the contents are correct and complete, not just that a file appeared.
  4. Time the whole thing and write the number down. That number is your real recovery expectation.
  5. Repeat for each system that matters: the file storage, the email tenant, the accounting system and any line-of-business database.
  6. Ask the bigger question: how long would a full recovery take if the server failed or ransomware hit everything at once, and what would the office do in the meantime.
  7. Record the date of the test in your documentation, so next year you can see whether it actually happened.

While you are there, confirm three facts. That the cloud accounts are backed up separately, because Microsoft 365 and Google Workspace do not protect you against deletion. That at least one backup copy is somewhere ransomware cannot alter or delete it. And that retention is long enough for your obligations, which for some businesses is years rather than months.

If the restore fails, or nobody can produce the file, you have found the most valuable thing this review will find. The backup and recovery setup I put in place is on the cybersecurity, backup and disaster recovery page.

What should you check on the firewall, the network and the Wi-Fi?

Firmware currency, the rules that are still open, who can reach the network remotely, and whether the Wi-Fi still fits the office. This is the technical part of the review, so hand it to whoever supports your systems, but ask for the answers in writing rather than a verbal "it's fine".

The questions to ask:

  • Is the firewall firmware current, and is the device still supported by its manufacturer? An unsupported firewall stops receiving security fixes and becomes the weakest point in the office.
  • Is the security subscription on the firewall still active? Many models need a paid subscription for their filtering to keep working, and it lapses silently.
  • What rules allow traffic in from the internet, and is each one still needed? Old rules for systems that were retired years ago are a common finding.
  • Is remote access still limited to the people who need it, with multi-factor authentication in front of it?
  • Are the switches and access points current on firmware, and are they still supported?
  • Has the Wi-Fi password been changed since the last person left, and is the guest network genuinely separate from the office network?
  • Does the coverage still match the office? Desks move, walls get added, and the conference room that used to work sometimes stops working.
  • Is the internet plan still right, particularly the upload speed if the office has grown or started using video heavily?

One more that people forget: check that someone other than your IT provider knows the administrator password for the firewall and the internet account, stored safely. If Wi-Fi coverage is the recurring complaint, office Wi-Fi access point installation explains what usually causes it and what a proper fix involves.

Who still has administrator access, and who should not?

Print the list of every account with administrative rights and justify each one out loud. Access drifts. People get admin rights for a project and keep them for years, former staff linger in systems nobody thought about, and old contractor accounts sit dormant with full permissions.

Work through this list:

  1. Every user account in your email and identity platform, compared to the current staff list. Anyone who left should be disabled, and their license reclaimed.
  2. Every account with administrator rights, named and justified. Most small offices need two, occasionally three.
  3. The break-glass administrator account: does it exist, does it still work, and are its credentials stored somewhere two people can reach?
  4. Guest and external accounts: contractors, freelancers, vendors and clients who were given access for something that finished.
  5. Multi-factor authentication coverage: is it on for everyone, with no exceptions carved out for an owner who found it annoying?
  6. Shared logins: any account several people use, which should move into a password manager with individual access instead.
  7. Your IT provider's access, including mine. You should know exactly what access they hold and be able to revoke it yourself.
  8. Third-party apps connected to your email or file storage, which accumulate permissions quietly and are worth pruning.

Then check the offboarding process itself, using the last person who left as the test case. Are they really gone from every system, or only from email? That single question finds more open doors than anything else on this agenda. An employee left with the company laptop and accounts covers the process that should have run.

Is your documentation still true, and are your renewal dates on a calendar?

Read the documentation as if you had just joined the company, and check that every renewal date is in a shared calendar with a reminder. Documentation rots faster than anything else in IT, because it is written once during a project and then quietly falls out of date as things change.

What should be written down, and verified this year:

  • Domain: registrar, who owns the account, renewal date, where DNS is hosted.
  • Email and identity: platform, administrators, the break-glass account and where its credentials live.
  • Internet and phones: provider, account number, circuit details, support number, contract end date.
  • Network: firewall, switches and access points, with model numbers and where they are physically located.
  • Backups: what is protected, where copies go, retention, and the date of the last tested restore.
  • Devices: the inventory from the hardware review, with warranty end dates.
  • Checklists: onboarding and offboarding, so both are repeatable.
  • Vendor and support contacts, including who to call out of hours.

Then put every renewal and contract end date into one shared calendar with a reminder ninety days ahead: internet, phones, software subscriptions, hardware warranties, the office lease, cyber insurance and any support agreement. Ninety days is deliberate, because that is roughly the notice period on many business contracts and it is enough time to get competitive quotes rather than renewing by default.

Two rules make documentation survive: it lives in the company's own storage where at least two people can reach it, never only in a provider's system, and it gets dated when it is updated. Mine is written so a client can hand it to someone else, including a different provider, which is the standard I think everyone should hold their IT to.

How do you turn this into next year's plan and budget?

Finish the review by writing three short lists: what to fix now, what to replace this year, and what to plan for the year after. A review that produces findings but no plan gets repeated unchanged next year.

ListWhat goes on itWhen
Fix nowFailed restore, unsupported firewall, missing multi-factor authentication, former staff still with access, lapsed security subscriptionThis month
Replace this yearComputers at year five, out-of-warranty machines, worn power supply batteries, access points with poor coverageSpread across the year, with dates
Plan for next yearMachines reaching year four, contracts ending, a growth-driven upgrade such as more storage or better internetInto next year's budget

On budgeting, the useful discipline is to replace roughly a fifth of your computers every year rather than replacing them all at once every five years. The yearly cost is lower and more predictable, and you never face a year where everything is old at the same time. Add the recurring per-user software costs and a contingency for the one thing that always breaks, and you have a realistic number. What a small business should budget for IT each year goes through the whole calculation.

If you want help running the review, I do it as part of managed IT services for the offices I look after, or as a one-off piece of work at my hourly rate of $100 remote and $150 onsite during business hours, one-hour minimum. Most annual reviews for a small office are a few hours including the write-up. I work with businesses across Dallas and the metroplex onsite and support businesses remotely anywhere in Texas.

Either way, run it. Even done imperfectly by an office manager with a spreadsheet, this agenda finds things worth finding. And if you are setting up a business rather than reviewing one, IT for a Dallas startup: what to set up first is the version for day one. Tell me what you have and I will tell you where I would start.

Questions people ask

How often should a small business review its IT?

A full review once a year, a fifteen-minute check each quarter on the things that drift fastest, and continuous monitoring of updates, security and backups. The annual review covers licenses, device age, a restore test, the firewall, admin access, documentation, renewal dates and next year's replacement plan. Quarterly checks catch user accounts, license counts and anything renewing in the next ninety days.

Can an office manager run the annual IT review without an IT company?

Yes, for most of it. Licenses, the device inventory, documentation, renewal dates and the replacement plan are organizational work that an office manager with a spreadsheet can do well. Two items need technical help: the backup restore test and the firewall and network check. Ask for those answers in writing rather than a verbal reassurance that everything is fine.

How do you test a backup properly?

Pick a specific file yourself, ideally a few months old, ask for it to be restored to a separate location, open it to confirm the contents are complete, and time the whole process. That time is your real recovery expectation. Repeat for file storage, email, accounting and any key database, then record the date so next year you can see whether the test actually happened.

When should office computers be replaced?

Plan replacement around year four and act by year five, or immediately if a machine no longer receives operating system updates. Age predicts support calls better than anything else, and an out-of-warranty machine that fails at a busy moment costs more in lost time than the replacement would have. Replacing about a fifth of your computers each year keeps the cost predictable.

What is the most commonly missed item in an annual IT review?

A real restore test, followed closely by administrator access that was never removed. Backup dashboards show green when the job ran, which is not the same as the data coming back. And access drifts constantly: people gain admin rights for a project, contractors keep guest accounts, and former staff linger in systems nobody thought to check.

What should go on the calendar after the review?

Every renewal and contract end date with a reminder ninety days ahead: internet, phones, software subscriptions, hardware warranties, the office lease, cyber insurance and any support agreement. Ninety days matches the notice period on many business contracts and leaves time to get competitive quotes. Add next year's review date before you close this year's.

Anthony Omini

Written and reviewed by

Anthony Omini, founder of Cross River Tech

Over 15 years in IT across many industries, now running Cross River Tech, a small owner-led managed IT company in Dallas. Every article is written from his own client work and checked by him before it is published.

Want someone to run the review with you? Tell me how many people and computers you have and where your files and backups live. I will go through the agenda with your office manager and write up what I find.

Let's fix it — or plan it.

Call, or send a short request and I will get back to you personally.

Call now Get a quote

Free, no-obligation quote

Tell me what is going on

Three quick steps. I read every request myself and reply personally, usually the same business day.

What can I help with?

Pick the closest option. There is room to explain in a moment.

or call (214) 612-7080