Skip to content

535 040 361511 275 531

Book an IT review

IT Help for Small Businesses: What a Team of 5-20 Needs

Above all, a small business needs accessible support, controlled updates, verified backups, account protection and up-to-date documentation. The scope should be determined by the risks and the way you work, not by the number of trendy tools.

Jakub MazurekJanuary 12, 2026updated September 11, 20264 min read

Technician providing remote IT support to a small company

In a small team, one failure can stop the entire process because there is often no backup computer, no second administrator, and no alternative way of working. Good IT support is not just about responding to requests. It should combine user support, prevention, security and preparation for disaster recovery.

Why company scale matters

A company employing 5-20 people may already use an accounting system, CRM, cloud services, file server and network devices, but still not have an internal IT department. Typical risks are:

  • account and configuration knowledge concentrated in one person;
  • no replacement equipment for critical positions;
  • files scattered between computers and private accounts;
  • updates performed accidentally or unchecked;
  • backups that no one monitors or tests;
  • shared passwords and too broad permissions.

Not every small business has all these problems. The scope of service should be determined after an inventory of the environment and processes whose downtime causes the greatest loss.

Basic scope of IT support

Helpdesk with clear reporting method

The employee should know where to report a problem, what information to provide and when to expect a response. The contract should distinguish between response time and service recovery time and specify support priorities and hours.

Controlled updates

Operating systems, browsers and applications require security updates. It's not enough to force every change immediately. You need a testing policy, an implementation deadline, a maintenance window, reboots, and nonconformance handling.

Backups and recovery attempts

The message about making a copy does not confirm that the data can be recovered. You need to define the scope, frequency, retention, backup location, who receives the alerts, and the trial recovery schedule. The required RPO and RTO times should be based on business needs.

Account and device protection

The basis is individual accounts, multi-factor authentication, limited administrator rights, device encryption and centrally managed station protection. MFA significantly reduces the risk of account takeover after password theft, but does not protect against all types of phishing or user error.

Documentation and procedures

The company should have access to an up-to-date inventory of devices, licences, vendors, administrators and key settings. Passwords should be stored in a controlled manager, not in a regular document. Procedures for connecting and disconnecting employees and for emergency access recovery are also needed.

Subscription or hourly assistance

An hourly model may suit a company with a simple infrastructure and occasional needs. However, prevention, monitoring and documentation must be ordered separately if they do not result from the contract.

A subscription makes it easier to maintain a consistent process and predict costs. It does not automatically mean unlimited scope. It is worth checking work limits, exclusions, visit conditions, licences and project management rules.

Selection should be based on frequency of calls, cost of downtime, complexity of the environment and expected liability of the supplier. There is no reason to consider one model as the best for every company with 5-20 people.

Cloud also requires a data protection plan

Microsoft 365 and Google Workspace provide service- and plan-specific availability, recovery, and retention mechanisms. This does not relieve the customer from account management, retention, accidental deletion and legal requirements. The decision on an additional copy should be preceded by an analysis of available mechanisms, storage period and required RPO and RTO.

How to prepare your company for a new employee and leaving the team

The repeatable checklist should include:

  • confirm role and necessary permissions;
  • preparation of managed device and accounts;
  • MFA enablement and security policy transfer;
  • granting access only to needed resources;
  • access withdrawn at the agreed time after departure;
  • securing company data and transferring responsibility;
  • updating the records of equipment, licences and resource owners.

Automation can shorten this process, but still requires approvals and exception checking.

Checklist before selecting a supplier

Ask:

  1. What are the support hours and how is response time measured?
  2. Who replaces the caregiver during their absence?
  3. Who monitors copies and how often are playbacks tested?
  4. How does the provider store administrative access and log its use?
  5. Does the client receive documentation and can export it after the cooperation?
  6. Which licences, visits and design work are billed separately?
  7. What does a security incident escalate?

Where to start

First, list your devices, accounts, vendors, and critical systems. Then assess what happens when each one goes down and how quickly the company needs to get back up and running. Only on this basis should you choose the scope of helpdesk, monitoring, backup and security.

Free IT review allows you to organise this information and indicate areas requiring further analysis.

Read more in the same topic.

Free · 60 minutes online · no obligation

You want to check this out at home in your company?

  1. You talk to an engineerOnline, by video call. Not with a salesperson. We don't install or change anything.
  2. We check 8 areasBackups, access, network, email, server, licences, protection and KSeF readiness.
  3. You get a scorecardThree priorities on one page, emailed after the meeting. Yours to use however you like.

We don't use a contact form. We answer the phone and reply to emails.