Why are these questions useful?
A business manager is not expected to write firewall rules or interpret server logs. They can still ask which systems the business uses, who has access, and whether the backups have actually been restored successfully.
These questions do not replace a full technical assessment. They are a useful starting point for seeing whether the environment is being managed or whether too much depends on one person's memory.
For each answer, look for two things: is there a clear owner, and is there a current record or test that supports the answer?
1. Do we know which devices and services we have?
If devices, licences, domains, network equipment, and cloud services exist only in one person's memory, information can disappear when the environment changes or that person leaves.
The inventory does not have to be perfect. Knowing the owner, purpose, location, and support or renewal date for critical assets is already a strong start.
An unowned system can remain both a cost and a security risk long after the project that created it has ended.
2. Do we know who can access each system and why?
Individual accounts, MFA, and role-based groups make access easier to explain. Shared passwords and years of accumulated group membership make it harder to establish who still needs what.
Former employees, old suppliers, guest users, and service accounts deserve particular attention. Sensitive access should also have a clear approver.
3. Do we know where important data lives?
Company data may not live only on a file server. Employee devices, Microsoft 365, Google Workspace, specialist SaaS products, and personal workarounds can all hold business information at the same time.
When the owner, approved storage location, and sharing method are known, backup and access decisions become easier.
Knowing where the data lives also shows which identity, application, and supplier the business depends on during a disruption.
4. Can we actually recover from backup?
A successful backup status and a restored business process are not the same thing. Ask when the latest restore test was performed, what was restored, and how long it took.
The application data may be present while the required licence, account, or configuration is missing. In that case the data has technically returned, but the service still has not.
5, 6, and 7. Are support, security, and change responsibilities clear?
When a user has a problem, it should be clear who follows it. The same is true for security alerts and approval of high-impact changes.
How are unsupported devices, critical update gaps, and excessively broad access identified? Are there approved routes for remote and onsite support? Is there a rollback option before important changes?
The assessment should finish with priorities and owners, not just a long list of technical findings. A list of issues with no business impact or decision path creates anxiety without helping management decide what to do.
- Who receives user requests and technical alerts?
- How are unsupported devices and critical update gaps identified?
- Are remote and onsite support channels defined?
- Who approves high-impact changes?
- Are current configurations and rollback paths available?
- Which risks need a budget or target date?
- Are outcomes reported in language management can act on?
You do not need to know every technical detail to understand whether the IT environment is under control.
If the business can answer what it owns, who has access, where the data lives, whether recovery works, and who owns support and change, management already has a strong starting point.
This article is for general information. It does not replace a technical assessment of your environment, a security guarantee, or legal advice.