10 IT infrastructure vulnerabilities that cost businesses data
Go through the list and check off the items you already have covered. At the end — your score and what to do about it. Honesty here is cheaper than data recovery.
Backups that are never tested with a restore
A backup that's never been restored is hope, not protection. Statistically, one in five backups turns out broken exactly when disaster strikes.
Check yourself: When did you last restore a database from a backup and confirm it opens?
Backups stored in the same place as the data
If backup copies sit on the same server or in the same room, a fire, theft, or ransomware attack destroys the data and the backups at once.
Check yourself: Is there a copy on a separate device in another location, or in the cloud?
The core database sits on an ordinary office computer
The accountant's computer gets turned off, rebooted, catches viruses from email — and the company's core database is at risk right along with it.
Check yourself: Where does your core business database physically live, and who else uses that computer?
Passwords live in a notebook or a shared file
One password for everyone and a sticky note on the monitor means you can't tell who did what in the system — and an employee leaving means changing everything.
Check yourself: Could you say, within a minute, who knows the server password?
Access for former employees is never revoked
A former employee with a working VPN or system password is the most common cause of data leaks. Resentment plus access is a bad combination.
Check yourself: Is there a list of everyone with remote access, and when was it last reviewed?
The whole network is one flat network
Guest Wi-Fi, cameras, printers, and the core server all on one network: infecting any device opens the road to the critical data.
Check yourself: Can a guest's laptop in the meeting room "see" your server?
Servers are exposed directly to the internet
An open RDP or database port facing the internet is a door that bots find within hours and try to pick the lock on, around the clock.
Check yourself: Do employees connect to the server remotely without a VPN?
Security updates aren't installed
Vulnerabilities in outdated OS and service versions get published along with instructions for exploiting them. Unpatched systems are an easy target.
Check yourself: When were the server and network equipment last updated?
No monitoring in place
A full disk, dying hardware, or a crashed service gets discovered from employee complaints — once work has already stopped.
Check yourself: Who finds out about a problem first — the monitoring system, or the accounting department?
Everything depends on one person
The network layout lives in the administrator's head, with no documentation. Their vacation, illness, or departure stalls IT development for months.
Check yourself: Could a new specialist figure out your system without "that one" employee?
Check off the items above — your score will appear here.
Discuss my results with an engineerPrint / save as PDF