How Should a 20-Person Company Build Its IT Foundation?

0
4
Asked By MellowPine47 On

I'm the CFO of a small industrial manufacturing company with about 20 employees. We use Google Workspace and Google Drive for most of our files, have no internal IT staff, and store very little sensitive customer information. Still, file sharing is broader than it should be and our overall structure is becoming difficult to manage.

I recently tried reorganizing Drive, but the effort didn't go well. I put everything into one Shared Drive with folders, when separate Shared Drives based on access levels probably would have made more sense. The team also sees cleanup as extra work today for problems that might not become obvious for another year or two.

The file structure is the immediate concern, but I'm also trying to understand the bigger picture. At this stage, what should we establish for permissions, onboarding and offboarding, company devices, device management, backups, security policies, and disaster recovery? What can reasonably wait until we grow?

Should a company this size hire an MSP or consultant to design and manage the environment, or is it practical to assign these responsibilities internally for now? I can own the governance and budget, but I'm not an IT specialist. For people who have helped companies through this phase, what did you prioritize first, and what do you wish you had addressed earlier?

4 Answers

Answered By CedarFox81 On

Bring in a qualified IT consultant or MSP before trying to redesign everything yourself. They can assess the current setup, establish sensible access groups and Shared Drives, document the environment, and create a short-term security plan. You don’t necessarily need a full-time hire; an initial project followed by periodic reviews may be enough.

Answered By QuartzHarbor26 On

Start with the basics: company-owned devices instead of BYOD, strong identity and MFA controls, role-based access, a documented onboarding and offboarding process, managed endpoint security, reliable backups, and tested recovery procedures. Cyber insurance can also be useful because its application requirements often expose missing controls. If you may handle regulated or government-related work later, plan for those requirements now rather than rebuilding everything.

Answered By CopperMeadow38 On

Keep the architecture simple, but make the fundamentals correct from the beginning. A professional can separate data by department and sensitivity, define who can access what, standardize employee accounts and devices, and set up a sensible firewall and endpoint controls. Whether you remain with Google Workspace or move to a Microsoft-based stack, consistency and documented ownership matter more than choosing the trendiest platform.

Answered By NorthstarLime63 On

An MSP with a virtual-CTO or strategic-planning service could be a good fit. Ask for an assessment and roadmap before buying a large bundle of services. Make sure the contract requires clear documentation, administrator access, ownership of your data and configurations, and a smooth handoff if you eventually build an internal IT team.

BrambleSky52 -

Even if you dislike the MSP model, this is one of the situations where outside expertise is usually cheaper than recovering from a poorly secured environment. The important part is making sure the provider can’t become a permanent black box.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.