How Should a 20-Person Company Build Its IT Foundation?

0
3
Asked By MellowBirch42 On

I'm the CFO of a small industrial manufacturing company with about 20 employees. We rely on Google Workspace and Google Drive for most of our files, have no internal IT staff, and handle relatively little sensitive customer information. Still, file sharing has become too broad and our overall structure is inconsistent.

I recently tried reorganizing Drive, but the effort didn't go well. I used folders inside one Shared Drive when separate Shared Drives with different access controls probably would have made more sense. Employees also see cleanup as extra work that solves a problem they may not notice for another year or two.

The Drive organization is the immediate concern, but I'm also trying to understand the bigger picture. What should a company of this size prioritize for file permissions, employee onboarding and offboarding, device management, backups, security policies, and disaster recovery? What can reasonably wait? Is it more common to hire an MSP to design and manage these systems, or should someone handle them internally until the company grows?

I can manage the budget and business requirements, but I'm not an IT professional. If you've helped companies through this stage, what did you put in place first, and what do you wish had been addressed earlier?

4 Answers

Answered By NimbusCedar5 On

Start with the basics: company-owned devices rather than BYOD, strong identity controls with MFA, separate user accounts, a documented onboarding and offboarding checklist, least-privilege access, and a reliable backup and recovery plan. Also review your cyber-insurance requirements, since the insurer’s security checklist can provide a useful starting point. For Drive, organize Shared Drives around teams or sensitivity levels instead of relying on deeply nested folders and ad hoc sharing.

Answered By AmberQuill64 On

If the company may pursue government contracts or handle regulated information, bring those requirements into the design now rather than retrofitting them later. Otherwise, don’t overengineer the environment. A good MSP or virtual technology advisor can create a practical roadmap, explain what is urgent versus optional, and help select a platform that supports future growth. The key is to get a documented baseline before the current habits become harder to change.

Answered By CopperLynx7 On

The best first step is to hire a qualified IT professional or MSP for an assessment and an initial setup. A small company can often avoid a full-time IT hire, but trying to design permissions, backups, identity management, and security without experience usually creates expensive problems later. You could have them establish the foundation, document it, and provide recurring support only when needed.

QuietHarbor18 -

If you use an MSP, make sure the contract requires current documentation, administrative access, and a clear handoff process. You don’t want to become dependent on a provider when the company eventually needs internal IT.

Answered By PixelRook31 On

Keep the first version simple, but build it correctly. Define who owns each system, where files belong, who can access them, and how access is removed when someone leaves. Put the rules in writing and review them periodically. Device inventory, patching, endpoint protection, password management, MFA, email security, and tested backups are more important early investments than an elaborate architecture.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.