Most Geelong businesses only look at their IT when something breaks. A server dies, an account gets locked, a laptop refuses to connect, and suddenly the owner is on the phone to an IT provider at 4pm on a Friday. A regular IT health check flips that around. You walk through your security, your AI readiness, your backups and your network on a quiet day, find the gaps, and fix them before they become a crisis.
This checklist is the one we run with small and mid-sized businesses across Geelong, the Bellarine and the Surf Coast. It is evergreen - you can use it any time of year, not just at end of financial year. Work through each section, mark everything green, amber or red, and you will have a clear picture of where your IT actually sits.
Why run an IT health check
An IT health check is a structured review of your technology stack - security, backups, network and increasingly AI readiness - done on a regular schedule rather than in response to a problem. The point is to find issues while they are still cheap to fix.
There are four good reasons to run one:
- Catch problems cheaply. A missing update or an untested backup costs nothing to find and a fortune to recover from.
- Plan your spending. A health check gives you a prioritised list, so you can budget for the year instead of reacting to invoices.
- Satisfy your insurer. Cyber insurers now ask pointed questions about MFA, backups and patching. A health check gives you the answers.
- Prepare for AI. Before you switch on Copilot or any other AI tool, you want clean data and sensible permissions. The health check flags that work upfront.
Security checklist
Security is the section most likely to turn up reds, especially in businesses that have grown quickly. Go through each item honestly - a tick that is not really true is worse than no tick at all.
- Multi-factor authentication (MFA) is on for every account, especially email and any remote access tool.
- All operating systems and key applications are patched and within vendor support - no Windows 10 machines hanging on past end of life.
- Antivirus or endpoint detection and response (EDR) is installed on every device and reporting into a dashboard someone actually checks.
- Backups exist, include a copy that is offline or immutable, and at least one restore has been tested.
- Staff have done phishing awareness training in the last six months.
- Admin accounts are separate from everyday work accounts - no one is reading email as a global admin.
- No shared logins. Every person has their own account so activity can be traced.
- The Essential Eight basics are in place: application control, macro restrictions, and regular patching.
If that list looks intimidating, our cybersecurity services cover the lot. You do not have to do it alone, but you do have to know where you stand.
AI readiness checklist
AI is now a standard part of an IT health check, not a nice-to-have. Even if you are not using Copilot yet, your data hygiene decides how safely you can switch it on later.
- You are on eligible Microsoft 365 licensing (Business Standard, Business Premium, E3 or E5) if you plan to use Copilot.
- Files live in the right places - SharePoint and OneDrive, not scattered across local drives and USB sticks.
- Oversharing has been reviewed. No company-wide access to folders that should be restricted.
- Sensitivity labels are applied to confidential documents so AI tools and staff treat them correctly.
- You have identified two or three realistic AI use cases for your business, not a wishlist of fifty.
- A small pilot group (five to ten people) has been chosen to test AI tools before a wider rollout.
- There is a short, plain-English AI acceptable-use policy so staff know what is and is not allowed.
Not sure where to start with AI? An AI strategy and roadmapping session will identify the use cases worth pursuing and the data work that has to happen first.
Backup and recovery checklist
Backups are the one thing that turns a disaster into an inconvenience. The trouble is most businesses think they have backups when what they actually have is a copy of something, somewhere, that has never been tested.
- You meet the 3-2-1 rule: three copies of your data, on two different media, with one offsite.
- At least one copy is offline or immutable, so ransomware cannot encrypt or delete it.
- A restore has been tested in the last six months - not just "the backup ran", but an actual file recovery.
- You know your recovery time objective (RTO): how long you can afford to be down before it seriously hurts.
- Microsoft 365 data is backed up separately if you need it. Microsoft's retention is not a backup - deleted items vanish after a set period, and there is no granular restore.
That last point catches a lot of Geelong businesses out. They assume Microsoft holds everything safely forever. It does not. If you rely on email history or SharePoint files for legal or operational reasons, a third-party Microsoft 365 backup is worth the small monthly cost.
Network checklist
A flaky network quietly costs hours every week in slow loads, dropped calls and staff wandering between access points. It is the least glamorous part of an IT health check and often the most satisfying to fix.
- You are running business-grade switches and access points, not consumer gear from a big-box store.
- Cabling is in decent condition - no dodgy joins, no ancient Cat5 holding everything back.
- WiFi coverage is adequate across the whole premises, including meeting rooms and the back office.
- Critical sites have internet redundancy - a 4G/5G fallback or a second connection - so a single outage does not stop the business.
- There are no unmanaged switches or rogue routers someone plugged in and forgot about.
If your network is due for an upgrade or you are not sure what is sitting in the comms cabinet, our network installation and upgrade services cover assessment, design and installation.
How to score it
For each section, give yourself a simple traffic-light rating. You do not need a spreadsheet - a few minutes of honest thought is enough.
- Green: every item ticked, tested in the last six months, and someone is responsible for keeping it that way.
- Amber: most items ticked but a few gaps, or things that work but have not been tested recently.
- Red: one or more critical items missing or untested. This is where a problem will come from if you do nothing.
Aim for green across all four sections. Amber is acceptable as a holding pattern while you fix things, but reds need attention - they are the gaps that turn into outages, breaches or lost data.
What to fix first
If you run the checklist and end up with a long list, do not try to fix everything at once. Work in this order.
- MFA and backups first. These two are non-negotiable. If nothing else happens, get MFA on every account and get a tested, offline backup in place. They are the difference between an incident and a disaster.
- Then patching. Bring every operating system and key application up to a supported, patched version. This closes the holes most attackers walk through.
- Then AI and network improvements. Once the fundamentals are solid, tidy up data hygiene for AI and sort out any network pain points. These make the business faster and more capable, but they assume the basics are already done.
This order matters. We have seen businesses spend thousands on a slick AI rollout while their backups had been quietly failing for months. Get the foundations right, then build on them.
Getting help
You can run this checklist yourself, and many Geelong business owners do. But if you want an independent set of eyes, a deeper test on security and backups, and a written report you can act on, an external IT health check is a one-off consulting audit - not a managed services contract and not a lock-in.
Better Networks runs IT health checks for small and mid-sized businesses across Geelong, the Bellarine and the Surf Coast. We cover cybersecurity, AI readiness and network, test the things that matter, and hand you a prioritised fix list. Book one through our contact page and we will walk you through what an audit would look like for your business.
