The 7 IT Mistakes Perth Small Businesses Keep Making

Not theory — the same seven problems, found over and over in real Perth offices. Every one is cheap to fix before it bites and expensive after.

From Real Perth Health Checks · Plain English · No Obligation

When we run a health check on a Perth office, we're rarely surprised anymore. The industries change — trades, retail, professional services, strata — but the problems don't. Here are the seven we find most often, what each one actually risks, and what fixing it involves.

Mistake 1

The backup nobody has ever tested

What we see: there's a backup — an old external drive, a sync tool someone set up years ago — and nobody has ever tried restoring a file from it. A backup you haven't tested is a hope, not a backup.

What it risks: the first time you find out the backup doesn't work is the day you need it — after a ransomware hit, a dead drive, or an accidental deletion. That's the most expensive possible moment to learn.

The fix: a proper backup with an actual test restore, on a schedule. Verifying an existing setup is usually a single session's work.

Mistake 2

One password, shared by the whole office

What we see: the same password on email, accounting software and the Wi-Fi — sometimes on a sticky note, often unchanged for years, and usually with no multi-factor authentication anywhere.

What it risks: one phished login opens everything at once. Shared passwords also mean you can never tell who did what — a problem the day something goes wrong.

The fix: individual accounts, a password manager, and MFA on email and banking first. This is the single highest-value security hour you can buy.

Mistake 3

Updates deferred forever

What we see: Windows updates postponed for months because "it always restarts at the worst time", software versions years out of date, and the occasional machine still running an unsupported operating system.

What it risks: most successful attacks on small businesses exploit holes that were patched long ago. Unpatched machines are the low-hanging fruit attackers scan for automatically.

The fix: updates applied on a schedule that doesn't interrupt work — automated where sensible, checked by a person either way.

Mistake 4

Ex-staff who can still log in

What we see: accounts belonging to people who left months or years ago — still active in email, file shares, accounting systems and cloud apps, because nobody's job is to switch them off.

What it risks: even without any bad intent, every forgotten account is an unwatched door. If a former employee's old password leaks in a breach elsewhere, it opens your systems.

The fix: an access review — who has an account, on what, and why — then a simple offboarding step for every departure. A one-off review plus a checklist solves it.

Mistake 5

Business email on a personal setup

What we see: the company running on a personal Gmail or bigpond address, or a Microsoft 365 tenancy signed up in a rush years ago with no security configuration ever applied.

What it risks: invoice fraud is the classic Australian small-business attack, and weakly-secured email is exactly how it happens. There's also a practical cost: no shared calendars, no central control, and a mess to untangle whenever staff change.

The fix: business-grade Microsoft 365 on your own domain, secured properly from day one. Migrations are quotable, predictable work — not the ordeal people fear.

Mistake 6

The single point of failure

What we see: one ageing PC that "runs everything", one person who knows all the passwords, or one server in a cupboard that nobody wants to touch. The business works — until that one thing doesn't.

What it risks: a single hardware failure or one person's holiday becomes a company-wide outage. The cost isn't the repair — it's every hour the business can't trade.

The fix: identify the single points of failure before they fail, then remove them one at a time — documentation, redundancy where it matters, and a plan for the rest.

Mistake 7

Nobody is actually watching

What we see: no monitoring of any kind — so failed backups, full disks, expiring licences and suspicious sign-ins go unnoticed until they become emergencies.

What it risks: problems that cost an hour to prevent become days to recover from. The difference between a non-event and a crisis is usually just whether anyone saw the warning.

The fix: lightweight monitoring on the machines that matter, with a human who actually reads the alerts. This is exactly what our Security Essentials baseline covers.

How many of the seven apply to your office?

A free health check tells you — a plain-English look at your backups, passwords, updates and email security, with no contract and no obligation. If everything's fine, we'll happily tell you that too.

Need IT help? Call 1300 769 337