Version 1.1 · 2026-08-07 · ToughBlue Uganda Ltd.
Rate each item: Good · Partial · Needs work · N/A. Complete triage first — optional sections apply only where marked Yes.
Answer Yes or No. Every client completes the core sections (31 questions). Optional sections add 37 more questions when relevant.
| # | Question | Y | N | If Yes → include |
|---|---|---|---|---|
| 1 | Do they have servers, NAS, or on-site equipment running 24/7? | Servers & On-Premises | ||
| 2 | Do they use cloud services (M365, Google, AWS, Azure, SaaS)? | Cloud & Online Services | ||
| 3 | Multiple sites, VLANs, business firewall, VPN, or site links? | Network (Advanced) | ||
| 4 | Do staff work remotely or need remote access? | Remote Work | ||
| 5 | Specialised business software (ERP, CRM, POS, MIS, custom apps)? | Business Software | ||
| 6 | Shop, hotel, restaurant, POS, or card payments? | Retail & Hospitality | ||
| 7 | Regulated or sensitive data (finance, health, donor, members)? | Compliance & Data | ||
| 8 | Field laptops, tablets, or mobile data collection? | Field Operations | ||
| 9 | Dedicated IT person, team, or contracted provider? | IT Support & Process | ||
| 10 | Would hours of downtime seriously hurt operations or revenue? | Continuity & DR |
Context and IT ownership
Every business depends on a few systems — email, accounting, POS, or a custom app. If those stop, work stops.
Look for: Ask: 'What would you do if email was down all day?' Note whether they can name specific systems and owners.
Someone must decide on IT spend, approve changes, and be called when things break — even if IT is not their main job.
Look for: A named director, office manager, or external vendor contact — not 'everyone just calls James'.
When the internet fails or email stops, you need account numbers and support lines without searching.
Look for: A shared document, spreadsheet, or binder — or nothing at all (flag as risk).
Domains, hosting, and cloud paid via a personal Gmail or mobile money lock you out when that person leaves.
Look for: Who receives renewal invoices? Whose phone number is on the domain registrar account?
Laptops, desktops, and phones
Unsupported Windows 10/11 builds or old macOS versions no longer receive security patches.
Look for: Check Settings → About on 2–3 machines. Note any Windows 7/8 or very old macOS.
Consumer trial antivirus that expired is the same as no protection.
Look for: Windows Security, Defender, Kaspersky, ESET, etc. — confirm definitions update date.
Unlocked laptops in open offices allow anyone to copy files or read email.
Look for: Walk away test: does the screen lock within a few minutes? Is there a login password?
Daily admin rights let malware install software and ransomware spread silently.
Look for: Ask if staff can install software themselves. Check User Account Control settings.
A stolen laptop without encryption exposes all local files and saved passwords.
Look for: BitLocker (Windows) or FileVault (Mac) status on laptops that leave the building.
Ad hoc setup means missed accounts, wrong permissions, and no record of what was issued.
Look for: Is there a checklist or standard kit (email, Wi-Fi, apps, phone extensions)?
Communication and document storage
Clients and partners trust @company.com. Personal Gmail for business looks informal and complicates handover.
Look for: Check email signatures and mail headers for 3–4 staff members.
Business platforms include proper admin controls, shared mailboxes, and recovery options.
Look for: Microsoft 365 admin, Google Workspace, Zoho, cPanel email — or mixed personal accounts.
If all files live on one PC, that person becoming sick or leaving halts the department.
Look for: Shared drive, SharePoint, Google Drive, server folder — who can access what?
Ex-staff with active email can read messages, reset passwords, or impersonate the company.
Look for: Ask HR/process: how quickly are accounts disabled? Any former staff still in the address list?
Without SPF/DKIM/DMARC, attackers can send email pretending to be the company.
Look for: Use MXToolbox or ask who manages DNS. Many SMEs have never configured this.
Internet and Wi-Fi essentials
If only one person knows the ISP account, billing lapses and outages take longer to fix.
Look for: ISP name (MTN, Airtel, Roke, Liquid, etc.), plan speed, and account contact.
ISP routers often have weak defaults and limited logging — not ideal for business traffic.
Look for: Dedicated firewall (FortiGate, MikroTik, Ubiquiti) vs single ISP-provided box.
Guest devices on the same network as file shares and printers is a common attack path.
Look for: Separate SSID for guests? Can guests see printers or internal IPs?
Default admin passwords (admin/admin, printed on router stickers) are widely exploited.
Look for: Ask if Wi-Fi or router passwords were ever changed from factory defaults.
Frequent drops or slow upload hurt video calls, cloud apps, and POS transactions.
Look for: Staff complaints, speed test on site, loose cables, or overloaded consumer router.
Protecting data from loss
Backing up 'some files' but not email, databases, or cloud data leaves major gaps.
Look for: Written or verbal list of what is backed up — compare to what they say is critical.
Manual USB copies happen weekly at best and are forgotten during busy periods.
Look for: Scheduled backup job, cloud sync, NAS task — or 'someone copies when they remember'.
Fire, theft, or ransomware destroys local backups on the same premises as originals.
Look for: Cloud copy, second office, or off-site drive rotation — not one USB in a drawer.
Many discover backups are empty or corrupt only during an emergency.
Look for: Ask for the date of the last successful file or mailbox restore test.
Backup jobs fail silently when disks fill up or credentials expire.
Look for: Email alerts, dashboard, or monthly manual check of backup logs.
Access control and threat awareness
Includes email, VPN, Wi-Fi passwords, cloud admin, and remote support tools.
Look for: Review active user list in email admin. Any names that should not be there?
Password-only email is the #1 route for business email compromise and fraud.
Look for: Microsoft/Google admin MFA enforcement status for admins and all users.
Shared admin passwords cannot be audited and stay unchanged for years.
Look for: Sticky notes, WhatsApp groups named 'passwords', Excel files on desktop.
Forgotten TeamViewer or AnyDesk installs allow remote access without your knowledge.
Look for: List remote tools in use, who installed them, and whether old IDs still work.
Unpatched systems are vulnerable to known exploits within days of disclosure.
Look for: Windows Update status, browser versions, server patch dates.
One clicked link on an finance PC can lead to invoice fraud or ransomware.
Look for: Any training? Do staff know to call IT before paying changed bank details?
Local infrastructure
Triage: Do they have servers, NAS, or on-site equipment running 24/7?
Without a list, nobody knows what will break when hardware fails.
Look for: Server names, roles (file, database, domain controller), OS version labels.
Unpatched servers are high-value targets and may not restart cleanly without planning.
Look for: Last Windows Update or apt upgrade date. Maintenance window agreed with business?
Power cuts without UPS cause corrupt databases and sudden outages.
Look for: UPS beeping tests, runtime minutes, whether servers shut down gracefully.
Heat, dust, and public access shorten hardware life and increase theft risk.
Look for: Locked cabinet, ventilation, temperature, clean cabling.
Shared 'Administrator' password on server means no accountability.
Look for: Named admin accounts, separate domain admin from daily user.
M365, Google, AWS, SaaS
Triage: Do they use cloud services (M365, Google, AWS, Azure, SaaS)?
Cloud tied to ex-employee personal email = loss of admin access and billing disputes.
Look for: Tenant owner account, billing contact, who can reset global admin.
Cloud global admin without MFA is a single password away from total tenant takeover.
Look for: Azure AD / Google admin security defaults and MFA registration report.
Microsoft 365 and Google have limited native retention — not full backup.
Look for: Third-party backup (Veeam, Datto, AvePoint) or 'we assume Microsoft keeps it'.
Paying for 50 licences when 38 staff remain wastes budget and hides security gaps.
Look for: Compare HR headcount to assigned licences in admin portal.
Multi-site, VLANs, VPN
Triage: Multiple sites, VLANs, business firewall, VPN, or site links?
Troubleshooting without a diagram wastes hours tracing cables and VLANs.
Look for: Visio, draw.io, whiteboard photo, or engineer tribal knowledge only.
POS, CCTV, and guest Wi-Fi on staff LAN increases breach blast radius.
Look for: VLAN IDs, separate SSIDs, firewall rules between segments.
Learning about outages from angry staff is reactive and damages trust.
Look for: UptimeRobot, PRTG, Zabbix, ISP SMS alerts — or nothing.
Single ISP fibre cut stops entire branch operations.
Look for: 4G/LTE router failover, second ISP, or manual phone hotspot only.
Home and mobile access
Triage: Do staff work remotely or need remote access?
RDP port open to internet is scanned and attacked thousands of times daily.
Look for: VPN client, Azure AD app proxy, or cloud-only apps vs direct RDP exposure.
Personal laptops may lack encryption, patches, or legal data controls.
Look for: BYOD policy, company-issued kit, MDM enrollment.
Clear rules reduce data leakage and set expectations for home workers.
Look for: Written policy or informal 'use your own laptop' approach.
ERP, CRM, POS, custom systems
Triage: Specialised business software (ERP, CRM, POS, MIS, custom apps)?
Surprise renewals and unsupported old versions create operational and legal risk.
Look for: List of ERP, accounting, HR, POS apps with version and renewal dates.
When the app fails on month-end, who gets called and how fast do they respond?
Look for: Vendor SLA, local partner, internal super-user, or panic.
Unlicensed software blocks updates and creates audit liability.
Look for: Receipts, volume licences, or cracked/pirated installs (note discreetly).
Custom systems without docs depend on one developer who may leave.
Look for: Git repo, hosting login, database schema, API docs.
POS, payments, guest Wi-Fi
Triage: Shop, hotel, restaurant, POS, or card payments?
Compromised guest Wi-Fi can reach POS terminals on flat networks.
Look for: Separate VLAN for POS, physical network isolation.
Internet outages during peak hours should not stop all sales.
Look for: POS offline queue mode tested? Manual fallback procedures?
Lost sales and inventory data from one night can take days to reconcile.
Look for: End-of-day export, cloud sync, or USB manual backup habits.
Regulated and sensitive information
Triage: Regulated or sensitive data (finance, health, donor, members)?
Auditors and regulators expect who-did-what trails on financial systems.
Look for: Audit logs enabled in accounting/SACCO/core banking software.
One person approving and executing payments enables fraud.
Look for: Separate approver and payer roles in finance systems.
Donor, member, patient, or student data mishandling carries reputational and legal risk.
Look for: Where PII is stored, who can export it, encryption at rest.
Mobile teams and data collection
Triage: Field laptops, tablets, or mobile data collection?
Lost tablets with beneficiary data and no tracking is a data breach.
Look for: Sign-out sheet, asset tags, remote wipe capability.
Field data on one device only disappears if the device is lost or damaged.
Look for: Kobo, ODK, SurveyCTO, custom app sync — or Excel on laptop only.
Rural sites with poor signal need apps that queue data until connected.
Look for: Test sync from a low-signal area or ask field staff about failures.
Helpdesk, policies, vendor management
Triage: Dedicated IT person, team, or contracted provider?
Untracked requests get forgotten and the same issue is fixed repeatedly.
Look for: Freshdesk, Zendesk, shared inbox, WhatsApp group — or verbal only.
Unclear expectations lead to frustration between staff and IT.
Look for: Published response times, even informal ones on office notice board.
New hires without IT setup lose first-week productivity; leavers keep access.
Look for: HR triggers IT checklist for start, move, and exit dates.
Surprise renewal costs or hardware failures stall projects without a budget line.
Look for: Annual IT line item in finance plan, or reactive 'find money when broken'.
Surviving serious outages
Triage: Would hours of downtime seriously hurt operations or revenue?
In a crisis, people need a written plan — not improvisation.
Look for: One-page DR doc: contacts, backup location, recovery steps.
One server, one IT person, one ISP — any one failure stops the business.
Look for: Brainstorm top three dependencies and whether backup exists for each.
Untested DR plans fail on assumptions — wrong backup age, missing credentials.
Look for: Date of last tabletop exercise or restore drill.
Recovery Time Objective sets expectations: how long until email, POS, ERP return.
Look for: Leadership agrees 'we can tolerate X hours/days' — even informally.
A subsidiary of ToughBlue GmbH (Germany) · German engineering · Ugandan delivery