Please answer every question in this step.
Step 1
Support and Devices
01
Support flow When someone has an IT issue, what usually happens?
There is a clear support path and response expectation
There is a support path, but response expectations are informal
People often ask whoever seems technical
Issues are handled only when they become urgent
02
Recurring problems How often do the same technology problems come back?
Rarely; root causes usually get fixed
Sometimes; a few recurring issues remain
Often enough that people work around them
Constantly; the business is mostly reacting
03
Device security Are work computers actively patched, protected, and monitored?
Yes, with patching, endpoint protection, and alerts reviewed
Mostly, but some devices or alerts need cleanup
We have antivirus, but visibility is limited
No clear device security or monitoring process
04
IT decisions How are technology changes, renewals, and vendor decisions made?
They are planned around business needs, risk, and budget
Some planning happens, but renewals still sneak up
Decisions are usually made when something breaks or expires
There is no clear owner for tools, vendors, or roadmap decisions
Step 2
Security, Access, and Recovery
05
Recovery confidence If important files, email, or systems were lost, how confident are you in recovery?
Confident; backups are monitored and restore tests happen
Backups exist, but restore testing is inconsistent
Not sure what is backed up or how long recovery would take
No clear backup or recovery process
06
Account protection How well are logins, MFA, and admin accounts controlled?
MFA is enforced and admin access is limited and reviewed
MFA is mostly used, but admin/access reviews need work
Some important accounts still rely on weak or shared access
We are not sure who has access to critical accounts
07
User lifecycle What happens when someone joins, changes roles, or leaves?
There is a checklist and access is reviewed
There is a basic process, but it depends on the situation
Access changes are manual and easy to miss
Old accounts or permissions may still exist
08
Email and phishing How prepared is the team for suspicious emails, links, and payment requests?
Email protection, training, and reporting steps are in place
Some protection exists, but training or reporting is informal
People rely mostly on judgment and asking around
There is no clear process for suspicious messages
Step 3
Cloud, Planning, and AI
09
Cloud organization How organized are Microsoft 365, Google Workspace, files, and permissions?
Well organized, with permissions and sharing reviewed
Mostly workable, but cleanup would help
People are not always sure where files live or who has access
It has grown messy and risky over time
10
AI guardrails How is your team using AI tools like ChatGPT, Copilot, or Claude?
Approved tools and clear data rules are in place
People use AI, but guidance is still being developed
A few people experiment without a shared standard
We do not know what tools are being used or what data goes into them
11
Incident response If email was compromised, systems went down, or ransomware was suspected, what would happen?
Roles, contacts, and first steps are documented
Key people know what to do, but it is not fully documented
We would probably figure it out in the moment
No clear response plan exists
12
Continuity expectations Does the business know which systems must come back first after an outage?
Yes, priorities and recovery expectations are clear
Mostly, but the plan needs to be written down
Only a few people have an informal idea
No; we would decide during the outage