One bad Monday can expose an entire IT strategy. At 9:17 in the morning, a Nairobi logistics coordinator opens the dispatch dashboard and finds that the shared drive is unavailable. Ten minutes later, the office internet drops. The backup connection was never configured, so staff start printing delivery forms while M-Pesa payments continue arriving in a phone inbox that no one is matching to orders.

By noon, deliveries are late, customers are calling, and the finance team is rebuilding records by hand. Most owners blame a bad router or one slow laptop. The real problem is usually much bigger: the business has equipment, but no reliable IT operating system.

That is where this checklist helps. These are 10 practical fixes that can reduce downtime, protect revenue, and stop costly IT decisions. They are designed for Kenyan SMEs, not multinational corporations with unlimited budgets.

Why Small IT Gaps Become Expensive KSh Decisions

Growing businesses rarely suffer from one dramatic technology failure. They lose money through dozens of small gaps: a laptop without support, an untested backup, two people holding the only cloud passwords, or an internet line that fails every afternoon.

The pressure is familiar. Owners must pay staff on time, send VAT and other tax records to the Kenya Revenue Authority, reconcile M-Pesa transactions, manage inventory, and respond to customers. Meanwhile, IT is often handled between other jobs by whoever knows how to restart the router.

Consider a growing retailer in Kilimani. It buys five new laptops, installs accounting software, and receives a second internet connection from a different provider. On paper, the setup looks modern. In reality, there is no asset register, no recovery test, no access policy, and no agreed response time if the accountant cannot log in.

The issue is not a lack of effort; it is the absence of an IT baseline. The costs then appear as delayed invoices, duplicated data entry, lost stock records, emergency repairs, and employees waiting idly when a system is unavailable.

Good infrastructure does not mean buying the most expensive equipment. It means knowing which systems support revenue, who owns them, how they recover, what they cost to run, and when they must be improved.

Stop the 3 IT Confusions That Slow Kenyan Teams First

You cannot manage what nobody can see. Before spending more money, establish a clear picture of your devices, systems, responsibilities, and daily workflows. This first phase often reveals problems that cheaper hardware cannot fix.

1. No One Knows What IT Assets the Business Actually Has

A laptop may be in use, in storage, borrowed by a sales representative, or already replaced without being recorded. The same confusion applies to servers, routers, external drives, accounting licences, barcode scanners, and cloud subscriptions.

  • Record the device name, serial number, purchase date, warranty, user, location, operating system, and critical applications.
  • Identify the business owner and technical owner for each important system.
  • Separate active, retired, and待被 disposed assets rather than assuming every device still exists.
  • Check licences against actual users so the company is not paying for unused seats or running unsupported software.
  • Reconcile the register every quarter and whenever staff join or leave.

Start with a simple spreadsheet if that is what you have. Consistency matters more than fancy software. If you cannot locate a device, its warranty, or its owner in under five minutes, the control is not working.

2. Every Critical System Has No Clear Owner

An asset owner looks after the physical equipment. A business owner decides how the system supports operations. A service provider maintains the technical environment. When all three responsibilities are vague, a problem becomes a chain of excuses.

  • Name one manager responsible for each revenue-critical system, such as accounting, customer records, e-commerce, or dispatch.
  • List the technical provider, support number, contract reference, and escalation contact.
  • Define who can approve spending, change access, restore data, and declare an outage serious.
  • Keep this information in a secure, access-controlled directory rather than inside one employee’s phone.

For a small team, one person can hold several roles. That is fine. What is not fine is discovering the only contact, password recovery method, or vendor contract during an emergency.

3. Important Processes Live Only in One Employee’s Head

When a senior administrator leaves, a business can unexpectedly lose access to email, cloud files, domain names, payment integrations, and administrative consoles. Even routine tasks such as closing the books or backing up a database become risky if nobody else understands them.

Document the essential workflows without exposing passwords in the document. Use a reputable password manager and grant access according to role.

  • Back up and restore accounting records.
  • Reconcile M-Pesa payments and identify exceptions.
  • Issue, amend, and retain invoices where KRA requirements apply.
  • Process payroll and protect employee information.
  • Revoke access when someone leaves and transfer outstanding work.

A useful procedure should allow a competent colleague to complete the task safely without calling the original employee at midnight. This is also valuable preparation for growth, audits, financing, and a future sale of the business.

Fix the 3 IT Weaknesses That Can Freeze Revenue

Availability is a revenue feature, not an IT luxury. Customers do not care how sophisticated your server is if they cannot place an order, receive a quotation, or confirm payment. Protect the systems that directly support cash flow first.

4. Power and Connectivity Fail Without a Tested Plan

Map the equipment that must remain alive during an outage: internet modem, router, switches, servers, Wi-Fi controllers, payment terminals, and the devices used to serve customers. A small uninterruptible power supply may keep network equipment running for 30 minutes. It will not power an entire office for a day.

  • Use a UPS for critical network and storage equipment, with automatic shutdown where supported.
  • Assess inverter or generator capacity before connecting sensitive electronics.
  • Keep a second internet connection ready, ideally through a different provider and physical entry point where possible.
  • Configure automatic or documented failover instead of assuming a spare router will activate itself.
  • Test mobile broadband, generator startup, backup internet, and recovery procedures at least quarterly.
  • Record outage duration and the time required to restore each service.

Do not test by unplugging cables randomly. Schedule the test, protect active work, and measure the result. A backup that has never been switched on is an assumption, not resilience.

5. Backups Exist, but Recovery Has Never Been Proven

Many businesses can create a backup. Far fewer can prove that the backup is complete, readable, secure, and restoreable within the time the business can tolerate. A corrupted file, deleted invoice, failed update, theft, fire, or ransomware event will expose the difference.

  • Follow the 3-2-1 principle: three copies of important data, on two types of storage, with one copy offline or off-site.
  • Encrypt sensitive backups and restrict who can delete or alter them.
  • Keep at least one backup outside the main office and, where appropriate, outside the local network.
  • Monitor jobs so a failed nightly backup produces an alert, not a silent record.
  • Run a real restoration test and verify that files, databases, permissions, and applications open correctly.

Define two simple targets. The recovery point objective is the oldest data you can afford to lose. The recovery time objective is how long systems can remain unavailable before the damage becomes serious.

For example, a dispatch database might tolerate 15 minutes of data loss but not four hours of downtime. Accounting records may tolerate more delay but require highly accurate restoration. These targets determine how much you should invest, not the other way around.

6. M-Pesa, Accounting, and Sales Records Do Not Reconcile Cleanly

M-Pesa can speed up collections, but it can also create a second source of truth. Payments may arrive through a Paybill or business shortcode, till number, STK push, QR code, or personal number. If those records are not linked to invoices and customer accounts, finance staff spend hours chasing mismatches.

  • Use a dedicated business payment channel wherever suitable and restrict access to authorised staff.
  • Capture the customer, order, invoice, M-Pesa reference, amount, date, and reconciled status.
  • Set a daily cutoff time and investigate failed, reversed, or duplicate transactions.
  • Separate payment initiation, approval, and reconciliation so one person does not control the whole process.
  • Ensure sales, discount, refund, and tax records agree with accounting records and applicable KRA requirements.

At day close, the total should tell a coherent story: what was sold, what was paid, what remains outstanding, and what needs investigation. If it does not, the business is making decisions from incomplete information.

Remove the 3 IT Bottlenecks That Make Growth Expensive

Your systems should get easier to manage as volume grows. A setup that works for 10 employees can become expensive and fragile at 50. Cloud choices, access controls, and performance assumptions need to be reviewed before the team hits that ceiling.

7. Cloud Decisions Are Based on Habit, Not Business Fit

Cloud does not automatically mean cheaper, faster, or safer. It changes where data is stored, who controls access, how integrations work, and what happens if the supplier relationship ends. Evaluate the business outcome before choosing a platform.

  • Confirm which applications are mission-critical and how much downtime each can tolerate.
  • Check integration with accounting, M-Pesa, inventory, email, customer support, and reporting tools.
  • Review data ownership, export options, service levels, support hours, security controls, and termination terms.
  • Consider where data is processed and stored, especially when personal data is involved under Kenya’s Data Protection Act.
  • Calculate total cost, including licences, setup, training, integrations, storage, support, and migration.

Run a small pilot before migrating an entire operation. Use a non-critical workflow, test data export, train a few users, and measure support response. Avoid replacing one dependency with another without knowing how to leave.

8. Users Have Too Much Access or Forgotten Accounts

Every employee, contractor, supplier integration, and old laptop can become an entry point. Excessive access increases the damage caused by a stolen password, phishing message, or accidental deletion. It also makes investigations difficult.

  • Use multi-factor authentication for email, accounting, cloud storage, remote access, and payment administration.
  • Grant the minimum access required for each role and avoid shared administrator accounts.
  • Review active users quarterly, including contractors and former employees.
  • Disable access immediately when someone leaves and confirm that company devices and data have been returned.
  • Review privileged access after major projects rather than allowing temporary elevation to become permanent.

Keep an offboarding checklist that covers email, cloud files, social media accounts, payment channels, VPN access, domain settings, and physical keys. The fastest way to prevent a painful exit is to design it before the last day.

9. Endpoints and Software Are Patched Only by Instinct

Laptops, desktops, mobile devices, routers, and applications need consistent security updates. Waiting until something breaks creates more expensive emergency work. At the same time, installing every update immediately can disrupt operations, so patching should be planned by risk.

  • Maintain a current list of devices and operating systems before trying to secure them.
  • Prioritise internet-facing systems and critical vulnerabilities using a risk-based schedule.
  • Enable device encryption, automatic screen locks, firewalls, and reputable endpoint protection.
  • Remove unused software and local administrator rights where practical.
  • Back up important data before major updates and test critical applications afterward.
  • Train staff to report suspicious messages, unexpected payment requests, and unfamiliar login prompts.

Security training should be specific to Kenyan business realities. Warn staff about fake delivery notifications, altered invoice emails, fraudulent M-Pesa messages, and requests to move payments to a new beneficiary. Technology controls help, but people remain an essential layer.

Turn the Final IT Fix Into a Budget Owners Trust

A credible IT roadmap makes growth easier to finance. Lenders, investors, partners, and senior teams are more confident when technology spending is connected to measurable business outcomes rather than vague requests for new computers.

10. There Is No IT Budget, Service Standard, or Success Metric

Separate spending into three categories: systems that must operate, controls that must protect the business, and technology that enables growth. This prevents every request from competing for the same emergency cash.

  • Run: internet, power protection, devices, licences, support, and routine maintenance.
  • Protect: backups, identity security, endpoint controls, patching, data privacy, and incident response.
  • Grow: automation, analytics, customer portals, e-commerce, inventory improvements, and scalable cloud services.

For external providers, agree on service expectations before an outage occurs. A basic service-level agreement should cover supported hours, response times, resolution targets, backup responsibilities, security duties, reporting, data ownership, and exit arrangements.

  • Track system availability for revenue-critical applications.
  • Measure backup success and actual restoration time.
  • Count urgent incidents and identify recurring causes.
  • Measure how long finance staff spend reconciling M-Pesa and invoices.
  • Track help requests, user adoption, and completed training.

A practical 90-day plan can be simple:

  1. Days 1-30: inventory assets, name owners, secure critical accounts, and test one important backup.
  2. Days 31-60: fix connectivity gaps, reconcile payment workflows, remove unused access, and define service standards.
  3. Days 61-90: automate one high-friction process, review cloud costs, train staff, and establish monthly IT metrics.

This sequence delivers visible improvement without turning the business into a technology laboratory. It also creates evidence of what changed, what it cost, and how it protected or increased revenue.

Why Smart Kenyan Businesses Are Fixing This Now

Forward-thinking businesses across Nairobi are already treating infrastructure as a growth control. They may not have a large IT department, but they share a disciplined approach.

Retailers connect M-Pesa activity to sales records. Logistics companies test backup internet and monitor vehicle-related systems. Agribusinesses protect inventory and finance data. Schools, clinics, manufacturers, and professional firms use cloud collaboration, multi-factor authentication, documented procedures, and vendor support.

  • They know which systems directly affect revenue.
  • They test recovery instead of trusting a green backup icon.
  • They measure uptime, incidents, and time saved.
  • They review access whenever people or responsibilities change.
  • They budget for protection before disaster strikes.

The urgency is practical. Customers now expect fast responses, accurate invoices, secure digital service, and minimal disruption. When two suppliers offer similar products, the business that keeps its systems reliable gains trust before the sales conversation even begins.

Your 30-Day IT Infrastructure Checklist Starts With One Honest Review

Do not start by buying more laptops. Start by finding the gaps that threaten revenue, data, and customer service. Then fix the highest-risk controls first and build from there.

Use the 10-point checklist above as your starting audit. If any answer feels uncertain, that is useful information, not a reason to panic. A clear priority list is better than another expensive purchase made under pressure.

Ready to turn scattered IT tasks into a practical growth plan? The team at Savannah Software Solutions can help you assess your current setup, prioritise urgent risks, and build an affordable roadmap for your Kenyan business.