If Your Business Went Offline Tomorrow, What Would You Do First?
October is Cyber Security Awareness Month. Before another reminder about passwords, ask a business question: could you still look after your customers if you suddenly lost access to email and files?

Picture this hypothetical Monday morning. A member of your team cannot open a shared folder. Someone else cannot sign in to email. You are waiting for approval on an important quote, and a customer is asking for an update you cannot check.
Within a few minutes, the questions are no longer technical. Can we send the invoice? Can we confirm the delivery? Who do we call? What should we tell the customer?
Your customer does not see an IT problem. They see a promise you might not be able to keep. Your staff are looking to you for a decision, but you do not yet know whether this is an ordinary outage, an account problem or something more serious.
Not every interruption is a cyber attack. Mistakes and service outages happen too. The point is not to assume the worst. It is to ask whether your business knows how to respond while the cause is being investigated.
Being Aware Is Not the Same as Being Ready
Most business owners know that cyber security matters. They have heard about phishing, stronger passwords and backups. But knowing the risks exist is different from knowing what would happen in their own business.
Listen to the difference between an assumption and an answer:
- “We have backups” is not the same as knowing which information can be restored and how long it takes.
- “Our IT company handles that” is not the same as knowing who responds, how to reach them and what they are responsible for.
- “Our staff are careful” is not the same as giving them a clear, blame-free way to report a mistake.
- “We use Microsoft 365” is not the same as checking how accounts, access and recovery are actually configured.
None of those statements makes someone careless. They are reasonable assumptions when you are busy running a business. Cyber Security Awareness Month is an opportunity to replace the assumptions that matter with clear answers.
Five Questions to Ask Your Team This October
Bring together someone who understands the day-to-day business and someone responsible for IT. Walk through these questions as a short discussion, not a test. Write down what you know and what needs checking.
1. Which Jobs Would Stop First?
Start with the work, not the software. Could you process an order, find a customer record, issue an invoice or access the documents needed for a job? Identify what must continue first and what can wait. That gives recovery planning a business priority rather than a generic list of systems.
2. Who Would Make the First Decisions?
Agree who contacts your IT provider, who keeps staff informed and who can authorise urgent action. Make important contact details available without relying on the systems you may have lost. If email might be compromised, know which trusted alternative you would use to coordinate the response.
3. Have We Proved We Can Get Our Information Back?
Ask what your backups cover, how they are protected and when a restore was last tested. A successful backup notification does not prove that the right information can be recovered quickly enough. Cloud storage and file synchronisation are useful, but they are not automatically a complete recovery plan.
4. Do We Know Who Still Has Access?
Think about former employees, contractors, shared accounts and administrator permissions. Are leavers removed promptly? Is access appropriate to each role? Are stronger sign-in methods in place? Those are questions to check with your provider, not reasons to make rushed account changes without understanding the consequences.
5. What Would We Tell Our Customers?
Decide who owns customer communication and how you would reach people if normal email was unavailable. Be clear about what you know, what you are investigating and when you will provide an update. Do not guess about the cause or promise a recovery time you have not confirmed. Clear communication helps protect trust while work is under way.
If You Found a Gap, You Have Found a Starting Point
You do not need to fix everything at once. Choose the uncertainty that would cause the greatest disruption, give someone responsibility for checking it and agree when you will review the answer.
That might mean confirming your provider's incident contact arrangements, testing the recovery of an important folder or reviewing access for people who have left. The useful outcome is something you can verify, not another reassuring statement.
This is not about blaming staff or changing IT providers for the sake of it. A review may confirm that important protections are already working. Where there are gaps, it helps you prioritise the ones that matter to your business.
How Konnetix Can Help You Get Clear Answers
Konnetix's Complete 365 is a fully managed IT, cyber security and business assurance service. It brings day-to-day support, account and device protection, monitoring, backup and ongoing oversight into a joined-up approach.
A first conversation starts with how your business works, what it depends on and where you want more confidence. We can discuss whether a free Complete 365 Security Review is an appropriate next step and explain what that review would cover. You do not have to arrive knowing which technical solution you need.
No service can promise that an incident will never happen. What matters is reducing avoidable risks, knowing who is responsible and having recovery arrangements that have been checked.
This October, do more than remind your team to be careful. Make sure they know who will help, what happens next and how you will keep looking after your customers.
You Do Not Need All the Answers Before You Call
If one of these questions made you pause, that is enough to start. Tell us what your business could not do without, and let's talk about how well it is protected.
Let's Talk About Your Cyber SecurityNo obligation. No pressure. A practical conversation about your business.
Prefer to call? 01462 417 070