Q3 is nearly over. For a lot of businesses across Liverpool, Wigan and Skelmersdale, that means Q4 planning is about to land on someone’s desk, budgets, hiring, growth targets, all of it.
IT rarely gets its own slot in that conversation. It either gets assumed to be fine because nothing has broken recently, or it gets bolted on at the end once everything else is already decided. By the time it does get mentioned, it is usually because something has already gone wrong and the conversation has turned into damage control rather than planning.
That is the wrong way round. A proper IT review before Q4 planning starts makes every other decision easier, because you are working from what is actually true rather than what you are hoping is true. Budgets get more accurate. Hiring plans account for the tools people will actually need. Growth plans do not get derailed halfway through the quarter by a piece of kit that quietly could not keep up.
Here is what we check on every review we run for a client, what it actually costs a business to skip this, and how to run a version of it yourself in an afternoon if you would rather start there.
1. Ageing And Unsupported Hardware
Hardware does not fail the moment it goes out of manufacturer support. It keeps running, right up until it does not, and by then there is no patch, no quick replacement part, and no easy fix. The failure tends to arrive at the worst possible moment, because ageing kit rarely waits for a convenient week.
The question worth asking is not “is everything still working.” It is “is anything running without support behind it.” Most manufacturers publish end of support dates for hardware and operating systems, so this is a genuine five minute check against a public list, not a guessing game.
It is also worth checking who in the business actually knows the answer. In a lot of the reviews we run, nobody does, because the last person who checked has since left, or it was never written down anywhere in the first place.
Quick self test:
Could you name, right now, a single piece of hardware in your business that is more than five years old? If you cannot, that is the first thing to find out.
2. Licenses You Are Paying For But Not Using
Software licences have a habit of sticking around long after the reason for buying them has gone. A tool trialled two years ago that never got cancelled. Extra user seats added for a project that finished months back. A subscription nobody currently at the business remembers signing up for.
None of it shows up as an obvious problem day to day. It just quietly adds up on the monthly invoice, often for years, without anyone noticing because the amount looks similar to what it always has been. A proper review lines up what you are paying for against what is actually being used right now, by real people, and cuts what is not.
This is usually the check that surprises business owners the most. It is rarely one large saving. It is normally three or four smaller ones that add up to more than expected once they are actually totalled.
Quick self test:
Pull up last month’s software invoices. Can you match every single line to a person who is actually using it? Most businesses cannot, on at least one line.
3. Who Still Has Access To Your Systems
This is the check that catches people out most often. Not who should have access, in theory. Who actually does, right now, today.
Ex employees whose accounts never got switched off after they left. Old suppliers who still have a login from a project that finished a year ago. Accounts nobody currently at the business remembers creating in the first place, sitting there with the same permissions they were given when they were set up.
Every one of these is an open door. Most businesses have at least one they do not know about, and the number tends to grow the longer it has been since anyone last checked. This is also one of the quickest wins to fix once it has actually been found, since removing access takes minutes once you know where to look.
Quick self test:
Think of the last person who left the business. Do you know, for certain, that every account they had access to has been switched off?
4. Security Gaps That Got Flagged And Never Fixed
Most businesses have had a security recommendation at some point that never quite got actioned. A patch that got delayed because it was not convenient at the time. A setting that got noted “for later” and then genuinely forgotten. A warning that got read, understood, and then quietly buried under everything else that felt more urgent that week.
None of this happens through carelessness. It happens because IT recommendations often arrive without a clear deadline attached, so they lose out to whatever has an actual date next to it. A Q3 review is the natural point to go back through anything flagged earlier in the year and actually close it out before Q4 starts, rather than letting it roll into another quarter unresolved.
Quick self test:
Has an IT recommendation ever been mentioned to you that you meant to come back to and never did? If one comes to mind immediately, that is where to start.
What Skipping This Actually Costs
None of the four things above are dramatic on their own. That is exactly why they get left. Nothing about an unused licence or an old login feels urgent, so it never quite makes it to the top of the list.
The cost shows up later, and it shows up bundled. The ageing server that finally needs replacing lands in the same month as a licence renewal nobody budgeted for, because both were left unchecked for the same length of time. A security gap that would have taken an hour to close in September becomes a genuine incident in November, at which point the cost is no longer just the fix, it is the lost time, the lost trust, and often the lost data too.
None of that is bad luck. It is what happens, predictably, when review gets left off the calendar for long enough. The businesses who avoid it are not the ones who have never had a problem. They are the ones who checked before the problem had the chance to arrive.
How To Run This Yourself In An Afternoon
If you would rather start with a version of this yourself before bringing anyone else in, here is a straightforward way to do it.
- List every piece of hardware older than three years and check its manufacturer support status against the vendor’s published end-of-life page.
- Pull your last three months of software invoices and match every line item to a named user who is actively using it.
- Ask whoever manages your accounts (or your IT provider) for a full list of active user accounts across your key systems, and cross it against your current staff list.
- Go back through any emails, notes, or previous IT reports for recommendations that were never actioned, and list them out in one place.
None of this requires specialist tools. It requires blocking out an afternoon and actually looking, which is usually the only step most businesses skip.
Why This Matters
Every quarter is a fine time to review IT. September specifically matters because it sits right before budgets and plans for the next quarter get finalised. A review done now feeds directly into the Q4 numbers while there is still time to act on what it finds. A review skipped now means Q4 gets planned around assumptions instead of facts, and any surprises that were sitting there all along land mid quarter instead of being priced in beforehand.
It is also simply easier to fix something in September, with a full quarter ahead, than to fix it in November under pressure because it has already caused a problem.
What To Do With What You Find
A review is not about finding fault. Nobody runs one to catch anybody out. It exists purely so you know what you are actually working with before you commit to a Q4 plan built around it.
Once you know what needs replacing, what is due for renewal, and where the current gaps sit, the rest of Q4 planning gets noticeably easier to write with any real confidence.
If you would rather have someone else run through this with you, we do exactly this review for businesses across Liverpool, Wigan and Skelmersdale, free of charge and with no obligation either way. Get in touch and we will find a time before Q4 starts.
FAQs
How long does a proper IT health check actually take?
For most small and medium businesses, a full review takes somewhere between half a day and two days depending on the number of systems and users involved. Each of the four checks above can be done in isolation in under an hour if you are short on time and want to start with just one.
Do I need to involve my current IT provider to get a second opinion?
No. A health check does not require access to change anything, only to look. Most reviews can be run alongside an existing provider without them needing to be involved at all, and plenty of business owners prefer it that way, at least until they have seen the results for themselves.
What happens if the review finds something serious?
It gets flagged clearly, along with an explanation of the actual risk and the options for fixing it. There is no pressure to act immediately unless something is genuinely urgent. Most findings are the kind of thing worth planning properly into Q4, not an emergency on the spot.
Is there a cost if I do not end up switching provider afterwards?
No. The review itself is free and there is no obligation to change anything as a result of it. Plenty of businesses use it purely to confirm their current setup is in good shape and walk away with nothing more than peace of mind.
How often should a business run this kind of review?
Quarterly is a sensible default for most small and medium businesses, timed just ahead of budget or planning cycles like this one. Businesses going through rapid change, such as hiring quickly or moving premises, often benefit from checking more frequently than that.
Can I run this check across a business with more than one site?
Yes, though it takes longer per extra site since access, hardware and licensing can vary between locations. Businesses across Liverpool, Wigan and Skelmersdale with more than one office usually find the access review is the step most likely to throw up differences between sites.
What is the single most common thing this kind of review finds?
Access that should have been removed and was not. Across the reviews we run, it comes up more often than ageing hardware, unused licences or unfixed security gaps combined, which is exactly why it gets its own section above.