Post Image

Insight: Proactive Starts Before Anything Breaks

Every IT company describes itself as proactive. Few explain what the word means, and fewer still can show you what it looks like in practice.

There is a simple test, and you can run it before you sign anything.

  • Did they make a real effort to understand your business?
  • Can they add value in solving business problems, not just technical ones?
  • Can they help you reach your business goals?

Proactivity starts at the very outset. It is visible in the first meeting. If a prospective partner spends that meeting on their toolset and their response times, you have your answer. If they spend it asking about your clients, your regulator, your growth plan and the way work actually moves through the firm, that is a different signal.

Proactive is not a service level. It is a habit, and habits show up early.

The short version:

  • Every IT company claims to be proactive — but you can test it before you sign, in the first meeting, by what they ask about.
  • Boutique firms of 40 to 50 people are strong, not unfinished. What they usually lack is the written process behind the work: no information security policy, no asset or risk register, no documented joiner or leaver process. None of it shows in a service report; all of it shows in a due diligence questionnaire.
  • A real partner does five things: a technology plan matched to your business plan, secure data flow, safe AI adoption, business-risk identification, and translation for the people who make decisions.

What a boutique firm does not have in-house

A firm of 40 or 50 people rarely has an HR function of its own, or easy access to HR advice when something difficult lands.

It does not have an in-house legal team.

It does not have an in-house information security expert. Often there is nobody who is both knowledgeable and formally responsible. The job drifts to whoever sits closest to the technology, which usually means the person with the most patience rather than the most training.

This is not a criticism. It is arithmetic. At 40 or 50 people you cannot justify a head of information security, and nobody expects you to.

Boutique is a strength, not a stage

Firms of this size choose to be this size. Decisions get made in a morning. Everyone knows the clients. Change lands in days rather than quarters. The partners are in the work, not three layers above it.

Scale is not sophistication. Some of the most disciplined, best-run firms we work with have fewer than 50 staff. Some large organisations are a mess behind the logo. Nor does scale determine risk. A boutique firm holding twenty years of confidential client files is a serious target, and attackers do not check headcount first.

What scale does affect is what falls off the desk. A firm of 50 rarely loses a client because the laptops are slow. It can lose a tender because it cannot evidence how it handles client data. Those are different problems, and only one of them looks like an IT problem.

What gets missed is the bigger picture

The pattern is consistent. Leaner firms are excellent at the work and thin on the written process behind it.

There is no written information security policy, or there is one that was bought as a template in 2019 and has not been read since.

There is no documented new user process. Someone starts, somebody sets them up from memory, and the permissions they end up with depend on who did it and how busy they were that week.

There is no leaver process, which is the same problem with sharper consequences.

There is no asset register, so nobody can say with confidence what devices exist, who holds them, or which ones are still receiving updates.

There is no risk register, so risks are held in individual heads and surface only when they turn into events.

None of this shows up in a monthly service report. All of it shows up in a due diligence questionnaire, a client audit, an insurance renewal or a tender.

What a proactive IT partner should actually do

Advise on what is best for your business, not just fix the matters you bring to them. In practice that means five things.

A technology plan that matches the business plan. Not a schedule of replacements and upgrades. A schedule tells you the laptops are three years old. A plan tells you what needs to be true about your technology in eighteen months for the business plan to work, and what that costs. If you are opening a second office, taking on regulated work or doubling headcount, the technology decisions change. If nobody is asking about the business plan, you are being given a schedule and sold a plan.

Secure information storage and flow. Where client data lives, how it moves, who can reach it, and what happens when someone shares the wrong thing with the wrong person. Secure sharing with clients and third parties. Data loss and leakage prevention, configured and understood rather than switched on and forgotten.

Help to design and implement AI safely and effectively. Your people are already using AI. The only open question is whether anyone knows which tools, on what data, with what oversight. Both failure modes cost you. Ban it and the use goes underground, onto personal accounts, outside your tenant and outside your control. Adopt it without design and you hand a language model access to every file a user can reach, including the ones they should never have been able to reach. Doing this properly means a written position on what is permitted, permissions cleaned up before anything is switched on, controls on what leaves the tenant, a named owner for each tool or agent, and a habit of checking that the output is fit to send to a client. Then it means finding the two or three uses that return real time, and measuring them.

Identification of operational and business risks. Not only the technical ones. Key person dependency. Single points of failure in a process. The spreadsheet that three people rely on and one person maintains. The supplier with access to your systems and no contract that mentions security.

Translation. Helping you understand what all of this means, and helping the key stakeholders understand it too. A risk that only the IT partner understands has not been managed. It has been described. Your board, your COO and your partners need to be able to make decisions about it, which means somebody has to explain it in language that supports a decision.

Where the process work actually happens

The registers and the written processes do not appear on their own, and they are not a by-product of good support. Somebody has to sit down and build them.

We do that work in two places. Some of it happens during onboarding, because a new client relationship is the natural moment to establish the asset register, the risk register, the new user and leaver processes and the information security policy that the rest of the service depends on. The remainder is scoped as defined pieces of work with an owner, a start, a finish and a document at the end.

That is a deliberate choice. Process work that lives on a wish list stays on the wish list. Process work with a date attached gets done.

This is what proactive looks like

Reports on what you have. Conversations about where you are going.

The reporting matters because you cannot manage what you cannot see — asset position, patch status, risk register, incidents, spend. The conversations matter more, because reports describe the present and business planning happens in the future.

Reports alone are administration. Conversations alone are opinion. Together they are help building the business, rather than support.

The question worth asking

Do you want someone who shows up when it does not work?

Or do you want a partner who values the same things you do, will look out for your best interests, and will help you build and run the show?

Both are legitimate purchases. They cost different amounts and they produce different outcomes. The mistake is paying for the first and expecting the second.

If you want to know what the second one looks like against your own business, book a no-strings discovery call: calendly.com/jamesratcliff/no-strings-discovery-call

James Ratcliff, Founder & Managing Director, Ratcliff IT
020 3551 6262 | hello@ratcliff.it

Common questions

How can you tell if an IT provider is genuinely proactive?

Run a simple test before you sign anything: did they make a real effort to understand your business, can they add value on business problems and not just technical ones, and can they help you reach your business goals? Proactivity shows up in the first meeting — in what they ask about. If they spend it on their toolset and response times rather than your clients, regulator and growth plan, you have your answer.

What IT and security processes do smaller firms typically lack?

Leaner firms are usually excellent at the work and thin on the written process behind it: no written information security policy, no documented new-user or leaver process, no asset register and no risk register. None of it shows up in a monthly service report, but all of it surfaces in a due diligence questionnaire, a client audit, an insurance renewal or a tender.

What should a proactive IT partner actually do?

Five things: a technology plan that matches the business plan; secure information storage and flow; help to design and implement AI safely and effectively; identification of operational and business risks, not only the technical ones; and translation — explaining risk in language that lets your board, COO and partners make decisions.

Should a boutique firm adopt AI?

Your people are already using it, so the real question is oversight. Ban it and the use goes underground onto personal accounts outside your control; adopt it without design and you hand a model access to files it should never reach. Do it properly: a written position on what is permitted, permissions cleaned up before anything is switched on, controls on what leaves the tenant, a named owner for each tool or agent, and a habit of checking the output is fit to send to a client.


Related Posts

Ratcliff IT

We recognise that IT isn't just about computers - It's about developing relationships and becoming a reliable partner to your business. Think of us as an extension of your own team. You'll enjoy a friendly and personalised service and you'll always have the right level of experienced support.

Contact Us New Enquiries: hello@ratcliff.it

Support: 020 3551 6272

Sales: 020 3551 6262


Ratcliff Consulting Ltd. Reg no: 07060479. Reg in England. Registered address: 10 Western Road, Romford, Essex, RM1 3JT

Privacy Policy | Modern Slavery Statement