Week 1 · Friday
Taking inventory of your business technology
Create a simple record of the devices, applications, accounts, and information your business depends on—and identify who is responsible for each.
Who would you call if your business email stopped working tomorrow?
Where would you find the renewal date for your website address? Which application holds your customer records? Who can manage the account if the person who set it up is unavailable?
In a small business, those answers often live in someone's memory. That may work until an employee leaves, a device fails, or an unexpected renewal appears on the company card.
A technology inventory puts the important answers in one place. Start with a simple list you can maintain. You can make it more detailed as you discover what the business needs.
Start with what the business does
On Monday, we separated equipment, applications, and information. On Wednesday, we looked at the connections between them.
Today, put those pieces around the work you need to accomplish: communicating with customers, scheduling jobs, taking payments, delivering services, and paying employees.
For each activity, identify what it relies on and who is responsible. Include physical equipment and online services. CISA recommends keeping track of both physical and software assets, understanding which systems and information are most important, and documenting their dependencies. CISA: #StopRansomware Guide.
What belongs on the list?
Begin with the things your team would notice immediately if they stopped working:
- Devices: Computers, phones used for work, tablets, printers, and payment equipment.
- Connections: Internet service, the router, Wi-Fi equipment, and any managed backup connection.
- Applications: Email, booking, invoicing, accounting, payroll, file storage, and tools used to deliver your work.
- Business accounts: Website hosting, the domain registration for your website address, and company social media accounts.
- Important information: Customer records, schedules, estimates, contracts, photographs, and other files the business needs.
If a personal phone is used for business email or customer communication, record that dependency. You can document its business role without collecting unrelated personal information.
Use a few useful columns
For each item, record:
| Field | What to write down |
|---|---|
| Name and purpose | The device or service, and the business job it supports. |
| Responsible person | Who owns the business decision and keeps the record current. |
| Administrator or support contact | Who can change settings, manage access, or help when it fails. |
| Location or provider | Where the device is, or which company supplies the service. |
| Important information | The kind of business information it handles and where that information is held, if known. |
| Cost and renewal | The current charge, billing schedule, and renewal date, if applicable. |
| Recovery or fallback | How the business would regain access or continue working; mark unverified plans clearly. |
| Last checked | When someone confirmed the details. |
You can add model numbers or serial numbers for devices when they will help with support, repair, or replacement. You do not have to collect every technical identifier to make the first version useful.
What a useful entry looks like
Here is an illustrative entry for a salon's booking service:
Item: Appointment booking service
Purpose: Schedule customers and view appointments
Responsible person: Owner
Administrator: Office manager, with an authorized backup administrator
Provider and support: Provider name and support contact on file
Information: Customer contact details and appointment history, held by the provider
Cost and renewal: Confirm against the current invoice
Recovery or fallback: Ask the provider about exports, recovery, and access during an outage
Last checked: Date of the review
This entry does not pretend every question is answered. It makes the missing answers visible and gives someone responsibility for finding them.
Keep passwords out of the inventory
The inventory should tell you which account exists and who manages it. Keep its password, recovery codes, and other sign-in secrets in an appropriate password manager with controlled access, rather than in the spreadsheet.
You can note that the credential is held in the company's password manager and who is authorized to use it. Do not turn the inventory into a shared list of passwords.
The inventory itself still deserves protection. It may reveal providers, account identifiers, equipment locations, and business dependencies. Limit access to people who need it and include the document in your backup arrangements. CISA also recommends securely storing asset documentation and keeping an offline copy available for an incident. CISA: #StopRansomware Guide.
Make your first pass manageable
Set aside 30 minutes and start with five important systems. Look at the tools staff use every day, your recent technology invoices, and the accounts behind your email and website.
For each system, answer what you can and assign someone to follow up on the unknowns. Check the list with the person who actually uses the system; an invoice may tell you what you pay for without explaining how the team uses it.
Then choose a few gaps to resolve. An account nobody can administer, important files with no confirmed recovery process, or a service no one recognizes on the company card is worth investigating. Confirm the business impact before canceling a service or changing access.
Update the inventory when you add or replace a tool, change providers, or change who manages an account. Put a brief review on your own calendar so the list stays useful.
Your takeaway: A useful technology inventory explains what the business depends on, who manages it, and what needs attention. It should help someone act when a question or problem comes up.
Test your knowledge
You have now covered the equipment, applications, information, and connections behind your business—and started putting them into one practical picture.
Ready to put this week's learning into practice? Visit the EdwardsCG Week 1 Knowledge Check. Review this week's topics or choose a cumulative check covering everything released so far. In Week 1, both choices cover this week's material; cumulative checks grow as new weeks are released.
There is no timer or account to create. Each answer includes an explanation and related reading, so you can revisit anything that is still unclear.
Next week, we will look at who controls your website, domain, email, and social accounts—and how to keep business access from depending on one person's personal login. Follow the Small Business Learning Series.