Category: RandTech Updates

  • Why Your Business Still Needs Microsoft 365 Backup

    Why Your Business Still Needs Microsoft 365 Backup

    Why Your Business Still Needs Microsoft 365 Backup

    Microsoft 365 stores business email, documents, Teams information and SharePoint data in highly resilient cloud infrastructure. That often creates the impression that everything in Microsoft 365 is automatically backed up forever.

    It is not quite that simple.

    Microsoft protects the availability and operation of its cloud platform, while your business remains responsible for how its users, administrators and connected applications handle company information. Deleted data may be recoverable for a limited period, but Microsoft 365 retention features should not automatically be treated as a complete independent backup system.

    Cloud storage and backup are different

    OneDrive synchronises files between a user’s computer and the cloud. SharePoint gives teams a central place to store and collaborate on documents. Exchange Online keeps business email accessible across devices.

    These services are built for productivity and availability. Backup has a different purpose: maintaining a separate recoverable copy of data in case the live information becomes unavailable, corrupted or deliberately removed.

    If a user deletes a synchronised folder, the deletion may be reflected across the environment. If an attacker compromises an administrator account, they may attempt to delete data or weaken retention settings. Malware can also encrypt files before the damaged versions synchronise to OneDrive or SharePoint.

    Microsoft 365 includes recycle bins, version history and retention capabilities, but each feature has rules, limits and configuration requirements.

    Common ways businesses lose Microsoft 365 data

    Data loss is not always caused by Microsoft suffering a major outage. More common causes include:

    • A staff member accidentally deleting a mailbox or folder
    • An employee leaving before important information is transferred
    • A compromised account deleting or manipulating data
    • Incorrect SharePoint permissions exposing files
    • Malware encrypting synchronised documents
    • An administrator changing a retention policy
    • A third-party application corrupting or deleting information
    • The business discovering a loss after the recovery window has passed

    A backup becomes particularly valuable when nobody notices the problem immediately.

    What should be protected?

    A Microsoft 365 backup strategy should account for the services the business actually uses. This may include:

    • Exchange Online mailboxes
    • Shared mailboxes
    • OneDrive accounts
    • SharePoint sites and document libraries
    • Teams files and associated SharePoint data
    • Contacts and calendars

    The system should also make it possible to restore individual items. Recovering one deleted email or folder should not require rebuilding an entire environment.

    Retention and backup solve different problems

    Retention policies are important for governance, compliance and controlling how long information is kept. They can help prevent permanent deletion during a defined retention period.

    Independent backup provides another recovery layer. It can preserve separate copies, offer longer recovery histories and reduce dependence on the state of the live Microsoft 365 tenant.

    Many businesses benefit from using both. Retention helps govern information inside Microsoft 365, while backup provides an additional route to recovery.

    A backup must be tested

    A dashboard showing successful backup jobs is reassuring, but it does not prove that the correct data can be restored quickly.

    Businesses should periodically test:

    • Restoring an individual email
    • Recovering a OneDrive folder
    • Restoring a SharePoint document and its previous version
    • Recovering data belonging to a former employee
    • Confirming who is authorised to initiate a restore
    • Measuring how long recovery takes

    These tests turn backup from a subscription into an operational recovery capability.

    RandTech IT helps South African businesses assess Microsoft 365 retention, implement independent cloud backup and test the recovery of Exchange, OneDrive and SharePoint information.

    Your data may be in Microsoft’s cloud, but it is still your business’s responsibility. A properly configured and tested backup ensures that one mistake, compromised account or late discovery does not become permanent data loss.

    Source: Microsoft 365 Backup documentation

  • RAM and SSD Prices Are Rising: Should You Upgrade or Replace?

    RAM and SSD Prices Are Rising: Should You Upgrade or Replace?

    RAM and SSD Prices Are Rising: Should You Upgrade or Replace?

    The cost of improving or replacing a computer is changing quickly as higher memory and storage prices reach South African retailers.

    Local industry reporting has described substantial increases in RAM and SSD costs, with some products doubling or tripling and certain DDR5 components rising sharply over a matter of months. Higher component costs eventually affect not only upgrades, but also new laptops and complete desktop computers.

    For consumers and SMEs, this makes one question more important than ever: is the current computer worth upgrading, or would replacement offer better value?

    Why RAM and SSD prices matter

    RAM allows a computer to keep more applications and browser tabs active without slowing down. An SSD stores Windows, applications and files, and is one of the most important factors affecting startup and loading speed.

    When these components become more expensive, quotations can change quickly. A price given several weeks ago may no longer reflect the supplier’s replacement cost.

    Businesses should expect shorter quotation-validity periods and may need to pay a deposit before volatile components are ordered. This is not simply a retailer increasing margins; it can reflect rapidly changing distributor pricing.

    When an upgrade still makes sense

    Despite price increases, an upgrade may remain much cheaper than replacing a good computer.

    An SSD upgrade can transform a machine that still uses an old mechanical hard drive. Additional RAM can improve multitasking, large spreadsheets, browser-heavy work and certain design applications.

    An upgrade is generally worth considering when:

    • The processor remains suitable for the user’s workload
    • The computer supports Windows 11
    • The motherboard, screen and chassis are in good condition
    • The battery or power supply is serviceable
    • The upgrade provides at least another two or three useful years
    • The total repair and upgrade cost is well below suitable replacement cost

    A business-grade computer may also be more worthwhile to repair than a newer but poorly built entry-level replacement.

    When replacement is the better decision

    Adding memory or faster storage cannot correct every limitation.

    Replacement may be preferable when the device has an unsupported processor, damaged hinges, a failing battery, unreliable motherboard and outdated connectivity at the same time. The same applies when several components must be replaced just to achieve basic reliability.

    Businesses must also consider downtime, warranty coverage and employee productivity. Saving money on an old computer is not good value if it continues interrupting work.

    Refurbished equipment can provide a middle option

    A professionally refurbished business laptop or desktop may offer better build quality than a new entry-level consumer model at a similar price.

    The important details are the device’s generation, condition, Windows 11 compatibility, SSD health, battery condition and warranty. “Refurbished” should not merely mean cleaned and resold.

    For some businesses, a mixed approach works best: upgrade the strongest existing computers, replace unreliable units and allocate quality refurbished devices to less demanding roles.

    Diagnose before spending

    Buying RAM based only on capacity can lead to compatibility problems. SSDs also differ by interface, size, performance and endurance. Before approving an upgrade, the computer should be inspected and its overall condition considered.

    PC Warehouse and RandTech IT can assess whether a slow computer needs repair, an SSD, more RAM or full replacement. We can also migrate data and configure replacement machines so users return to work with minimal disruption.

    With component prices changing rapidly, the smartest purchase is not automatically the cheapest upgrade or newest computer. It is the option that delivers the best reliable working life for the total cost.

    Source: MyBroadband’s report on South African PC component prices

  • AI-Powered Cybercrime Is Raising the Risk for South African SMEs

    AI-Powered Cybercrime Is Raising the Risk for South African SMEs

    AI-Powered Cybercrime Is Raising the Risk for South African SMEs

    Artificial intelligence is not only helping businesses automate work. It is also helping cybercriminals create convincing scams, analyse targets and launch attacks more efficiently.

    INTERPOL’s 2026 African Cyberthreat Assessment reports that artificial intelligence was involved in 55% of reported cybercrime across Africa. The assessment also identifies South Africa as a particularly significant ransomware target, accounting for 92% of detections in the African dataset cited by the report.

    These figures do not mean that 92% of every ransomware attack in Africa occurred in South Africa. They come from a specific threat-detection dataset. They do, however, reinforce what local businesses are already experiencing: South Africa is an attractive and active target.

    How criminals use AI

    Traditional phishing emails were often easy to identify because of poor grammar, strange wording or an obviously incorrect company logo.

    Generative AI can now produce polished emails that imitate the tone of a supplier, manager or colleague. Criminals can use information from company websites, social media profiles and leaked databases to create messages that feel relevant to the recipient.

    AI may help attackers:

    • Write convincing phishing messages
    • Translate scams into natural local language
    • Generate or modify malicious code
    • Analyse stolen information more quickly
    • Impersonate executives or suppliers
    • Automate reconnaissance against exposed systems
    • Produce fake voices, documents or payment instructions

    A small criminal operation can consequently target more businesses without employing a large technical team.

    Why SMEs are attractive targets

    Many business owners assume that criminals are interested only in banks, government departments and major corporations. In reality, SMEs frequently combine valuable information with weaker protection.

    A smaller business may hold customer identity documents, banking information, contracts, payroll records and access to larger customers or suppliers. At the same time, it may rely on a single administrator, basic antivirus and backups that have never been tested.

    Automated attacks do not need to know the company personally. They scan for weak passwords, exposed remote access, outdated websites, unpatched computers and compromised Microsoft 365 accounts.

    MFA is essential—but it is not the whole solution

    Multifactor authentication remains one of the most important protections a business can deploy. However, modern attackers also use fake login approval requests, stolen browser sessions, malicious email rules and social engineering.

    Effective SME protection should therefore include several layers:

    • MFA on all business accounts
    • Separate, protected administrator accounts
    • Endpoint security on every computer
    • Prompt Windows and application patching
    • Email filtering and domain protection
    • Independent Microsoft 365 and server backups
    • Regular restore testing
    • Monitoring for suspicious logins and forwarding rules
    • Staff training using current scam examples

    No individual security product can compensate for missing backups, excessive permissions or an administrator account shared by several people.

    What business owners should do now

    Start with a short security review rather than buying random products. Identify where company data resides, who has administrative access, whether departed employees still have access and whether the business could recover from a compromised account.

    Staff should also be given a clear verification rule: unexpected requests involving payments, bank-detail changes, passwords or confidential documents must be confirmed through a second communication channel.

    AI is increasing the speed and quality of cybercrime, but businesses are not powerless. Strong identity controls, managed protection, tested recovery and alert employees still stop many attacks.

    RandTech IT helps South African SMEs assess Microsoft 365, endpoints, backups and recovery readiness. A practical cybersecurity review can reveal the gaps before an attacker finds them.

    Source: INTERPOL’s 2026 African Cyberthreat Assessment announcement

  • Why Business Wi‑Fi Keeps Dropping (and How to Fix It)

    Why Business Wi‑Fi Keeps Dropping (and How to Fix It)

    Introduction

    Frequent Wi‑Fi dropouts can paralyse productivity in small and medium-sized businesses. Whether it’s slow checkout systems, interrupted VoIP calls or staff unable to access cloud apps, unstable wireless connectivity costs time and money. This article explains the common reasons why business Wi‑Fi keeps dropping, practical checks you can perform, and when to call RandTech IT for experienced, fast resolution.

    Common causes of business Wi‑Fi dropouts

    1. Interference from other devices

    Office environments are full of electronics that share the same frequencies as Wi‑Fi. Microwaves, Bluetooth devices, cordless phones and some security cameras can interfere with 2.4 GHz and 5 GHz channels, causing intermittent disconnections.

    2. Poor access point placement

    Access points (APs) placed too close to walls, metal cabinets or large machinery will have reduced coverage. Placing APs in ceilings or central, elevated positions improves range and reduces dead zones.

    3. Overloaded access points

    Consumer-grade routers and a single AP serving many devices will struggle. When too many users or IoT devices connect to the same AP, throughput drops and connections can time out.

    4. Channel congestion

    In dense office buildings or business parks in Gauteng, multiple Wi‑Fi networks overlap. If neighbouring networks use the same channels, they compete and cause packet loss and disconnects.

    5. Firmware and configuration issues

    Outdated firmware, incorrect power settings, or misconfigured security (WPA2/WPA3 mismatches) can produce unstable behaviour. APs and controllers require maintenance like any network device.

    6. ISP and WAN problems

    Sometimes the wireless is fine but the internet link is unstable. Packet loss, high latency or intermittent ISP outages will look like Wi‑Fi dropouts to users accessing cloud services.

    7. Hardware faults and ageing equipment

    Access points, switches and cabling degrade. Faulty PoE injectors, overheating APs or failing switches can cause intermittent network disruptions.

    Practical checks you can run now

    Quick on-site tests

    • Walk the office with a laptop or phone and note where disconnects occur.
    • Restart the problematic AP and check logs for repeated errors.
    • Switch a device to mobile data to confirm whether the issue is local Wi‑Fi or the internet link.

    Use basic diagnostic tools

    • Run a continuous ping to a reliable external IP (e.g. 8.8.8.8) to detect packet loss.
    • Use a Wi‑Fi analyser app to view channel usage and signal strength across 2.4 GHz and 5 GHz bands.
    • Check AP and controller firmware versions and upgrade if supported and tested.

    Quick configuration checks

    • Ensure SSID settings, authentication and encryption are consistent across APs.
    • Confirm auto-channel selection is working or manually set less congested channels.
    • Set appropriate transmit power to avoid co-channel interference between your own APs.

    When to upgrade or redesign your Wi‑Fi

    If dropouts persist after basic troubleshooting, it may be time to consider a professional redesign. Signs you need an upgrade include frequent congestion, many mobile users, VoIP/UC instability, expanding branch offices or ageing hardware.

    Enterprise-grade APs and controllers

    Business-grade APs handle more concurrent clients, offer better radios and advanced features such as band steering, airtime fairness and seamless roaming. A central controller or cloud-managed solution helps maintain consistent settings and visibility.

    Proper site survey and capacity planning

    A wireless site survey maps coverage, identifies interference sources and defines AP placement. Capacity planning ensures the network supports peak loads and the applications your team relies on.

    Segmentation and QoS

    Separate guest networks from business traffic and apply Quality of Service for VoIP and critical cloud apps. Segmentation improves security and ensures essential services remain usable during congestion.

    Cost considerations for South African SMEs

    Upgrading Wi‑Fi need not break the bank. Typical costs depend on scale: a small office might invest in a few quality APs and a managed service contract, while larger sites require a full site survey and controller licences. Factor in reduced downtime and productivity gains when evaluating return on investment. RandTech IT can provide clear, localised cost estimates in Rands and recommend solutions that suit your budget.

    When to call RandTech IT

    Some problems benefit from experienced engineers rather than piecemeal fixes. Call RandTech IT when:

    • Dropouts affect voice, payments or customer-facing services
    • You need a reliable site survey and capacity plan
    • Hardware replacement, firmware upgrades or network redesign are required
    • You prefer fast resolution by experienced engineers rather than learning on your time

    FAQ

    Why does Wi‑Fi drop more during peak hours?

    Peak periods see more devices actively using bandwidth, causing AP congestion, channel contention and higher latency. Proper capacity planning and AP density reduce peak-time dropouts.

    Can a single faulty device cause the network to drop?

    Yes. A malfunctioning device can flood the network or cause RF noise. Isolating and disconnecting suspicious devices helps identify the culprit.

    Is 5 GHz always better than 2.4 GHz?

    5 GHz offers higher throughput and less interference but shorter range. A mixed approach with band steering provides the best overall performance for most offices.

    Will upgrading to enterprise gear solve all issues?

    Enterprise hardware helps but must be deployed correctly. A professional site survey, proper configuration and ongoing management are essential to address root causes.

    How quickly can RandTech IT respond to Wi‑Fi outages?

    RandTech IT prioritises fast resolution. Response times depend on support level and location, but our approach focuses on practical fixes by experienced engineers to restore services quickly.

    Conclusion

    Intermittent Wi‑Fi dropouts are usually solvable with a mix of practical checks, better hardware and thoughtful network design. For South African SMEs, minimising downtime and restoring reliable connectivity is critical for productivity and customer service. If your business Wi‑Fi keeps dropping and internal troubleshooting hasn’t helped, RandTech IT provides experienced engineers, clear recommendations and fast resolution aligned with your budget and operational needs.

    Contact RandTech IT for practical, experienced assistance with Wi‑Fi troubleshooting, site surveys and managed networking solutions. Let us help you stop dropouts and keep your business connected.

  • Business Wi‑Fi vs Consumer Wi‑Fi: What SA SMBs Need

    Business Wi‑Fi vs Consumer Wi‑Fi: What SA SMBs Need

    Introduction

    Choosing the right wireless network is a practical decision for South African small and medium-sized businesses (SMBs). “Business Wi‑Fi vs consumer Wi‑Fi” is a distinction that affects performance, security, support and total cost of ownership. For Johannesburg and Gauteng companies where connectivity interruptions can mean lost productivity and revenue, understanding these differences helps you make a future‑proof choice.

    What distinguishes business Wi‑Fi from consumer Wi‑Fi?

    At a high level, consumer Wi‑Fi products are made for homes and light usage. Business Wi‑Fi is designed for multiple users, security compliance, and reliable uptime. The differences show up in hardware, features, management and support.

    Hardware and performance

    • Consumer routers: All‑in‑one devices that combine modem, router, switch and wireless radio. They are cost‑effective but struggle with many simultaneous connections and sustained throughput.
    • Business access points (APs): Separate APs and controllers scale across multiple offices, offer better antenna design, and maintain consistent coverage for dozens to hundreds of clients.

    Security and network segmentation

    Business Wi‑Fi supports advanced security like WPA3 Enterprise, RADIUS authentication, VLANs and guest network isolation. Consumer devices typically provide WPA2 Personal and a basic guest SSID without proper client segregation.

    Manageability and visibility

    Managed business Wi‑Fi gives centralised monitoring, performance analytics and remote troubleshooting. Consumer routers offer minimal logging and no central policy control, making proactive maintenance difficult.

    Why the differences matter for South African SMBs

    SMBs in South Africa face unique pressures: competition for skilled staff, the need to maintain client trust, and the cost of downtime. Choosing the wrong Wi‑Fi approach can increase risk and operating expense.

    Productivity and customer experience

    Slow or unreliable Wi‑Fi directly affects staff productivity and client interactions. For retail, professional services and small clinics in Gauteng, a poor network can mean delays at point of sale, slow cloud access, or disrupted video calls with clients.

    Security and compliance

    Data protection is essential. Business Wi‑Fi supports stronger encryption and authentication, reducing the chance of unauthorised access to company systems and customer information.

    Cost comparison: upfront vs long‑term

    Consumer Wi‑Fi has a lower upfront price, but business systems deliver savings over time through reliability, lower downtime costs and easier scaling.

    Upfront costs

    • Consumer: One off purchase of a router from a retail store (cheaper initially).
    • Business: Higher initial hardware cost for APs, controllers and cabling.

    Operating costs and ROI

    Consider these long‑term factors:

    • Reduced downtime and fewer on‑site fixes when using professional gear and managed services.
    • Better security reduces the risk and potential cost of breaches.
    • Scalability means avoiding repeated replacement cycles as your business grows.

    When a consumer setup might be acceptable

    There are scenarios where consumer Wi‑Fi is suitable, especially for micro‑businesses or home offices with light usage:

    • Single user or very small teams (1–3 people) with limited cloud usage.
    • Low security requirements and minimal visitor access.
    • Temporary locations or testing before committing to managed infrastructure.

    However, even small firms should keep an eye on performance and security as they grow.

    When to opt for business Wi‑Fi

    Choose business Wi‑Fi when the network is critical to daily operations or when you need reliable support:

    • Multiple users and devices, VoIP or frequent video conferencing.
    • Public or guest access that must be isolated from corporate systems.
    • Regulatory or client requirements for stronger data protection.
    • Desire for managed services to reduce internal IT workload.

    Managed Wi‑Fi vs in‑house IT

    Many SMBs in Gauteng prefer outsourcing network management to focus on their core business. Managed Wi‑Fi offers predictable costs, SLAs, and access to experienced engineers who can resolve issues quickly—consistent with RandTech IT’s approach of prioritising fast resolution by experienced staff.

    Benefits of managed Wi‑Fi

    • 24/7 monitoring and remote fixes reduce on‑site visits.
    • Regular firmware updates and security patching.
    • Capacity planning and scaling advice tailored to your business.

    Practical checklist for choosing the right Wi‑Fi

    1. Assess concurrent user numbers and typical applications (VoIP, video, cloud apps).
    2. Require business‑grade security: WPA3 Enterprise, RADIUS and VLANs.
    3. Plan for coverage: perform a site survey for proper AP placement.
    4. Decide on managed services vs in‑house support and review SLAs.
    5. Budget for cabling, professional installation and ongoing management.

    FAQ

    1. Can a consumer router be upgraded to meet business needs?

    Sometimes you can extend a consumer router with range extenders or mesh kits, but this rarely addresses security, manageability or high client density. For reliable performance and proper segmentation, business APs remain the better option.

    2. How many access points does a typical small office need?

    That depends on floor area, building materials and device density. A small office (50–100 m²) often needs 2–3 APs for consistent coverage; a site survey provides an accurate count.

    3. Is managed Wi‑Fi expensive for SMBs in South Africa?

    Costs vary, but managed services can be cost‑effective when you factor in reduced downtime and less burden on in‑house staff. Think in terms of monthly predictability rather than a large capital outlay alone.

    4. What security features should I require from a business Wi‑Fi solution?

    Insist on WPA3 Enterprise or at least WPA2 Enterprise with RADIUS, VLAN support, guest network isolation and centralised logging/monitoring.

    5. How quickly can issues typically be resolved with managed Wi‑Fi?

    Response times depend on your service agreement. A key advantage of experienced providers like RandTech IT is faster resolution by senior engineers rather than extended troubleshooting by junior staff.

    Conclusion

    For South African SMBs, the choice between business Wi‑Fi and consumer Wi‑Fi comes down to reliability, security and long‑term cost. While consumer gear can work for very small or temporary setups, business Wi‑Fi—especially when managed—delivers the performance and protection required for growth and professional operations in Johannesburg and across Gauteng.

    Contact RandTech IT to assess your environment and recommend a practical, cost‑effective Wi‑Fi solution. Our experienced engineers focus on fast, reliable resolutions so you can keep your business moving.

  • Office Network Security Checklist for South African SMBs

    Office Network Security Checklist for South African SMBs

    Introduction

    For small and medium-sized businesses (SMBs) in South Africa, protecting your office network is both practical and essential. Cyber incidents can disrupt operations, damage client relationships and incur unexpected costs. This office network security checklist helps business owners and IT managers in Johannesburg and across Gauteng take sensible, prioritized steps to reduce risk and ensure continuity.

    1. Establish clear network ownership and policies

    Security starts with responsibility. Assign a network owner—either an internal IT manager or your outsourced provider—who’s accountable for maintenance, updates and incident response.

    Develop concise policies

    • Acceptable Use Policy: Define permitted devices, internet use and remote work rules.
    • Access Control Policy: Describe how user accounts are created, approved and revoked.
    • Incident Response Plan: Outline immediate steps, contact lists and escalation paths.

    2. Segment and secure your network

    Network segmentation reduces the blast radius if a device is compromised. Separate guest Wi‑Fi, IoT devices and critical business systems.

    Practical segmentation steps

    • Create a dedicated guest SSID with internet-only access and a strong password or captive portal.
    • Use VLANs to isolate printers, security cameras and other non-essential devices from core servers.
    • Limit administrative interfaces to a management VLAN accessible only to trusted staff or a VPN.

    3. Harden endpoints and servers

    Every device on the network is a potential entry point. Apply baseline hardening to workstations and servers.

    Key actions

    • Keep operating systems and applications up to date with a patch schedule.
    • Install reputable endpoint protection and enable real-time scanning.
    • Disable unnecessary services and local administrator rights for day-to-day users.

    4. Use strong access controls and authentication

    Passwords alone are insufficient. Strengthen authentication and monitor account activity.

    Authentication best practices

    • Enforce multi-factor authentication (MFA) for email, VPN and remote access.
    • Use role-based access control (RBAC) to limit privileges to what staff need.
    • Require unique user accounts rather than shared logins.

    5. Secure remote access and Wi‑Fi

    Remote work and wireless connectivity are common in modern offices. Both need careful configuration.

    VPNs, Wi‑Fi and remote desktops

    • Offer a managed VPN for remote staff and avoid exposing RDP directly to the internet.
    • Use WPA3 where available, otherwise WPA2 with a strong passphrase for office Wi‑Fi.
    • Rotate Wi‑Fi credentials periodically and after staff changes.

    6. Monitor and log activity

    Timely detection reduces impact. Use logging and monitoring to spot anomalies and potential intrusions.

    What to monitor

    • Firewall and router logs for unusual inbound or outbound traffic spikes.
    • Authentication logs for repeated failed logins or logins from unexpected locations.
    • Endpoint alerts for malware, suspicious process behaviour or lateral movement.

    7. Backup and disaster recovery

    Backups are your last line of defence. A good backup strategy ensures rapid recovery with minimal data loss.

    Backup checklist

    • Adopt a 3-2-1 backup approach: three copies, on two media types, one offsite (including cloud).
    • Encrypt backups both in transit and at rest; test restores regularly.
    • Document recovery point objectives (RPO) and recovery time objectives (RTO) that match your business needs.

    8. Manage vendors and third-party risks

    Third-party services and contractors can introduce vulnerabilities. Review and control their access.

    Third-party risk steps

    • Grant least-privilege access and time-bound accounts where possible.
    • Require security clauses in contracts that include notification timelines for breaches.
    • Perform periodic reviews of vendor access and revoke unused accounts promptly.

    9. Train staff and build security awareness

    People are often the weakest link. Regular training reduces phishing and social engineering success.

    Training focus areas

    • Recognising phishing emails and suspicious links or attachments.
    • Safe use of USB devices and personal phones on the network.
    • Reporting procedures for suspected incidents or lost devices.

    10. Regular assessments and patch management

    Security is ongoing. Schedule routine checks and keep a documented patch process.

    Assessment tasks

    • Run vulnerability scans and review remediation plans monthly or quarterly depending on risk.
    • Conduct annual penetration tests or targeted assessments when significant changes occur.
    • Maintain an inventory of hardware and software to ensure timely patches and support coverage.

    Practical checklist summary

    1. Assign network ownership and document policies.
    2. Segment guest, IoT and critical systems.
    3. Harden endpoints; apply patches and endpoint protection.
    4. Enforce MFA and limit admin privileges.
    5. Secure Wi‑Fi and provide a managed VPN for remote work.
    6. Enable logging and monitor key systems.
    7. Implement encrypted backups and test restores.
    8. Control third-party access and review contracts.
    9. Train staff on phishing and reporting procedures.
    10. Schedule vulnerability scans and patch cycles.

    FAQ

    How often should I update my network security checklist?

    Review the checklist at least annually and after any major change—new software, after a breach, office expansion or change in workforce.

    Do I need a managed service provider?

    Many SMBs benefit from a managed provider for 24/7 monitoring, fast incident response and to access specialist skills without hiring full-time staff.

    What budget should a small business expect to allocate?

    Costs vary by size and complexity. Prioritise essentials—patching, endpoint protection, backups and MFA—then scale services like managed monitoring as needed. Consider the cost of downtime when planning.

    Is cloud backup safe for South African businesses?

    Cloud backup can be safe if data is encrypted, the provider follows strong security practices and you verify data residency and compliance requirements relevant to your sector.

    Can I do this checklist myself?

    Smaller tasks like enforcing strong passwords and training staff are achievable internally. For network segmentation, VPN design, threat monitoring and incident response, experienced engineers help implement correctly and quickly.

    Conclusion

    Securing your office network doesn’t require perfect technology: it requires practical, consistent steps and clear ownership. Use this office network security checklist to prioritise actions that reduce risk and support business continuity. For many South African SMBs, combining internal effort with experienced external support provides the best balance of cost and protection.

    Need practical, experienced help implementing this checklist? Contact RandTech IT to talk to engineers who prioritise fast resolution and proven experience. We work with businesses across Gauteng to secure networks, manage systems and keep operations running smoothly.

  • How to Improve Wi‑Fi Coverage in an Office — Practical Steps

    How to Improve Wi‑Fi Coverage in an Office — Practical Steps

    Introduction

    Good Wi‑Fi is essential for productivity in small and medium-sized South African businesses. Slow or inconsistent wireless access wastes time, disrupts cloud services and undermines collaboration. This guide explains practical steps to improve Wi‑Fi coverage in an office, tailored for SMEs that need reliable performance without unnecessary expense. RandTech IT specialises in fast, experienced support so your network works from day one.

    Understand the problem: diagnose before you buy

    Effective improvement starts with diagnosis. Replacing hardware without understanding coverage gaps or interference often wastes money.

    Perform a basic site survey

    • Walk the office with a laptop or smartphone and note areas with slow speeds or dropped connections.
    • Record where devices are used (desks, meeting rooms, warehouse areas) and peak usage times.
    • Look for obvious physical barriers: concrete walls, server cabinets, lifts and kitchens can all attenuate signals.

    Measure signal and interference

    Use free apps or low-cost tools to check RSSI (signal strength) and channel congestion. In dense office blocks in Johannesburg or other Gauteng suburbs, neighbouring networks can cause interference—especially on the 2.4 GHz band.

    Key causes of poor office Wi‑Fi

    • Poor access point (AP) placement or too few APs for office size.
    • Interference from neighbouring networks, Bluetooth devices, microwave ovens or heavy machinery.
    • Obstructions such as thick walls, glass partitions with metallic films, and server racks.
    • Older consumer-grade routers that cannot handle many concurrent users.

    Practical steps to improve coverage

    1. Optimise access point placement

    Access points should be ceiling mounted or high on walls, centrally located relative to users. Avoid placing APs inside enclosed cupboards or behind monitors. For larger or multi-room offices, plan for multiple APs with overlapping coverage but not on the same channel.

    2. Move to dual-band and use 5 GHz where possible

    Encourage devices and APs to use 5 GHz for bandwidth-sensitive applications. 5 GHz offers more channels and less interference, though with somewhat shorter range than 2.4 GHz. Reserve 2.4 GHz for legacy or IoT devices.

    3. Deploy a managed mesh or controller-based system

    Mesh Wi‑Fi or controller-managed APs simplify coverage across open-plan offices and multiple rooms. These systems provide automatic channel selection, power adjustment and handoff that reduce dead zones and improve roaming for mobile users.

    4. Replace consumer routers with business-grade equipment

    Consumer routers are cost-effective for homes but struggle under the concurrent device loads of a small office. Business-grade APs and switches offer better radios, load management and security features.

    5. Configure channels and power levels

    Avoid leaving APs on auto settings without verification. Manually set non-overlapping channels for 2.4 GHz (1, 6, 11) and select clear 5 GHz channels based on your survey. Adjust transmit power so APs don’t overpower adjacent cells and cause interference.

    6. Segment the network and prioritise traffic

    Create separate SSIDs or VLANs for guests, printers/IoT devices and business systems. Use Quality of Service (QoS) to prioritise VoIP, cloud backups or critical applications so slow connections don’t affect essential work.

    7. Use wired backhaul where possible

    Where APs are linked wirelessly, performance can degrade. Run Ethernet to AP locations when feasible—this provides reliable backhaul and frees wireless capacity for client devices.

    When to consider a professional site survey

    If basic steps don’t fix the problem, or your office supports many concurrent users, a professional RF site survey is worth the investment. A RandTech IT survey includes spectrum analysis, heatmaps of signal strength, and recommendations tailored to your office layout and business needs. This helps avoid over- or under-provisioning equipment.

    Cost considerations for South African SMEs

    Budget depends on office size, device density and performance expectations. Typical approaches include:

    • Low-cost improvements: move APs, change channels and update firmware—minimal cost.
    • Mid-range: add or replace APs with business-grade mesh units, run some Ethernet—R thousands depending on hardware and cabling.
    • High-end: full managed wireless deployment with controller, PoE switches and professional installation—higher upfront cost but better long-term ROI and support.

    RandTech IT can provide a clear estimate after a brief assessment so you understand the investment and likely benefits in Rands.

    Security and maintenance

    • Keep firmware and controller software up to date to address vulnerabilities.
    • Use strong WPA2/WPA3 encryption and unique passwords for employee and guest networks.
    • Schedule regular health checks and logs review to detect performance degradation early.

    Common office layouts and recommended approaches

    Small office (under 100 sqm)

    Often one or two business-grade APs ceiling-mounted will suffice. Prioritise a good central location and consider a small PoE switch.

    Open-plan space

    Multiple APs with managed roaming are advised. Use 5 GHz where device capabilities allow, and plan channels to avoid co-channel interference.

    Multi-floor or segmented office

    Deploy APs on each floor with wired backhaul. Avoid placing APs directly above/below each other where possible and coordinate channels carefully.

    Quick checklist to improve Wi‑Fi coverage

    1. Walk the office and map problem spots.
    2. Check device counts and peak usage.
    3. Move or add APs and choose 5 GHz for high-demand areas.
    4. Use business-grade APs and wired backhaul where possible.
    5. Segment networks and enable QoS for critical apps.
    6. Consider a professional site survey if issues persist.

    FAQ

    How many access points do I need for a small office?

    It depends on size, layout and device density. Many small offices can work with one to three well-placed APs; a short assessment will give an accurate recommendation.

    Can I use mesh Wi‑Fi at my office?

    Yes. Mesh systems suit open-plan spaces and where running Ethernet is difficult. For high device density, choose business-grade mesh with wired backhaul if possible.

    Will switching to 5 GHz solve my coverage problems?

    5 GHz reduces interference and provides higher throughput, but it has shorter range. Use it alongside 2.4 GHz and optimise AP placement for best results.

    Is a professional RF site survey necessary?

    Not always. Try basic fixes first. If problems persist, or you need reliable performance across many users, a professional survey saves time and money by producing targeted recommendations.

    How often should I update firmware and review settings?

    Check firmware quarterly and review network performance and logs at least twice a year, or more frequently if your business relies heavily on Wi‑Fi.

    Conclusion

    Improving Wi‑Fi coverage in an office requires a blend of practical actions—better AP placement, appropriate hardware, channel management—and, where necessary, professional assessment. Small and medium-sized businesses in South Africa can achieve reliable wireless performance without unnecessary expense by taking a methodical approach. RandTech IT focuses on experienced, fast resolutions so your team spends less time troubleshooting and more time working.

    Contact RandTech IT to arrange a quick assessment or a professional site survey. Our engineers deliver practical, experienced assistance to get your office Wi‑Fi working reliably.

  • Firewall Requirements for a Small Business in South Africa

    Firewall Requirements for a Small Business in South Africa

    Introduction

    For South African small and medium-sized businesses (SMEs), a firewall is a fundamental element of network defence. With increasing cyber threats and regulatory expectations, understanding firewall requirements for a small business helps protect customer data, maintain uptime and keep compliance efforts on track. This guide explains what SMEs in South Africa should consider when selecting, configuring and maintaining firewalls—presented in clear, practical terms for business owners and IT decision-makers.

    Why a firewall matters for small businesses

    Firewalls control the traffic between your internal network and external networks, reducing the risk of unauthorised access, data leakage and malware infections. For SMEs that operate in industries such as professional services, retail, or e-commerce, the consequences of a breach can include reputational damage, regulatory fines and operational disruption.

    Local context: South African risks and costs

    Threats are global but consequences are local. SMEs in Johannesburg and across Gauteng are frequent targets because of high business concentration. While exact breach costs vary, prevention through practical controls such as firewalls is generally far more cost-effective than remediation.

    Core firewall requirements for a small business

    Not every business needs an enterprise appliance. However, there are core capabilities every small business firewall should provide.

    • Stateful packet inspection: Basic traffic filtering that tracks connection state to block suspicious packets.
    • Network address translation (NAT): Hides internal IP addresses from the public internet.
    • VPN support: Secure remote access for staff working from home or on the road.
    • Application awareness: Ability to identify and control traffic by application (web, email, cloud services).
    • Intrusion prevention (IPS): Detects and blocks known attack patterns.
    • Web filtering: Block malicious or inappropriate sites to reduce risk.
    • Logging and reporting: Clear logs and simple reports for troubleshooting and compliance.

    Unified Threat Management (UTM) vs Next-Generation Firewall (NGFW)

    UTM appliances bundle multiple security features—AV, URL filtering, IPS—into an affordable package. NGFWs add stronger application control and deeper inspection. For many South African SMEs, a modern UTM with optional NGFW features strikes the right balance between cost and capability.

    Selecting the right firewall for your business

    Consider these factors when choosing hardware or a managed service.

    Business size and throughput

    Match the firewall’s throughput to your internet connection and typical usage. If your office uses a 100 Mbps connection and plans VoIP or cloud backups during business hours, factor in peak loads and growth projections.

    Number of users and remote access needs

    Licence-based models charge per user or VPN tunnel. Calculate concurrent remote users and ensure the solution supports secure mobile access without degrading performance.

    Budget and total cost of ownership

    Initial hardware cost is one part; include subscription fees for threat intelligence, antivirus updates and technical support. In South Africa, compare quotes in rand and factor transport and local support availability.

    Integration with existing systems

    Ensure the firewall integrates with your network switches, Wi-Fi controllers and any cloud services you use. Compatibility reduces configuration complexity and improves reliability.

    Configuration best practices

    Correct configuration is as important as choosing the right device.

    • Least privilege principle: Only open ports and services that are strictly necessary.
    • Segment your network: Separate guest Wi‑Fi, POS systems and administrative networks to limit lateral movement if an endpoint is compromised.
    • Use strong VPN settings: Prefer modern protocols (IKEv2, OpenVPN, or WireGuard) and enforce multi-factor authentication for remote access.
    • Apply regular security policies: Schedule updates for signatures and firmware during maintenance windows.
    • Enable logging and alerts: Configure actionable alerts and retain logs for incident investigation.

    Example rule set for a small office

    A practical rule set might include:

    1. Allow outbound HTTP/HTTPS from internal VLANs to the internet.
    2. Deny inbound traffic from the internet unless explicitly required (e.g., port 443 to a published web server behind a DMZ).
    3. Allow VPN traffic to the internal admin VLAN with MFA enforced.
    4. Block known malicious IP ranges and risky URL categories.

    Maintenance and monitoring

    Firewalls are not set-and-forget devices. Regular maintenance prevents drift and ensures threats are mitigated.

    • Patch firmware: Apply vendor updates promptly but test them in a controlled window.
    • Renew subscriptions: Keep threat feeds and signatures current; expired subscriptions diminish protection.
    • Review rules quarterly: Remove obsolete rules and fine-tune policies based on logs.
    • Backup configurations: Store encrypted backups of configurations off-site for quick recovery.
    • Use monitoring tools: Simple uptime and security monitoring detect issues before they become incidents.

    When to consider managed firewall services

    Many SMEs benefit from handing firewall management to specialists. Managed services provide:

    • Experienced engineers who implement and maintain policies.
    • 24/7 monitoring and response for alerts.
    • Consolidated billing and predictable monthly costs in rand.
    • Faster resolution times—avoiding on-the-job learning during an incident.

    If your business lacks in-house networking skills, a trusted managed provider keeps systems secure while you focus on core operations.

    Compliance and legal considerations

    South African businesses must consider POPIA (the Protection of Personal Information Act) when storing or processing personal data. A correctly configured firewall contributes to reasonable technical safeguards under POPIA by preventing unauthorised access and recording access attempts for audit purposes.

    Practical checklist before deployment

    • Inventory network devices and endpoints.
    • Map services that require inbound or outbound access.
    • Define acceptable use and remote access policies.
    • Budget for subscriptions and support in rand.
    • Plan staged deployment with backup configuration and rollback steps.

    FAQ

    • How much should a small business spend on a firewall?

      Costs vary. Expect a modest initial outlay for hardware (or a small monthly fee for a managed service) plus subscription fees for threat feeds. Budget for both capital and recurring expenses in rand.

    • Can a cloud service replace an on-premises firewall?

      Cloud security services complement but do not always replace an on-premises firewall—especially where local network segregation, VPN termination or edge protection is required.

    • How often should firewall rules be reviewed?

      Review rules at least quarterly, or immediately after significant changes to your network or applications.

    • What is the minimum feature set for a POS-enabled business?

      Ensure VLAN segmentation, strict inbound/outbound rules, PCI-compatible logging, and web filtering to protect payment systems.

    • Is managed firewall support worth it for a 10-person company?

      Yes, if you lack dedicated IT staff. Managed support provides quicker, experienced responses that reduce risk and downtime.

    Conclusion

    Firewall requirements for a small business are practical and achievable. Focus on essential features—stateful inspection, VPNs, IPS, logging and web filtering—combined with sound configuration, regular maintenance and clear policies. Where internal expertise is limited, a managed firewall service gives you experienced engineers and predictable costs in rand, removing the need to learn on the client’s time.

    If you’d like a practical assessment of your current firewall posture or assistance selecting and managing a solution, contact RandTech IT. Our engineers deliver fast, experienced support so your business stays secure and productive.

  • IT Checklist When Moving Offices: A Practical Guide for SMEs

    IT Checklist When Moving Offices: A Practical Guide for SMEs

    Introduction

    Relocating an office is a complex project for any South African small or medium-sized business. Beyond desks and furniture, IT systems—servers, networks, telephones and cloud integrations—must be planned and executed carefully to avoid downtime, data loss and security gaps. This IT checklist when moving offices provides a clear, practical sequence for RandTech IT clients and other SMEs to prepare, move and stabilise technology during a relocation.

    1. Start with planning and inventory

    Begin early. IT moves work best with a lead time of at least 8–12 weeks so you can assess, procure and schedule without rushing.

    Conduct a technology audit

    • List all hardware: servers, desktops, laptops, printers, network switches, wireless access points, VoIP phones and UPS units.
    • Document software licences, subscriptions and specialised configurations (accounting, point-of-sale, ERP).
    • Record serial numbers, network addresses and warranty/support details.

    Define business priorities

    Identify systems that require minimal downtime (for example, accounting at month-end) and schedule the move outside critical business periods. Decide on acceptable outage windows and communicate these to staff and your IT partner.

    2. Assess the new site’s infrastructure

    Inspect the new premises for adequate power, network cabling and space for equipment.

    Power and cooling

    • Confirm power capacity and suitable outlets for servers and networking gear.
    • Plan for UPS units and, if needed, a backup generator or secondary power options.
    • Check room ventilation and cooling for server closets to prevent overheating.

    Network and cabling

    • Verify the presence and routing of Cat6 or better cabling for wired connections.
    • Plan switch placement, patch panels and rack space; measure cable lengths.
    • Engage your ISP early to book fibre or ADSL installation and confirm lead times and SLAs.

    3. Backup and data protection

    Data protection is non-negotiable. Treat backups as your insurance policy during a move.

    Create and verify backups

    • Perform a full backup of servers and critical workstations before any packing.
    • Verify backups by performing test restores for selected files or systems.
    • Consider off-site replication or cloud snapshots to ensure an additional copy is available remotely.

    Protect physical media

    Transport backups in secure, labelled containers. Encrypt sensitive backups and keep a record of who handles them during transit.

    4. Network and connectivity checklist

    Connectivity is often the first visible pain point after a move. Plan for minimal disruption.

    Pre-provision and test

    • Order and pre-provision internet services so connectivity is available on move-in day where possible.
    • Document VLANs, IP addressing schemes and firewall rules to reproduce on-site quickly.
    • Label network ports and patching for easier troubleshooting after the move.

    Wi-Fi coverage and security

    • Conduct a Wi-Fi site survey to place access points for reliable coverage.
    • Apply secure authentication (WPA2/WPA3 Enterprise) and guest network isolation.

    5. Communication systems and telephony

    Phone systems—especially VoIP—require attention to avoid missed calls and lost business.

    VoIP and PSTN

    • Confirm SIP trunking or VoIP provider readiness and porting arrangements for numbers.
    • Test QoS settings on network equipment to prioritise voice traffic.

    Internal communications

    Inform staff of timelines for moving phone extensions, soft-phone reconfiguration and forwarding arrangements to minimise customer impact.

    6. Physical move and secure handling

    Coordinate logistics to protect equipment and data during transit.

    Packing and labelling

    • Label every item with owner, destination desk and any special instructions.
    • Wrap servers and sensitive hardware with anti-static packaging and secure in racked cases if possible.

    Chain of custody

    Assign responsibility for devices during the move. Keep a movement log and consider using a trusted IT mover or RandTech IT engineers to handle critical equipment.

    7. Rebuild, test and validate on move-in

    Have a clear post-move checklist to restore business operations quickly.

    Step-by-step rebuild

    1. Power up critical infrastructure: servers, switches, firewalls and UPS.
    2. Restore network configurations and verify WAN connectivity.
    3. Connect workstations, printers and VoIP phones. Run application tests.

    Validation and user testing

    • Run tests for email, file access, internal applications and internet speed.
    • Have key users verify function in their own workflows before declaring systems ‘live’.

    8. Cybersecurity considerations during a move

    Moves are attractive windows for attackers. Keep a security-first mindset.

    Maintain access control

    • Secure server rooms with locks and limit access to authorised personnel during the move.
    • Change administrative passwords if devices are handled by external movers or third parties.

    Monitor and audit

    Increase monitoring for unusual logins or network activity for several days after the move. Check firewall logs and endpoint alerts.

    9. Documentation and update of asset records

    Use the move as an opportunity to tidy records and licence inventories.

    Update inventories

    • Record new serial numbers, MAC addresses and physical locations for each device.
    • Update insurance schedules and maintenance contracts to reflect the new address.

    10. Post-move optimisation and review

    Once stable, review systems and look for optimisation opportunities.

    Performance tuning

    • Optimise Wi‑Fi channeling, switch port configurations and QoS policies.
    • Schedule a follow-up audit 2–4 weeks after the move to capture issues surfaced by everyday use.

    Frequently Asked Questions

    How far in advance should we involve an IT provider?

    Engage your IT partner as soon as you know the move date—ideally 8–12 weeks prior. Early involvement secures ISP appointments, designs the network and prevents last-minute surprises.

    Do we need to back up to the cloud before moving?

    Yes. A cloud or off-site backup provides an independent recovery copy if local backups are lost in transit. Verify restores before packing.

    Can we keep our phone numbers during a move?

    Most numbers can be ported, but the process needs lead time. Work with your telecom provider to plan porting dates and temporary call forwarding if required.

    What are common post-move IT problems?

    Typical issues include mispatched cabling, Wi‑Fi dead spots, misconfigured switches or missing licences. A methodical validation process catches these quickly.

    Should we replace old hardware during the move?

    The move is an ideal time to retire outdated hardware. Prioritise replacements for unsupported servers, end-of-life firewalls and devices out of warranty.

    How can RandTech IT help with an office move?

    RandTech IT provides planning, onsite engineers, network design, secure transport of equipment and post-move stabilisation. We focus on experienced technicians who resolve issues quickly without learning on your time.

    Conclusion

    An IT checklist when moving offices helps South African SMEs minimise risk and downtime. Start early, protect your data, verify connectivity and prioritise security. With careful planning and an experienced IT partner, most moves are completed smoothly and predictably.

    If you’re planning a relocation and want practical, experienced assistance, contact RandTech IT. Our engineers are ready to help with planning, implementation and fast resolution so your business gets back to work with confidence.

  • New Employee IT Onboarding Checklist for South African SMBs

    New Employee IT Onboarding Checklist for South African SMBs

    Introduction

    Bringing a new employee into your business is more than handing over a job description. For South African small and medium-sized businesses (SMBs), efficient IT onboarding ensures staff are productive quickly while protecting company systems and data. This checklist gives practical steps that RandTech IT uses when provisioning devices, access and security — tailored to local realities and common SMB constraints.

    Why a structured IT onboarding checklist matters

    A repeatable checklist reduces delays, prevents security gaps and avoids unnecessary costs. For SMBs in Johannesburg and Gauteng, rapid resolution and experienced engineers matter because downtime directly affects revenue. A solid process also sets expectations for new staff and IT teams.

    Pre-boarding essentials (before day one)

    Confirm role requirements and software

    Identify the applications, shared folders and systems the new hire needs. Create a role-based access list rather than assigning rights individually — it’s faster and more secure.

    Order and prepare hardware

    • Decide device type (laptop, desktop, tablet) and specs based on role.
    • Standardise on a small set of device models to simplify support and spares.
    • Image devices with a company baseline: OS updates, drivers and approved software.

    Set up accounts and licences

    Create email, directory (Active Directory/Azure AD), and cloud accounts. Ensure software licences (Microsoft 365, specialised apps) are assigned and tracked to avoid non-compliance or last-minute purchases.

    Security and compliance steps

    Apply least-privilege access

    Grant the minimum permissions required for the role. Use groups and policies in your identity provider to manage access efficiently.

    Enable multifactor authentication (MFA)

    MFA is a simple step with a big security impact. Configure MFA for email, VPN, cloud consoles and any administrative accounts before handing over credentials.

    Install endpoint protection and encryption

    • Deploy endpoint antivirus/EDR and ensure it’s enrolled in central management.
    • Enable full-disk encryption (BitLocker or FileVault equivalent) to protect data on lost devices.

    Network and remote access

    Provision secure Wi‑Fi and VPN

    Provide credentials for company Wi‑Fi and, if remote work is allowed, set up VPN access with split tunnelling policies as appropriate. Consider zero-trust access for sensitive systems.

    Configure printers and shared resources

    Map network drives, shared printers and intranet bookmarks so the user has immediate access to commonly used resources.

    Account handover and documentation

    Deliver credentials securely

    Never send plain-text passwords by email. Use a secure password manager or hand over credentials in person. Enforce password resets on first login.

    Provide concise user documentation

    • Include how to access email, VPN, support contact details and standard operating procedures.
    • Keep documentation role-specific and updated — a short checklist is more effective than lengthy manuals.

    Training and first-week support

    Conduct an IT orientation

    Walk new hires through essential systems, security expectations, and who to contact for support. Demonstrate MFA setup, password manager usage, and how to report incidents.

    Schedule follow-up checkpoints

    Arrange IT check-ins at day 3 and day 14 to resolve access issues and confirm required software is working correctly. Early follow-up prevents accumulated friction.

    Ongoing management and offboarding considerations

    Monitor and review access regularly

    Periodically audit group memberships and admin privileges. Remove access when roles change to maintain security hygiene.

    Plan offboarding in advance

    Document the offboarding process so accounts, licences and devices are revoked or recovered promptly when an employee leaves. This reduces risk and unnecessary licence spend.

    Practical checklist: Day-by-day at a glance

    1. Pre-boarding: hardware imaged, accounts created, licences assigned.
    2. Day 1: Deliver device, change initial passwords, enable MFA, orientation session.
    3. Day 3: Confirm access to apps, printers and shared drives; resolve any issues.
    4. End of week 1: Security refresher and incident reporting guidance.
    5. Day 14: Follow-up and adjustments to access or software as needed.

    Cost-conscious tips for South African SMBs

    • Standardise devices and software to reduce support overhead and stock spare hardware locally in Gauteng for fast swaps.
    • Use cloud-based identity and licence management to avoid large upfront capital expenses.
    • Prioritise controls that reduce business risk quickly: MFA, endpoint protection and encryption.

    FAQ

    How soon should IT onboarding start?

    Start pre-boarding as soon as the offer is accepted. Preparing accounts and imaging devices before day one avoids delays and demonstrates organisational professionalism.

    What if my business can’t afford dedicated IT staff?

    Managed IT services are cost-effective for SMBs. Outsourcing routine onboarding tasks to an experienced provider gives access to engineers who deliver fast, reliable setup without hiring full-time staff.

    Which security steps are essential for small businesses?

    At minimum: enforce MFA, deploy endpoint protection, enable disk encryption and apply least-privilege access. These yield a strong protection baseline for limited budgets.

    How do we manage licences to control costs?

    Track licences centrally, reclaim inactive ones and align subscriptions with role needs. Consider monthly cloud subscriptions to scale costs with headcount.

    Can onboarding be remote for new hires outside Johannesburg?

    Yes. Remote onboarding works with cloud identity, VPN and couriered devices. Ensure secure handover of credentials and provide clear virtual orientation sessions.

    Conclusion

    A reliable New employee IT onboarding checklist prevents costly delays, reduces security risk and supports new hires to become productive quickly. For South African SMBs, focusing on role-based access, MFA, endpoint security and a short, practical orientation will deliver the best outcomes without unnecessary expense.

    If you’d like practical, experienced assistance implementing this checklist or outsourcing onboarding to engineers who resolve issues quickly, contact RandTech IT. We specialise in managed services, cybersecurity and fast, professional support tailored to South African businesses.