Nothing broke. You just hired four people.
Small professional firms rarely outgrow their technology in a way anyone notices. It degrades one hire at a time, and the symptoms look like unrelated annoyances.
The setup was right once. Somebody sensible chose it when the firm was six people in one office, and it worked. It is now nineteen people across two locations and a lot of home working, and nothing has been re-decided since — because nothing ever broke badly enough to force the conversation.
This is the most common condition we meet, and it is not a failure of judgement. It is what happens when growth arrives in steps and infrastructure is only ever reviewed after an outage.
What it looks like from inside
- A shared drive that everybody can reach, because working out who should reach what became a job nobody had time for.
- Three people who know where the important files are, and a new starter who has to ask one of them every day for a fortnight.
- Accounts belonging to people who left, still live, because removing them was never anyone's specific responsibility.
- A VPN that half the firm has given up on and works around by emailing files to themselves.
- Software licences for a headcount you had two years ago — in both directions, and one of those directions is a compliance problem.
Why it matters before it breaks
None of these is urgent. Collectively they are the reason a single compromised account turns into a firm-wide incident, and the reason a client security questionnaire is painful to answer honestly. They are also the reason onboarding a new hire takes a week of somebody else's time, which is a cost nobody is counting.
The insurance renewal is often what forces it. The technical questionnaire attached to a cyber policy asks about access reviews, joiner and leaver processes and multi-factor coverage, and the honest answers are uncomfortable in a way that a working week never quite is.
The order to fix it in
Not a rebuild. Firms in this position almost never need to replace what they own, and being told they do is a reasonable reason to distrust whoever said it. What they need is a sequence, and the sequence is usually the same.
- Establish who has access to what. You cannot fix an access problem you cannot see, and the list is usually surprising.
- Fix joiners and leavers as a process, not as a series of favours. Everything else drifts back without it.
- Enforce multi-factor authentication everywhere, including for the partners who were exempted because it was inconvenient.
- Then, and only then, look at the shared drive structure — because reorganising files before fixing access just moves the problem into new folders.
If your setup was designed for the firm you were at the last step of growth, it will be wrong again at the next one. The fix is not a bigger design; it is reviewing it on a schedule instead of after an incident.