Start with business dependency. You do not need an inventory of every device. You need a defensible view of the systems, people, vendors, and sites that would interrupt orders, production, shipping, payroll, cash collection, or month-end close.
Questions finance leaders raiseCan I trust the number before close? Are the workarounds known? If the provider changes, who owns the knowledge? What happens if the ERP or identity system is unavailable on a production day?
Days 1–30: establish the facts
- Name the business systems that stop revenue, production, fulfillment, or close.
- Identify the executive, business owner, and technical owner for each critical system.
- Request the current IT budget, provider agreement, project list, asset lifecycle plan, and cyber-insurance questionnaire.
- Ask where critical knowledge lives: internal staff, a provider, a consultant, or an undocumented workaround.
Days 31–60: test the evidence
- For each critical system, ask for the last recovery test, its result, its owner, and its actual time to restore.
- Review current vendor access, privileged accounts, and what happens when a person leaves.
- Compare planned technology spend with open renewal, replacement, and implementation commitments.
- Confirm the status of ERP integrations, manual imports, data ownership, and reconciliations.
Days 61–90: turn findings into decisions
| Decision | Evidence to request | Useful output |
|---|---|---|
| Fund recovery | Restore-test record, RTO/RPO, system owner | Prioritized recovery plan |
| Change provider | Service history, access inventory, transition plan | Risk-managed transition decision |
| Approve ERP work | Dependencies, data-quality baseline, cutover plan | Go, pause, or phase decision |
| Set the budget | Run-rate, renewals, lifecycle, project estimates | 12-month investment roadmap |
The goal is not a technical audit. It is a short decision file that makes ownership, evidence, timing, and financial exposure visible.