What Happens in the First Hour After Something Breaks

Response times, coverage windows, and service levels are worth agreeing to in writing. They describe the shape of support. What they do not tell you is how it feels at eleven on a Wednesday morning when something has stopped working.

So here is the concrete version. This is what the first hour looks like.

Minute zero. How it gets noticed

A problem arrives in one of two ways. A system reports it, or a person does.

A good deal of what monitoring catches never becomes something anyone at your firm experiences. A disk filling up, a backup that did not finish, a service that needs restarting, a device that has fallen behind on updates. Those get handled quietly and turn up in a report.

The other route is a phone call, and some things are only visible from the desk of the person trying to work.

Minutes one to five. Somebody who knows your setup picks up

This part shapes the rest of the hour.

When the person answering already knows your environment, the conversation opens at what changed and who is affected. That familiarity does real work at minute three, and it is one of the practical reasons we keep the same people on the same accounts.

Minutes five to fifteen. Scope first

Before fixing anything, it helps to know how far it reaches.

One person or the whole office. One application or everything. Anything changed recently, a new device, an update, a password, a vendor doing work. And whether anything client facing is affected in the next hour.

That last question sets the priority, and it is a business question. A practice that cannot pause and a firm that can work offline for an afternoon need different sequencing, and knowing which you are is part of knowing the account.

Minutes fifteen to forty. Get people working

Restoring the work and fixing the cause are two jobs, and the work comes first.

Sometimes one action does both. Often there is a way to get people moving while the cause is still being traced: a different route to the same file, a temporary workaround, moving somebody to another machine. The point is that the firm stops being stopped.

This is also where a tested backup earns its keep. A restore you have already practiced is something you can reach for inside the hour.

Minutes forty to sixty. Say what is happening

Communication during an issue is what people remember afterward, often more than the fix itself.

What they need stays the same throughout. What is affected? What is being done? When they will hear next. Saying so at a predictable interval keeps a technical problem from turning into a dozen versions of the same question.

After the hour

Three things should follow. A plain English explanation of what happened. A change that makes it less likely next time. And a record of it, so the next person to look at your environment has the history.

The record is the one worth insisting on. It is what keeps the same problem from being solved twice, eighteen months apart, by somebody with no memory of the first time.

What gets agreed in writing

Everything above describes how the hour runs. What that hour is worth to you depends on what was agreed before it started.

Response time is the part worth pinning down. Some firms are fine with a four hour response and never think about it again. Others need a faster commitment than that, live coverage around the clock, and a set allowance of onsite hours written into the agreement. Those are different arrangements at different prices. I put the number in writing rather than leaving it to be worked out on the day something breaks.

Which arrangement a firm needs usually comes down to one question. How long can you be stopped before it costs you a client? A medical practice and a design studio will answer that differently, and they should buy differently.

The question worth asking

Ask any provider to walk you through this hour for a firm like yours. How the issue reaches them, who picks up, what that person will already know about your setup, and what gets communicated when.

A description tells you more than a document will.

Call to action

If you want to hear how that hour would run for your firm, call 617-221-4100 or use the contact form at cmitsolutions.com/boston-ma-1020. No obligation.

Frequently Asked Questions

1. What are the signs that a business has outgrown handling IT internally?+
Common signs include relying on one employee for all IT issues, slow onboarding and offboarding, difficulty answering security questionnaires, untested cybersecurity controls, unused software licenses, and increasing IT problems as the company grows.
2. When should a small business consider outsourcing IT support?+
A business should consider outsourcing IT when technology responsibilities are taking significant time away from employees’ primary jobs, security requirements are becoming more complex, or there is no clear person responsible for managing IT.
3. Why is relying on one employee for IT risky?+
If one employee holds most of the company’s technical knowledge, the business can become vulnerable when that person is unavailable, takes leave, or leaves the organization.
4. What is undocumented IT knowledge?+
Undocumented IT knowledge includes passwords, configurations, vendor details, network information, processes, and troubleshooting knowledge that exists only in one person’s memory instead of being formally recorded.
5. How can poor IT documentation affect a business?+
Poor documentation can slow troubleshooting, onboarding, system changes, disaster recovery, and vendor transitions. It can also make the business overly dependent on specific employees.
6. What should an effective employee onboarding process include?+
IT onboarding should include account creation, email setup, device configuration, software access, security permissions, multi-factor authentication, and confirmation that the employee has the correct level of access.
7. Why is employee offboarding important for cybersecurity?+
Proper offboarding helps ensure former employees cannot continue accessing business email, cloud platforms, files, applications, shared accounts, or company data after they leave.
8. What happens if inactive employee accounts are not removed?+
Unused accounts can become security risks because attackers may exploit credentials that are no longer actively monitored. They can also create unnecessary software licensing costs.
9. Why are clients sending cybersecurity questionnaires to businesses?+
Clients increasingly want assurance that vendors and partners are protecting sensitive information. These questionnaires often ask about access controls, backups, multi-factor authentication, incident response, and data security practices.
10. What cybersecurity information should a business have documented?+
Businesses should know where their data is stored, who can access it, how accounts are protected, how backups work, what security tools are being used, and what happens when a cybersecurity incident occurs.
11. Is multi-factor authentication necessary for every business account?+
Multi-factor authentication is an important security control for accounts containing or providing access to business information. Coverage should be reviewed regularly to identify accounts that may have been overlooked.
12. Is antivirus software enough for a business?+
Antivirus is only one layer of cybersecurity. Businesses may also need endpoint detection, multi-factor authentication, patch management, security monitoring, backups, email protection, and other controls depending on their environment.
13. What is endpoint detection and response?+
Endpoint detection and response, or EDR, monitors computers and other endpoints for suspicious behavior and helps detect and respond to threats that traditional antivirus tools may miss.
14. Is cloud file syncing the same as data backup?+
No. Cloud synchronization keeps files updated between locations and devices, while backup systems are designed to preserve recoverable copies of data if files are deleted, corrupted, encrypted, or otherwise lost.
15. Why should businesses test their backups?+
A backup is only useful if the data can actually be restored. Regular restore testing helps confirm that backups are working properly before a real outage, ransomware incident, or data loss occurs.
16. What is software license drift?+
License drift happens when businesses accumulate unused accounts, duplicate subscriptions, unnecessary applications, or devices that are no longer properly covered as their technology environment changes.
17. How often should businesses review their software licenses?+
A formal license review at least annually can help identify unused subscriptions, duplicate applications, unnecessary spending, and gaps in software or security coverage.
18. How does business growth affect IT management?+
Adding employees, remote workers, locations, applications, and clients increases technology complexity. Processes that worked for a small team can become inefficient and difficult to manage as the organization expands.
19. Does outsourcing IT mean losing control over technology decisions?+
No. A managed IT provider can handle monitoring, maintenance, security, support, and routine administration while the business continues making the strategic decisions about its technology.
20. What should a Greater Boston business look for in a managed IT provider?+
Look for a provider that offers proactive monitoring, cybersecurity, backup management, patching, onboarding and offboarding support, clear documentation, responsive help desk services, and familiarity with businesses in Newton and Greater Boston.

 

Back to Blog

Share:

Related Posts

Protecting Your Data Amidst Cyber Attacks” with Scott Krentzman of CMIT Solutions

Scott Krentzman, President of CMIT of Solutions of Boston, Newton, Waltham, joins…

Read More

How Hackers Hack & How to Protect Your Business

A webinar brought to you by CMIT Solutions and Barracuda MSP. Simply…

Read More

Email Authentication Changes: What Google and Yahoo’s Updates Mean for You

Email Authentication Changes: What Google and Yahoo’s Updates Mean for You By…

Read More