What a New IT Partner Usually Finds in the First 90 Days

Most businesses that outsource their IT assume the biggest change will be who answers the phone when something breaks. In practice, the more significant moment usually happens earlier and more quietly — during the first assessment, when a new provider actually looks at what’s been running behind the scenes. What gets found in those first 90 days is remarkably consistent across businesses that have never had an outside, professional review.

Why the Findings Are So Predictable

The pattern repeats often enough that it’s become a documented phenomenon rather than a surprise. A professional assessment of a small business environment typically finds unpatched systems, misconfigured cloud permissions, no network segmentation, no tested recovery process, no logging, no monitoring, and no formal incident response plan — even in businesses whose internal setup looked complete from the inside, with a firewall and antivirus already in place, according to research on small business cybersecurity assessment findings. None of this reflects negligence. It reflects the reality that a business without a dedicated security specialist has no reliable way to know what a professional review would actually surface.

The scale of what typically goes unpatched is significant. Sixty percent of security compromises trace back to known, unpatched vulnerabilities — meaning the fix already existed; it simply hadn’t been applied, according to Verizon’s 2025 Data Breach Investigations Report. That statistic alone explains much of what a new IT partner finds during an initial assessment: not exotic, hard-to-detect threats, but ordinary, known issues that had simply never been addressed because nobody with the right expertise had looked closely enough to catch them.

The Specific Categories That Show Up Almost Every Time

A handful of findings appear with striking consistency across initial assessments:

Unpatched software and operating systems. Critical updates that address known vulnerabilities often go unapplied for months, sometimes because there’s no formal process for patching, sometimes simply because nobody realized how far behind systems had fallen.

Accounts that should have been deactivated but weren’t. Former employees, old vendor relationships, and abandoned trial accounts frequently still have active access long after anyone remembers they exist.

Backups that exist but have never actually been tested. A backup process that’s technically running gives false confidence if nobody has confirmed that data can genuinely be restored from it when needed.

No documented incident response plan. Most small businesses have never written down who gets called first, who has authority to make emergency decisions, or what the actual recovery steps look like if something goes wrong — meaning a crisis starts with confusion rather than a plan.

Missing multi-factor authentication on key systems. Even businesses that feel reasonably secure often discover that MFA was only partially rolled out, covering some systems but leaving critical ones exposed.

Why This Keeps Happening to Businesses That Feel Fine

Federal cybersecurity guidance has documented this exact pattern for years. Weak security controls routinely exploited for initial access include accounts of former employees that were never properly removed, missing multi-factor authentication, and unpatched software running well past when updates were available, according to CISA’s advisory on weak security controls exploited for network access. The advisory doesn’t describe rare, sophisticated failures — it describes ordinary gaps that accumulate quietly in any environment without a dedicated process for closing them.

Part of why these gaps go unnoticed for so long comes down to a basic sequencing problem: most security frameworks, including the widely used NIST Cybersecurity Framework, treat asset inventory and identification as the foundational first step of any security program, precisely because an organization can’t secure what it doesn’t know it has. A business that’s never conducted a formal inventory of its own devices, accounts, and software has no way of knowing what’s actually running, let alone whether it’s properly secured — which is exactly the gap a new provider’s initial assessment is designed to close.

What This Means for the First Few Months of a New Partnership

Given how consistent these findings are, the first 90 days of a new IT relationship are rarely quiet. This is actually a healthy sign, not a red flag — a provider who reports back a clean, issue-free environment during an initial assessment is either working with an unusually well-maintained business or hasn’t looked closely enough. A thorough discovery period followed by a prioritized remediation plan is a sign the partnership is starting on solid footing, not evidence that something was previously being done badly by whoever managed IT before.

For businesses considering IT outsourcing in Philadelphia for the first time, understanding that this discovery phase is normal — expected, even — helps set the right expectations from day one. The goal of those first 90 days isn’t to assign blame for what’s found. It’s to build an accurate, current picture of what’s actually running, so remediation can be prioritized based on real risk rather than assumptions.

What a Healthy First 90 Days Actually Looks Like

A well-run onboarding period typically includes a full inventory of devices, accounts, and software; a prioritized list of findings sorted by actual risk rather than presented as one overwhelming list; a clear remediation timeline distinguishing urgent fixes from longer-term improvements; and transparent communication about what was found and why it matters, rather than technical jargon delivered without context.

The Real Value of Going Through This Process

The findings from an initial IT assessment aren’t a verdict on how badly a business was previously managing its technology — they’re simply what happens when a trained set of eyes looks closely at systems that have been running without that kind of scrutiny. Businesses that go through this process gain something most never had before: an accurate, documented picture of their actual technology environment, rather than an assumption based on the absence of visible problems. That clarity, more than any single fix, is usually the most valuable outcome of the first 90 days. See More