When a Dubai business first takes IT seriously, the temptation is to fix everything at once. That produces a list nobody completes. What works is accepting that some things must happen before others are even possible, and sequencing accordingly.
Quarter one: know what you have and stop the bleeding
You cannot plan around an estate you have not documented, and there is almost always something actively at risk that nobody has noticed.
- 1Asset and licence register: every device, every subscription, every renewal date. This alone usually pays for the quarter
- 2Verify backups actually restore, rather than that they report success. These are different things
- 3Multi-factor authentication on email and any remote access, which is the highest-return security action available
- 4Find and remove shared logins, starting with anything financial
- 5Document who has administrative access to what, which is frequently more people than anyone expects
The two that matter most
If you do nothing else in quarter one, test a restore and turn on MFA. Those two cover the failure modes most likely to seriously damage a business this year.
Quarter two: identity and endpoints
This quarter depends on quarter one, because you cannot design role-based access without knowing who has what today.
- 1Single sign-on across your main applications, so access follows one identity
- 2Role-based access groups replacing individual grants
- 3A joiner, mover and leaver process tied to HR rather than to someone remembering
- 4Device management enrolment, starting with company-owned hardware
- 5Patching and endpoint protection deployed and actually monitored
Quarter three: resilience
- 1Backup strategy properly designed, with off-site and immutable copies rather than one NAS in the same building
- 2A written recovery plan naming who does what, tested rather than filed
- 3Network and Wi-Fi brought up to standard, since most daily complaints trace here
- 4Vendor and contract review, using the register from quarter one to find overlaps and renewal dates
- 5Security awareness training started, once the technical basics are in place
Quarter four: plan the next year properly
- 1Hardware refresh plan with a staggered cycle rather than a cliff-edge replacement
- 2Budget forecast built from real renewal dates and refresh timing
- 3Compliance position established, if contracts or clients are starting to ask
- 4Documentation review, so the knowledge does not live in one person's head
- 5Roadmap for year two, written from evidence gathered rather than from assumptions
Why the order is not negotiable
| This | Depends on | Because |
|---|---|---|
| Role-based access | The access audit | You cannot define roles without knowing current state |
| Device management | The asset register | You cannot enrol devices you have not found |
| Recovery plan | Verified backups | A plan built on untested backups is fiction |
| Budget forecast | Vendor and asset registers | Forecasting without renewal dates is guessing |
| Awareness training | MFA and endpoint basics | Training people to compensate for missing controls is unfair |
What we deliberately leave out of year one
Cloud migration, major software replacement and anything described as digital transformation. Not because they are wrong, but because doing them on an undocumented estate with unverified backups multiplies the risk. Year two is the right time, once the foundations hold.
No roadmap and not sure where to start?
We run discovery, tell you what is actually at risk, and produce a sequenced twelve-month plan written for the people who have to approve the budget.
Frequently asked questions
Where should a Dubai SMB start?
Test whether your backups actually restore, and turn on multi-factor authentication for email and remote access. Those two address the failure modes most likely to cause serious damage, and neither requires a project or a large budget to begin.
Why not fix everything at once?
Because half the items depend on the ones above them. You cannot design role-based access without auditing current access, or enrol devices you have not inventoried. Attempting everything simultaneously produces a list nobody finishes.
How long does discovery take?
Typically one to two weeks for a small or mid-size business, depending on how many systems and vendors are involved and how much is documented. It is almost always the phase that surfaces the biggest surprises, particularly around licences nobody is using.
Should cloud migration be in year one?
Usually not. Migrating an undocumented estate with unverified backups multiplies risk rather than reducing it. Get the register, the access model and the backups right first. Migration becomes a much safer project in year two.
Who needs to be involved?
Whoever holds the budget, whoever knows the systems day to day, and one person from each department heavily dependent on IT. The total time commitment is usually a few hours spread across the engagement, plus the session where the roadmap is presented.
Usman K.
· IT Support LeadIT support lead at Azizi Technologies. Manages 24/7 helpdesk, Microsoft 365 migrations, server administration, and managed IT contracts for Dubai SMBs. Microsoft Certified. Mentioned by name in client reviews for fast resolution.
Need a quote for IT Strategy Consulting Dubai?
WhatsApp this article plus your device or site. We reply with next steps and a written quote.