In most companies, reducing IT costs is synonymous with major decisions: which service provider to work with, what level of support to purchase, and how much to spend on hardware. In reality, however, at least as much money is being wasted through small, unnoticed habits that nobody picks up on, because they do not appear as a large, one-off expense, but slip away quietly in the background, month after month.
We’ve put together a list of five such habits. None of them requires a major investment, and each can be implemented in just a few hours, yet the long-term savings can be surprisingly substantial.
1. Two-factor authentication wherever possible
For a long time, it was standard practice to require passwords to be changed at regular intervals, at least every 60–90 days. However, this recommendation has since been officially withdrawn by NIST (the US standards organisation that sets the global benchmark in this field), after it emerged that: forced password changes actually lead to weaker, rather than stronger, passwords in practice, as most people simply change one character or the year in their old password, which an automated cracking attempt can figure out in a matter of minutes.
The current, truly effective solution is to implement multi-factor authentication (MFA) for all key accounts: email, enterprise management systems, cloud storage and online banking. This means that a stolen or guessed password alone is no longer enough to gain access; a second factor, which only you possess (a code, a notification or a physical key), is also required. This is one of the cheapest – and often free – layers of protection, yet it alone stops the majority of successful password-based attacks; in other words, it prevents precisely the sort of incident whose resolution, investigation and follow-up communication would otherwise cost real money and time.
2. Regular review of redundant software licences
This is one of the least visible, yet most expensive areas. According to international surveys, on average 30–50 per cent of SaaS licences purchased by companies remain under-utilised or completely unused; in other words, we pay for them, but practically nobody uses them. According to another wide-ranging survey, nearly 37 per cent of all installed software is never opened by anyone, which in itself represents a significant, recurring annual expense per desktop computer.
In practice, this usually happens when someone takes out a subscription for a project; the project then comes to an end, but the licence remains. Or a colleague leaves, and their account – along with the associated licence – simply remains in the system. A simple review, carried out every six months or annually, to check who is actually using each piece of software and who isn’t, immediately reduces monthly expenditure for many companies without any additional investment.
3. Enabling automatic updates
This is perhaps the simplest of the five habits, yet in many places it remains switched off because a restart „interrupts work”. However, the vast majority of updates are not convenience features, but security patches. They plug precisely those gaps that attackers are most actively seeking to exploit. An outdated system is one of the most common points of entry, and recovering from such an incident – from lost working time to emergency service provider fees – is orders of magnitude more expensive than a scheduled restart lasting just a few minutes.
4. Regularly tested backup
Most companies have backups, but the question is: when was the last time anyone actually tested whether it’s possible to restore data from them? A backup in itself is not protection, just a promise; real protection comes from regularly carrying out actual tests to ensure that it works. A backup that has been set up incorrectly or has not been checked for years tends to cause problems precisely when it is most needed. After a computer replacement, a hardware failure or a ransomware attack, when there is no longer any way to recover the lost data.
5. Immediate revocation of access rights for departing colleagues
When someone leaves the company, their physical access card is usually reclaimed immediately, but digital access rights are, surprisingly often, left active for weeks or even months. This costs money in two ways: on the one hand, it poses a security risk (a former employee who still has access to company systems); on the other, it is one of the most common sources of the licence wastage mentioned in point 2. A simple „exit checklist”, which is worked through every time someone leaves, addresses both risks in a single step.
None of the above practices requires any serious technical knowledge or major investment; they are all more a matter of mindset: regularly checking on the things that would otherwise „just run” in the background. In the long term, it is precisely these small, consistently followed habits that yield the greatest and most easily achievable savings in a company’s IT budget.