Systems & Operations Audit

What you're running, who can reach it, and what it's quietly costing you.

Most small businesses never had an IT plan. Email, files, access and the website each got decided once, years apart, usually under pressure. Nobody has looked at the whole thing since. This is that look - fixed fee, plain English, and yours to keep.

Two reasons people call

Most owners call me for one of two reasons.

It's the same audit either way. The reason you called just tells me where to start.

“Something about my systems worries me.”

Maybe your email keeps landing in spam. Maybe you read about another business getting hit and realized you don't actually know who can still get into yours. I start there: who has access, whether your email can be trusted, where your files really live, and what happens if a laptop walks out the door.

“The work's there. The money isn't.”

You're booked. You're busy. And the profit still isn't what it should be at the end of the month. I start with the spend and the flow: what you pay for, what you pay for twice, and where a lead slips out before it turns into a paid invoice.

Either way I look at the whole business, not just the half you called about. You get one document in plain English, with the fixes in the order I'd actually do them. Fixed fee, from $3,500.

What it covers

Five places small businesses lose money and don't know it.

Accounts & access

Who can reach what, which accounts hold administrator rights, and who still has access that shouldn't. Former staff and contractors are the usual finding.

Email & authentication

Whether your domain can prove your mail is really yours - SPF, DKIM and DMARC. Missing records mean more of your mail lands in spam and anyone can send as you.

Files & backup

Where business data actually lives, whether it's on someone's personal account, and what happens to it if a laptop dies or a subscription lapses.

Licensing & spend

What you're paying for, what you're paying for twice, and what you're paying for that doesn't do the thing you bought it to do.

And the fifth: the workflow between them - how a lead becomes a client and a client becomes an invoice, and where that path drops things.

What you get

A document you can act on without a translator.

1

A findings document in plain English

Every finding explained so you understand it, with the technical detail underneath for whoever implements it. If a sentence doesn't make sense to you, that's my error, not yours.

2

Marked by confidence, not opinion

Verified, reported, or still to confirm. You'll always know which findings I checked myself and which came from our conversation.

3

A prioritized sequence

Not a list of forty things. What to do first, what can wait, what to avoid - and the order that keeps your email working while you do it.

Real findings

What an honest outside look actually turns up.

Coaching practice

Hired to finish a stalled Microsoft 365 migration. The migration was the smaller half. Their domain had no SPF and no DMARC - mail had been going out unauthenticated for years. An administrator account nobody meant to create held the keys to the whole tenant. They were paying for licences that didn't include the apps they were trying to use. And 10 GB of business files sat on a personal account with an expiry date on it.

Event venue

Told by a previous consultant to "post more on social media." The real problems were underpricing, software they were paying for twice, and a booking funnel that dropped enquiries between the form and the follow-up. Roughly $100K a year, none of it visible from the outside.

Concrete contractor

A working website that simply didn't load if you typed "www" in front of it. Every customer who did that hit a dead server and assumed the business had closed. Nobody had ever checked.

One recent engagement went past an audit into live incident response: a medical practice encrypted twice in three months. Read the ransomware recovery case study →

Terms

Fixed fee. And you can stop after it.

The audit is a defined piece of work with a defined price - from $3,500. You get the findings document whether or not you hire me to fix anything. No retainer, no obligation, and no upsell built into the report.

The same promise as every engagement: if the audit doesn't surface at least three times its cost in savings or recoverable revenue, you don't pay for it.

If you do want the fixes done, that's a separate conversation with a separate scope - priced after you've seen the findings, not before.

Not ready for the full audit? The free Systems Checkup is a 20-minute surface read of the same five areas, with traffic lights and a one-page report. The audit is the investigation that follows: what's wrong, why, and the order to fix it.

Fit

This is built for owner-run businesses.

A good fit if

You have somewhere between 2 and 25 people. You run on Microsoft 365 or Google Workspace. Nobody in the building is the "IT person," and the answer to "who set this up?" is either a former employee or a company you no longer use.

Probably not a fit if

You already have an internal IT team or an active managed service provider doing this work. I'd rather tell you that on the first call than take the engagement.

Who does the work

A working IT & security leader who speaks plain English.

I'm Leonel Lordeus. Twenty-one years in IT - network engineering and datacenter operations early on, and today a solutions architect designing multi-site network and cloud environments, and a chief information security officer. My job has always been finding the risk and the waste other people missed, and explaining it to non-technical people without the jargon. I don't upsell, and I'll tell you the truth even when it isn't what the last consultant said. (I work in English and Haitian Creole.)

In their words

What it's like on the other side of it.

“Leonel was very knowledgeable, very thorough, and his work style was perfect. I especially appreciated how clearly and empathetically he communicated. I highly recommend Leonel to anyone needing tech support.”

Jodi - Understory Coaching

Common questions

Questions owners actually ask.

What is a systems and operations audit?

A fixed-fee, read-only review of the systems your business actually runs on: who can reach your accounts, whether your email can be trusted, where your files really live, what you are paying for every month, and how the work moves between all of it. You get a plain-English findings document you can act on, whether or not you hire me to fix anything.

Do you need my password or admin access?

No. I have never needed a client's password, and if anyone doing this work asks for yours, that alone is a reason to stop. We do it one of two clean ways: you create a read-only administrator account that you remove afterward, or we work on a short screen share where you click and I tell you where to look. You keep control the whole time.

Will you change anything, or just look?

Just look. The audit is read-only by design. Nothing gets changed, deleted, or reconfigured during it. If something needs fixing, that is a separate decision with your explicit go-ahead, priced after you have read the findings, not before.

I already have an IT provider. Why would I need this?

If you have an active provider or an internal IT person, you may not, and I will say so. The useful move there is to ask them the questions I would ask. This is built for owner-run businesses with nobody whose actual job is this, where email, files, access, and licensing each got decided once, years apart, and nobody has looked at the whole thing since.

Do you cover both Microsoft 365 and Google Workspace?

Yes. Most of the businesses I work with run one or the other, and the same review applies to both: accounts and access, email authentication, files and backup, licensing and spend, and the workflow between them.

What do I get, and what does it cost?

A plain-English findings document you can act on, with a prioritized sequence of what to fix first. Fixed fee, from $3,500, and you keep the document whether or not you hire me for anything after. You can stop there.

What if you don't find anything wrong?

Then you get a short document saying exactly that, and you stop wondering. That is a real result, and it is worth paying for. A fixed fee is what makes it honest: I am paid the same either way, so I have no reason to inflate the list.

How do I know my business email is set up right?

Three records, SPF, DKIM, and DMARC, decide whether your email can be trusted, and most owners have never checked them. It is the first thing I look at on every audit. If you want a quick read on your own, send me your domain and I will check all three for free.

Next step

Start with a free 15-minute call.

Tell me what's frustrating you. I'll tell you straight whether an audit would find anything worth the fee - and if I don't think it would, I'll say so.

Or run the free website scan first - it checks the public-facing half in about two minutes, and it's a reasonable way to see how I work before you talk to me.