IT Standard Operating Procedures · British Virgin Islands
An IT standard operating procedure (SOP) is a written, repeatable set of steps for carrying out a specific technology task the same way every time, regardless of which technician performs it or when they joined the team.
SOPs turn IT knowledge that would otherwise live in one person's head into a document the whole team, and any new hire, can follow.
Fresh Mango Technologies builds and maintains SOPs for every client environment we manage, from staff onboarding to disaster recovery, so support quality does not depend on which engineer picks up the ticket.
Which SOPs a business actually needs
Not every task needs a formal procedure, but any task that is repeated regularly, carries security or compliance risk, or would cause damage if done inconsistently, does. In practice most British Virgin Islands businesses need SOPs covering: staff onboarding and offboarding, backup verification, incident response, device provisioning and disposal, password and access resets, patching and change control, and vendor escalation.
The right number of SOPs is the smallest set that covers every task where inconsistency creates risk — a handful of well-maintained documents beats a large library nobody reads.
Worked examples
Staff onboarding
A documented onboarding SOP specifies exactly what is created and in what order: Microsoft 365 account and licence assignment, group and SharePoint access aligned to role, Microsoft Teams channels, device build, multi-factor authentication enrolment, and a signed acceptable-use acknowledgement. Following the same sequence every time prevents both under-provisioning, which delays a new starter, and over-provisioning, which creates unnecessary access risk.
Staff offboarding
Offboarding is the SOP most often skipped under time pressure, and the one with the highest security cost when it is. A proper procedure revokes Microsoft 365 sign-in immediately, resets shared passwords the departing person knew, transfers mailbox and OneDrive ownership, removes remote access and VPN credentials, and recovers company hardware — all logged with a completion date.
Backup verification
A backup job reporting 'success' is not the same as data being recoverable. The SOP defines a fixed schedule for restoring a sample file or mailbox to confirm the backup actually works, who performs the test, and where the result is logged, closing the gap between believing backups work and knowing they do.
Incident response
When ransomware, a phishing compromise or an outage hits, decisions made in the first hour matter most. The SOP sets out who is notified, in what order systems are isolated, how evidence is preserved, when Complete Cyber Security or law enforcement is engaged, and what staff and clients are told and when — removing guesswork from a moment when guesswork is most dangerous.
Device provisioning
A device SOP standardises the build image, security baseline (disk encryption, Microsoft Defender, patch level), asset tag and registration in the asset register before a laptop or desktop reaches a user, so every machine in the fleet starts from the same known-good state.
Keeping SOPs current
Assign an owner for each SOP who is responsible for reviewing it, not just the person who first wrote it.
Review procedures whenever the underlying system changes — a Microsoft 365 licensing change, a new backup platform, a new device model — not on a fixed annual date that quietly drifts out of sync.
Test the procedure by having someone who did not write it follow it; anywhere they get stuck is a gap in the document, not the reader.
Store SOPs in one shared, version-controlled location such as SharePoint, not scattered across individual inboxes or desktops.
Retire SOPs for retired systems immediately, so nobody follows a step for a platform that no longer exists.
How Fresh Mango helps
Fresh Mango Technologies has documented and maintained SOPs for British Virgin Islands businesses since 2008. Every managed client environment we run has written procedures for onboarding, offboarding, backup verification, incident response and device lifecycle, held in a shared location and reviewed on a fixed schedule rather than left to individual memory.
Frequently asked questions
What is an SOP in an IT context?
An IT standard operating procedure (SOP) is a written, step-by-step instruction for carrying out a specific technology task the same way every time. It covers activities such as onboarding a new employee, verifying a backup, provisioning a device or responding to a security incident, so the outcome does not depend on which technician performs the task or how long they have worked there.
Does Fresh Mango Technologies have SOPs in place for client support?
Yes. Every environment Fresh Mango Technologies manages has documented procedures covering staff onboarding and offboarding, backup verification, patching and change control, device provisioning, and incident response. Procedures are held in a shared, version-controlled location, assigned an owner, and reviewed whenever the underlying system changes, so support quality is consistent regardless of which engineer is on a ticket.
Why do small businesses need IT SOPs if they only have a handful of staff?
Small teams are the most exposed when knowledge lives in one person's head, because there is no backup if that person is unavailable or leaves. A short set of SOPs covering onboarding, offboarding, backups and incident response costs little to write and protects a small business from the single biggest IT risk it faces: dependence on one individual's memory.
How many IT SOPs does a typical business need?
There is no fixed number — the right target is the smallest set of documents that covers every repeated task where inconsistency creates risk. Most businesses need SOPs for onboarding, offboarding, backup verification, incident response, device provisioning and password resets; larger or regulated organisations add change control, vendor escalation and compliance evidencing procedures.
Who should own an IT SOP?
Each SOP should have a named owner responsible for keeping it accurate, not just the person who originally wrote it. The owner reviews the procedure whenever the system it covers changes, and confirms at a fixed interval that it still reflects reality, so documents do not quietly go stale while everyone assumes they are correct.
Standard Operating Procedures (SOPs) first came into common business parlance and usage in the manufacturing industry post-World War II.
Simply put, an SOP is “a set of written guidelines or instructions for the completion of a routine task, designed to increase performance, improve efficiency, and ensure quality through systemic homogenization”* Knowing the importance of SOPs is very important in the IT industry.
So manufacturers set about writing procedures, training their workforce in following them and then monitoring the same to ensure procedures were followed consistently. This brought huge benefits to manufacturers, including:
· Consistency of production – by following the same procedure every product and component would be the same. This brings huge benefits in terms of quality control, reduction in defects and therefore customer satisfaction
· Improved efficiency – no need to try and figure out how to do something – staff are trained on the procedure and then follow it. Eliminating guesswork streamlines processes and makes production faster
· Continuous improvement. With a procedure in place, consistently adhered to, it’s much easier to improve on it. If everyone ‘does their own thing’ best practice is almost impossible to determine. With a standard procedure and a feedback culture in the workforce, it’s possible to improve procedures and processes continuously.
McDonald's famously adopted an SOP approach to ensure consistency of food production and service. As a result, a Big Mac in New York looks and tastes the same as one served in Tokyo. This doesn’t mean the menus don’t also reflect local tastes – you can order a Teriyaki burger in Japan – but consistency remains key.
How McDonald's has approached SOPs
So what does this have to do with Information Technology and IT support for customers? Well, I’ve found that as our business has expanded so too has the need for consistency. As a start-up 11 years ago (in the British Virgin Islands) there was pretty much nothing written down – we were focused on building the business. Then as we grew and we recruited technicians, it was possible to explain procedures to them individually and advise them on an ongoing basis. With a co-located handful of staff, this was entirely possible and also made ongoing improvement communications possible too.
Then we expanded and acquired a company in England (CCS2000). We now had a choice – allow the businesses to operate autonomously and ‘go their own way’ - or standardise. We chose the latter route for several reasons:
· We wanted to ensure best practice could be shared across the companies
· First-class IT management requires the same expertise, training and knowledge no matter where you operate
· We wanted technicians on either side of the Atlantic to be able to provide support to customers no matter where they (the customers) were located
· We wanted to adopt a proactive-support model that minimised client IT issues – to move away comprehensively from the ‘Break-Fix’ approach which (to my astonishment) is still prevalent in the industry.
In adopting this approach we were also mindful of the need for flexibility of approach on a local basis (as for the McDonalds teriyaki burger example). This meant we needed to adopt a dual approach:
1. Operational standardisation – consistency of approach on all IT-related matters. So for example, setting up a new PC for a staff member in one of our customers
2. Non-standard standardisation - an oxymoron that means ensuring any non-standard requirements for a customer are recorded and written into a procedure accordingly. Customer ABC may require their PCs to have some additional configuration in addition to our standard approach from (1).
So how did (do) we do this? Well, by the adoption of SOPs in Information Technology.
SOPs Information Technology
I can tell you from experience, it’s much easier said than done! We have been working on it for several years and it’s fair to say that it will always be an ongoing activity. There’s always a new procedure to write or an existing one to amend or improve upon.
Nonetheless, when we acquired another IT business in England (IDT) in 2019, it was clear that all the hard work had paid off. We were able to standardise working practices in a matter of weeks. Furthermore, we were able to adopt best-practice from within the new business to our existing procedures.
It’s worth noting that it isn’t just a matter of writing (and updating) the SOPs. Underpinning standardisation is the need for:
· Ongoing training – existing staff refreshers, new starters all need to be trained and monitored for process adherence
· Open culture – openness to feedback from the technicians following the procedures is key to continuous improvement. It also has the added benefit of participation which lends itself to a healthy work culture
· Integrating tools – we have the benefit of a bespoke business management system that we have developed ourselves (JIM). This allows us to deploy and monitor SOPs accordingly, with the flexibility to amend our processes thanks to the bespoke nature of our BMS.
It’s been a challenging and fascinating journey to move from ‘start-up in the sun’ to a Trans-Atlantic IT business. No doubt it will continue to be so, but without the adoption of SOPs, I know it would not have been possible.
Adoption of SOPs
Explore more in IT Support
Managed IT support, helpdesk, monitoring and outsourcing for BVI and Caribbean businesses.