A manager calls because "the computers can't keep up any more". On arrival you find three people emailing each other the same stock file, invoicing kept on a machine that is backed up nowhere, and a personal email address used for the entire customer base. None of those problems is solved by buying a computer. All of them are solved by first understanding how this team works.
Translating a business into tools
That translation is the core of the trade. A client never describes an IT need: they describe an irritation. "We waste time", "we can't find anything", "the file disappeared", "I don't know who changed what".
The work consists in going back from the irritation to its cause, then from the cause to a tool — in that order. Many failed installations come from the reverse order: software chosen first, and a business bent afterwards to fit inside it.
It is an interpreter's position between two languages: the owner speaks about their trade, the market speaks about products. Nobody else makes that crossing, and it is what you buy when you call a consultant.
Observe before recommending
The simplest method is also the rarest: spend time on site watching people work before saying anything.
You learn what no interview provides. Who enters what, and when. Which information is typed twice. Which document circulates as a phone photograph because it exists nowhere else. Which person has become, without anyone deciding it, the company's memory.
Out of that come honest priorities: what costs money today, what will cost money tomorrow, what can wait. A plan that tackles everything at once never happens.
A written assessment rather than a verbal opinion
An opinion given standing in a corridor binds nobody and is lost within three days. A written assessment changes the nature of the relationship.
It describes what was observed, what is a problem, what is recommended, at what cost and effort, and what the client loses by doing nothing. It also states its limits: what was not checked, what depends on a third party, what remains uncertain.
The point is not formality: a document lets the owner decide knowingly, weigh it against their budget, and find out again in six months why a given choice was made.
The independence of the advice
This is where the trade's credibility is decided, and it deserves saying plainly: advice paid for by the seller is not advice.
A consultant can recommend hardware, software or a host without selling them, saying where to buy and at what market price. They may also choose to resell — but they must then say so, because a client does not weigh a disinterested recommendation and a sales proposal in the same way.
What a consulting engagement pays varies by country, by the size of the organisation, by duration and by the nature of the commitment. What matters is not the amount but the clarity: what is billed, what is not, and what the consultant earns elsewhere on the choices they recommend.
Accounts, access and who owns what
This is the subject that causes the most damage and gets discussed the least, because it only becomes visible at the moment of separation.
The question is easy to ask: in whose name are the accounts opened? The domain name, the hosting, the email, the management tools, the advertising accounts, the analytics, the social networks, the payment solution. If the answer is "in the provider's name", the business does not own its own working tools.
ICANN, which coordinates the domain name system, publishes a list of registrants' rights and responsibilities. It recalls that registration is the subject of an agreement with an ICANN-accredited registrar, that the registrant may review that agreement at any time, and that they are entitled to accurate information about their registrar's identity, its pricing, its customer support and its processes for registering, managing, transferring, renewing and restoring the name. In return, the registrant assumes sole responsibility for the registration and use of the name, must provide accurate information and keep it current, and must respond to their registrar's enquiries within fifteen days.
The practical consequence is clear: a domain name forgotten at renewal can take down both the website and the email addresses that depend on it. Good practice is to keep an inventory of services, accounts, holders and renewal dates — and to keep a copy of it somewhere other than in one person's head.
The legal rules on ownership of content and accounts depend on the contracts signed and on each country's law. What precedes is governance and organisation, not a universal rule.
Backing up is not synchronising
A frequent and expensive confusion: a folder synchronised across several machines is not a backup. A deletion synchronises too, and a file encrypted by ransomware synchronises just as diligently.
Five things need separating: live data, a backup kept separately, a synchronised copy, a version history, and an export usable elsewhere. They protect against different risks.
The principles are few: copies genuinely separated from production, a frequency matched to what you accept losing, restricted access, and above all tested restores. A backup never restored is not a backup: it is a hypothesis. No numbered scheme is a universal standard; the right rhythm depends on the activity and the risk accepted.
Professional email and the domain name
Many organisations run for years on a free personal address. It works, until it does not: nobody else can get into it, the commercial history belongs to an individual, and the address says nothing about the business.
Email attached to the domain name changes three things: each person has their own named address, the company keeps control when someone leaves, and the identity is consistent with the site. The cost and the solution depend on context; what matters is that the domain and the mailboxes are in the company's name.
Migrating without losing data
Changing tools is the riskiest operation in an IT estate, because it touches data, habits and the calendar at the same time.
It is prepared: an inventory of what exists, a decision on what is carried over and what is archived, a test on a sample, a period where both systems coexist, training, then the switch — with a verified backup before starting and a fallback plan.
Maintenance, incidents and continuity
A serious maintenance contract says what it covers: which machines, which software, which interventions, remote or on site, within what times, and what is excluded. The times announced are the provider's commitment, not a standard.
Handling an incident follows a constant pattern: identify, reproduce if possible, collect the symptoms, prioritise by impact, resolve, verify with the user, document and close. Documentation is not bureaucracy: the same incident comes back, and the second time must cost less.
Continuity extends all of this. An estate where one person alone knows the passwords, the suppliers and the renewal dates is a fragile estate, however good that person is.
Security: a framework for ranking risks
The consultant is not necessarily a security specialist, but they lay its foundations. The NIST Cybersecurity Framework, whose version 2.0 was published in February 2024, offers a useful way to structure the approach without jargon. That framework is explicitly voluntary: it helps organisations understand and improve their management of cybersecurity risk, it imposes nothing by itself.
For a small organisation it comes down to simple, ranked habits: named accounts rather than a shared one, rights limited to what is necessary, stronger authentication where it is available, updates actually applied, tested backups, and access revoked when someone leaves. None of this requires a large budget; all of it requires actually being done.
Personal data
A consultant reaches, by the nature of the work, data that is not theirs: customer files, contact details, accounting documents, sometimes personnel records. The discipline is to look only at what the job requires, to copy nothing outside the agreed scope, and to be able to say which access they hold and until when.
Legal obligations depend on the country. At continental level, the African Union Convention on Cyber Security and Personal Data Protection, adopted on 27 June 2014 in Malabo, covers electronic transactions, personal data protection and cybersecurity — but it produces effects only in the States that have ratified it, through their national laws and through competent authorities where these exist.
In African contexts
The trade is practised under very different conditions from one country and one city to another, and it would be wrong to describe a single African context.
Connectivity gives one measure of it. The International Telecommunication Union states that 74 per cent of the world's population uses the Internet in 2025, some six billion people, and that the figure reaches 36 per cent for Africa — the lowest of the regions it measures — against 94 per cent in high-income countries and 23 per cent in low-income countries. Those averages cover considerable gaps: the situation in a capital's business district has nothing in common with a secondary city or a rural area of the same country.
In practice this shapes the recommendations. Where the connection is irregular or billed by volume, a tool that works offline and synchronises afterwards is worth more than a fully online solution. Where power cuts are frequent, a UPS and automatic backup matter more than the machine's processing power. Where card payment is uncommon, a subscription payable by a local method is a condition of adoption, not a detail.
Other realities follow the same logic: how formalised the organisations being helped are, whether technical skills are available locally, whether a data protection authority exists, and what national rules apply to data localisation or transfer. Each is checked locally — none is deduced from the continent.
What a consultant does not promise
An IT consultant does not guarantee that no breakdown will occur, that no data will ever be lost, that a tool will suit forever, or that a third-party supplier will stay available. They themselves depend on a host, an operator, a software publisher, a registrar: they cannot promise total availability of a chain they do not control.
What they do commit to can be checked: real observation on site, a written assessment, justified recommendations with their limits, backups restored in front of the client, accounts opened in the company's name, documentation handed over and teams trained.
That is also what makes the activity legible: a professional name, stable contact details, an address on the company's domain, a service catalogue described without jargon, quotations and invoices, request tracking, and verifiable references. Artificial intelligence can help draft a report, sort requests or prepare an explanation; it can be wrong, invent a reference, and must receive no confidential data without precaution. Responsibility for what is handed to the client remains entirely the consultant's.
Finally, this article describes a trade; it replaces neither an audit nor a consultation. The obligations mentioned vary from country to country.