Back to Blog
Modernisation

Running Your Business on Spreadsheets: When It Is Fine, and When It Becomes a Risk

A
Arun Godwin Patel
July 27, 20267 min read

Spreadsheets are underrated, right up until they are dangerous. Seven signals that yours has quietly become critical infrastructure, and what to do about it without a rebuild.

A spreadsheet grid with warning cells and a crack running across it, showing a file that has quietly become critical infrastructure.

Spreadsheets are the most underrated business software ever written. They are instant, they cost nothing extra, anyone can change one without asking permission, and they do exactly what the person who built them wanted. No purpose-built system can say all four of those things.

So this is not an article about getting off spreadsheets. Most businesses should keep most of theirs. It is about the specific moment when a spreadsheet stops being a useful tool and quietly becomes critical infrastructure that nobody maintains, nobody backs up and nobody fully understands.

This article is part of our guide to modernising a legacy business.

When a spreadsheet is the right answer

It is worth being clear about this first, because plenty of firms will happily sell you a system to replace something that works.

A spreadsheet is the right tool when one person uses it, changes are infrequent, the logic fits on a screen, and being wrong for a day would be annoying rather than expensive. Quotes, models, planning, one-off analysis, tracking a project. In all of these a spreadsheet beats a system, and buying software to replace one is a waste of money.

It is also the right tool for working out what you actually need. Building a spreadsheet first is the cheapest possible specification exercise, in the same way that an MVP is cheaper than a full product. If someone proposes a system for a process that has never been run manually, they are guessing.

The seven signals

Here is when it has stopped being fine. You do not need all seven. Three is usually enough to act on.

1. More than one person edits it. The moment two people can change the same file, you have a concurrency problem that spreadsheets were never designed to solve. Shared cloud versions help with the file locking and do nothing about the underlying issue: two people making reasonable changes that contradict each other.

2. There is a version with a name like "FINAL v3 (use this one)". This is the clearest signal there is. It means nobody is certain which copy is authoritative, which means decisions are being taken from a document that might be wrong.

3. Somebody would have to be called on holiday. If a formula broke and only one person could fix it, that person is now a dependency. They also cannot be promoted, because nobody else can take it on.

4. It feeds something external. Payroll, VAT returns, statutory accounts, a customer-facing quote, a regulator. Once a spreadsheet output leaves the building, the cost of an error stops being internal.

5. Nobody can explain a number without opening the file. If the answer to "why is that figure what it is" requires tracing formulas, the logic has outgrown the medium. This is where the well-known finance blow-ups come from, and they are almost always caused by an ordinary error in a very large sheet.

6. It has stopped being a calculation and started being a database. Thousands of rows, with each row a customer, job or transaction, and columns that record status. That is a database with no validation, no relationships and no audit trail.

7. It is not backed up in a way you have actually tested. Not "it is on the server". Tested. Someone has restored a previous version and confirmed it worked.

What it costs to leave it

The costs are the ones covered in what a legacy system actually costs you every year, with one addition that is specific to spreadsheets: they fail silently.

A proper system that goes wrong usually stops or throws an error. A spreadsheet that goes wrong keeps producing numbers, confidently, in the same format as before. A dragged formula that stops one row short will give you a total that looks entirely plausible for months.

That is the real risk. Not that the spreadsheet breaks, but that it does not, and you find out at year end.

What to do instead, in order of cost

The answer is almost never "buy a system". Work down this list and stop at the first step that removes the risk.

Free: make it single-purpose and single-owner. Split the sheet that does four jobs into four sheets. Name an owner for each. Most of the risk comes from files that grew sideways over years.

Free: lock the calculation, open the input. Protect the cells containing formulas. Leave the input cells editable. Ten minutes of work that prevents the majority of accidental breakages.

Cheap, under £500: add validation and a change log. Dropdown lists instead of free text, a rule that dates must be dates, and version history switched on. This removes most data entry errors without changing how anyone works.

£1,000 to £5,000: move the data, keep the interface. The data lives somewhere with validation and an audit trail. People carry on working in a familiar grid. This is the sweet spot for the majority of businesses at signal three or four, and the step most often skipped in favour of something far more expensive.

£5,000 to £25,000: build the process properly. Warranted when the spreadsheet is genuinely a database (signal six), when multiple people need to work at once, which is where a custom internal tool starts to earn its cost, or when something external and expensive depends on the output.

The one to fix first

If several of your spreadsheets are showing signals, start with the one that feeds something outside the business. Not the biggest, not the ugliest, not the one that annoys people most. The one where being wrong costs money or credibility with somebody who is not you.

Key Takeaways

  • Spreadsheets are excellent software. Most businesses should keep most of theirs, and building one first is the cheapest way to specify a system.
  • Watch for the seven signals. Multiple editors, "FINAL v3", a single person who can fix it, external outputs, untraceable numbers, database-shaped data, and untested backups.
  • The specific danger is silent failure. A broken spreadsheet keeps producing confident, plausible, wrong numbers.
  • Work up the cost ladder and stop as soon as the risk is gone. Splitting and protecting a sheet costs nothing and removes most of it.
  • Fix the one that feeds something outside the business first, regardless of size.

Frequently Asked Questions

Is moving to a cloud spreadsheet enough?

It fixes version conflicts and backups, which are two of the seven signals, and leaves the other five untouched. Validation, audit trail, traceable logic and key-person dependency are all still open. It is a genuine improvement and it is not a solution.

Our accountant is happy with our spreadsheets. Should I worry?

Your accountant is assessing whether the numbers reconcile, which is a different question from whether the process is safe to depend on. Both can be true: the figures are correct today, and the way they are produced carries a risk nobody has priced.

How do I persuade the person who built it that it needs to change?

Usually by not framing it as a criticism, because it rarely is one. The sheet has probably held the business together for years. The useful framing is continuity: what happens to this when you are on leave, and what would it take for someone else to run it for a fortnight. That conversation tends to go somewhere, where "we are replacing your spreadsheet" does not.


Not sure whether your spreadsheets are fine or fragile? Talk to Halo Technology Lab. Our strategy and scoping service includes a review of the ones your business actually depends on, and we will tell you which to leave alone.

Share this article

Enjoyed this? Get the next one by email

Practical AI playbooks, build logs and tool teardowns. One email a week, free, unsubscribe in one click.

See what’s in it first

Have a project in mind?

Let's discuss how we can help bring your ideas to life.

Get in Touch