Practical IT guidance for apprentices and small teams
One of the most fundamental skills you'll develop as an IT apprentice is learning how to evaluate computer equipment — not just whether a machine works, but whether it's the right tool for the job at the right price. Whether you're setting up a workstation for a client on a tight budget, recommending an upgrade path for an aging office fleet, or helping someone get the most value out of their old Apple gear, your ability to make smart equipment decisions will set you apart.
This chapter covers two of the most common equipment ecosystems you'll encounter in the field: Apple Mac hardware and budget PC desktops. We'll walk through what makes each unique, how to stretch a dollar without sacrificing performance, and how to navigate the secondhand market like a pro. By the end of this chapter, you'll have a practical framework for making confident equipment recommendations — even when the budget is tight.
Apple's Mac lineup is a staple in creative industries, education, and increasingly in enterprise environments. As an IT professional, you will encounter Macs — so understanding their quirks before you're standing in front of one is essential.
The most important thing to understand about modern Macs is that Apple has moved away from user-upgradeable hardware. Unlike traditional PCs, where you can open the case and swap out components, most Mac models produced in recent years have their storage and memory soldered directly onto the motherboard. This means:
This is a critical point to communicate to clients and end users. If someone is buying a new Mac, they need to think carefully about their needs upfront, because upgrading later simply isn't an option.
Most consumer Mac models come in two standard RAM configurations:
Pro Tip for Apprentices: When a client asks "which one should I get?", a good rule of thumb is: if they have to ask, they probably want the 16GB. It's always better to have headroom you don't use than to hit a wall you can't break through.
When budget is a concern but a client is committed to the Mac ecosystem, the Mac Mini is almost always your first recommendation. Here's why it's such a reliable choice:
The key takeaway here is that shopping around pays off. A Mac Mini from 2014 might be more than sufficient for a client who just needs to browse the web, manage spreadsheets, and send emails — and it might cost less than $150 on the secondhand market.
In a world obsessed with sleek laptops and tablets, the humble desktop PC is often overlooked — but in IT, we know better. Budget desktops are one of the most cost-effective and flexible tools in your arsenal, and here's why:
One of the most satisfying skills in IT is taking an aging machine and transforming it into something genuinely powerful. This is where understanding component upgrades becomes incredibly valuable.
Consider this real-world scenario: You find an old desktop on clearance for $60. It runs slowly, the storage is nearly full, and it struggles with modern software. On the surface, it looks like junk. But with a few targeted upgrades, that same machine could become a powerhouse:
The Big Picture: This is the kind of creative problem-solving that makes a great IT professional. You're not just fixing computers — you're maximizing value and finding solutions that fit the client's actual needs and budget.
Whether you're helping a client sell their old MacBook before upgrading, or you're sourcing used equipment for a deployment, knowing the market value of Apple gear is an essential skill. Apple products hold their value better than almost any other consumer electronics brand, which cuts both ways — they're more expensive to buy used, but also more rewarding to sell.
Your go-to tool for estimating the value of used Apple equipment is:
🔗 mac2sell.net — Enter the model and specs of any Apple device and get an instant market value estimate. Use this before buying or selling to make sure you're getting a fair deal.
Platform | Notes |
Specializes exclusively in used and refurbished Apple products. Reliable and well-regarded in the Apple community. | |
BackMarket | Broad refurbished electronics marketplace with quality tiers and buyer protections. |
eBay | Wide selection and competitive pricing, but requires more due diligence. Check seller ratings and return policies carefully. |
Discount Electronics | Texas-based independent shop with a solid reputation for honest pricing on refurbished gear. |
When it's time to move old Apple gear, you have several options depending on how quickly you need the money:
Selling Strategy Tip: If a client has time and wants maximum value, listing on eBay or BackMarket as a seller will typically yield more money than an instant buyback service. If they need cash quickly or don't want the hassle of managing a listing, BuyBackWorld or Gazelle are the right call. Matching the solution to the client's actual situation — not just the "best" option in theory — is a hallmark of great IT support.
As you work through this chapter, you'll encounter several technical terms that are important to understand. Here's a clear breakdown of each:
RAM (Random Access Memory)
The short-term memory of a computer. RAM temporarily holds the data that the processor is actively using. More RAM means the computer can handle more tasks at once without slowing down. Unlike storage, RAM is volatile — its contents are erased when the computer is turned off.
SSD (Solid State Drive)
A type of storage device that uses flash memory chips instead of spinning magnetic disks. SSDs are significantly faster, quieter, more durable, and more energy-efficient than traditional HDDs (Hard Disk Drives). Upgrading from an HDD to an SSD is one of the most impactful performance improvements you can make to an older machine.
HDD (Hard Disk Drive)
The traditional form of computer storage, which uses spinning magnetic platters to read and write data. HDDs are slower than SSDs but are often cheaper per gigabyte, making them useful for bulk storage.
GPU (Graphics Processing Unit)
A specialized processor originally designed to handle the complex calculations required for rendering images and video. Modern GPUs are also used for AI and machine learning workloads, scientific computing, and cryptocurrency mining, because they can perform many calculations simultaneously.
Motherboard
The main circuit board inside a computer. It connects and allows communication between all other components — the CPU, RAM, storage, GPU, and more. When components are described as "soldered to the motherboard," it means they are permanently attached and cannot be removed or replaced.
Soldered
In the context of computer hardware, soldering refers to permanently attaching a component (like RAM or storage) directly to the motherboard using molten metal. Soldered components cannot be upgraded or replaced without specialized equipment, which is why this is a significant limitation in modern Macs.
Refurbished
A device that has been previously used, returned, or repaired, and then inspected, cleaned, and restored to working condition before being resold. Reputable refurbishers test components and often provide warranties. Refurbished equipment is a cornerstone of budget IT procurement.
RTX 3060
A mid-range consumer graphics card manufactured by NVIDIA. It represents a strong balance of performance and price, and is capable of handling demanding tasks including gaming, video editing, and running local AI models.
AI Server (Local)
A computer configured to run artificial intelligence models and processes locally — meaning on the machine itself — rather than sending data to a cloud service. Running a local AI server gives users privacy, eliminates subscription costs, and allows for customization. A capable GPU is typically required.
Buyback Service
A company or platform that purchases used electronics directly from consumers at a set price. The process is fast and simple, but typically yields less money than selling directly to another buyer. Examples include BuyBackWorld and Gazelle.
Mac Mini
A compact, affordable desktop computer made by Apple. It does not include a monitor, keyboard, or mouse (it is "headless"), which keeps the price lower. It has been in production since 2006, making it one of the most accessible entry points into the Mac ecosystem.
Next Chapter: Peripherals and Accessories — Building a Complete Workstation on Any Budget
In August 2025, Google announced↗ that as of September 2026, it will no longer be possible to develop apps for the Android platform without first registering centrally with Google. This registration will involve:
The promise of Android - and a marketing advantage it has used to distinguish itself against the iPhone - has always been that it is “open”. But Google clearly feels that they have enough of a lock on the Android ecosystem, along with sufficient regulatory capture, that they can now jettison this principle with prejudice and impunity.
If you are an app developer, do not sign up for the early access program, perform identity verification, or accept an invitation to the Android Developer Console. Respond (politely) to any invitation with a list of your concerns and objections.
Discourage fellow app developers and organizations from signing up to the program. Use community forums, social media, and blog posts to spread the message. Include the FreeDroidWarn library↗in your code to inform your app users. If you manage a website, consider adding the countdown banner to the top of your page.
Add the countdown banner to your sitewith a single<script>tag — no dependencies, 20 built-in localizations, fully customizable.
Regulators worldwide are genuinely concerned about monopolies and the centralization of power in the tech sector, and want to hear directly from individuals who are affected and concerned. When contacting regulators directly, you should bepoliteandspecificabout the harm you believe these policies will cause, both to consumers and to competition.
Complaints are especially impactful when they are authored by a citizen of that country or region, and when the language of the email is written in one of the official languages of the region's governing body. Request awritten acknowledgementof the complaint, and consider forwarding any responses you receive tovictory@keepandroidopen.orgso that we might highlight and reference them.
When most people think of computers, they think of Windows or maybe macOS. But there is a third operating system quietly running beneath the surface of much of the modern world — and as an IT professional, you need to know it exists. That operating system is Linux.
From the servers that host your favorite websites, to the phone in your pocket, to the tools used by cybersecurity professionals to test and defend networks — Linux is everywhere. You may never see its desktop wallpaper, but you will absolutely encounter it in your IT career. This chapter is not going to make you a Linux expert overnight. That is not the goal. The goal is simple: by the end of this chapter, you should know what Linux is, where it came from, why businesses and tech professionals rely on it, and where you are likely to run into it in the real world. Think of this as your first introduction to a very important colleague you will be working alongside for the rest of your career.
To understand Linux, we need to take a quick trip back to the 1970s. At that time, computers were enormous, expensive machines called mainframes — room-sized systems that universities, governments, and large corporations used for serious computing work. These machines ran an operating system called Unix, which was powerful, stable, and designed to handle multiple users and tasks at the same time.
Unix was groundbreaking, but it was expensive and tightly controlled by the companies that owned it. Fast forward to 1991, when a Finnish computer science student named Linus Torvalds decided to build his own Unix-inspired operating system from scratch — and then, crucially, give it away for free. He called it Linux.
What made Linux revolutionary was not just that it was free. It was open-source, meaning the underlying code — the actual instructions that make the operating system work — was made publicly available for anyone to read, modify, and improve. Developers all over the world began contributing to it, and over the decades, Linux grew from a hobbyist project into one of the most powerful and widely used operating systems on the planet.
Think of it this way: If Windows is a finished product sold in a box, Linux is more like a recipe that anyone can read, cook from, and improve upon. The result is an operating system that is constantly being refined by thousands of experts worldwide.
You might be wondering — if Windows works fine, why bother with Linux at all? It is a fair question, and the answer comes down to a few key advantages that make Linux the preferred choice in professional and high-tech environments.
In short, Linux is the backbone of the internet and modern enterprise computing. Knowing it exists — and having a basic familiarity with it — immediately sets you apart as a more well-rounded IT professional.
Linux does not always announce itself. It often runs quietly in the background, doing its job without a flashy interface. Here are some of the most common places you will encounter it, both in everyday life and in professional IT settings.
You do not need to master these topics right now, but as an IT apprentice, you should be aware that they exist. These are areas where Linux knowledge becomes especially powerful, and they represent natural next steps as your skills grow.
A Virtual Machine is essentially a computer running inside another computer. Using software, you can create a simulated environment that behaves exactly like a separate physical machine — complete with its own operating system, files, and settings. Linux is very commonly used as the operating system inside these virtual machines, especially in enterprise and development environments. VMs are great for testing software, learning new systems, or running multiple operating systems on one piece of hardware without conflict.
Docker is a technology that takes the concept of virtual machines a step further by creating lightweight, portable packages called containers. Each container holds an application and everything it needs to run, isolated from the rest of the system. Docker runs on Linux and is one of the most important technologies in modern software development and IT operations. If you find yourself moving into more advanced IT roles — particularly in DevOps, cloud engineering, or systems administration — Docker will be one of the first major tools you encounter. For now, just know it exists and that it is built on Linux principles.
Kali Linux is a specialized version, or distribution, of Linux that is purpose-built for cybersecurity professionals. It comes pre-loaded with hundreds of tools used for penetration testing — the practice of legally and ethically attempting to hack into systems in order to find and fix vulnerabilities before real attackers can exploit them. When you see cybersecurity professionals in documentaries, news segments, or training videos sitting in front of a dark terminal screen running complex commands, there is a very good chance they are using Kali Linux. It is the industry-standard operating system for ethical hacking and security research.
Important Note: Kali Linux is a professional tool designed for authorized security testing. It is not something to experiment with carelessly. As you grow in your IT career and potentially move toward cybersecurity, Kali Linux will become a topic worth studying in depth.
The following terms were introduced in this chapter. Make sure you are comfortable explaining each one in your own words.
Term | Definition |
Linux | A free, open-source operating system originally created by Linus Torvalds in 1991, inspired by the older Unix system. It is widely used in servers, mobile devices, and professional IT environments. |
Open-Source | Software whose underlying source code is made freely available to the public. Anyone can read it, modify it, and distribute their own version. |
Unix | A powerful operating system developed in the 1970s that served as the inspiration for Linux. It was designed for multi-user, multi-tasking environments on mainframe computers. |
Mainframe | A large, powerful computer used primarily in the 1960s–1980s by governments, universities, and corporations for heavy-duty computing tasks. |
Kernel | The core component of an operating system. It manages communication between software and hardware. When we say Android is "built on Linux," we mean it uses the Linux kernel as its foundation. |
Distribution (Distro) | A version of Linux packaged with specific tools, interfaces, and software for a particular purpose or audience. Examples include Ubuntu, Kali Linux, and ChromeOS. |
Android | Google's mobile operating system, used on the majority of smartphones worldwide. It is built on top of the Linux kernel. |
ChromeOS | Google's operating system for Chromebook laptops, which is based on Linux. |
Bootable USB Drive | A USB flash drive configured to run an operating system directly, without installing anything on the host computer. Commonly used by IT technicians for troubleshooting and system recovery. |
Virtual Machine (VM) | A software-based simulation of a physical computer. It runs its own operating system and applications inside a host machine, completely isolated from the host environment. |
Docker | A platform that uses Linux-based technology to create and run containers — lightweight, portable packages that include an application and all of its dependencies. Widely used in modern software development and IT operations. |
Container | A lightweight, self-contained package that holds an application and everything it needs to run, isolated from the rest of the system. Think of it as a very efficient, stripped-down virtual machine. |
Kali Linux | A specialized Linux distribution designed for cybersecurity professionals. It comes pre-installed with tools used for penetration testing and ethical hacking. |
Penetration Testing (Pen Testing) | The authorized, ethical practice of attempting to hack into a system or network in order to identify security vulnerabilities before malicious attackers can find them. |
DevOps | A professional discipline that combines software development and IT operations, focused on automating and streamlining the process of building, testing, and deploying software. Linux and Docker are core tools in DevOps work. |
Server | A computer or system that provides resources, data, or services to other computers over a network. Most servers in business environments run Linux. |
End of Chapter 4 — Up Next: Navigating the Linux Command Line
When most people hear the word "security" in an IT context, their minds immediately jump to images of hooded hackers furiously typing code in a dark room. Hollywood has done a fantastic job of making cybersecurity look like a niche, almost mystical skill reserved for a select few geniuses. The reality, however, is far more grounded — and far more interesting.
Security, at its core, is not just about computers. It is about protecting everything — people, information, systems, and processes — from threats that come in all shapes and sizes. The "cyber" part is simply the modern battlefield where many of those threats now live. As an IT apprentice, understanding security from this broader perspective will set you apart from the very beginning of your career. You will not just be someone who knows how to run a scan or patch a vulnerability. You will be someone who thinks like a protector.
This chapter will introduce you to the foundational mindset, concepts, and vocabulary you need to begin your journey into IT security. We will explore where security thinking comes from, how computers communicate with each other, and why the skills you are building now are the same ones used by professionals guarding some of the most critical systems in the world.
One of the biggest reasons newcomers feel intimidated by cybersecurity is the assumption that you need to be an expert hacker before you can even get started. This misconception is also one of the biggest reasons many talented people never enter the field at all. Let's clear this up right now.
Cybersecurity is a discipline that evolved from two very traditional, very human industries: the military and the physical security industry. Long before computers existed, people were developing strategies to protect valuable assets, guard sensitive information, and anticipate the moves of adversaries. The digital world simply gave those same professionals a new environment to work in.
Think about it this way: if your company needed to transport one million dollars in cash from one bank to another, what would that operation look like?
Now replace "cash" with "sensitive customer data" or "a company's financial records," and you have described a cybersecurity operation. The tools are different, but the thinking is identical. Security professionals ask the same questions their predecessors in the physical security world always have: What are we protecting? Who might want it? How could they get to it? How do we stop them?
In professional security environments, teams are often divided into two roles that mirror the classic dynamic of attacker and defender:
Here is the critical thing to understand about this dynamic: the villain, or attacker, will stop at nothing. A real-world threat actor is not playing by rules. They are motivated — whether by money, ideology, or mischief — and they are persistent. This is why the Blue Team must always be vigilant, always learning, and always improving. You cannot defend what you do not understand, and you cannot understand a threat you have never studied.
This is also why many security professionals spend time learning both sides. Understanding how an attacker thinks makes you a dramatically better defender.
Interestingly, the security field has also been heavily shaped by gaming culture. Many of the brightest minds in cybersecurity got their start not in a classroom, but in competitive security challenges called Capture the Flag (CTF) competitions.
In a CTF, participants are given a series of technical challenges — puzzles, vulnerabilities to exploit, codes to crack — and the goal is to find hidden "flags" (usually a specific string of text) that prove you have successfully completed the challenge. The name is borrowed directly from the classic playground game: there are real flags to find and protect, and if the wrong person captures yours, it is game over.
CTF competitions are a fantastic way to build real skills in a safe, legal environment, and many employers in the security field actively look for CTF experience on a résumé. If you enjoy problem-solving and have a competitive streak, this is a world worth exploring.
The military has always operated on a principle that translates perfectly into IT security: be ready for any threat, and always be watching. Military planners do not wait for an enemy to attack before they start thinking about defense. They conduct threat assessments, monitor their perimeter constantly, and run drills to ensure their team is prepared for scenarios they hope will never happen.
IT security professionals operate the same way. A strong security posture is not reactive — it is proactive. This means:
Here is something that surprises many new IT apprentices: a significant portion of real-world security work has nothing to do with software or code. Physical security is the foundation upon which all digital security is built, and it is often the most overlooked layer.
Consider this scenario, famously illustrated by the webcomic xkcd: you could build the most sophisticated, unbreakable encryption system in the world to protect a database of passwords. But if an attacker can simply walk into your server room, unplug the hard drive, and walk out — your encryption means nothing.
Physical security in IT includes:
The lesson here is powerful and worth repeating: security is not a single tool or a single layer. It is a complete system, and every layer matters.
Before you can protect a system, you need to understand how that system works. One of the most fundamental concepts in networking and IT security is the server/client relationship. Let's break it down using an analogy that everyone can relate to: a restaurant.
Imagine you walk into a restaurant and sit down at a table. You are the customer — you have a need (you are hungry), and you are going to make a request. A waiter comes to your table, takes your order, goes back to the kitchen, and returns with exactly what you asked for. The kitchen prepares the food; the waiter delivers it.
In this analogy:
This is exactly how computers communicate across a network.
Here is something important to understand: any computer can be a server, a client, or both at the same time. The terms describe roles, not specific types of hardware. Your personal laptop is acting as a client right now if you are browsing the internet. But if you installed server software on that same laptop and started hosting a website from it, it would also be acting as a server.
Let's look at some real-world examples:
Understanding the server/client model is essential for security because it defines the attack surface. Every point of communication between a client and a server is a potential vulnerability. Security professionals need to ask:
When you understand how systems communicate, you begin to see where they can be exploited — and more importantly, how to protect them.
While this chapter focuses primarily on security concepts, it is worth briefly touching on two hardware terms that come up frequently in IT environments, particularly when discussing the kinds of powerful systems that security professionals often work with or protect.
Understanding the hardware that underlies the systems you are securing is part of being a well-rounded IT professional. Security is not just about software — it is about understanding the complete picture.
Here are the key terms introduced in this chapter, defined clearly for your reference:
Term | Definition |
Cybersecurity | The practice of protecting computers, networks, programs, and data from digital attacks, damage, or unauthorized access. |
Red Team | A group of security professionals who simulate real-world attacks on an organization's systems to identify vulnerabilities. Also known as ethical hackers or penetration testers. |
Blue Team | A group of security professionals responsible for defending an organization's systems, monitoring for threats, and responding to incidents. |
CTF (Capture the Flag) | A competitive cybersecurity challenge where participants solve security puzzles to find hidden "flags," building real-world skills in a safe, legal environment. |
Server | A computer or program that provides resources, data, or services to other computers (clients) upon request. |
Client | A computer or program that requests resources or services from a server. |
Physical Security | The protection of hardware, personnel, and physical spaces from unauthorized access, theft, or damage. |
Social Engineering | A manipulation technique used by attackers to trick people into revealing confidential information or granting unauthorized access, rather than exploiting technical vulnerabilities. |
Least Privilege | A security principle stating that every user and system should have access to only the minimum resources necessary to perform their function. |
Attack Surface | The total number of points in a system where an unauthorized user could attempt to enter or extract data. |
Denial of Service (DoS) | An attack that attempts to overwhelm a server with requests, making it unavailable to legitimate users. |
RAM (Random Access Memory) | A computer's short-term, active working memory that holds data currently being used by the processor. |
VRAM (Virtual Memory) | An extension of RAM that uses hard drive space as overflow memory, used in high-demand computing environments. |
Penetration Testing | An authorized, simulated cyberattack on a system performed to evaluate its security and identify weaknesses before real attackers can exploit them. |
Threat Actor | Any individual or group that poses a threat to the security of a system or organization. |
In the next chapter, we will begin exploring the specific tools and techniques used to monitor, test, and defend IT systems — building directly on the foundational mindset you have developed here.
Healthcare is a regulated industry with strict guidelines and procedures. This document explains the basics of the healthcare industry, the mindset of healthcare professionals, and
Data security in healthcare is essential for protecting patients' sensitive information and avoiding costly penalties due to data breaches.
A Business Associate (BA) is a business that works with a healthcare provider and their protected health information (PHI). The BA is equally liable for the security of the PHI as the healthcare provider.
A Business Associate (BA) is a business that works with a healthcare provider and their protected health information (PHI). The BA is equally liable for the security of the PHI as the healthcare provider.
A Business Associate Agreement (BAA) is a contract between a healthcare provider and any business that handles their PHI.
The Health Insurance Portability and Accountability Act (HIPAA) is a US regulation developed to protect the privacy and security of certain health information. Matomo Analytics is used by many companies in the healthcare industry, building medical and health-related applications. Matomo can be configured in a way that it is compliant with HIPAA.
When you are a Covered Entity or a Business Associate as defined in HIPAA, and you handle any Protected Health Information (PHI) using Matomo, you must comply with HIPAA rules that govern privacy, security, breach notification, and enforcement, unless that particular processing is exempt.
Not all personal information or data is PHI, which is defined as any health-related data that can be linked to the individual via identifiers such as name, geolocation data, elements of birth date, contact details, device ID, account number, IP address, medical record number, or web URL.
In the context of Matomo, PHI may be, for example, User ID, custom dimensions possibly storing health data, or URLs, page titles, or session recordings that may record personal data.
To comply with HIPAA, you must complete at least the following steps:
If you have any question or if you need help with your Matomo On-Premise setup contact us, we’re always happy to help.
These are the workflows we use for our business processes.
This workflow is designed for professionals and teams who need to monitor multiple RSS feeds, filter the latest content, and distribute actionable updates as a Trello comment. Ideal for content managers, marketers, and team leads managing news or content pipelines.
Manually monitoring RSS feeds and keeping track of the latest content can be time-consuming. This workflow automates the aggregation, filtering, and distribution of news, ensuring that only relevant and timely updates are shared with your team or audience.
This workflow ensures your team stays informed with minimal effort and delivers content updates in an organized and professional manner.
N8N Details
Enable the IT team to help customers remove their email addresses from public spam lists.
For a full tutorial on using the OffList tool, go to: .
Big Tech companies are spying on every conversation you have with your AI. ChatGPT, Claude, Gemini, all of these companies have the ability to see your entire chat history. They can use that information not only to "train" their models, but to take competitive actions against your business, from stealing your business idea to even reporting you to the police if they think you've said something they don't like.
That's why we have our own private AI chat servers. Instead of going through ChatGPT, we prefer you to use our AI models. That way all company information stays private and doesn't get exposed to Big Tech companies.
@todo - add AI info here.
We recommend downloading model files from Hugging Face since it provides several features to verify that the download is genuine and safe.
Also see:
Go to https://privacytests.org/ to see where different browsers rank for privacy. These rankings change over time, so browse through this page and notifying team members if any info in this document seems out of date.
Tip: use AI to review the rankings and break down what info you should be paying attention to. Ask it to teach you how to review for yourself in the future.
Before downloading a new AI model, always make sure it is authentic and free from viruses.
To check the authenticity and safety of the model, look for:
sha256sum filenameshasum -a 256 filenameGet-FileHash filename -Algorithm SHA256CertUtil -hashfile filename SHA256A downloaded model is generally safe if it satisfies all the above checks.