TL;DR: A monthly IT check takes about 30 minutes and catches problems while they’re still cheap to fix. Work through six things: updates, backups, who has access, multi-factor authentication, devices, and subscriptions. Write down what you find instead of stopping to fix it. Handle the small items yourself and send the rest to your IT provider. Most breaches start in gaps this review would have caught.
Most business owners only look at their technology after something has already gone wrong. A file won’t open, a laptop won’t boot, or an invoice gets paid into a scammer’s account. A monthly IT check is the cheapest way to break that pattern, and it takes less time than your average staff meeting.
Almost none of these problems show up without warning. The backup that fails when you finally need it had been failing quietly for weeks. The account a scammer used belonged to someone who left last spring. The update that would have closed the hole had been sitting at “restart required” since February.
That’s the whole idea behind a monthly check. You’re not troubleshooting and you’re not fixing. You’re looking, on purpose, at the handful of things that fail silently. Thirty minutes on the calendar catches most of what would otherwise become a five-figure emergency.
Here’s what to look at, in what order, and what to do with what you find.
Why Is a Monthly IT Check Worth the Time?
Most successful attacks use a problem that was already known, with a fix that was already available. Nobody had installed it yet. A monthly review catches those gaps while they’re still an inconvenience instead of an incident.
The 2026 Verizon Data Breach Investigations Report found that 31% of breaches started with attackers exploiting unpatched software, which makes it the most common way in, ahead of stolen passwords. The same report found the median time to fully fix a known problem has climbed to 43 days.
Attackers move in hours. Forty-three days isn’t a race, it’s a head start you’re handing them. And for most small businesses, the delay isn’t a decision. It’s just that nobody looked.
What Should You Check Every Month?
Six areas cover most of the risk for a small business: software updates, backups, active user accounts, multi-factor authentication, connected devices, and software subscriptions. Each one takes about five minutes and needs no technical background beyond knowing your own business.
1. Updates
Check whether Windows updates are actually installing or just sitting at “restart required” week after week. Do the same for phones, browsers, and the software your team uses most, like your accounting or practice management system.
If people keep clicking “remind me later,” that’s the finding. It means your updates depend on employee willpower, which is not a security control. Automated patching is a core part of managed IT services for exactly this reason.
2. Backups
Open your backup tool and look at the last several runs. You want a list of recent successes, not a mix of warnings and errors nobody investigated.
Then ask the harder question: when did anyone last restore a file from it? If the answer is never, you don’t have a backup. You have a hope. Despite 92% of organizations saying they have backups, 31% fail to recover their data when ransomware hits. Tested restores are why our backup and recovery service checks the restore, not just the job.
3. Who has access
Pull up your user account list in Microsoft 365 or Google Workspace and read every name. Each one should be someone who still works for you.
Look for three things:
- People who left, sometimes months or years ago
- Contractors whose projects finished
- Shared logins like “office” or “admin” that several people use
Turn off anything you don’t need. Shared accounts are the ones that hurt during an investigation, because when something goes wrong you need to know which person did what.
4. Multi-factor authentication
Confirm MFA is switched on, and that it’s on for everyone rather than just the people who set it up first. Pay closest attention to administrator accounts and anyone who touches money or client data.
This is the highest-value five minutes in the whole check. Microsoft’s research shows MFA blocks more than 99.2% of account compromise attacks. Very few security controls come close to that, and this one is free with the license you already own.
While you’re in there, look for mailbox forwarding rules pointed at outside addresses. That’s a common sign someone already got in, and it pairs directly with email and spam protection.
5. Devices
Look at what’s connected to your systems. If there’s a laptop or phone you don’t recognize, find out whose it is before you do anything else.
Then check two basics: that company laptops are encrypted, and that any phone with company email on it has a passcode or fingerprint lock. A phone left in a Highlands restaurant shouldn’t be a data breach.
6. Subscriptions and licenses
Open your billing page and read what you’re paying for. Small businesses regularly pay for licenses belonging to people who left, or for two tools that do the same job.
This is also the fastest way to spot software somebody signed up for without telling anyone. Unapproved tools with your company data in them are a real risk, and they usually surface on an invoice before they surface anywhere else.
How Do You Turn This Into an Actual Routine?
Put it on the calendar for a fixed day, like the first Monday of the month, and give it to the same person every time. Write down what you checked and what you found. Consistency matters more than thoroughness here, because the value comes from comparing one month to the next.
Keeping notes is what turns a checklist into information. After three or four months you’ll see whether the same laptop, the same person, or the same application keeps showing up. A problem that returns every month isn’t being fixed, it’s being cleared.
One rule makes or breaks the whole thing: don’t stop to fix anything while you’re looking. Thirty minutes only works if you write down what you find and handle it afterward. The moment you start troubleshooting a printer, you’ve lost the hour and you’ll never finish the list.
What Should You Fix Yourself, and What Goes to Your Provider?
Handle the small, obvious items yourself: a laptop that needs restarting, a license to cancel, an account to switch off, a phone that needs a passcode. Send anything that repeats or resists to your IT provider, because a recurring failure usually means something bigger sits behind it.
The items worth escalating:
- Backups that keep failing or can’t complete a restore
- MFA that won’t turn on for a specific person or app
- A device on your network nobody can identify
- Updates that fail on the same machine every month
- Any sign-in from a country where you don’t do business
That last one isn’t a monthly-check item, it’s a today item. If you see it, call someone. Our cybersecurity consulting and training work often starts with a business owner who noticed exactly that and didn’t know what it meant.
What the Monthly Check Doesn’t Cover
A monthly review isn’t monitoring, and it shouldn’t be sold to you as one. A good IT provider runs tools that watch your systems all day and flag things no human would catch from a once-a-month glance: unusual logins, failing drives, malware behavior, security alerts at two in the morning.
The check covers the part those tools can’t know. Software doesn’t know who resigned last month, which subscription you approved, or whose laptop that is. You do. That’s the whole reason this stays on your calendar even after you hire help.
The two work together. Monitoring handles the technical side continuously, and your monthly half hour handles the business context. Neither one substitutes for the other, and neither one replaces security awareness training for your team.
Start With Next Month
Three things to take away. Backups that have never been restored are assumptions, not protection. Old accounts and unpatched software cause more breaches than sophisticated attacks do. And a problem that shows up on your list three months running needs a real fix, not another pass.
You don’t need a program or a policy to begin. Put 30 minutes on the calendar for the first business day of next month, work through the six areas, and write down what you find. Do it three times and you’ll know more about your own risk than most owners ever do.
If you’d rather have someone run it for you and act on what turns up, schedule an intro call with our team. We’ll tell you plainly what’s solid and what isn’t.
Frequently Asked Questions
How often should a small business check its IT?
Once a month is enough for this list. Backups deserve a quicker look more often if losing a day’s work would seriously hurt, since that’s the item most likely to fail without telling anyone. Anything involving active security alerts needs continuous monitoring rather than a monthly glance.
Who should do the monthly IT check?
You, or whoever runs the administrative side of the business. Most of the list needs no technical skill. It needs someone who knows who works there, what the company pays for, and whose laptop is whose. That knowledge is the part an IT provider can’t supply.
Isn’t this my IT provider’s job?
Your provider handles the monitoring, the patching, and the fixing. The monthly check covers the part that depends on knowing your business, like who left last month or which subscription nobody approved. Many providers will also send you a monthly summary that covers several of these items.
If I only have ten minutes, what matters most?
Backups and updates. Without a working, tested backup you can lose everything you’ve stored, and unpatched software is now the most common way attackers get in. If you have a spare minute after that, confirm multi-factor authentication is on for every account.
Does this apply if everything we use is in the cloud?
Yes. Cloud tools still run on devices that need updates, still need MFA switched on, and still need an access list that matches who actually works for you. Cloud platforms also don’t back up your data the way most owners assume they do, so a separate backup still matters.
Not Sure Where to Find Any of This?
Most business owners we talk to in Louisville are handling three or four of these well and have never looked at the rest. That’s normal, and it’s fixable in an afternoon. Reach out for a straightforward conversation about what your business needs, with no jargon and no pressure.
