NEW

The 30-Minute IT Check Every Small Business Should Do Once a Month

Summary: Most IT problems don't appear out of nowhere. Backups quietly stop running, updates sit unfinished for weeks, and old staff accounts stay switched on for months. A short check once a month catches these while they're still cheap to fix. This post covers the...

How to Keep Your Business Running When Microsoft 365 Goes Down

Summary: The tools that run your business, like Microsoft 365, your accounting app, or your booking system, are reliable most of the time, but they do go down. When one does, work can stop for hours, and you often can't do anything but wait for the provider to fix it....

OneDrive or SharePoint? Where Your Business Files Should Live

Summary: If your business uses Microsoft 365, you have both OneDrive and SharePoint, and files usually end up scattered across them with no clear rule. OneDrive is for your own work, and SharePoint is for files the team shares. Getting this right makes files easier to...

Is Your Business Website a Security Risk?

Summary: Most small-business websites run on WordPress, and the biggest risk is usually old plugins that nobody has updated. Attackers scan the web for these known weak spots and use the sites they find to spread malware, post spam, or steal what visitors type into...

Why You Should Scroll Past the First Result on Google

Summary: Scammers buy ads on Google and other search engines using the names of trusted brands and software, so their fake site shows up at the very top, above the real one. Click it and you can land on a fake page that steals your login or installs malware. You can...

How to Spot a Scam Email Now That They Look Real

Summary: Scammers now use AI to write their phishing emails, so the spelling and grammar mistakes that used to give them away are gone. The UK's National Cyber Security Centre and the FBI both warn that AI makes these messages cleaner, more personal, and harder to...

What to Do in Case of a Cyberattack (Step by Step)

Article Summary: If your business is hit by a cyberattack, the first hour matters. Disconnect the affected devices from the network instead of powering them off, call your IT provider by phone, and leave the evidence in place. If money was wired to a scammer, call...

What Are Passkeys, and Should Your Business Use Them?

Article Summary: A passkey lets you sign in to an app or website using the same fingerprint, face, or PIN you use to unlock your phone or laptop, with no password to type. It's built on a security standard called FIDO that can't be phished, because the passkey only...

Still on Windows 10? Here’s Why You’re Putting Your Business at Risk

Article Summary: Windows 10 reached the end of Microsoft support on October 14, 2025, which means it no longer gets security updates. The computers still work, but any new flaw found in Windows 10 will never be fixed, which makes them easier to attack and can cause...

Who Can See What Your AI Note-Taker Records?

Article Summary: AI note-takers join your meetings, transcribe everything said, and save the recording and summary to the vendor's servers. Who can see that recording depends on the tool. Some keep your data inside your own Microsoft or Google environment and never...

Summary: Most IT problems don’t appear out of nowhere. Backups quietly stop running, updates sit unfinished for weeks, and old staff accounts stay switched on for months. A short check once a month catches these while they’re still cheap to fix. This post covers the six things to look at.

Most owners only look at their IT when something has already gone wrong. A file won’t open, a laptop won’t start, or an invoice gets paid into a scammer’s account. Fixing it at that point costs more than preventing it would have.

Almost none of it happens without warning. The backup that fails when you finally need it had been failing for weeks. The account a scammer used belonged to someone who left last year. Thirty minutes a month is usually enough to catch that kind of thing.

Why a monthly look is worth the time

Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches started with attackers exploiting software that hadn’t been patched. That makes unpatched software the most common way in, ahead of stolen passwords. The same report found the median time to fully fix a known problem has risen to 43 days.

Most attacks use a problem that was already known, with a fix already available. Nobody had installed it yet.

The check

1. Updates

Check whether Windows updates are installing on your computers, or sitting at “restart required” week after week. Do the same for phones and for the software you use most, like your browser and your accounting app. If people keep clicking “remind me later,” that’s something to fix.

2. Backups

Open your backup tool and look at the last few runs. You want recent successful backups, not a list of errors. Then check when anyone last restored a file from it. If it’s never been tested, you don’t know whether it works.

3. Who has access

Pull up the list of user accounts in Microsoft 365 or Google Workspace and read through it. Every name should be someone who still works for you. Look for people who left, contractors who finished months ago, and shared logins like “office” or “admin” that several people use. Switch off anything you don’t need.

4. Multi-factor authentication

Check that MFA is switched on, and that it’s on for everyone, not just the people who set it up first. Pay closest attention to admin accounts and anyone who handles money. Microsoft’s research shows MFA blocks more than 99.2% of account compromise attacks.

5. Devices

Look at what’s connected to your systems. If there’s a laptop or phone you don’t recognize, find out whose it is. While you’re there, check that laptops are encrypted and that any phone with company email on it has a passcode or fingerprint lock.

6. Subscriptions and licenses

Open your billing page and read what you’re paying for. Businesses regularly pay for licenses belonging to people who left, or for two tools that do the same job. It’s also how you find software somebody signed up for without telling anyone.

Make it a routine

Put it in the calendar on a fixed day, like the first Monday of the month, and give it to the same person each time. That’s you or whoever handles the admin side.

Keep a running note of what you checked and what you found. After a few months you’ll see whether the same problem keeps coming back. If it does, it needs fixing properly instead of clearing each time.

Thirty minutes only works if you don’t stop to fix things along the way. Write down what you find and deal with it afterward.

Who fixes what

Most of it is small, like a laptop that needs restarting, a license to cancel, or an account to switch off. Handle those yourself.

Send the rest to your IT provider: backups that keep failing, MFA that won’t turn on for someone, a device nobody recognizes, or updates that fail on the same machine every month. Those usually mean there’s a bigger problem behind them.

What this check doesn’t do

It isn’t monitoring. A good IT provider has tools watching your systems all day and flagging things you’d never spot from a monthly glance.

The check covers what those tools can’t know. You know who left, which subscriptions you approved, and whose laptop is whose.

Frequently asked questions

How often should a small business check its IT?

Once a month is enough for this list. Backups are worth a quick look more often if losing a day’s work would seriously hurt, since that’s the item most likely to fail quietly.

Who should do it?

You or whoever runs the admin side of the business. Most of the list needs no technical skill, just someone who knows who works there and what the business pays for.

What if I don’t know where to find any of this?

Ask your IT provider to walk you through it once and write down where each thing lives. Many will also send you a monthly summary covering most of it.

Isn’t this my IT provider’s job?

They handle the monitoring, the patching, and the fixing. The check is the part that depends on knowing your business, like who left last month or which subscription nobody approved.

If I only have ten minutes, what matters most?

Backups and updates. Without working backups you can lose everything you’ve stored, and unpatched software is now the most common way attackers get in.

Does this apply if everything we use is in the cloud?

Yes. Cloud tools still need updated devices, working backups, MFA switched on, and access lists that match who actually works for you.

Sources and further reading

If you’d like a hand setting this up, your IT provider can show you where each of these lives in your systems and take the fixing off your plate. And if you don’t have an IT provider, feel free to reach out to us and we’ll help you sort it.

—

Featured Image Credit

This Article has been Republished with Permission from The Technology Press.