Most owners only look at their IT once something’s already gone wrong — a laptop won’t boot, a file’s missing, or an invoice gets paid into an account that isn’t your vendor’s. By then, fixing it costs a lot more than catching it early would have.
That’s the part worth sitting with: almost none of it happens out of nowhere. The backup that failed right when you needed it had been quietly failing for weeks. The account a scammer used to get in belonged to a contractor who wrapped up work six months earlier. Thirty minutes a month is usually enough to catch that before it turns into your worst week of the quarter.
Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches started with attackers exploiting software that simply hadn’t been patched — more common than stolen credentials. The same report clocks the median time to fully remediate a known flaw at 43 days. Translation: most attacks don’t rely on some novel technique. They use a hole that was already known, with a fix already sitting there. Nobody had gotten around to installing it.
We see it the same way across our New York clients, whether it’s a professional services firm in Midtown or a distribution business out on Long Island — it’s rarely the exotic attack that causes damage. It’s the update that’s been sitting at “restart required” since last month.
1. Updates. Are Windows updates actually completing, or parked at “restart required” indefinitely? Same question for phones, and for the software your team lives in every day — browser, accounting platform. If people keep hitting “remind me later,” that’s a habit worth breaking.
2. Backups. Pull up your backup tool and look at the last several runs. You want recent, successful backups — not a list of errors nobody looked at. Then check when someone last actually restored a file from it. An untested backup is a hope, not a plan.
3. Who has access. Go through the user list in Microsoft 365 line by line. Every name should be someone currently on staff. Watch for former employees, contractors whose project ended months back, and shared logins like “frontdesk” that half the office knows. Turn off anything that isn’t needed anymore.
4. Multi-factor authentication. Confirm MFA is switched on for everyone, not just whoever set it up first. Admin accounts and anyone with access to money are the priority. Microsoft’s own data shows MFA stops more than 99% of account-compromise attempts — one of the cheapest, highest-return items on this whole list.
5. Devices. Take a look at what’s actually connected. A laptop or phone you don’t recognize is worth a quick call to figure out whose it is. While you’re in there, confirm laptops are encrypted and any phone with company email carries a passcode or biometric lock.
6. Subscriptions and licenses. Open the billing page and read what you’re actually paying for. It’s common to find licenses tied to someone who left two jobs ago, or two tools doing the exact same job. It’s also how you catch the software someone signed up for on a company card without telling anyone — a real problem if that tool’s handling customer data nobody reviewed.
Set a fixed day — the first Monday of the month works well for a lot of our clients — and assign it to the same person every time. Keep a short running log of what got checked and what turned up. A few months in, patterns show up on their own, and a recurring issue is a sign it needs a real fix instead of a monthly workaround.
One rule keeps this honest: don’t stop to fix things mid-check. Note it and circle back after, or your 30 minutes becomes a lost afternoon.
It isn’t monitoring. Real managed IT — the kind built around an actual business continuity plan — has tools watching your environment around the clock, catching problems long before a once-a-month glance ever would. This checklist covers what those tools can’t know on their own — who actually left the company, which subscription got approved, whose device is whose.
Anything that turns up here — backups that keep failing, MFA that won’t stick for someone, a device you don’t recognize — is the point to loop in your IT partner rather than chase it down solo. Getting these basics tight is worth pairing with getting your team trained to catch the rest — the things a monthly checklist alone can’t.
How often should a small business run this check?
Once a month handles this list. Backups deserve a quicker look more often if losing a day’s work would genuinely hurt — that’s usually the item most prone to failing silently.
Who should be doing this?
You, or whoever runs the admin side day to day. Most of it needs no technical background, just someone who knows who’s actually on the team and what the business pays for.
What if I don’t know where any of this lives?
Ask your IT provider to walk through it with you once and note down where everything is. Many, ours included, will send a monthly summary covering most of it automatically.
Doesn’t my IT provider already handle this?
They handle monitoring, patching, and fixing. This check covers what depends on knowing your own business — who left last month, which subscription nobody signed off on.
If I only have ten minutes, what matters most?
Backups and updates. A working backup is what stands between you and losing everything stored, and unpatched software remains the single most common way attackers get in the door.
Prepared by the EB Solution team — managed IT services for small and mid-sized businesses across the New York area. Want us to run this check for you every month instead? Get in touch with our team and we’ll take it off your plate.