2 September 2026
The 30-Minute IT Check Every Small Business Should Do Once a Month
By Jack Wetson-Catt
Photo by Agence Olloweb on Unsplash
Nearly half of UK businesses, 43%, told the government's 2025/2026 Cyber Security Breaches Survey they'd identified a cyber security breach or attack in the past year. That's not a reason to panic. It's a reason to look, because most of what leads to a breach doesn't happen in secret. A backup job has usually been failing for weeks before anyone needs it. An account that gets misused usually belonged to someone who left months earlier and was never switched off.
A short, honest look at your own setup once a month is often enough to catch that kind of thing before it costs anything to fix. This post sets out six things worth checking, in an order that puts the cheapest, most damaging item first, and finishes with who should actually be doing the fixing once you've found something.
Why this is worth thirty minutes of anyone's time
Verizon's 2026 Data Breach Investigations Report found that exploiting a known, unpatched software vulnerability has overtaken stolen passwords as the single most common way attackers get into a business, present in 31% of breaches, the first time in the report's 19-year history that credential theft hasn't topped the list. The same report found the median time organisations take to fully fix a known vulnerability has stretched to 43 days, up from 32 days the year before.
Put simply: the fix usually already exists. Somebody just hasn't installed it yet. If your business holds a Cyber Essentials certification, or is working towards one, this isn't optional either. The current standard requires critical and high-risk security updates to be applied within 14 days of release, and a managed IT provider's own patching schedule doesn't automatically satisfy that requirement on your behalf. You still need to be able to show it's actually happening.
The six-point check
1. Updates
Look at whether Windows, macOS and phone updates are actually installing, or sitting at "restart required" for the third week running. Do the same for whatever software gets used daily, browsers and accounting packages especially. If people have got into the habit of clicking "remind me later" on every prompt, that's worth fixing before it's worth chasing down every individual machine.
2. Backups
Open the backup tool and look at the last handful of runs. You're checking for recent, successful completions, not a wall of red error messages. Then check when a file was last actually restored from it. A backup that's never been tested is a backup you're assuming works, not one you know works, and that distinction only ever gets discovered at the worst possible moment. We've written more on what a genuinely resilient backup setup looks like, including what "immutable" actually means on a cyber insurance form, if that's an area you're less confident about.
3. Who still has access
Pull up the full list of user accounts in Microsoft 365 or Google Workspace and read through it properly, name by name. Every single one should belong to someone who currently works for you. Watch for people who left, contractors whose project finished months ago, and shared logins like "office" or "reception" that several people use at once. Anything that doesn't clearly belong gets switched off. This is one of the more common gaps we see, and it's usually a process problem rather than a technology one, which we've covered in more depth in why bad onboarding is the real cause of messy offboarding.
4. Multi-factor authentication
Confirm MFA is switched on, and that it actually covers everyone, not just whoever set it up first. Admin accounts and anyone who handles payments deserve the closest look. A widely cited measurement study of Microsoft Entra ID accounts found that enabling MFA cut the risk of account compromise by more than 99%, even for accounts whose password had already been leaked somewhere. If your business hasn't moved past SMS codes and app prompts yet, it's worth reading what passkeys are and whether your business should use them, since they close off a type of attack that traditional MFA still lets through.
5. Devices
Check what's actually connected to your systems. A laptop or phone you don't recognise is worth tracking down straight away. While you're there, confirm laptops are encrypted and that any phone carrying company email has a passcode or biometric lock switched on. A managed, company-issued mobile makes this considerably easier, since it can be locked or wiped remotely the moment it's needed, rather than depending on whatever settings someone chose on their own personal phone.
6. Subscriptions and licences
Open the billing page and actually read what's on it. Licences belonging to people who left, two tools doing the same job, or software somebody signed up for without telling anyone are all more common than most owners expect, and all three cost money every single month until someone notices.
Turn it into a routine, not a one-off
Pick a fixed day, the first Monday of the month works well, and give the job to the same person every time, whether that's you or whoever runs the admin side of the business. Keep a short running note of what you checked and what you found. After a few months a pattern usually shows up. If the same problem keeps reappearing, it needs a proper fix rather than clearing it out again next month.
One rule makes the thirty minutes actually work: don't stop to fix things mid-check. Write each finding down and deal with it once the check itself is finished, otherwise a quick look turns into an afternoon.
What to handle yourself, and what to hand over
Most items on this list are small and don't need a technician: restarting a laptop, cancelling a licence, switching off an account. Deal with those directly.
Send the rest to whoever manages your IT: backups that keep failing, MFA that won't switch on for one particular person, an unrecognised device, or updates that fail on the same machine every single month. Those usually point to something bigger sitting underneath, and they're exactly the kind of thing a proper IT support and Microsoft 365 review is built to dig into properly.
What this check doesn't replace
This isn't a substitute for monitoring. A good IT provider runs tools that watch your systems continuously and flag problems the moment they appear, long before a monthly glance ever would, and a formal vulnerability assessment goes considerably deeper than a self-check can, scanning for the specific unpatched software and misconfigurations attackers actually look for.
What this check does cover is the part no monitoring tool can know on its own: who's actually still with the business, which subscriptions you approved, and whose laptop is sitting on whose desk. That's knowledge only you have, which is exactly why it needs a human doing the looking.
For businesses whose IT we already manage day to day, most of this list happens as a matter of course rather than something a client needs to remember to ask for: patching, backup monitoring and access reviews are built into that ongoing work, not treated as a separate favour.
If it's been a while since anyone worked through this properly, or you'd simply rather someone else took it on, book a call with our team and we'll take it from there.
Frequently Asked Questions
How often should a small business actually do this check?
Once a month covers this list well. If losing a day's work would genuinely hurt the business, it's worth glancing at backups more often than that, since it's the item most likely to fail quietly without anyone noticing.
Who in the business should be doing it?
Whoever handles the admin side, or the owner directly in a smaller business. Most of the list needs no technical background at all, just familiarity with who currently works there and what the business is actually paying for.
We don't know where to find half of this in our own systems. What then?
Ask your IT provider to walk through it with you once and note down where each item lives. Many providers will also send a monthly summary covering most of this automatically, which is worth asking about directly.
Doesn't our IT provider already do all of this?
They handle the monitoring, the patching, and fixing what breaks. This check covers the part that depends specifically on knowing your business: who left last month, which subscription nobody remembers approving, whose device is whose.
Does this monthly check count towards Cyber Essentials?
It helps, but it isn't the certification process itself. Cyber Essentials specifically requires evidence that critical and high-risk patches are applied within 14 days, which is tighter than most businesses manage through an informal monthly look alone. If certification is the goal, treat this check as good habit-building rather than the compliance record itself.
If we've only got ten minutes, what matters most?
Backups and updates, in that order. Without a backup that actually works, a bad day can mean losing everything stored on that system. Unpatched software is now the single most common way attackers get in, so it's the next place worth spending whatever time is left.
Written by
Jack Wetson-CattJack co-founded Atema in 2017 and leads the team day to day, bringing years of IT experience across telecoms, finance and legal to how Atema supports its own clients.
