Most business owners only look at their IT when something's already gone wrong. A file won't open. A laptop won't start. An invoice gets paid into a scammer's account instead of the vendor's.
Here's the thing: almost none of that happens without warning. The backup that failed when you needed it had been failing quietly for weeks. The account a scammer used to get in belonged to someone who left the company last year. By the time you notice, the problem has already been sitting there — getting more expensive to fix every day.
Thirty minutes a month is usually enough to catch it first.
The numbers make a pretty strong case for building this into your routine:
Put those together and the pattern is clear: most attacks aren't clever. They're walking through a door that was already known to be unlocked, because nobody had gotten around to closing it.
Print this section, save it, or copy it into your notes app — this is the part you'll actually use.
Check whether Windows updates are actually installing on your computers, or quietly sitting at "restart required" week after week. Do the same for phones and for the software you use most — your browser, your accounting app. If people keep clicking "remind me later," that's the thing to fix.
Open your backup tool and look at the last few runs. You want recent, successful backups — not a list of errors you've learned to scroll past. Then check when anyone last actually restored a file from it. A backup that's never been tested is a guess, not a safety net.
Pull up the list of user accounts in Microsoft 365 or Google Workspace and read through it, name by name. Everyone on it should still work for you. Watch for people who've left, contractors who wrapped up months ago, and shared logins like "office" or "admin" that half the team knows the password to. Switch off anything you don't need.
Confirm MFA is switched on — and that it's on for everyone, not just the first few people who set it up. Pay the closest attention to admin accounts and anyone who handles money. This single setting blocks the overwhelming majority of account takeover attempts.
Look at what's actually connected to your systems. A laptop or phone you don't recognize is worth chasing down immediately. While you're at it, confirm laptops are encrypted and that any phone with company email on it has a passcode or fingerprint lock.
Open your billing page and read what you're actually paying for. It's common to be paying for licenses that belong to someone who left, or for two different tools that do the same job. It's also usually how you discover software someone signed up for without telling anyone.
A checklist you run once doesn't help you six months from now. A few things make it stick:
Most of what turns up is small enough to handle yourself:
You can usually handle:
Send this to your IT provider:
If something keeps showing up on your list two or three months running, that's usually a sign there's a bigger issue underneath it.
This isn't monitoring, and it isn't meant to be. A good IT provider has tools watching your systems all day, flagging things you'd never catch from a monthly glance. This check covers what those tools can't know — who left last month, which subscriptions you actually approved, whose laptop is whose. It's the layer that depends on knowing your business, not your network.
How often should a small business check its IT? Once a month covers this list well. Backups are worth a quicker look more often if losing a day's work would genuinely hurt — that's the item most likely to fail quietly.
Who should actually do this? You, or whoever handles the admin side of the business. Almost none of it requires technical skill — just someone who knows who works there and what the business pays for.
What if I don't know where to find any of this? Ask your IT provider to walk you through it once and write down where each item lives. Many will also send a monthly summary covering most of it for you.
Isn't this my IT provider's job? They handle the monitoring, the patching, and the fixing. This check is the part that depends on knowing your business — who left last month, which subscription nobody approved — not your infrastructure.
If I only have ten minutes, what matters most? Backups and updates. Without a working backup, you can lose everything you've stored. And unpatched software is now the single most common way attackers get in.
Does this still apply if everything we use is in the cloud? Yes. Cloud tools still need updated devices, working backups, MFA switched on, and access lists that actually match who works for you today.
If you're not sure where half of this even lives — backups, licenses, admin accounts — that's a normal starting point, not a bad sign. Attitude IT can walk through your first monthly check with you, show you exactly where everything is, and set you up with a monthly summary so the list stays this easy going forward.