Most business owners only look at their IT once something’s already broken — a file won’t open, a laptop won’t start, or an invoice gets paid into a scammer’s account. By the time you notice, it usually costs more to fix than it would have to prevent.

Here’s the thing: almost none of it happens without warning. The backup that failed the day you needed it had been failing quietly for weeks. The account a scammer used to get in belonged to someone who left the company last spring. Thirty minutes a month is usually enough to catch that kind of thing before it turns into a bad Tuesday.

Why a monthly look is worth the time

Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches started with attackers exploiting software nobody had patched yet — ahead of stolen passwords as the most common way in. The same report puts the median time to fully fix a known vulnerability at 43 days. Put plainly: most attacks use a hole that was already known, with a fix that already existed. Nobody had installed it.

We see the same pattern with clients across the GTA, from professional services firms in the Financial District to manufacturers out in Brampton and Vaughan. It’s never the exotic attack that gets them. It’s the update that’s been sitting at “restart required” for three weeks.

The check

1. Updates. Are Windows updates actually installing, or sitting at “restart required” week after week? Check phones too, and the software your team uses daily — browser, accounting app. If people keep clicking “remind me later,” that’s worth fixing.

2. Backups. Open your backup tool and look at the last few runs. You want recent successful backups, not a wall of red errors. Then check when anyone last restored a file from it. If nobody’s ever tested a restore, you don’t actually know it works.

3. Who has access. Pull the list of user accounts in Microsoft 365 and read through it. Every name should be someone who still works there. Watch for people who left, contractors who wrapped up months ago, and shared logins like “office” or “reception” that half the team knows the password to. Switch off anything you don’t need.

4. Multi-factor authentication. Confirm MFA is on for everyone — not just the two people who set it up first. Admin accounts and anyone who touches money matter most here. Microsoft’s own research shows MFA blocks over 99% of account compromise attempts, which makes it one of the cheapest wins on this list.

5. Devices. Look at what’s actually connected to your systems. An unfamiliar laptop or phone is worth a phone call to figure out whose it is. While you’re there, confirm laptops are encrypted and any phone carrying company email has a passcode or fingerprint lock on it.

6. Subscriptions and licences. Open the billing page and read what you’re actually paying for. It’s remarkably common to find licences for people who left two jobs ago, or two tools doing the same thing. It’s also how you find the software someone signed up for without telling anyone — a real compliance headache under Ontario’s privacy rules if that tool is handling client data nobody vetted.

Make it a routine, not a one-off

Put it on the calendar for a fixed day — first Monday of the month works for a lot of our Toronto clients — and give it to the same person every time. Keep a short running note of what you checked and what you found. After a few months a pattern usually shows up, and if the same problem keeps recurring, that’s a sign it needs fixing properly rather than clearing every month.

One rule that keeps the 30 minutes honest: don’t stop to fix things mid-check. Write it down and deal with it after, or the “quick check” turns into a two-hour afternoon.

What this check doesn’t replace

This isn’t monitoring. A proper managed IT services setup has tools watching your systems around the clock and flagging problems long before a monthly glance would catch them. What the 30-minute check covers is the stuff those tools can’t know on their own — who actually left the company, which subscription you approved, whose laptop is whose.

For anything that turns up — backups that keep failing, MFA that won’t switch on for someone, a device nobody recognizes — that’s the point to loop in your IT partner rather than chase it yourself. Getting the basics right also closes off a lot of what attackers go looking for first — pairing it with getting your team trained to catch the rest covers what a monthly checklist alone can’t.

Frequently Asked Questions

How often should a small business check its IT?
Once a month covers this list well. Backups are worth a quicker glance more often if losing a day’s work would genuinely hurt — that’s usually the item most likely to fail without anyone noticing.

Who should actually do this?
You, or whoever handles admin day-to-day. Most of it needs no technical background — just someone who knows who works there and what the business is paying for.

What if I don’t know where to find any of this?
Ask your IT provider to walk through it with you once and write down where each item lives. A lot of providers, including our team, will also send a monthly summary that covers most of it for you.

Isn’t this my IT provider’s job already?
They handle the monitoring, patching, and fixing. This check covers the part that depends on knowing your own business — who left last month, which subscription nobody approved.

If I only have ten minutes, what matters most?
Backups and updates. Without a working backup you can lose everything you’ve stored, and unpatched software is currently the single most common way attackers get in.

Prepared by the EB Solution team — managed IT services for small and mid-sized businesses across the Greater Toronto Area. Want us to run this check for you every month instead? Get in touch with our team and we’ll set it up.

Watch Our Latest Tech Videos From EB Solution

Call Now