Thirty Minutes a Month Is Enough to Catch Most IT Problems
Ikram Massabini
September 1, 2026
IT failures are rarely sudden. They announce themselves for weeks and nobody is looking.
The backup that turns out to be empty on the worst possible day had been erroring since spring. The account a scammer used to send invoices belonged to someone who resigned fourteen months ago. The laptop that got encrypted had been skipping updates since it came out of the box. In each case the warning sat in a dashboard nobody opened.
Verizon’s 2026 Data Breach Investigations Report put a number on the pattern: 31 percent of breaches began with attackers exploiting unpatched software, which now outranks stolen credentials as the leading route in. Verizon also measured how long full remediation takes once a flaw is known, and the median has drifted out to 43 days. The fix existed. Nobody had applied it yet.
A short, scheduled look at six things catches most of this while it is still boring.
The six things
Updates. Open a few machines and see whether Windows updates are actually completing or parked indefinitely at “restart required.” Extend the same look to phones, browsers, and whatever accounting or line-of-business software the team lives in. A pattern of people clicking “remind me later” for weeks is itself the finding.
Backups. Look at the job history, not the marketing dashboard. You want a run of recent successes, not a wall of warnings someone learned to ignore. Then ask a harder question: when did anyone last restore a file from it? An untested backup is a hypothesis, not a safety net.
Access. Pull the user list out of Microsoft 365 or Google Workspace and read every line. Each name should be someone who still works there. Watch for departed employees, contractors whose engagement ended two quarters ago, and generic logins like “office” or “reception” that three people share. Disable anything that fails that test.
Multi-factor authentication. Confirm it is enabled, and confirm it covers everyone rather than the handful of people who were in the room when it was turned on. Administrators and anyone who can move money deserve the closest look. Microsoft’s research puts MFA’s effectiveness against account compromise above 99 percent, which makes a gap in coverage unusually expensive.
Devices. Review what is connecting to your systems. An unfamiliar laptop or phone is worth a question. While you are there, verify that laptops are encrypted and that any phone carrying company email has a screen lock.
Subscriptions. Open the billing page and read it properly. Businesses routinely pay for seats belonging to people who left, and for two products that do the same job. It is also how you discover the tool somebody expensed without telling anyone.
Make it a habit, not a project
Put it on the calendar on a fixed day, give it to one named person, and keep the appointment. First Monday of the month works as well as anything.
Keep a short running log of what you looked at and what you found. The value shows up around month four, when you notice the same machine failing updates every single time. A problem that keeps returning needs a root cause, not another manual clear.
One discipline matters more than the rest: do not stop to fix things mid-review. Note each issue and handle it later. Repairing as you go is how thirty minutes becomes an afternoon, and how the review quietly stops happening by March.
Sorting what you found
Most of it is yours to handle. A laptop that needs a restart, a seat to cancel, an account to disable.
Send the rest to your IT provider, and be specific about which category it falls into. Backups that fail repeatedly, MFA that refuses to enroll for one person, a device nobody can identify, updates that break on the same machine every month. Those are symptoms rather than tasks, and they usually have something larger behind them.
What this is not
This is not monitoring. A competent provider runs tooling that watches your environment continuously and surfaces things no monthly glance would catch.
The review covers the part that tooling cannot know. Software has no idea who resigned last month, which subscription you actually approved, or whose laptop that is. That context lives with you, which is exactly why the review has to be done by someone inside the business.
If you would rather have this handled
MVP Network Consulting runs this review for businesses across Buffalo and Western New York, and hands back a short list of what needs attention and what we already fixed. If your honest answer to “when did anyone last check the backups” is that you are not sure, that is the place to start. Get in touch and we will take a look.