Have Questions? Call ParJenn Technologies (409) 684-2517   |   Customer Portal
it checklist
IT Management Small Business IT

IT Checklist: 6 Simple Checks to Run Once a Month

Most owners look at their IT when something has already gone wrong. A file will not open, a laptop will not start, or an invoice got paid into a scammer’s account. By then it costs more to fix than it would have cost to catch. An IT checklist you run once a month, for thirty minutes, is how you catch it.

Almost none of this happens without warning. The backup that fails the day you need it had been failing for weeks. The account the scammer used belonged to someone who left last year. Those are not surprises. They are things nobody looked at, and a monthly IT checklist is how you look.

I want to walk through why a monthly look is worth the time, then give you the six things on the IT checklist, then tell you which of them are yours to fix and which ones to hand to us.

Why an IT checklist beats monitoring alone

We run monitoring tools on every client’s systems, all day. They flag failed updates, full disks, backups that did not run. I will be straight about their limit: they know what the computers are doing. They do not know what your business is doing.

The monitoring tool does not know that Dave left in March. It sees a user account that logs in sometimes, which is normal. It does not know that the “office” login is shared by four people. It does not know you stopped using that scheduling app in the spring and are still paying for it.

Those are the things only you can see, and they are exactly where problems start. That is the whole point of the IT checklist: it looks at what the tools cannot.

There is a number behind this. Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches started with attackers using software that had not been patched. That puts unpatched software ahead of stolen passwords as the most common way in. The same report found the median time to fully fix a known problem has climbed to 43 days. So most attacks use a hole that was already known, with a fix already available. Nobody had installed it yet. An IT checklist is where you would have caught it.

The IT checklist: six things to check

None of this needs a technical background. The IT checklist needs someone who knows who works there and what the business pays for.

1. Updates

Look at whether Windows updates are actually installing on your computers, or sitting at “restart required” week after week. The update that has been waiting for a restart since June is not protecting anything. Do the same for phones, and for the software you use most, like the browser and the accounting app.

If people keep clicking “remind me later,” that is a thing to fix, not a thing to nag about. We schedule restarts overnight for exactly this reason.

2. Backups

Open the backup tool and look at the last few runs. You want recent green checkmarks, not a list of errors. Then ask a harder question: when did anyone last restore a file from it?

A backup that has never been tested is a backup you hope works. Here is what a failed backup actually looks like in the tool, since people ask: usually a yellow or red status on a job, a “last successful” date that is weeks old, or a job that says it completed but backed up a fraction of what it should have. That last one is the sneaky one, and it is the reason backups sit near the top of the IT checklist.

3. Who has access

Pull up the list of user accounts in Microsoft 365 or Google Workspace and read every name. Each one should be someone who works for you today.

Look for people who left, contractors who finished months ago, and shared logins like “office” or “admin” that several people use. Switch off anything you do not need. This is the check that stops the scam that starts with an old account, and it is the part of the IT checklist most businesses have never done once.

We did a version of this for a nonprofit client and found accounts for two volunteers who had moved away. Nothing bad had happened. Nothing bad had happened yet.

4. Multi-factor sign in

Check that multi-factor sign in, the code on your phone after the password, is switched on. Then check that it is on for everyone, not just the people who set it up first. Pay closest attention to admin accounts and anyone who handles money.

The reason is simple. Microsoft’s own research shows it blocks more than 99% of account takeover attempts. A stolen password on its own gets an attacker almost nowhere when this is on.

5. Devices

Look at what is connected to your systems. Most business email and cloud tools show you a list of signed in devices. If there is a laptop or a phone you do not recognize, find out whose it is.

While you are there, check that laptops are encrypted, so a lost laptop is just a lost laptop, and that any phone with company email on it has a passcode or fingerprint lock. We have a longer post on securing company laptops used at home if that is your situation.

6. Subscriptions and licenses

Open your billing page and read what you are paying for. Every business we onboard is paying for something they do not use. Licenses for people who left. Two tools that do the same job. Software somebody signed up for on a company card and never told anyone about.

This is the only item on the IT checklist that pays for the other five. It is also how you find the apps nobody approved, which our post on uncovering unsanctioned cloud apps goes into.

Make the IT checklist a routine

Put the IT checklist on the calendar on a fixed day, like the first Monday of the month, and give it to the same person each time. That is you, or whoever handles the admin side of the business.

Keep a running note of what you checked and what you found. After a few months you will see whether the same thing keeps coming back. If it does, it needs fixing properly instead of clearing every month.

Thirty minutes only works if you do not stop to fix things along the way. Write down what you find. Deal with it afterward.

The thing nobody asks about, and should: run the IT checklist at the same time each month, because the value is in the comparison. A backup that shows one error means nothing. A backup that shows an error three months running means the tool is broken and nobody is watching it.

Who fixes what

Most of what the IT checklist turns up is small. A laptop that needs a restart. A license to cancel. An account to switch off. Handle those yourself; they take minutes.

Send the rest to your IT provider. Backups that keep failing. Multi-factor sign in that will not turn on for someone. A device nobody recognizes. Updates that fail on the same machine every month. Those usually mean there is a bigger problem behind them, and they are what we are for. For our clients, the monthly summary from our managed IT services covers most of the first two items on this list automatically, so the check gets shorter.

What the IT checklist does not do

It is not monitoring, and it is not a replacement for it. A good IT provider has tools watching your systems all day and flagging things you would never spot from a monthly glance. A disk filling up at 2 a.m. does not wait for the first Monday.

The IT checklist covers what those tools cannot know. Who left. Which subscriptions you approved. Whose laptop is whose. The two together are the whole picture. Either one alone has a blind spot, and I would rather you know where the blind spot is than assume there is not one.

Frequently asked questions

How often should a small business run an IT checklist? Once a month is enough for this list. Backups are worth a quicker look more often if losing a day’s work would seriously hurt, since that is the item most likely to fail quietly.

Who should run the IT checklist? You, or whoever runs the admin side of the business. Most of the list needs no technical skill, just someone who knows who works there and what the business pays for.

What if I do not know where to find any of this? Ask your IT provider to walk you through the IT checklist once and write down where each thing lives. Many, including us, send a monthly summary that covers most of it.

Is this not my IT provider’s job? They handle the monitoring, the patching and the fixing. The IT checklist is the part that depends on knowing your business, like who left last month or which subscription nobody approved.

If I only have ten minutes, what matters most? Backups and updates. Without working backups you can lose everything you have stored, and unpatched software is now the most common way attackers get in.

Does this apply if everything we use is in the cloud? Yes. Cloud tools still need updated devices, working backups, multi-factor sign in turned on, and an access list that matches who actually works for you.

If you would like the first one done with you rather than by you, we do a plain language walkthrough of exactly these six items, and we tell you what we found and nothing more. You can book the IT health checkup and use it as month one.

Featured image: Unsplash

Leave a Reply