Interested in our Cybersecurity Framework?
An organised document structure supports better governance.
Build confidence in your cyber security posture.
Many organisations only pay attention to their technology when something has already gone wrong. A critical document becomes inaccessible, a laptop fails unexpectedly, or a fraudulent payment is made following a phishing attack. By that stage, the focus shifts to recovery rather than prevention.
Most technology failures provide warning signs long before they become serious problems. Backups that fail during a crisis have often been reporting errors for weeks. Unauthorised access frequently stems from accounts that should have been removed months earlier. Small governance gaps can gradually develop into significant operational and security risks.
A structured monthly review, taking no more than 30 minutes, can help identify these issues early and strengthen your organisation’s overall resilience.
Why a Monthly IT Review Matters
The National Cyber Security Centre describes Cyber Essentials as the minimum standard of cyber security for UK organisations and notes that organisations implementing these controls are significantly less likely to experience common cyber attacks. The scheme’s core controls include secure configuration, security update management, user access control, and malware protection, all areas that benefit from regular review.
A simple monthly IT health check helps ensure these controls remain effective as users, devices, applications, and business requirements change over time.
The Six-Point Monthly IT Health Check
1. Review Software and Device Updates
Outdated software remains one of the most common causes of preventable cyber incidents.
Check whether Windows updates are being installed across company devices or whether machines are repeatedly sitting in a “restart required” state. The same review should include mobile devices, web browsers, antivirus software, and any core business applications.
If updates are consistently being postponed, the issue is no longer technical. It becomes a governance and risk-management concern.
Questions to ask:
- Are all devices receiving updates regularly?
- Are there any unsupported operating systems in use?
- Have any critical security patches failed to install?
2. Verify Your Backups Are Working
A backup is only valuable if it can be restored.
Review your backup platform and confirm recent jobs have completed successfully. Look for recurring failures, missed schedules, or storage warnings.
Equally important is testing recovery. If no one has attempted a restore recently, you cannot be certain your backups will work when needed.
Questions to ask:
- Were the last backup jobs successful?
- When was the last file restoration performed?
- Have critical systems been included in the backup scope?
The NCSC identifies secure, tested backups as one of the most effective safeguards against ransomware and operational disruption.
3. Review User Access
Access management should closely reflect your current workforce.
Review user accounts within Microsoft 365, Google Workspace, and any critical business systems. Every account should belong to an active employee, authorised contractor, or approved service account.
Pay particular attention to:
- Former employees
- Temporary contractors
- Shared accounts
- Privileged administrator accounts
4. Confirm Multi-Factor Authentication (MFA) Is Enabled
Multi-Factor Authentication remains one of the simplest and most effective security controls available.
While many organisations have enabled MFA for some users, it is common to find gaps, particularly within administrative accounts, service accounts, or long-standing users who were exempted during implementation.
Questions to ask:
- Is MFA enabled for all users?
- Are administrator accounts protected?
- Are authentication methods current and phishing-resistant where appropriate?
5. Review Devices Connected to the Organisation
Most organisations underestimate how many devices are connected to their systems.
Review your device inventory and verify that every laptop, mobile phone, tablet, and workstation is recognised and authorised.
During this review, confirm that:
- Device encryption is enabled
- Passcodes and biometric protection are enforced
- Lost, retired, or replaced devices have been removed
Unknown or unmanaged devices can represent a significant security and compliance risk.
6. Review Software Licensing and Subscriptions
Technology spending can gradually increase without anyone noticing.
Review your Microsoft 365 licences, software subscriptions, security tools, cloud services, and other recurring costs.
It is common to find:
- Licences assigned to former employees
- Duplicate tools performing the same function
- Unauthorised software purchases
- Legacy systems that are no longer required
A simple monthly review can reduce unnecessary expenditure while improving governance and visibility.
Make It Part of Your Operational Routine
The most effective approach is to schedule this review on the same day each month, whether that is the first Monday, the final Friday, or another consistent date.
Document what was reviewed, any issues identified, and any follow-up actions required. Over time, these records provide valuable evidence of good governance and can help identify recurring weaknesses before they become significant problems.
Importantly, resist the temptation to fix issues immediately during the review itself. The purpose of the exercise is to identify risks, prioritise them, and ensure they are addressed appropriately afterwards.
Remember: This Is Not Monitoring
A monthly IT review complements, rather than replaces, professional monitoring and support.
An IT Managed Services provider should already be monitoring backups, devices, security alerts, and system performance continuously. However, technology tools cannot identify everything.
They cannot know:
- Which employees have recently left
- Which subscriptions were approved
- Whether an unfamiliar device should still exist
- Whether a recurring issue reflects a broader operational concern
Those decisions require business knowledge and governance oversight.
As cyber resilience becomes increasingly important for organisations across the UK, particularly those working towards frameworks such as Cyber Essentials or Cyber Essentials Plus, regular operational reviews help ensure that technology remains aligned with business risk, compliance requirements, and organisational objectives.