Our Blog

Most owners only look at their IT when something has already gone wrong. A file won't open, a laptop won't start, or an invoice gets paid into a scammer's account. Fixing it at that point costs more than preventing it would have.
Almost none of it happens without warning. The backup that fails when you finally need it had been failing for weeks. The account a scammer used belonged to someone who left last year. Thirty minutes a month is usually enough to catch that kind of thing.
Verizon's 2026 Data Breach Investigations Report found that 31% of breaches started with attackers exploiting software that hadn't been patched. That makes unpatched software the most common way in, ahead of stolen passwords. The same report found the median time to fully fix a known problem has risen to 43 days.
Most attacks use a problem that was already known, with a fix already available. Nobody had installed it yet.
Check whether Windows updates are installing on your computers, or sitting at "restart required" week after week. Do the same for phones and for the software you use most, like your browser and your accounting app. If people keep clicking "remind me later," that's something to fix.
Open your backup tool and look at the last few runs. You want recent successful backups, not a list of errors. Then check when anyone last restored a file from it. If it's never been tested, you don't know whether it works.
Pull up the list of user accounts in Microsoft 365 or Google Workspace and read through it. Every name should be someone who still works for you. Look for people who left, contractors who finished months ago, and shared logins like "office" or "admin" that several people use. Switch off anything you don't need.
Check that MFA is switched on, and that it's on for everyone, not just the people who set it up first. Pay closest attention to admin accounts and anyone who handles money. Microsoft's research shows MFA blocks more than 99.2% of account compromise attacks.
Look at what's connected to your systems. If there's a laptop or phone you don't recognise, find out whose it is. While you're there, check that laptops are encrypted and that any phone with company email on it has a passcode or fingerprint lock.
Open your billing page and read what you're paying for. Businesses regularly pay for licenses belonging to people who left, or for two tools that do the same job. It's also how you find software somebody signed up for without telling anyone.
Put it in the calendar on a fixed day, like the first Monday of the month, and give it to the same person each time. That's you or whoever handles the admin side.
Keep a running note of what you checked and what you found. After a few months you'll see whether the same problem keeps coming back. If it does, it needs fixing properly instead of clearing each time.
Thirty minutes only works if you don't stop to fix things along the way. Write down what you find and deal with it afterward.
Most of it is small, like a laptop that needs restarting, a license to cancel, or an account to switch off. Handle those yourself.
Send the rest to your IT provider: backups that keep failing, MFA that won't turn on for someone, a device nobody recognizes, or updates that fail on the same machine every month. Those usually mean there's a bigger problem behind them.
It isn't monitoring. A good IT provider has tools watching your systems all day and flagging things you'd never spot from a monthly glance.
The check covers what those tools can't know. You know who left, which subscriptions you approved, and whose laptop is whose.


Friendly, jargon-free IT Support for businesses around Newcastle, Tyneside and the North East of England.
0191 662 0100
Room 2, Henson House
Planet Place, Stephenson Industrial Estate
Newcastle upon Tyne
NE12 6RZ
