The 30-Minute Monthly IT Checklist Every Texas Small Business Should Run

Most business owners only think about IT after something has already broken. A file won't open, a laptop won't start, or an invoice gets paid into a scammer's account. Fixing a problem at that point almost always costs more than preventing it would have.

Here's the thing: almost none of it happens without warning. A backup that fails right when you need it had usually been failing quietly for weeks. The account a scammer used to get in often belonged to someone who left the company last year. A simple monthly IT checklist, run in about 30 minutes, is usually enough to catch this kind of problem before it turns into a bigger one.

This guide walks through the six checks every small business in Texas should run once a month, why they matter, and who should handle what when something needs fixing.

Why a Monthly IT Check Is Worth the Time

Verizon's 2026 Data Breach Investigations Report found that 31% of data breaches started with attackers exploiting software that hadn't been patched. That makes unpatched software the single most common way attackers get in, ahead of stolen passwords. The same report found the median time to fully fix a known vulnerability has risen to 43 days.

In other words, most attacks don't rely on some clever new trick. They use a problem that was already known, with a fix that was already available. Nobody had gotten around to installing it yet.

For small businesses without a full-time IT department, a short monthly review is one of the most cost-effective ways to close that gap.

The Six-Point Monthly IT Checklist

1. Updates

Check whether Windows updates are actually installing on your computers, or sitting at "restart required" week after week. Do the same for phones and for the software your team uses most, like your browser and your accounting app. If people keep clicking "remind me later," that's a habit worth fixing before it becomes an open door.

2. Backups

Open your backup tool and look at the last few runs. You want to see recent, successful backups, not a growing list of errors. Then check when anyone last restored a file from it. If a backup has never been tested, you don't actually know whether it works, you're just hoping it does.

3. Who Has Access

Pull up the list of user accounts in Microsoft 365 or Google Workspace and read through it line by line. Every name should belong to someone who still works for you. Watch for people who've left, contractors who finished months ago, and shared logins like "office" or "admin" that several people use. Switch off anything you no longer need.

4. Multi-Factor Authentication (MFA) ‍

Confirm that multi-factor authentication is switched on, and that it's turned on for everyone, not just the people who set it up first. Pay the closest attention to admin accounts and anyone who handles money. Microsoft's research shows MFA blocks more than 99.2% of account compromise attacks, which makes it one of the highest-value checks on this list.

5. Devices

Look at what's actually connected to your systems. If there's a laptop or phone you don't recognize, find out whose it is before assuming the best. While you're at it, confirm that laptops are encrypted and that any phone with company email on it has a passcode or fingerprint lock set up.

6. Subscriptions and Licenses

Open your billing page and read through what you're actually paying for. Small businesses regularly pay for licenses that belong to people who left, or for two different tools that do the same job. This is also how you catch software someone signed up for without telling anyone else.

Make It a Routine, Not a One-Time Project

Put the check on the calendar for a fixed day, like the first Monday of the month, and assign it to the same person every time. That's you or whoever handles the administrative side of the business.

Keep a running note of what you checked and what you found each time. After a few months, patterns show up, and you'll notice if the same problem keeps coming back. If it does, it needs a real fix instead of being cleared and forgotten every month.

Thirty minutes only works if you don't stop to fix things along the way. Write down what you find, then deal with it afterward.

Who Fixes What

Most items on this list are small and quick: a laptop that needs a restart, a license to cancel, an account to switch off. Handle those yourself as you go.

Send the rest to your IT provider: backups that keep failing, MFA that won't turn on for someone, a device nobody recognizes, or updates that fail on the same machine every single month. Issues like these usually point to a bigger problem underneath.

What This Checklist Doesn't Replace

This monthly review isn't the same as ongoing monitoring. A good managed IT provider has tools watching your systems around the clock, flagging issues you'd never spot from a once-a-month glance.

What this checklist covers is exactly what those tools can't know on their own: who left the company, which subscriptions you actually approved, and whose laptop belongs to whom. That's information only you have.

Frequently Asked Questions

How often should a small business check its IT? Once a month is enough for this checklist. Backups are worth a quicker look more often if losing a day's work would seriously hurt your business, since that's the item most likely to fail quietly without anyone noticing.

Who should run this check? You or whoever handles the administrative side of the business. Most of this list requires no technical skill, just someone who knows who works there and what the business actually pays for.

What if I don't know where to find any of this? Ask your IT provider to walk you through it once and write down where each item lives. Many providers, including Griffin Technology Solutions, will also send a monthly summary covering most of it for you.

Isn't this my IT provider's job? Your provider handles the monitoring, the patching, and the fixing. This checklist covers the part that depends on knowing your own business, like who left last month or which subscription nobody approved.

If I only have ten minutes, what matters most? Backups and updates. Without working backups, you can lose everything you've stored. And unpatched software is now the single most common way attackers get in.

Does this still apply if everything we use is in the cloud? Yes. Cloud tools still need updated devices, working backups, MFA switched on, and access lists that match who actually works for you today.

Ready for Help Running This Checklist Every Month?

Griffin Technology Solutions helps Texas small businesses stay ahead of IT problems instead of reacting to them. If you'd rather have a team run this checklist for you and flag what needs attention, we're here to help, contact us today.

Next
Next

Is Your Business Website a Security Risk? What Texas Owners Need to Know