Back to Blog
    Dark blue IT workspace with laptop, desktop PC, monitor, network switches, Wi-Fi access point, tools, and server racks in background.

    What Your IT Provider Should Be Doing Every Month

    managed-it
    business-it
    cybersecurity
    backups
    networking
    Author: Fix My PC Store Editorial TeamPublished: 8/14/2026Last Updated: 8/14/2026

    Most businesses find out their IT provider was cutting corners after something breaks. Here's the monthly checklist Server Steve uses to judge whether a managed IT provider is actually doing the work or just billing for it.

    TL;DR: A managed IT provider worth paying should be patching systems, verifying backups, reviewing security logs, checking network health, and reporting on all of it every single month. If you can't remember the last time you got a report, or you've never seen one, that's not a paperwork problem. That's a warning sign.

    I've taken over enough neglected networks in Palm Beach County to know the pattern. The business had a contract. They paid a monthly fee. Nobody ever showed them what that fee bought. Then a server dies, or ransomware lands, and the first question is always the same: what were we paying for?

    Good managed IT isn't mysterious. It's a short list of repeatable tasks done on a schedule, whether anything looks broken or not. Here's what should be happening every single month, and what it means if it isn't.

    1. Patch management, actually verified

    Every vendor pushes updates. Windows, macOS, browsers, firmware, line-of-business software. Patches close security holes and fix bugs, but they also occasionally break things, which is why "set it to auto-update and walk away" isn't management. It's neglect with extra steps.

    A real provider should be:

    1. Reviewing which patches are pending across every device
    2. Testing or staging updates before mass deployment, especially on servers
    3. Confirming patches actually installed, not just that they were sent
    4. Documenting which machines are behind and why

    If your provider can't tell you your current patch compliance rate in under a minute, they're not tracking it. That's the whole point of managed IT: someone is watching this so you don't have to.

    2. Backup verification, not just backup scheduling

    Backing up data is easy. Backing up data that actually restores when you need it is the hard part, and it's the part almost everyone skips.

    Every month, your provider should be able to answer:

    1. When was the last successful backup for each critical system
    2. When was a restore last tested, not just checked for a green checkmark
    3. Where backups are stored, and whether at least one copy is offsite or isolated from your main network
    4. How long a full recovery would actually take, in hours, not "quickly"

    I've seen backup software report success for months while quietly failing to capture a database. Nobody noticed until they needed a restore. That's why backups and disaster recovery has to include verification, not just a scheduled job. A backup nobody has tested is a guess, not a plan.

    3. Security log review and alert triage

    Firewalls, antivirus, endpoint detection, and email filters generate a constant stream of alerts. Most are noise. Some aren't. The job is knowing the difference, every month, not just when something obviously breaks.

    Monthly security review should include:

    1. Checking for repeated failed login attempts, especially from unfamiliar locations
    2. Reviewing quarantined emails for phishing patterns targeting your staff specifically
    3. Confirming antivirus and endpoint protection are active and updated on every device, not just most of them
    4. Checking for unauthorized software or new admin accounts that shouldn't exist

    If your provider only looks at this stuff after you report a problem, you don't have cybersecurity management. You have incident response, which is a different and more expensive thing.

    4. Network health and performance checks

    Networks degrade slowly. A switch starts dropping packets intermittently. Wi-Fi coverage gets worse as more devices join. Bandwidth gets eaten by something nobody approved. None of this trips an alarm. It just makes everyone's day slightly worse until someone finally complains.

    Each month, someone should be checking:

    1. Uptime and error rates on switches, routers, and access points
    2. Bandwidth usage trends, so capacity problems get caught before they're emergencies
    3. Firmware status on network hardware, which gets ignored more than almost anything else
    4. Whether guest and staff traffic are still properly separated

    This is standard stuff for business networking, and it's the difference between a network that quietly ages and one that quietly fails during a busy week.

    Tired of IT that breaks at the worst time? Talk to our business IT team

    5. User account and access review

    Employees leave. Contractors finish projects. Interns come and go. Every one of those events should trigger an access change, and every month someone should be double-checking that it actually happened.

    A proper review covers:

    1. Accounts for former employees that should have been disabled and weren't
    2. Shared or generic logins that make it impossible to tell who did what
    3. Admin privileges granted for a one-time task and never revoked
    4. Multi-factor authentication status across email and critical systems

    This matters more than most owners realize. A former employee with working credentials three months after their last day is not a hypothetical, it's a recurring finding when I audit new clients' systems.

    6. Microsoft 365 or email platform hygiene

    If your business runs on Microsoft 365, there's a specific set of checks that should happen monthly, separate from general IT tasks:

    1. Reviewing mail flow rules for anything suspicious or unauthorized
    2. Checking storage usage before mailboxes or SharePoint sites hit limits
    3. Confirming licensing matches actual headcount, since overpaying for unused licenses is common and easy to miss
    4. Verifying conditional access and MFA policies are still enforced and haven't been quietly disabled by a setting change

    This one gets skipped constantly because it doesn't look like "real" IT work. It's still where a lot of quiet financial waste and quiet security gaps live.

    7. Documentation updates

    Networks change. New devices get added, old ones get retired, passwords get rotated, vendors get swapped. If the documentation describing your environment doesn't change with it, it becomes fiction, and fiction is useless during an actual emergency.

    Monthly, documentation should reflect:

    1. Current inventory of hardware and software, including warranty and end-of-life dates
    2. Network diagrams that match what's actually plugged in
    3. Password and access records stored securely, not in a spreadsheet on someone's desktop
    4. Vendor contacts and account numbers for anything critical to operations

    When I take over a new account, outdated or missing documentation is one of the most common problems I find. It's invisible until you need it, and then it's the only thing that matters.

    8. A monthly report you can actually read

    Everything above is only worth something if you can see it. A report should be short, specific, and honest, not a wall of green checkmarks that tells you nothing.

    A useful monthly report includes:

    1. What was patched, backed up, and reviewed, with dates
    2. Any alerts or incidents, however minor, and how they were resolved
    3. Open issues that haven't been fixed yet, and why
    4. Recommendations, even ones that don't generate more billing

    If your reports are vague, late, or nonexistent, that's not a communication issue. It usually means the underlying work isn't happening consistently either. Reporting is the easiest part to fake and the easiest part to verify, which makes it a pretty reliable canary.

    Bottom line

    Monthly IT maintenance isn't glamorous, and that's exactly why it gets skipped. Patched systems, tested backups, reviewed logs, healthy networks, clean access lists, and honest reporting don't prevent every problem, but they prevent the predictable ones, and most IT disasters are predictable ones that got ignored for months.

    If you're not sure what your current provider is actually doing, ask for last month's report. If there isn't one, that tells you what you need to know. For businesses anywhere in Palm Beach or the Treasure Coast who want a straight answer about what's being maintained and what's been neglected, contact us and we'll walk through it plainly, no scare tactics required.


    Tired of IT that breaks at the worst time?

    We run managed IT, backups, and security for South Florida businesses so you can stop thinking about it.

    Talk to our business IT team

    Frequently asked questions

    How do I know if my IT provider is actually doing monthly maintenance?

    Ask for a written monthly report showing what was patched, backed up, and reviewed, with dates and specifics. If they can't produce one on request, or it's vague and repetitive month to month, the work likely isn't happening consistently.

    What's the difference between managed IT and just calling someone when something breaks?

    Managed IT is proactive, meaning patching, backup checks, and security reviews happen on a schedule regardless of whether anything looks wrong. Break-fix support only shows up after a problem exists, which is usually more expensive and more disruptive than catching issues early.

    How often should backups actually be tested, not just scheduled?

    Critical systems should have a test restore verified at least monthly, and any business-critical database or server should be checked more frequently. A backup that has never been restored successfully is unverified, regardless of how many green checkmarks show in the software.

    Is monthly patching risky for business systems?

    Unpatched systems are riskier than patched ones in almost every case, but patches should be tested or staged before wide deployment, especially on servers, to avoid compatibility issues. A responsible provider balances speed of patching against stability testing rather than skipping one for the other.

    What should I do if I find out my current provider has been skipping these tasks?

    Ask directly for documentation of the last few months of maintenance and get a written explanation for any gaps. If the answers are unsatisfying or the gaps are significant, it's worth getting a second opinion or a full IT audit before renewing any contract.

    Frequently Asked Questions

    How do I know if my IT provider is actually doing monthly maintenance?
    Ask for a written monthly report showing what was patched, backed up, and reviewed, with dates and specifics. If they can't produce one on request, or it's vague and repetitive month to month, the work likely isn't happening consistently.
    What's the difference between managed IT and just calling someone when something breaks?
    Managed IT is proactive, meaning patching, backup checks, and security reviews happen on a schedule regardless of whether anything looks wrong. Break-fix support only shows up after a problem exists, which is usually more expensive and more disruptive than catching issues early.
    How often should backups actually be tested, not just scheduled?
    Critical systems should have a test restore verified at least monthly, and any business-critical database or server should be checked more frequently. A backup that has never been restored successfully is unverified, regardless of how many green checkmarks show in the software.
    Is monthly patching risky for business systems?
    Unpatched systems are riskier than patched ones in almost every case, but patches should be tested or staged before wide deployment, especially on servers, to avoid compatibility issues. A responsible provider balances speed of patching against stability testing rather than skipping one for the other.
    What should I do if I find out my current provider has been skipping these tasks?
    Ask directly for documentation of the last few months of maintenance and get a written explanation for any gaps. If the answers are unsatisfying or the gaps are significant, it's worth getting a second opinion or a full IT audit before renewing any contract.

    Share this article

    You May Also Like