What Monthly IT Management Actually Covers: What Gets Checked

The short answer: Monthly IT management isn’t „someone you call when things stop working." It’s a recurring routine that runs even in a month when nothing broke: verifying that backups actually ran and can be restored, updating systems and firmware, monitoring disks, servers and the network, handling user requests, managing accounts and access rights, and keeping documentation current. An on-call IT guy deals with consequences; IT management watches the causes — and you’ll notice the difference on the day the server dies, the NAS gets encrypted, or an employee walks out with the admin password in their head.

When we ask companies who looks after their IT, the most common answer is: „We have a guy — when something doesn’t work, we call him.„ That’s a legitimate model, up to a certain size and a certain level of risk. The problem is that plenty of owners have no idea where that line sits, and even less idea what they should actually be getting for a monthly retainer. „IT management" sounds like a vague line item on an invoice.

This article clears that fog. We’ll walk through a concrete monthly checklist — what actually gets checked, why it gets checked, and what happens when nobody does it. We’re deliberately not discussing prices here; we’re discussing scope. Only once you know what management should include can you compare quotes against each other.

Two modes: on-call IT guy vs. ongoing management

Let’s name the difference first, because everything else follows from it.

An on-call IT guy is a reactive mode. The principle is „it broke → I call → they come out or connect remotely → they fix it." You pay for interventions; between interventions, nothing happens. Nobody checks the backups, nobody notices that disk space on the server is running low, nobody knows the NAS has been reporting a degraded array for three weeks.

Monthly IT management is a preventive mode. Most of the work happens when nothing is on fire: checks, updates, monitoring, small user requests. The goal is to make „it broke" happen as rarely as possible — and when it does happen, to have a backup, documentation and a plan for getting out of it.

The reactive model has one insidious property: it looks cheaper until something happens. But IT incidents don’t arrive at an even pace. You get a quiet year, and then a single encrypted server matches five years’ worth of retainer fees — not counting the downtime while the business stands still.

The monthly checklist: what actually gets watched

The specifics vary with company size, but the backbone is always the same. This is the checklist that anyone invoicing you for IT management should be able to document.

1. Backups: not that they run, but that they can be restored

The most important item, and the one most often skimped on. „We have backups" often means in practice that somebody once set up a backup job — and nobody has looked at it since. Backup software is perfectly capable of failing silently: a full target disk, a changed password on the network storage, a job disabled after an update, a backup running empty against a folder that was moved.

The monthly routine therefore covers two different things:

  • Verifying that backups ran — going through job reports, checking the age of the last backup for every protected machine and data set, checking free space at the destination.
  • Restore testing — regularly picking a file, a database or a whole machine and actually trying to bring it back from the backup. A backup nobody has ever restored anything from is just hoping.

That includes reviewing the architecture: whether the backup meets the 3-2-1 rule and whether there’s a copy that neither ransomware nor a power surge can reach. Why a single external drive sitting next to the computer isn’t a backup, we break down in detail in our article on the 3-2-1 rule and the external-drive anti-pattern. And that ransomware can encrypt a NAS along with the backups attached to it, we know from our own lab — we described it on a real case in our piece on ransomware on a NAS.

2. Updates: Windows is only the beginning

The second regular item. It isn’t just about „letting Windows update itself" — without oversight, updates get stuck, some machines stay months behind, and nobody knows about it.

What typically gets maintained over the course of a month:

  • Operating systems on workstations and servers — including verifying that updates really installed and that machines aren’t running a version that lost support long ago. A typical example from practice: support for Windows 10 ended in October 2025, and yet some companies are still running it — unpatched, with growing risk.
  • Firmware on network gear and storage — router, firewall, switches, Wi-Fi access points, NAS (Synology and QNAP release security patches on an ongoing basis, and an unpatched NAS exposed to the internet is a favourite target).
  • Third-party applications — browsers, PDF tools, accounting software, remote access clients.

An important part of this routine is risk management: critical security patches as soon as possible, large feature updates with careful judgement and a backup taken before the work, so a firmware update doesn’t take down a NAS holding live data.

3. Monitoring: knowing about a problem before the users do

The third pillar, and one the reactive model doesn’t have at all. Monitoring means that selected metrics are watched continuously by someone (or rather something), and the administrator gets an alert when something drifts:

  • Disk health — SMART attributes on disks in workstations, the server and the NAS. A dying disk usually announces itself in advance; it’s just that nobody reads it. How to spot it, we describe in our article on how to tell that an HDD is dying.
  • RAID array status — a degraded array on a NAS is exactly the state where the data still works, but one more failed disk means an outage and an expensive recovery. Without monitoring, the company finds out about the degradation only when the whole array collapses.
  • Free space — a full system disk on the server can bring accounting and email to a halt; a full backup target quietly stops backups.
  • Service availability — server, shared folders, website, VPN, printers.
  • Small operational details with large impact — domain and certificate expiry, UPS battery age, antivirus status on individual workstations.

The essence of monitoring fits in one sentence: a problem you hear about on Monday from monitoring is a service task; a problem you hear about on Friday from your accountant is an incident.

4. Incidents and user requests

Even in preventive mode, things break and people need help: the printer won’t work, a new laptop is needed for a starter, a folder was deleted by mistake and needs restoring, email needs setting up on a phone. The difference from the on-call IT guy isn’t that this work disappears — it’s how it’s organised:

  • requests are logged (helpdesk, email, phone) and don’t get lost,
  • they have an agreed priority and response time — „the warehouse is at a standstill„ gets a very different response speed than „my second monitor isn’t working",
  • recurring incidents lead to conclusions: when a third of all tickets come down to slow computers or Wi-Fi dropouts, that’s a prompt for a systemic fix, not for the thirtieth router reboot. We’ve written up the typical causes of a misbehaving wireless network in our overview of Wi-Fi problems and dropouts.

5. Accounts, access rights and security

An item that’s often missing from the list, yet carries the biggest security risk:

  • Onboarding and offboarding — a new employee gets an account and exactly the permissions they need; a departing one has their accounts disabled the same day. An active VPN account belonging to a former employee is a classic hole that only gets discovered after an incident.
  • Admin rights — a regular review of who holds local or domain admin and whether they really need it.
  • Multi-factor authentication — for email, VPN and cloud services (Microsoft 365, Google Workspace), two-factor is a baseline today, not a bonus.
  • Verifying protections — that antivirus or EDR is running on every workstation, reporting to the console, and hasn’t been „temporarily" switched off by anyone.

6. Documentation and records

The last regular item: a maintained network map, an inventory of devices and licences, an overview of accounts and securely stored passwords, a description of backups and restore procedures. It sounds dull, but documentation is exactly what decides whether replacing an administrator or resolving a night-time outage takes hours or weeks. When we take over IT from someone who „kept the documentation in their head", we start by mapping the actual state — what such mapping uncovers, we describe in our article on auditing a computer network and cabling.

When an on-call IT guy is enough

The honest answer: sometimes it genuinely is. The reactive model is defensible when most of the following holds:

  • you have a handful of computers and no server, no NAS and no shared live data,
  • a day of downtime doesn’t stop you — the computer is a tool, not the operation,
  • your data sits in the cloud with a major provider and you have its backup sorted,
  • nobody connects to you remotely and you hold no data whose leak would hurt.

But as soon as the company runs on shared data, accounting, a production or warehouse system, an e-shop or deadlines towards clients, the reactive model stops making sense — not because the IT guy is bad, but because nobody is doing the work between the phone calls. Backups, monitoring and access rights don’t get watched „while we’re at it". Either they’re someone’s regular responsibility, or they don’t happen.

A practical one-minute test: do you know right now when your key data was last backed up and who would be able to restore it? If the answer is „I’d have to ask", you also have your answer on whether the reactive mode is enough for you.

How to tell whether IT management is worth anything

Whether you’re sourcing IT management for the first time or already paying a retainer and want to know what you’re getting for it, ask about three things:

  1. What exactly gets checked at our place every month? The answer should look like the checklist above — backups including restore tests, updates including firmware, monitoring, accounts, documentation. „We look after your IT" is not an answer.
  2. How will I find out about problems? Good management has an output: an overview of what was handled that month, what monitoring caught and what we recommend next. When the only output is an invoice, you have no way of knowing whether anything is being done.
  3. What happens when something goes wrong? Agreed response times, a documented restore procedure, and clarity about who carries which responsibility.

That’s exactly how we build IT management for companies: first mapping the actual state, then an agreed scope — what we watch, how often, and what you’ll see in the report. If you’re not sure what state your IT is in today, there’s a no-obligation way to start: we’ll go through the checklist from this article with you point by point and tell you what you already have covered and where the gap is. Just get in touch.

FAQ: monthly IT management

What should monthly IT management include?

At a minimum: checking backups including restore tests, updating operating systems, applications and firmware, monitoring disks, servers, RAID arrays and services, handling user requests with an agreed response time, managing accounts and access rights, and maintaining documentation. The scope scales with company size; the backbone stays the same.

Is IT management worth it for a small company with a few computers?

It depends on what would bring you to a standstill. A company with five computers, no server, data in the cloud and no remote access often gets by with reactive support. As soon as you have shared live data, a NAS, accounting or operations that depend on IT, somebody needs to regularly watch backups, updates and access rights — and the reactive model can’t do that.

What’s the difference between IT management and IT support?

IT support (a helpdesk) is one component of management: handling user requests and incidents. IT management adds a preventive layer on top — backups, updates, monitoring, security, documentation — that is, the work that happens even when nobody reports anything, and thanks to which there are fewer incidents.

How do I check that our current administrator is doing their job?

Ask for three things: a backup report with the date of the last successful run and the last restore test, an overview of update status across all machines, and a sample from monitoring (what’s being watched and where alerts go). Anyone who doesn’t have these outputs is, with high probability, not watching backups and monitoring. An independent check is an audit — for the network, see our article on auditing a computer network.

Does the IT administrator have to sit in our office?

For small and medium-sized companies, no. Most of the routine — monitoring, updates, backup checks, account management — is done remotely; physical presence is needed for work on hardware and cabling. What matters is having an agreement on how quickly the administrator connects remotely and when they turn up on site.