- Why Monthly Is the Right Cadence
- What Should Be Monitored Every Month
- What Should Be Patched Every Month
- What a Monthly Report Should Include
- What This Looks Like for a Small Business Without IT Staff
- The Difference Between Reactive and Managed Security
- Frequently Asked Questions
Most small businesses don't find out their network had a gap until something breaks. A ransomware infection, a locked server, an employee who clicked the wrong link — these aren't random events. They're the result of things that weren't monitored or patched when they should have been.
If you're working with a managed service provider, or trying to decide whether to, this article covers what good network security services actually look like month to month. Not in theory — in practice.
Why Monthly Is the Right Cadence
Security isn't a one-time setup. Threats evolve, vendors push patches constantly, new devices get added to your network, and staff turn over. Every one of those changes creates a potential opening.
A monthly rhythm gives your MSP enough frequency to catch problems before they compound. Some tasks run continuously — 24/7 monitoring never stops — but monthly reviews are where patterns surface and decisions get made.
What Should Be Monitored Every Month
Network Traffic and Anomaly Detection
Your MSP should know what's moving across your network. A device sending large amounts of data at 2 a.m., or a workstation contacting an unfamiliar server — these are often the first signs of a compromise.
This isn't someone staring at a screen. It's automated monitoring with alerts that route to a human who investigates. If your MSP can't tell you what triggered an alert last month, that's worth asking about.
Endpoint Activity
Every computer, laptop, tablet, and phone on your network is a potential entry point. Endpoint Detection and Response (EDR) tools watch device behavior in real time and flag anything suspicious. They should be running on every managed device, and your MSP should review those alerts monthly — with a summary of what was flagged and how it was handled.
Firewall Logs and Rule Sets
A firewall controls what traffic is allowed in and out of your network. Over time, rules accumulate. Rules added for a specific project or vendor often never get removed, and they can leave doors open that should have been closed long ago.
Monthly log reviews catch unusual connection attempts. Periodic rule audits clean up the clutter. Your MSP should be doing both.
Backup Integrity
Backups are your last line of defense against ransomware. But a backup that's never been tested isn't a backup — it's a hope.
Every month, your MSP should verify that backups completed successfully, that files aren't corrupted, and that a recovery test has been run recently. If you've never seen a documented restore test, ask for one.
User Account Activity
Accounts that belong to former employees are one of the most common and preventable security gaps. A login that was never deactivated after someone left can be used by anyone who has those credentials.
Monthly account audits should confirm that terminated employees are removed, dormant accounts are disabled, and no one has more access than they actually need.
Patch Status Across All Devices
Software vulnerabilities are discovered constantly, and vendors release patches on a regular schedule. Microsoft, for example, pushes security updates every second Tuesday of the month — commonly called Patch Tuesday.
Critical patches should go out within days of release, not weeks. A monthly patch status report should show you which devices are current, which are pending, and whether anything was skipped and why.
What Should Be Patched Every Month
Operating System Updates
Windows, macOS, and Linux all receive regular security updates. These aren't optional. Unpatched operating systems are the single most common entry point for network attacks, and your MSP should be deploying OS patches across all managed devices on a defined schedule — typically within 7 days for critical patches, 30 days for standard updates.
Third-Party Applications
The OS is only part of the picture. Web browsers, PDF readers, productivity suites, and line-of-business software all need patching too. Many attacks specifically target third-party applications because organizations patch the operating system and forget everything else.
A good MSP maintains an inventory of installed software and patches it on the same schedule.
Network Devices
Routers, switches, and wireless access points run firmware — software embedded in the hardware. Firmware vulnerabilities are real and often overlooked because these devices sit in a closet and work quietly until they don't.
Monthly firmware checks on network hardware should be standard in any managed network security service.
Email Security Configuration
Email is still the most common delivery method for phishing and malware. SPF, DKIM, and DMARC are authentication standards that verify emails claiming to come from your domain actually did. Without them, attackers can send convincing fake messages that appear to be from you or your staff.
Your MSP should confirm these are configured correctly and review email filtering logs monthly for patterns that suggest your organization is being targeted.
What a Monthly Report Should Include
If your MSP isn't sending you a monthly report, ask for one. It doesn't need to be long, but it should cover:
- Patches applied and devices updated
- Alerts triggered and how they were resolved
- Backup completion status and any failed jobs
- User account changes made during the month
- Any open vulnerabilities and the plan to address them
This report is your documentation that work was done. It also protects you in the event of an audit or an insurance claim after an incident.
What This Looks Like for a Small Business Without IT Staff
Most small businesses in Coos Bay and across Coos County don't have a dedicated IT person. That's exactly who managed network security services are built for.
You shouldn't need to understand firewall rule sets or know what EDR stands for to have a secure network. You need a team that handles all of it and communicates what matters in plain language.
At Epuerto, that's how it works. Monitoring runs continuously. Patches go out on schedule. Backups get tested. And if something needs your attention, you hear about it directly — not through a ticket queue routed to a national call center.
The goal is straightforward: your network stays secure, and you stay focused on running your business.
The Difference Between Reactive and Managed Security
Reactive IT means you call someone when something breaks. Managed security means problems get caught before they break anything.
The monthly monitoring and patching cycle described above is what separates the two. It's not glamorous work, but it's the work that keeps a ransomware attack from becoming a business-ending event.
For a business with 5 to 15 employees and no IT staff, the cost of managed network security services is a fraction of what a single incident costs — in downtime, recovery, and lost trust.
Frequently Asked Questions
What does a managed service provider actually do for network security?
An MSP monitors your network continuously, applies software and firmware patches on a regular schedule, manages your firewall, verifies backups, and responds to security alerts. The goal is to prevent incidents rather than react to them after the fact.
How often should patches be applied to business computers?
Critical security patches should be applied within 7 days of release. Standard updates typically follow a 30-day cycle. Operating systems, third-party applications, and network device firmware all need to be included — not just Windows updates.
What is EDR and why does my business need it?
EDR stands for Endpoint Detection and Response. It's software installed on each device that monitors behavior in real time and flags anything suspicious — like a program trying to encrypt files or reach an unknown server. It's a layer of protection that goes beyond traditional antivirus.
What happens if my MSP doesn't test backups?
An untested backup may not restore correctly when you actually need it. Backup files can become corrupted, jobs can fail silently, and recovery processes can break under real conditions. Monthly verification and periodic restore tests confirm your backups will actually work.
How do I know if my current MSP is doing these things?
Ask for a monthly report. It should document patches applied, alerts triggered and resolved, backup status, and user account changes. If your MSP can't produce that documentation, the work may not be getting done.
What's the risk of leaving old employee accounts active?
Former employee credentials can be used to access your systems, email, or files long after someone leaves. Attackers specifically look for dormant accounts because they tend to attract less scrutiny. Monthly account audits eliminate this exposure.
Does my small business really need all of this?
Yes. Attackers don't target businesses based on size — they target based on vulnerability. A small business with unpatched software and no monitoring is easier to compromise than a larger one with active security in place. Managed network security services are sized and priced for businesses without dedicated IT staff.
If you're ready to get your network properly monitored and protected, Epuerto handles it all — locally, fully managed, with no tech team required on your end. Let's talk.