Nobody schedules a dental check-up because their teeth fell out. They go once a year so that small problems get caught while they are still small, cheap, and painless to fix. IT is exactly the same, and almost nobody treats it that way. Most businesses only look closely at their technology on the day it stops working, which is the single most expensive moment to discover that the backups were never running.

Almost every IT disaster gives weeks or months of warning. The outage is not the start of the problem, it is the moment the problem finally became impossible to ignore. A health check is just listening to the warnings on purpose.

You do not need to be technical to run one, and you do not need to do it more than once a year. You need a checklist, an honest afternoon, and the willingness to write down the answer even when it is uncomfortable. Here is the round we walk clients through.

1. Backups, and proof they actually work

This is first because it is the one that ruins businesses. The question is not "do we have backups?", because almost everyone believes they do. The questions are sharper: when did a backup last complete successfully, when did anyone last restore from one to check it works, and is a copy kept somewhere that a fire, a theft, or ransomware could not reach? A backup nobody has ever tested is not a backup, it is a hope. Test a restore once a year and you will sleep differently. We unpack the full picture in Disaster Recovery: What Happens the Day Your Server Dies.

2. The security basics

You are not auditing for a state-sponsored hacker. You are checking that the ordinary doors are locked, because that is what stops the overwhelming majority of incidents. Walk through the essentials:

If any of that felt shaky, our Cybersecurity Basics piece is the plain checklist to fix it.

3. The single points of failure

Every business has them, the thing that, if it died on a Tuesday, would stop the whole operation. Sometimes it is a server humming in a cupboard with no spare. Sometimes it is a person, the only one who knows the password, the process, or how the system is held together. Name them out loud. You cannot remove every single point of failure, but you can stop being surprised by the ones you have, and quietly fix the cheap ones before they pick their own moment.

The day your server dies is a terrible day to learn how your server works. The whole purpose of a yearly check is to have that conversation on a calm afternoon instead of a chaotic morning.

4. Licences, subscriptions, and quiet bleed

Money leaks out of IT in two directions, and a yearly look catches both. On one side, you are paying for software seats nobody uses, trials that became subscriptions, and tools two departments bought separately to do the same job. On the other, you are running something on a licence that has lapsed or a version that is no longer supported, which is a risk dressed up as a saving. Pull the list of everything you pay for monthly, put a name next to each one, and cancel the orphans. It usually pays for the health check several times over.

5. The hardware and its age

Computers, servers, and network gear do not last forever, and they tend to fail in clusters because they were all bought at the same time. Keep a simple list: what you have, how old it is, and what it would cost and how long it would take to replace. The goal is not to replace everything on a schedule, it is to never be caught completely flat-footed when something gives out. Knowing a machine is on borrowed time turns an emergency into a planned purchase.

6. Documentation and the bus test

If the person who set up your systems walked out tomorrow, could anyone else keep them running? For most businesses the honest answer is no, and that is a quiet emergency nobody is treating as one. You do not need a manual for everything. You need the critical things written down: where things are, how they connect, what the key passwords protect, and who to call. We make the case for this in What Good Software Documentation Actually Looks Like, and it is the cheapest insurance you will ever buy.

Write down the answer, even the ugly ones

The value of a health check is not in nodding along, it is in the written record. For each item, note the honest status, who owns the fix, and a rough deadline. A check that produces a one-page list of "here is what is fine, here is what needs attention, here is who is on it" is worth ten that produce a vague feeling of "we should probably look at that sometime".

Once a year, on a calm day

None of this is exotic, and that is exactly why it gets skipped, there is always something more urgent than the thing that is not yet on fire. But the businesses that run a simple yearly check are not the ones you find frozen on a Monday morning, calling around for someone, anyone, who can recover a server they did not know was the only one. An afternoon a year, a short list, and the discipline to act on it. That is the whole discipline, and it is the difference between IT that quietly works and IT that quietly waits to ambush you.