Preventive IT maintenance: the monthly and quarterly checklist for an SMB
Preventive IT maintenance for businesses: the monthly and quarterly checklist for an SMB in Morocco (patches, backups, firmware, licences, UPS).

Preventive IT maintenance for an SMB fits in two lists: what you check every month (patches, backups, disk space, security alerts, accounts) and what you check every quarter (full restore test, network firmware, licence, warranty and certificate expiry dates, UPS units, access rights, documentation). Anything that can be watched automatically should be, continuously, by monitoring.
Most of the outages we come across during audits were entirely predictable: a disk that had been reporting errors for weeks, a failed backup nobody read, a certificate that expired on a Monday morning, a firewall licence that lapsed. Each would have been avoided by a check taking a few minutes. Here is the checklist we apply to SMB environments, in Morocco and elsewhere, whether maintenance is done in-house or by a provider.
Why a schedule rather than “when we have time”
Without a schedule, preventive maintenance is always the task that comes after today’s emergency. And since its effects are invisible, nobody notices it has stopped, until the outage. A written schedule, with an owner for each task and a record of each pass, changes that: you know what was done, when and by whom.
The principle is simple:
- Automate everything that can be: backup status, disks, services, security alerts.
- Schedule what needs a human: tests, reviews, decisions.
- Record every task in an intervention report or a monthly report.
The schedule in one table
| Task | Continuous | Monthly | Quarterly |
|---|---|---|---|
| Backup status (successes, failures) | Yes | Summary | |
| Restore test | One random file | One full machine or server | |
| Workstation and server patches | Yes | ||
| Firewall, switch, Wi-Fi firmware | Check security advisories | Planned update | |
| Disk space and disk health (SMART, RAID) | Yes | Trend | |
| Antivirus / EDR alerts | Yes | Summary | |
| Inactive accounts and leavers | Yes | Full rights review | |
| Licences, warranties, certificates | Expiries this quarter | Full review | |
| UPS units | Alerts | Runtime test, battery condition | |
| Documentation | Updated with each change | Full review |
Every month: the checklist
Security patches
- Apply the month’s patches to workstations, first on a small pilot group, then to all.
- Apply server patches in an announced maintenance window, after a successful backup.
- List the machines that did not receive patches (switched off, off network, failed) and deal with them.
- Identify systems and software that no longer receive vendor updates.
Backups
- Read the month’s summary: did each job succeed, and if not, why?
- Restore a randomly chosen file and check that it opens.
- Check that the off-site copy is up to date.
A “backup successful” message proves nothing until a restore has been tested. Our method for testing a backup restore explains how.
Disks and capacity
- Check free space on servers, shares and backup storage, and its trend.
- Check disk health (SMART indicators) and RAID arrays: a degraded disk in a RAID must be replaced without waiting for the second one to fail.
Security and accounts
- Read antivirus or EDR alerts and check they were handled.
- Disable the accounts of people who left during the month, including in cloud applications.
- Identify accounts without MFA and inactive accounts.
Every quarter: the checklist
Full restore test
Restore a full machine or server, ideally in an isolated environment, and time it. It is the only way to know whether your recovery time is realistic. For virtual machine backups, see our Veeam best practices.
Network equipment firmware
- Compare firewall, switch and access point versions with the versions recommended by the manufacturer.
- Plan the update with a prior configuration backup and a rollback plan.
- Also follow security advisories continuously: a critical flaw on an internet-facing firewall or VPN does not wait for the end of the quarter.
Licences, warranties and certificates
- List expiry dates for the next six months: firewall security subscriptions, Microsoft 365 licences, backup software, antivirus or EDR, domain names.
- Check warranties and manufacturer support for servers and network equipment.
- Check certificate expiry dates (website, email, VPN, internal applications) and automatic renewal where it exists.
An expired security subscription can silently disable protections: we explain this for Fortinet in our article on FortiGate licence renewal.
UPS units
- Check battery condition and the date they were last replaced.
- Test runtime and the clean shutdown of servers during an extended power cut.
- Check that UPS alerts actually reach someone.
Access rights
- Review the list of administrators: is each privileged account named and justified?
- Review access to sensitive shares (finance, HR, management).
- Check access for external providers and remove what is no longer used.
Documentation
- Update the inventory (workstations, servers, network equipment, licences).
- Update the network diagram and recovery procedures.
- Check that administrator credentials are stored in a password vault, not in a shared file.
Common mistakes
- Updating without a prior backup: a patch that fails on a server with no recent backup becomes an incident.
- Forgetting the network: workstations and servers are patched, but the firewall runs old firmware.
- Never testing restores: the most important task and the one most often skipped.
- Tracking expiry dates from memory: licences and certificates always expire at the worst moment.
- Recording nothing: without a report, there is no way to know whether maintenance is being done.
From checklist to 24/7 monitoring
A manual checklist has a limit: between two passes, nobody is watching. A disk can fill up on a Friday evening, a backup can fail three nights in a row, a service can stop over the weekend. That is the role of monitoring: continuously watching servers, backups, disks, firewalls and internet links, and raising an alert at the slightest deviation.
The right setup combines both: 24/7 monitoring continuously detects drift, and preventive maintenance handles what no alert reports (tests, reviews, decisions). The monthly report ties it all together; our article on IT monitoring KPIs explains what it should contain.
Summary checklist
- Monthly patches applied, failed machines dealt with.
- Backups reviewed, one file restored, off-site copy up to date.
- Disk space, SMART and RAID checked.
- Security alerts handled, leavers’ accounts disabled.
- Every quarter: full restore, timed.
- Every quarter: network firmware checked and updated.
- Every quarter: licence, warranty and certificate expiry dates listed.
- Every quarter: UPS units tested, administrator rights reviewed.
- Documentation and inventory up to date.
How we do it
At ALLSAFE SOLUTIONS, preventive maintenance is included in our managed IT services contracts. We start with a free initial audit to build the inventory and assess backups, then set up 24/7 monitoring of critical equipment and a written preventive schedule. Critical incidents are handled in under 15 minutes, other requests get a reply within 24 business hours, and every month a report shows what was done. For backups, we rely on our backup and business continuity offer and on our partners Veeam, Fortinet and Microsoft.
If you are comparing providers, our article on the IT maintenance contract explains what it should cover. Examples of our work are in our case studies.
Not sure when your last restore was tested? Request your free audit: we review your equipment and hand you a maintenance schedule that fits.
Frequently asked questions
What is preventive IT maintenance?
It is the set of scheduled tasks that prevent outages and security incidents: patches, backup checks and restore tests, firmware updates, disk monitoring, account reviews, tracking of licences, certificates and UPS units, and keeping documentation up to date.
How often should preventive maintenance be done on IT equipment?
Some checks are continuous (monitoring of backups, disks and alerts), some monthly (patches, accounts, report), others quarterly (full restore test, firmware, expiry dates, UPS units, documentation). The exact schedule depends on how critical each device is.
Should updates be installed as soon as they are released?
Critical security patches should be applied quickly, especially on internet-facing devices such as the firewall or VPN. For servers and business applications, test first on a pilot group, with a recent backup and an announced maintenance window.
Does 24/7 monitoring replace preventive maintenance?
No, they complement each other. Monitoring continuously detects drift (a disk filling up, a failed backup, a stopped service). Preventive maintenance handles what no alert reports: restore tests, rights reviews, expiry dates, documentation.
About the editorial team
ALLSAFE SOLUTIONS
Network, security and cloud engineers
Written by the engineering team at ALLSAFE SOLUTIONS, a managed IT provider founded in Casablanca by network, security and cloud engineers. Our articles draw on the projects we deliver for clients in Morocco and abroad.
LinkedIn









































