You do not need to be an IT Director to run this check. You do not need a certification or a decade of experience or a rack full of monitoring tools.
You need ten minutes, something to write with, and the willingness to actually look.
This checklist is built for anyone who has responsibility for technology – whether that is a Tier 1 help desk tech, an accidental IT manager, a vCISO doing a weekly review, or a business owner who wants to understand what healthy looks like before something breaks. The goal is not deep-dive troubleshooting. The goal is rapid anomaly detection – finding the red flags that indicate a breach, an impending crash, or a failed safety net before they become a crisis.
Ten minutes. Four pillars. One simple question for each one: does anything look wrong?
|
FREE PRINTABLE TOOL The 10-Minute IT Pulse Check One page. Four pillars. Green / Yellow / Red status tracking. Print it, run it every week, and never get blindsided by a problem that was already trying to tell you something. ⬇ Download the Free One-Page Checklist PDF · Free · No sign-up required |
The Ground Rule Before You Start
If something is Yellow or Red during this check – do not fix it right now. Document it. Open a ticket. Flag it for the right person. Schedule a dedicated block to address it.
The purpose of this ten minutes is to look at the whole picture, not to dive into one corner of it and lose the rest. The check only works if you finish it.
|
1. Security & Perimeter – Target: 2 Minutes |
|
What you are checking: Are the castle walls holding and is there any sign you are already compromised? EDR or Antivirus Central Console Open your endpoint protection dashboard – SentinelOne, CrowdStrike, Microsoft Defender, whatever is in place. Look for unresolved alerts, malware detections from the past seven days, and devices showing as unmanaged or disconnected. An endpoint that dropped off the console is an endpoint you cannot see. Firewall and Edge Logs Scan the firewall dashboard for anomalies – traffic spikes that do not match the time of day, repeated blocked authentication failures on the same account or IP (brute force sign), and unusual outbound data transfers to destinations you do not recognize. MFA and Identity Check your identity provider – Microsoft Entra ID, Okta, Google Workspace – for flagged risky sign-ins or logins from unexpected geolocations. Someone logging in from your city at 9am and from another country at 9:15am is not a travel schedule. It is a compromised account. |
|
2. Servers & Core Infrastructure – Target: 3 Minutes |
|
What you are checking: Is the computing environment healthy and are core services running? Virtualization Host or Hypervisor Health Check your cluster dashboard (VMware vSphere, Hyper-V, Proxmox) for host resource exhaustion. CPU or RAM pinned near 100% is a warning, not normal. Also check for hardware alarms – failed power supplies, amber indicator lights, anything the system is already trying to surface. Storage and Datastores Flag any volume or datastore with less than 15% free space immediately. When a volume fills up, write failures follow. In a virtualized environment that means virtual machines crash mid-operation and snapshots corrupt. Fifteen percent is the line. Below it is a ticket. Core Services – Active Directory, DNS, DHCP Quick glance at directory service event logs. Look for replication errors, critical system failures, or anything in the error category that was not there last week. Active Directory replication failures are quiet until they are catastrophic – this is how you catch them early. |
|
3. Network & Connectivity – Target: 2 Minutes |
|
What you are checking: Is the highway clear and is traffic flowing the way it should? Switch and Router Status Open your network management tool – Cisco Meraki, Cisco DNA Center, UniFi. Look for offline switches, disconnected access points, and port errors. CRC errors on a specific port indicate bad cabling or a failing SFP module. They do not fix themselves. WAN and Internet Uplinks Review bandwidth utilization graphs for unusual saturation – traffic higher than normal for the time of day or week. Unexpected saturation can indicate a rogue internal process, a misbehaving device, or the early signs of a denial of service event. |
|
4. Business Continuity & Fail-Safes – Target: 3 Minutes |
|
What you are checking: If everything else fails right now, what saves the company? Backup Success Rates Open your backup console – Veeam, Datto, Acronis. Look at every backup job from the past seven days. Failed jobs, partial jobs, hung jobs – any of these is a ticket. As we covered in A Copy Is Not a Backup, a backup you have never verified is not a backup. It is a hope. This is the weekly moment where hope becomes confirmation. UPS and Power Infrastructure Check network-attached UPS units for healthy batteries, passed self-tests, and no environmental alerts – temperature warnings, humidity flags, bypass faults. A UPS with a failed battery will not protect anything when the power goes out. It will just fail quietly alongside everything else. |
The 10-Minute Documentation Template
The check only creates value if it is documented. Use this Green / Yellow / Red format every week. Keep it simple, scannable, and somewhere the right people can see it.
| System Pillar | Status | Notes and Action Items |
|---|---|---|
| Security and Edge | G / Y / R | e.g., 3 unresolved EDR alerts on workstations – isolation triggered, ticket opened |
| Compute and Storage | G / Y / R | e.g., SAN Volume 2 at 88% capacity – cleanup scheduled for Thursday |
| Network and Wireless | G / Y / R | e.g., Core stack healthy – SFP error on Switch 3 Port 24, replacement ordered |
| Backups and Power | G / Y / R | e.g., All VM backups successful – UPS self-test passed |
Green means it looked normal. Yellow means something is worth watching. Red means a ticket is already open and someone is on it.
That is the whole document. Four rows. Fifteen minutes of your Friday afternoon that may save the entire business from a Monday morning disaster.
|
FREE PRINTABLE TOOL The 10-Minute IT Pulse Check One page. Four pillars. Green / Yellow / Red status tracking. Print it, run it every week, and never get blindsided by a problem that was already trying to tell you something. ⬇ Download the Free One-Page Checklist PDF · Free · No sign-up required |
Why This Matters More Than It Looks
The businesses that get hit hardest by outages and breaches are almost never the ones where something catastrophic happened without warning. They are the ones where the warning was there – in a log nobody checked, in a backup console nobody opened, in a storage volume that crossed 15% six weeks ago and nobody noticed.
The 10-Minute Weekly Health Check is not a sophisticated security program. It is not a replacement for professional monitoring or a managed security provider. It is the minimum viable act of paying attention – the habit that turns invisible problems into documented ones before they become disasters.
Anyone responsible for technology can run this check. The Accidental Custodian. The IT Director. The vCISO on a weekly call. The business owner who wants to understand what their team should be looking at.
Ten minutes. Four pillars. Every week.
Look at the network. Write down what you see. Flag what is wrong before it becomes a crisis.
That is the whole thing.
Kelly Hansen is the author of The IT Dilemma: Why Good Businesses Fail During Cyberattacks, Outages, and Technology Disasters – and How to Prevent It. Learn more at theitdilemma.com.