Skip to main content
Dig IT Solutions logo

Cyber Security

Why cyber security needs continuous monitoring, not periodic checks

Why an annual audit cannot protect a small business, what continuous security monitoring includes (EDR, identity alerts, patching, backups) and what it costs.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

Attackers work continuously and most breaches begin quietly, weeks before visible damage. An annual audit or quarterly scan only shows the state of your systems on that day. Continuous monitoring means EDR on every device, alerts on unusual sign-ins, measured patching, backups verified daily and someone acting on what is found, so compromise is caught in hours rather than months.

For years, cyber security in small businesses was treated like a boiler service: an engineer looks once a year, signs it off, and everyone forgets about it until the next visit. That approach made some sense when systems changed slowly and attacks were rare. It does not fit how attacks work now, and it is one of the reasons businesses that "had an audit last year" still find themselves rebuilding from backups.

This article explains why periodic checks leave gaps, what continuous monitoring actually consists of for a business of up to 250 people, and how to tell whether you have it.

An audit tells you about one day

A security audit, a vulnerability scan or a Cyber Essentials assessment gives you a picture of your systems on the date it was carried out. It is a valuable picture. It finds the open remote desktop port, the unsupported server, the six global administrators. But it is a snapshot, and everything of interest happens between snapshots.

A new vulnerability is published in a product you use. A member of staff joins, another leaves, a third starts using a personal laptop. A supplier's account is compromised and sends your accounts team a convincing invoice. An attacker who obtained a password from a leaked database logs in at 3am on a Saturday. None of that waits for the next review. The Cyber Security Breaches Survey shows that most businesses reporting incidents identify them through their own staff or systems noticing something odd, which only works if somebody, or something, is looking.

Attacks begin quietly and attackers are automated

The image of a cyber attack as a sudden event is mostly wrong. Ransomware operators typically gain access through a phished credential, a stolen VPN login or an unpatched service, then spend days or weeks inside the network mapping systems, escalating privileges, locating backups and copying data before they encrypt anything. During that period there are signs: a sign-in from an unfamiliar country, a new mailbox rule, a service account behaving unusually, a tool nobody installed appearing on a server. Each is small and each is missable by a person who is not watching. To an EDR platform or an identity alert, each is a flag.

On the other side, attackers do not work office hours or wait for your review. Scanners probe every internet address continuously. Scripts try leaked passwords against Microsoft 365 around the clock. Once a vulnerability is public, automated exploitation often starts within days. A business that checks its exposure quarterly is competing against adversaries that check it hourly.

What continuous monitoring actually includes

"Monitoring" is a vague word, and some providers use it to describe uptime pings. For an SME, meaningful security monitoring has six parts.

1. Endpoint detection and response (EDR) on every device. Unlike traditional antivirus, EDR watches behaviour: a process encrypting files rapidly, credentials being dumped from memory, a script launched from an email attachment. It can isolate the device from the network automatically, which is often the difference between one infected laptop and an encrypted file server. A managed response service behind it means a human investigates within a defined time, day or night. See EDR vs antivirus.

2. Identity and Microsoft 365 alerting. Sign-ins from impossible locations, repeated MFA failures, new inbox forwarding rules, mass downloads from SharePoint, new administrator roles, consent granted to unknown apps. Microsoft 365 generates these signals, someone has to receive and act on them.

3. Patch cadence with measurement. Not "updates are on" but a report every month showing every device, server and firewall against the 14-day requirement for critical patches that Cyber Essentials sets, with exceptions chased. Remote monitoring and management (RMM) platforms do this, they also flag devices that have not checked in, disks filling up and services that have stopped.

4. Backup verification. Daily confirmation that every backup job completed, that the offline or immutable copy is intact, and periodic test restores. A backup that silently failed three months ago is discovered during a ransomware incident unless someone is checking. See backup and disaster recovery.

5. Network and firewall visibility. Firmware currency, rule changes, unusual outbound connections, new devices appearing on the network, and confirmation that nothing has been opened to the internet "temporarily".

6. External exposure scanning. Regular automated checks of what your public addresses and domains expose: open ports, expired certificates, mail authentication (SPF, DKIM, DMARC) misconfigured, leaked credentials for your domain appearing in breach data.

Larger organisations add a security information and event management (SIEM) platform to collect and correlate logs from all of the above. Most businesses of up to 250 people do not need a SIEM to begin with, they need the six items above run properly by an accountable team, which is what proactive monitoring within a managed service is for.

Monitoring versus periodic checks

Periodic checksContinuous monitoring
What it showsThe state of controls on one dayWhat is happening every day
DetectsMissing controls, misconfigurationsActive compromise, drift, failures
Typical time to discover a breachWeeks to months, often via a customer or ransom noteHours, via an alert
Who does the workAn auditor or assessorTooling plus a responsible team
Cost patternOne-off feePer-device or per-user monthly
RoleSets the standard, finds structural gapsKeeps you at the standard, catches incidents

They are complementary. Monitoring without a periodic assessment never finds the open port. Assessment without monitoring never catches the 3am login.

Why one-time setup decays

A related mistake is treating security as a project with an end date: firewall installed, antivirus deployed, MFA rolled out, done. Every one of those controls degrades without attention. Firewall firmware falls behind. Antivirus licences lapse on a few machines. MFA gets an exception for a director, then for the accounts team. Staff join and are given access "the same as Sarah", accumulating rights nobody reviews. Backups are re-pointed during a server change and the offline copy quietly stops. Suppliers who were fine at onboarding suffer their own breaches. The threats change too: the phishing lure that staff were trained on two years ago has been replaced by QR codes and MFA prompt bombing.

Attackers exploit neglect far more often than clever design. Continuous management, meaning monitoring plus scheduled reviews of access, configuration, suppliers and training, is what keeps a good setup good. It is also what compliance increasingly expects: the ICO asks businesses to demonstrate ongoing appropriate security under UK GDPR, not a single historical assessment, and cyber insurers now ask about EDR and monitoring directly.

What it costs, and what it saves

Monitoring is priced per device and per user, and for an SME it typically sits inside a managed IT agreement rather than as a separate contract. Our cost calculator gives indicative per-device figures. Against that, consider that the difference between a monitored and an unmonitored ransomware incident is usually the difference between one isolated laptop reimaged in an afternoon and a week of downtime, a full rebuild and a conversation with the ICO.

How to check whether you have it

Ask your provider, or yourself, these questions.

  1. Is EDR installed on every device including servers, and who receives its alerts, within what hours?
  2. Would anyone know if a user's mailbox gained a forwarding rule tonight?
  3. Can you show me last month's patch compliance report, including the firewall?
  4. When did a backup job last fail, and how did you find out?
  5. What external services are exposed from our public IP addresses right now?
  6. If ransomware was detected on a Saturday, what happens, step by step?

If the answers are vague, the monitoring is probably nominal. Our comparison of IT support and cyber security contracts shows where monitoring should appear in a service schedule.

What to do next

An annual review is still worth doing, and if you have not had one recently our IT health check is the place to start: it establishes the baseline, and shows what monitoring is actually in place between reviews.

Frequently asked questions

What is continuous security monitoring?
It is the combination of tools and people that watch your systems all the time rather than at review points: endpoint detection and response on every device, alerts on unusual Microsoft 365 sign-ins and mailbox rules, patch compliance reporting, daily backup verification and firewall log review, with a named team responsible for investigating and responding to what those tools raise.
How is monitoring different from a security audit?
An audit is a snapshot: it tells you whether controls were in place on the day of the review. Monitoring tells you what is happening between audits, which is when attacks occur. You need both. The audit sets the standard and finds structural gaps, monitoring keeps you at that standard and catches the incidents the audit cannot see.
Is continuous monitoring only for large companies?
No. The tooling is now priced per device and per user, and managed IT providers deliver it for businesses of ten people. Small businesses arguably need it more, because they have no internal team to notice that something looks wrong, and because the same automated attacks hit them as hit large firms.
Does monitoring replace assessments and penetration tests?
No. Monitoring detects activity, it does not tell you that remote desktop is open to the internet or that a server is two years behind. Annual assessment against the Cyber Essentials controls, periodic vulnerability scanning and, for higher-risk firms, penetration testing remain necessary. Monitoring is what happens between them.
What tools are used for continuous monitoring in an SME?
Typically endpoint detection and response (EDR) with a managed response service, Microsoft 365 identity protection and sign-in alerting, a remote monitoring and management (RMM) platform for patch and device health, backup software with verification reports, and firewall logging. Larger environments add a SIEM to collect and correlate logs, but most SMEs do not need one to start.
Can a managed IT provider do the monitoring for us?
Yes, and for a business without internal IT it is the usual arrangement. Check that the contract names the tools, says who watches the alerts and within what hours, and describes what happens when something is detected. Monitoring that sends alerts to an unread mailbox is not monitoring.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us