Cyber Security
Why cyber security needs continuous monitoring, not periodic checks
Why an annual audit cannot protect a small business, what continuous security monitoring includes (EDR, identity alerts, patching, backups) and what it costs.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
Attackers work continuously and most breaches begin quietly, weeks before visible damage. An annual audit or quarterly scan only shows the state of your systems on that day. Continuous monitoring means EDR on every device, alerts on unusual sign-ins, measured patching, backups verified daily and someone acting on what is found, so compromise is caught in hours rather than months.
For years, cyber security in small businesses was treated like a boiler service: an engineer looks once a year, signs it off, and everyone forgets about it until the next visit. That approach made some sense when systems changed slowly and attacks were rare. It does not fit how attacks work now, and it is one of the reasons businesses that "had an audit last year" still find themselves rebuilding from backups.
This article explains why periodic checks leave gaps, what continuous monitoring actually consists of for a business of up to 250 people, and how to tell whether you have it.
An audit tells you about one day
A security audit, a vulnerability scan or a Cyber Essentials assessment gives you a picture of your systems on the date it was carried out. It is a valuable picture. It finds the open remote desktop port, the unsupported server, the six global administrators. But it is a snapshot, and everything of interest happens between snapshots.
A new vulnerability is published in a product you use. A member of staff joins, another leaves, a third starts using a personal laptop. A supplier's account is compromised and sends your accounts team a convincing invoice. An attacker who obtained a password from a leaked database logs in at 3am on a Saturday. None of that waits for the next review. The Cyber Security Breaches Survey shows that most businesses reporting incidents identify them through their own staff or systems noticing something odd, which only works if somebody, or something, is looking.
Attacks begin quietly and attackers are automated
The image of a cyber attack as a sudden event is mostly wrong. Ransomware operators typically gain access through a phished credential, a stolen VPN login or an unpatched service, then spend days or weeks inside the network mapping systems, escalating privileges, locating backups and copying data before they encrypt anything. During that period there are signs: a sign-in from an unfamiliar country, a new mailbox rule, a service account behaving unusually, a tool nobody installed appearing on a server. Each is small and each is missable by a person who is not watching. To an EDR platform or an identity alert, each is a flag.
On the other side, attackers do not work office hours or wait for your review. Scanners probe every internet address continuously. Scripts try leaked passwords against Microsoft 365 around the clock. Once a vulnerability is public, automated exploitation often starts within days. A business that checks its exposure quarterly is competing against adversaries that check it hourly.
What continuous monitoring actually includes
"Monitoring" is a vague word, and some providers use it to describe uptime pings. For an SME, meaningful security monitoring has six parts.
1. Endpoint detection and response (EDR) on every device. Unlike traditional antivirus, EDR watches behaviour: a process encrypting files rapidly, credentials being dumped from memory, a script launched from an email attachment. It can isolate the device from the network automatically, which is often the difference between one infected laptop and an encrypted file server. A managed response service behind it means a human investigates within a defined time, day or night. See EDR vs antivirus.
2. Identity and Microsoft 365 alerting. Sign-ins from impossible locations, repeated MFA failures, new inbox forwarding rules, mass downloads from SharePoint, new administrator roles, consent granted to unknown apps. Microsoft 365 generates these signals, someone has to receive and act on them.
3. Patch cadence with measurement. Not "updates are on" but a report every month showing every device, server and firewall against the 14-day requirement for critical patches that Cyber Essentials sets, with exceptions chased. Remote monitoring and management (RMM) platforms do this, they also flag devices that have not checked in, disks filling up and services that have stopped.
4. Backup verification. Daily confirmation that every backup job completed, that the offline or immutable copy is intact, and periodic test restores. A backup that silently failed three months ago is discovered during a ransomware incident unless someone is checking. See backup and disaster recovery.
5. Network and firewall visibility. Firmware currency, rule changes, unusual outbound connections, new devices appearing on the network, and confirmation that nothing has been opened to the internet "temporarily".
6. External exposure scanning. Regular automated checks of what your public addresses and domains expose: open ports, expired certificates, mail authentication (SPF, DKIM, DMARC) misconfigured, leaked credentials for your domain appearing in breach data.
Larger organisations add a security information and event management (SIEM) platform to collect and correlate logs from all of the above. Most businesses of up to 250 people do not need a SIEM to begin with, they need the six items above run properly by an accountable team, which is what proactive monitoring within a managed service is for.
Monitoring versus periodic checks
| Periodic checks | Continuous monitoring | |
|---|---|---|
| What it shows | The state of controls on one day | What is happening every day |
| Detects | Missing controls, misconfigurations | Active compromise, drift, failures |
| Typical time to discover a breach | Weeks to months, often via a customer or ransom note | Hours, via an alert |
| Who does the work | An auditor or assessor | Tooling plus a responsible team |
| Cost pattern | One-off fee | Per-device or per-user monthly |
| Role | Sets the standard, finds structural gaps | Keeps you at the standard, catches incidents |
They are complementary. Monitoring without a periodic assessment never finds the open port. Assessment without monitoring never catches the 3am login.
Why one-time setup decays
A related mistake is treating security as a project with an end date: firewall installed, antivirus deployed, MFA rolled out, done. Every one of those controls degrades without attention. Firewall firmware falls behind. Antivirus licences lapse on a few machines. MFA gets an exception for a director, then for the accounts team. Staff join and are given access "the same as Sarah", accumulating rights nobody reviews. Backups are re-pointed during a server change and the offline copy quietly stops. Suppliers who were fine at onboarding suffer their own breaches. The threats change too: the phishing lure that staff were trained on two years ago has been replaced by QR codes and MFA prompt bombing.
Attackers exploit neglect far more often than clever design. Continuous management, meaning monitoring plus scheduled reviews of access, configuration, suppliers and training, is what keeps a good setup good. It is also what compliance increasingly expects: the ICO asks businesses to demonstrate ongoing appropriate security under UK GDPR, not a single historical assessment, and cyber insurers now ask about EDR and monitoring directly.
What it costs, and what it saves
Monitoring is priced per device and per user, and for an SME it typically sits inside a managed IT agreement rather than as a separate contract. Our cost calculator gives indicative per-device figures. Against that, consider that the difference between a monitored and an unmonitored ransomware incident is usually the difference between one isolated laptop reimaged in an afternoon and a week of downtime, a full rebuild and a conversation with the ICO.
How to check whether you have it
Ask your provider, or yourself, these questions.
- Is EDR installed on every device including servers, and who receives its alerts, within what hours?
- Would anyone know if a user's mailbox gained a forwarding rule tonight?
- Can you show me last month's patch compliance report, including the firewall?
- When did a backup job last fail, and how did you find out?
- What external services are exposed from our public IP addresses right now?
- If ransomware was detected on a Saturday, what happens, step by step?
If the answers are vague, the monitoring is probably nominal. Our comparison of IT support and cyber security contracts shows where monitoring should appear in a service schedule.
What to do next
An annual review is still worth doing, and if you have not had one recently our IT health check is the place to start: it establishes the baseline, and shows what monitoring is actually in place between reviews.

