Why ‘Set and Forget’ Is the Most Dangerous Phrase in Modern IT

Set-and-forget is dangerous because systems drift, patches lapse and threat vectors change; leaving tools like Microsoft 365 Defender or an on-prem server unreviewed turns controls into stale liabilities. Regular maintenance, monitoring and a named owner stop small misconfigurations becoming major breaches.

Many UK firms deploy services, enable defaults and then treat them as ‘done’. That quiet negligence is where problems start: expired certificates, unattended accounts and unpatched endpoints all accumulate risk until an attacker finds an easy route in. The practical takeaway is simple — the work is ongoing, not a one-off.

Action 1 — Make ownership, cadence and patching non-negotiable

Assign a named person or team to each system and give them a clear calendar. Named ownership means someone is responsible when updates fail, alerts pile up or a configuration drifts away from baseline. For many SMEs that owner will be an internal IT lead or an external supplier with a documented SLA. Without that single point of accountability, tasks fall between people and months pass without checks.

Concrete steps to implement this today:

  • Pick a named owner for each critical system (email, file storage, domain controllers).
  • Set a recurring review: at minimum, run a configuration and patch review every 30 days.
  • Automate critical patching where safe (Windows Update for Business, managed M365 updates) and log exceptions in a simple register.
  • Treat exceptions as incidents: assign an owner, a remediation deadline and document why it’s deferred.

For general hardening principles see the NCSC’s practical collections on basic cyber hygiene (ncsc.gov.uk/10-steps-to-cyber-security), which reinforce assigning responsibility and scheduling regular checks.

Action 2 — Test, monitor and verify that controls still work

Controls that were effective at deployment can stop working without anyone noticing. Add measurement and testing to ownership: monitoring, restore tests and friction-free alerting turn hidden failures into visible tasks. Verify that backups restore, MFA blocks unauthorised access and that mail filters still quarantine threats — don’t assume they do.

Practical routines that scale for a 10–200 person firm:

  • Automated alerts: configure admin alerts for failed updates, new admin accounts and privileged-access changes; review high-priority alerts weekly.
  • Backup restores: run a restore test from backups at least twice a year and after any major change.
  • Tabletop and simulated checks: run a short tabletop incident drill quarterly and a focused phishing simulation twice a year.
  • Third-party checks: schedule an external configuration review or vulnerability scan annually or after significant change.

If you lack internal resource, move monitoring to a managed detection provider or retain an MSP for scheduled checks — the cost of a subscription is usually lower than the bill for an avoidable breach and the downtime it causes.

Related reading

FAQ

How often should I check Microsoft 365 or mail filter settings?

Review admin alerts weekly and run a configuration and policy check at least every 30 days; address critical findings within 72 hours where possible.

Can small budgets still avoid ‘set and forget’ mistakes?

Yes; automate patches, assign a named owner and use a modest outsourced monitoring service to cover gaps — you don’t need a big team, just predictable processes.

If I inherit an old server, what’s the quickest fix to reduce risk?

Isolate it from the public network, apply critical OS patches, enable MFA on associated accounts and schedule migration or decommissioning within 7 days.

Will an annual penetration test be enough to prevent issues?

No; pair an annual external test with continuous monitoring and configuration reviews at least quarterly to catch configuration drift between tests.

Take one action this week: pick one critical system, name its owner and add a 30-day recurring review to the calendar. That single change reduces exposure, saves time later and buys you breathing space to plan bigger improvements.