The Helios blog

Running modern IT

Practical writing on patching, security, automation and the day-to-day of managing IT estates at scale, whether you run them for clients or for your own organisation. From the team building Helios.

★ Featured
Perspective 25 July 2026 · 7 min read

Do you still need an MSP? An honest answer from someone who runs one

An MSP contract always bundled tooling, expertise and accountability, and AI has just changed the middle one. Who genuinely no longer needs an MSP, who absolutely still does, and the test to hold any platform to.

Read the founder note →
Patch management 1 August 2026 · 6 min read

How fast should you patch? Faster than your rings allow

Exploits land in days while deployment rings add weeks of ritual to guard against a risk that is rare, loud and reversible. Why a ring nobody watches is just a queue, and the faster cadence to run instead.

Read article →
Security 31 July 2026 · 8 min read

IT offboarding checklist: how a leaver's account becomes a breach

Months after someone leaves, one of their accounts logs in. A post-mortem of the most common offboarding failure, traced to its root causes, and a three-pass checklist with a trigger, an owner and proof.

Read article →
Patch management 30 July 2026 · 4 min read

Why Windows updates fail: how to find the real cause

A failed Windows update is a symptom with about five common causes. How to tell full disks, reboot loops, broken components, stale update servers and absent machines apart, and the right fix for each one.

Read article →
Operations 29 July 2026 · 5 min read

MSP client offboarding checklist: how to lose a client well

Clients leave, and the way you exit is the story they tell for years. An annotated offboarding checklist in four phases: agree the exit, hand over the estate, remove your access completely, and close out with sign-off.

Read article →
Lean IT 28 July 2026 · 8 min read

One person IT department: how to make it work

One person can run IT for a hundred people, but not by heroics. A sustained argument for systems over firefighting, with the five obvious objections, staffing, standards, automation, security and holidays, met head on.

Read article →
Asset lifecycle 27 July 2026 · 8 min read

Hardware refresh cycles: how often to replace laptops, desktops and servers

Realistic lifespans by device class, the health and support signals that matter more than age, the Windows 11 long tail, and the budget maths that make a rolling refresh cheaper than running hardware into the ground.

Read article →
Microsoft 365 26 July 2026 · 6 min read

Microsoft 365 security checklist: the ten settings to fix first

A new tenant is configured for adoption, not safety. The ten settings to fix first, from MFA and legacy authentication to forwarding rules and offboarding, and how to stop them drifting back.

Read article →
Client management 25 July 2026 · 6 min read

MSP QBR guide: quarterly business reviews clients actually value

A QBR should prove value, surface decisions and set the next quarter, not read out ticket counts. A 45-minute agenda, the metrics worth showing, and how to prepare one without losing half a day.

Read article →
Service desk 24 July 2026 · 6 min read

MSP SLA response times: setting targets you can actually hit

Response is not resolution, and neither means anything undefined. Sensible response targets by priority, the triage matrix that keeps them honest, and the clock mechanics that quietly break SLA reporting.

Read article →
Operations 23 July 2026 · 7 min read

MSP client onboarding checklist: the first 30 days done properly

Contracts are rarely lost at the sales stage: they are lost in the first 30 days. A practical onboarding checklist covering discovery, agent rollout, baselining patching, protection and backups, and the 30-day review.

Read article →
Perspective 22 July 2026 · 7 min read

SMEs are not small enterprises: what the big IT tools keep getting wrong

A founder's view on the IT tooling market right now: why the big platforms are built for the biggest buyers, how SME needs genuinely differ from enterprise, and what the AI vibe-coding wave does and doesn't change.

Read the founder note →
Backup & continuity 22 July 2026 · 6 min read

Backup monitoring: why a green tick is not a restore

A successful backup job is not proof you can restore. The silent failure modes that stay green for months, the 3-2-1-1-0 rule, and a tiered restore-testing cadence that fits in a real working week.

Read article →
Monitoring 21 July 2026 · 6 min read

Alert fatigue in IT: how to cut alert noise without missing real incidents

Alert noise is a configuration problem, not a staffing problem. Where RMM noise really comes from, five changes that cut it at the source, and the three numbers that stop it growing back.

Read article →
Patch management 21 July 2026 · 6 min read

Third-party patching: why it is harder than Windows Update

Browsers, PDF readers and conferencing tools are where most breaches start, yet they patch on their own schedules. A practical look at third-party patching at scale, winget's sharp edges, and what real coverage requires.

Read article →