Every business does a year-end review of the numbers. Far fewer do one for security, and that’s a shame, because the same few gaps turn up in almost every business at this point in the year: an old account that never got switched off, a backup nobody has tested, a renewal that rolls over unnoticed.
The good news is that a proper check takes an afternoon, not a project. Here are the five things worth reviewing before January.
Why Do This Now, Not in January
December is busy and quiet at the same time. Staff take leave, projects wind down, and attention drifts to the break. Then January arrives with its own pile of priorities, and the security review slips to February, then March.
Doing it in October or November means you can fix things while people are still around to answer questions, and you start the new year with a clean slate rather than a list of loose ends.
1. Leavers: Has Everyone Who Left Actually Been Switched Off?
Over a year, people come and go. Contractors finish, staff move on, temporary cover ends. Each of them had accounts, and each of those accounts is worth checking.
Look at your user list and ask a simple question for every name: is this person still with us? Then check beyond the main login. Shared mailboxes, cloud apps, remote access, mobile devices and any apps nobody remembers signing up for can all outlive someone’s last day.
2. Access: Does Everyone Still Need What They Have?
People change roles, and their access rarely changes with them. Over time, someone who moved from finance to operations can still be holding permissions from both.
A quick review of who can see what, especially financial systems, client data and admin rights, usually turns up a handful of things to tidy. The goal is simple: each person has what they need for their current job, and nothing more.
3. Backups: Have You Ever Actually Tested One?
Most businesses have backups. Far fewer have checked that they can restore from them. A backup that has been quietly failing for months looks exactly like a working one until the day you need it.
Pick a file, a folder or a system and try a real restore. Check how long it takes and whether the result is what you expected. It’s a small test that tells you more than any dashboard, and it connects directly to what downtime actually costs if recovery turns out to be slower than you assumed. The NCSC has practical guidance on backing up your data if you want a reference point.
4. MFA: Is It On Everywhere It Should Be?
Multi-factor authentication is one of the most effective protections available, and one of the most commonly left half finished. It tends to get switched on for email and a couple of key systems, then never revisited.
Go through your list of systems that hold sensitive data, money or customer information, and confirm MFA is actually enabled on each one. Pay particular attention to admin accounts and anything accessed remotely.
5. Renewals: What’s About to Roll Over Without a Second Look?
Licences, support contracts, domains, certificates and subscriptions all have renewal dates, and plenty of them land in December or January. Some roll over automatically, which is convenient until you realise you’re paying for seats nobody uses, or a service that no longer fits.
List what’s renewing in the next three months and check each one. There are some questions worth asking before renewing any IT contract, and a good number of them apply just as well to software and subscriptions. Expiring certificates and domains are worth a particular look, because they tend to cause problems at the least convenient moment.
The Bottom Line
None of these checks is complicated, and none needs new tools. They are the everyday housekeeping that keeps a business tidy and protected, and it all comes back to fixing the basics first. Do them once a year, ideally before the break, and you head into January knowing where you stand.
If you’d like a second pair of eyes, our free security audit gives you a clear, no-obligation picture of where your business sits today. You can also explore our cybersecurity solutions or get in touch with the team at Gardner Systems to talk it through.
