End of financial year is a natural point to review business records, accounts and suppliers. It is also a useful time to check whether old staff, devices or software still have access to your systems.
These seven checks can become part of the same annual process. Security still needs attention throughout the year, but a scheduled review helps stop small gaps from being forgotten.
1. Install supported updates
Check operating systems, browsers, business applications, routers and other network equipment. Turn on managed automatic updates where they suit the system, then confirm they are actually completing.
Plan to replace software or equipment that no longer receives security updates.
2. Review user access
Compare current staff and contractors with the accounts in Microsoft 365, cloud services and business applications. Disable accounts that are no longer needed.
Check who has administrator access and remove it from people who do not need it for their role.
3. Check backups and test a restore
Confirm that important files, email and business systems are included in the backup. Check recent reports for failures and make sure the backup is kept separately from the main system.
Test a restore and record the result. A successful job report does not prove that the right information can be recovered.
4. Replace reused passwords
Important accounts should each have a long, unique password. A business password manager can create and store them without relying on a shared spreadsheet or one person's memory.
Change passwords that have been shared too widely and remove old recovery email addresses or phone numbers.
5. Turn on multi-factor authentication
Require more than a password for email, administrator accounts, remote access and important cloud services.
Check coverage for every user. Turning it on for the owner while other accounts remain unprotected leaves a gap.
6. Review email and payment checks
Confirm that spam and impersonation protections are configured and monitored. Remind staff to report unusual links, attachments and login pages.
Every request to change bank details should be checked using a phone number already held in the business's records, not contact details supplied in the request.
7. Review cyber insurance details
Check whether the policy still matches the business's systems, staff and data. Read the incident contact process and keep the current policy details with the response plan.
Answer renewal questions from evidence rather than memory. Ask the insurer, broker or a suitable adviser when wording is unclear.
Keep a record of the review
Note what was checked, what changed and who owns each remaining action. The list gives next year's review a clear starting point and may help when a customer or insurer asks about your controls.
If the review keeps slipping, ask JCPIT about planning an EOFY security clean-up. We will confirm the systems and access in scope before reviewing accounts, devices, email or backups.