The end of the year is a natural time to review and reset. Staff are finishing up projects, the pace slows slightly, and it's one of the few times you can get approval to do maintenance work without disrupting critical operations. It's also a period of elevated cyber risk — attackers know that IT coverage is reduced over the holiday period and that staff distracted by end-of-year fatigue are more likely to click a phishing link. This checklist helps you go into the new year with your security posture in good shape.
The 12-Point Checklist
1Review User Access — Focus on Leavers
Run a report of all active user accounts across Microsoft 365, your line-of-business applications, and your VPN. Cross-reference against your current staff list. Accounts belonging to former employees are a primary target for attackers — they may have weak or known passwords and no one is watching their activity. Disable or delete accounts within 24 hours of a staff member's last day. Make this a formal offboarding step.
2Audit MFA Enrolment
In Microsoft Entra ID, run the MFA registration report to see which accounts have MFA enrolled and which don't. Any account without MFA — particularly one with access to email, financial systems, or sensitive data — is a significant risk. Set a deadline for full enrolment and use Conditional Access to block sign-ins from accounts without MFA registered.
3Test Your Backup Restores
When did you last actually restore from a backup? Not just check that a backup job completed successfully, but actually recover a file, a folder, or a full server from backup? If the answer is "never" or "more than 3 months ago," this needs to happen before the holiday period. A backup you haven't tested may not restore when you need it most.
4Review Firewall Rules
Firewall rule sets accumulate cruft over time. Rules added for a specific project, a temporary remote access requirement, or a vendor who needed access years ago may still be open. Have your IT provider review the current firewall policy and remove any rules that are no longer required. Pay particular attention to inbound rules and any rules that permit direct RDP access from the internet.
5Check Software Licences and Renewals
Review your software licence renewals coming up in Q1. Software that lapses into an unlicensed state may stop receiving security updates, creating a vulnerability. This is also a good time to identify and remove software that is no longer used — every unused application is an unnecessary attack surface.
6Update Your IT Asset Register
You cannot secure what you don't know about. Your IT asset register should include every managed device — desktops, laptops, servers, network equipment, and mobile devices. End of year is a good time to reconcile the register against your RMM tool's device list, ensure all devices are enrolled in management, and retire or securely wipe any devices that are no longer in use.
7Review Your Cyber Insurance Policy
Cyber insurance has become far more demanding in its policy requirements. Many policies now require MFA on all remote access, offline backups, and email security controls as conditions of coverage. Review your policy carefully, confirm you meet the requirements, and check when it renews. If you don't have cyber insurance, the start of the new year is a good time to discuss it with your broker.
8Check Patch Compliance Across Your Fleet
Run a patch compliance report from your RMM tool. Identify devices that are significantly behind on OS or application patches, and schedule catch-up patching during the holiday maintenance window when staff are not using their machines. Pay special attention to any Windows 10 devices — Microsoft ended mainstream support in October 2025, meaning these devices will no longer receive security updates.
9Disable or Expire Unused Accounts and Service Accounts
Beyond former employees, check for service accounts and shared mailboxes that are no longer needed. Service accounts with administrative privileges and weak or default passwords are a favourite target for lateral movement. Review each one, ensure it has a strong, unique password, and disable any that are not actively in use.
10Review Administrator and Privileged Access
List every account with domain admin, global admin (Microsoft 365), or local administrator rights across your systems. Question whether each one still needs that level of access. Attackers who compromise a standard user account have limited reach — attackers who compromise an admin account can do catastrophic damage. Apply the principle of least privilege: reduce permissions to the minimum required.
11Run a Security Awareness Refresher
Phishing and BEC attacks spike over the holiday period, when criminals know staff are busy, distracted, and processing a higher volume of invoices and payment requests. A short security awareness refresher — even just a 10-minute email to staff with the top threats to watch for over summer — meaningfully reduces risk. Remind staff to verify any unusual payment requests by phone and to report suspicious emails.
12Plan for Holiday IT Coverage Gaps
Who handles IT incidents if something goes wrong during the holiday closure? If you rely on an internal IT person who is on leave, you need a plan. Confirm your managed IT provider's holiday support coverage, their emergency contact number, and what their response time SLA is during the break. If you don't have a managed IT provider, consider putting one in place before the next holiday period.
Key Takeaways
- Former employee accounts left active are a significant and easily preventable security risk — audit and disable them immediately.
- A backup you haven't tested may not restore when you need it most — test before the holiday period, not after a crisis.
- Holiday periods are high-risk for cyberattacks — reduced IT coverage and distracted staff create an attractive window for attackers.
- Confirm your IT coverage arrangements for the holiday period — know who to call and what the response time is before you need it.