Let's talk about your project
01 / Knowledge hub

Year-end security checklist

The end of the year is a period when attacks are common and teams go on leave. Reviewing accounts, backups, updates and the incident plan before the new year noticeably reduces the impact of a possible attack. This checklist was prepared for small and medium-sized businesses.

  1. 01

    Account and permission clean-up

    Close access for employees who have left, former suppliers and unused service accounts. List everyone with administrator rights and limit permissions to what is truly needed; convert shared accounts into personal accounts.

  2. 02

    Two-step verification

    E-mail, admin panels, domain and hosting accounts, and accounting and banking access should never be left without two-step verification. Where possible, use an authenticator app or a passkey instead of SMS.

  3. 03

    Test backups by restoring them

    What matters is not that a backup exists but that it can be restored. Try a real restore for your most critical system, make sure at least one backup is separate from the network and immutable, and measure how long it takes to bring the system back.

  4. 04

    Updates and end-of-life software

    Check that operating systems, CMS, plugins, server software and network devices are up to date. List software whose vendor has ended security support and plan to replace it in the new year; end-of-life software gets no patches for new vulnerabilities.

  5. 05

    Domain, certificate and e-mail settings

    Check domain and SSL certificate expiry dates, auto-renewal and the registered contact e-mail. Review your SPF, DKIM and DMARC records; they make it harder to send fake e-mail in your brand's name. You can check these in a few minutes with our free tools.

  6. 06

    Incident plan and notification duty

    When a breach happens, it should be written down who does what, who is notified and which records are kept. Under KVKK, data breaches must be reported to the Board without delay and within 72 hours at the latest, and under GDPR to the competent supervisory authority within 72 hours where feasible; appoint someone who can be reached during the holidays too.

  7. 07

    Staff awareness

    Phishing e-mails themed around year-end campaigns, shipping notifications and year-end payments are common in this period. Give your team a short reminder: requests such as a change of bank account should be verified using a known phone number, and suspicious e-mails should be reported.

Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.