Year-end security checklist
The end of the year is a period when attacks are common and teams go on leave. Reviewing accounts, backups, updates and the incident plan before the new year noticeably reduces the impact of a possible attack. This checklist was prepared for small and medium-sized businesses.
- 01
Account and permission clean-up
Close access for employees who have left, former suppliers and unused service accounts. List everyone with administrator rights and limit permissions to what is truly needed; convert shared accounts into personal accounts.
- 02
Two-step verification
E-mail, admin panels, domain and hosting accounts, and accounting and banking access should never be left without two-step verification. Where possible, use an authenticator app or a passkey instead of SMS.
- 03
Test backups by restoring them
What matters is not that a backup exists but that it can be restored. Try a real restore for your most critical system, make sure at least one backup is separate from the network and immutable, and measure how long it takes to bring the system back.
- 04
Updates and end-of-life software
Check that operating systems, CMS, plugins, server software and network devices are up to date. List software whose vendor has ended security support and plan to replace it in the new year; end-of-life software gets no patches for new vulnerabilities.
- 05
- 06
Incident plan and notification duty
When a breach happens, it should be written down who does what, who is notified and which records are kept. Under KVKK, data breaches must be reported to the Board without delay and within 72 hours at the latest, and under GDPR to the competent supervisory authority within 72 hours where feasible; appoint someone who can be reached during the holidays too.
- 07
Staff awareness
Phishing e-mails themed around year-end campaigns, shipping notifications and year-end payments are common in this period. Give your team a short reminder: requests such as a change of bank account should be verified using a known phone number, and suspicious e-mails should be reported.
Related pages
Articles that complete this topic, plus the matching service page.
Let's talk about your project.
Tell us what you need; we will define the scope together.