All resources

20 July 2026 · Guide · CyberSec360 Australia

A New-Financial-Year Cyber Health Check: 10 Items for the First Week of July

The new financial year already has a rhythm — reconciliation, renewals, planning. Borrow one morning of it for security. These ten checks catch the drift that accumulates in every business over twelve busy months.

The checklist

  • 1. Access review: list every user account across email, accounting and key apps. Disable ex-staff, contractors and mystery accounts.
  • 2. Admin audit: who has admin rights, and do they still need them?
  • 3. MFA sweep: confirm it’s on for every account that matters — new starters slip through.
  • 4. Restore test: recover a file, a mailbox and (if you can) a machine from backup. Time it. Write it down.
  • 5. Patch posture: any machine or device that hasn’t updated in 90+ days gets attention or retirement.
  • 6. Payment controls: confirm the verification-callback rule for bank-detail changes survived the year’s staff turnover.
  • 7. Password manager adoption: check usage; chase the holdouts kindly.
  • 8. Insurance answers: reread last year’s cyber-insurance questionnaire — is every "yes" still true?
  • 9. Incident plan: numbers current? Print a fresh copy.
  • 10. One improvement: pick a single Essential Eight gap to close this year, and budget it now while the spreadsheets are open.

Why July specifically

Because security reviews that lack a calendar anchor don’t happen. Tying the health check to a ritual you already perform — like closing the books — is the difference between an annual habit and a good intention. Two hours, once a year, and next July the list is mostly ticks.

Want help with this in your business?

Book a free security check with our Sydney team — plain-English advice, no obligation.

Get a Free Security Check