The new financial year already has a rhythm — reconciliation, renewals, planning. Borrow one morning of it for security. These ten checks catch the drift that accumulates in every business over twelve busy months.
The checklist
- 1. Access review: list every user account across email, accounting and key apps. Disable ex-staff, contractors and mystery accounts.
- 2. Admin audit: who has admin rights, and do they still need them?
- 3. MFA sweep: confirm it’s on for every account that matters — new starters slip through.
- 4. Restore test: recover a file, a mailbox and (if you can) a machine from backup. Time it. Write it down.
- 5. Patch posture: any machine or device that hasn’t updated in 90+ days gets attention or retirement.
- 6. Payment controls: confirm the verification-callback rule for bank-detail changes survived the year’s staff turnover.
- 7. Password manager adoption: check usage; chase the holdouts kindly.
- 8. Insurance answers: reread last year’s cyber-insurance questionnaire — is every "yes" still true?
- 9. Incident plan: numbers current? Print a fresh copy.
- 10. One improvement: pick a single Essential Eight gap to close this year, and budget it now while the spreadsheets are open.
Why July specifically
Because security reviews that lack a calendar anchor don’t happen. Tying the health check to a ritual you already perform — like closing the books — is the difference between an annual habit and a good intention. Two hours, once a year, and next July the list is mostly ticks.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check