Back to Blog
    Cybersecurity

    Small Business Cyber Security Checklist: What to Review Every Quarter

    20 July 2026
    6 min read

    Why Quarterly Reviews Matter

    Cyber threats evolve continuously. New vulnerabilities are discovered, new attack techniques emerge, and business changes — new staff, new devices, new software — introduce new risks. A security posture that was adequate three months ago may have gaps today.

    A quarterly review does not need to take long. Working through this checklist takes approximately an hour and identifies the most important things to address before they become problems.

    Identity and Access (Every Quarter)

    • [ ] Review all user accounts — are there any accounts for staff who have left?
    • [ ] Confirm MFA is still enabled on all Microsoft 365 / Google Workspace accounts (check for new staff who may not have been fully onboarded)
    • [ ] Review admin accounts — only those who currently need admin access should have it
    • [ ] Check for any accounts with unusual login activity (Microsoft 365 admin centre > Users > Sign-in logs)
    • [ ] Confirm your password manager is in use across the team and all staff have enrolled

    Devices and Endpoints (Every Quarter)

    • [ ] Check that all devices have received security patches in the last 30 days
    • [ ] Confirm EDR software is running and current on all devices
    • [ ] Identify any new devices that have not been enrolled in MDM
    • [ ] Check for any devices running Windows 10 (end-of-support October 2025 — these should have been upgraded or replaced)
    • [ ] Review mobile devices — any lost or stolen devices to wipe?

    Backup Verification (Every Quarter — Non-Negotiable)

    • [ ] Confirm backup has run successfully in the last 30 days — check the backup console, not just an assumption
    • [ ] Perform a test restore — actually retrieve a file from the backup to confirm recovery works
    • [ ] Confirm Microsoft 365 / Google Workspace data is backed up (cloud platforms are not automatic backup)
    • [ ] Check backup storage usage — is it approaching capacity?

    Email Security (Every Quarter)

    • [ ] Run your domain through a DMARC checker (MXToolbox or EasyDMARC) to confirm policy is still correct
    • [ ] Check email filtering logs for any unusual volumes of blocked threats
    • [ ] Review any phishing simulation results if your IT provider runs them
    • [ ] Confirm SPF record is still correct if you have added any new email sending services

    Software and Licences (Every Quarter)

    • [ ] Check for any software applications that are past their end-of-support date
    • [ ] Confirm all software licences are current — no expired licences running unpatched
    • [ ] Review subscription list for any unused licences to deactivate
    • [ ] Confirm Microsoft 365 licence count matches current staff headcount

    Staff Security Awareness (Every Quarter)

    • [ ] Has any staff member reported a suspicious email this quarter? Was it investigated?
    • [ ] Is phishing awareness training scheduled for the next 12 months?
    • [ ] Are new staff being briefed on cyber security basics during onboarding?

    After the Review

    Items identified during the review should be assigned to specific people with target completion dates. Unaddressed items from previous quarters that keep appearing are a signal that they need a dedicated project rather than a checklist item.

    Why Quarterly Security Reviews Work Better Than Annual

    Cyber security is not a once-a-year project. Threats evolve continuously, your IT environment changes (new staff, new devices, new software), and the specific controls that protect you need maintenance to remain effective. A quarterly review cycle — short enough to catch problems before they become incidents, frequent enough to build organisational security awareness — is the practical rhythm for small businesses.

    Quarterly reviews do not need to be comprehensive IT audits. The quarterly checklist should take 30–60 minutes to work through. The annual review is the comprehensive deep dive. Quarterly is the maintenance check.

    The quarterly cycle:

    • Q1 (July): Post-EOFY review — new financial year IT alignment, licence reviews, hardware planning
    • Q2 (October): Security and awareness focus — phishing training, password review, dark web scan
    • Q3 (January): Backup and disaster recovery test — test restore from backup, review recovery procedures
    • Q4 (April): Pre-EOFY — hardware refresh planning, licence audit, compliance review

    The Access and Accounts Quarterly Review

    Access control degrades over time without deliberate maintenance. Every quarter, review:

    Active accounts for current employees only. Export the list of active Microsoft 365 accounts. Compare against current headcount. Investigate any account that does not correspond to a current employee. Disable and then delete confirmed former employee accounts.

    Admin accounts. How many accounts have global admin in Microsoft 365? The answer should be two or three maximum — one break-glass emergency account and one or two named administrators. If there are more, review each one and reduce to the minimum required.

    External sharing. In SharePoint and OneDrive, check for files or folders shared with external parties. Some external sharing is legitimate; some will be outdated links that should be removed.

    Application permissions. In the Microsoft 365 admin portal (Enterprise applications), review which third-party applications have been granted access to your tenant. Revoke permissions for applications that are no longer in use.

    The Security Controls Quarterly Check

    Verify that the controls you think are in place actually are:

    MFA enrollment. In the Microsoft 365 admin centre, check the MFA status for all users. All standard users should show as "Enabled" or "Enforced". Any user showing "Disabled" should be followed up — new staff who have not set up MFA, or a configuration issue.

    Backup completion. Check the backup management console (or ask your managed IT provider) to confirm that backup jobs have completed successfully every day in the past month. Any failed backup jobs should have an explanation.

    Patch status. In Microsoft Intune or your RMM tool, check the patch compliance status for all enrolled devices. Devices with outstanding patches more than two weeks old should be investigated.

    EDR alerts. If you have EDR deployed, review the threat detection log for the past 90 days. Any detections that are marked as "remediated" should be reviewed to understand what was detected and whether any follow-up action is required.

    Simulated Phishing: The Most Valuable Quarterly Exercise

    Running a simulated phishing exercise — sending a fake phishing email to staff to see who clicks — provides the most actionable data of any security awareness activity. It is not about catching people out; it is about understanding which staff are most at risk and where training needs to focus.

    Microsoft Defender for Office 365 (included in Microsoft 365 Business Premium) includes an Attack Simulator that makes this straightforward. Choose a realistic template (a fake Microsoft account security alert, a fake HR announcement, a fake invoice email), send it to all staff, and see who clicks. Staff who click receive immediate training. The click rate over time is a measurable indicator of improving security awareness.

    For businesses without Microsoft Defender for Office 365, free tools like GoPhish allow running simulated phishing exercises with some setup effort.

    The target: below 10% click rate on simulated phishing is considered good for a small business without a dedicated security function. Most businesses starting this exercise see 20–40% click rates initially, which is a sobering but useful baseline.

    Netluma IT conducts quarterly security reviews for SE Queensland managed clients. Call 1300 521 162 to discuss including this in your IT service agreement.

    Worried About Your Business Security?

    Get 24/7 threat detection and response, managed endpoint security, business backup and recovery, and dark web monitoring in Netluma Business Shield — $89 per device per month, ex GST. One flat-price module that bolts onto any managed IT plan.

    Related Services

    96% first-hour resolution
    Local Gold Coast team