The September Security Reset

September is a useful time to take stock of your organisation’s security. People are back from leave, temporary arrangements should be ending, and projects that slowed over the summer are picking up again.

A reset does not need to mean a major review of every system. A few focused checks can uncover changes that were easy to miss while teams were away. Here are five places to start.

1. Check who has access

Summer cover often involves giving someone temporary access to a mailbox, shared folder or business system. Check that those permissions are still needed. The same applies to accounts belonging to people who have changed roles or left the organisation.

Pay particular attention to administrator accounts. These can make significant changes, so access should be limited to people who need it for their work. If a colleague only needed elevated permissions to cover a two-week absence, those permissions should now be removed.

This is also a good moment to check that staff know which account to use for everyday work and which to use for administrative tasks.

2. Catch up on updates

Devices that have been switched off or used less frequently over the summer may have missed software updates. Servers and network equipment can fall behind too, especially if maintenance was postponed to avoid disrupting holiday cover.

Start with systems exposed to the internet and devices used to access sensitive information. Check whether updates have installed successfully rather than assuming that an automatic update setting has taken care of them.

If an update cannot be applied yet, record why, decide what protection is needed in the meantime and set a date to review it. An exception that nobody revisits can quietly become a permanent weakness.

3. Look at what is visible from outside

A new service may have been put online for a short project. A firewall rule may have been changed to help someone work remotely. When the immediate need passes, those changes are easy to forget.

Review your internet-facing systems and ask whether each exposed service is still needed. Include websites, remote access tools, test environments and cloud systems. Check that someone in your organisation knows who owns each one and how it is maintained.

You do not need to assume that every unexpected change is malicious. It may simply be an unfinished piece of work. The important thing is to find it and make a deliberate decision about it.

4. Check that recovery will work

Most organisations know whether they have backups. Fewer know exactly how long it would take to restore a critical service or who would coordinate the work if the usual person were away.

Choose one important system and walk through what would happen if it became unavailable tomorrow. Are its backups completing? Has a recent restore been tested? Do the right people have the information and access needed to recover it?

You may already have a recovery plan. September is a good time to check whether it still reflects the systems you use and the people responsible for them. A contact list from last year is of little help during an incident.

5. Remind staff how to report a concern

A colleague who spots a suspicious message or an unusual login alert should know what to do next. Make the reporting route clear and easy to find, including for staff who work remotely.

Keep the message simple. Staff do not need to decide whether something is definitely an attack before reporting it. They should know whom to contact, what information to include and that raising a concern promptly is helpful, even if it turns out to be harmless.

This is also an opportunity to remind managers how incidents will be handled if the usual IT contact is unavailable. A short conversation now can prevent confusion when time matters.

Make it a starting point

These checks are useful in September because the change of season gives teams a natural moment to pause. They should also lead to regular habits throughout the year. Access changes need reviewing, updates need tracking, exposed systems need owners, and recovery plans need testing.

If you find a problem, give someone responsibility for resolving it and agree when it will be checked again. A short list of completed actions is more valuable than a long checklist filed away until next September.

If you would like a hand working through any of these checks, our Cyber Security service can help you turn them into a practical review. Feel free to get in touch.