IT security is not something you fix once and forget. The threat landscape shifts, your business evolves, and employees come and go. Security requires regular maintenance, just like a car or a building. The good news is it doesn't need to consume much time if you distribute the effort sensibly throughout the year.

Here is a concrete annual calendar you can use as a starting point.

Q1, January, February, March: Access and backup

Review access rights

Start the new year by cleaning up who has access to what. Ask yourselves:

  • Do former employees still have active accounts? (Disable them.)
  • Does anyone have permissions they no longer need? (Remove them.)
  • Are there accounts with administrator privileges that should be normal user accounts?

Test your backup

A backup you have not tested is really just wishful thinking. Perform a real restore test: select a random set of files and restore them from backup to a test environment. Does it work? Document what you learned and correct any issues.

Put it in the calendar now. These tasks do not happen on their own. Book a recurring meeting with your IT partner at the start of each quarter. 1–2 hours is typically enough to review the quarterly tasks.

Q2, April, May, June: Policy and human factors

Review and update the IT security policy

Is your security policy updated to reflect reality? Have you adopted new systems or new work practices, or is there new legislation to consider? Review the policy and update it as needed. Send a reminder to employees about the key rules.

Run a phishing simulation

It has been half a year since the last one. The click rate may have risen again, and that is natural. Run a new simulation, measure the result, and run a short refresher module for those who click.

Q3, July, August, September: Technical review

Patch audit

Review all your systems: is Windows updated? Firmware on routers, switches, and printers? Third-party software like Adobe, Java, browsers? Map out the gaps and close them systematically. Are there systems that no longer receive updates? It is time to replace them.

Review supplier security

NIS2 and best practices require you to assess your suppliers' security posture. Review your critical suppliers: do they have a security policy? Do they use MFA? Have they experienced incidents? Your risk is not limited to your own systems. It also includes those you are connected to.

Q4, October, November, December: Annual review and budget

Full risk assessment

Once a year, you should conduct a structured review of your risk profile. What are your most critical assets? What are the most likely threats against them? What are the consequences? What are you already protected against, and what is missing? This forms the basis for next year's priorities.

Plan next year's IT security budget

Use the risk assessment to prioritize investments. What needs renewal? What should be upgraded? Are there new threats or regulatory requirements that demand action? Create a concrete plan with budget and ownership, not vague intentions.

This annual calendar is a starting point, not a checklist. Adapt it to your company's size, industry, and risk profile. The most important thing is not to do it perfectly, but to do it regularly.