Most SMBs do not lack security tools. They lack a rhythm. Patches slip, backup restore tests wait until next quarter, access reviews happen when someone leaves, and the incident plan sits in a shared folder that nobody has opened since it was written. An IT security annual cycle turns that into a calendar you can actually follow.
This article is a practical cadence for a busy IT owner or IT partner in a Danish mid-market / SMB context: what you do monthly, quarterly and yearly, who owns what, and a concrete Q1–Q4 plan. No fake statistics, no "world-leading" claims — just a working rhythm.
Rule of thumb: If an activity is not in the calendar with an owner and a date, it does not happen. Put the annual cycle in Outlook/Teams the same way you book board meetings.
Why an annual cycle beats ad-hoc security
Ad-hoc security follows incidents and vendor emails. An annual cycle follows risk. The goal is not more meetings — it is fewer surprises: fewer unpatched servers, fewer orphaned admin accounts, backups you have actually restored, and an incident plan people have rehearsed once.
Use the cycle as a living checklist. Adjust frequency to your size and risk — a 15-person office and a 150-person production company will not run identical calendars, but both need the same building blocks.
Monthly rhythm
These are short, recurring tasks. Aim for a fixed day each month (for example the first Tuesday) so they do not compete with firefighting.
- Patch management status. Confirm critical OS, browser, VPN, firewall and M365/endpoint updates are applied or scheduled. Track exceptions. See our patch management guide.
- Backup health check. Verify last successful jobs, retention and offsite/immutable copies. Spot-check one restore path monthly if you do not run a full quarterly restore test.
- Security signal review. Skim MFA failures, risky sign-ins (Entra ID), EDR alerts and firewall top events. Escalate anything unexplained — do not just clear tickets.
- Joiner/mover/leaver hygiene. Confirm leavers lost access the same day, and that shared mailboxes/groups were cleaned up.
Quarterly rhythm
Quarterly work needs a half-day block and a named owner. Book all four quarters in January.
- Access review. Review admin roles, privileged groups, shared mailboxes, VPN and key SaaS apps. Remove standing privileges you cannot justify. Pair with MFA coverage.
- Backup restore test. Restore a critical system or dataset to a safe target and time it. Document RTO/RPO reality vs. ambition. Guide: backup restore test.
- Phishing awareness / simulation. Run a simulation or short awareness refresh. Measure click rate and reporting rate — celebrate reporting, do not shame clicks. See phishing simulation and how to spot phishing.
- Microsoft 365 / Entra security check. Review Secure Score themes that matter: MFA, Conditional Access, external sharing, admin accounts, audit logging. Practical overview: Microsoft 365 security.
- Vendor / supplier touchpoint. Confirm support contacts, escalation paths and any security notices from ISP, hosting, EDR and backup vendors.
Annual activities
- IT security policy review. Update acceptable use, remote work, admin rules and data handling. Keep it short enough that people read it. See IT security policy.
- Incident plan tabletop. Ninety minutes with IT, leadership and communications: walk a ransomware or account-takeover scenario. Update the plan afterwards. Guide: IT incident response plan.
- Broader risk / architecture review. Firewall rules, segmentation, endpoint (EDR) coverage, backup topology and identity design. Decide what to fund next year.
- Optional external validation. Penetration test or configuration review where risk or customers require evidence — not theatre. See penetration testing.
Quarter by quarter (Q1–Q4)
A sample year you can copy into your calendar. Shift months if your fiscal year differs — keep the spacing.
Q1 — Foundation and cleanup
- Freeze the annual cycle in the calendar (all monthly + quarterly slots).
- Full access review of admin and privileged roles.
- Backup restore test of one business-critical system.
- M365/Entra baseline check (MFA, Conditional Access, external sharing).
- Publish or refresh a one-page phishing tip for staff.
Q2 — People and process
- Phishing simulation + short follow-up for clickers (coaching, not blame).
- Review joiner/mover/leaver process with HR.
- Patch exception board: close stale exceptions or accept risk in writing.
- Vendor contact sheet update (who do you call at 02:00?).
Q3 — Resilience
- Second restore test — preferably a different system or full mailbox/file share.
- Incident-plan tabletop (ransomware or BEC/invoice fraud).
- Access review focused on shared mailboxes, guest users and dormant accounts.
- EDR/endpoint coverage check: any devices missing agent or outdated OS?
Q4 — Governance and next-year plan
- Policy review and leadership sign-off.
- Annual security summary for management: what ran, what failed, what to fund.
- Budget proposals: MFA hardware keys, EDR gaps, backup immutability, training.
- Schedule next year's cycle before Christmas week disappears.
Ownership: who does what
Without names, the calendar is fiction. A simple RACI for SMBs:
- IT owner / MSP (Responsible): Runs monthly ops, patches, backup checks, M365 hygiene, simulations and evidence collection.
- Leadership (Accountable): Owns risk acceptance, policy sign-off, budget and tabletop participation.
- Department managers (Consulted): Confirm who still needs access each quarter.
- All staff (Informed / actors): Report phishing, follow MFA and acceptable use, join awareness moments.
Write the names next to each quarterly slot. Rotate a deputy so vacation does not erase the rhythm.
NIS2-style governance cadence (guidance, not legal advice)
If you are in scope for NIS2 — or you supply organisations that are — add a light governance layer on top of the operational cycle. This is practical guidance for relevant organisations, not legal advice; get counsel for formal compliance.
- Document risks and treatment decisions at least annually; refresh when major systems change.
- Give leadership a short quarterly security status (incidents, patch debt, restore-test result, access review outcome).
- Keep evidence: who ran what, when, and what was found. Auditors ask for traces, not intentions.
- Align supplier contracts with security expectations (notification, MFA, backup).
Background reading: What is NIS2?
Get started in 30 days
- Pick owners for monthly and quarterly slots; put all dates in the calendar.
- Run one backup restore test and write down the real restore time.
- Export a list of global admins / privileged roles and shrink it.
- Confirm MFA on all admin and email accounts.
- Book the Q3 tabletop now — calendars fill up.
Claim vs. evidence: "We take security seriously" is a claim. A dated restore-test log, a signed access review and a tabletop attendee list are evidence. Build the latter.
FAQ
Is this only for companies with an internal IT department?
No. Many SMBs run the cycle with an external IT partner. What matters is that someone is Responsible in the calendar — not whether they sit in your office.
How strict should we be on monthly tasks?
Protect the rhythm more than perfection. A 45-minute monthly slot that always happens beats a perfect checklist that dies after February.
Do we need new tools to start?
Usually not. Calendar, ticket system, existing backup, Entra/M365 admin centres and your EDR console are enough to begin. Buy tools to close proven gaps — not to decorate the annual cycle.