Autumn is a natural time for a security checkpoint. Many contractors are busy finishing projects before winter, finalizing budgets, preparing for insurance renewals, and planning for holiday coverage. Fraud attempts also tend to grow when offices are short-staffed and attention is divided.
A modest checklist now can catch problems before they become year-end emergencies. Use it as a working list, assign owners, and set dates.
Accounts and access
- Review all user accounts. Compare the list in Microsoft 365, project platforms, and accounting software with current employees and active subcontractors. Disable accounts for people who have left.
- Check MFA coverage. Confirm multifactor authentication is on for every user, especially executives, finance staff, and administrators.
- Review administrator accounts. Make sure each has a named owner and a clear reason to exist.
- Look at seasonal and temporary staff. Confirm their access ends when their work does.
- Check outside parties. Remove subcontractors and consultants whose projects have closed.
Email and fraud defenses
- Review email security settings, including filtering of impersonation attempts and external sender warnings
- Check for automatic forwarding rules to outside addresses
- Remind finance staff of the bank change verification procedure
- Plan holiday coverage so that payment approvals do not fall to one person without backup
- Confirm vendors and subcontractors have current, verified contact information in your records
Fraudsters often time attempts for periods when decision makers are away. Make sure delegates know the verification rules.
Backups and recovery
- Confirm backups completed successfully in the past week.
- Run a test restore of at least one critical system and one set of files.
- Verify that one copy is offline or immutable.
- Check that backup administrator accounts are protected with MFA.
- Make sure the incident contact sheet is current and accessible without company systems.
Devices and updates
- Check that laptops, phones, and tablets are receiving updates
- Identify devices that have not checked in for weeks
- Retire or replace unsupported operating systems and hardware
- Confirm disk encryption is enabled
- Reconcile the device inventory against employee and project lists
Jobsite connectivity
- Review routers and firmware at active sites
- Confirm default passwords have been changed
- Check data plans and billing status for cellular and satellite services
- Plan for winter conditions, including power, heat, and cold for equipment
- Remove equipment from completed sites and reset it before redeployment
Software and data
- Review who has access to project, accounting, and estimating platforms
- Check integrations between systems and remove any that are unused
- Verify that licenses match actual use, which also supports budgeting
- Confirm retention settings for closed projects
- Archive completed projects and remove unneeded active access
Policy and compliance
- Review contracts and subcontracts for security requirements
- Update your incident response plan and contact list
- Check cyber insurance renewal requirements and gather evidence, such as MFA and backup test records
- If you work on defense contracts, review your CUI scope and documentation progress
- Schedule security awareness training for the winter, including phishing examples drawn from recent attempts
Budget and planning
Consider the following when drafting next year's IT plan.
- Devices due for refresh
- Software renewals and potential consolidation
- Security improvements identified during this review
- Training and exercises
- Compliance work required by customers or contracts
An early conversation with your IT provider helps align the budget with real needs.
A hypothetical approach
Consider a hypothetical 60-person contractor that spends one afternoon in October with its controller, operations manager, and IT provider walking through this list. They find eleven accounts that should be disabled, two vendors with outdated banking verification, and a backup job that has failed quietly for two weeks. None of the fixes is expensive, but each would have been awkward to discover during a December incident.
Make it a habit
Treat the checklist as a quarterly routine rather than a one-time event. Record who completed each item and when. Over time you will build a record that supports insurers, customers, and auditors, and a company culture that treats security as routine maintenance.
Where Ironfield Cyber helps
Ironfield Cyber helps contractors run seasonal security reviews and turn the findings into a short, prioritized plan. If you would like a hand working through this checklist, we are glad to do it alongside your team.