December is a busy month for contractors. Projects are closing out, crews are finishing weather-sensitive work, and owners are looking at the year's numbers. It is also an ideal moment to spend a few hours on security housekeeping. Many of the tasks below take little money and reduce risk meaningfully. They also feed into next year's budget, since you will know where gaps remain.
People and accounts
- Review all user accounts. Compare the list of active accounts in email, project software, accounting and remote access against the current employee and contractor roster. Disable anyone who has left.
- Check administrator access. Confirm that only a few named people hold administrative rights and that each still needs them.
- Review outside access. Subcontractors, consultants and owner representatives on closed projects should be removed.
- Confirm multi-factor authentication. Verify that it is enabled for every user on email, project platforms and remote access. Look for exceptions that were granted temporarily and never closed.
- Update shared credentials. If any shared passwords exist, such as for equipment portals or supplier sites, change them and plan to eliminate sharing.
Money and fraud controls
- Reread your payment verification procedure. Make sure everyone who handles vendor payments knows it, including seasonal or backup staff.
- Check bank settings. Review who can initiate wires and ACH, approval thresholds, and alert settings with your bank.
- Review vendor master changes. Look at bank detail changes from the past year and confirm each was verified.
- Remind staff about year-end scams. Fake invoices, gift card requests and urgent executive messages tend to rise when offices are thin.
Devices and software
- Inventory company devices. Account for laptops, tablets and phones, especially those assigned to crews that have rotated off projects.
- Confirm encryption and screen locks. Spot-check a few devices, particularly field laptops.
- Install pending updates. Operating systems, browsers, office applications and firmware on routers and firewalls.
- Retire unsupported systems. Identify operating systems or software that no longer receive security updates and plan their replacement.
- Review software licenses. Remove unused seats to cut cost and reduce attack surface.
Backups and recovery
- Test a restore. Restore a few files, and if you can, one full system. Record how long it took.
- Confirm offsite and immutable copies. Verify that at least one copy cannot be deleted by a compromised administrator account.
- Check cloud data coverage. Confirm that email, SharePoint and key project data are covered.
- Update the recovery priority list. What must come back first if systems go down: payroll, accounting, email, project files?
Network and connectivity
- Review firewall rules and remote access. Remove rules that are no longer needed and check that nothing sensitive is exposed to the internet.
- Change default or old passwords on routers. This includes jobsite routers and trailers that will be reused.
- Inventory jobsite connectivity. Note which sites have active service, who owns the account, and what should be canceled or moved.
- Separate guest and equipment networks. Confirm they remain isolated from business systems.
Vendors and customers
- List key technology vendors. Note what access each has and when it was last reviewed.
- Check customer security requirements. Review any new clauses or questionnaires received this year, especially from defense, utility or energy customers.
- Review cyber insurance. Confirm renewal dates, coverage, and the controls the insurer expects. Be ready to answer renewal applications accurately.
Plans and training
- Update the incident response plan. Refresh phone numbers, decision makers, insurer hotline and provider contacts. Print a copy.
- Run a short tabletop exercise. Spend an hour walking through a scenario such as a ransomware note appearing on a Saturday.
- Schedule training for the new year. Short, realistic sessions throughout the year work better than one annual lecture.
- Review lessons from the year. Note any phishing attempts, fraud attempts or outages, and what would have helped.
Planning ahead
Turn your findings into a short list of projects with owners and rough costs. Typical candidates include extending multi-factor authentication, replacing aging hardware, improving jobsite connectivity, adding managed detection and response, and formalizing compliance work. A prioritized list makes budget discussions much easier than a vague sense that "we should do more security."
Do it in small pieces
You do not need to complete everything in a day. Assign sections to the people who own them, set a date, and meet briefly to review results. Keep the checklist and update it each year so you can see progress.
If you would like help working through it, Ironfield Cyber offers year-end security reviews for contractors and energy companies and can turn the results into a practical plan and budget.