The annual security review for small teams

Big companies do security reviews because an auditor demands one. Small companies skip them because nobody demands one — and then the one moment the answer matters arrives anyway: the insurance renewal application, a customer's security questionnaire, or the morning of an incident, when "how long since we tested our backups?" becomes the most expensive question nobody wrote down. An annual review is just the habit of answering those questions before someone asks under deadline.

This is a one-morning exercise, not a project. Block half a day once a year — a fixed date you'll remember (the insurance renewal, fiscal year end, the week after the holidays) works better than a floating intention. You finish with a one-page summary of what you checked, what you fixed, and what you're consciously accepting. That page is the deliverable: it satisfies the underwriter, briefs the next hire, and becomes exhibit A in your own defense if something breaks anyway.

1. Prove the recoveries, not just the backups

Start with the question that ends businesses: can you actually get your data back? Not "do backups exist" — does a restore work:

2. Rotate the things that rotate

Secrets age like milk, not wine. Once a year, walk the secrets rotation schedule end to end:

3. Audit who can get in — and who still could

Access drifts. People join, leave, change roles; vendors come and go; the exception granted during a crunch becomes permanent. The annual pass:

4. Test the humans before the phishers do

The cheapest security control you own is a staff that recognizes a fake invoice. Once a year, deliberately:

5. Check the machinery nobody looks at

6. Write the one page, accept the rest

A review that produces no record is a conversation. Close it out with a single page:

Then put next year's date in the calendar before you close the laptop. The review that gets scheduled recurs; the one that "we should do this again sometime" doesn't. Twelve months from now, the underwriter's renewal form, the customer's security questionnaire, or an incident at 2AM will ask these questions — and you'll have a page with answers dated, signed, and boring. That's the whole point: security that is documented and dull is the kind that works.