Back to Business: Five IT Security Checks for September

Back to Business: Five IT Security Checks for September

The school run is back, holiday auto-replies are disappearing and most teams are returning to something resembling their normal routine.

September can feel like a second January for businesses. It is a natural point to get organised, clear up anything that was put off over the summer and make sure your IT security is ready for the months ahead.

Here are five useful checks to make as everyone gets back to business.

1. Remove temporary access and holiday workarounds

When employees are away, colleagues often need access to additional inboxes, folders, systems or customer information.

Most of that access is provided for a perfectly good reason. The problem is that temporary permissions have a habit of becoming permanent.

Check whether anyone still has:

  • Access to a colleague’s mailbox
  • Additional administrator permissions
  • Access to folders they no longer need
  • Temporary remote-working arrangements
  • Email forwarding or delegation rules
  • Shared passwords created to cover an absence

Removing unnecessary access reduces the number of accounts that could be used to reach sensitive information.

It is also worth checking for employees who have recently joined, changed roles or left the business. Access should reflect what someone needs now, not the job they were doing six months ago.

2. Update and restart every device

Updates are easy to postpone when someone is rushing to finish work before a holiday.

Unfortunately, closing the laptop lid for two weeks does not complete them.

Ask employees to restart their laptops and allow outstanding operating system, browser and application updates to install. Do the same for office desktops and any shared devices that may have been left running.

This is also a good opportunity to identify older computers that are no longer receiving security updates.

Windows 10 reached the end of standard support in October 2025. A Windows 10 computer may still appear to work normally, but unless it is covered by an appropriate Extended Security Updates arrangement, it will not receive the same ongoing protection as a supported device.

3. Check account security and multifactor authentication

Passwords are still regularly stolen through phishing emails, fake Microsoft 365 sign-in pages and data breaches.

Multifactor authentication adds another check before someone can access an account. It remains one of the most effective ways to protect Microsoft 365 and other important business services.

Make sure it is enabled for every suitable account, particularly administrators and anyone with access to financial or customer information.

Employees should also review their authentication details. An old phone number, unused device or former employee’s details should not remain connected to an important account.

People should never approve an unexpected authentication request. Repeated prompts can mean someone already has the password and is waiting for the user to let them in.

4. Test whether your backups can be restored

Seeing a green tick next to a backup job is reassuring, but it does not prove that the right information can be recovered when it is needed.

Choose a small selection of files and test the restoration process. Check that the backup includes the information the business genuinely relies on, including email, SharePoint, OneDrive and Teams data where appropriate.

Do not assume that storing information in Microsoft 365 automatically provides every type of backup and recovery your business may require.

The National Cyber Security Centre’s latest recovery guidance recommends practising incident response and testing how systems can be rebuilt from backups. Discovering a problem during a planned test is much better than finding it during a real emergency.

5. Make it easy to report something suspicious

Employees are often told not to click suspicious links. That advice is useful, but it cannot be the whole security strategy.

Phishing emails are increasingly convincing and can imitate suppliers, delivery companies, colleagues and Microsoft 365 notifications. Even a careful employee can make a mistake when clearing a full inbox.

Make sure everyone knows:

  • How to report a suspicious email
  • Who to contact if they click a link
  • What to do after entering a password into an unfamiliar page
  • Who will make decisions during an IT incident
  • How the business will communicate if email or Teams is unavailable

The sooner someone reports a mistake, the more chance the IT team has of stopping it from becoming a bigger problem.

Technical protection also matters. DNS filtering can help block access to known malicious websites, while monitored security can identify suspicious activity that an employee may not notice.

The NCSC’s guidance for small organisations recommends combining employee awareness with practical protection for accounts, devices and data.

Start autumn with a cleaner IT setup

A September security check does not need to become a major project.

Removing old access, installing updates, checking multifactor authentication, testing a backup and reminding employees how to report a problem can all make a meaningful difference.

WTS Systems can help review your setup, check your Microsoft 365 backup arrangements and explain how services such as DNS filtering can add another layer of protection.

If you would like us to carry out a back-to-business IT check, get in touch with WTS Systems.