Published:

September IT Security Review: A Practical Guide for UK SMEs
September is the most practical month for an IT security review. Your team is back from summer holidays, your Q4 planning cycle has begun and you have a clear view of what happened (or didn't happen) during the summer months.
A September security review doesn't need to be a formal, resource-intensive exercise. For a 10–25 seat SME, a structured review covering six key areas takes about two hours and gives you enough information to make informed decisions for the rest of the year.
1. Patch Management Status
Start with the basics: are your devices receiving security updates? This is the single most impactful control you can verify:
Check that all workstations and servers have received critical patches released in the last 90 days
Verify that network equipment (routers, switches, firewalls, access points) has current firmware
Confirm that third-party applications (browsers, PDF readers, office suites) are up to date
Identify any devices that have consistently failed to patch and determine why
Devices that haven't received patches in three months are sitting on known vulnerabilities. This is the fastest path to a successful breach.
2. User Access and Identity Security
Review your access controls against current reality:
Are all leaver accounts from the summer period fully disabled?
Is multi-factor authentication enabled for all remote access?
Are administrative accounts properly restricted and MFA-protected?
Have any shared or generic accounts been created during the summer period?
Are password policies enforced across all systems?
Identity security is your first line of defence. Most breaches start with compromised credentials, and MFA is the single most effective control against credential-based attacks.
3. Endpoint Protection Verification
Confirm that your endpoint protection is active and effective:
All devices have approved endpoint protection software installed
Protection definitions are up to date (check the last update date)
Real-time scanning is enabled on all devices
Any devices that lost protection during summer have been re-enrolled
Endpoint protection is a baseline requirement for Cyber Essentials and a practical necessity for any business handling client data.
4. Backup Integrity Check
Backups that haven't been tested are unproven:
Verify that backup schedules ran successfully throughout summer
Perform a sample restore from each critical system
Confirm that backup storage has adequate capacity
Ensure offsite or cloud backups are accessible independently of your primary infrastructure
Test restores are the only way to know whether your backups will work when you need them.
5. Network Security Assessment
Your network perimeter may have changed during summer:
Firewall rules are current — no stale rules from temporary projects or contractors
Wi-Fi security is appropriate (WPA3 or WPA2-AES, separate guest network)
Remote access solutions are configured securely with MFA enforcement
Any VPN or remote access logs show no unusual activity during the summer period
6. Threat Readiness Review
Consider your current threat landscape:
Has your sector seen increased phishing or social media targeting? (September is a peak period for business email compromise)
Are your staff aware of current threat trends? When was their last security awareness training?
Do you have an incident response plan, and has it been reviewed in the last 12 months?
Is your cyber insurance policy current and does it cover your actual IT setup?
How Often Should SMEs Do Security Reviews?
A formal security review should happen at least annually. However, the most practical approach is a brief quarterly check (15–30 minutes) with a more comprehensive review twice a year — ideally in March and September, aligned with the tax year change and post-summer return.
Your Next Step
A Security Triage Call delivers exactly this kind of structured security review — covering all six areas above — and provides a prioritised action plan for any gaps identified.
*This article is part of the Infinite Cloud IT retrospective blog series, filling publication gaps identified during our 2026 content audit.*

Cyber Security
September IT Security Review: A Practical Guide for UK SMEs

Managed IT Services
Back-to-Business IT Setup: A Practical Guide for UK SMEs in September

Managed IT Services
Post-Holiday IT Review: What UK SMEs Should Check When Returning from Summer Break

Cyber Security
Q4 IT Security Checklist: What UK SMEs Should Complete Before Year-End

Cyber Security