The IT Security Checklist Every 50-Person Company Should Run This Quarter

A quarterly security pass keeps the company in a state where a customer questionnaire, an auditor, or a surprise departure finds nothing to clean up: access matches roles, every login sits behind multi-factor authentication, and the laptop fleet reports compliant. This checklist covers the eight reviews we run each quarter for startups and SMBs, ordered so each pass makes the next one faster. It reads the same for a 5-person startup running it for the first time and a 120-person company putting structure around what grew up ad hoc: configure the cadence for scale from day one, and if you have never run a pass like this, the first one is the cleanup.

Cross-referenced against Google Workspace, Okta, Microsoft Entra ID, 1Password, Kandji, and Microsoft Intune documentation on 2026-08-27.

1. Review Who Has Access to What

Pull the user list from your identity provider and walk it against the org chart. Every account should belong to a current employee or a documented service, and every group membership should still match the person's role. Accounts that moved teams months ago tend to keep their old grants, so the review is mostly subtraction. Record the result, because the same export becomes evidence the next time a customer security questionnaire asks whether you run access reviews.

2. Verify Multi-Factor Coverage, Including the Exceptions

Enforcement policies drift as new apps arrive and exceptions accumulate, so check coverage rather than assuming it. In Google Workspace or your identity provider, pull the report of accounts without a second factor enrolled and close each one out. Pay particular attention to shared accounts, service accounts, and anyone granted a temporary exception that quietly became permanent. The quarter's target is simple: zero human accounts signing in on a password alone.

3. Reconcile Departures Against Active Accounts

Take the list of everyone who left since the last pass and confirm each identity is suspended, each device is recovered or wiped, and each app that lives outside single sign-on has had its seat removed. Offboarding done at departure time is usually complete in the identity provider and incomplete everywhere else, and this reconciliation is where the everywhere-else gets caught. A clean quarterly reconciliation is also the strongest signal that your offboarding process itself is working.

4. Count Your Admins and Cut the List

List every account holding admin rights in the identity provider, the device management tool, the billing systems, and each major SaaS app. Most companies find the list longer than anyone expected, padded by grants made to solve a one-time problem. Reduce each app to the minimum set of named admins, replace personal super-admin use with scoped roles where the platform offers them, and confirm break-glass credentials are stored in the password manager rather than in someone's head.

5. Check Device Compliance Across the Fleet

Open the device management console and read the compliance report: disk encryption on, screen lock enforced, operating system within your update window. Chase the stragglers, which are usually a laptop that has not rebooted in a month or a device that never finished enrollment. A fleet that reports compliant every quarter means a lost laptop is an inconvenience and a paperwork entry rather than an incident.

6. Sweep for Shadow IT and Stale OAuth Grants

Review the third-party apps your team has connected to company accounts. Google Workspace and Microsoft 365 both list the OAuth grants users have approved, and the list grows every quarter as people trial tools. Revoke anything unused, unrecognized, or requesting broader scopes than its job requires, and move the tools the team actually adopted onto company billing with a named owner. This is the pass that keeps the approved stack and the real stack from drifting apart.

7. Time-Box Guest, Contractor, and Vendor Access

External access is granted with an end date in mind and almost never removed on it. List guest accounts in Slack, shared drives, Jira, and your code hosting, plus any vendor accounts with standing access, and confirm each one is still needed. Convert open-ended grants to expiring ones where the platform supports it, so next quarter's list starts shorter than this quarter's.

8. Test One Backup Restore for Real

Pick one system that matters, a shared drive, the CRM export, a database, and restore something from backup: a file, a record set, a mailbox. A restore that succeeds proves the backup pipeline end to end, and a restore that fails is the cheapest possible way to learn it. Rotate the target each quarter so coverage accumulates, and log what was restored and how long it took.

What Did Not Make the List

Penetration tests, security awareness training, and full policy reviews are annual work, and folding them into a quarterly pass makes the pass heavy enough to skip. Incident response drills earn their own calendar slot. The quarterly checklist stays limited to hygiene that decays in ninety days, because a checklist the team actually completes every quarter protects more than a comprehensive one that slips.

Would you like this checklist run every quarter without owning it yourself? We can help. Book a free call and we will run it as part of your managed IT.

Cross-referenced against Google Workspace, Okta, Microsoft Entra ID, 1Password, Kandji, and Microsoft Intune documentation on 2026-08-27.