Small business owner and IT advisor reviewing a checklist at a desk with a laptop

CybersecurityLifecycle ManagementManaged Services

What to Include in a Year-End Technology Review

December is when most organizations set next year’s budget, which makes it the right month for a year-end technology review. What you replace, renew or fix ends up in that budget whether you plan it or not, so it is better to plan it.

The review doesn’t need to be a big project. Work through the areas below, write down what you find, and sort it into a plan before the budget is final.

Key takeaways

  • Start with accounts, because leftover access and extra admins are an easy way in.
  • Run a real restore and time it. A backup report proves less than you think.
  • List every device and app near end of support and budget its replacement.
  • Cut unused licenses and duplicate tools before renewing anything.
  • Fold in the tasks your regulations require, such as risk assessments and testing.

Accounts and access

  • Remove accounts for former employees, contractors and shared logins in Microsoft 365, line-of-business apps, and your firewall or VPN.
  • List everyone with administrator access and trim it. Fewer admin accounts means less damage from one stolen password.
  • Confirm MFA is required for every user and every app that supports it, and look for exceptions someone added and forgot.
  • Move shared passwords out of spreadsheets and sticky notes into a business password manager.
  • Confirm endpoint protection, email filtering and patching cover every device, including the laptop that was offline for three months.

Departures are the most common source of leftover access. For our clients, access is disabled the same day the client asks. Our post on employee departures and security includes an offboarding checklist.

Backups and disaster recovery

A report that says “successful” isn’t proof you can recover. Year-end is a good time to check:

Hand-drawn calendar page with a highlighter for planning
  • Everything is backed up, including Microsoft 365 email, OneDrive, SharePoint and Teams, and any system added this year.
  • A full restore works, and you know how long it takes.
  • At least one backup copy is off site and protected from deletion.
  • Your disaster recovery and incident response plan still has the right phone numbers, vendors and steps.

Schedule a tabletop exercise for the new year. In Louisiana, finish it well before hurricane season.

Hardware and software near end of life

Anything that no longer gets security updates belongs on the list. Two to check right now:

  • Windows 10 support ended on October 14, 2025. Businesses can buy Extended Security Updates for up to three years, but the price doubles each year, so treat it as a bridge.
  • Office 2016 and Office 2019 support also ended on October 14, 2025, so they get no more security fixes.

Then look at servers, firewalls, switches, wireless access points, phone systems and printers, and note the age, warranty and support end date of each. The cycle we recommend is PCs every three to four years, servers at five and firewalls at three to five. Planning replacements across the year spreads the cost, and our lifecycle management service keeps that list current. If you are buying before year-end, ask your accountant whether Section 179 applies.

Licenses and cloud spending

Subscriptions pile up quietly. When we review client Microsoft 365 and Azure accounts, the waste usually falls into the same groups:

  • Licenses that are unused or were never assigned to anyone.
  • Azure virtual machines that sit idle or are much bigger than the work requires.
  • Storage and snapshots left behind after a server was retired.
  • Two or three software tools doing the same job.

Also check whether your Microsoft 365 plan still fits, since some security features you need may only come with a higher tier, and look for apps staff use without approval, including AI tools and browser extensions. Our post on forgotten cloud resources goes further.

Policies, training and staff feedback

Policies that don’t match reality get ignored. Review your acceptable use, remote work, device and password policies, and add an AI use policy if you don’t have one. We write these policies for clients, including retention, BYOD, work-from-home and acceptable use. When a policy changes, tell staff what changed and why.

Then ask your team which tools slow them down and what breaks most often. That feedback usually points to the improvements with the best return.

Year-end compliance tasks

Healthcare organizations should revisit their HIPAA risk analysis. HHS says risk analysis should be ongoing and updated when your environment changes, and year-end is a natural point to do it, along with confirming business associate agreements and reviewing access to patient data.

Under the FTC Safeguards Rule, accounting, tax and other covered financial firms need a written report from their Qualified Individual at least annually, plus annual penetration testing and vulnerability scans every six months unless they use continuous monitoring. Some provisions don’t apply to firms with customer information on fewer than 5,000 consumers. Law firms should check that client data access, retention and vendor agreements still match their confidentiality obligations. Our compliance services help document all of it.

Turn your year-end technology review into a plan

GroupWhat goes in itExample
Fix nowSecurity gapsAn admin account without MFA
Plan and budgetReplacements and upgradesA server reaching five years
WatchItems that are fine for nowA firewall with two years of support left

Give each item a date and an owner, and keep the list where the leadership team can see it. Next December, start by checking what got done and what slipped. If you want us in the room, our managed services clients can ask for a planning review at any time, and our IT health check guide covers the same ground in more depth.

Budget season is short, and decisions made without this list tend to be expensive ones. Book a 20-minute call if you would like an outside set of eyes before the numbers are final.

Sources: Microsoft Learn, Extended Security Updates for Windows 10; Microsoft Support, End of support for Office 2016 and Office 2019; HHS, Guidance on Risk Analysis; FTC, FTC Safeguards Rule: What Your Business Needs to Know; eCFR, 16 CFR 314.4 Elements of an information security program.

Talk to an advisor

Questions about your own environment?

Our team can walk through how this applies to your organization, with honest recommendations and no pressure.