The post-Q1 security checklist

May 2026 Asset Management, Security Services & Risk Management

By this time of year, new employees have joined the business, while others have left. Roles might have changed, and suppliers may have been added. Devices have moved between offices, homes, and sites. Teams have found quicker ways to get work done, some of them approved, some of them a bit more informal.


Dillon Gray.

That is normal, but it also means that cybersecurity and POPIA controls that looked right may no longer reflect how the organisation is operating. In my view, this is the right time for businesses to run a practical post-Q1 security check.

This should not be a scare exercise or become a massive audit. It is simply a disciplined way to ask whether the basics are still in place, whether responsibility is clear, and whether the business can respond properly if something goes wrong.

Start with access

It all starts by examining who still has access to what. Businesses should check whether users who have left the business have been removed from systems. They must also review employees who changed roles during the first quarter and ensure their access rights still align with their responsibilities. This is especially important for administrator rights, shared mailboxes, finance systems, HR information, cloud platforms, and remote access.

From a cybersecurity perspective, unnecessary access increases exposure, and from a POPIA perspective, personal information should be available only to those who need it for a legitimate business purpose.

Test recovery before you need it

Backups are useful only if recovery works. Many businesses can say that backups are running. Fewer can say with confidence when they last tested whether critical data, systems, or email records could actually be restored.

If ransomware, accidental deletion, or a system failure affects the business, the question will be how quickly the business can recover and what information can be restored. A simple restore test gives leadership a much clearer view of operational resilience.

Check devices and patching

Every business has devices that can fall through the cracks. It may be a laptop used by a remote employee, a spare machine given to a contractor, or an older server that still supports an important process. These devices often become weak points because they are no longer visible in the same way as the main environment.

A post-Q1 review should check which devices are managed, whether patching is up to date, and whether endpoint protection is active.

Hybrid work has made this more important. The office is no longer the only place where work happens, so security controls must align with how people actually work.

Review email and phishing behaviour

Email remains one of the easiest ways to reach employees, which also makes it one of the easiest ways to introduce risk. Security awareness should therefore be treated as an operating discipline rather than a one-off training requirement.

Businesses should know whether employees are completing awareness training, whether repeated phishing risks are being addressed, and whether staff understand how to report suspicious emails.

Completion rates are useful, but they do not tell the whole story. The real question is whether behaviour is improving.

Revisit personal information

POPIA compliance is not only about having policies in place. It is about understanding how personal information is collected, stored, accessed, shared, and retained in day-to-day business operations.

Customer records, employee information, supplier documents, and project files may have moved into new folders, systems, or collaboration spaces. The business should be able to answer basic questions. For example, where is personal information stored? Who has access to it? Is it being shared externally? Is it being retained for a valid reason?

Look at third-party access

Suppliers, consultants, and service providers often need access to systems or data. That access should not continue indefinitely without review. Check which third parties still have access. Confirm whether they still need it. Review whether the level of access matches the work being done.

Third-party access is often granted quickly during a project or in response to an urgent request. The discipline is in reviewing it afterwards.

Confirm incident visibility

Finally, ask what would happen if something went wrong today. Would the right people know quickly? How are incidents logged? Who communicates with leadership? What information would be needed if personal data were involved?

If the answer depends on a single person remembering what to do, the process is not robust enough. A post-Q1 security check will not solve every risk. The point is to identify where attention is needed before small gaps become larger problems.

Cybersecurity and POPIA compliance are not annual events. They are operating disciplines. The businesses that manage them well are the ones that keep checking whether their controls still align with how they operate.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Connecting access control, logistics and asset tracking
Access Control & Identity Management Asset Management Logistics (Industry)
Physical barriers matter, but a site is not secure just because the gate is strong or the container is locked. True security requires verifying every movement, tracing handovers, making exceptions visible, and allowing intervention before minor issues become major losses.

Read more...
AI assistants learn bad workplace habits
AI & Data Analytics Security Services & Risk Management
An employee under pressure at a logistics firm finds a productivity-boosting shortcut. Instead of manually parsing a 40-page supplier contract, they paste the confidential PDF into a public generative AI tool for a quick summary.

Read more...
SA does not have an AI problem, it has a data problem
AI & Data Analytics Asset Management
Organisations are investing in generative AI, predictive analytics and intelligent automation, driven by the promise of increased productivity, faster decision-making and competitive advantage. Yet many businesses discover AI is not delivering the results expected.

Read more...
Shadow AI: The next evolution of Shadow IT
AI & Data Analytics Security Services & Risk Management
Today, as AI gains traction in all aspects of life and business, African organisations face a new challenge, known as ‘Shadow AI’, where employees at all levels make use of AI without considering the potential impact.

Read more...
Free live travel risk map covering multiple countries
News & Events Security Services & Risk Management
Most widely cited travel risk maps are published once a year as static documents, but risk conditions do not follow a publishing calendar. The Sicuro map draws on official travel advisories from the ...

Read more...
The line between locking residents out and restricting their access
News & Events Security Services & Risk Management Residential Estate (Industry)
A June 2026 High Court judgment has clarified one of the most contested issues in modern estate governance: when an HOA's digital access restrictions amount to unlawful self-help or spoliation, and when they do not.

Read more...
Modernise field communications with Push-to-Talk over Cellular
Products & Solutions Security Services & Risk Management
Sentiv is bringing Hytera’s Push-to-Talk over Cellular (PTToC) portfolio to organisations that need a more structured and controlled way to coordinate field teams, without extending a full private radio model to every team, site, or function.

Read more...
Zero-touch automation certificate life cycle management loop
Products & Solutions Information Security Security Services & Risk Management
ManageEngine completes the certificate life cycle management loop with CA-agnostic, zero-touch automation. New post-deployment automation in Key Manager Plus removes the last manual step in certificate renewal as lifespans gradually shrink to 47 days

Read more...
Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
Sophos launches AI-native cybersecurity defence system
News & Events Information Security Security Services & Risk Management
Built for a threat landscape reshaped by AI, Sophos Fusion unites security operations, endpoint, network security, identity, email, and cloud into one defence system that prevents, detects, investigates, and responds at AI speed.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.