The post-Q1 security checklist

May 2026 Asset Management, Security Services & Risk Management

By this time of year, new employees have joined the business, while others have left. Roles might have changed, and suppliers may have been added. Devices have moved between offices, homes, and sites. Teams have found quicker ways to get work done, some of them approved, some of them a bit more informal.


Dillon Gray.

That is normal, but it also means that cybersecurity and POPIA controls that looked right may no longer reflect how the organisation is operating. In my view, this is the right time for businesses to run a practical post-Q1 security check.

This should not be a scare exercise or become a massive audit. It is simply a disciplined way to ask whether the basics are still in place, whether responsibility is clear, and whether the business can respond properly if something goes wrong.

Start with access

It all starts by examining who still has access to what. Businesses should check whether users who have left the business have been removed from systems. They must also review employees who changed roles during the first quarter and ensure their access rights still align with their responsibilities. This is especially important for administrator rights, shared mailboxes, finance systems, HR information, cloud platforms, and remote access.

From a cybersecurity perspective, unnecessary access increases exposure, and from a POPIA perspective, personal information should be available only to those who need it for a legitimate business purpose.

Test recovery before you need it

Backups are useful only if recovery works. Many businesses can say that backups are running. Fewer can say with confidence when they last tested whether critical data, systems, or email records could actually be restored.

If ransomware, accidental deletion, or a system failure affects the business, the question will be how quickly the business can recover and what information can be restored. A simple restore test gives leadership a much clearer view of operational resilience.

Check devices and patching

Every business has devices that can fall through the cracks. It may be a laptop used by a remote employee, a spare machine given to a contractor, or an older server that still supports an important process. These devices often become weak points because they are no longer visible in the same way as the main environment.

A post-Q1 review should check which devices are managed, whether patching is up to date, and whether endpoint protection is active.

Hybrid work has made this more important. The office is no longer the only place where work happens, so security controls must align with how people actually work.

Review email and phishing behaviour

Email remains one of the easiest ways to reach employees, which also makes it one of the easiest ways to introduce risk. Security awareness should therefore be treated as an operating discipline rather than a one-off training requirement.

Businesses should know whether employees are completing awareness training, whether repeated phishing risks are being addressed, and whether staff understand how to report suspicious emails.

Completion rates are useful, but they do not tell the whole story. The real question is whether behaviour is improving.

Revisit personal information

POPIA compliance is not only about having policies in place. It is about understanding how personal information is collected, stored, accessed, shared, and retained in day-to-day business operations.

Customer records, employee information, supplier documents, and project files may have moved into new folders, systems, or collaboration spaces. The business should be able to answer basic questions. For example, where is personal information stored? Who has access to it? Is it being shared externally? Is it being retained for a valid reason?

Look at third-party access

Suppliers, consultants, and service providers often need access to systems or data. That access should not continue indefinitely without review. Check which third parties still have access. Confirm whether they still need it. Review whether the level of access matches the work being done.

Third-party access is often granted quickly during a project or in response to an urgent request. The discipline is in reviewing it afterwards.

Confirm incident visibility

Finally, ask what would happen if something went wrong today. Would the right people know quickly? How are incidents logged? Who communicates with leadership? What information would be needed if personal data were involved?

If the answer depends on a single person remembering what to do, the process is not robust enough. A post-Q1 security check will not solve every risk. The point is to identify where attention is needed before small gaps become larger problems.

Cybersecurity and POPIA compliance are not annual events. They are operating disciplines. The businesses that manage them well are the ones that keep checking whether their controls still align with how they operate.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Enhancing mine fleet safety
Asset Management Mining (Industry)
Probe IMT has partnered with Optix to bring safety technologies to mining operations across southern Africa, addressing critical challenges in fleet safety and operations through monitoring, coaching and behaviour management.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...
Your company is already breached, you just do not know it yet
Information Security Security Services & Risk Management
Attackers are no longer relying on sophisticated exploits to break-in. Instead, they are systematically targeting weak credentials, misconfigured systems, and exposed devices stemming from preventable gaps such as identity weaknesses and poor visibility across digital environments.

Read more...
Excellerate Services sets a new standard
News & Events Security Services & Risk Management
Excellerate Services relies on specialist expertise and the sophistication of its operations deployment and management. Central to this is an investment in smarter, data-driven operations through the Velocity and Performance Centre platforms.

Read more...
957 women killed in three months
News & Events Security Services & Risk Management
Despite years of summits, task teams and public commitments, South Africa’s femicide rate remains around five times higher than the global average, and too few are using the legal lifelines available.

Read more...
Verification is reshaping South Africa’s labour market
Security Services & Risk Management Asset Management Commercial (Industry)
Hiring faster, trusting less: in a labour market defined by both constraint and potential, the ability to hire with confidence may well become one of the most important competitive advantages.

Read more...
Africa’s opportunity to shape the future of human-centred AI
AI & Data Analytics Security Services & Risk Management
Across the Global South, countries are not yet locked into decades of legacy AI systems, energy-intensive infrastructure, or governance frameworks designed for a different technological era. That creates something rare in technology development: a cleaner slate.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.