## Purpose

Use this checklist at least annually to review whether the company’s cybersecurity arrangements still reflect its systems, people, vendors, risks, and business operations.

This is not intended to replace continuous security management, but rather provide a structured annual checkpoint to identify areas that have drifted, become outdated, or received insufficient attention.

## Governance and Risk

- [ ]  Cybersecurity owner confirmed.
- [ ]  Backup owner confirmed.
- [ ]  Incident Response Lead confirmed.
- [ ]  Leadership responsibilities reviewed.
- [ ]  Cybersecurity Risk Register reviewed.
- [ ]  Critical and high risks reviewed.
- [ ]  Risk acceptance decisions reviewed.
- [ ]  Security exceptions reviewed.
- [ ]  Overdue improvement actions escalated.
- [ ]  Leadership cybersecurity review completed.

## Compliance and Business Requirements

- [ ]  Legal requirements reviewed.
- [ ]  Regulatory requirements reviewed.
- [ ]  Customer security requirements reviewed.
- [ ]  Contractual requirements reviewed.
- [ ]  Cyber insurance requirements reviewed.
- [ ]  Significant changes recorded in the Requirements Register.

## Data

- [ ]  Important data identified.
- [ ]  Sensitive information identified.
- [ ]  Data owners reviewed.
- [ ]  Access to sensitive data reviewed.
- [ ]  External sharing reviewed.
- [ ]  Public sharing reviewed.
- [ ]  Data retention requirements reviewed.
- [ ]  Unapproved storage identified and addressed.

## Assets and Systems

- [ ]  Asset Inventory reviewed.
- [ ]  Applications and Services Inventory reviewed.
- [ ]  Unknown devices investigated.
- [ ]  Unsupported devices identified.
- [ ]  Unsupported software identified.
- [ ]  Retired systems removed from inventories.
- [ ]  Internet-facing assets reviewed.
- [ ]  Critical system owners confirmed.

## Identity and Access

- [ ]  Former employee accounts reviewed.
- [ ]  Contractor accounts reviewed.
- [ ]  Vendor accounts reviewed.
- [ ]  Privileged Access Register reviewed.
- [ ]  Administrator access reviewed.
- [ ]  MFA coverage reviewed.
- [ ]  Shared accounts reviewed.
- [ ]  Service accounts reviewed.
- [ ]  Temporary access reviewed.
- [ ]  Access review completed for sensitive systems.

## Devices and Protection

- [ ]  Endpoint protection coverage reviewed.
- [ ]  Device encryption coverage reviewed.
- [ ]  Patch status reviewed.
- [ ]  Critical vulnerabilities reviewed.
- [ ]  Secure configuration reviewed.
- [ ]  Local administrator rights reviewed.
- [ ]  Mobile device protections reviewed.
- [ ]  Remote access controls reviewed.

## Email, Cloud, SaaS, and AI

- [ ]  Email security settings reviewed.
- [ ]  Administrative accounts reviewed.
- [ ]  Mailbox forwarding reviewed.
- [ ]  OAuth applications reviewed.
- [ ]  SaaS administrator access reviewed.
- [ ]  External sharing reviewed.
- [ ]  Unused SaaS services removed.
- [ ]  Browser extensions reviewed where practical.
- [ ]  AI tool use reviewed.
- [ ]  Unapproved cloud or AI services investigated.

## Network and Internet Exposure

- [ ]  Firewall configuration reviewed.
- [ ]  Remote administration exposure reviewed.
- [ ]  VPN configuration reviewed.
- [ ]  Internet-facing services reviewed.
- [ ]  Unnecessary ports or services removed.
- [ ]  Public websites and portals reviewed.
- [ ]  Network equipment support status reviewed.

## Backups and Recovery

- [ ]  Critical systems have backups.
- [ ]  Backup failures are monitored.
- [ ]  Backup retention reviewed.
- [ ]  Backup administrator access reviewed.
- [ ]  Backup protection against ransomware reviewed.
- [ ]  Restore tests completed.
- [ ]  Recovery priorities reviewed.
- [ ]  Critical recovery dependencies reviewed.
- [ ]  Recovery contact information updated.

## Detection and Monitoring

- [ ]  Important systems generate appropriate logs.
- [ ]  Security alerts have owners.
- [ ]  Endpoint alerts are monitored.
- [ ]  Authentication monitoring reviewed.
- [ ]  Cloud and SaaS logging reviewed.
- [ ]  Internet exposure monitoring reviewed.
- [ ]  Log retention reviewed.
- [ ]  Detection gaps recorded.

## Vendors and Third Parties

- [ ]  Critical vendor list reviewed.
- [ ]  Vendor owners confirmed.
- [ ]  High-risk vendors reassessed.
- [ ]  Vendor access reviewed.
- [ ]  MSP Responsibility Matrix reviewed.
- [ ]  Critical vendor emergency contacts updated.
- [ ]  Vendor incident notification requirements reviewed.
- [ ]  Former vendor access removed.
- [ ]  Critical vendor recovery dependencies reviewed.

## Incident Response

- [ ]  Incident Response Plan reviewed.
- [ ]  Emergency contact list updated.
- [ ]  Incident Decision Authority Matrix reviewed.
- [ ]  Employee reporting instructions reviewed.
- [ ]  External incident response support confirmed.
- [ ]  Cyber insurance contact and policy information confirmed.
- [ ]  Incident records reviewed for recurring issues.
- [ ]  Tabletop exercise completed where appropriate.

## Finance and Fraud Prevention

- [ ]  Payment Change Verification Procedure reviewed.
- [ ]  Finance staff understand independent verification.
- [ ]  Bank fraud contact information confirmed.
- [ ]  High-risk transaction approval process reviewed.
- [ ]  Payroll change verification reviewed.
- [ ]  Recent fraud attempts reviewed for lessons.
- [ ]  Separation of duties reviewed where practical.

## Training and Awareness

- [ ]  Core employee training completed.
- [ ]  New employee training reviewed.
- [ ]  Higher-risk teams received role-based training.
- [ ]  Phishing or security exercises reviewed.
- [ ]  Reporting channels remain easy to use.
- [ ]  Training records maintained.
- [ ]  Training updated based on recent incidents and threats.

## Policies and Documentation

- [ ]  Cybersecurity Policy reviewed.
- [ ]  Acceptable Use Policy reviewed.
- [ ]  Password and MFA Policy reviewed.
- [ ]  Access Control Policy reviewed.
- [ ]  Data Handling Policy reviewed.
- [ ]  Backup Policy reviewed.
- [ ]  Vendor Policy reviewed.
- [ ]  Other relevant procedures reviewed.
- [ ]  Outdated references corrected.
- [ ]  Policy owners confirmed.

## Improvement Planning

Record the most important findings.

### Priority 1

Finding: ____________________

Required action: ____________________

Owner: ____________________

Due date: ____________________

### Priority 2

Finding: ____________________

Required action: ____________________

Owner: ____________________

Due date: ____________________

### Priority 3

Finding: ____________________

Required action: ____________________

Owner: ____________________

Due date: ____________________

All material findings should be transferred to the Cybersecurity Improvement Action Tracker.

## Annual Review Completion

Review period: ____________________

Review lead: ____________________

Leadership reviewer: ____________________

Date completed: ____________________

Number of critical findings: ____________________

Number of high findings: ____________________

Overdue actions: ____________________

Next review date: ____________________

Evidence location: ____________________

## Practical Rule

Do not use the annual review merely to confirm that policies still exist.

Use it to find what changed, what drifted, what failed, and what needs attention next.
