
A quarterly security review checklist
Security work on a membership site tends to happen in bursts. Something alarming happens, or you hear about another business being hacked, and you spend a weekend tightening everything up. Then months pass. A contractor finishes but keeps their login, a tool you tried stays connected, the card on file for your domain expires and the backup job quietly stops running.
A quarterly review catches that drift before it matters. Four times a year, you sit down for about ninety minutes and work through the same checklist. It is not a deep audit, and it does not replace urgent action when something is wrong. It is a routine that keeps the basics in place, and because the list is the same every time, it gets quicker.
How to run the review
- Book it. Put four dates in your calendar for the year ahead, perhaps in the first week of each quarter.
- Use the same document. Keep the checklist as a template and make a fresh copy each quarter, so you can compare findings over time.
- Split it if you need to. Three thirty-minute sessions work as well as one long one.
- Involve the right people. If someone else manages payments or hosting, ask them to handle their section.
- Record findings and actions. Anything you cannot fix during the session becomes a task with a name and a date.
Section one: people and access
- List everyone with admin or staff access to your membership platform, and remove anyone who no longer needs it.
- Do the same for your payment processor, hosting, domain registrar, business email, email marketing tool, community tools and shared drives.
- Check that each person’s permissions still match their role.
- Confirm there are no shared logins and that every admin account has two-factor authentication switched on.
- Check that the recovery email and phone number on your most important accounts are current.
Section two: software and connections
- Confirm your platform, add-ons and theme are up to date, and note anything that has not had an update in a long time.
- Remove add-ons you no longer use.
- Review connected tools and access keys, revoking any you no longer need, using your integration inventory.
- Check operating systems and browsers on the devices your team uses for admin work.
Section three: domain, email and website
- Confirm your domain is on automatic renewal, the card on file is valid and the transfer lock is on, as described in securing your domain name and DNS.
- Compare your DNS records with your last saved snapshot, and investigate any change you do not recognize.
- Check that your secure connection certificate is valid and set to renew.
- Check your business inbox for unfamiliar forwarding rules, connected apps and active sessions.
- Load your login, checkout and account pages in a private browser window and confirm they work and load securely.
Section four: backups, payments, data and logs
- Confirm backups are running, check the date of the latest copy, and restore one file or record to prove you can.
- Confirm the payout bank details are correct and that alerts about payment setting changes still reach you.
- Scan the quarter’s refunds, disputes and failed payments for anything unusual.
- Skim activity logs for new admins, exports, security settings switched off and logins from unexpected places.
- Apply your retention schedule, deleting or anonymizing whatever has reached the end of the period you set when deciding how long to keep member data.
- Search shared drives, laptops and inboxes for member exports that should already have been deleted.
Section five: documents and readiness
- Check your incident contact sheet. Are the phone numbers and account details for your host, processor and registrar still right?
- Check that your privacy policy still matches the tools you use and the data you collect.
- Review your offboarding and device policies if your team has changed.
- Choose one improvement to make before the next review, such as a new alert or a full restore drill.
A worked example: a rowing club’s quarterly review
A hypothetical rowing club runs its membership with a volunteer committee. Its secretary, Thandiwe, runs the review with the treasurer on a ninety-minute video call. Their notes from one quarter read:
Access: removed platform access for last season’s social coordinator; the treasurer’s processor login had no two-factor authentication, now fixed. Software: all updated; removed an unused event add-on. Connections: revoked an access key for a survey tool from a past campaign. Domain: card on file expires next month, now updated; DNS matches the snapshot. Backups: latest copy from last night; restored one page to the test site successfully. Payments: payout details correct; two disputes this quarter, both resolved. Data: deleted regatta entry forms from last season. Documents: the host’s support number had changed; contact sheet updated. Improvement: set up alerts for new admin accounts. Next review: booked.
None of these findings was dramatic. Together, they close the small gaps that most often grow into real problems.
Your next steps
- Copy the five sections above into a template document.
- Book four review dates in your calendar.
- Decide who covers each section if others manage parts of your setup.
- Run your first review, recording findings and assigning actions with dates.
- Compare each quarter’s notes with the last to see whether the same problems keep returning.
0 Comments