A quarterly security review checklist

A quarterly security review checklist

Membergate Support -

Security work on a membership site tends to happen in bursts. Something alarming happens, or you hear about another business being hacked, and you spend a weekend tightening everything up. Then months pass. A contractor finishes but keeps their login, a tool you tried stays connected, the card on file for your domain expires and the backup job quietly stops running.

A quarterly review catches that drift before it matters. Four times a year, you sit down for about ninety minutes and work through the same checklist. It is not a deep audit, and it does not replace urgent action when something is wrong. It is a routine that keeps the basics in place, and because the list is the same every time, it gets quicker.

How to run the review

  • Book it. Put four dates in your calendar for the year ahead, perhaps in the first week of each quarter.
  • Use the same document. Keep the checklist as a template and make a fresh copy each quarter, so you can compare findings over time.
  • Split it if you need to. Three thirty-minute sessions work as well as one long one.
  • Involve the right people. If someone else manages payments or hosting, ask them to handle their section.
  • Record findings and actions. Anything you cannot fix during the session becomes a task with a name and a date.

Section one: people and access

  1. List everyone with admin or staff access to your membership platform, and remove anyone who no longer needs it.
  2. Do the same for your payment processor, hosting, domain registrar, business email, email marketing tool, community tools and shared drives.
  3. Check that each person’s permissions still match their role.
  4. Confirm there are no shared logins and that every admin account has two-factor authentication switched on.
  5. Check that the recovery email and phone number on your most important accounts are current.

Section two: software and connections

  1. Confirm your platform, add-ons and theme are up to date, and note anything that has not had an update in a long time.
  2. Remove add-ons you no longer use.
  3. Review connected tools and access keys, revoking any you no longer need, using your integration inventory.
  4. Check operating systems and browsers on the devices your team uses for admin work.

Section three: domain, email and website

  1. Confirm your domain is on automatic renewal, the card on file is valid and the transfer lock is on, as described in securing your domain name and DNS.
  2. Compare your DNS records with your last saved snapshot, and investigate any change you do not recognize.
  3. Check that your secure connection certificate is valid and set to renew.
  4. Check your business inbox for unfamiliar forwarding rules, connected apps and active sessions.
  5. Load your login, checkout and account pages in a private browser window and confirm they work and load securely.

Section four: backups, payments, data and logs

  1. Confirm backups are running, check the date of the latest copy, and restore one file or record to prove you can.
  2. Confirm the payout bank details are correct and that alerts about payment setting changes still reach you.
  3. Scan the quarter’s refunds, disputes and failed payments for anything unusual.
  4. Skim activity logs for new admins, exports, security settings switched off and logins from unexpected places.
  5. Apply your retention schedule, deleting or anonymizing whatever has reached the end of the period you set when deciding how long to keep member data.
  6. Search shared drives, laptops and inboxes for member exports that should already have been deleted.

Section five: documents and readiness

  1. Check your incident contact sheet. Are the phone numbers and account details for your host, processor and registrar still right?
  2. Check that your privacy policy still matches the tools you use and the data you collect.
  3. Review your offboarding and device policies if your team has changed.
  4. Choose one improvement to make before the next review, such as a new alert or a full restore drill.

A worked example: a rowing club’s quarterly review

A hypothetical rowing club runs its membership with a volunteer committee. Its secretary, Thandiwe, runs the review with the treasurer on a ninety-minute video call. Their notes from one quarter read:

Access: removed platform access for last season’s social coordinator; the treasurer’s processor login had no two-factor authentication, now fixed. Software: all updated; removed an unused event add-on. Connections: revoked an access key for a survey tool from a past campaign. Domain: card on file expires next month, now updated; DNS matches the snapshot. Backups: latest copy from last night; restored one page to the test site successfully. Payments: payout details correct; two disputes this quarter, both resolved. Data: deleted regatta entry forms from last season. Documents: the host’s support number had changed; contact sheet updated. Improvement: set up alerts for new admin accounts. Next review: booked.

None of these findings was dramatic. Together, they close the small gaps that most often grow into real problems.

Your next steps

  1. Copy the five sections above into a template document.
  2. Book four review dates in your calendar.
  3. Decide who covers each section if others manage parts of your setup.
  4. Run your first review, recording findings and assigning actions with dates.
  5. Compare each quarter’s notes with the last to see whether the same problems keep returning.

0 Comments

Comments are reviewed before they appear.