Cybersecurity risk assessment frequency and review schedule

Most small and mid-sized businesses should complete a formal cybersecurity risk assessment at least once a year. They should also carry out a targeted review after a serious incident, major technology or supplier change, rapid growth, an acquisition, a new office or a significant change in working practices.

How often should a business carry out a cybersecurity risk assessment?

Use an annual formal assessment as the minimum baseline. Support it with quarterly security and access reviews, monthly patch and vulnerability checks, continuous security monitoring and additional risk assessments whenever material change occurs. Higher-risk or fast-changing organisations may need a formal review every six months.

In this guide

SET A RELIABLE BASELINE

Is an Annual Cybersecurity Risk Assessment Enough?

An annual assessment is a sensible minimum for many smaller organisations because it creates a structured opportunity to review business-critical systems, sensitive data, Microsoft 365, identities, devices, networks, suppliers, backup, continuity and incident response.

Annual formal assessment

Provides a complete view of business risk, records evidence, scores findings and creates a prioritised remediation plan with owners and target dates.

Reviews between assessments

Respond to changes, incidents, vulnerabilities, new users, leavers and warning signs that should not wait for the next anniversary.

The right approach combines both. An organisation that reviewed security 12 months ago may since have added cloud systems, remote workers, suppliers, locations or new ways of using data.

See What Should Be Included in a Cybersecurity Risk Assessment? for the recommended scope.

REVIEW AFTER MATERIAL CHANGE

When Should You Carry Out an Additional Assessment?

INCIDENT

After a cyber incident

Reassess after account compromise, phishing, ransomware, malware, a data breach or suspicious administrator activity. Identify why controls failed and whether the weakness exists elsewhere.

PROVIDER

After changing IT provider

Review Microsoft 365, administrator access, endpoints, patching, backup, email and networks to uncover inherited gaps and undocumented risk.

CLOUD

After a major cloud change

Tenant migration, SharePoint, Intune, Conditional Access, Teams, permissions and new AI tools can all alter identity, sharing and data risk.

SITE

After opening a location

Assess new internet services, firewalls, Wi-Fi, network equipment, devices, physical access and remote administration.

M&A

After an acquisition or merger

Identify unknown devices, legacy servers, unsupported software, unmanaged accounts, suppliers, weak policies and untested backups before integration.

GROWTH

After significant growth

More employees, devices, applications, permissions, sites and data increase both exposure and the impact of disruption.

REMOTE

After changing working practices

Remote and hybrid work need suitable device management, MFA, home-working controls, secure access and support arrangements.

SYSTEM

After a critical system launch

Review authentication, permissions, backup, recovery, supplier controls, integrations and data movement for CRM, ERP, finance, payroll or document systems.

SUPPLY

After a supplier change

Confirm what the supplier can access, how privileges are controlled, what evidence is available and what happens if the service fails or is compromised.

ASSURE

Before assurance or renewal

Verify the live environment before cyber insurance renewal, Cyber Essentials certification, major tenders or customer security reviews.

PROJECT

After a major IT project

Cloud migrations, server replacement, new Wi-Fi, phone systems and digital transformation projects should end with security validation.

THREAT

When the threat changes

Act when a serious vulnerability, supplier incident or attack pattern creates a credible new risk to the organisation.

Related planning includes Mergers and Acquisitions, Modern Workplace Deployments and Vendor Management.

MATCH FREQUENCY TO EXPOSURE

Should Higher-Risk Businesses Assess More Frequently?

Yes. A six-monthly formal review may be appropriate when the organisation handles sensitive or high-volume data, provides essential services, has many locations, relies on complex suppliers or is changing quickly.

Sensitive information
Customer, beneficiary, legal, financial, health, payroll or commercially valuable data increases potential harm.
Operational dependence
Technology failure would stop manufacturing, customer support, field operations, payments or another essential service.
Rapid growth or change
Frequent hiring, acquisitions, new sites, applications, AI tools and suppliers make an annual snapshot age quickly.
Complex access
Large numbers of administrators, contractors, remote workers or third parties create more paths to critical systems.
Customer and regulatory expectations
Contracts, insurers, certification schemes and regulators may require more frequent evidence and review.
Previous incidents
A recent compromise or repeated near miss can justify shorter review cycles until remediation is proven.

A stable 20-person organisation may be well served by an annual assessment with routine checks. A fast-growing 100-person organisation with multiple sites and cloud platforms may need quarterly risk meetings and formal six-monthly reviews.

USE A LAYERED REVIEW CYCLE

A Practical Cybersecurity Review Schedule

Frequency Recommended focus
Continuous or daily Security alerts, suspicious sign-ins, endpoint detections, backup failures and other events requiring prompt action.
Monthly Patch compliance, vulnerability findings, failed protection, unsupported technology and overdue remediation.
Quarterly Microsoft 365, privileged access, leavers, supplier accounts, security trends, backup status and risk register progress.
Six-monthly Higher-level risk review for organisations with greater exposure, complexity or pace of change.
Annually Full formal cybersecurity risk assessment, policy review, recovery testing and leadership review.
After major change Targeted assessment of the affected systems, data, suppliers, people and recovery arrangements.

This schedule is a starting point. The organisation should shorten any interval where delay could allow a significant risk to remain unnoticed or untreated.

REVIEW THE WHOLE ENVIRONMENT

What Should the Annual Assessment Cover?

ASSETS

Systems and data

Critical services, sensitive information, business dependencies, owners, locations and the impact of loss or disruption.

ACCESS

Identity and permissions

Users, administrators, MFA, Conditional Access, joiners, leavers, service accounts and external access.

DEVICE

Endpoints and servers

Management coverage, EDR, encryption, supported systems, secure configuration, patching and local administrators.

CLOUD

Email and Microsoft 365

Sharing, forwarding, suspicious sign-ins, application consent, tenant controls and protection against impersonation.

NETWORK

Networks and remote work

Firewalls, Wi-Fi, segmentation, remote access, internet exposure, mobile devices and home-working controls.

RECOVER

Backup and continuity

Coverage, retention, immutability, restore evidence, recovery order, recovery time and tested response arrangements.

PEOPLE

Awareness and process

Training, phishing, payment changes, data handling, reporting concerns and lessons from incidents.

SUPPLY

Suppliers and applications

Third-party access, assurance, contracts, critical dependencies, integration and exit or continuity planning.

RESPOND

Monitoring and incidents

Logging, alert ownership, escalation, containment, communications, evidence, recovery and post-incident learning.

KEEP THE BASELINE CURRENT

What Should Be Reviewed Quarterly?

Users and leavers
Confirm starters, role changes, leavers, dormant accounts and temporary access have been handled correctly.
Administrator access
Verify privileged accounts, MFA, separate admin identities, emergency access and unnecessary permissions.
Microsoft 365 controls
Review Conditional Access, external sharing, risky sign-ins, forwarding, application consent and security alerts.
Vulnerabilities and patches
Track critical findings, failed updates, unsupported software and remediation that remains overdue.
Backup and recovery evidence
Review failures, exclusions, retention, test restores and any change to critical data or systems.
Risk and incident trends
Check open risks, attempted attacks, user reports, supplier issues and progress against target dates.

Guidance for these checks is available through Accounts and MFA, Reporting Concerns and Monitoring and Maintenance.

USE DIFFERENT CONTROLS FOR DIFFERENT JOBS

Risk Assessment, Vulnerability Scanning and Monitoring

Activity Purpose Typical cadence
Risk assessment Connect threats and control weaknesses to business impact, then prioritise action. At least annually and after material change.
Vulnerability scanning Find known technical weaknesses and missing updates across relevant systems. Monthly, quarterly and after significant changes according to risk.
Security monitoring Detect suspicious activity, malware, risky sign-ins and control failures as they happen. Continuous or as close to real time as the risk requires.
Recovery testing Prove that important data, systems and communications can be restored within the required time. At least annually for many organisations and more often for critical services.
Awareness activity Keep employees prepared for phishing, impersonation, payment fraud and data-handling risks. Annual formal learning supported by short refreshers and exercises.

These activities complement each other. Continuous monitoring cannot replace a business risk assessment, and an annual assessment cannot detect an attack that begins tomorrow. Explore Monitoring and Response and Awareness Training.

KEEP LEADERSHIP ACCOUNTABLE

Who Should Review Cybersecurity Risk?

Cybersecurity risk should not sit entirely with the IT provider. The assessment needs technical evidence and business judgement from leadership, operations, finance, HR, internal IT, relevant data owners and specialist providers.

1

Assess

Identify important assets, realistic threats, weaknesses, existing controls and business impact.

2

Prioritise

Decide which risks need immediate, short-term or planned treatment using consistent scoring.

3

Assign

Give every material action an accountable owner, funding decision and achievable target date.

4

Improve

Implement proportionate technical, operational, supplier and people controls.

5

Monitor and review

Track evidence, incidents, changing conditions and residual risk, then repeat the cycle.

Directors should see the critical and high risks, business impact, treatment decision, cost, owner and progress. Significant risks belong on the organisation’s main risk register, with likelihood, impact, mitigation and review date.

KNOW WHEN THE PICTURE IS STALE

What Are the Signs an Assessment Is Overdue?

More than a year has passed
There is no current assessment or scheduled review date.
The business has changed
Growth, new locations, suppliers, systems, remote work or AI have altered the environment.
An incident has occurred
The organisation restored service but did not reassess related weaknesses and control failures.
There is no current risk register
Management cannot see material cyber risks, owners, actions and target dates.
Evidence is unavailable
No one can demonstrate MFA enforcement, device coverage, patch status, backup restoration or alert handling.
Leaders cannot explain the risk
Directors receive technical activity reports without a clear view of business exposure and priorities.
A useful test: if management cannot explain the organisation’s most important cybersecurity risks, who owns them and what is being done, the assessment is probably overdue.

FREQUENTLY ASKED QUESTIONS

Questions About Cybersecurity Assessment Frequency

How often should a small business assess cyber risk?

At least annually, with additional reviews after significant changes or incidents. Routine monitoring and access checks should happen more frequently.

Is annual assessment enough?

It can be a suitable formal baseline for a stable smaller business, but risks created during the year should be reviewed when they arise.

When is a six-monthly review appropriate?

When the organisation has sensitive data, complex suppliers, essential services, previous incidents or a fast rate of business and technology change.

How often should Microsoft 365 be reviewed?

Many organisations benefit from a quarterly configuration and access review, supported by ongoing monitoring of alerts and risky sign-ins.

How often should disaster recovery be tested?

At least annually for many small and mid-sized organisations, and more frequently where service availability is critical.

Does monitoring replace an assessment?

No. Monitoring detects events, while the assessment examines business exposure, control design, priorities and the risk that remains.

Is Your Cybersecurity Assessment Due?

Stratiis can review your Microsoft 365 environment, users, devices, networks, suppliers, backup and recovery arrangements, then provide a prioritised improvement plan.

Discuss a Cybersecurity Risk Assessment

Related Cybersecurity Services and Guidance