Most annual security reviews are a slide deck, a sigh, and a repeat of last year's budget. Done properly, the review is the one scheduled moment each year where you step back from tickets and alerts and ask whether your security program is pointed at the right things. This guide covers what to put on the agenda and the questions that surface real gaps.

It assumes a small or mid-sized organization: you may not have a CISO, but you have systems worth protecting and obligations to customers, insurers or regulators.

Why an annual review at all?

Security work is mostly reactive: patches, alerts, audits, renewals. Without a scheduled review, nobody ever answers the bigger questions. What are we protecting? What changed this year? Are we spending on the right things? A calendar forces the conversation.

It's also increasingly expected. Cyber insurance applications, enterprise customers and frameworks like SOC 2 and ISO 27001 all ask whether leadership reviews the security program on a defined cadence. An annual review with written minutes answers that question with evidence, not adjectives.

Set the scope and the room

A review fails in two directions: too narrow, and it's a tooling report nobody acts on; too broad, and it's a strategy offsite that produces slogans. Aim for a half-day working session after two to four weeks of light preparation.

Invite:

  • Whoever runs IT day to day, internal or outsourced
  • An executive sponsor who can approve budget
  • Someone who can speak for the business: operations, finance or HR
  • Your MSP or security provider, if you use one — as a presenter, not the chair

Keep it under eight people. Assign prep work in advance: each area below needs a one-page summary, not a verbal tour.

The seven areas to review

1. Assets and attack surface

Do you still know what you own? Compare your asset inventory against reality: new cloud accounts, acquired domains, shadow IT, and systems that were "decommissioned" but never actually turned off. If the inventory and reality disagree, everything downstream is built on sand.

2. Identities and access

Pull the numbers: how many admin accounts exist, how many people still have access to systems they no longer use, whether this year's leavers were fully deprovisioned, and whether MFA is actually enforced everywhere it matters.

3. Vulnerabilities and patching

Look at the trend, not the snapshot: how fast did you fix critical findings this year versus last, and what's the oldest open critical? A growing backlog is a resourcing signal, not bad luck.

4. Vendors and third parties

List every vendor with access to your data or systems, tier them by criticality, and check which ones were reassessed this year. Tools adopted mid-year often skip review entirely.

5. Incidents and near-misses

Walk through every incident, outage and near-miss from the year: what failed, what worked, and what was actually fixed afterward. If the same root cause appears twice, that's the finding.

6. Policies, training and awareness

Are policies current, acknowledged and reflected in practice? Did phishing simulation results improve? And has anyone read the incident response plan since it was written, let alone tested it?

7. Budget, roadmap and staffing

Compare this year's spend against last year's promises. What got funded, what got deferred, and does next year's roadmap address this year's findings? If you need a structure for this, see our guide to building a 12-month security roadmap.

Questions that surface real gaps

Ask these out loud. Uncomfortable pauses are data.

  1. If we were breached tomorrow, how would we find out, and how long would it take?
  2. What did we say we'd fix last year that we didn't, and why?
  3. Which single system failing would hurt us most, and when did we last test its backup?
  4. Who has admin access to our most critical systems, and is that list current?
  5. Which vendor going down, or getting breached, would hurt us most?
  6. If our IT lead or MSP disappeared tomorrow, could someone else take over from documentation alone?
  7. What will customers, insurers and regulators ask us about next year that we can't answer today?

Turning findings into a plan

A review that ends without assignments was a meeting, not a review. For every gap, record four things:

  • What: the specific action, not a theme — "enforce MFA on the VPN," not "improve identity security"
  • Who: one named owner, not a team
  • When: a date, with quick wins inside 90 days
  • How much: budget or hours, so that deferral is a conscious decision rather than a quiet one

Write minutes and file them. They're evidence for auditors and insurers, and they're the baseline for next year's "what did we say we'd fix" question. If the findings point at work you can't staff internally — a risk assessment, a penetration test, or program build-out — that's a reasonable outcome, and our team can help you scope it.

Related reading: How to Run a Security Posture Assessment in 30 Days and Reporting Security Posture to the Board.

Frequently asked questions

How long should an annual security review take?

For a small or mid-sized organization, expect two to four weeks of light preparation, one-page summaries of each area, and a half-day working session. If it takes longer, the scope is too broad; if it takes an hour, you're rubber-stamping.

Who should be in the room?

Whoever runs IT day to day, an executive sponsor who can approve budget, someone who speaks for the business such as operations or finance, and your MSP or security provider as a presenter rather than the chair. Keep it under eight people.

How is this different from an audit or a penetration test?

A review is a management exercise about priorities and direction. An audit tests you against a standard, and a penetration test attacks your systems. A good annual review often decides which audits, assessments or tests you need next year.

Key takeaways

  • An annual review answers the questions daily work never touches: what we protect, what changed, and whether spending matches risk.
  • Review seven areas: assets, access, vulnerabilities, vendors, incidents, policies and budget.
  • Prepare one-page summaries in advance and keep the session to a half day with under eight people.
  • Every finding needs a named owner, a date and a cost, or it will be on next year's list too.
  • File the minutes — they're evidence for auditors and insurers, and the baseline for next year.