Security in a small team doesn't fail from lack of concern. It fails from drift: the patching cadence slips a week, then a month; the backup test gets postponed twice; the person who knew about the VPN leaves. None of these is a crisis in the quarter it happens. Together, over a year, they become one.

The fix is a 30-minute quarterly review with a standing agenda — the same six checks, every quarter, with the numbers written down. It's deliberately small, because a review that takes half a day won't survive its second quarter. This is the tripwire between annual reviews, not a replacement for them.

Why quarterly, and why 30 minutes?

Quarterly because security-relevant things change on that rhythm: staff come and go, vendors get added, patches accumulate, insurers renew. Monthly is overhead for a small team; annually means a problem found in month two festers for ten.

Thirty minutes because of a simple trade: a short meeting that happens beats a thorough meeting that gets rescheduled until it dies. You make it fit by reviewing the same numbers every time rather than exploring new ground — you're checking for drift against your own baseline, not discovering the field of security from scratch.

If a number moves the wrong way or something looks odd, that's not a failure of the format. It's the format working: park it, and book a deeper session within the week.

Set it up once

Before the first meeting, do three things:

  • Name the owner. One person gathers the numbers and runs the agenda — your IT lead, office manager or MSP contact. No owner, no meeting.
  • Take the baseline. Record the six numbers below for the first time. The first quarter's job is establishing what "normal" looks like, not judging it.
  • Lock the calendar. Recurring invite, same day and time each quarter, treated like a board meeting rather than a status call that can slide.

Attendees: the owner, one business-side decision-maker, and optionally your MSP or provider rep. Two to three people. More than that and it becomes a project meeting.

The standing agenda

Six items, five minutes each. The power is in repetition: you ask the same questions every quarter, so any movement is visible immediately.

1. Accounts and access (5 minutes)

How many people joined and left this quarter, and were leavers fully deprovisioned? Any new admin accounts, and do they all have MFA? One look at the admin list takes a minute and catches the most common small-team breach enabler: an account nobody remembered existed.

2. Patching and vulnerabilities (5 minutes)

Two numbers: average days to apply critical patches this quarter, and the oldest unpatched critical issue. If the first number is growing or the second is embarrassing, the question for the room is why — workload, a system nobody owns, or a patch that keeps failing?

3. Backups (5 minutes)

One question: did we restore something this quarter to prove backups work? Not "did the backup job succeed" — did we actually get a file or system back. If the answer is no for two quarters running, schedule a real restore test before the third.

4. Incidents and alerts (5 minutes)

What happened this quarter: phishing clicks, blocked malware, odd logins, near-misses — and who saw the alerts when they fired? If your EDR or email security sent alerts that nobody reviewed, that's the finding. (If nobody is watching alerts at all, our EDR + MDR vs. running it yourself guide covers that decision.)

5. Vendors and changes (5 minutes)

What changed: new software or vendors with access to your data, expiring certificates or contracts, insurance renewal dates, new customer security requirements. Changes adopted mid-quarter are where unmanaged risk enters.

6. Open actions (5 minutes)

The items from last quarter and from the last annual review: done, in progress or stuck? Stuck items need a decision in the room — fund it, descope it, or accept the risk explicitly and write that down.

The numbers worth tracking

Keep one running document — a single page, updated each quarter:

Number What it tells you
Leavers fully deprovisioned Whether access control keeps up with staff changes
Admin accounts with MFA Exposure of your most powerful accounts — should be 100%
Days to apply critical patches Your real patching speed, trending over time
Last successful restore test Whether backups are a control or a hope
Incidents and near-misses this quarter Whether anyone is watching, and what they're seeing
Security actions open vs. closed Whether the program moves or stalls

Written down over a year, these six numbers become something more valuable than a checklist: evidence. Insurers, customers and auditors all respond better to four quarters of tracked numbers than to any policy document.

Making the habit stick

Three rules keep the review alive past its third quarter:

  • Never skip twice. One skipped quarter is life; two is the end of the practice. If the slot conflicts, move it within the month, don't cancel.
  • Same agenda every time. Resist adding items. The meeting stays at 30 minutes because the agenda is frozen — new concerns get their own session.
  • Write three sentences afterward. What moved, what's stuck, what's decided. That's enough for continuity and for anyone who later asks whether leadership reviews security regularly.

Once the habit is running, it compounds: the quarterly numbers feed the annual review, the annual review sets the priorities the quarterly meeting tracks, and if you ever face an incident, the record of both shows a program that pays attention. If you'd like an outside hand to run the first one or sanity-check your numbers, our virtual CISO advisory does exactly that.

Frequently asked questions

Is 30 minutes really enough?

Yes, because you're reviewing the same six numbers every quarter, not exploring. Depth belongs to the annual review; the quarterly meeting is a tripwire that catches drift while it's still cheap to fix.

What if we find something serious?

Park it in the meeting and schedule a deeper session with the right people within the week. Trying to solve a big finding inside the 30 minutes destroys the habit; ignoring it until next quarter defeats the point.

Who should attend?

Two or three people: whoever owns IT day to day, one business owner or executive, and optionally your MSP or provider rep. Any more and it becomes a project meeting instead of a review.

Key takeaways

  • Small teams lose security to drift, not to attackers' brilliance — a quarterly tripwire catches drift early.
  • Thirty minutes works because the agenda never changes: access, patching, backups, incidents, vendors, open actions.
  • Track six numbers in one running document; a year of them is real evidence for insurers and auditors.
  • Park big findings into their own session rather than blowing up the 30 minutes.
  • Never skip two quarters in a row — the habit is the control.