Before Everyone Goes on Leave: An IT Security and Operations Checklist
A pre-holiday checklist for patches, firewalls, inactive users, backups, UPS, monitoring, certificates, documentation and on-call readiness.
Patch and remove unnecessary exposure
Both the 2012 holiday article and the 2025 summer update start with patching and unnecessary systems. Review servers, network devices and test environments before leave begins. If something does not need to be running, shutting it down reduces both operational and security risk.
Review accounts, VPN and entry points
Check firewall rules, wireless entry points, remote-access paths, old accounts and inactive users. The 2025 version explicitly adds old/test users to the checklist. Holiday coverage is not the time to discover that a forgotten account or remote-access credential still works.
Check power and hardware health
UPS batteries, storage health and monitoring alerts are mundane until something fails while the normal team is unavailable. Clear known hardware warnings before the leave period or make sure the on-call plan accounts for them.
Verify backups instead of trusting green status
The archive repeatedly says to look at backup logs and replication, not just assume backups are fine. For critical services, confirm that the recovery path and required credentials are available to whoever may be on call.
Make monitoring and escalation explicit
Monitoring only helps if somebody receives and understands the alert. Confirm alert recipients, on-call schedules, supplier contacts and where the contingency plan can be reached if the normal office or datacenter is unavailable.
Add the current Scantide checks
For a Scantide environment, the same checklist naturally maps to tools already in the platform: review Guard events and license/Datacenter connectivity, use Auditor for unmanaged hosts and stale software, and use Online/Web Monitor for public TLS, DNS and endpoint changes. These are product mappings added for the modern Scantide version; the operational checklist itself comes from the archive.
Questions that usually come next
Is this only a Christmas or summer checklist?
No. The 2012 article explicitly says the idea applies to any longer holiday or vacation period.
What is the most important check?
There is no single one. The value is in removing known operational surprises before staffing and attention are reduced.
Use the evidence, then choose the tool
Scantide Guides explains the problem. Use Online for outside-in public evidence, Auditor for authorized internal visibility, Observe for browser-visible behavior and Guard for active server protection.
All Scantide GuidesScantide ProductsPractical depth: examples, failure modes and what to verify
Field experience from the archive
Also a bit off topic but still important. Be sure to have a good monitoring on the hardware aspects of your server and operating system aspects (running services, disk space used and so on ) . Personally I'm fond of Spiceworks för monitoring server health, licenses and inventory but it all boils down to resources and taking the time to set it up. As long as you have some working monitoring and someone who actually deals with the alerts that come up.
Patch you servers with all of the security patches that are released. Do it as quickly as possible. There's is absolutely no defense against 0day attacks.
Printer Security: Printers store documents, have web interfaces, and can be entry points. Update firmware, disable unnecessary services, use authentication.
14. Backups! Backups! and again. BACKUPS!! Make sure you have good backups (and test them at least once a year for a complete disaster revovery scenario) and make sure you have multiple generations of them in case any of them is corrupted, preferrably stored offsite in some manner in case of a fire, theft or anything really.For day to day operations and generation management I highly recommend using the builtin VSS snapshot method but never ever have it instead of backups. You can also use the built in Windows Server backup for DR as described here
8. If your server has any monitoring agents from the manufacturer such as HP Server Agents, then install them and set them up with notifications for any hardware events to be prepared incas of hardware failures. If possible, also have spare parts readu for the common failures such as hard drives and PSu (Power Supply Units)
Always have you data center locked and secured from unauthorized access, If you have the means, also have it secured against an EMP attack from the outside. Of course, I haven't even touched the subjects but be sure your data center has all the necessary fire prevention/extinction equipment in place, UPS backups and , if possible, also an outside source for generating current in case the UPS or battery runs out of current. There should also be a system in place for protecting you servers against spikes in current. Be sure to know where water pipes are running in the building so you don't place your server directly underneath one.
Practical review checklist
- Printer Security: Printers store documents, have web interfaces, and can be entry points.
- Always have you data center locked and secured from unauthorized access, If you have the means, also have it secured against an EMP attack from the outside.
- Patch you servers with all of the security patches that are released.