Security Operations · Scantide Guides

Before Everyone Goes on Leave: An IT Security and Operations Checklist

A pre-holiday checklist for patches, firewalls, inactive users, backups, UPS, monitoring, certificates, documentation and on-call readiness.

Short answer: Long periods with fewer administrators around are a good reason to verify the boring things before they become emergency work: patching, access, backups, hardware health, monitoring and the recovery/contact plan.
From the archive: This guide was refurbished from Juha Jurvanen's earlier technical writing, primarily Getting the datacenter ready for the Holidays - a few thoughts / Preparing for Extended Summer Leaves (2012 / 2025). Historical vendor/product specifics were not silently presented as current guidance.

Patch and remove unnecessary exposure

Both the 2012 holiday article and the 2025 summer update start with patching and unnecessary systems. Review servers, network devices and test environments before leave begins. If something does not need to be running, shutting it down reduces both operational and security risk.

Review accounts, VPN and entry points

Check firewall rules, wireless entry points, remote-access paths, old accounts and inactive users. The 2025 version explicitly adds old/test users to the checklist. Holiday coverage is not the time to discover that a forgotten account or remote-access credential still works.

Check power and hardware health

UPS batteries, storage health and monitoring alerts are mundane until something fails while the normal team is unavailable. Clear known hardware warnings before the leave period or make sure the on-call plan accounts for them.

Verify backups instead of trusting green status

The archive repeatedly says to look at backup logs and replication, not just assume backups are fine. For critical services, confirm that the recovery path and required credentials are available to whoever may be on call.

Make monitoring and escalation explicit

Monitoring only helps if somebody receives and understands the alert. Confirm alert recipients, on-call schedules, supplier contacts and where the contingency plan can be reached if the normal office or datacenter is unavailable.

Add the current Scantide checks

For a Scantide environment, the same checklist naturally maps to tools already in the platform: review Guard events and license/Datacenter connectivity, use Auditor for unmanaged hosts and stale software, and use Online/Web Monitor for public TLS, DNS and endpoint changes. These are product mappings added for the modern Scantide version; the operational checklist itself comes from the archive.

FAQ

Questions that usually come next

Is this only a Christmas or summer checklist?

No. The 2012 article explicitly says the idea applies to any longer holiday or vacation period.

What is the most important check?

There is no single one. The value is in removing known operational surprises before staffing and attention are reduced.

Use the evidence, then choose the tool

Scantide Guides explains the problem. Use Online for outside-in public evidence, Auditor for authorized internal visibility, Observe for browser-visible behavior and Guard for active server protection.

All Scantide GuidesScantide Products

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Field experience from the archive

Historical source · JufCorp: Securing your servers, users and customers online

Also a bit off topic but still important. Be sure to have a good monitoring on the hardware aspects of your server and operating system aspects (running services, disk space used and so on ) . Personally I'm fond of Spiceworks för monitoring server health, licenses and inventory but it all boils down to resources and taking the time to set it up. As long as you have some working monitoring and someone who actually deals with the alerts that come up.

Patch you servers with all of the security patches that are released. Do it as quickly as possible. There's is absolutely no defense against 0day attacks.

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

Printer Security: Printers store documents, have web interfaces, and can be entry points. Update firmware, disable unnecessary services, use authentication.

Historical source · JufCorp: Securing Windows Server with a baseline security

14. Backups! Backups! and again. BACKUPS!! Make sure you have good backups (and test them at least once a year for a complete disaster revovery scenario) and make sure you have multiple generations of them in case any of them is corrupted, preferrably stored offsite in some manner in case of a fire, theft or anything really.For day to day operations and generation management I highly recommend using the builtin VSS snapshot method but never ever have it instead of backups. You can also use the built in Windows Server backup for DR as described here

8. If your server has any monitoring agents from the manufacturer such as HP Server Agents, then install them and set them up with notifications for any hardware events to be prepared incas of hardware failures. If possible, also have spare parts readu for the common failures such as hard drives and PSu (Power Supply Units)

Historical source · JufCorp: Securing your datacenter - Physical aspects

Always have you data center locked and secured from unauthorized access, If you have the means, also have it secured against an EMP attack from the outside. Of course, I haven't even touched the subjects but be sure your data center has all the necessary fire prevention/extinction equipment in place, UPS backups and , if possible, also an outside source for generating current in case the UPS or battery runs out of current. There should also be a system in place for protecting you servers against spikes in current. Be sure to know where water pipes are running in the building so you don't place your server directly underneath one.

Practical review checklist