Chant's IT
Back to Insights
Managed IT5 min read

The end-of-Q3 IT checklist — what to tie off before winter

September is the last predictable month before the year gets busy. Here's the short IT checklist Cape Breton businesses should run through now, so Q4 and January don't catch you flat-footed.

For most Cape Breton businesses, September is a quiet moment between the back half of tourism season and the pre-holiday rush of Q4. Great time to look at things that are easy to postpone and expensive to skip.

Here's the short checklist we walk our managed clients through in September every year. Same list works if you're not a client — feel free to steal it.

1. Verify a real backup restore

Not "did the backup run" — did it actually restore. Pick a file that lives in your backup, delete it (or move it, safer), and restore it. Time how long the process takes. If you can't do this in an hour, your backup isn't actually protecting you.

For our managed clients, we run scheduled quarterly restore tests as part of the plan. September is a good time to check yours if we haven't already this quarter.

2. Audit your active user accounts

Pull a list of every user account in your Microsoft 365 or Google Workspace tenant. Compare to your current staff list. For every account that doesn't match a current employee:

  • Is this a former employee whose account should have been disabled? (Very common miss.)
  • Is this a shared account nobody remembers creating? (Should probably die.)
  • Is this a service account for an application? (Should be documented, with a rotation plan for the password.)
  • Is this a mystery? (Investigate before it becomes a security incident.)

Every extra account is an extra attack surface AND a monthly licensing cost. A ten-minute audit usually finds one or two of each.

3. Renew before you forget

September is when most annual software renewals for the year land in spam folders and get missed. Look at:

  • Antivirus / endpoint security subscriptions
  • Backup service (if separate from managed IT)
  • SSL certificates (usually auto-renew now, but check)
  • Domain registrations (chantsit.com renewals fit in this bucket too)
  • Any specialty business software with annual licensing

A missed renewal isn't just an outage — it often means paying reinstatement fees plus losing whatever discount you had grandfathered in.

4. Refresh the emergency contact list

Who calls whom, in what order, if something goes wrong. Written down somewhere physical (not just in a Word doc on the server that just went offline). Should include:

  • Your IT company's after-hours number
  • Your internet provider's business support number
  • Your alarm company
  • Your insurance broker (cyber and general)
  • Key vendor contacts (POS, industry-specific software)
  • Bank fraud department (yes, seriously — a business email compromise call to your bank in the first hour can prevent a wire transfer from clearing)

5. Update the departing-employee checklist

What happens on the last day an employee works. Who deactivates what accounts, who wipes the phone, who collects the laptop, who changes the door code, who forwards their email to whom. If this isn't written down, write it down now. Every time it happens ad-hoc, something gets missed.

6. Budget conversations for Q4

Whatever your fiscal year is, Q4 is where next year's IT budget gets locked in. Now is the time to look at:

  • Hardware that's due for replacement (typically 4-5 year cycle for workstations, 5-7 for servers).
  • Cyber insurance renewal (if it's an annual policy, the questionnaire is much easier if you've addressed the gaps before renewal — see our May article on this).
  • Security investments — MFA hardening, endpoint upgrades, MDR/MTR, staff training. If you're going to do these, budgeting in Q4 for a Q1 rollout is much cleaner than doing them mid-fiscal.
  • Software subscription cleanup — the "we're pretty sure nobody uses this anymore" ones you keep meaning to cancel.

7. Consider a security assessment

September is a great time for a formal security assessment because you have runway to actually act on the findings before Q4 crunch AND before the January cyber-insurance renewal season kicks in for most carriers.

Our Comprehensive Security Assessment runs 2-6 weeks depending on tier — start now and you have the findings and remediation done before your next big deadline. Starts at $2,500.

Print this list. Actually do it.

None of these items are hard individually. All of them are easy to postpone. The businesses that stay ahead of trouble are the ones that actually do them in September, not the ones that write down "do these in September" and then rediscover the list in March.

If it'd help, book a 15-minute call and we'll walk through the list with you and knock out whichever ones are our responsibility on the same call. Every year we do this, at least one business finds something they didn't know was broken.


Want to run the checklist together?

15-minute call. We'll walk through what applies to your business and take care of whatever's in our lane on the same call.