Most Perth businesses go quiet for at least a week or two over Christmas and New Year, and quiet offices are exactly what attackers wait for, longer to move undetected, fewer people watching, and a skeleton or non-existent on-call team if something breaks. Run this before the office empties out, not after everyone's already gone.
Know someone who needs this checklist?
Forward it to whoever handles IT, admin, or operations on your team.
Security Checks Before You Lock Up
- Confirm MFA is enforced everywhere - see our MFA setup guide if it isn't already, this is the single highest-impact check on this list.
- Review recent departures - anyone who left in the last few months should have zero remaining access, confirmed against your offboarding checklist, not assumed.
- Patch everything you can before closing - see patch management, an unpatched vulnerability sitting open for three unattended weeks is a longer window than most businesses would accept any other time of year.
- Confirm backup jobs are actually running - not just scheduled, verify the last completed job succeeded, per our guide to testing your backup.
Physical and Operational Checks
- Server room and comms room access - confirm doors are locked and alarm systems are active for the closure period.
- UPS and power protection - check battery health before an unattended power event does the check for you.
- Auto-reply and call diversion - set these up properly rather than leaving callers and emails with no indication anyone's coming back.
Who's On Call, and Do They Know It?
If your business doesn't have 24/7 IT coverage, confirm well before December who staff should actually call if something goes wrong, and make sure that number is saved somewhere accessible, not buried in an old email. Our guide to the first hour of an IT emergency is worth a re-read heading into the break, since the usual advice about who's in the office to help often doesn't apply over the holidays.
Why Attackers Specifically Target This Period
Ransomware activity has historically spiked around Christmas and New Year in Australia, timed deliberately to exploit reduced staffing and slower detection. It's worth pairing this checklist with a quick reminder to staff before they leave, our Cyber Security Awareness Month plan covers the same MFA and phishing basics that matter most heading into an unattended stretch.
Frequently Asked Questions
Why is the holiday shutdown period specifically higher risk?
An empty office with a skeleton or non-existent on-call team means an attacker who gets in has far longer to move around undetected. Australian businesses have historically seen a rise in ransomware activity timed deliberately around Christmas and New Year for exactly this reason.
Should we turn computers off completely over the break, or leave them on?
Turning workstations off saves power and reduces the attack surface, but servers, backup systems, and anything needed for monitoring should stay on and patched, not powered down for weeks in a way that delays critical updates.
Who should be on call over the break if we don't have 24/7 IT support?
At minimum, someone should know who to call and have that number saved before the office closes, not be searching for it during an actual incident. If your provider doesn't offer holiday coverage, that's worth clarifying well before December, not assuming.
Does this apply to a business that's fully cloud-based with no server on site?
Yes, though the checklist shifts, MFA and access review, patching for endpoint devices, and confirming backup jobs completed all still apply. Cloud-based doesn't mean unattended is safe, it just changes what needs checking.
We can run this shutdown checklist for you and provide holiday on-call cover.
Managed IT Services →Closing up for the break soon?
Call 0433 087 091 for a free, no-obligation IT health check before you lock the doors.
Book a Free IT Health CheckFor related reading, see How to Test Your Business Backup, What to Do in the First Hour of an IT Emergency, and End of Financial Year IT Checklist.