Once a year, properly.
DATA
What do you hold, where, and why? Delete what you no longer need Confirm retention periods are applied
BACKUPS
Test an actual restore Confirm one copy is separated Confirm coverage of everything important
RECOVERY
Test recovering a critical account without your usual device Confirm recovery addresses are independent and current Confirm two-factor recovery codes are stored safely
DEVICES
Which are out of support and need replacing Confirm encryption and locks everywhere
POLICY AND PEOPLE
Is the policy followed? Ask the people expected to follow it Refresh awareness, briefly Confirm the joiner and leaver process works
PLANS
Review the incident plan Confirm contacts are current Confirm the draft customer message still reads correctly
OBLIGATIONS
Anything changed about your data, sector or contracts?
WHAT TO DOCUMENT
The review, the findings, and what you changed.