Year-End IT Housekeeping: 7 Things to Do Before Closing Shop for the Holidays
Why Your Business Needs a Year-End IT Checklist This December
Most Philippine offices lock up today and reopen on January 3, with Christmas, Rizal Day on December 30, and New Year in between. What does not take a break is the IT: the file server keeps humming, the CCTV keeps recording, and the company SIM keeps receiving one-time passwords in an empty drawer. A year-end IT checklist, run in your last working hours, separates a quiet holiday from a January 3 emergency.
This year the stakes changed. On August 27, 2022, the National Privacy Commission's guidelines on administrative fines took effect: 0.25% to 3% of annual gross income per infraction, capped at PHP 5,000,000 for a single act. It is the first year-end close where a forgotten account carries a peso figure.
Every December we get the same January 3 phone calls: a backup that never ran, a website defaced over the break, an ex-employee's login still working. So we made a standing year-end IT checklist — the routine our managed IT outsourcing service runs for clients before every holiday shutdown.
Seven items, about half a day, worst-first: do 1 to 4 before you leave today, and delegate 5 to 7.
Items 1 and 2: Back Up Everything — Then Patch Before You Power Down
These two protect your data. The rest protect your people and your reputation.
1. Run a full backup and actually test the restore
Back up three things: the file server or shared drive, your accounting or POS database, and your website (a full cPanel backup covers a WordPress site's files and database at once). Follow the 3-2-1 backup rule — three copies, two kinds of media, one off-site.
Then do the part everyone skips. A backup nobody has restored is a guess. Restore one folder and one database table to a spare machine, and confirm the files open. We catch dead backup jobs this way every year.
December is the busiest sales month for most Philippine retailers. A corrupt backup found on January 3 means days of re-encoding December sales from paper receipts.
2. Update servers, workstations, and antivirus while nobody is working
The break is the one window all year when a bad update cannot interrupt anyone's work. Patch Windows 10 and 11 workstations, Windows Server, router and firewall firmware, and WordPress core and plugins. Let antivirus run a full scan before shutdown.
Order matters: patch after the verified backup from item 1, never before. If an update breaks a line-of-business app, you need a rollback point.
If your "server" is a dusty PC under somebody's desk that nobody dares touch, that is the machine that will fail in January — our server infrastructure services exist for that.
Items 3 and 4: Review Who Has Access — and Warn the Skeleton Crew About Holiday Scams
Locked doors mean nothing if the keys are scattered.
3. Audit accounts and revoke access that should not exist
Give this 30 minutes. List everyone holding company email, admin rights, payroll access, and online banking. Disable the accounts of anyone who resigned this year, strip admin rights nobody needs, and rotate shared passwords — the "admin123 that the whole office knows" problem.
This is where compliance bites. Under the Data Privacy Act of 2012 (RA 10173) you are accountable for the personal data your systems hold, and since August 27, 2022 those NPC fines apply to mishandling it. An ex-employee's live account on your customer database is exactly that kind of finding.
While you are in there, switch on 2FA — two-factor authentication, a second code by SMS or app on top of the password — for email and banking. Nobody reads logs over the break.
4. Brief your team: scam season peaks while your guard is down
This is the first holiday season after the 2022 smishing wave. Smishing is phishing delivered by text, and this year's batch landed because the messages greeted people by name. In an August 26, 2022 memorandum the NTC ordered Globe, Smart, and DITO to text-blast warnings about them; we explained why scam texts know your name back then.
In September the NTC also ordered telcos to block the domains, URLs, TinyURLs, and QR codes used in scams. Blocking lags behind whoever registers the next link, so treat every "claim your prize" message as hostile.
Brief whoever watches email and Messenger over the break:
- Never click a payment, delivery, or "verify your account" link from SMS — open the site or app directly.
- Verify a supplier's new bank details by phone, on a number you already had.
- No fund transfer is approved because a chat from "the boss" says it is urgent. December is prime season for fake-boss scams, because the boss is unreachable.
Items 5 and 6: Set Auto-Replies, Update Your Hours, and Power Down Safely
These two are the cheapest items on the list and the most often skipped.
5. Tell customers you are closed — everywhere they look
Four places, ten minutes:
- Email auto-reply with your reopening date and one emergency contact.
- Holiday hours on your Google Business Profile and Facebook Page, plus a pinned schedule post.
- A banner on your website, if you have one.
This is commercial, not just courteous. A buyer who messages a silent page in December buys from whoever answers; an auto-reply with a firm reopening date keeps the inquiry warm.
Then name one person to check the inbox every two or three days; "everyone assumed someone else was checking" is the most common January complaint we hear.
6. Decide what powers down and what stays on
Sort every device into three lists:
Off and unplugged: workstations, monitors, printers, non-essential gear — unplugging guards against the surge when power returns.
Stays on: CCTV and its recorder, the alarm, the router if you view CCTV remotely, and any customer-facing server.
Stays on, with backup power: everything in that second list belongs behind a UPS — an uninterruptible power supply, a battery that carries gear through an outage — or at least an AVR. Brownouts do not take holidays.
Sweep before locking up: server closet locked, ventilation for anything left running, no daisy-chained extension cords near the decorations. Tape the power-up order inside that closet — router, server, workstations.
Item 7: Get Your Company SIMs Ready — Registration Opens December 27
Republic Act No. 11934, the SIM Registration Act signed on October 10, 2022, makes registration a prerequisite to activation, giving existing subscribers 180 days. The NTC has set the national window at December 27, 2022 to April 26, 2023 — it opens next week, in the middle of your break — and SIMs unregistered past the deadline face deactivation.
Everyone is thinking about their personal number; almost nobody has counted the company's. Do that inventory today, while staff are in the office:
- the hotline number printed on your tarpaulins and receipts
- SIMs in company phones running GCash or Maya business accounts
- SIMs that receive bank and payment-gateway OTPs
- SIMs inside biometric terminals, CCTV modems, and alarm units
A deactivated OTP SIM in May means being locked out of your own money.
Registration will be electronic, through each telco's own platform — Globe, Smart, and DITO each run their own site or app, with no central government portal. New SIMs bought from December 27 must be registered before they activate.
Our step-by-step SIM registration guide covers the individual process. Do the company SIMs in the first week of January rather than on opening day; you have until April 26. Give each one an owner, a date, and a decision on whose name it goes under.
Print This Business Shutdown Checklist — and Name Who's On Call
Here is the whole business shutdown checklist. Print it, fill in the blanks, tape it to the door.
- Full backup plus restore test — owner: _____ · done: _____
- Patch servers, workstations, firmware, WordPress — owner: _____ · done: _____
- Access audit, ex-staff off, 2FA on — owner: _____ · done: _____
- Scam briefing for the skeleton crew — owner: _____ · done: _____
- Auto-replies and holiday hours set — owner: _____ · done: _____
- Power-down plan and physical sweep — owner: _____ · done: _____
- SIM inventory, January dates set — owner: _____ · done: _____
Then add what no checklist can do: name who is on call. One person with the alarm code, one with server admin access, both numbers posted where the skeleton crew can find them. "The boss is in Batangas with no signal" is not a continuity plan.
Items 1 to 6 fit into half a day for a 10 to 30-person office. If you cannot name one person who owns those IT maintenance tasks year-round, the business has outgrown do-it-yourself IT.
Seven items, half a day of work, or one phone call. If you would rather someone else ran this year-end IT checklist and kept watch while your team is on vacation, book a free call with us before you close today, or first thing in January.