Skip to main content
ISMS

4 information security measures you can still implement before year-end

4 information security measures you can still implement before year-end. As 2024 draws to a close, IT teams can use the year-end period to secure budgets, strengthen backups, improve password security and lay the foundation for a structured ISMS for 2025.

Srdan Manasijevic

Srdan Manasijevic

CEO

4 information security measures you can still implement before year-end

4 information security measures you can still implement before year-end

The year 2024 is coming to an end. While many organisations are focusing on year-end closing and the holiday season, one topic remains especially important: information security. Cyberattacks, data loss and increasingly complex compliance requirements have shown that a proactive approach to security is essential. The turn of the year is a perfect opportunity to act.

For IT professionals, this is an ideal moment to review the current situation and take concrete steps to start the new year in a stronger position – whether that’s budget planning, backup strategy or laying the groundwork for a structured security management system. With a few targeted measures, you can make sure your organisation is well prepared for the challenges of 2025.


1. Budget planning: taking a strategic approach to information security

Year-end is not only a time for looking back; it is also the moment to set clear goals for the upcoming year. For IT and security teams, this should include one key point: planning the budget for information security. In a world of growing cyber threats, it is crucial to allocate sufficient funds for prevention, protection and continuous improvement.

Why now is the right time

Towards the end of the year, budget discussions and strategic planning for the next year are usually on the agenda. This is the ideal moment to put information security in the spotlight. Defining security goals and measures early helps you set priorities and implement projects in a structured way.

Practical steps for security budget planning

  • Perform a risk assessment: Identify vulnerabilities and evaluate potential risks. This analysis gives you strong arguments for targeted budget allocation.

  • Define objectives: Decide which measures are realistic and necessary for next year – for example, introducing an ISMS, running security awareness training or investing in new security solutions.

  • Prepare a cost plan: Estimate the required budget for hardware, software and services such as penetration tests or external advisory.

  • Convince stakeholders: Use numbers and scenarios, e.g. the potential cost of a data breach compared to investment in prevention.

Example: planning an ISMS based on IT-Grundschutz

A strong goal for 2025 is the introduction of an Information Security Management System (ISMS). It not only makes security processes more efficient, but also supports compliance with regulations and standards.

A possible planning approach:

  • First steps in Q1 2025: perform a gap analysis and define responsibilities.

  • Reserve budget for tools such as the fuentis Suite 4, which support a structured and transparent implementation.


2. Year-end backup: ensuring data security

Data is the foundation of every modern organisation, and protecting it is one of the most important measures to reduce the risk of data loss or system outages. The year-end period is an excellent opportunity to review existing backup strategies and ensure that your data is both protected and recoverable.

Why a year-end backup is essential

Cyberattacks, hardware failures or human error can lead to data loss at any time. Regular backups are critical to ensure that you can recover quickly in an emergency. At year-end – when financial statements and annual reports are being finalised – having an up-to-date backup is particularly important.

Best practices for a secure year-end backup

  • Create a full backup: Back up all relevant systems, databases and documents that are critical for operations and compliance.

  • Verify integrity and restorability: Check whether all backups are complete and error-free. Regularly test restore procedures to avoid surprises in a real incident.

  • Choose the right storage location: Store backups in a secure location that is physically separated from your main systems, e.g. in the cloud or at an off-site location.

  • Optimise your backup strategy: Review whether your current backup intervals are sufficient. For business-critical data, daily or even hourly backups may be appropriate.


3. Password check: a simple but highly effective measure

Passwords are one of the first lines of defence against cyberattacks – and at the same time one of the most common weaknesses. Stolen or weak credentials give attackers easy access. A regular password check is therefore essential. The end of the year is a great time to review and strengthen password security across your organisation.

Why a password check matters

Attacks such as phishing and brute-force attempts often target passwords directly. Simple changes can have a big impact: strong, unique passwords significantly reduce the probability of a successful attack. IT teams play a key role in defining and enforcing secure standards.

Steps to improve password security

  • Review existing passwords: Use tools to check whether corporate credentials appear in known data breaches.

  • Establish strong password standards: Promote passwords with at least 12 characters that combine letters, numbers and special characters.

  • Introduce a password manager: Password managers help users generate, store and manage secure passwords without having to remember them all.

  • Enable multi-factor authentication (MFA): Add a second factor such as one-time codes or biometrics to protect critical accounts. This significantly increases security.

Awareness programmes for employees

Technical controls alone are not enough – the security awareness of employees is equally important. Run awareness initiatives to:

  • explain the risks of weak or reused passwords,

  • teach best practices for password hygiene,

  • increase acceptance of measures like MFA.

Technical tools for IT teams

Security and IT teams can leverage additional tools to improve password security:

  • enterprise password managers to manage shared accounts,

  • SIEM systems (Security Information and Event Management) to detect and analyse suspicious login activity,

  • password checking tools that compare passwords against known breach databases.


4. Introducing an ISMS: a systematic path to information security

An Information Security Management System (ISMS) forms the foundation for sustainable and effective security measures. It creates structures and processes that protect sensitive information and support compliance with legal and regulatory requirements. The year-end period is an excellent time to set the course for introducing an ISMS so that information security remains a priority in 2025.

Why an ISMS is important

An ISMS provides a clear framework to:

  • identify and systematically reduce security risks,

  • ensure compliance with standards such as ISO 27001 or Germany’s IT-Grundschutz,

  • continuously review and improve security measures,

  • build trust with customers and business partners.

In a world of increasingly complex cyber threats, an ISMS is not a nice-to-have – it is a strategic necessity.

First steps towards implementing an ISMS

  • Conduct a gap analysis: Assess your current security posture. Where are the gaps? Which standards or requirements should you meet?

  • Define responsibilities: Assign a person or team to lead the ISMS implementation. Clear ownership is critical to success.

  • Use tools and resources: ISMS software – for example, the free version of the fuentis Suite 4 – can make it much easier to structure processes and automate recurring tasks.

  • Start with pilot projects: Begin with small, manageable scopes to demonstrate quick wins and build internal support.

Overcoming common challenges

  • Reducing perceived complexity: An ISMS can seem overwhelming at first. Using proven frameworks like ISO 27001 or IT-Grundschutz building blocks helps structure the process.

  • Engaging employees: Information security is a team effort. Train employees early and raise awareness for the importance of the ISMS.

  • Ensuring continuous improvement: An ISMS is not static. Plan regular audits and updates to keep pace with new threats and requirements.

Practical tip: ISMS tools

Modern ISMS tools such as the fuentis Suite 4 provide a wide range of features to simplify implementation – from automated risk assessments to templates for security policies. They save time and reduce organisational overhead.


Conclusion: your year-end information security checklist

Year-end is more than a time for reflection – it is an opportunity to act and set the course for a secure and successful new year. With the four measures outlined above, you can strengthen information security in your organisation quickly and effectively:

  • Budget planning: Set strategic goals and secure funding to implement security initiatives in the long term.

  • Year-end backup: Protect critical data and create a solid foundation for your disaster recovery strategy.

  • Password check: Review account security and significantly improve protection with simple changes.

  • ISMS introduction: Build a structured security management system that reduces risks and supports compliance.

By tackling these measures now, you ensure that your organisation is better prepared for the challenges of 2025. Information security is not a one-off task – it is a continuous process and a key factor for long-term success.

Take a proactive approach into the new year with a clear strategy and a strengthened security mindset. Use available tools and resources to make the process more efficient and turn information security into a visible priority. This will not only create stability, but also build trust with customers, partners and employees.

Srdan Manasijevic

Srdan Manasijevic

CEO

Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI and advanced risk methodologies.

From reading to doing: your ISMS with fuentis

ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 in one platform – the free/Basic plan is €0 for 12 months.