September is the month when most companies call us with the same type of problem: the laptop that was left switched off for a month and now won't boot, the server that rebooted by itself in August and nobody noticed, the summer intern's account that's still active, the Wi-Fi that “was fine in the summer” and now, with everyone back, can't cope. None of this is unexpected — it's the effect of a month with half the team away and IT on autopilot. This checklist is designed to kick off the final quarter without surprises, and to use the return to work for the decisions that get put off all year.
Equipment that has been out of service
Laptops and desktop PCs left switched off for a month accumulate Windows, Office and antivirus updates. Turn them on before people return, let them update and restart — preferably outside working hours, so the first morning isn't wasted on “updating 3 of 12”. Check the batteries of laptops that were left discharged and hard drives that weren't used: September is the month with the most startup failures. If there are still PCs running Windows 10, now is the time — support ended in October 2025.
Servers and backups
Confirm that the servers are up to date and that there have been no pending reboots for weeks. Check the August logs: ignored alerts, unexpected reboots, filling disks. Above all, confirm the backups: did they run every day? Did any fail without anyone noticing? Do a restore test of a file and a mailbox — if it wasn't done during the summer, it's the first task. How does a managed backup with restore testing.
3. Accounts and logins
Summer interns, temporaries and holiday cover: have the accounts been deactivated? Have temporary accesses to folders and management software been removed? Do suppliers who carried out work in August still have VPN access? Compare the active user list with the September employee list and deactivate the differences today. Take the opportunity to confirm that everyone has multi-factor authentication active — the accounts hastily created in June are the ones that fail the most.
4. Network and Wi-Fi with a full house
The Wi-Fi that coped with ten people in August will have fifty in the second week of September, plus the new mobile phones and laptops. If there were complaints in June, they'll be back. It's the right time for a coverage survey before the problem becomes routine — take a look why the company Wi-Fi fails. Check also the Internet connection: if the company spent the summer relying on a single connection and survived, that was luck, not a plan.
5. Licences and subscriptions
September is a good month to do a licence audit: how many Microsoft 365 licences are assigned to accounts that no longer exist? Which subscriptions were taken out “for the summer” and are still being billed? Which contracts renew automatically in October or November and can be renegotiated now? This work feeds directly into the next point.
6. The 2027 budget starts now
September and October are the months when the following year's budget is finalised. With the inventory up to date, it is time to list what expires in 2027 (Windows Server 2016 in January, equipment reaching the end of its warranty, contracts), what the company will need (more people? a new office? new software?) and what can be moved to a fixed cost. We have written a specific guide: IT budget for 2027: what to include, what to cut and what not to postpone.
7. Security: what August let slip
Summer is peak phishing season — fewer people, more stand-ins, more rush. Review any suspicious emails that have come in with the team, update the firewall firmware and security signatures (subscriptions expire quietly), and schedule the next awareness session for the second half of September, when everyone is back. Our cyber security checklist for SMEs Cover the essentials.
8. People and processes
Anyone joining in September needs an account, equipment and access on the first day — not the first week. Anyone who left in August needs to have their account deactivated and their equipment returned and checked. If these two procedures do not exist in writing, September is the month to create them; they are part of the seven internal cybersecurity policies that the whole company should have.
How to do all this in a week
Day 1: equipment and upgrades, out of hours. Day 2: servers and restoration testing. Day 3: accounts, access and MFA. Day 4: licences and contracts. Day 5: network, Wi-Fi and security, with the team all back to measure the real problem. In contracted clients IT Unlimited, most of these points are not waiting for September: a 24/7 monitoring caught the reboots and failed copies in August, the updates ran in the scheduled windows and the licence inventory is part of the monthly report. What is left for September is the conversation about 2027.
Frequently Asked Questions
Why do appliances break down more often in September?
Equipment that remains switched off for weeks — above all laptops with a flat battery and older hard drives — is more likely to fail upon startup. Added to this are accumulated updates, which expose latent issues.
Should I do all the updates at once?
Yes, but outside of working hours and by groups, not all workstations on the same night. If an update causes an issue, it affects one group and not the entire company.
How do I know if the August backups ran successfully?
Don't rely on “I didn't receive any alerts” — it might mean nobody received them. Open the backup software log, check the days, and restore a file and a mailbox as a test.
Is it too late to budget for 2027 in September?
No — it's the right time. Equipment renewals and server replacements need lead times and migration windows that are planned months in advance.
Would you like us to go through the September checklist with you?
We will go through the list with your company, sort out anything that is pending and deliver in writing what needs to be included in the 2027 budget. See the IT Unlimited or call 211 459 950.





































