Every October a poster shows up in break rooms reminding everyone to use a strong password. Somebody forwards a slide deck. Maybe there is a lunch and learn. Then November arrives, the poster stays up until it curls at the corners, and nothing is measurably safer than it was in September.

We are not going to tell you Cybersecurity Awareness Month is a waste. It is not. But here is the contrarian part: the problem with awareness campaigns is not the advice, which is usually fine. The problem is that awareness is not the bottleneck. Most owners we talk to already know they should turn on multifactor authentication. They know phishing is a thing. Knowing was never the hard part. Finishing was. So pick four things, do them during the month, and let the posters take care of themselves.

Why a Month of Attention Beats a Year of Intentions

Cybersecurity Awareness Month was launched in October by the National Cybersecurity Alliance and the U.S. Department of Homeland Security, and the Alliance and CISA co-lead it today. The Alliance frames the goal well: staying safe online is not about making one perfect decision, it is about building habits and repeating them consistently in the small moments that happen every day.

That framing lowers the bar in a productive way. You are not trying to become a security company this month. You are converting a handful of intentions into finished work while there is a convenient reason to bring it up. October gives you cover. Nobody thinks it is strange to talk about security in October. Use it. Four items is enough.

One: Pick a Single Control and Actually Finish It

Not four controls. One. The most common security problem we see in small businesses is not a missing protection, it is a half deployed one. Multifactor authentication turned on for leadership and never rolled out to the warehouse. Disk encryption on the newer laptops and not the older ones. A backup covering the file server but not the accounting software.

Half deployed is worse than it looks, because it produces the feeling of coverage without the coverage. Pick the one furthest along and drive it to one hundred percent.

  • Finish multifactor authentication for everyone. Every account, including shared mailboxes and the owner. CISA names turning on multifactor authentication as one of the four core actions in its Secure Our World campaign, alongside recognizing and reporting phishing, using strong passwords, and updating software.
  • Or finish the backup you never tested. A backup nobody has restored from is a hypothesis, not a backup. Restore one real file and one full folder, and time it.
  • Or finish patching the machines that keep getting skipped. Usually there are three or four, and usually somebody knows exactly which ones.

If you pick multifactor authentication and want to understand the difference between app codes, text messages, hardware keys, and passkeys, our comparison of YubiKey versus passkey versus MFA lays out the tradeoffs in plain language.

Two: Run a No Blame Reporting Drill

Most businesses have never answered this out loud: what should an employee do in the first sixty seconds after realizing they clicked something they should not have?

If the honest answer is “hope nobody notices,” you have a reporting problem, and reporting problems cost more than the original mistake. The gap between a bad click and someone in charge knowing about it is where damage compounds.

So run a drill, and design it so that reporting is the only thing being measured.

  • Name the destination. One person, one phone number, one email address. Written down where people can find it without asking.
  • Say the no blame part out loud, from the owner. Not from IT. Staff need to hear from the person who signs their check that reporting fast is the win.
  • Teach the signs worth knowing. CISA points to urgent or emotionally appealing language, requests for personal and financial information, untrusted shortened links, and lookalike addresses. It also notes that poor grammar used to be a giveaway, but in the era of artificial intelligence some messages now have perfect grammar and spelling, so watch the other signs.
  • Practice the reporting step itself. Have someone actually send the report about a harmless test message. The muscle you want is the sending, not the spotting.

One caution. This is a drill, not a trap. Simulated phishing campaigns that publicly shame the people who fall for them teach staff to hide mistakes, which is the opposite of what you want.

Three: Review Who Has Access to What

The least exciting item on the list and probably the highest value. Access accumulates. It almost never gets removed. Somebody covers for a colleague on leave and keeps the permissions for three years. A vendor gets access to one folder during a project and still has it. An employee moves from operations to sales and gains the new access without losing the old.

Sit down with a list and go account by account. It takes less time than people fear, usually an hour or two under fifty employees.

  • Everyone who has left. Check email, file storage, accounting, the phone system, and anything with its own separate login.
  • Everyone with administrator rights. Ask why for each. If the answer is “it was easier at the time,” that is a candidate for removal.
  • Every outside party. Bookkeepers, marketing agencies, former IT providers, contractors. Vendor access is the category most often forgotten.
  • Shared logins. Any account where more than one person knows the password is one where nobody is accountable. List them now, fix them next quarter.

Four: Have the Money Movement Conversation

If you only did one item, make it this one. Business email compromise, where a criminal impersonates a vendor or an executive to redirect a payment, does not require anyone to break into your systems. It requires a convincing message and a person who wants to be helpful.

The defense is a rule, not a product. Any request to change bank details, redirect a payment, or send funds urgently gets verified by voice on a number you already had on file, never a number in the message. CISA gives the same advice in broader form: do not call any number in a suspicious message, and use another way to reach the person to confirm whether they contacted you.

Three things make the rule stick. Put it in writing so it survives staff turnover. Grant explicit permission to be slow, because urgency is the lever these messages pull. And apply it to the owner too, since a rule with an exception at the top is not a rule. Know what to do if it goes wrong, too: the FBI’s Internet Crime Complaint Center advises that if you discover a fraudulent transfer, time is of the essence, and to immediately contact your financial institution and request a recall of the funds.

The Bottom Line

Awareness campaigns fail quietly because they end with agreement rather than a change. Everyone nods, and nothing is different on November first. The fix is not more awareness. It is a shorter list with a deadline on it.

Four things: finish one control, run a reporting drill, review access, set the money movement rule. None of it requires new spending. All of it fits inside a month. Do it every October and you close roughly twenty gaps in five years, which beats a filing cabinet of good intentions. For the longer argument on why this matters at your size, see our post on why cybersecurity is no longer optional for mid-sized businesses.

If you want a hand picking which control to finish, or someone to run the access review with you so nothing gets missed, that is ordinary work for us. We serve small and mid-sized businesses across Denton County. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).