October Is Cybersecurity Awareness Month. Its Advice Wasn't Written for a Twelve-Person Business — So Here's the Translation.
For over twenty years, every October has brought the same national campaign: patch your systems, use a password manager, enable multi-factor authentication. None of it is wrong. All of it quietly assumes a dedicated IT department exists to carry it out. At a typical small business, that job falls to an owner, an office manager, or whoever already handles too much. This year's theme is about building toward the country's next quarter-century. Here's the version of that written for a business your size — one month, four weeks, and a direct link back to everything this series has already covered.
Since 2004, the Cybersecurity and Infrastructure Security Agency and the National Cybersecurity Alliance have co-led a national campaign every October, urging individuals and organizations to take stock of their digital defenses. This year's theme, Securing the Next 250, is framed around the country's 250th anniversary — a deliberately long view, less about this year's specific threat list and more about building lasting habits into how organizations of every size operate.
That's a good aim. The advice underneath it, though, has a structural problem it's carried for two decades: it's written assuming a security team exists to execute it. Patch your systems. Enable MFA. Use a password manager. None of that is wrong — every one of those recommendations has appeared, with real evidence behind it, throughout this series. But "patch your systems" reads very differently to a security operations team running scheduled maintenance windows than it does to an office manager who also handles payroll, scheduling, and the phones.
Why the translation matters more this year than most
New research published alongside this year's campaign gives the translation real teeth. Verizon's 2026 breach investigations report — analyzing more than 22,000 confirmed breaches across 145 countries — found something worth building the rest of this post around.
of ransomware victims had a credential leak or infostealer infection in the year before the attack — half of them within just 95 days
This is one of the most useful findings in the entire report, because it reframes ransomware from something that strikes without warning into something with a documented, often-recent precursor. The credential leak isn't background noise. In nearly three out of four cases, it's a warning that arrived weeks or months ahead of the attack it preceded — and, per the report, usually went unaddressed.
Put together, the picture is encouraging in a specific way: the two most common doors in — stolen credentials and unpatched internet-facing devices — are also the two most thoroughly covered topics in this series, and the businesses handling them well are increasingly the ones who get to say no when the demand arrives.
The translation: four weeks, four habits
Rather than repeat generic advice, here's our own month-long version, sized for a business without a dedicated security team — one habit a week, each with a direct link to a fuller explanation already published on this blog if you want the detail behind it.
Know what's actually exposed to the internet
Nearly a third of this year's breaches traced back to unpatched devices facing the internet — routers, VPN appliances, firewalls. You can't defend what you haven't inventoried. This week, spend thirty minutes finding out what your business exposes to the outside world and whether it's current.
Go past "is MFA on" to "what happens after someone logs in"
Multi-factor authentication is still one of the highest-value controls available, and it remains correct advice. This week's addition: confirm your highest-risk accounts use a phishing-resistant method, and make sure whoever manages your systems knows how to revoke an active session — not just reset a password — if something looks wrong.
Audit who — and what — still has access
A credential created for a project that ended, a vendor integration nobody's used in a year, an ID-scanning tool holding more customer data than you realized — each is a standing risk with no remaining benefit. This week, review your connected apps and ask your key vendors the direct questions worth asking.
Make sure the bad day has a plan, and that the plan has been tested
The single most repeated, most reliably true finding in security research: a written incident response plan and a backup that's actually been restored — not just scheduled — separate a contained incident from a business-ending one. This week, if you don't have either, build them. If you do, test them.
Why this month, specifically, is worth the effort
It would be easy to treat an awareness campaign as a symbolic gesture — a poster in the break room, an email nobody reads. The data argues against that read. The businesses driving this year's record ransomware refusal rate weren't lucky; researchers attribute the shift directly to better preparation. The credential leaks that precede three in four ransomware attacks are, per this year's findings, usually visible for weeks or months before the attack lands — which means the window to act on Awareness Month's advice isn't hypothetical. It's often already open, right now, for businesses that haven't checked.
The short version
This year's national campaign is built around a 250-year view, which is the right instinct — durable habits matter more than any single year's threat list. But durable habits, for a business without a security team, means a short, specific list done consistently rather than a long one attempted once. Know what's exposed. Go past "MFA is on." Audit who still has access. Test the plan for the bad day. Four weeks, four habits, and — per this year's own data — a meaningfully better chance of being one of the businesses that gets to say no when the moment arrives.
Start the month knowing exactly where your business actually stands.
View the Threat Intelligence feed → Find Out More About Veriti Spottr →📚 Credential Security Series → Read the full series

Comments
Post a Comment