October Is Cybersecurity Awareness Month. Its Advice Wasn't Written for a Twelve-Person Business — So Here's the Translation.


Awareness Month SMB Translation
September 2026  ·  8 min read

For over twenty years, every October has brought the same national campaign: patch your systems, use a password manager, enable multi-factor authentication. None of it is wrong. All of it quietly assumes a dedicated IT department exists to carry it out. At a typical small business, that job falls to an owner, an office manager, or whoever already handles too much. This year's theme is about building toward the country's next quarter-century. Here's the version of that written for a business your size — one month, four weeks, and a direct link back to everything this series has already covered.


Since 2004, the Cybersecurity and Infrastructure Security Agency and the National Cybersecurity Alliance have co-led a national campaign every October, urging individuals and organizations to take stock of their digital defenses. This year's theme, Securing the Next 250, is framed around the country's 250th anniversary — a deliberately long view, less about this year's specific threat list and more about building lasting habits into how organizations of every size operate.

That's a good aim. The advice underneath it, though, has a structural problem it's carried for two decades: it's written assuming a security team exists to execute it. Patch your systems. Enable MFA. Use a password manager. None of that is wrong — every one of those recommendations has appeared, with real evidence behind it, throughout this series. But "patch your systems" reads very differently to a security operations team running scheduled maintenance windows than it does to an office manager who also handles payroll, scheduling, and the phones.

This post isn't a criticism of the campaign — the advice is sound, and the people behind it know exactly who they're trying to reach. It's a translation. Awareness Month gives you the "what." This is the "what, in the time you actually have, using the tools you already have access to."

Why the translation matters more this year than most

New research published alongside this year's campaign gives the translation real teeth. Verizon's 2026 breach investigations report — analyzing more than 22,000 confirmed breaches across 145 countries — found something worth building the rest of this post around.

73%

of ransomware victims had a credential leak or infostealer infection in the year before the attack — half of them within just 95 days

This is one of the most useful findings in the entire report, because it reframes ransomware from something that strikes without warning into something with a documented, often-recent precursor. The credential leak isn't background noise. In nearly three out of four cases, it's a warning that arrived weeks or months ahead of the attack it preceded — and, per the report, usually went unaddressed.

48% of all confirmed breaches this year involved ransomware, up from 44% the year before — the trend line keeps rising Verizon 2026 DBIR
38% / 29% of breaches traced to compromised credentials and unpatched edge-device vulnerabilities respectively — the two entry points this series has returned to all year Verizon 2026 DBIR
69% of ransomware victims refused to pay last year — a record high, and the subject of one of our own posts this year (linked below) Verizon 2026 DBIR

Put together, the picture is encouraging in a specific way: the two most common doors in — stolen credentials and unpatched internet-facing devices — are also the two most thoroughly covered topics in this series, and the businesses handling them well are increasingly the ones who get to say no when the demand arrives.

The translation: four weeks, four habits

Rather than repeat generic advice, here's our own month-long version, sized for a business without a dedicated security team — one habit a week, each with a direct link to a fuller explanation already published on this blog if you want the detail behind it.

1

Know what's actually exposed to the internet

Nearly a third of this year's breaches traced back to unpatched devices facing the internet — routers, VPN appliances, firewalls. You can't defend what you haven't inventoried. This week, spend thirty minutes finding out what your business exposes to the outside world and whether it's current.

2

Go past "is MFA on" to "what happens after someone logs in"

Multi-factor authentication is still one of the highest-value controls available, and it remains correct advice. This week's addition: confirm your highest-risk accounts use a phishing-resistant method, and make sure whoever manages your systems knows how to revoke an active session — not just reset a password — if something looks wrong.

3

Audit who — and what — still has access

A credential created for a project that ended, a vendor integration nobody's used in a year, an ID-scanning tool holding more customer data than you realized — each is a standing risk with no remaining benefit. This week, review your connected apps and ask your key vendors the direct questions worth asking.

4

Make sure the bad day has a plan, and that the plan has been tested

The single most repeated, most reliably true finding in security research: a written incident response plan and a backup that's actually been restored — not just scheduled — separate a contained incident from a business-ending one. This week, if you don't have either, build them. If you do, test them.

Notice what's absent from all four weeks: a large budget, a security hire, or specialized expertise. Every item is something an owner or office manager can do directly, in the time already available this month. That's the actual point of a national awareness campaign — not that everyone becomes a security expert in October, but that everyone does the handful of things that matter most, once, and then keeps doing them.

Why this month, specifically, is worth the effort

It would be easy to treat an awareness campaign as a symbolic gesture — a poster in the break room, an email nobody reads. The data argues against that read. The businesses driving this year's record ransomware refusal rate weren't lucky; researchers attribute the shift directly to better preparation. The credential leaks that precede three in four ransomware attacks are, per this year's findings, usually visible for weeks or months before the attack lands — which means the window to act on Awareness Month's advice isn't hypothetical. It's often already open, right now, for businesses that haven't checked.

If you take one thing from this post, make it this: the credential leak or exposed device sitting unaddressed in your business right now, if one exists, is not a future problem. Per this year's own breach data, it's frequently the thing that's already begun.
This is precisely what the Veriti Spottr CyberScore is built to surface continuously — not a once-a-year audit, but an ongoing answer to whether the exposures and credential leaks behind most of this year's breaches exist in your business right now. Our Threat Intelligence feed does the same for what's confirmed under active attack. Awareness Month is a good prompt to start. The point is not stopping once October ends.

The short version

This year's national campaign is built around a 250-year view, which is the right instinct — durable habits matter more than any single year's threat list. But durable habits, for a business without a security team, means a short, specific list done consistently rather than a long one attempted once. Know what's exposed. Go past "MFA is on." Audit who still has access. Test the plan for the bad day. Four weeks, four habits, and — per this year's own data — a meaningfully better chance of being one of the businesses that gets to say no when the moment arrives.

Start the month knowing exactly where your business actually stands.

View the Threat Intelligence feed → Find Out More About Veriti Spottr →
VS
Veriti Spottr Team AI-powered cyber risk clarity for SMBs  ·  veritispottr.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.