Cybersecurity Awareness Month: A 30-Day Action Plan
October 1st, 2026
October is Cybersecurity Awareness Month. For most small and mid-sized businesses it passes the way it always does: a vendor email, a poster in the break room, and nothing in the environment that actually changes. That is the wrong outcome for the cheapest month of security work on the calendar.
The patterns behind breaches at companies this size do not change much from year to year. Credentials that were stolen or reused, a device nobody patched, an employee who believed a convincing email, and a backup that turned out not to restore. None of that requires a security department to fix. It requires four weeks of attention and one person who owns the list.
Here is a 30-day plan for a company without a security team. One task per week, each one something you can verify, and each one producing a result you can hand to an auditor, an insurer, or a customer who sends a security questionnaire.
Week 1: Put Multi-Factor Authentication Where It Counts
If you do one thing in October, do this one. Stolen credentials are still the most common way an attacker gets in, and multi-factor authentication is the control that breaks it. A password that leaks in a breach somewhere else is useless to an attacker who cannot pass the second factor.
Do not try to cover every system in a week. Work in this order:
- Email, because it is the account everything else resets through
- Remote access, including VPN and any published desktop
- Finance and payroll systems, where the money moves
- Administrative accounts on your servers, network gear, and cloud consoles
- Line of business applications holding customer or patient data
Use an authenticator app or a hardware key. Text message codes are better than nothing, but they are the weakest form and are routinely defeated by SIM swapping and relay attacks. Expect a week of support tickets and a few people who lose a phone. Plan the help desk time rather than being surprised by it.
Week 2: Build the Device List, Then Patch It
You cannot patch what nobody has counted. Most organizations can name their servers and have no idea how many devices actually sit on the network. Start with an inventory, and include the equipment that never makes the IT spreadsheet:
- Workstations and laptops, including the ones people bought themselves
- Servers, physical and virtual
- Firewalls, switches, and wireless access points
- Multifunction printers and copiers, which run firmware and often hold a hard drive
- Phone systems, cameras, and anything else with an IP address
Once the list exists, set a patch cadence you can keep: operating systems and browsers on automatic updates, servers and network gear on a monthly maintenance window, firmware checked quarterly. The exploitable vulnerabilities in most small business incidents were public for months before anyone used them. Good network security is less about exotic tools than about closing known holes on a schedule.
Week 3: Run a Phishing Drill, Then Train to the Result
Awareness training that everyone clicks through once a year does not change behavior. A simulated phishing email does, because it produces a number you can compare month over month.
Run a baseline test in week three and keep it fair. Use a template that looks like the real thing at your company: an invoice from a known vendor, a password expiry notice, a message that appears to come from a manager. Then train to what people actually missed rather than to a generic module.
Three things make the difference between a drill that helps and one that breeds resentment:
- Tell people the program exists and that reporting is the goal, not a clean click rate
- Give every mailbox a one-click report button, and thank the people who use it
- Never punish someone who clicks. Punished employees hide the next mistake, and hiding is what turns an incident into a breach
Van Ausdall & Farrar offers free security awareness training and free security training tools you can run against your own staff this month at no cost.
Week 4: Restore a Backup on Purpose
An untested backup is a hope, not a control. The failure mode is consistent: the backup job reports success for two years, and on the day it matters, the restore fails halfway through. Ransomware operators count on exactly that.
Spend week four proving recovery works:
- Pick a real server or a real file share, and restore it to a lab or spare hardware
- Time the restore and write the number down, because that is your actual downtime
- Confirm at least one copy is offline or immutable, so an attacker with domain admin cannot encrypt it
- Check whether the last year of data is really in the backup, or only the last 30 days
If the restore fails, you have found a problem in October instead of on a Tuesday morning when production is down. That is a win, not a failure. Most organizations that recover quickly from ransomware got there by testing, and the ones that pay are usually the ones that never did.
The Other Eleven Months
The month ends and nothing you fixed stays fixed on its own. Access changes when people are hired and leave, new devices appear, and last year's clean phishing number drifts back up. What keeps the work from decaying is a regular review: who has access to what, what is unpatched, whether the backup still restores, and whether the alerting you pay for is being read by someone.
That is what managed IT services covers for companies without a security team of their own. Awareness month is a good prompt to start, but the value is in the twelve months that follow it.
If you want a starting point that tells you where your environment actually stands, a cyber threat assessment gives you the inventory, the gaps, and the priorities in one pass. Contact our team to schedule one this October.
Posted in: Cybersecurity
