Cybersecurity Basics

What Should a Small Business Do for Cybersecurity Awareness Month?

Five ordinary weak spots keep showing up in breaches. These seven steps address them, and each one is a task you can start in an afternoon.

96%
of ransomware victims (attacks that lock your files until you pay) with a known size had fewer than 1,000 employees, so ransomware clearly reaches small businesses (Verizon 2026 Data Breach Investigations Report)
31%
of all breaches, at companies of every size, started when attackers used a known software flaw nobody had fixed, the most common way in (Verizon 2026 report)
62%
of all breaches, at companies of every size, involved a person being tricked or making a mistake, not just technology failing (Verizon 2026 report)
Published October 6, 2026Simpatico SystemsManaged IT15 Min Read

What should a small business do for cybersecurity awareness month, and where do you even start? Start with the habits that the month’s organizers publish every October: a password manager with strong passwords, multifactor authentication (a second proof that it is really you, such as a code on your phone), software updates, and a plan for spotting and reporting phishing. Then add three business basics: backups you have tested, a short list of who has admin access, and a printed list of who to call in an incident. Each is a task you can start in an afternoon, and the list starts with the cheapest steps. This is where good security starts, not where it ends. Doing these seven things puts you far ahead of doing none of them, and the hard part is not doing them once. It is keeping them done.

Key Takeaways

What matters most. Breaches keep coming through the same five ordinary doors: weak or stolen passwords, out-of-date software, fake emails, ransomware that locks your files, and the vendors you trust with access.

What it means for you. Cybersecurity at your size is a handful of habits, each doable in an afternoon. The hard part is keeping them done as people and software change, which is the job a good managed service provider (MSP) takes on.

What to do.

  • Turn on a second sign-in step (multifactor authentication, a code on your phone) for email and banking first.
  • Put every login in a password manager and switch on automatic updates.
  • Restore one real file from a backup to prove it works, and print a one-page list of who to call in an incident.
  • If you would rather not run this list yourself, ask an outside IT company to take it on and show you proof of each one.
Small business owner checking a list of what a small business should do for cybersecurity awareness month (image for: what should a small business do for cybersecurity awareness month)

What does cybersecurity actually mean for a small business, and what matters most?

For a business your size, cybersecurity is not a security department or a pile of expensive tools. It is a short list of habits that close the most common ways attackers get in, plus knowing who to call on the day something goes wrong. Five things matter most. This grouping is ours, drawn from Verizon’s data, and each one maps to a step later in this post:

Stolen or weak passwords

If an attacker has a working password, they can walk in the front door. Steps 1 and 2 close this.

Software that is out of date

Attackers scan for known flaws that were never fixed. In Verizon’s data, across companies of every size, this was the most common way in. Step 3 closes it.

Fake emails and messages

A convincing message gets a person to click, share a password, or send money. Step 4 helps your team spot them.

Ransomware

This is software that locks your files until you pay. A tested backup is what keeps it from stopping your business. Steps 5 and 6 are your defense.

The companies you trust with access

Your IT provider, your software vendors and your accountant can all be a way in. Step 6 and the questions in the provider section cover this.

The sixth thing is not an attack at all. It is not knowing who to call, which turns a bad hour into a bad week. Step 7 fixes that.

The goal is not to cover every risk. It is to get these few things right and keep them right. Getting them right once takes an afternoon each. Keeping them right as people join and leave, passwords change and software updates pile up is the part that slips, and it is the case for having an expert do it. A managed service provider, or MSP, is an outside IT company that does this work for you every month.

What is Cybersecurity Awareness Month, and who runs it?

Cybersecurity Awareness Month is an annual October observance. According to the National Cybersecurity Alliance, it launched in 2004, and the Alliance and CISA, the US Cybersecurity and Infrastructure Security Agency, lead the campaign every October. Its purpose is to raise awareness of online safety so individuals and businesses can protect themselves from cybercrime.

Each year has a theme. In 2026, CISA’s page used “Securing the Next 250,” while the Alliance’s page used “Don’t Make It Easy for Them.” The four actions both pages publish match the core actions of CISA’s Secure Our World program: strong passwords, multifactor authentication, software updates, and recognizing and reporting phishing.

Why does this matter for a business your size?

Verizon’s 2026 Data Breach Investigations Report covers breaches from October 2024 through November 2025 and treats organizations with fewer than 1,000 employees as small. Where the victim’s size was known, about 96 percent of ransomware victims were that size. Ransomware is software that locks your files until you pay.

Across all sizes, the report found ransomware in 48 percent of breaches and the human element present in 62 percent. It only captures breaches that were detected and reported, so it shows patterns, not your personal odds.

What counts as confidential information in a small business?

Every step below protects something, and rules only work when people know what that something is. The National Institute of Standards and Technology (NIST) says in its small business quick-start guide you cannot protect your assets until you identify them, then match the protection to each one’s sensitivity. It also tells you to inventory and classify your business data, and to limit sensitive information to the employees who need it to do their jobs.

Here is a simple way to start. This list is ours, not NIST’s, so adjust it to your business:

  • Customer and client information. Names tied to account or ID numbers, contracts, payment details, and anything a client told you in confidence.
  • Employee information. Payroll, Social Security numbers, bank details for direct deposit, and health or HR records.
  • Money and access. Bank and card details, logins, security codes, and the answers to security questions.
  • Business-confidential material. Pricing, bids, contracts, plans, and anything covered by a nondisclosure agreement.

Put this on one page with a real example of each from your own business, so nobody has to guess. Mark which items may never go into email, a chat tool, or an AI tool outside the ones you approve. If an item is hard to place, treat it as confidential until someone decides. Any policy you write later, whether for passwords, AI tools or sharing files, can then point back to this list.

What should a small business do for cybersecurity awareness month, step by step?

Work down this list, starting with step 1. Each item says how to tell it is done and who can skip it.

Turn on multifactor authentication, starting with email and money

Multifactor authentication, or MFA, asks for a second proof of identity, such as a code from an authenticator app, at sign-in. CISA says that even if someone steals your password, they cannot meet the second step. NIST’s small business quick-start guide calls MFA one of the fastest, cheapest ways to protect your data and suggests starting with banking, accounting and tax, merchant, email, and Google, Microsoft or Apple accounts. You are done when a written list of those accounts shows MFA on for each. This might not be for you if a provider enforces MFA for you, but ask them to show you the report.

Put every login in a password manager

A password manager is a program that generates, stores and fills in your passwords, so people remember one strong master password. CISA says a strong password is at least 16 characters, random, and different for every account. The FTC’s small-business guide says at least 12. Aim for 16 or more where a site allows it, and never go below 12. You are done when every person has a manager and shared accounts like banking and payroll live in it. This might not be for you if your IT provider already issues one to everyone, in which case ask to see the setting instead of redoing it.

Turn on automatic updates

CISA says many software updates are created to fix security risks and that every product you use should have auto-updates on. In Verizon’s data, exploiting vulnerabilities was the most common way into a breach at 31 percent, ahead of credential abuse at 13 percent. Only 26 percent of critical vulnerabilities in CISA’s Known Exploited Vulnerabilities catalog were fully fixed in 2025, with a median of 43 days to full resolution. You are done when laptops, phones, browsers and the office router show updates on. This might not be for you if a provider patches for you, but ask for the patch report.

Learn the signs of phishing, and agree on how to report it

Phishing is a fake message built to get a click, a password or a payment. CISA’s phishing guidance lists urgent or emotional language, requests for personal or financial information, shortened links you do not trust, and look-alike addresses. A 2018 FTC post suggests teams “take five before responding”: mention the message to a coworker and call the sender on a number you already know. You are done when everyone knows where to forward a suspect message. We cover the types in our phishing guide. This might not be for you if a provider already runs training, but ask for completion dates.

Back up your data and test the restore

CISA’s small business guidance says to perform and test backups, and its ransomware guide recommends offline, encrypted backups with regular restore tests. A 2020 FTC post adds separate credentials for backups. You are done when you have restored a real file from backup and written down the date. This might not be for you if an IT provider runs backups, in which case ask for the date of the last test restore.

Check who has admin access

Admin access is the power to install software and change settings. CISA’s small business guidance lists removing administrator privileges from user laptops and turning on MFA for all system administrator accounts. NIST asks whether access is restricted to people who need it and removed when they no longer do. You are done when a written list names everyone with admin rights, including vendors and former staff, with a reason beside each. This might not be for you if you run a one-person shop, where the list is one name and the job is confirming MFA is on.

Write a one-page incident contact list

CISA’s Incident Response Plan Basics says a plan should include a list of key people and that copies should be printed, because email, chat and document storage may be down during an incident. NIST’s guide sketches a table with a business leader, technical contact, state police, legal, bank and insurance. You are done when printed copies sit with the owner and one backup person. This might not be for you as written if you have contractual or legal notification duties, since CISA suggests reviewing the plan with an attorney.

What should you ask an outside IT provider to confirm is already in place?

If a managed service provider, or MSP, runs your IT, you may not need to redo these. You do need proof. Verizon’s definition of “partner” includes outsourced IT support, and it reports that breaches with third-party involvement reached 48 percent of breaches, up 60 percent from the prior year’s dataset. The FTC says to put security provisions in vendor contracts and confirm vendors follow your rules.

Ask for answers you can see:

  • MFA: Is it required on email, admin accounts and remote access, and can you show me the report?
  • Updates: Are they automatic on every device, and how do you report failures?
  • Admin access: Who has it, including your staff and former employees?
  • Backups: Where are they, are they kept separate from the network, and when was the last test restore?
  • Incidents: Who is our first call, and what is the after-hours number?

This is where Simpatico fits. As an MSP, we help make sure our clients are consistently doing all of these things, so none of it depends on one person’s memory or on a busy week. If you would rather not run this list yourself, that is what outsourcing to an expert is for.

Unsure which kind of provider you have? Read the difference between an MSP and an MSSP, a managed security services provider and how to choose managed IT services. If you have no outside provider, the list above is your own to-do list.

How should you respond to a phishing email or suspected incident in the first hour?

Use this order, drawn from FTC and CISA guidance.

Stop and tell someone

Do not click again. The FTC says to talk to your colleagues and share what happened.

Contain it

Change any compromised passwords and disconnect the infected computer or device from the network. The FTC says to disconnect without powering down. CISA says to power down only if you cannot disconnect.

Call your experts

CISA says to share information with your IT department, security providers, insurance company and leadership.

Report it

For phishing, forward the message to reportphishing@apwg.org and report it at ReportFraud.ftc.gov. For ransomware, CISA says to notify CISA, your local FBI field office, or the FBI’s Internet Crime Complaint Center.

Notify the right people

The FTC’s data breach guide says to contact law enforcement and, where personal information was exposed, follow your state’s notification rules.

This might not be for you if your provider has its own incident process. Follow theirs and use this list as a check.

What should you do next?

Pick one item from the seven and finish it first, or hand the list to your provider and ask for proof of each. Schedule a strategy session and we will walk through which of these are already covered in your setup and which are still open.

Which of these seven could you show proof of, and which one are you least sure about?

Frequently Asked Questions

What is Cybersecurity Awareness Month?
It is an annual October observance about online safety. According to the National Cybersecurity Alliance, it launched in 2004, and the Alliance and CISA lead it every October. Individuals, schools and businesses join in, usually by adopting a short set of safe habits.
What is CISA?
CISA is the Cybersecurity and Infrastructure Security Agency, a US federal agency. It publishes free cybersecurity guidance for businesses of every size, including a small business guide and the Secure Our World program, and it co-leads Cybersecurity Awareness Month each October with the National Cybersecurity Alliance.
What is multifactor authentication?
Multifactor authentication, or MFA, asks for a second proof that it is really you, such as a code from an authenticator app, in addition to your password. CISA says that even if someone steals your password, they cannot complete the second step. The National Institute of Standards and Technology calls it one of the fastest, cheapest protections.
What are the four basic actions CISA recommends?
CISA’s Secure Our World program names four: use strong passwords with a password manager, turn on multifactor authentication, update software, and recognize and report phishing. For organizations, CISA’s awareness page adds backing up data, using logging, encrypting data, and keeping an incident response plan.
Are small businesses really targeted by cybercriminals?
Yes. In Verizon’s 2026 report, about 96 percent of ransomware victims with a known size had fewer than 1,000 employees, which the report counts as small. The FTC also tells small businesses that cybercriminals target companies big and small, so basics matter at every size.
What should I do first if someone clicks a phishing link?
Tell a coworker, then change any compromised passwords and disconnect the affected device from the network. Contact your IT provider, and report the message to the FTC at ReportFraud.ftc.gov. If personal information may be exposed, follow your state’s notification rules and consider contacting law enforcement.
Which action should a small business do first?
Turn on multifactor authentication for email and banking. NIST calls MFA one of the fastest, cheapest ways to protect data and suggests starting with accounts that reach sensitive information. After that, add a password manager, automatic updates, and a tested backup, in that order.
Do I still need to act if an IT provider manages my systems?
You still need to confirm the work is done. Ask your provider to show MFA reports, update status, admin access, and the date of the last test restore. Verizon counts outsourced IT support among business partners, so a provider can be part of your risk, not only your protection.

Prove each one is done

Walk the seven actions with us and see which are covered and which are open.

  • Seven actions in a sensible order
  • What to ask your IT provider to show
  • A first-hour plan for phishing

30 Minutes · No Pressure · No Obligation