
October 5, 2026
Cyber Security Awareness Month: five basics that work
Five simple security controls every business should have in place, from MFA everywhere to a verification process that stops payment fraud.
Read MoreOctober is Cyber Security Awareness Month, which means your inbox and LinkedIn feed are about to fill up with security advice. Some of it useful, a lot of it recycled.
We are going to keep this one simple. Most successful attacks on smaller businesses don't start with anything clever. They start with a reused password, an unpatched system, or someone being talked into doing something they shouldn't. The fixes aren't glamorous, but they work. Here are five things every business should be doing, and if you can honestly tick them all off, you are ahead of plenty of organisations much bigger than you.
Multi-factor authentication (MFA) means a stolen password on its own isn't enough to get in. For the effort involved, nothing else comes close.
The important word is everywhere. We regularly see businesses with MFA on email that have forgotten the finance system, the cloud admin console, the VPN, the domain registrar and the company social media accounts. Attackers don't need every door open. They need the one you forgot to lock.
Not all MFA is equal. An authenticator app, passkey or hardware key is stronger than an SMS code, which can be intercepted through SIM swapping. Watch out for push notification fatigue too, where an attacker spams approval prompts until someone taps "approve" to make them stop. Turning on number matching deals with most of that. SMS is still far better than nothing.
Length beats complexity. "P@ssw0rd1" ticks every complexity box and falls over in seconds. Three random words strung together is longer, harder to crack and easier to remember. If you want to see the difference for yourself, we cover it in how secure is my password?
The bigger problem is reuse. When a site you signed up to years ago gets breached, those credentials get tried against your email, Microsoft 365 and VPN. It's called credential stuffing, and it works because people reuse passwords.
A password manager is the best answer. Everyone gets long, unique passwords for every account and only has to remember one. Shared vaults also replace that spreadsheet called passwords.xlsx (you know the one). Just make sure the password manager itself is protected with a strong passphrase and MFA, because it is now the most valuable account you have. For the policy side, see our guide to password policy for small businesses.
Routinely and actively. They are two different jobs.
Routinely means automatic updates switched on for laptops, phones, browsers and Office apps. Most of your estate will look after itself if you let it.
Actively means someone owns the things that don't update themselves: firewalls, routers, VPN appliances, website plugins and line-of-business applications. Internet-facing devices are a favourite target because they are exposed and easily forgotten. Critical security patches should be applied in days, not saved for the next quarterly maintenance window.
Two more things. Know when software reaches end of life, because no more patches means a growing list of known holes. And keep a simple list of what you actually have. You can't patch what you don't know exists. Regular vulnerability assessments are a good way to check nothing has slipped through.
It does if it isn't a once-a-year tick box. An annual 45-minute video watched at double speed is forgotten within weeks.
Little and often works better. Keep it short and relevant to the attacks your people will actually see: fake invoices, fake delivery notices, fake Microsoft login pages and calls from "IT support". Our phishing awareness guide for small businesses covers the common ones.
Then test it. Simulated phishing tells you whether the training is landing. The point is learning, not catching people out. If clicking a test link gets someone named and shamed, the next time they click a real one they won't tell you, and early reporting is what limits the damage. Make reporting easy and thank people when they do it.
It also pays to teach people to protect themselves at home. Staff who look after their own accounts tend to look after yours. There is more on building this into your culture in our post on security awareness training.
This is the one that rarely gets mentioned, and it is the most underrated control on the list.
Some of the most expensive frauds involve no malware at all. Finance receives an email from the MD asking for an urgent payment to a new supplier. A supplier emails to say their bank details have changed. A Teams or Slack message comes from a colleague's account asking for a login. The email might come from a genuinely compromised account. The voice on the phone might even be cloned. Technology often won't catch it, because nothing technically malicious has happened.
A good process will. The rule is simple: any request to move money, change bank details, share credentials or skip normal procedure gets verified through a different channel to the one it arrived on.
Write it down and make it non-negotiable, including for senior leadership. The attacker is relying on urgency and seniority to rush someone past their judgement. A process that says "we always check, no exceptions" takes both away. It costs nothing, and it stops scams that would get straight past expensive tools. Like any control, it only works if it is followed under pressure, so test it now and then.
None of this is new, and that is the point. Use this month as a reason to check honestly. MFA everywhere? Unique passwords? Patches applied? Staff who know what to look for? A process for verifying unusual requests? If any answer is "mostly", that is your to-do list.
Cyber Security Awareness Month runs every October. It is a useful prompt for businesses to review their security basics and refresh staff awareness.
SMS codes are much better than no MFA, but they can be intercepted through SIM swapping. Authenticator apps, passkeys or hardware keys are stronger and should be used for email, admin and finance accounts where possible.
MFA on every account that supports it gives the biggest return for the least effort. Pair it with a verification process for payment and bank detail changes, which stops most invoice and impersonation fraud.
Verify any request to move money or change bank details through a different channel to the one it came in on, using contact details you already hold. Make it a written rule that applies to everyone, including directors.
If you want a hand with any of this, whether that's rolling out MFA and a password manager, getting patching under control or setting up phishing simulations, get in touch through our contact page. We're happy to talk it through.

October 5, 2026
Five simple security controls every business should have in place, from MFA everywhere to a verification process that stops payment fraud.
Read More
October 2, 2026
A single phone call to an IT help desk cost TfL a reported £29 million. Here's how help desk impersonation works and how to stop it.
Read More
August 24, 2026
AI has made phishing emails harder to spot by sight. Here's what's changed, and the checks that still work.
Read More