October is Cybersecurity Awareness Month. Skip the posters.
Every October brings a wave of generic security advice. Here's what actually moves the needle for a Cape Breton business with 10 to 100 employees.
Every October our inbox fills up with the same thing: vendor-branded awareness kits, lunch-and-learn templates, posters with cartoon padlocks, and PDFs titled 10 Tips to Stay Safe Online. Most of it has been recycled since 2014.
We're not going to add to that pile. If you run a business in Cape Breton and you've got between 10 and 100 people on payroll, there are really only a handful of things that will change your actual risk this month. Here they are, in the order we'd tackle them with a client.
1. Confirm MFA is actually on — on every account, not just email
We wrote back in July about why MFA being enabled doesn't mean you're protected. The short version: most businesses have MFA on their Microsoft 365 logins and nothing else. That leaves VPNs, remote-access tools, your line-of-business software, your accounting package, and your admin consoles wide open.
Spend an hour this month pulling a list of every system someone logs into with a password. For each one, answer: is MFA on, is it enforced (not optional), and is it something stronger than SMS. If any answer is no, that's your October project.
2. Run a phishing simulation — a real one, not a free sample
Awareness training without measurement is theatre. You need to know, as a number, what percentage of your staff will click a convincing lure. Then you need to know whether that number is going up or down over time.
We run phishing simulations for clients on a quarterly basis. The first run almost always lands between 15% and 30% click-through. By the fourth or fifth run most teams are under 5%, and the people who do click know to report it immediately — which is honestly more important than not clicking in the first place.
October is a natural time to start. If you've never done one, you'll learn more about your real exposure in a week than you would from a year of posters.
3. Get an honest inventory of what's actually on your network
We sit down with new clients all the time and ask: how many computers do you have, how many servers, what's on your WiFi, who still has a login. The answer is almost always wrong by a factor of two.
Old laptops that someone took home three years ago. A printer with default admin credentials sitting on the main network. The former bookkeeper's Microsoft 365 account, still active, still receiving mail. A spare WAP somebody plugged in to extend coverage to the back office.
Every one of those is a potential entry point. A proper security assessment will surface them. If you don't want to go that formal, at minimum do a login audit this month: pull the user list from Microsoft 365, from your accounting software, and from your line-of-business apps, and disable everyone who shouldn't be there anymore.
4. Verify your backups by actually restoring something
We've said it before and we'll keep saying it: a backup you haven't restored from is a hope, not a backup. Microsoft 365, in particular, catches people off guard — it's not a backup, it's a live service with a 30-to-90-day retention window depending on what you deleted and how.
Pick one file, one mailbox, and one database. Restore each to a test location. Time how long it takes. If any of those three fails or takes longer than you can live with, you've found a problem that would be catastrophic in a real incident. Our Cloud Workspace Backup covers the Microsoft 365 side; for everything else you need to know who owns the restore process and when it was last tested.
5. Decide what you'd actually do at 2 AM on a Saturday
This is the part most awareness months skip. If a ransomware note shows up on a workstation tomorrow morning, what are the first three phone calls you make, in order? Who has authority to shut down the network? Who talks to the insurance carrier? Who talks to staff? Who talks to customers?
If you can't answer those questions in writing, you don't have an incident response plan — you have an intention. Write it down, print it, and put a copy somewhere that doesn't require network access to read. One page is fine. One page you can find at 2 AM beats a 40-page policy that lives on the file server you can no longer get to.
For clients on our Managed Threat Response tier, we're the first call and we take it from there. For everyone else, make sure the first call isn't we'll figure it out when it happens.
What we'd actually do if you gave us October
If a Cape Breton business owner handed us the month and said make us meaningfully more secure by November 1, here's the order:
- Week 1 — MFA audit across every system, not just email.
- Week 2 — Baseline phishing simulation, user cleanup across Microsoft 365 and line-of-business apps.
- Week 3 — Test restores from backup. Document what worked, what didn't.
- Week 4 — One-page incident response plan, printed, posted, and walked through with the owner.
None of that is glamorous. None of it will make a good poster. It will make you measurably harder to breach by the time the Christmas rush hits.
If you want a hand picking the right starting point for your business, book a free walkthrough and we'll give you an honest read on where you actually stand.
Talk to us about your business.
Free walkthrough at your business — no obligation, no sales pitch. We'll tell you honestly whether what you have now is fine or whether something we do would actually help.