CybersecurityOpleidingKMO

October is Cybersecurity Month: 4 things your team can actually do this month

October is European Cybersecurity Month. No reason for a project, but a good hook to actually do four small things: one per week, with an honest time estimate and a simple measurement at the end.

Brian

Brian

Co-Founder & CEO

2 October 20265 min read
Illustration of a calendar with four check marks, cybersecurity month theme

Every October, European Cybersecurity Month takes place, an initiative of ENISA and the European Union. In Belgium, the Centre for Cybersecurity Belgium runs its campaign through Safeonweb. You see tips and posters everywhere, and by November everything is back to how it was. For an SME or non-profit of around fifteen people without an IT department, that month is nevertheless a handy hook. Not to set up a project, but to actually do four small things. A month is long enough for four actions and too short for anything big, and it comes back every year, so what you set up now, you repeat next year almost by itself. Below is the week-by-week plan, with an honest time estimate.

Week 1: discuss three real phishing emails (15 minutes)

Phishing is still the way most incidents at small businesses begin. Bring three real examples to the team meeting that is already on the calendar: a fake supplier invoice, a 'your password expires today' email and a message supposedly from the owner with an urgent request. Go through together what gives them away, and what you do when you are not sure.

  • Time: 15 minutes, in a meeting that was already planned. No IT knowledge needed.
  • Result: everyone knows who to report a suspicious email to, and that reporting never gets you blamed.

A phishing exercise with a test email is also an option, but the conversation matters more than the test. How to recognise phishing and what to do if someone clicked anyway is covered in our post on phishing.

Week 2: password manager and MFA per employee (10 minutes per person)

In week two you go round one by one. Not with an email saying 'everyone turn on MFA', because then half of them will not. Instead, ten minutes per person. You check two things: is multi-factor authentication (MFA) enabled on their email and Microsoft 365, and are their passwords in the team's password manager rather than in a note or an Excel file?

  • Time: 10 minutes per employee, so about 2.5 hours for a team of 15, spread over the week.
  • Result: a list of who has MFA, who uses the password manager and who does not yet.

For MFA we have written a step-by-step plan that you can work through in a few weeks. If you do not have a password manager yet, first read why it is no longer a luxury.

Week 3: restore a back-up and make an emergency contact list (1 hour)

Almost every business has a back-up. Few businesses have ever tried to restore something from it. In week three, pick one folder and restore it to a different location. Does it work and is the content correct? Then you know what you have. If it does not work, you know that too, and better now than after a ransomware attack.

In the same hour, make a one-page emergency contact list: your IT partner, your bank, your insurer, your accountant, your telecom provider and the colleague who holds the keys to the most important accounts. Print it, because if your email is down, a digital list is useless.

  • Time: 1 hour for the owner, possibly together with your IT partner.
  • Result: one successful restore test with the date noted, and a list hanging on the wall.

Why OneDrive or SharePoint alone is not a back-up is explained in our post on the 3-2-1 rule.

Week 4: clean-up day for accounts, devices and access (1 hour)

In the last week you tidy up: old accounts of people who have left, laptops sitting in a cupboard but still connected to your environment, shared folders with external parties who no longer collaborate, and access for suppliers who finished their project.

  • User accounts: who is on the list but no longer works here? Block, and delete after a fixed period.
  • Devices: wipe old laptops and phones or remove them from your Microsoft 365.
  • Sharing with external parties: revoke shared links and guest accounts that are no longer needed.
  • Suppliers and freelancers: access that outlived the project goes.

Count on an hour, no more. If you find a lot, get your offboarding in order straight away with our checklist for when an employee leaves.

How to announce it, and what to measure on 31 October

The tone decides whether this works. Do not announce it as 'mandatory security awareness'. Just say what you are going to do: October is cybersecurity month, we are doing four small things, one per week, and it costs you ten minutes. Do not ask for signatures, ask for cooperation. And if someone admits they almost clicked last month, that is the best thing that can happen.

Is your team also using AI tools like ChatGPT or Copilot by now? How to start with them safely is covered in our post on the AI workshop.

Four actions without measurement are four good intentions. Three questions are enough, without a report or slide deck.

  • Who reports? How many suspicious emails were reported in October, and by whom? More reports is good news, not bad.
  • Who has MFA? The list from week two. Aim for everyone, and follow up on the exceptions in November.
  • Is the test in the calendar? Put the next restore test in the calendar now for six months out, and the clean-up day for next October.

Want to know where you stand before you start the four weeks? A free cyber scan gives you a clear picture of your devices, access and back-ups within a few weeks, so you know which week deserves the most attention.