Skip to main content
Business · Government · Public Safety
Freedom Tech — Technology Solutions for Business, Government & Public Safety
Cybersecurity

Cybersecurity Awareness Month: A 10-Minute Security Check for Small Businesses

October 6, 2026 6 min readBy Matt Jones, President & CTO
Business owner reviewing security settings on a laptop

October is Cybersecurity Awareness Month. Answer these ten yes-or-no questions to see where your business stands, and which gaps to close first.

October is Cybersecurity Awareness Month, the national campaign led by CISA and the National Cybersecurity Alliance. It’s a good excuse to do something most small businesses never get around to: take ten minutes and honestly check the basics.

Here are ten yes-or-no questions. You don’t need to be technical to answer them, and every “no” is a specific, fixable gap. In our experience, most attacks on small and midsize organizations don’t start with anything clever. They start with one of these.

1. Is multi-factor authentication on for everyone’s email?

Email is the key to everything else: password resets, invoices, client files. A stolen password alone shouldn’t be enough to get in. If even one account, including the owner’s or a shared mailbox, skips multi-factor authentication (MFA), that’s the one criminals will find.

2. Does everyone use a password manager?

If people reuse passwords, a breach at some unrelated website becomes a breach at your company. A business password manager makes unique, strong passwords the easy option and lets you shut off access the day someone leaves.

3. Are your backups separate, and have you tested a restore?

Ransomware goes after backups first. Ask two questions: is at least one copy stored where an attacker on your network can’t delete or encrypt it, and when did someone last restore files from it to prove it works? “We have backups” and “we can recover” are not the same thing. Microsoft 365 and Google Workspace data needs its own backup too.

4. Do updates install automatically, on every device?

Most attacks use known flaws that already have a fix. Computers, phones, browsers, and especially firewalls and remote-access tools need updates on a schedule, with someone checking that they actually happened.

5. Have you removed everyday admin rights?

When people work from accounts with full administrator rights, one bad click can install anything. Day-to-day accounts should be standard users, with admin access used only when it’s needed.

6. Do your computers have modern protection, and is someone watching it?

Traditional antivirus misses a lot of today’s attacks. Endpoint detection and response (EDR) watches for suspicious behavior, but its alerts only help if someone responds to them, including at 2 a.m. on a Saturday.

7. Would your team know what to do with a suspicious email?

Your people will see phishing emails. What matters is whether they recognize them, report them with one click, and feel comfortable saying “I clicked something” right away. Short, regular training and practice emails build that habit far better than a once-a-year video.

8. Do you verify payment changes by phone?

A fake “our bank details have changed” email from a real vendor, or a rushed wire request from the “boss,” needs no malware at all. A simple rule stops it (more email safeguards here): any new or changed payment instructions get confirmed by phone, using a number you already have, not the one in the email.

9. Is access removed the same day someone leaves?

Former employees, and the accounts and apps they signed up for, are a common back door. Keep a short checklist: disable accounts, change shared passwords, recover devices, and transfer ownership of files and mailboxes.

10. Do you know who to call, and what happens next, if something goes wrong?

The first hour of an incident matters most. Write down who to call, who can make decisions, and how you’ll keep working. Check whether your cyber insurance requires you to use specific responders, and keep those numbers somewhere you can reach if email is down.

How did you score?

  • 9–10 yes: You’re ahead of most small businesses. Keep testing, especially backups and training.
  • 6–8 yes: You have a foundation, but the gaps are the kind attackers look for. Close them this quarter.
  • 5 or fewer: Start with MFA, backups and payment verification this month. Those three stop a large share of the incidents we see.

If you answered “I’m not sure” to several of these, that’s an answer too. It usually means nobody owns security day to day.

Want a second opinion?

Freedom Tech offers a free, confidential Cybersecurity Risk Assessment: a dark-web credential scan, a review of your Microsoft 365 or Google Workspace security, a backup check, and a plain-English report with your priorities. For the full picture, download our free guide, The Cybersecurity Crisis: 12 Protections Every Organization Must Have Now, or book a 10-minute call at freedomtech.us/book.

The Cybersecurity Crisis: 12 Protections Every Organization Must Have Now guide cover

Free Executive Report · 2026

The Cybersecurity Crisis: 12 Protections Every Organization Must Have Now

How attacks really happen, what a breach really costs, and the 12 protections every organization needs, with a five-minute self-assessment.

Get the Free Guide

Start With the Outcome.

Tell us what your organization needs to accomplish. We’ll help determine the right technology path. Book a 10-minute call, or call 910-920-0999.

Technology Platforms We Work With

Cloud & Productivity

  • Microsoft
  • Google
  • Amazon Web Services

Computers & Devices

  • Apple
  • Dell
  • HP
  • Lenovo

Networking & Power

  • Ubiquiti UniFi
  • Cisco Meraki
  • SonicWall
  • WattBox

Security & Management

  • Datto
  • 1Password
  • Cisco Duo
  • Absolute
  • Splashtop

Communications & Video

  • Cisco
  • Yealink
  • Verkada

These are the brands we prefer, but we work with virtually any equipment or platform. Bring us the hard problems.