October is Cybersecurity Awareness Month, which in most offices means a poster in the break room, an email with a padlock icon on it, and no change whatsoever to how anything actually works. Awareness is not the problem. Almost every business owner I talk to is already aware. What they do not have is a list of specific things to do this month that will still be true in December.

So here is one. Four weeks, two or three tasks each. Each task is either a decision you make or a job you hand to someone with a clear definition of “done.” A 20-person office can genuinely finish this in October. The only way to fail is to add to it — if you decide halfway through that you also need a new firewall and a written security policy, you will finish neither.

Keep a single page open the whole month. Three columns: task, who owns it, date finished. That page is the deliverable.

Week 1: Accounts and Multi-Factor Authentication

Accounts are where nearly every small-business incident starts. The most common entry points are stolen credentials, exposed remote access, and phishing email — all three are account problems before they are anything else.

Task 1: Get a list of every account in your tenant and confirm each one is a current employee. Ask whoever administers your Microsoft 365 or Google Workspace to export the user list. Print it. Go down it with a pen. You are looking for three things: people who left, accounts nobody recognizes, and shared logins like “frontdesk” or “info” that several people use. Disable the accounts belonging to people who have left — disable, not delete, so the mailbox and history survive. Flag anything you do not recognize and have whoever administers the tenant identify it before touching it — some unrecognized accounts are service accounts an application signs in with, or emergency administrator accounts that must stay enabled. For the third, decide whether the shared login needs to become a shared mailbox with individual access instead, which is almost always the right answer.

Task 2: Turn on multi-factor authentication for everyone, including you. Microsoft’s research has consistently found that multi-factor authentication blocks more than 99% of automated account-compromise attempts. That is the single best return on effort available to a small office.

But MFA is not a force field. Adversary-in-the-middle phishing kits steal the session token after you approve the prompt, which defeats app codes and push approvals alike. For finance, email administration, and anything touching money, use phishing-resistant MFA — passkeys or a hardware security key. If you want the longer version of that argument, we wrote it up in a guide to MFA for business owners.

The realistic obstacle here is not technical, it is the exception list. Someone will ask to be excluded because it is inconvenient. The accounts people ask to exclude are the accounts attackers most want. The only accounts that sit outside a policy are the emergency administrator accounts described in our passkeys post, and those get their own protection and monitoring — they are not an exemption anyone gets to request.

Task 3: Roll out a password manager. A twenty-seat rollout is an afternoon of setup for most offices, and it replaces the spreadsheet, the sticky notes, and the group text with a bank login in it. It also gives you an answer to a question you will need later: which shared credentials exist, and who knows them.

Done looks like: a signed-off user list with departed accounts disabled, MFA enforced for every person, with no convenience exceptions, and every employee logged into a password manager.

Week 2: Backups and an Actual Restore Test

Almost everyone has backups. Far fewer have ever restored from them. The gap between those two states is where businesses lose weeks.

Task 1: Write down what is being backed up, and find what is not. Servers, yes. But what about the data in Microsoft 365 — email, SharePoint, OneDrive? Many owners assume the cloud provider backs that up in the sense they mean. What is on individual laptops that never touches a server? What about the line-of-business system your practice or shop runs on: is it backed up by you, by the vendor, or by nobody? What about the QuickBooks file on the bookkeeper’s desktop? List every one and mark it covered or not covered.

Task 2: Run a restore test this week. Not a report showing green checkmarks — an actual restore. Pick a specific file and a specific mailbox item from a specific date at least a month ago. Restore them. Open them. Confirm the contents are right and nothing is truncated. Note how long it took, because that number is the beginning of an honest recovery estimate.

The standing cadence after this month: test a restore quarterly, and do one full restore test a year, where you bring back an entire server or system and time it end to end.

Task 3: Confirm one copy is out of reach. Ransomware operators look for backups first, and a backup on a drive plugged into the server it protects is not a backup. You want at least one copy that is offsite and either immutable or otherwise not deletable by an administrator account that has been compromised. Ask your provider one question and get the answer in writing: if an attacker gains administrator access to our environment today, which backup copy survives? If the honest answer is “none,” that is the finding of the month.

Done looks like: a one-page inventory of what is and is not backed up, a restore you performed with your own eyes, and a written answer about the offsite copy.

Week 3: Devices and Patching

This week is about the machines themselves — and about finding the ones nobody has thought about in years.

Task 1: Inventory every device that touches company data. Desktops, laptops, tablets, the reception PC, the machine in the back that runs the label printer, the personal laptops people use from home, and phones with work email on them. For each, record who has it, what operating system version it runs, and whether it is encrypted. The two things you are hunting for are devices running an operating system that no longer receives security updates, and personal devices holding company data with nothing managing them.

Task 2: Set and confirm a patching cadence. The standard worth holding to is critical and actively-exploited vulnerabilities within 72 hours, and everything else on a weekly cycle — and that applies to more than Windows. Browsers, Adobe products, Java where it still lurks, and the firmware on your firewall and network gear all need to be in the cycle. Ask for a report showing current patch compliance across every machine, not a promise that updates are automatic. Automatic updates fail quietly on machines that are never rebooted.

Task 3: Verify what is actually protecting the endpoints. Check that every machine on your inventory is running your security software, that it is reporting in, and that someone is looking at what it reports. Traditional signature-based antivirus is no longer sufficient on its own, which is the whole reason endpoint detection and response exists. The failure mode here is not usually the absence of software; it is three machines that dropped off the console in June and nobody noticed.

Done looks like: a device list with owner, OS version, and encryption status; a documented patch cadence; and a report showing every device reporting into your endpoint protection.

Week 4: People, a Phishing Test, and a Contact Card

Task 1: Run one simulated phishing test. Twenty people, one realistic message, one report at the end. Two rules make this work. Announce beforehand that a test is coming sometime this quarter, without saying when — you are measuring the office’s habits, not ambushing individuals. And never use the results for discipline. The moment this becomes a disciplinary tool, people stop reporting the real ones because they are afraid of looking foolish, and reporting is the behavior that protects you. The number to watch is how many people reported it, not how many clicked.

Task 2: Teach one specific procedure, not general vigilance. “Be careful with email” changes nothing. A rule with a number in it does. The one we recommend for every client: any request to change bank details, wire funds, or buy gift cards gets verified by phone, on a number already in your records, before anything moves — regardless of who appears to be asking. Say it out loud in a staff meeting, put it on one page, and make it explicit that the CEO expects to be called back. This is also where voice cloning is changing the calculation, which is why we suggest agreeing on a verbal safe word for anything urgent involving money. Fifteen minutes of focused security awareness training on one concrete rule beats an hour of generalities.

Task 3: Make the incident contact card. One page, printed, in the manager’s desk and the server room and one person’s car — because if this is only stored in email or on a network share, you will not have it on the day you need it. What goes on it:

That last line matters. Powering off a compromised machine can destroy the memory-resident evidence responders need. Disconnecting it from the network stops the spread without destroying the trail. If you want the full sequence, our walkthrough of the first 72 hours after a breach covers it.

Done looks like: one phishing test run and discussed, one verification rule everybody can recite, and a printed contact card in three physical locations.

What to Do on November 1

Take the sheet with your four weeks on it and turn the recurring items into calendar entries: quarterly restore test, quarterly access review, annual full restore, an annual repeat of the phishing test. Then put the one thing you could not finish at the top of next quarter’s list, with a date.

None of this is exotic. It is the unglamorous baseline, done deliberately, once. Businesses that get hurt are rarely the ones that missed some sophisticated defense — they are the ones where the backup had been failing since spring, or where one account never had MFA on it. Thirty days of ordinary work closes most of that gap.

Related Questions

Can a 20-person office really finish this in a month?

Yes, if you treat it as four short blocks rather than one project. Each week here is two or three tasks, and most of them are decisions rather than technical work. The two that take real time are the restore test and the phishing test, and both can be delegated to whoever manages your IT. What kills these plans is scope: if you add a password policy rewrite, a firewall replacement, and a compliance framework, you will finish none of it.

Which single task matters most if we only do one?

Multi-factor authentication on every account, with no exceptions carved out for executives. Microsoft’s research has consistently found that multi-factor authentication blocks more than 99% of automated account-compromise attempts. It is not a force field: adversary-in-the-middle phishing kits steal the session token after you approve the prompt, which defeats app codes and push approvals alike. For finance, email administration, and anything touching money, use phishing-resistant MFA, meaning passkeys or a hardware security key.

How often should we test that our backups actually restore?

Test a restore quarterly, and do one full restore test a year. A quarterly test can be small: pick a file and a mailbox item from a specific date, restore them, and confirm the contents are correct and complete. The annual test is the real one, where you restore a whole server or system and time how long it takes. A backup that has never been restored is a theory, not a backup.

Should we punish employees who fail the phishing test?

No. The moment a simulated phishing test becomes a disciplinary tool, people stop reporting real ones because they are afraid of looking foolish, and reporting is the behavior that actually protects you. Announce that a test is coming sometime this quarter, do not name individuals in the results, and celebrate reports rather than clicks. The number to watch over time is how many people reported the message, not how many clicked it.

Want Someone to Run the Four Weeks With You?

We can do the parts that need admin access — the account audit, the restore test, the patch report, the phishing simulation — and write up what we find in plain language as we go. No jargon, no upsell attached to the report. Just an honest picture of where a 20-person office stands.

Start Your 30-Day Plan (888) 735-7701