Cybersecurity Awareness Month Starts October 1. Here's What SMBs Should Actually Do in 60 Minutes.
Cybersecurity Awareness Month kicks off October 1 and the internet is about to flood you with 47-item checklists you'll never finish. Here's what an hour of real hardening looks like, and why it will do more for your business than any poster in the breakroom.
You already know what's coming. On October 1, every vendor with an email list will send you a cybersecurity awareness post. Most of it will be a bulleted checklist with 40 items on it. "Use a password manager." "Turn on multi-factor authentication." "Train your employees." You'll skim it, feel vaguely guilty, forward it to nobody, and get back to work.
That is the entire cybersecurity awareness industry in one paragraph. And it is not working.
Small businesses are getting hit anyway. Around 43 percent of cyberattacks target small businesses, and roughly 60 percent of small businesses that suffer a breach go out of business within six months [1]. The average small business breach costs somewhere between $120,000 and $1.24 million, according to Verizon's Data Breach Investigations Report [2]. That is a company-ending number for most of the businesses reading this.
So let's skip the checklist. This year the two organizations running Cybersecurity Awareness Month, CISA and the National Cybersecurity Alliance, went with themes of "Securing the Next 250" and "Don't Make It Easy for Them" [3]. The second one is honest. Most attackers are not sophisticated. They are opportunistic. Your job is not to be uncrackable. Your job is to be annoying enough that they move on to the next small business that did not bother.
Here is what one focused hour looks like. Block it on your calendar for the first week of October. Bring a coffee.
Minutes 0 to 15: Turn on MFA for the accounts that actually matter
Only 27 to 34 percent of small businesses have real multi-factor authentication rolled out, compared to 87 percent at large enterprises [4]. That gap is not a resource problem. It is an attention problem. Nobody scheduled the hour.
Do not try to enable MFA everywhere at once. That is how projects die. Instead, list your five highest-blast-radius accounts. For most small businesses that list looks something like this:
- Your email (Google Workspace or Microsoft 365)
- Your bank and payment processor
- Your domain registrar
- Your primary CRM or business system of record
- Your payroll provider
If someone gets into any of those, you have a bad quarter. If they get into all of them, you have a lawsuit. Turn on MFA for these five in the next 15 minutes, using an authenticator app rather than SMS wherever possible. SMS-based codes are still better than nothing, but SMS phishing surged 40 percent year over year and is now roughly 35 percent of all phishing attacks [5]. Attackers know your phone number is easier to hijack than your Google Authenticator app.
Minutes 15 to 30: Kill the shared logins
Every small business has a shared login. It is usually for the social media account, or the shipping software, or the customer support tool. Somebody set it up in 2019 with the password "companyname2019" and now nine people know it, including two who left last year.
Spend 15 minutes finding them. Ask around. Check your password manager. Look at the tools that never made it into your SSO setup. For each one, either:
- Add it to a shared vault in a password manager so nobody knows the raw credential, or
- Create individual logins so departures do not become emergencies
This one is unsexy and it will save you from the most common small business breach. Phishing is the number one attack vector for small businesses, and 40 percent of small organizations cite it as their most frequent breach vector, compared to 27 percent of large enterprises [5]. When one person's shared credential leaks, the whole company leaks with it.
Minutes 30 to 45: Test one phishing scenario with your team
You do not need a formal training program to make your team more phishing-resistant. You need one specific example, in your voice, sent this week.
Pick a scenario that actually applies to your business. If you run a legal practice, it is the fake wire transfer request from a "client." If you run a restaurant group, it is the fake DoorDash update asking a manager to re-enter payment info. If you run a service business, it is the fake vendor invoice for a tool you already use.
Write a one-paragraph email to your team describing the scenario. Tell them exactly what to do if they see it: forward to a specific person, do not click, do not reply. That is the whole training. Do it once a quarter with a new scenario. You will get more retention from four two-minute emails a year than from an annual training video nobody watched.
Over 90 percent of cyberattacks begin with phishing as the initial vector, per CISA [5]. Everything else you do is second-order compared to this.
Minutes 45 to 60: Write down the "if this happens" plan
Most small businesses do not have an incident response plan because they think it needs to be a 40-page document. It does not. It needs to be a one-page doc that lives in a place your team can find without email access, because email is often the thing that got breached.
Answer four questions on that one page:
- Who do we call first if we think we've been breached? (Include personal cell numbers.)
- What do we shut off immediately? (Bank access, email admin, payment processor.)
- Who tells our customers, and what do they say?
- Where is this document if our systems are down? (Print it. Yes, really.)
That is your plan. It is not comprehensive. It is not perfect. It is a hundred times better than the plan most of your competitors have, which is "panic and google what to do."
What this hour actually buys you
Sixty minutes will not make you invulnerable. It will not satisfy a SOC 2 auditor. It will not check every box on the vendor blog post.
What it will do is make your business meaningfully harder to breach than the small business next door. Attackers are running a numbers game. They send a thousand phishing emails, they compromise the five accounts that had no MFA, and they walk away with money. Your job on October 1 is not to become impossible to attack. It is to fall out of the top of that funnel.
The other thing worth noting: the tools you already pay for are probably underused. Your Google Workspace or Microsoft 365 subscription includes MFA, phishing protection, and audit logs you have never opened. Your phone system, if it is any good, has admin controls and call logs that would catch a vishing attempt in progress. At Tonet we build call recording and transcription in so that the "did that call really happen" question has a real answer, not a shrug. Most of what you need for baseline security is sitting in tools you already own. You just have to spend the hour turning it on.
Block the hour. Show up. Cybersecurity Awareness Month is not about awareness. It is about the one hour a year you actually do something.
What's the one security task you keep meaning to do and never get around to? Drop it in the comments. If it involves your phone system, that's a conversation we're happy to have.
Sources:
[1] StrongDM (2026). Alarming small business cybersecurity statistics, including the 43 percent targeting figure and the 60 percent post-breach failure rate.
[2] Sagiss (2026). SMB data breach cost analysis citing Verizon's DBIR range of $120,000 to $1.24 million.
[3] CISA Cybersecurity Awareness Month (2026). Official themes for Cybersecurity Awareness Month 2026.
[4] Swif MFA Statistics (2026). Multi-factor authentication adoption rates by company size.
[5] StationX Small Business Cybersecurity Statistics (2026). Phishing as the dominant attack vector for SMBs, including smishing growth and CISA's 90 percent figure.