Blog / Practical controls

Practical controls

Cybersecurity Awareness Month for a 30-Person Business: Four Controls, in Order

Cybersecurity Awareness Month, done properly by a 30-person business: four controls in the order that removes the most risk per hour of work, not a poster.

Sam KhanSam Khan The Cyber ExpertFounder and CEO24 September 2026 · 6 min read

October arrives and somebody suggests posters

The office manager of a 30-person freight brokerage in the north suburbs is handed Cybersecurity Awareness Month on the first Thursday of October, along with a budget of "keep it reasonable". She does what most people do. She orders pizza for the Friday lunch, prints four posters about strong passwords, and books a 45-minute session with a slide deck the insurance broker sent over.

It goes fine. People laugh at the slide about "P@ssw0rd1". Two dispatchers ask decent questions. The posters go up by the coffee machine and stay there until March.

Eleven days later a dispatcher's login is used from an address in another country at 03:14 to read six weeks of email and set a forwarding rule. Nobody notices for nine days. The account had a strong password, exactly as the poster instructed, and no second factor, because that was not on the poster.

The training was not the mistake. The order was. She spent her October on the fourth-most useful thing and never got to the first three.

What the heck should October actually buy you

Awareness Month is a marketing campaign, and a good one, but a campaign is not a plan. The plan question is narrower: with a few dozen hours and no security team, which controls remove the most risk per hour of work?

Four, in this order.

Multi-factor authentication: a second proof of identity beyond the password, so a stolen login on its own is worthless.

Patching: applying vendor updates to software and devices, on a schedule, everywhere, including the machines that never come to the office.

Tested backup: a copy of your data that an attacker cannot reach and that you have proved you can restore, with a date and a name against the test.

Awareness training with a report button: short, monthly, plus a one-click way for staff to send a suspicious message to whoever handles security.

The order is not arbitrary. Stolen credentials and unpatched software are how attackers get in. A tested backup is what decides whether an incident is a bad week or the end of the business. Training is the control that keeps working after the other three are running, and it is the one everyone starts with because it is the easiest to schedule.

The numbers that matter

Vulnerability exploitation appeared in 31 percent of breaches and credential abuse in 13 percent, according to the Verizon 2026 Data Breach Investigations Report. Two controls, most of the front door. Neither requires a purchase order.

Ransomware was present in 48 percent of all breaches and in 88 percent of breaches at small and medium businesses in that same Verizon 2026 report, with a median ransom paid of 139,875 US dollars. Sixty-nine percent of victims refused to pay. The ones who can refuse are the ones with a restore they have tested.

The Center for Internet Security's Community Defense Model v2.0 found that Implementation Group 1, a set of 56 safeguards, defends against 77 percent of attack techniques overall and 78 percent of ransomware techniques. The four controls above sit inside that group. You are not building a security programme in October. You are switching on the cheapest three quarters of one.

What to do this week

  1. Turn on multi-factor authentication everywhere a login opens something that matters: email, payroll, accounting, the cloud drive, the VPN, the transport management or practice system, and the domain registrar. Start with anything that moves money. Finish the list before you print anything. (CIS 6 Access Control Management)
  2. Pull every account against payroll and disable what does not match, including shared logins and the account of anyone who left this year. Then set access reviews for the first Monday of every quarter. (CIS 6 Access Control Management)
  3. Patch on a schedule and prove the coverage against an asset list, not a vendor dashboard summary. The laptops that live in vans and home offices are the ones that will be missing, and they are the ones that will be exploited. (CIS 7 Continuous Vulnerability Management)
  4. Restore a real file from last month to a clean machine, open it, and write the date and the person's name on the record. Keep one copy of your data offline or otherwise out of reach of an administrator account. (CIS 11 Data Recovery)
  5. Replace the annual slide deck with ten minutes a month built on what actually reached your inboxes, and put a report button in every mail client. Tell everyone what it does and make a small fuss the first time someone uses it. (CIS 14 Security Awareness and Skills Training)

Where AccuSights fits

Start with the three-minute Cyber Hygiene Test so October begins with your real coverage rather than a guess. It scores the twelve controls that matter at your size and hands back the specific gaps.

Our assessment maps the same four to your regulators, and the read-only compliance agent shows where coverage is missing so you can prioritise and keep an eye on it. We have no access and we do not remediate. You or your IT partner fix; we show you where.

Questions people ask

Why these four controls and not a longer list? Because a 30-person business gets roughly twenty usable hours out of October, and these four absorb the majority of what actually causes losses at that size: stolen logins, unpatched software, ransomware with no clean restore, and a person tricked by an email. Longer lists get abandoned in week three. Four controls, finished, beat twenty controls started.

Can we do this without hiring anyone? Most of it, yes. Turning on multi-factor authentication, disabling dead accounts, running a restore test and holding a ten-minute session are owner-and-office-manager work. The part that usually needs help is finding what you cannot see: the unpatched device nobody remembers, the cloud app somebody signed up for, the backup that silently stopped.

What do we do in November? Repeat the check and fix what drifted, because coverage decays every month you hire, buy or rebuild something. Awareness Month is a useful excuse to start. It is a terrible schedule. The businesses that stay out of trouble treat October as month one of twelve, not as the annual event.

Keep the pizza. Move the posters to March, when everyone has forgotten, and spend October on the four things a poster cannot do.

Questions people ask

Why these four controls and not a longer list?

Because a 30-person business gets roughly twenty usable hours out of October, and these four absorb the majority of what actually causes losses at that size: stolen logins, unpatched software, ransomware with no clean restore, and a person tricked by an email. Longer lists get abandoned in week three. Four controls, finished, beat twenty controls started.

Can we do this without hiring anyone?

Most of it, yes. Turning on multi-factor authentication, disabling dead accounts, running a restore test and holding a ten-minute session are owner-and-office-manager work. The part that usually needs help is finding what you cannot see: the unpatched device nobody remembers, the cloud app somebody signed up for, the backup that silently stopped.

What do we do in November?

Repeat the check and fix what drifted, because coverage decays every month you hire, buy or rebuild something. Awareness Month is a useful excuse to start. It is a terrible schedule. The businesses that stay out of trouble treat October as month one of twelve, not as the annual event.

Controls this post maps to

CIS 6 Access Control ManagementCIS 7 Continuous Vulnerability ManagementCIS 11 Data Recovery

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with your Risk Assessor draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.