Group Discussion

October is Cybersecurity Awareness Month, which makes it a good time to take another look at some of the things we assume about cybersecurity. And "assume" is the important word.

Most businesses we work with aren't ignoring cybersecurity. They have protections in place. They've talked with employees about suspicious emails. They use backups and multifactor authentication. They're doing many of the right things. But cybersecurity keeps changing.

Advice that made sense a few years ago may be incomplete today. Technology changes, businesses change, and the techniques used to fool people change too. So rather than adding another list of things to worry about, let's look at six common assumptions and ask a simple question:

Does this still hold up?

Assumption #1: "We're Too Small for Anyone to Target Us"

It's understandable why a smaller business might think this way. Why would someone spend time targeting a 20-person company in Morgantown when there are much larger organizations out there? The problem with that thinking is the word targeting.

Not every cyberattack begins with someone specifically choosing your company. Many attacks are opportunistic or automated. If there's an exposed account, a compromised password or another easy way in, the size of the company may not matter very much.

And small businesses still have things worth protecting: financial information, employee records, customer information, email accounts and access to vendors or other organizations.

The better assumption: Your business doesn't have to be large to be worth protecting.

Assumption #2: "Our Employees Will Recognize a Phishing Email"

Remember when suspicious emails were easier to spot? Strange wording. Misspelled words. Odd formatting. A greeting that didn't make sense. Those clues haven't disappeared completely, but they're much less dependable than they used to be.

Today's phishing emails can be polished and convincing. AI has made it easier to create messages that sound professional and natural. That's why we encourage employees to look beyond whether an email is written well and think about whether the request makes sense.

  • Would this person normally ask you to change payment information by email?
  • Is it unusual for this vendor to send you a login link?
  • Why does someone suddenly need sensitive information?
  • Is this request different from the way your company normally handles this process?

When something doesn't fit the normal pattern, verify it another way before acting.

The better assumption: A professional-looking email isn't necessarily a legitimate one.

Assumption #3: "We Have MFA, So Our Accounts Are Protected"

Multifactor authentication—MFA—is one of those cybersecurity terms that's become fairly familiar. And that's a good thing. MFA adds an important layer of protection.

But having it doesn't mean employees can stop paying attention.

For example, someone may receive repeated authentication prompts they didn't initiate. After the fourth or fifth notification, it can be tempting to approve one just to make the notifications stop. That's exactly what the person trying to access the account may be hoping for.

Employees should know that an unexpected MFA prompt is something to question, not approve automatically. And not every form of MFA provides the same level of protection, which is another reason your authentication strategy should be reviewed as part of your overall security approach.

The better assumption: MFA is an important layer of protection, not permission to stop paying attention.

Assumption #4: "Our Backups Have Us Covered"

We've talked about this one before because it's worth repeating. Having a backup and being able to recover your business aren't necessarily the same thing.

A better question is: If we needed our backups tomorrow, do we know they would work?

And then: How long would it take us to get the important parts of the business running again?

Those questions turn "We have backups" into a much more useful conversation. A tested recovery process gives you something an unchecked backup cannot: confidence based on knowing what actually happens when you need it.

The better assumption: A backup becomes much more valuable when you've verified you can recover from it.

Assumption #5: "Cybersecurity Is IT's Responsibility"

Your IT provider absolutely has an important role to play. Good security tools can block a tremendous amount of suspicious activity before employees ever see it. But some decisions still happen outside the technology.

  • An employee receives an unusual request from someone who appears to be the owner.
  • Accounting receives new banking information from a vendor.
  • Someone gets a login prompt they weren't expecting.
  • An employee needs to decide whether it's okay to put company information into an AI tool.

Those are business decisions as much as technology decisions. Employees don't need to become cybersecurity experts. They need clear expectations, sensible procedures and someone they can ask when something doesn't feel right.

The better assumption: IT provides the safeguards, but good cybersecurity also depends on good decisions throughout the business.

Assumption #6: "We'll Know What to Do if Something Happens"

Imagine it's Tuesday morning and several employees suddenly can't access their files. What happens next?

  • Who calls your IT provider?
  • Should employees keep working on their computers?
  • Who communicates with employees?
  • If email isn't available, how do you reach everyone?
  • Who contacts your cyber insurance provider if that's necessary?
  • Who decides whether customers need to be notified?

Most businesses can eventually answer those questions. The important question is whether you want to answer them during the problem or before it happens. Your response plan doesn't need to account for every possible scenario. But the people who run the business should understand the basics of who does what and where to turn for help.

The better assumption: A few decisions made ahead of time can eliminate a lot of uncertainty later.

Good Cybersecurity Starts With Good Decisions

There's something these six assumptions have in common. None of them is solved by simply telling employees to "be more careful." And none is solved by buying one more cybersecurity product.

Good cybersecurity comes from putting sensible protections in place, checking that they're working, giving employees clear guidance and having a plan for what happens when something doesn't look right. That's what Cybersecurity Awareness Month should really be about.

Not making business owners more worried about cybersecurity. Making them more informed about it.

Let’s Have the Conversation

If one of these six assumptions made you stop and think, that’s a good place to start.

At Literati IT, we help businesses throughout Morgantown, Fairmont, Clarksburg and North Central West Virginia understand what protections they already have, where assumptions may need to be verified, and what practical improvements make sense.

You don’t need to have all the answers before you call. That’s what the conversation is for.

Call us at 304-296-8026 or visit www.literatiit.com to schedule a quick discovery call.

No pressure. No scare tactics. No technical jargon. Just a practical conversation about what you’re already doing, what’s working, and whether there are a few things worth another look.