October is almost here. Do not wait until Cybersecurity Awareness Month begins to protect your business.
If you operate in Cedar Rapids, Iowa City, Marion, Coralville, or North Liberty, your business depends on email, cloud software, mobile devices, online payments, and connected systems every day. One stolen password or convincing phishing message can interrupt operations, expose customer information, and damage the trust you have worked years to build.
Cybersecurity Awareness Month has been observed every October since 2004. In 2026, the national theme is “Securing the Next 250,” with a focus on building a safer digital future. You can review the official NIST Cybersecurity Awareness Month resources for broader guidance.
But you do not need a massive IT department to take meaningful action. You need a practical plan and the discipline to follow it.
Verizon’s 2025 Data Breach Investigations Report found that more than 90% of breached organizations were small and medium-sized businesses. Vulnerability exploitation increased 34% year over year and accounted for about 20% of breaches. The human element appeared in roughly 60% of breaches, often involving stolen credentials, phishing, or social engineering.
Here are five moves you should make now.
1. Require multifactor authentication on every critical account
A password alone is not enough. Even strong passwords can be stolen through phishing, reused after another breach, or exposed by a compromised device.
Multifactor authentication, or MFA, adds another verification step. That could be an approval in an authenticator app, a security key, a passkey, or a one-time code. If an attacker steals your password, MFA can still stop the login.
Start with the accounts that could cause the most damage:
- Business email
- Microsoft 365 or Google Workspace
- Banking and payment platforms
- Payroll and accounting software
- Remote access tools
- Cloud storage
- Domain registrar and website accounts
- Administrator accounts
- Customer relationship management systems
CISA recommends MFA for business accounts and encourages organizations to use phishing-resistant options, such as security keys or passkeys, whenever possible. You can review its small-business cybersecurity guidance for more detail.
Ask your IT provider:
- Which accounts do not have MFA enabled today?
- Are former employees and contractors still listed as users?
- Are administrator accounts protected with stronger MFA?
- Can you detect unusual logins from unfamiliar locations or devices?
- What happens if an employee loses their phone or security key?
What to look for:
You want a clear account inventory, documented MFA coverage, rapid offboarding, and alerts for suspicious sign-ins. If your provider cannot show you a current report, you may have a visibility problem.
Pro tip: Turn on MFA for email first. Email is often the reset button for your other accounts, which makes it one of the most valuable targets for attackers.
For a broader look at how outside expertise can help, see our guide to choosing a business IT services company in Iowa City.
2. Treat phishing as an everyday business risk
Phishing is not just an obvious email from a stranger with spelling mistakes. Today’s scams can look polished, local, and personal. Artificial intelligence helps criminals create convincing messages, imitate writing styles, and generate fake invoices or urgent requests.
A message may appear to come from:
- Your owner or president
- A trusted vendor
- A customer
- Your bank
- A delivery company
- A payroll provider
- A real estate closing contact
- A colleague asking for a gift card or wire transfer
Your employees should know that urgency is a warning sign. So is a request to bypass normal procedures.
Create a simple verification rule:
No payment change, wire transfer, payroll update, or sensitive-data request is approved from email alone.
Require a phone call using a known number, an in-person confirmation, or a second communication channel. Do not use the number or link included in the suspicious message.
Ask your IT provider:
- Does your email system use spam filtering, malware scanning, and impersonation protection?
- Are SPF, DKIM, and DMARC configured correctly for your domain?
- Can employees report suspicious messages with one click?
- Do you provide short, recurring security awareness training?
- Are phishing simulations used to teach rather than punish?
What to look for:
Look for a report-first culture. Employees should feel comfortable reporting a suspicious message quickly, even if they clicked something. Delays give attackers more time to steal credentials, redirect payments, or spread malware.
Verizon’s 2025 research found that the human element remains involved in a majority of breaches. That does not mean your employees are careless. It means your systems should assume someone will eventually face a convincing scam.
Our business IT support services guide explains how ongoing support can help you combine employee habits with stronger technical controls.
3. Patch every device and know what is connected
Attackers do not need to break through an imaginary wall. They look for an unlocked door.
That door might be an outdated router, an unpatched laptop, a forgotten remote desktop account, an unsupported server, or a cloud application configured years ago and never reviewed.
Make a complete list of your technology:
- Computers and laptops
- Servers
- Firewalls and routers
- Wireless access points
- Printers and scanners
- Smartphones and tablets
- Security cameras
- Point-of-sale systems
- Cloud applications
- Remote access tools
- Internet-connected equipment
Then identify which systems are business-critical and which are no longer supported.
Ask your IT provider:
- How quickly are critical security patches installed?
- Who monitors vendor security advisories?
- Which devices are no longer supported?
- Can you identify unauthorized software or devices?
- Are remote access tools protected with MFA and logging?
- Do you receive a monthly patch and vulnerability report?
What to look for:
A reliable provider should use automated patch management, maintain an accurate asset inventory, and prioritize serious vulnerabilities. You should not have to discover an old device because it caused an outage.
This is especially important for businesses with multiple locations or hybrid staff. A Cedar Rapids office, an Iowa City satellite location, and employees working from home all expand your technology footprint. Without centralized oversight, a device in Marion or North Liberty can become the weak point nobody is watching.
4. Test your backups before you need them
A backup that has never been tested is a hope, not a recovery plan.
Ransomware can encrypt files, disable systems, and attempt to delete backup copies. Hardware failure, accidental deletion, storm damage, and cloud-account compromise can create similar problems.
Your backup strategy should include:
- Automatic backups on a defined schedule
- Encrypted backup data
- Copies separated from your production network
- Protection against unauthorized deletion
- Documented recovery priorities
- Regular restore testing
- A recovery plan employees understand
Start with the systems your business cannot operate without. That may include accounting data, customer records, project files, inventory information, email, line-of-business applications, and shared documents.
Ask your IT provider:
- When was the last successful restore test?
- How much data could you lose if systems failed today?
- How quickly could your most important applications be restored?
- Are backups isolated from administrator accounts?
- Can you recover if ransomware reaches your primary network?
- Who makes recovery decisions during an emergency?
What to look for:
Look for written recovery objectives, routine test results, and a provider that can explain recovery in plain English. “We have cloud backups” is not a complete answer.
Pro tip: Ask your provider to demonstrate the recovery of one important file and one complete business system. A real test often reveals problems that dashboards miss.
5. Build a local response plan before an incident
When a security incident happens, confusion becomes expensive.
Your team needs to know who to call, which systems to disconnect, how to preserve evidence, and how to communicate with customers, employees, insurers, banks, and law enforcement. You should not be creating that process while an attacker is moving through your network.
Your plan should identify:
- The person authorized to make emergency decisions
- Your IT and cybersecurity contacts
- Your cyber-insurance requirements
- Your legal and accounting contacts
- Your bank’s fraud-response number
- Your backup and recovery procedures
- Your customer and employee communication process
- The systems that must be restored first
Run a short tabletop exercise. Give your team a realistic scenario, such as:
“The controller receives an alert that an unfamiliar user accessed the company’s email account and changed vendor payment instructions. What happens next?”
Do not focus on blame. Focus on speed, communication, and clear decisions.
Ask your IT provider:
- Is 24/7 monitoring included?
- Who responds if an alert occurs after business hours?
- What is the process for containing a compromised account?
- Will you help coordinate with cyber-insurance and legal partners?
- How often is our response plan reviewed?
- Can you provide a written incident report after an event?
What to look for:
A strong response plan includes real people, current contact information, defined responsibilities, and regular testing. It should also account for local realities, including severe weather, power interruptions, regional internet outages, and staff working between Cedar Rapids, Iowa City, Coralville, and surrounding communities.
Your October cybersecurity checklist
Before October begins, make these five commitments:
- Enable MFA on critical accounts.
- Train employees to recognize and report phishing.
- Patch and inventory every device and application.
- Test your backups and document recovery priorities.
- Practice your response plan with the people who will act.
These steps will not eliminate every risk. Nothing can. But they can reduce the chances that one stolen password, missed update, or malicious attachment becomes a business-ending event.
If you are unsure where to begin, review our practical checklist of mistakes Cedar Rapids small businesses make when blocking hackers.
Do not wait for an alert from your bank, a locked file server, or an angry customer to expose the gaps in your security.
CMIT Solutions of Cedar Rapids-Iowa City helps local businesses strengthen email security, manage devices, protect cloud systems, test backups, monitor networks, and respond to threats. You get enterprise-level expertise with personal local attention and proactive support.
If you operate in Cedar Rapids, Iowa City, Marion, Coralville, or North Liberty, contact CMIT Solutions of Cedar Rapids-Iowa City to schedule a conversation before Cybersecurity Awareness Month begins. Your safest October starts with the action you take today.


