The Cybersecurity Assumptions That Quietly Put Businesses at Risk

Cybersecurity Awareness Month brings plenty of reminders about passwords, phishing emails, MFA and software updates. All of those things matter. But this October, there may be a more valuable exercise for your organization...

Question what you assume is already secure.

Some of the biggest cybersecurity gaps don't necessarily come from ignoring security altogether. They can develop when an organization believes something is being handled, protected or monitored when the reality is a little different.

  • “We have backups.”

  • “Our employees know what to look for.”

  • “We have antivirus.”

  • “Our IT provider handles that.”

  • “We would know if something happened.”

Maybe all of those statements are true. But when was the last time you actually tested them?

Assumption #1: “We Have Security Tools, So We're Protected”

Most organizations today have multiple cybersecurity technologies in place. Firewalls, endpoint protection, email filtering, MFA and other security tools can provide important layers of defense. But purchasing security technology is not the same as having a cybersecurity strategy.

  • Who monitors the alerts?

  • Who makes sure policies and configurations remain current?

  • What happens when a tool identifies suspicious activity?

  • Are there gaps between the different systems?

Security tools are only part of the equation. The people, processes and response plans surrounding those tools matter just as much.

Cyber Smarter question: Do you know who is responsible for each part of your security environment?

Assumption #2: “Our Employees Would Recognize a Phishing Email”

Phishing has come a long way from the poorly written messages many people learned to recognize years ago. A suspicious email may now appear to come from a coworker, executive, vendor or other trusted contact. Attackers can use information about an organization and its employees to make messages significantly more convincing. That means cybersecurity awareness cannot be treated as a one-time training exercise.

Employees should feel comfortable questioning unusual requests, reporting suspicious activity and asking for help without worrying that they are wasting IT's time. Creating that culture can be just as important as teaching people what a suspicious link looks like. Cyber Smarter question: Would your employees report something that felt slightly “off,” even if they weren't sure it was malicious?

Assumption #3: “We Have Backups, So We Can Recover”

Having backups can provide a sense of security. But the more important question is: Can you restore them? A backup strategy should consider what is being backed up, how frequently backups occur, where those backups are stored, who can access them and how quickly critical systems could be recovered. Testing matters, too.

Discovering during an emergency that an important system wasn't included in a backup, credentials are unavailable or restoration will take significantly longer than expected is not the kind of surprise an organization wants.

Cyber Smarter question: When was the last time your organization actually tested a recovery?

Assumption #4: “MFA Means a Compromised Password Isn't a Big Deal”

Multi-factor authentication is an important security layer and should be used wherever appropriate. But it doesn't make credentials irrelevant. Employees can still be targeted by MFA fatigue attacks, social engineering and increasingly convincing attempts to gain access to accounts. Compromised sessions and improperly secured applications can create additional risks as well. MFA should be one layer of a broader identity and access strategy, not the finish line.

Cyber Smarter question: Beyond MFA, how does your organization detect unusual account activity?

Assumption #5: “Our IT Provider Handles Cybersecurity”

An outside IT or security partner can play an important role in protecting an organization, but “they handle it” can be a dangerous assumption if responsibilities have never been clearly defined.

  • Who handles employee security awareness?

  • Who reviews security alerts?

  • Who manages third-party application access?

  • Who tests backups?

  • Who responds after hours?

  • Who contacts your cyber insurance provider following an incident?

Cybersecurity works best when everyone understands where their responsibility begins and ends. Cyber Smarter question: Could you clearly explain what your internal team handles versus what your technology partners handle?

Assumption #6: “We're Too Small to Be an Interesting Target”

Cybercriminals don't necessarily need to personally select your organization. Automated attacks can scan large numbers of systems looking for exposed services, weak credentials, unpatched vulnerabilities and other opportunities. Smaller organizations can also have something attackers value: data, money, access to other businesses and a need to restore operations quickly. The better question isn't whether your organization is interesting enough to attack. It's whether an attacker could find an opportunity.

Cyber Smarter question: If someone were looking for the easiest way into your environment today, where would they find it?

Assumption #7: “We Would Know If Someone Got In”

Not every cyberattack begins with systems going offline or a ransom message appearing on a screen. Sometimes the first stage is quiet. An attacker may attempt to access email, collect credentials, explore systems or establish persistence before doing anything that creates an obvious disruption. That's why visibility and monitoring matter. The goal isn't simply to stop every possible attempt. It's also to identify unusual behavior early enough to investigate it.

Cyber Smarter question: Who would notice unusual activity in your environment, and how quickly?

Assumption #8: “Nothing Has Happened Yet, So What We're Doing Must Be Working”

This may be the most comfortable assumption of all. An organization can go years without experiencing a major cybersecurity incident. That doesn't necessarily mean its defenses have been tested. Technology changes. Employees come and go. New applications are introduced. Vendors receive access. Devices are replaced. Cloud environments grow. Temporary exceptions become permanent. The cybersecurity environment you reviewed two years ago may not be the environment you're operating today. Cybersecurity shouldn't only be reconsidered after something goes wrong.

Cyber Smarter question: When was the last time you looked at your environment with fresh eyes?

This Cybersecurity Awareness Month, Challenge Your Assumptions

Cybersecurity Awareness Month shouldn't just be about reminding employees not to click suspicious links. It is an opportunity to have bigger conversations. Ask your IT team difficult questions. Review responsibilities. Test your backups. Look at your security tools. Review who has access to what. Talk through what would happen during an incident. Most importantly, don't settle for “I think we're covered.” Find out.

At Total Communications, we help organizations take a closer look at their cybersecurity environments, identify potential gaps and build a more complete approach to protecting their technology and operations. From managed IT and cybersecurity services to endpoint security, email protection, vulnerability scanning, employee security awareness, backup and disaster recovery, and strategic technology planning, our focus is helping organizations understand where they stand and where improvements may be needed. This Cybersecurity Awareness Month, becoming Cyber Smarter can start with one simple question: What are we assuming about our cybersecurity that we haven't actually verified?