Our site uses cookies

This site uses optional cookies for performance and quality purposes in line with out Cookie Policy.

News

Cybersecurity Awareness Month

by Rupert Davey
October 2026

October is Cybersecurity Awareness Month, but protecting a business against cyber threats cannot be a once-a-year exercise.

Cybersecurity Awareness Month: good cybersecurity protects the whole business

Cybersecurity needs continuous attention.

The technology changes, the threats change and the way people work changes.  New cloud services, applications, devices and AI tools can all deliver significant benefits, but they also create new identities, data, connections and potential routes into the organisation.

Businesses therefore need more than antivirus software, a firewall or somebody helpful to call once an incident has happened.  They need a comprehensive cybersecurity capability that reduces the likelihood of a successful attack, detects suspicious activity quickly and helps the organisation respond and recover effectively if something does go wrong.

A compromised account is not just a compromised mailbox

One of the most common mistakes businesses make is to underestimate the potential impact of an account compromise.

A compromised Microsoft 365 identity may provide access to much more than email.  Depending on the user’s permissions, an attacker could potentially access SharePoint sites, OneDrive files, Teams conversations, cloud applications and other company information available to that identity.

This is why identity has become one of the most important parts of modern cybersecurity; the user identity is the new parimeter.  Strong multifactor authentication, comprehensive Conditional Access suite, appropriate administrative permissions including Priviliaged Identitiy Management and the secure management of authentication method, including passwordless, all help reduce the risk of an attacker gaining access.

Businesses must also consider what happens after an account is secured.  An investigation may need to establish what the attacker accessed, what actions they performed, whether information was removed and whether any persistence mechanisms remain.  Resetting a password may be necessary, but it should not automatically be treated as the end of the incident.

Hackers don't hack, they log in.

Prevention and response are equally important

Good cybersecurity must improve both the organisation’s pre-breach and post-breach position.

Pre-breach security is about making a successful attack less likely.  This includes risk identifiction, secure configuration, managed devices, endpoint protection, email filtering, multifactor authentication, encryption, software updates, vulnerability management, AI observability and appropriate access controls.

Post-breach security is about detecting, containing, investigating and recovering from an incident.  This requires usable security logs, effective alerting, clearly defined responsibilities, an escalation process and documented incident response and recovery plans.

No responsible provider should claim that an organisation can eliminate every cyber risk.  The objective is to make the business significantly harder to compromise, identify suspicious activity earlier and reduce the operational, financial and reputational impact of an incident.

Assume a breach will occour and plan accordingly.

Security products are not the same as a cybersecurity service

Many businesses already pay for capable cybersecurity technology, particularly within Microsoft 365.  However, owning security products does not mean those products are correctly configured, monitored or maintained.

A managed cybersecurity service brings the necessary controls together and provides people who are responsible for operating them.  That should include ongoing monitoring, investigation, remediation, policy management, risk reviews, technical improvement and clear reporting.

This Security Operations (SecOps) capability is important because modern attacks rarely produce one obvious warning.  The useful evidence may be spread across identities, devices, email, cloud applications and infrastructure.  Looking across those different signals provides a much clearer view of what is happening than relying on a single appliance or security product.

"Secure" is a journey, not a destination.

Earlier detection can make a decisive difference

Attackers may spend time inside an environment before they are discovered, the dwell time.  During that period they may investigate systems, search for valuable information, establish additional access or prepare for further activity.

Large quantities of information can also be copied very quickly.  A response that begins only after the organisation notices obvious disruption may therefore begin too late.

Comprehensive monitoring helps identify indicators of compromise and unusual behaviour before they develop into a major incident.  Security Information and Event Management (SIEM) platforms such as Microsoft Sentinel can bring together information from identities, endpoints, cloud applications and other relevant systems to support earlier detection and faster investigation.

External Attack Surface Management (EASM) can also help identify internet-facing assets and exposures from an attacker’s perspective.  This is increasingly important because organisations may not always have a complete view of every service, application or resource connected to their business.

You need to know your assets to know your high value assets. 

Cyber resilience requires preparation

Security controls reduce risk, but every business should still prepare for the possibility of an incident.

An Incident Response Plan should define how an incident is identified, escalated, investigated and contained.  An Incident Recovery Plan should set out how the organisation will restore services and return to normal operation.

These plans need named responsibilities and a clear route for escalation.  The person managing information security should understand their operational responsibilities, while a senior manager should be available when a security concern requires business authority, difficult decisions or escalation across the organisation.

Plans should also be tested.  A document that has never been exercised may contain assumptions, missing information or impractical steps that only become apparent during a real incident. 

Testing gives the business an opportunity to correct those weaknesses in controlled circumstances.

People remain an essential security control

Employees regularly make decisions about emails, links, attachments, authentication requests, information sharing and cloud applications.

Awareness training should help people understand the risks they are most likely to encounter and make it easy for them to report something suspicious.  Phishing simulations can reinforce that learning and help identify where further support may be needed.

Employees should not be expected to investigate threats themselves.  They need a clear and trusted reporting route so that a specialist can assess the message, block the sender where appropriate and remove malicious content from other mailboxes.

A positive security culture encourages people to report concerns quickly without fearing blame.  Prompt reporting gives the Security Operations team more time to contain a potential threat and protect other users.

Cybersecurity is not solely a technical responsibility.

Cybersecurity needs governance as well as technology

Technical controls are only one part of a comprehensive security programme.  Businesses also need appropriate policies, defined responsibilities, risk assessments and regular management review.

Governance becomes particularly important when organisations develop their own applications or adopt AI services.  Without suitable oversight, different teams may create systems, store information or use cloud services without consistent security controls.

Businesses need to understand who is responsible for development and testing, which resources may be deployed, where information may be processed and what security standards must be followed.  Approved configurations and cloud policies can help prevent insecure or unauthorised resources from being introduced while still allowing teams to work productively.

The same principle applies to generative AI.  Organisations should know which AI tools are being used, what business information is being shared with them and whether those tools have been reviewed and approved. 

AI governance and cybersecurity should be addressed together rather than treated as unrelated projects, or worse, ignored.

Independent certification provides valuable assurance

Cyber Essentials provides businesses with a recognised baseline for protection against common cyber threats.  Cyber Essentials Plus adds an independent technical assessment of the controls implemented by the organisation.

Certification can provide valuable assurance to customers, insurers and supply-chain partners, but it should not be treated as the entire cybersecurity strategy.  A successful assessment represents a point in time, while the organisation’s people, systems and risks continue to change.

Cyber Essentials and Cyber Essentials Plus are most effective when supported by ongoing security management, monitoring, vulnerability remediation and annual renewal.

If you're looking for somewhere to start, Cyber Essentials is a great cornerstone.

Comprehensive cybersecurity should not be salami-sliced

It can be tempting to select individual cybersecurity features or remove controls to meet a particular budget.  However, security controls are designed to work together.

Removing elements without considering these dependencies can create apparent coverage while leaving crtitical gaps.  It can also make the service harder to operate consistently because different organisations end up with different combinations of controls and unclear responsibilities.

Select an appropriate security level, implement it properly and create a roadmap for further improvement as the risks and requirements of the business develop.

Cybersecurity is a business investment

Good cybersecurity supports business continuity, protects confidential information and gives customers confidence that their data is being handled responsibly.

It can also support contractual requirements, cyber-insurance discussions, supply-chain assurance and future compliance initiatives.  Security frameworks and certifications provide stronger evidence when they are backed by technical controls, documented risk management and an active Security Operations capability.

The commercial discussion should therefore consider more than the monthly cost of a products and services.  It should consider the value of earlier detection, tested recovery plans, access to security specialists, better visibility of risk and a continuously improved security posture.

The true value of cybersecurity is not what it costs, but what it protects and enables.

A comprehensive approach from ctm

Our Cybersecurity Managed Services provide structured levels of protection through our Bronze, Silver, Gold and Platinum packages.

Our services bring together the formidable Microsoft security technology stack, experienced cybersecurity professionals, risk management, governance, monitoring, testing and continuous improvement.

We work with each customer to understand its systems, people, information and business risks.  We then implement a consistent level of protection, monitor the environment and maintain a practical cybersecurity roadmap.

Rule 1 of cybersecurity;  don't talk about your technical controls in public!

Make Cybersecurity Awareness Month count

Cybersecurity awareness month is a useful opportunity to ask some direct questions:

If the answer to any of these questions is unclear, October is the right time to address it.

Cybersecurity Awareness Month lasts for one month. Protecting your organisation, its people and its customers is a year-round responsibility.

Explore ctm Cybersecurity Managed Services

Find out more about Cybersecurity Awareness Month