Cybersecurity Awareness Month began on October 1. This year the Cybersecurity and Infrastructure Security Agency built its campaign, Securing the Next 250, around the four basics it repeats every year, phishing awareness, strong passwords, multifactor authentication, and software updates, plus three Rs for organizations that keep essential services running: reduce attack surfaces, replace end-of-support devices, and recover quickly to sustain operations.
The campaign is aimed at critical infrastructure, but the reasoning reaches every small business that depends on it, and every small business those operators depend on. Acting CISA Director Nick Andersen put it this way in the agency's announcement: "Whenever critical infrastructure is disrupted, so are the businesses and communities that depend on vital services."
Of the three Rs, the first two get most of the attention. The third is the one most small offices assume they have covered, and the one they have most often never tested.
The three Rs in plain terms
Reduce means fewer ways in. Remote access tools nobody uses anymore, administrator pages that answer from the open internet, and flat office networks where every device can reach every other device all widen the target. We covered two practical controls in network segmentation for small offices and protective DNS.
Replace means retiring equipment that no longer receives security updates. Last week's post on Windows 10 reaching end of support walks through how to find those machines and what to do with them.
Recover means getting back to operating after something goes wrong, whether that is ransomware, a failed drive, or a mistaken deletion. It is the one R that cannot be bought in a box, because it depends on whether a process works when it is needed.
A backup is not a recovery
Most small businesses can say yes to the question "do you have backups." Far fewer can answer the questions that decide whether those backups will save them. Which systems are included, and which are not? Where do the copies live, and could an attacker who reached the office network also reach them? Who has the credentials to the backup console, and are those credentials stored anywhere other than the systems being restored? How long would a full restore take?
CISA's #StopRansomware Guide is direct about what good looks like. It tells organizations to "Maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of backups in a disaster recovery scenario." The same guide explains why the offline part matters: "Test backup procedures on a regular basis. It is important that backups are maintained offline, as many ransomware variants attempt to find and subsequently delete or encrypt accessible backups."
Read those two lines together and the gap becomes clear. A backup that sits on the same network, under the same administrator account, can be found and destroyed by the same attacker who encrypted everything else. And a backup that has never been restored is an assumption, not a plan.
Four questions to answer this month
- What exactly is backed up? List the systems that would stop the business if they disappeared: the accounting file, the shared drive, the line-of-business application, email, and the customer records in any cloud service. Then confirm each one is in the backup, rather than assuming it is. Cloud services do not all back up your data the way you might expect; our post on who owns your data in a cloud service covers what to check in the terms.
- Is at least one copy out of reach? At least one copy should be offline or isolated, protected by credentials that are separate from the everyday administrator account.
- How long does a restore take? Not how long the vendor says it takes. How long it took the last time someone did it.
- When was the last test, and who ran it? If nobody can name a date and a person, the honest answer is never.
Run a restore test in one afternoon
A restore test does not need a disaster drill or a weekend. Pick one system that matters, such as the accounting data or a busy shared folder, and restore it to a separate location, not over the live copy. Time the whole process from the moment you start looking for the backup to the moment a person can open and use the restored files. Open several of those files to confirm they are complete and current.
Write down every snag along the way: the password nobody could find, the restore that needed a vendor call, the folder that turned out not to be included. Each snag is a finding, and each one is far cheaper to fix on a calm afternoon than during an outage. Fix what you found, then repeat the test on a schedule, quarterly for the systems the business cannot run without.
Plan to rebuild, not only to restore
Restoring data assumes there is a working computer or server to restore it onto. After ransomware, there may not be. The #StopRansomware Guide also recommends that organizations "Maintain and regularly update 'golden images' of critical systems." For a large enterprise that means prepared system images. For a small office, the practical version is a written rebuild list for each critical machine: the operating system version, the software and license keys it needs, the settings that matter, and where the installers are kept. Store that list, and the backup credentials, somewhere that does not depend on the systems you are trying to recover.
What to do before October 31
- List the systems the business cannot operate without, and confirm each one is in the backup.
- Confirm at least one backup copy is offline or isolated, with credentials separate from everyday administrator accounts.
- Restore one critical system to a separate location, time it, and open the files.
- Write down every problem the test exposed, and assign an owner and a date to each fix.
- Write a rebuild list for each critical machine and keep it, with the backup credentials, somewhere outside the systems it describes.
- Put the next restore test on the calendar.
Awareness Month is a reasonable deadline for a job that is easy to postpone. The first two Rs make an incident less likely. The third decides how long it lasts. Of the three, it is the only one you can measure in an afternoon, and the measurement is the point: a recovery time you have timed is a number you can plan around, and one you have not is a guess.
Sources
- CISA Launches Cybersecurity Awareness Month: Securing the Next 250, October 1, 2026 - Cybersecurity and Infrastructure Security Agency
- #StopRansomware Guide, September 2023 - Cybersecurity and Infrastructure Security Agency
Find out how long your recovery really takes
Adams Cloud & Cybersecurity helps small businesses confirm what their backups cover, run a timed restore test, and write a rebuild plan staff can follow when it counts.
Book a free consultation