Cybersecurity Awareness Month began on October 1. This year the Cybersecurity and Infrastructure Security Agency built its campaign, Securing the Next 250, around the four basics it repeats every year, phishing awareness, strong passwords, multifactor authentication, and software updates, plus three Rs for organizations that keep essential services running: reduce attack surfaces, replace end-of-support devices, and recover quickly to sustain operations.

The campaign is aimed at critical infrastructure, but the reasoning reaches every small business that depends on it, and every small business those operators depend on. Acting CISA Director Nick Andersen put it this way in the agency's announcement: "Whenever critical infrastructure is disrupted, so are the businesses and communities that depend on vital services."

Of the three Rs, the first two get most of the attention. The third is the one most small offices assume they have covered, and the one they have most often never tested.

The three Rs in plain terms

Reduce means fewer ways in. Remote access tools nobody uses anymore, administrator pages that answer from the open internet, and flat office networks where every device can reach every other device all widen the target. We covered two practical controls in network segmentation for small offices and protective DNS.

Replace means retiring equipment that no longer receives security updates. Last week's post on Windows 10 reaching end of support walks through how to find those machines and what to do with them.

Recover means getting back to operating after something goes wrong, whether that is ransomware, a failed drive, or a mistaken deletion. It is the one R that cannot be bought in a box, because it depends on whether a process works when it is needed.

A backup is not a recovery

Most small businesses can say yes to the question "do you have backups." Far fewer can answer the questions that decide whether those backups will save them. Which systems are included, and which are not? Where do the copies live, and could an attacker who reached the office network also reach them? Who has the credentials to the backup console, and are those credentials stored anywhere other than the systems being restored? How long would a full restore take?

CISA's #StopRansomware Guide is direct about what good looks like. It tells organizations to "Maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of backups in a disaster recovery scenario." The same guide explains why the offline part matters: "Test backup procedures on a regular basis. It is important that backups are maintained offline, as many ransomware variants attempt to find and subsequently delete or encrypt accessible backups."

Read those two lines together and the gap becomes clear. A backup that sits on the same network, under the same administrator account, can be found and destroyed by the same attacker who encrypted everything else. And a backup that has never been restored is an assumption, not a plan.

Four questions to answer this month

Run a restore test in one afternoon

A restore test does not need a disaster drill or a weekend. Pick one system that matters, such as the accounting data or a busy shared folder, and restore it to a separate location, not over the live copy. Time the whole process from the moment you start looking for the backup to the moment a person can open and use the restored files. Open several of those files to confirm they are complete and current.

Write down every snag along the way: the password nobody could find, the restore that needed a vendor call, the folder that turned out not to be included. Each snag is a finding, and each one is far cheaper to fix on a calm afternoon than during an outage. Fix what you found, then repeat the test on a schedule, quarterly for the systems the business cannot run without.

Plan to rebuild, not only to restore

Restoring data assumes there is a working computer or server to restore it onto. After ransomware, there may not be. The #StopRansomware Guide also recommends that organizations "Maintain and regularly update 'golden images' of critical systems." For a large enterprise that means prepared system images. For a small office, the practical version is a written rebuild list for each critical machine: the operating system version, the software and license keys it needs, the settings that matter, and where the installers are kept. Store that list, and the backup credentials, somewhere that does not depend on the systems you are trying to recover.

What to do before October 31

Awareness Month is a reasonable deadline for a job that is easy to postpone. The first two Rs make an incident less likely. The third decides how long it lasts. Of the three, it is the only one you can measure in an afternoon, and the measurement is the point: a recovery time you have timed is a number you can plan around, and one you have not is a guess.

Sources

Find out how long your recovery really takes

Adams Cloud & Cybersecurity helps small businesses confirm what their backups cover, run a timed restore test, and write a rebuild plan staff can follow when it counts.

Book a free consultation