Cybersecurity Awareness Month – Breaches

4th October 2022 | Blog Cybersecurity Awareness Month – Breaches



Data Breaches

Two out of Three Businesses have been Breached

Forrester’s article sites a sobering statistic.  They state that “63% of organizations were breached in the last year, 4% points higher than the previous year.”  CyberHoot was founded nearly a decade ago to help Small to Medium sized Businesses protect themselves from cyberattack.  The attacks we see are become more sophisticated and common.  They are more devious and impactful each and every year.  SMBs and Managed Service Providers (MSPs) must prepare for the onslaught of attacks by following CyberHoot’s advice below.  Build your protections now before it’s too late.

CyberHoot Best practices:
  1. Train your employees on the common attacks that are out there.  From weak passwords and password managers, to the importance of multi-factor authentication and how to spot phishing attacks.  Awareness is the key to defending your business.
  2. Govern you employees with cybersecurity policies including Acceptable Use, Password, Information Handling and a Written Information Security Policy.
  3. Establish cybersecurity best practice processes such as a Vulnerability Alert Management Process (VAMP) and a Cybersecurity Incident Management Process (CIMP) to guide and require action in the face of an emergency.  Then move on onboarding and offboarding processes, SaaS management processes, and 3rd party risk management.
  4. Establish strong technical protections including: a Firewall, antivirus, anti-malware, anti-spam, multi-factor authentication on all critical accounts,  Enable full disk encryption, manage the keys carefully, and most importantly, adopt, train on and require all employees to use a Password Manager.
  5. Train employees on how to spot and avoid phishing attacks.  CyberHoot has released a disruptive method of Phish Testing the fills in gaps in your employees knowledge without punishing them for failure.  Instead we reward them for success.  More info is available here.
  6. Backup your data by following our 3-2-1 Backup methodology to ensure you can recover your business from a cybersecurity event.
  7. In the modern Work-from-Home era, make sure you’re managing personal devices connecting to your network by validating their security (patching, antivirus, DNS protections) or prohibiting their use entirely.
  8. If you haven’t had a risk assessment by a 3rd party in the last 2 years, you should have one now. Establishing a risk management framework in your organization is critical to addressing your most egregious risks with your finite time and money.
  9. Buy Cyber-Insurance to protect you in a catastrophic failure situation. Cyber-Insurance is no different than Car, Fire, Flood, or Life insurance. It’s there when you need it most.

CyberHoot believes that for many small to medium sized businesses and MSPs, you can greatly improve your defenses and chances of not becoming another victim of cyberattack if you follow the advice above.

We hope you’re enjoying Cybersecurity Awareness Month (CAM).  Visit or subscribe to CyberHoot’s Facebook, LinkedIn, or Twitter pages to get daily updates throughout the month.

Sources:

Forrester: 2 of 3 Companies Have Been Breached in the Last Year

Secure your business with CyberHoot Today!!!


Sign Up Now

Latest Blogs

Stay sharp with the latest security insights

Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.

Your Employees Connected 47 Apps to Google Last Year. Can You Name One of Them?

Your Employees Connected 47 Apps to Google Last Year. Can You Name One of Them?

OAuth tokens don't expire when employees leave, passwords change, or apps go rogue. Your security program needs...

Read more
Attackers Don’t Need a Key. They Already Have Yours.

Attackers Don’t Need a Key. They Already Have Yours.

Most breaches don't start with a hacker in a hoodie cracking code at 3am. They start with your username and a...

Read more
Claude Mythos Opened Pandora’s Box. Project Glasswing Is Racing to Close It.

Claude Mythos Opened Pandora’s Box. Project Glasswing Is Racing to Close It.

Article Updates: As of May 6th 2026, every major U.S. AI lab, including Google DeepMind, Microsoft, xAI,...

Read more