
Cybersecurity Awareness Month Starts in a Week. Here's a Plan Your Team Won't Ignore.
October starts in a week. Here is a four week plan a small business can run without a security team, including the parts worth skipping.
Your team probably hasn't thought about cybersecurity since last year's password reset. October gives you a reason to fix that, and a built-in structure so you're not making it up as you go.
CISA, the federal cybersecurity agency, urges all U.S. small and medium businesses to take action during Cybersecurity Awareness Month. The month is designed to give you a four-week reason to run a real security program without needing a dedicated security team. This post is a week-by-week plan you can actually execute, with honest calls on what to skip and what to focus on.
The skeleton: NIST CSF 2.0 in four weeks
You don't need to memorize security frameworks. But NIST CSF 2.0, the standard the FTC points small businesses toward, organizes cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Compress those into October, and you have a plan that actually builds on itself instead of feeling like four random tasks.
The NIST CSF 2.0 Small Business Quick Start Guide is free and designed for exactly your situation. We'll map the four weeks to its structure.
Week 1: Kickoff and baselines (Govern + Identify)
Start by answering three questions: What do we have? What matters most? Who's responsible?
Spend 30 minutes on a cyber tune-up. Walk through your systems and write down:
- Where do we store customer data, financial records, or employee information?
- Which systems would shut down our business if they went offline for a day?
- Who has admin access to email, remote access, and accounting software?
- When was the last time we updated our passwords or reviewed who has access to what?
- Do we have a backup? Where is it? When was the last time we tested it?
That's your baseline. Post it somewhere visible. You'll come back to it in Week 4.
CISA's guidance for small businesses emphasizes that all staff must be formally trained to understand the organization's commitment to security and what tasks they need to perform. Week 1 is when you name who owns each task. It doesn't have to be a security expert, it's usually the office manager, the owner, or the person who already handles IT. Clarity on ownership is what makes the rest of the month stick.
Week 2: Access, identity, and patching (Protect)
This week is about locking the doors. Three things:
Multi-factor authentication (MFA). Turn it on for email, remote access (VPN or RDP), and accounting software. CISA training guidance calls out MFA as a core requirement, and it's the single most effective thing you can do. If someone guesses a password, they still can't get in without a second factor, usually a code on a phone.
Patching cadence. Set a day each month when you update Windows, Mac, phones, and any business software. The U.S. Department of Labor recommends cybersecurity awareness training at least annually, updated to reflect the most recent risk assessment. That includes keeping software current. Mark it on the calendar. It takes 30 minutes and prevents most ransomware.
Password hygiene. If you're still using the same password for multiple systems, stop. Use a password manager (Bitwarden, 1Password, LastPass) so people have unique, strong passwords without memorizing them. CISA guidance includes avoiding clicking on suspicious links that could be phishing attacks as a core training point, and that starts with not reusing passwords.
Week 3: Data, devices, and phishing drills (Detect)
This week is about seeing what's happening and teaching people to spot trouble.
Backups. If you don't have an off-site backup (cloud, external drive, or managed backup service), set one up this week. Test it by restoring a file. Ransomware is the most common attack on small businesses, and a backup is your only real defense.
Device inventory. List every computer, phone, and tablet that accesses your network. Who owns it? When was it last updated? Does it have encryption turned on? This takes an hour and tells you where your gaps are.
Phishing simulation. Send a fake phishing email to your team. Not to trick them, to teach them. Behavioral change, not just awareness, is what lowers phishing click rates, and it requires monthly phishing simulations with immediate, specific feedback at the point of failure. If someone clicks, they get a one-minute training video right then, not a lecture from IT weeks later. That's how people actually learn.
Week 4: Response readiness (Respond + Recover)
The last week is about knowing what to do when something goes wrong.
Create four playcards, one for each scenario every small business faces:
Scenario 1: Account compromise. Someone's email or system password was stolen. What do you do? Change the password immediately. Check what was accessed. If customer data was involved, you may need to notify them. Who makes that call?
Scenario 2: Sensitive email to the wrong recipient. Someone sent payroll data or a contract to the wrong email address. Who do you contact? How fast? Can you ask the recipient to delete it?
Scenario 3: Device lost or stolen. A laptop or phone with company data went missing. Who do you tell? How do you wipe it remotely? Is it encrypted so the data can't be read anyway?
Scenario 4: Phishing suspected. Someone thinks they clicked a malicious link or opened a suspicious attachment. What happens next? Who do they tell? Do you isolate the device? Do you check for damage?
Write these down. Walk through them as a team. CISA guidance emphasizes how to escalate suspicious activity as a core training point. Most breaches happen because people don't know who to tell or feel embarrassed to report it.
What to skip
Not everything in a typical awareness program actually works.
Compliance-only framing. If the only message is "this is required," people disengage. Tie security to how it protects their own data, finances, and reputation, not just the company's. People care about their own stuff.
Completion-rate dashboards. Measuring how many people clicked "I read this" tells you nothing about whether they changed their behavior. Focus on whether people actually use MFA, whether they report phishing, whether they patch on schedule. Those are the metrics that matter.
Annual once-a-year training. One training session in January fades by March. Monthly phishing simulations, a quarterly "what's changed" email, and a refresher when you add new systems, that's what sticks.
What this costs
Cost depends on how much you do yourself versus outsource.
Managed security awareness platforms run $3–$8 per user per month (provider-reported range). For a 15-person business, that's $45–$120 per month. Self-serve platforms range from $20–$55 per user per year; fully managed programs run $5,000–$40,000 per year (provider-reported ranges). For a 100-person company, total investment typically runs $5,000–$15,000 annually.
The return comes from avoided breaches. The ROI formula is straightforward: ROI = (Risk Reduction Value − Program Cost) ÷ Program Cost × 100. If a breach would cost you $50,000 and awareness training costs $5,000, and it cuts your breach risk in half, the math is clear. Many cyber insurance policies also require annual awareness training as a condition of coverage, so this work often checks an E&O box you need anyway.
Free resources you can use right now
You don't have to buy anything to start. CISA publishes a free Cybersecurity Awareness Month toolkit with posters, email templates, and talking points you can share with your team and customers. KnowBe4 also publishes a free Cybersecurity Awareness Month kit with similar resources. Both are ready to pull from this week.
Running this with local support
If you're in the Chippewa Valley, western Wisconsin, or Southwest Florida, you don't have to run this alone. Coulee Tech serves small and mid-size businesses across those regions with local engineers and on-site response. We cover IT, cybersecurity, phones, cloud, and AI under one managed agreement, which means the "who owns this" question that sinks most awareness programs doesn't come up. For a business that wants to actually run the four-week plan in October, our team can be on-site to set up MFA, walk through the response playcards, run the phishing drill, and sit in the Week 4 review.
The flat-rate managed model means this kind of work is already covered, not a surprise bill.
Book a 30-minute October readiness call. We'll spend half an hour walking through the four-week plan against your actual setup, what you already have, what's missing, and what we can cover under your existing managed agreement.


