October is Cybersecurity Awareness Month. While the designation is meant to promote best practices for digital safety and security, it shouldn’t just be an annual observance.
Cybersecurity should be a point of focus every time we log on to a connected device. It should be a focus of every employee, manager and business owner. All it takes is one wrong move – clicking a bad link, downloading a malware-laden attachment or believing a scammer on the other end of the phone has good intentions – and a business’ livelihood could be at stake.
John Joyce, co-owner of CRS Technology Consultants, recently appeared on ABC7 to discuss steps to protect ourselves from cyberattacks, data breaches and ransomware attacks. During that conversation, John hammered home the point that cybersecurity awareness should be a nonstop focus for businesses.
“It’s every hour of every day. It’s vigilance,” John says. “We have to stay on top of it because it affects every part of our lives. What’s important about this time of the year is having the conversations around it.”
WATCH
Cybersecurity awareness: One alarming statistic
It’s widely reported that a cyberattack happens every 39 seconds. In reality, it’s likely much more often because computer users often are not aware cybercriminals have attacked their device. Astra, a tech organization focused on digital safety, notes that cybercrimes are predicted to cost the world $9.5 trillion in 2024.
In recent years, though, there has been less media coverage about cybersecurity breaches impacting large corporations.
“It’s not because they don’t happen; it’s because they happen so much,” John says. “It’s borderline not a newsworthy event most of the time. These companies and services that we utilize we utilize get breached and compromised day in and day out, and your credentials get stolen.”
No one is immune from a cyberattack. Businesses often are the target. This includes multinational corporations as well as mom-and-pop shops. Unlike a burglary, where criminals want “stuff,” cybercriminals want data. To them, data is money.
Businesses aren’t the only ones that should be concerned about cybercriminals. Nonprofit organizations, schools, churches and individuals have all been subject to cyberattacks. Today, artificial intelligence is helping cybercriminals, as noted in a previous Tech Bytes blog: Email scams get sophisticated with AI’s help. Additionally, more of our transactions and communications are online: banking and investments, shopping, travel bookings, emails, texts, social media and more.
In today’s business climate, work and personal lives often overlap. So, too, does technology. Many employees access work emails, files, accounts and documents at home or on the go using personal devices. They take Zoom or Teams calls from home. Those devices should have the same level of protection as computers in the office.
“Back then, it was the one computer in your home, or maybe just the one computer at work,” John says. “Now, you go to work and use the computer there, you’re on your phone on the way home and you probably sit on the couch scrolling social media, and these connected devices are with us everywhere. We have to be thinking in that mindset – every hour of every day.”
Our security mindset is generally strong while sitting at a computer in the office. Unfortunately, we tend to be more relaxed when scrolling on a cell phone or tablet at home. Given that security experts estimate one-third of cyberattacks originate with a mobile device, this is especially alarming for businesses trying to safeguard data.
“Even when we’re not using the devices, we still have to be thinking about the security of those services,” John notes. “When you’re not logged into your bank, that server is still running. Your bank account is still there. Your password is still vulnerable.”
The top source of cyberattacks
The Cybersecurity & Infrastructure Security Agency (CISA) notes that more than 90% of cyberattacks start with a phishing email.
“A phishing scheme is when a link or webpage looks legitimate, but it’s a trick designed by bad actors to have you reveal your passwords, social security number, credit card numbers or other sensitive information,” CISA notes. “Once they have that information, they can use it on legitimate sites. And they may try to get you to run malicious software, also known as malware.”
CISA has a simple saying: Think before you click.
“If it’s a link you don’t recognize, trust your instincts, and think before you click.”
CRS Technology Consultants advises partners and their employees to ask themselves these questions before clicking on an email or text:
- Do you know the sender?
- Are you expecting an email from this person or business?
- Have you subscribed to receive emails from this sender?
- Does the email look like the sender’s previous emails?
- Does the sender’s name match the email address?
- Is an email signature at the bottom?
Answers to these questions will help sniff out any potential cybersecurity threats.
The first step for businesses
All businesses, regardless of their employee count or annual revenue, should partner with a local, experienced IT company. CRS Technology Consultants partners with dozens of local businesses, nonprofits and organizations to safeguard digital systems. The firm offers a personal connection, a tailored experience and a practical approach while providing support for businesses.
Our systems engineers note analogies when explaining why businesses should partner with an IT specialist. It’s simple: if you’re not a mechanic, you shouldn’t fix your own car. If you’re not an IT specialist, you shouldn’t try to DIY your digital infrastructure.
Every year, one in 10 small businesses suffers a cyberattack. The longer a company is in business, the greater the chance is that its time will come. Cyberattacks and ransomware attacks have literally bankrupted businesses and destroyed their reputations.
“Every single one of us has been hacked, whether we realize it or not,” according to John. “Whether it was your device or not, whether it was your account or not, some service you utilize has been compromised.”
That information is often exchanged on the “dark web,” a platform that cybercriminals frequent to purchase compromised information.
“Your passwords are out there, whether you realize it or not,” John advises. “Whether it’s your account that will be gone after next is a numbers thing. That’s why we have to take the steps to protect ourselves now.”
All is not lost if a business suffers a cyberattack, though. An IT specialist can help mitigate the damage while looking to solidify a company’s digital security in the future.
In many cases, the post-breach conversation starts by addressing how the cyberattack happened. Human error oftentimes opens the door for cyberattacks.
These five basic questions help frame a post-breach cybersecurity awareness discussion with businesses:
- Does the business have an antivirus program and firewall?
- Is the company requiring employees to use multifactor authentication to access accounts remotely?
- Do employees update software when prompted or is someone responsible for ensuring programs are up to date?
- Are employees using strong, complex passwords and changing them every 60-90 days?
- Does the company have a written policy governing computer use and digital security?
Answering “no” to any of these questions indicates the need to strengthen digital security.
“If you haven’t been hacked yet, count yourself lucky,” John says. “Always act like you’re the next one. We operate under the assumption in our business that it’s not if… it’s when.”
READ MORE: Tech Resources


