October is Cybersecurity Awareness Month. The Cybersecurity and Infrastructure Security Agency (CISA) launched this year’s campaign, “Securing the Next 250,” on Oct. 2, tying it to the nation’s 250th anniversary. Much of the messaging targets critical infrastructure, but the core advice applies just as well to a five-person office or a family-run shop.
Here’s a checklist built from the Federal Trade Commission’s cybersecurity basics for small businesses and CISA’s recommendations.
Protect devices and files
- Turn on automatic updates. The FTC recommends setting apps, web browsers and operating systems to update automatically.
- Back up important files. Keep copies offline, on an external drive or in the cloud. CISA also recommends encrypting data.
- Lock every device. Require passwords on laptops, tablets and phones, and don’t leave them unattended in public.
- Encrypt sensitive data on devices and storage media.
- Replace outdated equipment. CISA urges organizations to replace devices that no longer get security support.
Lock down logins
- Use multifactor authentication (MFA). The FTC says to require it for any part of your network with sensitive information.
- Use strong, unique passwords. The FTC suggests at least 12 characters mixing numbers, symbols and upper- and lowercase letters. Never reuse them or share them by phone, text or email.
- Limit login attempts to make password-guessing attacks harder.
Secure your Wi-Fi
Change your router’s default name and password, turn off remote management and log out once setup is done. The FTC also recommends using WPA2 or WPA3 encryption.
Train your team
Many attacks start with a convincing email or text. The FTC recommends regular security training for all staff, updated as new risks appear. CISA’s advice for individuals is the same message in short form: recognize and report phishing, use strong passwords, turn on MFA and keep software updated.
Plan for a bad day
Decide in advance what you’ll do if something goes wrong. The FTC suggests a plan that covers preserving data, keeping the business running and notifying customers if their information is exposed. CISA recommends practicing an incident response plan at least once a year and having a way to recover quickly.
If you’re hit, you can report incidents to CISA at cisa.gov/report. For larger concerns, such as handling customer data or legal notification requirements, an IT security professional or attorney can help.
More on Contoh
- Cybersecurity Awareness Month: Four Habits That Make You a Harder Target
- How to Set Up a Passkey for Your Google Account
- The Small Business Guide to AI Tools: Where to Start, What to Avoid