October is Cybersecurity Awareness Month, an annual reminder that protecting a business from cyber threats isn’t just an IT responsibility. Every employee who opens an email, approves a payment, chooses a password or accesses company data has a role to play.
And while cyber threats continue to evolve, the good news is that businesses don’t need to become cybersecurity experts overnight. A handful of practical habits can make a meaningful difference.
Start With What You Can Control
Make good security habits part of everyday business.
1. Strengthen Your Passwords
Strong, unique passwords remain one of the first lines of defense.
Use lengthy passwords—generally 15 or more characters—and avoid personal information or predictable patterns. Choose different passwords for different accounts and take advantage of a password manager rather than keeping passwords in a notebook or plain-text document.
Ask yourself:
- Are employees reusing passwords between business and personal accounts?
- Are important accounts protected by unique credentials?
- Does your business use a password manager?
- What happens to an employee’s passwords and access when they leave the company?
2. Turn On Multifactor Authentication
A password alone may not be enough.
Multifactor authentication, or MFA, adds another verification step when someone logs into an account. Use MFA wherever it is available, particularly for email, financial accounts, social media and other sensitive systems.
And there’s an important reminder for employees: don’t automatically approve an MFA prompt you didn’t initiate. An unexpected authentication request can be a warning that someone else is attempting to access the account.
Ask yourself:
- Is MFA enabled for business email?
- Is it enabled for financial and cloud-based systems?
- Does remote access require MFA?
- Do employees know what to do when they receive an unexpected MFA request?
3. Slow Down When Something Feels Off
Phishing remains one of the most common ways attackers attempt to gain access to information and systems. And today’s scams aren’t necessarily obvious, and can originate in emails, text messages, phone calls, fake websites and other forms of social engineering. Warning signs can include unusual requests, urgency, unfamiliar links or attachments, mismatched email domains and requests to provide sensitive information or bypass normal procedures.
Business owners should pay particular attention to business email compromise—scams in which criminals impersonate executives, vendors, attorneys or other trusted contacts to convince employees to transfer money or information.
The best defense may be surprisingly simple:
Slow down. Verify.
If a vendor suddenly changes payment instructions, verify the request using a known phone number. If the boss asks for an urgent wire transfer, confirm it through another channel. If an email seems suspicious, don’t click first and investigate later.
AI-assisted scams may be polished and free of the spelling and grammar mistakes that once made phishing easier to recognize. Deepfake technology can also be used to impersonate business leaders, vendors and other trusted individuals.
That doesn’t mean you need to become an expert at spotting a deepfake.
It means your business should have verification procedures that don’t depend entirely on recognizing one.
4. Keep Everything Updated
Software updates aren’t just about getting the newest features. They frequently include security patches designed to address vulnerabilities.
Keep operating systems, browsers, applications and antivirus software current, and enable automatic updates when appropriate.
If your employees work remotely or regularly use public Wi-Fi, make sure they understand your company’s requirements for VPNs and other secure connections. A VPN can help protect information while using an untrusted network, but it isn’t a substitute for MFA, phishing awareness or other security controls.
Be Sure You’re Covered.
Good cybersecurity practices can reduce the likelihood and potential impact of an incident. But no security system is perfect.
That’s where cyber insurance plays an important role.
Cyber policies can address a range of expenses and losses associated with an incident, but coverage varies significantly from policy to policy. And as businesses adopt new technologies and rely more heavily on vendors and cloud-based systems, it’s important to review the policy rather than simply assume last year’s coverage still fits today’s risk.
During your next insurance review, consider asking:
What exactly does our cyber policy cover?
Does it address both the costs of responding to a breach and the financial consequences of an interruption to your business?
How much coverage do we have for business interruption?
If your systems are unavailable for days—or longer—what happens to your income? What about continuing expenses such as payroll, rent, loan payments and other obligations?
What happens if a vendor or cloud provider has a cyber incident?
Your business may not be attacked directly. If a critical technology provider goes down, could your operations be affected?
Are ransomware and cyber extortion covered?
If your systems are encrypted or held hostage, what expenses could the policy respond to? What conditions, limits or sublimits apply?
What about fraudulent payments or social engineering?
A cyberattack doesn’t always look like a locked computer. If an employee is tricked into sending money to a fraudulent account, determine whether and how that exposure is addressed—and whether separate crime coverage or a specific endorsement is involved.
Are there specific security requirements in the policy?
MFA, employee training, backups, endpoint protection and other controls can be important not only for cybersecurity but also for insurance underwriting and coverage. Ask your agent what requirements apply to your particular policy.
Has our business changed since we purchased the policy?
Have you added remote employees? Moved more systems to the cloud? Started using AI tools? Added new locations or vendors? Changed how customers pay you?
Your insurance should reflect the business you operate today, not the business you operated when the policy was originally purchased.
Cybersecurity Is a Team Sport
Improving your organization’s security doesn’t have to begin with an expensive technology overhaul. It can begin with a conversation.
Ask your employees whether they know how to report a suspicious email. Confirm that MFA is turned on. Review who has access to sensitive systems. Make sure software is updated. Establish a second method for verifying unusual payment requests. Work with a third-party cybersecurity training and awareness platform such as knowbe4.com to keep your team informed of the latest best practices.
Then sit down with your insurance advisor and ask whether your cyber coverage still matches your business.
The Bottom Line
Cyber threats will continue to change. But your businesses can change with them—by building good habits, creating clear procedures and regularly reviewing both your security and your insurance protection.
This Cybersecurity Awareness Month, take a few minutes to Be Sure. A safer business starts with steps you can take today.
Reach out to Delmarva’s friendly cyber insurance experts at Deeley Insurance Group. Call or text us today at 410.213.5600.








