
The fourth quarter is consistently the highest-risk cybersecurity quarter for U.S. small businesses. Attackers know that decision-makers are distracted, IT teams are short-staffed, and the financial pressure of the holiday season makes urgent-sounding fraud easier to fall for.
If you run a Houston small business, the four weeks between now and the end of October are the right window to tighten the basics. Here are the five we’d prioritize.
1. MFA on every account, with no "temporary" exceptions
Audit MFA enrollment for every user. Often there are accounts that quietly never got enrolled — owner accounts, service accounts, shared mailboxes. Each one is a foothold waiting to be exploited.
If your platform offers conditional access, set the policy so unmanaged devices logging in from unfamiliar geographies (e.g., outside the US) face additional friction.
2. Backup test-restore — for real, on calendar
The single highest-leverage test you can run before year-end: pick a critical file, delete it, restore it from backup, time how long it took, document the result. If you couldn’t actually do it, the time to find out is now.
Run the same test against your Microsoft 365 backup. Most Houston small businesses have never test-restored an email from M365 in their lives. The 30 minutes it takes to verify is worth more than the next month of insurance premium.
3. Vendor payment verification rules
Q4 is peak BEC (business email compromise) season. Attackers know vendors are sending year-end invoices and businesses are rushing to close the books.
One paragraph emailed to your accounts payable team this week:
"Effective immediately: any request to change vendor banking information, regardless of source, requires verbal confirmation via a previously-known phone number for that vendor before the change is processed. Reply-to-email confirmation is not acceptable. No exceptions, no exceptions for urgency."
That single rule, enforced, blocks the majority of BEC fraud.
4. Patch the laggards
Run a real patch report. Find the machines that are behind. Get them current. Pay special attention to:
- Browsers (Chrome, Edge, Firefox)
- PDF viewers (Adobe, Foxit)
- Microsoft Office
- Operating system itself
- Any niche line-of-business application
If a machine can’t be patched (legacy app, hardware too old), it shouldn’t be on the general network. Move it to a segmented VLAN.
5. Out-of-office and travel access review
Q4 = holiday travel. Verify:
- Out-of-office auto-replies don’t reveal more than they should (no detailed travel dates, no "contact my CFO at…" that gives attackers a target).
- Owners and executives aren’t using personal devices to check email from countries where they wouldn’t normally log in (which can trigger account locks at the worst possible moment, or look like compromise).
- Anyone leaving the company in Q4 has access cleanly removed within 24 hours of their last day.
What about new threats?
The five above will block more attacks than any new tool you could buy. Foundations first.
If you want a no-pressure walkthrough of where your business stands going into Q4, book a free discovery call. We’ll spot the gaps in 15 minutes.
Aspendora Technologies has provided cybersecurity and managed IT to Houston-area small businesses since 2010.
