October is Cybersecurity Awareness Month — a national initiative led by CISA and the National Cybersecurity Alliance since 2004. It’s a useful prompt: plenty of small businesses know they should be doing more on security but never block the time.

Here’s a 4-week plan you can run yourself, designed for a Houston small business owner without a dedicated security team. One hour per week, real impact.

Week 1 (Oct 5-11): Identity

This week’s focus: stop unauthorized account access.

  • Audit MFA. Pull a list of every account that has access to email, file storage, and remote access. Verify MFA is enrolled and required on every one. Common gaps: owner accounts, service accounts, shared mailboxes, vendors with delegated access.
  • Roll out a password manager. If your team doesn’t have one, pick a business password manager and get every employee onboarded by the end of the week.
  • Review who has admin rights. Many Houston small businesses we audit have admin scattered across people who haven’t needed it in years. Trim it back to the minimum.

Week 2 (Oct 12-18): Email

This week’s focus: stop phishing from working.

  • Verify email filtering is in place and current. If you’re on Microsoft 365 or Google Workspace, the built-in filters are decent but require configuration. An advanced email-security layer — Microsoft’s Defender for Office 365 Plan 1, Google Workspace’s advanced protections, or a dedicated email security service — is the minimum.
  • Run a phishing simulation. Even a basic one (Microsoft 365’s built-in Attack Simulation Training if your license includes it, or a phishing-simulation platform) gives you a baseline.
  • Install a one-click report button. Every employee should be able to forward a suspicious email with one click.
  • Check your SPF, DKIM, DMARC records. Use a free online DMARC lookup tool to scan. Move DMARC policy to at least "quarantine" if it’s currently "none."

Week 3 (Oct 19-25): Endpoint and Backup

This week’s focus: limit damage if something does get through.

  • Verify EDR coverage. Every laptop, every server. If you’re still on traditional antivirus, this is the week to upgrade.
  • Patch. Run a real patch report. Get the laggards current.
  • Test restore from backup. Pick a file, delete it (or pretend to), restore it. Time it. Document it.
  • Verify M365 is backed up outside Microsoft. The native retention is not backup.

Week 4 (Oct 26-31): Response and people

This week’s focus: be ready if something happens.

  • Write or refresh your incident response plan. One page. Who calls the insurer? Who calls the lawyer? Who calls the IT provider? What’s the first 60 minutes?
  • Verify cyber insurance is current. Read the actual policy. Note coverage limits, deductibles, exclusions, and the 24-hour claim number.
  • Talk to your team. Spend 30 minutes in your next staff meeting on cybersecurity. What to do if you suspect a phishing email. What to do if a device feels "off." Who to call.
  • Plan your 2027 cybersecurity budget. What gaps did you find this month? What’s it cost to close them?

If you’d rather have someone run it for you

This plan is genuinely doable as a small business owner. It’s also the kind of thing that gets put on the calendar and then never happens because something more urgent shows up.

For our managed IT services clients, all four of these weeks are baked into ongoing operations — you don’t have to think about it. If you’d like to talk about that model, book a free discovery call.

Aspendora Technologies provides cybersecurity, managed IT, and IT consulting to Houston-area small businesses since 2010.