It's Cyber Security Awareness Month: Have You Got the Basics Covered?
Posted by: Richard Barnett
October is Cyber Security Awareness Month, the annual push to get individuals and businesses thinking about the basics of staying safe online. It's easy to skip past campaigns like this as background noise, but the government's own figures make the case for paying attention. In its latest Cyber Security Breaches Survey, 42% of micro businesses and 46% of small businesses said they'd identified a cyber security breach or attack in the past 12 months.
It's rarely anything sophisticated
When those businesses were breached, the cause was overwhelmingly ordinary. Phishing remains by far the most common attack type, now accounting for 51% of all breaches reported. That's not a nation state hacking group exploiting a zero day vulnerability. It's someone clicking a convincing email, or a login being guessed, reused, or lifted from a data breach somewhere else entirely.
The practical upshot is reassuring, in a way. Most small businesses don't need to defend against sophisticated attacks. They need to close off the obvious gaps, the kind that take an afternoon to sort out rather than a security budget.
Passwords and the login nobody remembers exists
Every website has more logins behind it than most people realise: the CMS admin, the hosting control panel, the domain registrar, email, any third party plugins or booking systems. It's common for these to share a password, or for that password to have been set years ago and never changed.
Two factor authentication closes off most of the risk here, but take up is still patchy. Only 43% of micro businesses currently have it in place, even though it's usually a free toggle sitting in the account settings. If you haven't checked, it's worth going through your CMS, hosting panel, domain registrar, and email account and turning it on wherever it's offered, alongside a proper password manager so nothing's reused across systems.
Backups you've never actually tested
Most businesses do have backups in some form. The gap isn't whether a backup exists, it's whether anyone has ever tried restoring from one. A backup that silently stopped running three months ago, or one that turns out to be corrupted, is only discovered at the worst possible moment. A quick test restore once or twice a year is worth far more than trusting that the backup job is quietly working in the background.
Who still has access
Staff leave, agencies change, plugins get abandoned, but the accounts they used rarely get removed at the same time. It's worth a periodic look at who actually has admin access to your website, hosting account, and domain registrar, and removing anyone who shouldn't still be there. It's a five minute check that closes off a surprising amount of risk.
How J&L Digital can help
Awareness Month is really just a prompt to do the housekeeping that's easy to put off. As part of how we manage hosting and maintenance for clients, we review access, authentication, and backup practices as standard, so these gaps get caught before they become a problem rather than after.
J&L Digital, based in Redhill, Surrey, specialises in comprehensive technology solutions including website design, software development, IT services, and digital marketing. Contact us to talk through how we can help keep your systems secure.
Source: Cyber Security Breaches Survey 2025/2026, UK Government (Department for Science, Innovation and Technology).