Marking Cyber Security Awareness Month With Practical Advice From the People Protecting Organisations Every Day

Cyber Security Awareness Month is here, and this year’s theme from the National Cybersecurity Alliance is ‘Don’t Make It Easy for Them’. It’s a good line, and a better principle. Most successful attacks don’t hinge on sophisticated exploits, they hinge on the small doors organisations leave open. This October, I asked each member of the CyberLab leadership team for one thing UK businesses should be doing to close those doors. Here are their nine tips.

The picture in 2026 is not softening. Ransomware payments have shifted, but recovery costs are up. AI is compressing the time attackers need to move through a network. The UK Cyber Security and Resilience Bill is bringing new obligations for supply-chain risk and incident reporting. And the gap between the businesses that recover quickly from an attack and the ones that spend months catching up is almost always down to what was done before the attack, not during it.

Nine tips, one from each of us, in the order I’d take action on them.


1. Make Cyber a Board Discipline

My tip, and the one I’d start with, is to make cyber security a proper board discipline.

If cyber security sits below the top three risks on your board agenda, you are already exposed. The threat trajectory, the regulatory shift, and the operational cost of a serious incident all point in the same direction. Boards that treat cyber as an operational line item, rather than a strategic risk, keep being surprised by what shows up on their doorstep.

Two things belong on the board pack every month. An honest read of your organisation’s cyber security exposure. And a plan that stands up to the pace the threat landscape is moving at. Both need to be in a language non-technical directors can act on.

The businesses I speak to that have made this shift are the ones already treating cyber testing, board reporting and incident readiness as standing agenda items. If you’re still bolting it onto the end of an operations update, that’s a change worth making this Cyber Security Awareness Month.

2. Get Cyber Essentials Certified

Sandra’s tip goes to the baseline that closes the door on most of what actually lands.

Cyber Essentials is the UK’s government-backed baseline set of controls. It covers multi-factor authentication, secure configuration, patching, malware protection and access management, the five areas that show up in most breaches. If you meet the standard, most opportunistic attackers move on to a softer target.

Two things are worth acting on this month. If you already hold Cyber Essentials on the old Willow question set, you have until 26 October to complete your renewal before it retires. Miss it, and your next assessment moves to Danzell, which is tighter across MFA, cloud, and board-level compliance declarations.

If you’re not certified yet, use October as the deadline you needed. As an IASME-approved certification body, CyberLab has issued over 1,500 Cyber Essentials and Cyber Essentials Plus certificates to UK organisations. The process is faster than most compliance leads expect.

Sandra Lovell-Struthers, Head of Quality & Compliance
Get Cyber Essentials Certified

3. Read Your Cyber Insurance Policy

Tom’s tip is the one most CFOs regret not taking sooner.

The policy you think you have is not always the cover you actually have. War and nation-state exclusions are broader than most policyholders realise. Known, unpatched vulnerabilities are frequently cited as grounds for claim rejection. Failure to maintain the security controls stated at renewal can void a claim mid-incident.

There is also a direct financial upside to documented controls. UK SMEs in the £1m to £10m revenue bracket see cyber insurance premiums range from £1,500 to £9,000, and the gap is largely explained by what a business can evidence. MFA, EDR, patching cadence, incident response readiness. If you can prove the controls, your premium goes down. If you can’t, they don’t count at renewal.

Cyber insurance is a financial discipline, not a purchase. On 7 October, CyberLab is hosting a webinar with Beazley and Capsule Insurance to unpack how insurers actually respond when a claim comes in.

Tom Davies, CFO
Register for the Webinar

4. Pen Test Your External Attack Surface

Wayne sees the pattern across every UK organisation CyberLab tests.

We deliver over 14,000 hours of penetration testing every year, and the finding is the same. What attackers can see is often not what internal teams think they can see. Old subdomains still resolve. Forgotten dev environments still respond. Third-party services return more than they should. The controls sit inside the perimeter. The exposure sits outside it.

If you have not tested your external attack surface in the last twelve months, you are not testing recently enough. Threats and exposed assets change faster than an annual scan can catch. Continuous external testing, or at minimum a full annual pen test paired with monthly automated attack surface monitoring, gives you the same view the attacker has.

CyberLab is CREST and CHECK accredited, and every consultant on the pen testing team holds those credentials personally. Testing where the attacker looks, not where you’re comfortable, changes what you find.

Wayne Price, Commercial Director
Learn about Pen Testing

5. Automate Your Patching

Jim’s tip is the boring one that stops most of what actually lands.

Exploited vulnerabilities remain the top technical root cause of ransomware attacks in the UK, per the Sophos State of Ransomware 2026 report. And most of the time, the fix already existed. Nobody applied it in time.

Manual patching does not scale. Between the CVEs published each week, the third-party libraries, the shadow assets nobody remembers, and the operational risk of applying patches without testing, keeping up by hand is a losing game. Automated patch management closes the window between disclosure and exposure, and it removes the single point of failure that a manual process depends on: a human remembering.

If your patching cadence relies on a person remembering to apply Tuesday’s Windows updates on Wednesday, that cadence is not fast enough for the threat landscape you’re operating in. Tools like Vicarius vRx run vulnerability discovery, prioritisation and remediation continuously.

Jim Strongitharm, Technical Services Manager
Learn About Vicarius vRx

6. MFA on Every Account That Needs It

Chris hears the same pattern in new-business conversations, again and again.

Organisations say they have multi-factor authentication. What they mean is they have MFA on some accounts. Admin accounts, sometimes. Legacy systems, rarely. Service accounts, almost never. Third-party integrations, forgotten.

Compromised credentials remain one of the top root causes of ransomware attacks affecting UK businesses. If MFA is on every account that touches your data, the credential doesn’t get the attacker in. If it’s on some accounts, they walk around the ones without it.

Audit where MFA is enabled, and where it isn’t. Every SaaS platform, every legacy application, every service account, every integration. The gap is where the risk lives, and it’s usually much wider than IT teams initially think. Cyber Essentials Danzell now makes not enabling MFA where it’s available an automatic fail, which is a good forcing function for organisations still auditing their coverage.

Chris Workman, Head of Sales
Learn about Strong Authentication

7. See What an Attacker Sees

Ric’s tip picks up where Wayne’s ends, on the continuous side.

Most security tools look inward. They monitor what’s inside your network, your identity system, your endpoints. All of that matters. But it doesn’t show you what an attacker actually sees when they look at your business from the outside, which is where their reconnaissance starts.

Exposed subdomains. Leaked credentials on the dark web. Certificates expiring on public services. Third-party services you no longer remember exposing you. Continuous outside-in monitoring closes that gap. Not an annual snapshot. Every night. So when something changes on your perimeter, you know before the attacker does.

HackRisk is CyberLab’s continuous outside-in attack surface monitoring product, and it now brings dark web scanning, vulnerability scanning, reconnaissance and asset discovery, supply chain risk, and phishing simulation and awareness training into one platform. AI-generated remediation guidance means users get actionable next steps, not just a CVE number.

Ric Wainwright, AI and Product Director
Get Free HackRisk Report

8. Tabletop Your Incident Response

Adam takes a lot of calls from prospects who’ve just had an incident. They always start the same way.

“We didn’t think it would happen to us. And then, we didn’t know what to do first.”

Tabletop exercises are the calm before the crisis. They walk your board and your response team through a realistic scenario. One hour. No systems down. And they surface every gap in your plan. Who calls the ICO. Who talks to customers. Who decides whether to pay a ransom. Who’s on holiday. Which supplier holds the backup. Whether your incident response retainer covers what you think it covers.

The businesses that recover fastest from a cyber incident are almost always the ones that practised. The ones that spend weeks catching up are the ones who assumed a plan on paper was enough. A tabletop exercise costs a few hours of leadership time and pays back in every hour of downtime it prevents.

Adam Myers, Sales Director
Book a Tabletop Exercise

9. Train Your People Like You Train Your Systems

Mimi’s tip is the one that quietly changes the odds most.

Culture isn’t a poster on the wall, and cyber security isn’t a policy in a folder. Both are built by the same thing. Small, consistent actions, taken by people who understand why.

Phishing simulations. Security awareness training. Making it easy for someone to flag a suspicious email without feeling silly. Repeating the training often enough that it becomes muscle memory, not a once-a-year tick-box. These are the daily habits that turn the biggest attack surface, your people, into the strongest one.

At CyberLab, cyber security awareness is part of how we work, not something we wheel out in October. It’s built into onboarding, refreshed monthly, and reinforced through simulated phishing that treats being caught as a learning moment, not a punishment. The result is a team that flags suspicious activity because it’s easy to, not because they’ve been told they have to.

Mimi Rostron, People and Culture Manager
Train Your People with HackRisk

How CyberLab Supports Cyber Security Awareness Month

Cyber Security Awareness Month is a month, but the tips above are a year-round discipline. CyberLab supports UK organisations across every one of them.

Get Started