Category: Article

  • Holiday Scams: How to Stay Cyber Safe This Christmas

    By J. Mesa

    Christmas is a time for joy and celebration. It is also the busiest season of the year for cybercriminals. More people shop online, more packages are in transit, and more of us are distracted. Scammers plan for it.

    This guide covers the scams you will see this season and how to keep your family and your business safe.

    Why do scams increase during the holidays?

    • More online shopping. More orders mean more chances to slip in a fake confirmation or a fake store.
    • More deliveries. A text about a package feels normal in December.
    • More giving. Generosity makes charity scams and gift card requests effective.
    • Less attention. People rush, travel, and check email on their phones.

    What are the most common holiday scams?

    • Fake delivery notices. A text or email says a package is delayed and asks you to click a link to reschedule or pay a small fee.
    • Fake stores and apps. Copycat websites and apps imitate real retailers to collect card numbers.
    • Phishing from “your bank” or “a retailer.” A message warns of a problem with your order or account and links to a fake login page.
    • Gift card scams. Someone posing as a boss, a relative, or a government agency asks you to buy gift cards and send the codes.
    • Charity scams. Fake charities ask for donations by phone, social media, or email.
    • Holiday e-cards. A greeting card link from a stranger installs malware.
    • Travel deals. Fake listings for flights and rentals take your payment and vanish.

    How do I spot a fake delivery text?

    • You were not expecting it, or it names no retailer
    • The link uses an odd web address
    • It asks for a fee, a card number, or personal details

    Delivery companies do not charge a redelivery fee by text. To check a package, open the retailer’s app or type the carrier’s web address yourself and enter the tracking number from your order confirmation.

    How do I protect myself from phishing?

    Scammers send emails and texts that appear to come from a retailer or a bank and ask for personal information or payment. Some carry a link or attachment that installs malware.

    • Be wary of unsolicited messages
    • Never click links or open attachments from unknown senders
    • Go to the company’s site or app directly to check your account

    How can I tell if a website or app is fake?

    • Check the web address letter by letter. Look for misspellings and extra words.
    • Look for contact details, a return policy, and a physical address.
    • Search the store’s name with the word “scam” or “reviews.”
    • Be suspicious of prices far below every other seller.
    • Download apps only from the official app store, and check the developer’s name.

    The padlock icon and “HTTPS” in the address bar mean your connection to the site is encrypted. They do not prove the site is honest. Scam sites have padlocks too.

    Should I use a VPN for holiday shopping?

    A VPN, or virtual private network, encrypts your internet connection. It helps on public Wi-Fi in airports, hotels, and cafés, where other people share the network. It does not protect you from a fake store or a phishing link. If you have no VPN, use your phone’s mobile data for purchases while you travel.

    What is the safest way to pay online?

    Credit cards and well-known payment services such as PayPal offer fraud protection and a process for disputing charges.

    • Use a credit card in place of a debit card. A fraudulent debit charge takes money straight out of your account.
    • Avoid wire transfers, cash transfer apps, cryptocurrency, and gift cards as payment to a seller you don’t know. Those payments are hard or impossible to reverse.
    • Turn on purchase alerts from your card issuer.

    A seller who insists on one of those hard-to-reverse methods is telling you it is a scam.

    How do gift card scams work?

    Someone contacts you with an urgent story. A “boss” needs gift cards for clients. A “grandchild” is in trouble. A “government office” says you owe a fine. They ask you to buy gift cards and read out the numbers.

    No legitimate business or agency takes payment in gift cards. If a coworker or relative asks, call them on a number you already have.

    How do I check a charity before I donate?

    • Look the charity up on a rating site such as Charity Navigator or the BBB Wise Giving Alliance
    • Confirm its name exactly, since scammers use names close to real ones
    • Donate through the charity’s own website, not a link in a message
    • Pay by credit card, never by gift card or wire

    How do I set up new devices safely?

    New phones, tablets, cameras, and smart speakers arrive as gifts. Before anyone uses them:

    1. Install all updates.
    2. Change any default password.
    3. Turn on a screen lock.
    4. Review privacy settings and app permissions.
    5. For children’s devices, set up parental controls.

    Why should I update my devices before the holidays?

    Attackers target flaws in older software. Updates from your operating system and app vendors fix those flaws. Turn on automatic updates on your computer and phone before the shopping season starts.

    What should I keep off social media?

    Avoid posting your home address, phone number, or travel dates. A photo of your empty living room and a caption about your trip tell a burglar what they need to know. Share the vacation photos when you get home. Use strong, unique passwords for all your accounts as well. Our post on the most hacked passwords explains how to build a good one.

    How can a business stay safe during the holidays?

    Criminals know offices run on skeleton crews in late December.

    • Remind staff about gift card and invoice scams before the break
    • Require a phone call to confirm any payment change
    • Make sure someone is monitoring alerts and knows who to call
    • Check that backups ran before everyone leaves
    • Install pending updates

    What should I do if I get scammed?

    1. Call your bank or card issuer right away and dispute the charge.
    2. Change the password on any account involved.
    3. Report it at reportfraud.ftc.gov and to the FBI at ic3.gov.
    4. If you bought gift cards, contact the card company with the receipt.
    5. Tell your family, so the same scam doesn’t reach them.

    Your next step

    Share this list with the people you will see this holiday, and help older relatives recognize the delivery and gift card scams. Knowing the threats and taking a few precautions lets you enjoy a happy and secure season. If your business wants to prepare its team, Cerberus Cybersecurity offers cybersecurity training. Contact us to learn more.

  • The 5 Most Hacked Passwords (and What to Use Instead)

    The 5 Most Hacked Passwords (and What to Use Instead)

    By J. Mesa

    Attackers don’t break into most accounts. They log in. They take a list of the passwords people use most, try each one against your email or your bank, and move on to the next person. If your password sits on that list, the attack takes seconds and needs no skill.

    This post covers the passwords attackers try first, why they work, and the stronger habit I recommend to every client: the passphrase.

    What are the most common passwords?

    NordPass publishes a yearly study built from millions of passwords exposed in data breaches. In its 2025 report, these five led the United States list:

    1. admin
    2. password
    3. 123456
    4. 12345678
    5. 123456789

    The global list looks much the same, with 123456 in first place. Older favorites such as qwerty, 111111, and abc123 still rank high every year. The names change order. The pattern holds: short, predictable, and typed by millions of people.

    Why do hackers try these passwords first?

    Attackers don’t type guesses by hand. They run software that tests thousands of passwords per second, and that software starts with wordlists built from past breaches. Three common attacks rely on those lists:

    • Dictionary attack. The tool tries every word and common password on a list against one account.
    • Password spraying. The attacker tries one common password, such as Password1, against every employee in a company. One match gives them a way in.
    • Credential stuffing. The attacker takes email and password pairs leaked from one site and tries them on other sites. This works because people reuse passwords.

    A password from the top five fails all three attacks on the first try.

    Is adding a number or symbol enough?

    No. Attackers know the tricks. Their tools swap a for @, add 1 or ! to the end, and capitalize the first letter. Password1! sits at number 16 on the 2025 list.

    A short password full of symbols, such as x7g9@k2!, is also weak. Eight characters is short enough that cracking hardware can work through every combination when a site stores passwords poorly. It is also hard for you to remember, so you write it down or reuse it.

    Length beats complexity. Each character you add multiplies the work an attacker has to do.

    How long should a password be?

    The National Institute of Standards and Technology (NIST) writes the password guidance that most US security standards follow. Its current guidance, SP 800-63B, calls for at least 15 characters on an account protected by a password alone. It also tells organizations to stop requiring mixed character types and to accept long passwords of at least 64 characters.

    Fifteen random characters are hard to remember. Fifteen characters of words are easy. That is the case for a passphrase.

    What is a passphrase, and is it safer than a password?

    A passphrase is a string of several unrelated words. It runs longer than a traditional password, so it resists guessing and brute-force attacks, and you can remember it because you know the words.

    Compare the two. The password x7g9@k2! has 8 characters. The passphrase kadu tasi ayuyu babui has 21.

    That example uses words from Chamorro, my own language. Words from a language other than English make a passphrase stronger, because many attacker wordlists focus on English and on passwords leaked from English-language sites. The phrase means something to me and reads as gibberish to a cracking tool.

    How do I create a strong passphrase?

    1. Pick four or more words that have no connection to each other.
    2. Avoid quotes, song lyrics, and famous examples. If a phrase appears in a book or a movie, it appears in a wordlist.
    3. Mix in a word from another language, a place only you know, or an invented word.
    4. Aim for 15 characters or more.
    5. Use a different passphrase for every important account.

    A personal touch helps you remember it. Keep personal facts out of it. Your pet’s name, your birth year, and your street all show up on your social media, and attackers check there first.

    Do I need to change my password every 90 days?

    No. NIST now tells organizations to stop forcing password changes on a schedule. Forced changes push people toward weak patterns, such as Summer2025 turning into Fall2025. Change a password when you have a reason: a breach notice, a phishing link you clicked, or a shared login after someone leaves the company.

    How do I know if my password was exposed?

    Search your email address at haveibeenpwned.com, a free service that tracks breached accounts. Many password managers and browsers run the same check and warn you about exposed logins. If a password shows up in a breach, change it on that site and on every site where you reused it.

    How do I remember a different passphrase for every account?

    You don’t. Use a password manager. You remember one strong passphrase, and the manager creates and stores a unique password for each account.

    Then turn on multi-factor authentication (MFA) wherever a site offers it. With MFA, a stolen password alone does not open the account.

    What should a small business do about passwords?

    • Set a minimum length of 15 characters and drop the forced 90-day change.
    • Block the common passwords listed above. Most identity systems, including Microsoft 365, can do this.
    • Give every employee a password manager.
    • Require MFA on email, banking, and remote access.
    • Train your team to spot phishing. A passphrase does not help once someone types it into a fake login page.

    What makes a password weak?

    A password is weak when an attacker can predict it. Short length, common words, keyboard patterns such as qwerty, repeated characters, and personal details all make a password easy to predict. Reuse makes a strong password weak too, because one breached site exposes every account that shares it.

    Your next step

    Check your own accounts against the list in this post today. If you run a business and want help writing a password policy or training your team, contact Cerberus Cybersecurity. We put people first, and passwords are a people problem.

    A strong passphrase is your first line of defense. Treat it that way.

  • Is Online Shopping Safe? 9 Tips for Secure Shopping

    By J. Mesa

    Shopping from home is convenient, and most of the time it is safe. The trouble comes from a small number of fake stores, stolen accounts, and scam messages. A few habits protect you from nearly all of them.

    Here are nine tips to help you shop online with confidence, in the holiday season and all year.

    Is online shopping safe?

    Yes, when you buy from retailers you can verify and pay with a method that protects you. The risk rises when you follow a link from an ad or a message, buy from a store you have never heard of, or pay in a way you can’t reverse.

    1. How do I check that a website is secure?

    Look for “HTTPS” at the start of the web address and a lock icon in the address bar. They show that the site encrypts the information you send.

    Encryption is the minimum. Scam sites use HTTPS too, so treat the lock as one check among several.

    2. How do I know an online store is legitimate?

    • Read the web address carefully for misspellings
    • Look for a physical address, a phone number, and a return policy
    • Search the store’s name with “reviews” and “scam”
    • Check how long the site has existed. A store created last month with huge discounts is a warning.
    • Be wary of sites that accept only wire transfers, payment apps, or cryptocurrency

    When in doubt, buy the item from a retailer you already know.

    3. Why should I use strong, unique passwords?

    A store account holds your address, your order history, and often a saved card. If you reuse a password and one site is breached, attackers try that password everywhere.

    Avoid passwords such as “123456” or “password.” Use a password manager to create and store a different password for each account.

    4. Should I turn on two-factor authentication for shopping accounts?

    Yes. Turn it on for your email first, since password resets go there, and then for the retailers and payment services you use most. With two-factor authentication, a stolen password alone does not open the account.

    5. How do I avoid phishing while shopping?

    Scammers send fake order confirmations, shipping notices, and “problem with your payment” alerts.

    • Don’t click links in messages about orders you don’t remember
    • Open the retailer’s app or type its address yourself to check an order
    • Never enter your password or card number on a page you reached from a link

    6. Why does the privacy policy matter?

    A privacy policy tells you what a store collects and who it shares it with. Before you buy from an unfamiliar site, skim it. Avoid stores with no policy or one that is vague about selling your data.

    7. Is a credit card safer than a debit card?

    Yes. In the United States, federal law limits your liability for fraudulent credit card charges, and most issuers set it at zero. You dispute the charge while the bank’s money is at stake.

    A debit card pulls money directly from your bank account. Your protection depends on how fast you report the fraud, and you wait for the money to come back.

    8. Should I save my card on shopping sites?

    Saving a card is convenient, and it means a breach of that store or your account exposes it. Save cards only with retailers you use often and trust. For one-time purchases, check out as a guest. Digital wallets such as Apple Pay and Google Pay add protection, because they give the store a one-time code in place of your card number.

    9. Is it safe to shop on public Wi-Fi?

    Avoid it for purchases. Public networks are shared, and an attacker can set up a fake hotspot. Use your phone’s mobile data or a VPN when you buy something away from home.

    How do I shop safely on social media and marketplaces?

    • Pay through the platform’s checkout, which carries buyer protection
    • Don’t move the conversation or the payment off the platform
    • Be wary of sellers with new accounts and stock photos
    • Meet in a public place for local pickups

    What are the signs of a scam deal?

    • A price far below every other seller
    • A countdown timer pushing you to buy now
    • A request for payment by gift card, wire, or payment app
    • A seller who avoids questions

    If a deal looks too good to be true, it is.

    How do I monitor my accounts after I shop?

    • Turn on transaction alerts from your card issuer
    • Review statements each week during heavy shopping periods
    • Check your credit reports, which are free at annualcreditreport.com
    • Keep order confirmations until the items arrive

    What should I do if I am scammed?

    1. Contact your card issuer and dispute the charge.
    2. Change the password on the affected account.
    3. Report the seller to the platform.
    4. Report the scam at reportfraud.ftc.gov and to the FBI at ic3.gov.
    5. Watch your accounts for more charges.

    Act fast. Disputes have deadlines.

    What if an order never arrives?

    Contact the seller first and keep a record of the conversation. If the seller does not respond or refuses a refund, file a dispute with your card issuer. Card networks allow a dispute for goods that were not delivered, and the issuer will ask for your order confirmation and the messages you exchanged.

    Does my business need to think about this?

    If you sell online, your customers are asking the same questions about you.

    • Use a reputable payment processor and never store card numbers yourself
    • Keep your website and plugins updated
    • Publish a clear privacy policy, return policy, and contact details
    • Follow PCI-DSS, the security standard for businesses that accept cards

    If employees buy for the company, give them a company card with alerts and a simple approval rule.

    Your next step

    Before your next purchase, turn on two-factor authentication for your email and set up transaction alerts on your card. Those two steps catch most problems early. If you run an online store and want to know how well you protect your customers, contact Cerberus Cybersecurity about a risk and compliance assessment.

  • How Much Does a Data Breach Cost a Small Business?

    By J. Mesa

    A cybersecurity breach is expensive, and the cost lasts long after the systems are back on. For a small business, one incident can decide whether the company survives the year.

    This post breaks down what a breach costs, where the money goes, and what lowers the bill.

    How much does a data breach cost a small business?

    Estimates vary with the study and the size of the company.

    • The Hiscox Cyber Readiness Report 2019 put the mean cost of a firm’s largest single cyber incident at just under $200,000, across businesses of all sizes. That figure counts recovery, lost revenue, and lost customers.
    • IBM’s yearly Cost of a Data Breach Report covers organizations of all sizes. It measured a global average of $4.24 million in 2021 and $4.35 million in 2022, and the 2024 report put it at $4.88 million.

    Your number depends on what data you hold, how long you are down, and how prepared you are. A small breach caught early may cost a few thousand dollars. A ransomware attack with no usable backup can cost far more than $200,000.

    What are the direct costs of a breach?

    • Incident response. Forensic investigators and IT specialists to find and remove the attacker
    • System recovery. Rebuilding computers, restoring data, replacing equipment
    • Legal advice. An attorney to guide notification and liability
    • Notification. Letters, a call center, and credit monitoring for the people affected
    • Regulatory fines. Penalties under rules such as HIPAA, the FTC Safeguards Rule, or state privacy laws
    • Card brand penalties. Assessments under PCI-DSS if payment card data was involved
    • Ransom. If you choose to pay, with no guarantee of results

    What are the hidden costs?

    • Downtime. Every hour your systems are down is an hour you can’t sell, bill, or serve customers.
    • Lost customers. People leave a business that loses their data, and they tell others.
    • Damaged reputation. Winning new clients gets harder.
    • Higher insurance premiums. Your cyber policy costs more after a claim.
    • Staff time. Your team spends weeks on recovery in place of their jobs.
    • Lost contracts. Larger clients may drop a vendor after an incident.

    For many small businesses, the downtime and the lost customers cost more than the technical cleanup.

    What makes a breach more expensive?

    • Sensitive data. Stolen card numbers, health records, and Social Security numbers bring notification duties and fines. A breach that touches only internal systems costs less.
    • Slow detection. The longer an attacker stays inside, the more they take.
    • No backups. Without a clean backup you rebuild from nothing or face the ransom.
    • No plan. Decisions made in a panic cost time and money.
    • Compliance gaps. Regulators penalize a business that skipped required safeguards.

    What makes a breach less expensive?

    Studies of breach costs point to the same factors each year.

    • An incident response plan that the team has practiced
    • Employee training, which reduces successful phishing
    • Multi-factor authentication and limited access
    • Encryption of sensitive data
    • Tested backups, kept offline or offsite
    • Fast detection through monitoring and alerts

    Each one shortens the incident or shrinks the amount of data exposed.

    Can a small business survive a breach?

    Many do. The ones that recover have backups, a plan, insurance, and cash reserves to cover the gap. You may have heard a claim that 60 percent of small businesses close within six months of an attack. That number circulates widely, and nobody has produced a study that supports it. The honest answer is that survival depends on preparation.

    Does cyber insurance cover the cost?

    A cyber insurance policy can pay for investigation, legal help, notification, business interruption, and sometimes extortion payments. Before you rely on one, know three things:

    • Insurers require controls such as multi-factor authentication and backups, and they can deny a claim if your application was inaccurate.
    • Policies have limits, deductibles, and exclusions. Read them.
    • Insurance pays bills. It does not restore lost customers.

    How do I estimate my own risk?

    1. List the data you hold and how many people it covers.
    2. Estimate what one day of downtime costs in lost sales and wages.
    3. Ask how long a full restore from backup would take.
    4. Check which laws and contracts apply to your data.
    5. Add the cost of outside help: IT, legal, and notification.

    That rough total shows how much prevention is worth to you.

    How much should a small business spend on cybersecurity?

    No single figure fits every company. Match your spending to your risk. Start with the low-cost basics that prevent the most common attacks, then add assessment and monitoring as your data and your contracts demand.

    Compare the cost of each measure with your estimate above. A password manager and multi-factor authentication cost a few dollars per user per month. A day of downtime costs far more.

    What steps prevent or reduce the cost of a breach?

    1. Use strong, unique passwords with a password manager.
    2. Turn on multi-factor authentication for email, banking, and remote access.
    3. Update software and security systems on a schedule.
    4. Train employees on cybersecurity best practices, and repeat the training.
    5. Back up your data and test the restore.
    6. Encrypt laptops and phones.
    7. Write an incident response plan and keep a printed copy.
    8. Limit the data you keep.
    9. Review your vendors’ security.

    What should I do in the first 24 hours of a breach?

    1. Disconnect affected systems from the network.
    2. Call your IT provider or incident response firm.
    3. Notify your cyber insurer. Many policies require prompt notice.
    4. Call your attorney.
    5. Preserve evidence. Don’t wipe systems before they are examined.
    6. Change passwords from a clean device.
    7. Document every action and the time you took it.

    Fast, orderly action in the first day lowers the final cost more than anything you do afterward.

    Your next step

    The cost of a breach is significant, and most of it is avoidable. Investing in strong cybersecurity measures protects your business from financial and reputational damage. Cerberus Cybersecurity helps small businesses find their gaps with risk and compliance assessments, write practical policies, and train their teams. Contact us to find out where you stand.

  • Black Friday and Cyber Monday Scams: How to Shop Safely

    By J. Mesa

    It’s that time again! Black Friday and Cyber Monday bring some of the best prices of the year. They also bring scammers, who know that shoppers in a hurry check fewer details.

    Here is how to get the deals and keep your money.

    Why do scammers love Black Friday?

    • Shoppers expect big discounts. A fake 80 percent discount looks plausible for one week of the year.
    • Deals have deadlines. Real time limits make fake urgency harder to spot.
    • Inboxes overflow. A scam email hides among hundreds of real promotions.
    • People try new stores. A shopper chasing a deal will buy from a site they have never used.

    What are the most common Black Friday scams?

    • Fake online stores that take payment and send nothing, or send a counterfeit
    • Phishing emails and texts that imitate real retailers
    • Fake order and delivery notices that link to malicious sites
    • Social media ads for products that don’t exist
    • Bogus coupon and gift card offers that collect personal details
    • Counterfeit apps that imitate a retailer’s shopping app

    How do I know a website is secure?

    Before you enter a card number, check that the address starts with “HTTPS” and shows a lock icon. That means the site encrypts what you send.

    The lock does not prove the store is real. Fake stores use encryption too. Use the next section to check the seller.

    How do I spot a fake store?

    • Check the address. Look for misspellings, extra words, or an unusual ending.
    • Look for contact details and a return policy.
    • Search for reviews on independent sites, not only on the store itself.
    • Compare prices. A price far below every competitor is a warning.
    • Check the payment options. A store that takes only wire transfers, payment apps, or cryptocurrency is unsafe.
    • Look at the writing and images. Copied photos and awkward text suggest a quick copy of another site.

    How do I tell a real deal from a fake one?

    If a deal seems too good to be true, it is. Be careful with offers that:

    • Last only minutes and show a countdown timer
    • Ask for personal or financial details before you can “claim” them
    • Arrive by text or direct message from an unknown sender
    • Come through an ad for a store you can’t find elsewhere

    Go to the retailer’s own website by typing its address. If the deal is real, you will find it there.

    How do I protect my accounts?

    Create a strong, unique password for each online account and use a password manager to keep track. Turn on two-factor authentication for your email and your main shopping accounts. Those steps keep a breach at one store from spreading to the rest.

    Should I click links in sale emails and texts?

    Be careful. Scammers copy the design of real promotions. Even when a message comes from a company you shop with, confirm it before you click.

    • Check the sender’s full address
    • Hover over a link to see where it leads
    • Type the store’s address yourself when you are unsure

    What is the safest way to pay?

    • Use a credit card. It gives you the strongest fraud protection and a dispute process.
    • Use a digital wallet such as Apple Pay or Google Pay where a store offers it. The store never receives your card number.
    • Avoid debit cards for online purchases. Fraud takes money straight from your account.
    • Never pay a seller by wire transfer, gift card, or cryptocurrency.

    What should I avoid posting on social media?

    Be careful about what you share during the season.

    • Don’t announce that you are out of town
    • Don’t post photos of expensive new purchases
    • Don’t share order confirmations or tracking numbers

    That information tells burglars and package thieves when and where to look.

    How do I keep my packages safe?

    • Track deliveries and bring packages in the same day
    • Use a pickup locker or ship to your workplace if nobody is home
    • Require a signature for expensive items
    • Ask a neighbor to collect packages when you travel

    How do I shop safely on my phone?

    • Download shopping apps only from the official app store
    • Check the developer’s name and the number of reviews
    • Keep your phone’s software up to date
    • Avoid making purchases on public Wi-Fi. Use mobile data.

    How do I prepare before Black Friday?

    1. Update your computer, phone, and browser.
    2. Turn on two-factor authentication for your email.
    3. Set up transaction alerts with your card issuer.
    4. Make a list of what you want and where you will buy it.
    5. Bookmark those stores, so you don’t need to follow links.

    A plan keeps you from making rushed decisions when the sales start.

    What should I do if I fall for a scam?

    1. Call your card issuer and dispute the charge.
    2. Change the password on any account you used.
    3. Report the scam at reportfraud.ftc.gov and to the FBI at ic3.gov.
    4. Report the fake store or ad to the platform where you found it.
    5. Watch your statements for further charges.

    How should a small business prepare?

    If you sell during the holiday rush, criminals target you too.

    • Update your website, shopping cart, and plugins before the season
    • Watch for unusual orders, such as many small test charges
    • Warn staff about fake supplier invoices and gift card requests
    • Tell customers how you will contact them, so they can spot impostors

    Are buy now, pay later plans safe?

    They are legitimate services, and they carry weaker dispute rights than a credit card in some cases. Read the terms before you use one, and sign up through the retailer’s checkout or the provider’s own app. Scammers send fake “payment overdue” messages in the names of these services, so check your balance in the app, not through a link.

    Your next step

    Bookmark your favorite stores and set up card alerts before the sales begin. With those two steps and the checks above, you protect yourself and your loved ones from scammers this season. Happy shopping! If your business wants its team ready for the holiday rush, contact Cerberus Cybersecurity about our cybersecurity training.

  • How to Secure Your Small Business Online: 10 Expert Tips

    By J. Mesa

    Your online presence is your storefront. Your website, email, domain name, social media, and business listings are how customers find and trust you. An attacker who takes over any one of them can steal from you, pose as you, or shut you down.

    Cyberattacks can bring financial loss, damage to your reputation, and legal penalties. These ten tips protect the accounts and systems your business shows to the world.

    What is an online presence, and why protect it?

    Your online presence includes every account and service that represents your business:

    • Your domain name and website
    • Business email
    • Social media profiles
    • Business listings, such as your Google Business Profile
    • Online banking and payment accounts
    • Cloud storage and business applications

    Each one is a way in. Losing your domain or email account can take the others with it, because password resets flow through them.

    1. How do I create strong passwords for business accounts?

    Weak or easy-to-guess passwords are among the most common ways criminals get into accounts.

    • Use a long, unique password for every account
    • Never reuse a password
    • Use a password manager to create and store them
    • Give each employee their own login. Don’t share accounts.

    2. What is two-factor authentication, and should I use it?

    Two-factor authentication (2FA) adds a second proof of identity at login, such as a code from an app on your phone. With it on, a stolen password is not enough.

    Turn it on for every account that offers it. Start with email, your domain registrar, banking, and social media. An authenticator app or a security key is stronger than a text-message code.

    3. Why do updates matter?

    Criminals exploit flaws in outdated software and devices. Updates fix those flaws.

    • Turn on automatic updates for computers and phones
    • Update your website platform, themes, and plugins
    • Update routers, firewalls, and other network devices
    • Replace equipment that no longer receives security updates

    4. How do I handle emails and attachments safely?

    Phishing emails imitate people and companies you trust.

    • Check the sender’s full email address
    • Don’t click links or download attachments from unknown or unexpected senders
    • Confirm any request for money or a change in payment details by phone
    • Report suspicious messages to your IT contact

    5. How do I know a connection is secure?

    When you open financial accounts or enter personal information, check that the web address begins with “HTTPS” and shows a padlock icon. That means the site encrypts the data you send and receive.

    Your own website needs HTTPS as well. Browsers warn visitors away from sites without it, and search engines favor sites that have it.

    6. How do I monitor my accounts?

    • Review bank and card statements for transactions you don’t recognize
    • Check your business credit reports
    • Turn on login and transaction alerts
    • Look at the login history on your email and social accounts

    If you see something suspicious, contact your bank or card company right away and change the affected passwords.

    7. How do I protect my website?

    • Keep the platform and plugins updated, and remove the ones you don’t use
    • Use strong passwords and 2FA for every administrator
    • Limit the number of administrator accounts
    • Back up the site and store the backup somewhere else
    • Use a web application firewall, which many hosting and DNS providers include

    8. How do I protect my domain name?

    Your domain is the root of your online identity. If someone takes it, they control your website and your email.

    • Turn on 2FA at your domain registrar
    • Turn on the registrar lock, which blocks unauthorized transfers
    • Keep the contact email on the account current
    • Set the domain to renew automatically, so it never lapses

    9. How do I stop criminals from spoofing my email?

    Attackers send email that appears to come from your domain to trick your customers and staff. Three DNS records help prevent it:

    • SPF lists the servers allowed to send mail for your domain
    • DKIM adds a signature that proves a message was not altered
    • DMARC tells receiving mail servers what to do with messages that fail those checks

    Your email provider or IT contact can set these up. A DMARC policy of “quarantine” or “reject” gives the strongest protection.

    10. How do I secure my social media and business listings?

    • Use a unique password and 2FA on every profile
    • Assign roles to staff through the platform’s business tools. Don’t share one login.
    • Remove access when an employee or agency leaves
    • Claim your business listings, so nobody else does
    • Watch for fake profiles that copy your name and logo, and report them

    What should I do if an account is hacked?

    1. Change the password from a clean device.
    2. Sign out of all other sessions.
    3. Turn on 2FA.
    4. Check for changes: forwarding rules, new administrators, new payment details.
    5. Tell customers and partners if the attacker sent messages as you.
    6. Use the platform’s recovery process if you are locked out.
    7. Report fraud to your bank and at ic3.gov.

    How often should I review my online security?

    Review it every quarter. Check who has access, confirm that updates and backups ran, and test that you can recover an account. Review again whenever an employee or vendor leaves.

    Are these steps enough?

    No security measure is foolproof. These practices cut your risk sharply and help keep your business and your customers’ information safe. Businesses that hold regulated data or serve larger clients should add written policies, employee training, and a regular risk assessment.

    What is the most common way a small business loses an account?

    A reused password and no second step at login. An employee uses the same password for a business account and a personal one. The personal site is breached, criminals try the leaked password on the business account, and it works. A password manager and two-factor authentication close that route, which is why they come first on this list.

    Your next step

    Turn on two-factor authentication for your email and your domain registrar today. Those two accounts protect all the others. To see how we can help with your cybersecurity goals, contact us or write to [email protected]. At Cerberus Cybersecurity, we believe in people first.

  • 5 Cybersecurity Mistakes Small Businesses Make (and How to Fix Them)

    By J. Mesa

    Small businesses are frequent targets for cyberattacks, and many fall victim to data breaches and other threats. In my work, the cause is seldom a clever attacker. It is one of five common mistakes.

    This post covers each mistake, why it matters, and how to fix it.

    Why are small businesses targeted?

    • They hold data worth stealing: customer records, payment details, and bank access.
    • They have fewer defenses than large companies.
    • Automated attacks scan the whole internet and don’t care about company size.
    • They connect to larger clients, which makes them a way in.

    An attacker does not need to pick you. Your business only needs an open door.

    Mistake 1: Failing to update software and security systems

    Criminals look for flaws in outdated software. If your systems are behind, you are open to attacks that a free update would have blocked.

    How to fix it:

    • Turn on automatic updates on every computer and phone
    • Check for updates to servers, firewalls, routers, and business applications each month
    • Plan a time to install updates that need a restart
    • Replace software and devices the vendor no longer supports

    Mistake 2: Using weak passwords

    Weak passwords are easy to guess, and an attacker with access to one account can do a great deal of damage. Reused passwords are just as risky, because a breach at one site exposes every account that shares the password.

    How to fix it:

    • Use a long, unique password for every account and system
    • Give staff a password manager
    • Turn on multi-factor authentication for email, banking, and remote access
    • Change a password when there is a sign it was exposed. Current guidance from NIST no longer recommends forced changes on a fixed schedule.

    Mistake 3: Neglecting employee training

    Many small businesses give their staff no cybersecurity training. That leaves employees open to phishing and other scams, and most attacks start with a person.

    How to fix it:

    • Train every employee when they join and at least once a year after that
    • Add short refreshers through the year
    • Use real examples of phishing emails
    • Write clear policies for handling suspicious messages and sensitive data
    • Reward reporting. Never punish someone for admitting they clicked.

    Mistake 4: Not backing up data

    Without a recent backup, a ransomware attack or a failed drive can end the business. With one, you recover in hours or days.

    How to fix it:

    • Back up on a schedule, daily for important data
    • Keep a copy somewhere separate from your business systems, so an attacker who gets in can’t reach it
    • Follow the 3-2-1 rule: three copies, two types of storage, one offsite or offline
    • Test a restore every few months

    Mistake 5: Not having a cybersecurity plan

    Many small businesses have no plan. When something goes wrong, they improvise, and that costs time and money.

    How to fix it: Write a short plan that covers:

    • Who is responsible for security
    • How you handle updates and backups
    • How and when you train employees
    • What to do and who to call when an incident happens
    • How you will notify customers if their data is exposed

    One or two pages is enough to start. Review it once a year.

    What other mistakes should I watch for?

    • No multi-factor authentication. It blocks most attacks that use stolen passwords.
    • Too much access. Every employee can see every file, and former staff still have accounts.
    • Believing “we’re too small.” That belief is the reason the other mistakes go unfixed.
    • Leaving it all to the IT provider. Many IT contracts cover support and exclude security. Ask what yours includes.
    • No inventory. You can’t protect devices and accounts you don’t know about.

    How do I know if my business is at risk?

    Answer these questions:

    1. Do all our computers and phones update automatically?
    2. Does every account have a unique password and multi-factor authentication?
    3. Did every employee receive training in the past year?
    4. Did we restore a file from backup in the past three months?
    5. Do we have a written plan with phone numbers on it?

    Each “no” is a gap an attacker can use.

    How much does it cost to fix these mistakes?

    Less than most owners expect. Automatic updates and multi-factor authentication are free with the tools you already own. A password manager and cloud backup cost a few dollars per user each month. Training and a written plan cost time. Compare that with the cost of a week of downtime.

    Where should I start?

    Follow this order. Each step builds on the one before.

    1. Turn on multi-factor authentication for email.
    2. Turn on automatic updates.
    3. Set up backups and test a restore.
    4. Roll out a password manager.
    5. Schedule a training session.
    6. Write your plan.

    Most small businesses can finish the first three in a week.

    Who should be responsible for cybersecurity?

    Name one person. In a small company it is often the owner or the office manager. That person does not need to be technical. They need to make sure the tasks on this list happen and to know who to call for help.

    Do I need outside help?

    You can handle the basics yourself. Consider outside help when you store regulated data such as health or payment information, when a client or insurer asks for proof of your security, or after an incident. An assessment from a security professional shows you the gaps you can’t see from inside.

    How do I keep these fixes from slipping?

    Put them on the calendar. Schedule a monthly 15-minute check that updates and backups ran, a quarterly review of who has access, and a yearly review of the plan and the training. Security fails when it depends on someone remembering.

    Does antivirus fix these mistakes?

    No. Antivirus is useful, and it addresses none of the five. It can’t create a backup, train an employee, or write a plan. Keep it running, and treat it as one layer.

    Your next step

    Small businesses face growing risk, and these five mistakes account for most of it. Update your systems, use strong passwords, train your people, back up your data, and write a plan. Cerberus Cybersecurity can help with training, policy development, and assessments. Contact us to get started.

  • Why Cybersecurity Is Good for Business: 6 Ways It Supports Small Business Success

    By J. Mesa

    Most owners think of cybersecurity as a cost. I’d ask you to see it as part of how a small business succeeds. Your company runs on technology and the internet to operate and to reach customers. That reliance brings risk, and managing the risk well gives you an edge over competitors who ignore it.

    This post lays out the business case.

    Why does cybersecurity matter for a small business?

    Without effective security, a small business faces financial loss, damage to its reputation, and legal penalties. With it, the business keeps running, keeps its customers’ trust, and can take on work that less prepared companies can’t.

    1. How does cybersecurity protect revenue?

    A breach or a ransomware attack stops sales. Staff can’t take orders, send invoices, or reach customer records. Each day offline costs money you don’t get back.

    Security measures reduce the chance of an incident and shorten the outage when one occurs. Protecting customer data and financial records prevents direct theft as well.

    2. How does cybersecurity build customer trust?

    Customers hand you their names, addresses, payment details, and sometimes their health or financial history. They expect you to protect it.

    A business that handles data with care keeps its customers. One that loses data loses them, and word spreads. Trust takes years to build and one incident to damage.

    3. How does cybersecurity keep operations running?

    Security prevents the disruptions that malware and other incidents cause. Updated systems crash less. Tested backups turn a disaster into an inconvenience. A written plan means your team knows what to do when something goes wrong.

    Reliable operations are a form of productivity. Your staff spend their time on customers and none of it on recovery.

    4. Can cybersecurity help me win contracts?

    Yes. Larger companies and government agencies now check the security of their suppliers. Expect to see:

    • Security questionnaires before a contract is signed
    • Requirements to follow a framework or standard
    • Requests for proof of cyber insurance
    • Contract terms about breach notification

    A small business that can answer those questions with confidence wins work that competitors lose. Security becomes a selling point.

    5. Does cybersecurity lower insurance and legal costs?

    Cyber insurers price policies by the controls you have. Multi-factor authentication, backups, and training lower your premium and make you insurable at all.

    Security also keeps you on the right side of the rules that apply to your data:

    • PCI-DSS for businesses that accept payment cards
    • HIPAA for health information
    • GLBA and the FTC Safeguards Rule for financial information
    • State privacy and breach notification laws

    Meeting these rules avoids fines and the legal fees that follow a failure.

    6. How does cybersecurity let me adopt new technology?

    Strong security lets a small business adopt tools such as cloud computing, online payments, remote work, and automation with confidence. You can move fast because you know how to do it safely.

    Businesses that fear technology fall behind. Businesses that adopt it without security get hurt. The ones that do both stay competitive as the market changes.

    Is cybersecurity a cost or an investment?

    It is an investment, and you can measure it. Compare the yearly cost of your security measures with:

    • The revenue you would lose in a week of downtime
    • The cost of notifying every customer of a breach
    • The value of contracts that require proof of security
    • The difference in your insurance premium

    For most small businesses, the basics cost a small fraction of a single incident.

    What does good cybersecurity look like in a small business?

    • Every account has a unique password and multi-factor authentication
    • Devices update automatically
    • Backups run daily and get tested
    • Employees receive training at least once a year
    • Access matches each person’s job
    • A written plan says what to do in an incident
    • Someone owns the responsibility

    None of this needs a security department. It needs attention and follow-through.

    How do I show customers that I take security seriously?

    • Publish a clear privacy policy
    • Use HTTPS on your website
    • Explain how you will contact customers, so they can spot impostors
    • Respond fast and openly if something goes wrong
    • Mention your security practices in proposals

    Customers notice when a business treats their data with respect.

    How does cybersecurity support my employees?

    Training gives staff skills they use at work and at home. Clear rules remove the worry of not knowing what to do with a strange email. A culture that thanks people for reporting problems makes the whole team more confident.

    What does it cost to get started?

    The first steps cost little. Multi-factor authentication and automatic updates are free with the tools you already own. A password manager and cloud backup run a few dollars per user each month. Training and a short written plan take time more than money.

    What mistakes should I avoid?

    • Treating security as a one-time project
    • Buying tools without training the people who use them
    • Assuming your IT provider handles everything
    • Waiting for an incident before you act

    How do I measure whether it is working?

    Track a few simple numbers each quarter:

    • The share of accounts with multi-factor authentication
    • The share of devices that are up to date
    • The date of your last successful backup restore test
    • The share of staff who completed training
    • The number of suspicious emails your team reported

    Rising numbers show a business that is getting harder to attack.

    Where should I start?

    1. Turn on multi-factor authentication for email and banking.
    2. Turn on automatic updates.
    3. Set up and test backups.
    4. Train your team.
    5. Write a one-page incident plan.

    Is my business too small for this to matter?

    No. Attackers automate their work, and their tools test every business they can reach. Size offers no protection. Small companies also have less room to absorb a week of lost sales. The smaller the business, the more one incident matters.

    Your next step

    Cybersecurity protects against threats, keeps operations running, and opens new opportunities. Small businesses that put it in place set themselves up for long-term success. Cerberus Cybersecurity helps with training, policy, and assessments sized for small and mid-sized businesses. Contact us to talk about your goals.

  • Cybersecurity Training for Employees: Why It Matters and What to Teach

    By J. Mesa

    One of the most important steps a small business owner can take against cyber threats is to educate employees. Staff who can recognize phishing and other common tactics reduce the chance that your systems get compromised.

    This guide explains why training matters, what to teach, and how to make it stick.

    Why is employee cybersecurity training important?

    Attackers target people because people are easier to fool than software. An employee who clicks a malicious link or shares a password can undo the best security tools.

    Training turns that weakness into a defense. An employee who spots a suspicious email and reports it protects the whole company.

    What are the benefits of training?

    • A stronger defense. Even with the best security systems and software, attackers get in through employees. Trained staff catch attacks that technology misses.
    • Fewer costly mistakes. A small business faces real risk from an employee who clicks a phishing link or gives a password to the wrong person. Training on best practices prevents those mistakes.
    • Better morale and productivity. Training shows your employees that you value their safety. That supports a positive workplace, and people use the same skills to protect their families.
    • Protection for your customers and your reputation. A breach brings financial loss and lost trust. Staff who know how to protect your systems prevent incidents.

    What topics should training cover?

    1. Phishing and social engineering. How to spot fake emails, texts, and calls, with real examples.
    2. Passwords and multi-factor authentication. How to use a password manager and why the second step matters.
    3. Safe handling of data. What counts as sensitive, where to store it, and how to share it.
    4. Device security. Updates, screen locks, and what to do with a lost phone or laptop.
    5. Safe browsing and downloads. Which sites and files to avoid.
    6. Remote work and travel. Public Wi-Fi, home networks, and working in public places.
    7. Payment and invoice fraud. How to verify a request for money or a change in bank details.
    8. Reporting. Who to tell, how, and how fast.

    Match the topics to each role. Staff who handle money need more on payment fraud. Managers need more on impersonation.

    How often should employees be trained?

    • At hire, before they get access to systems
    • At least once a year for everyone
    • In short refreshers through the year, such as a monthly five-minute tip
    • After any incident or near miss

    One long annual session fades within weeks. Short, frequent lessons keep the habits alive.

    What makes training effective?

    • Keep it short. Ten to twenty minutes per session.
    • Make it relevant. Use examples from your own industry and your own inbox.
    • Make it practical. Show people what to do, not only what to fear.
    • Practice. Simulated phishing emails give staff a safe place to make mistakes.
    • Explain the reason. People follow rules they understand.
    • Include everyone. Owners and executives are frequent targets and need the training most.

    What is a phishing simulation?

    A phishing simulation is a harmless test email that imitates a real attack. It shows who clicks and who reports. Run one every month or quarter, and use the results to guide your next training.

    Never use a simulation to embarrass or punish. Staff who fear blame stop reporting, and silence is what attackers count on.

    How do I build a security culture?

    • Thank people who report suspicious messages, including false alarms
    • Treat an honest mistake as a chance to learn
    • Talk about security in staff meetings
    • Make the safe way the easy way, with tools such as a password manager
    • Lead by example. If the owner skips the rules, so will everyone else.

    Culture decides what people do when nobody is watching.

    How do I measure whether training works?

    • The click rate on simulated phishing emails over time
    • The number of suspicious emails staff report
    • How fast people report after a test or a real attempt
    • Training completion rates
    • The number of incidents caused by human error

    A falling click rate and a rising report rate tell you the training is working.

    Is training required by law or by insurers?

    Often, yes. Standards such as PCI-DSS and HIPAA call for security awareness training. The FTC Safeguards Rule requires it for covered financial businesses. Cyber insurers ask about it on applications, and some clients write it into contracts. Keep records of who completed training and when.

    How much does training cost?

    Costs range from free resources published by CISA and the FTC to paid online platforms and live sessions with a consultant. Compare the price with the cost of one wire fraud or one ransomware incident. Training is among the cheapest protections you can buy.

    What mistakes should I avoid?

    • Running training once and never again
    • Using generic material that has nothing to do with your business
    • Relying on fear
    • Skipping contractors and part-time staff
    • Leaving out the reporting process
    • Treating a completed quiz as proof of changed behavior

    How do I train a remote team?

    • Deliver sessions by video and record them
    • Use short online modules people can complete on their own schedule
    • Cover home network basics, such as router passwords and updates
    • Give remote staff a clear way to report problems outside office hours

    How do I get started?

    1. Pick the three topics that matter most to your business. Phishing belongs on every list.
    2. Schedule a 20-minute session this month.
    3. Set up a simple way to report suspicious messages.
    4. Plan short refreshers for the rest of the year.
    5. Record attendance.

    Who should run the training?

    A trusted manager can deliver the basics with free material from CISA. An outside trainer adds current examples, answers hard questions, and gets attention that an internal memo does not. Many small businesses combine the two: a consultant leads one live session a year, and a manager sends short reminders in between.

    Your next step

    Employee education on cybersecurity is essential to the security and success of your small business. Training and support give your team the means to protect your systems against cybercriminals. Contact us or write to [email protected] to see how our cybersecurity training can meet your goals. At Cerberus Cybersecurity, we believe in people first.

  • How to Write a Small Business Cybersecurity Plan in 7 Steps

    By J. Mesa

    As a small business owner, you protect your company from many threats. You lock the doors, buy insurance, and keep the books in order. Many small businesses skip the same care for cybersecurity.

    Every small business needs a cybersecurity plan to protect its data, its customers, and its bottom line. Without one, you are open to criminals who look for weaknesses to exploit. This guide shows you how to write a plan that works and that you can put in place.

    What is a cybersecurity plan?

    A cybersecurity plan is a written document that states what your business needs to protect, how you protect it, who is responsible, and what you do when an incident occurs. For a small business, a few pages is enough.

    Why does every small business need one?

    • It sets priorities. You spend time and money on your biggest risks first.
    • It prevents panic. In an incident, people follow the plan and don’t improvise.
    • Clients and insurers ask for it. Contracts and policy applications now request proof.
    • Rules require it. The FTC Safeguards Rule, HIPAA, and PCI-DSS all call for a written security program.

    What should the plan include?

    • An inventory of your assets and data
    • Your main risks
    • Policies and procedures
    • The security measures you use
    • A training schedule
    • An incident response section
    • A schedule for review

    The seven steps below build each part.

    Step 1: Identify your assets

    List what you need to protect:

    • Computers, phones, servers, and network equipment
    • Software and online services
    • Customer data, employee records, and financial information
    • Accounts: email, banking, domain, social media

    Note where each item lives and who can access it. You can’t protect what you haven’t listed.

    Step 2: Identify your vulnerabilities and risks

    For each asset, ask three questions:

    1. What could go wrong? Think of theft, ransomware, loss, or an honest mistake.
    2. How likely is it?
    3. How badly would it hurt?

    Rank the results. The items that are both likely and damaging go to the top. A simple high, medium, low scale works.

    Step 3: Develop policies and procedures

    Write short, clear rules for how your business protects its assets. Start with these:

    • Password policy. Unique passwords, a password manager, and multi-factor authentication.
    • Acceptable use. What staff may do on company devices and networks.
    • Access control. Who gets access to what, and how you remove it when someone leaves.
    • Data handling. How you store, share, and dispose of sensitive information.
    • Remote work. Rules for home networks, personal devices, and public Wi-Fi.
    • Vendor management. How you check the companies that hold your data.

    Keep each policy to a page. People follow rules they can read in five minutes.

    Step 4: Implement security measures

    Put the tools in place that carry out your policies:

    • Multi-factor authentication on email, banking, and remote access
    • Automatic updates on all devices
    • A firewall and security software
    • Encryption on laptops and phones
    • Backups that follow the 3-2-1 rule: three copies, two types of storage, one offsite
    • Email filtering

    Start with the measures that address your top-ranked risks.

    Step 5: Train your employees

    Your plan depends on the people who follow it.

    • Train every employee when they join and at least once a year
    • Teach them to recognize phishing and other common scams
    • Explain each policy and the reason for it
    • Make reporting simple and free of blame

    Step 6: Plan your incident response

    Decide now what you will do when something goes wrong. Write down:

    • Who leads the response
    • Who to call: IT provider, cyber insurer, attorney, bank
    • How to isolate affected systems
    • How to reach staff if email is down
    • How and when you notify customers and regulators
    • Where the backups are and how to restore them

    Print this section. You can’t open a file on a locked computer.

    Step 7: Monitor and update the plan

    A cybersecurity plan is a living document. Review it:

    • Once a year
    • After any incident or near miss
    • When you add a new system, vendor, or location
    • When laws or contract requirements change

    Check each quarter that the measures in the plan are still running: updates, backups, and access reviews.

    How long should the plan be?

    For a business with fewer than 50 people, five to ten pages covers it. A short plan that people use beats a long one that sits in a drawer.

    Who should write it?

    The owner or a senior manager should own it, with input from whoever handles IT. A cybersecurity consultant can speed the work and bring experience from other businesses. The plan must reflect how your company operates, so someone inside has to be involved.

    What frameworks can I use as a guide?

    You don’t need to start from a blank page.

    • NIST Cybersecurity Framework. A widely used structure built around identifying, protecting, detecting, responding, and recovering.
    • CIS Critical Security Controls. A prioritized list of safeguards, with a starter group suited to small organizations.
    • FTC guidance for small business. Plain-language guides at ftc.gov.

    Pick one and adapt it to your size.

    What mistakes should I avoid?

    • Copying a template without changing it to fit your business
    • Writing the plan and never testing it
    • Leaving out the incident response section
    • Forgetting vendors and cloud services
    • Assigning no owner

    How do I test the plan?

    Run a tabletop exercise once a year. Gather the people named in the plan, describe a realistic incident, and walk through each step. You will find missing phone numbers and unclear roles. Fix them while the stakes are low.

    Is a cybersecurity plan the same as an incident response plan?

    No. The incident response plan is one section of the larger document. The cybersecurity plan covers prevention, training, and review as well as response. A business needs both, and writing the full plan produces the response section along the way.

    Your next step

    Start with Step 1 this week. List your assets and data on a single page. Following these seven steps gives you a plan that protects your small business from the growing threat of cyberattacks. Don’t wait until it’s too late. Cerberus Cybersecurity offers policy and documentation development to help you write a plan that fits. Contact us or write to [email protected].