The One Piece Of Cybersecurity Advice Every Business Should Follow? Experts Weigh In

October is Cybersecurity Awareness Month, the annual reminder for businesses of every size to take a second look at their security habits. Every year it brings a wave of reminders, guides and checklists, and every year most of them cover much of the same ground.

The NCSC says four in 10 UK businesses reported a cyberattack in the previous 12 months, and it points out that small businesses shouldn’t assume they’re too small to be targeted. The threats range from fake invoices and weak passwords to AI-written messages that sound like they came from someone you know.

The reality of exposure hit home this week. Customers opening the ASOS app on 6 October were met with an “ASOS HACKED” notification. ASOS confirmed an investigation into unauthorised third-party activity that may have exposed names and contact details. However, the retailer stated that payment card data and account passwords were unaffected.

 

Smaller Teams, Longer To-Do Lists

 

The incident shows how much of a modern business is now outside its own walls. The attackers’ claim about a cloud data platform hasn’t been verified, and the provider says it hasn’t found a compromise of its own platform.

Smaller teams feel that pressure more acutely than others. A young enterprise adopts cloud utilities, payment processors, shared credentials, freelance contractors and AI assistants capable of reading internal files long before anyone is hired to manage that architecture. The digital risk inventory grows, but the headcount available to handle it remains tiny.

We put one question to CISOs, consultants, IT leaders, trainers and founders: what’s the one action every business should put first this Cybersecurity Awareness Month, and why?

 

 

Our Experts

 

  • Harvey Dhillon, Founder and CEO, Zmartly
  • Sarah Bone, Co-Founder, YEO Messaging
  • Mary Ann Miller, VP, Fraud Executive Advisor, Prove
  • Nic Sarginson, Principal Product Manager, Yubico
  • Jackson Schultz, Co-Founder and CEO, ArgusEye
  • Evgenii Arsentev, CEO, AskDocDoc
  • Khushboo Kashyap, Senior Director of Governance, Risk and Compliance, Vanta
  • Ray Heffer, Field CISO, Veeam
  • Lianne Potter, Chief AI Security and Ethics Officer, Northstar Intelligence
  • Kim Larsen, Group Chief Information Security Officer, Keepit
  • Jon Lucas, Co-Founder and Director, Hyve Managed Hosting
  • Paul Speciale, Chief Marketing Officer, Scality
  • Cheryl Martin, Head of Cyber, C86
  • Simon Lawrence, Co-Founder and CEO, i-Confidential
  • Tim Williams, CEO, Quod Orbis

 

Harvey Dhillon, Founder and CEO, Zmartly

 

Harvey Dhillon, Founder and CEO, Zmartly

 

“My one tip: never change a supplier’s bank details because of an email. Phone the supplier on a number you already hold, not one in the message, and confirm the change before a single payment goes out. I chose it over everything else because the attack it stops needs no hacking skill and costs real money in one go.

“A convincing email asking you to update payment details, sent at a busy moment, is enough. Passwords and software updates matter, but this is the one where a two-minute call protects the bank balance directly. Write it down as a rule, make it apply to everyone including the owner, and never let urgency in the email be a reason to skip it.”

 

Sarah Bone, Co-Founder, YEO Messaging

 

Sarah Bone, Co-Founder, YEO Messaging

 

“If I could give founders building amazing apps and solutions one piece of advice to change a security habit this October, it would be to stop treating an initial successful login as proof that the right person is still in charge throughout the interaction.

“I’d choose this over the usual advice because the usual advice is already well known. Strong passwords, multi-factor authentication and phishing training still matter, but they all check identity once, at the door. Attackers have adapted. More of them now target what happens next: hijacked sessions, compromised devices and AI-generated voices and messages that pass for a colleague or supplier. Once someone is in, most systems simply carry on trusting them.

“For a small team, that is where the damage happens. One compromised account can expose customer data, redirect a payment or leak a confidential document, and there is rarely a security team to spot it.

“A login only shows who arrived. Cybersecurity depends on knowing who stayed.”

 

Mary Ann Miller, VP, Fraud Executive Advisor, Prove

 

Mary Ann Miller, VP, Fraud Executive Advisor, Prove

 

“The one piece of advice I would give is to stop treating identity verification as a one-point-in-time checkpoint at login. Establishing trust at login or onboarding is no longer enough. Fraudsters are continuing to get more sophisticated and use stolen credentials, social engineering and AI-powered impersonation to bypass traditional security measures.

“Businesses need to take a more continuous approach to identity and trust, verifying that the person or entity behind an interaction is legitimate throughout the entire customer journey. This means moving beyond passwords and static credentials and incorporating stronger identity multi-signal and risk-based authentication at critical moments, such as account changes, high-value transactions or requests to access sensitive information.

“The goal isn’t to create more friction for customers, but to make smarter decisions about when additional verification is necessary. As threats continue to evolve and become harder to detect, businesses must recognise that trust isn’t established once. It needs to be continuously maintained before it’s too late.”

 

Nic Sarginson, Principal Product Manager, Yubico

 

Nic Sarginson, Principal Product Manager, Yubico

 

“With 81% of hacking-related breaches stemming from weak or reused passwords, it is clear that passwords are an out-of-date and fundamentally flawed method of security designed for an Internet not prepared for the cyber attacks of today. Despite this, Yubico’s 2026 Global State of Authentication survey found that an alarming 43% of respondents continue to rely on passwords at work.

“Rather than requiring employees to remember a password – which can easily be forgotten, stolen or phished – businesses should opt for passkeys which link a public and secure private cryptographic key pair to authenticate. In its most secure form, a hardware-backed passkey is stored on a local device like a physical hardware security key. It proves intent of authentication by requiring a user’s physical touch of the key registered to the account. This means hardware-bound keys cannot be remotely extracted, synced across unauthorised devices or accessed even if a user’s cloud account is compromised.

“Additionally, embracing modern authentication helps ensure compliance with evolving regulations like PCI DSS 4.0 and NIS2 – helping businesses on their journey to true cyber resilience.”

 

Jackson Schultz, Co-Founder and CEO, ArgusEye

 

Jackson Schultz, Co-Founder and CEO, ArgusEye

 

“The primary advice I’d give businesses is to treat technical severity as a starting point for understanding risk, not the final answer.

“Cybersecurity teams have long relied on vulnerability severity to decide where to prioritise their attention. But as software becomes more embedded in systems and devices that interact with the physical world on a daily basis, technical severity alone doesn’t always reflect the full risk level. A vulnerability that appears critical on its own may pose limited risk in the real world, while a seemingly less severe one could seriously disrupt operations, damage equipment or even cause people physical harm.

“Organisations need visibility into how devices and software are connected, what an attacker could potentially access through those connections and what those systems ultimately control. Securing each component individually doesn’t necessarily mean the broader system is secure – especially when connections between them can create hidden attack paths.

“For example, a flaw in two identical devices might have the same level of technical severity, but if one sits at the edge of an isolated system while the other presents a possible point of entry to interfere with critical systems, like those controlling water treatment facilities, addressing them equally misses a fundamental part of the risk.

“The goal shouldn’t simply be to find and fix more vulnerabilities, but to understand which ones could cause the most harm based on where they’re situated in a system, the attack paths they could create and the potential real-world consequences.”

 

Evgenii Arsentev, CEO, AskDocDoc

 

Evgenii Arsentev, CEO, AskDocDoc

 

“I’m a medical doctor by education and CEO of AskDocDoc (telehealth). Not a security specialist at all, but in our company AI agents work on the live server, and something small breaks almost every day.

“My one advice: treat an AI agent like a new employee account, with access for one task. When the task is done, we take the access back.
“And the logs – the agent can’t edit them, so a person reads them afterwards. Logins to our accounts on other platforms are done by a human, not by the agent.

“Our chatbot was once down for 3 days and nobody noticed.”

 

Khushboo Kashyap, Senior Director of Governance, Risk and Compliance, Vanta

 

Khushboo Kashyap, Senior Director of Governance, Risk and Compliance, Vanta

 

“Every Cybersecurity Awareness Month, I see the same advice: train your people, patch your systems, rotate your passwords. All still true. But the state of cybersecurity in 2026 is defined by something that advice doesn’t touch: AI is being adopted faster than anyone can govern it. Shadow AI – unsanctioned AI use inside organisations – is already present in 70% of companies, and most security teams can’t tell you in real time what data those tools are touching or where the risk sits.

“Organisations know this. Vanta’s data shows a 26x rise in AI security job titles since 2023 – AI Governance Lead, AI Security Architect, roles that didn’t exist three years ago. We’ve watched this movie before with security and privacy: new technology creates new risk, and ownership eventually formalises around it. AI is following the same arc, just compressed.

“But a job title isn’t a control. If your AI governance plan is ‘wait until we hire someone,’ you’ve already lost the race you’re in. Start with visibility: inventory every AI system in your environment – the ones you deployed deliberately, the models embedded in your SaaS stack and the ones your employees adopted without asking. Then put guardrails where the risk actually concentrates, and revisit them as the technology moves, because it will.

“The goal isn’t to slow AI down. It’s to make the approved path easier than the shadow one – so managing AI risk is easy for your people and hard for risk to take hold.”

 

Ray Heffer, Field CISO, Veeam

 

Ray Heffer, Field CISO, Veeam

 

“Cybersecurity Awareness Month should serve as a catalyst for turning security fundamentals into operational discipline. Organisations need to enforce the basics: strong authentication, phishing awareness, timely patching, least-privilege access and tested recovery.

“With the use of AI, that discipline must extend to clear visibility into where data lives, how it flows, who or what can access it, including AI agents, and whether clean, trusted data can be recovered when something goes wrong. Cyber resilience gives the business the confidence to say ‘yes’ safely, prove trust and keep moving.”

 

Lianne Potter, Chief AI Security and Ethics Officer, Northstar Intelligence

 

Lianne Potter, Chief AI Security and Ethics Officer, Northstar Intelligence

 

“My Tip: Stop confusing awareness with behaviour change.

“Every Cybersecurity Awareness Month, businesses are reminded to use strong passwords, spot phishing emails and keep their software up to date. All sensible advice. But telling people what they should do and changing what they actually do are two very different things (and if your security awareness efforts only make an appearance once a year, you might want to ask yourself how much awareness you’re actually raising!).

“There is a gap between what people know and how they behave. People don’t make decisions in a vacuum. They work under pressure, deal with competing priorities, follow the habits of their colleagues and find ways around processes that make their jobs harder. You can run all the security awareness training you like, but if your staff are so busy that they don’t have time to report a suspicious email, or your security processes are so cumbersome that people find workarounds, the problem isn’t necessarily a lack of awareness. It’s how the organisation works.

“My advice to every business is to pick one risky behaviour and work out why it happens before trying to fix it. Talk to your people. Look at the pressures they’re under. Make the secure option the easiest, most practical option, and give people a straightforward way to ask for help when something doesn’t look right. Then measure whether behaviour actually changes, rather than simply counting how many people completed the training.

“Security awareness matters. But awareness is the beginning of the job, not evidence that you’ve finished it.”

 

Kim Larsen, Group Chief Information Security Officer, Keepit

 

Kim Larsen, Group Chief Information Security Officer, Keepit

 

“My one piece of advice would be to prioritise your crown jewels. Know what needs to happen first if and when you experience an attack, and ask yourself: what can’t your business survive without?

“Preparedness is critical. In the military, police or amongst firefighters, the same steps cannot be repeated enough: training, planning, exercises and prioritisation. The same should apply to the IT world. Define your IT landscape, prioritise it, identify your critical service providers and make sure you know who your stakeholders and participants will be during an incident or emergency.

“Those priorities also need to be communicated and accepted across the organisation. The effects of a cyberattack won’t be limited to the IT department, and without an agreed plan, different parts of the business may all demand that their systems are restored first.
“Finally, make preparedness exercises realistic. For example, start with the scenario: ‘Microsoft 365 is down. How will we get hold of people during this crisis?’

“The better you know your architecture and the better prepared you are, the better placed you will be to respond when an attack happens.”

 

Jon Lucas, Co-Founder and Director, Hyve Managed Hosting

 

Jon Lucas, Co-Founder and Director, Hyve Managed Hosting

 

“Heading into Cybersecurity Awareness Month, one of the biggest challenges for enterprises is keeping pace with an expanding attack surface. AI adoption and growing technology complexity are only adding to that challenge. As IT environments become more complex, there are more systems handling sensitive data and more infrastructure that needs to be secured. The risk is that while organisations focus on what’s new, some of the infrastructure they have relied on for years can be easier to overlook.

“File transfer systems are a good example. They are deeply embedded in day-to-day operations, moving sensitive data between employees, customers, partners and critical systems. Because that activity is so routine, it can fade into the background. Strong authentication and access controls are essential, but they need to be backed by consistent patching, proactive monitoring and visibility into file and data movement.

“What I would tell security teams this Cybersecurity Awareness Month is simple: don’t confuse familiar infrastructure with low-risk infrastructure. As environments become more complex, organisations need to ensure the systems they depend on every day receive the same security scrutiny as the newest technologies in their environment.”

 

Paul Speciale, Chief Marketing Officer, Scality

 

Paul Speciale, Chief Marketing Officer, Scality

 

“My one piece of cybersecurity advice would be to test your recovery plan under realistic conditions. It isn’t enough to know that you have a backup or even that you can restore from it. You need to know whether you can recover your critical data within the timeframe the business actually requires.

“When ransomware takes production systems offline, the important question isn’t how quickly yesterday’s backup completed. It’s when the business can start operating again. The longer a recovery takes, the longer employees may be unable to work, customers may be unable to access services and the greater the potential financial impact.

“Businesses should also make sure the data they’re recovering can be trusted. A fast restore offers little value if ransomware, malware or corruption has reached the backup itself.

“So, make recovery testing realistic. Identify your most critical data, test how long it actually takes to restore and verify that the recovered copy is clean and protected. Ultimately, the measure of cyber resilience isn’t simply whether you have a backup. It’s whether you can confidently turn that backup back into a functioning business.”

 

Cheryl Martin, Head of Cyber, C86

 

Cheryl Martin, Head of Cyber, C86

 

“This Cybersecurity Awareness Month, my advice to businesses is simple: don’t just test your ability to respond to cyber threats. Test your ability to adapt.

“Historically, organisations have measured cybersecurity success through metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). These remain important indicators of how effectively a business handles incidents once they occur.

“But today’s cyber landscape is changing faster than ever. AI is accelerating attack methods, cloud adoption continues to expand and supply chains are increasingly interconnected. In this environment, resilience is no longer defined solely by how quickly an organisation responds, but by how quickly it learns, adapts and strengthens itself before the next incident.

“This is why businesses should start paying attention to a new measure: Mean Time to Adapt (MTTA). MTTA reflects how quickly an organisation can identify a change in the threat landscape and turn that knowledge into action, whether that’s updating security controls, revising supplier risk assessments or enhancing employee awareness.

“My challenge is simple: ask your organisation, ‘How quickly do we adapt when the threat landscape changes?’ If nobody can answer with confidence, that’s your biggest cyber risk.

“Don’t wait for a breach to force action. Set clear expectations, measure adaptation alongside response and make cyber resilience a business-wide responsibility.

“The organisations that succeed will be those that learn fastest, adapt fastest and act before attackers do.”

 

Simon Lawrence, Co-Founder and CEO, i-Confidential

 

Simon Lawrence, Co-Founder and CEO, i-Confidential

 

“Security controls are an essential part of protecting an organisation’s sensitive information and data. A control is a measure put in place to manage a specific risk, whether that is a technical safeguard, a process, a policy or something an employee does as part of their everyday role but businesses often misunderstand what a control is, or what it does.

“Businesses need to understand what each control is there to achieve, what risk it addresses and who is responsible for it. Without that understanding, it is difficult to know whether your controls are actually working or what the impact is on business operations.”

 

Tim Williams, CEO, Quod Orbis

 

Tim Williams, CEO, Quod Orbis

 

“Businesses need to focus on visibility and assurance. Having the right controls in place is a great starting point, but organisations need to know whether they are working as intended, managing the risks they were designed to address and delivering the protection the business expects.

“Too many approach this like an MOT, checking their controls at a particular point in time and assuming everything is fine in between. But a car can develop a fault the day after its MOT, and the same is true of cyber controls.

“In today’s climate, where the entire business ecosystem is under threat, sporadic checks aren’t enough. Businesses need real-time visibility to identify what needs fixing, take action and prove those fixes are effective. This means adopting a continuous cycle of find, fix, prove and repeat, giving organisations the assurance to understand where they are exposed, address weaknesses quickly and demonstrate that their controls are doing what they are supposed to do.”