The biggest cybersecurity gaps often begin with something leadership assumes is already handled.
October is Cybersecurity Awareness Month, which means business leaders will hear plenty of reminders about passwords, phishing, multi-factor authentication, backups, and employee training. All of those topics matter. But there’s another cybersecurity risk that receives far less attention: the assumptions businesses make about how well protected they already are.
Most organizations aren’t ignoring cybersecurity. They have security tools in place. Employees have been told to watch for suspicious emails. Backups are running. Multi-factor authentication is enabled. Someone is responsible for IT.
From a leadership perspective, that can create a reasonable sense that cybersecurity is being handled.
The problem is that each of those statements can be true while significant risk still exists.
For professional services firms throughout Las Vegas and Southern Nevada, that distinction matters. CPA firms, wealth management practices, insurance agencies, engineering firms, and consultants hold exactly the kind of information cybercriminals can monetize or use to gain access to other organizations.
Cybersecurity Awareness Month is a good opportunity to challenge some comfortable assumptions. Here are six we still see businesses making—and the questions leadership should be asking instead.
Myth #1: “We’re too small for cybercriminals to care about.”
It’s easy to imagine cybercriminals choosing targets the same way a burglar might choose houses: find the biggest, wealthiest target and go after it.
Modern cybercrime often doesn’t work that way.
Many attacks are opportunistic and automated. Criminals look for exposed accounts, vulnerable systems, compromised passwords, or employees who can be convinced to provide access. They don’t necessarily care whether the organization has 25 employees or 2,500 if they find an opportunity they can exploit.
Professional services firms can be particularly attractive because of what they have access to. An accounting firm may hold financial and tax information. A wealth management practice has sensitive client records. An insurance agency may possess personal and financial data. Consultants and engineering firms can hold confidential information belonging to clients and business partners.
Your organization can also become a pathway to someone else. A compromised email account may allow an attacker to impersonate a trusted advisor and target clients or vendors.
The better question isn’t, “Are we big enough to be targeted?”
It’s, “If someone tested our defenses today, what opportunities would they find?”
Myth #2: “Our employees would recognize a phishing email.”
There was a time when phishing emails were relatively easy to spot. The grammar was awkward, the formatting looked strange, and the message often came from an obviously suspicious email address.
Those days are largely behind us.
Today’s phishing attempts can be polished, personalized, and remarkably convincing. AI has made it easier to create professional-looking messages quickly, while information available online can help criminals make those messages feel familiar and credible.
That changes what employees should be looking for.
Instead of relying primarily on spelling mistakes or strange formatting, employees need to recognize unusual behavior. Would this executive normally ask you to change payment information by email? Would this vendor suddenly provide new banking instructions? Why is someone requesting confidential information they don’t normally need? Were you expecting that Microsoft 365 login link?
This is especially important in professional services, where employees routinely receive documents, payment instructions, client requests, and links throughout the day. A fraudulent message doesn’t need to look suspicious if it looks exactly like the work your employees already perform.
Security awareness training shouldn’t teach people to become suspicious of every email. It should teach them when to slow down, verify a request, and ask for help.
That small pause can prevent a very expensive mistake.
Myth #3: “We have MFA, so our accounts are protected.”
Multi-factor authentication is one of the most important security controls a business can implement.
But important doesn’t mean infallible.
Attackers have developed ways to take advantage of human behavior around authentication. One example is MFA fatigue, sometimes called prompt bombing, where a user receives repeated authentication requests in the hope that they’ll eventually approve one out of confusion, habit, or frustration.
Other attacks may involve convincing an employee to approve a login they believe is legitimate.
None of this means businesses should question the value of MFA. Quite the opposite. It means leadership should understand that no single cybersecurity control should be expected to carry the entire security strategy.
Strong authentication works best alongside employee awareness, access controls, monitoring, good security policies, and people who know how to respond when something unusual occurs.
Cybersecurity works in layers.
If your confidence depends entirely on one layer, it’s worth asking what happens when that layer fails.
Myth #4: “Our backups have us covered.”
This may be one of the most common assumptions we encounter.
Leadership asks whether the business has backups. Someone confirms that backups are running. The box gets checked.
There’s just one problem.
Having backups and being able to recover your business are not the same thing.
Imagine a ransomware incident makes critical files and systems unavailable tomorrow morning. How quickly could your organization restore them? Which systems would come back first? Are cloud applications and Microsoft 365 data included in your strategy? When was the last time someone actually tested the recovery process?
Those questions matter because the purpose of a backup isn’t simply to preserve data. It’s to help the business resume operations.
For a professional services firm, every hour of downtime can affect client service, productivity, deadlines, and revenue. Recovery capabilities can also matter during cyber insurance reviews and other risk-management conversations.
A successful backup report tells you data was copied.
A successful recovery test tells you whether the business can use it when it matters.
Myth #5: “Cybersecurity is IT’s responsibility.”
Your IT team or managed technology provider has an important role in cybersecurity. They can secure systems, monitor networks, manage access, maintain security tools, and respond to technical threats.
What they can’t do is make every decision your employees make throughout the day.
Cybersecurity decisions happen across the organization. Someone receives a request to change banking information. An employee decides whether to enter credentials into a website. A manager determines who should have access to sensitive client files. Leadership decides whether security requirements receive budget and attention.
That’s why cybersecurity is ultimately a business responsibility, not simply an IT function.
For leadership, this doesn’t mean becoming a cybersecurity expert. It means creating an environment where employees understand expectations, security responsibilities are clearly assigned, and people feel comfortable questioning something that doesn’t look right.
Your technology partner can build strong defenses.
Your organization still needs to operate responsibly inside them.
Myth #6: “We’ll know what to do if something happens.”
Imagine it’s 9:15 on an ordinary Tuesday morning. Several employees suddenly report that they can’t open important files.
What happens next?
Does everyone immediately call IT? Should employees disconnect their computers? Who determines whether this is a technical outage or a cybersecurity incident? If email becomes unavailable, how will employees receive instructions? At what point does leadership contact the cyber insurance carrier? Who decides whether clients need to be notified?
Most leadership teams can eventually answer those questions.
The issue is how much time they’ll lose figuring them out during the incident.
An incident response plan exists to remove that uncertainty before the business is under pressure. Roles should be established, communication methods identified, outside contacts documented, and employees given enough guidance to know what they should – and shouldn’t – do.
Just as importantly, that plan needs to be reviewed and practiced.
The middle of a cybersecurity incident is a terrible time for your recovery plan to make its debut.
Cybersecurity Confidence Should Come From Verification
There’s a common thread running through all six myths.
Each begins with something that sounds reassuring.
We’re too small to be targeted.
Our employees know what phishing looks like.
We have MFA.
We have backups.
IT handles security.
We’ll know what to do.
The problem isn’t that those statements are completely wrong. It’s that they’re incomplete. And incomplete assumptions can create a level of confidence the organization’s actual cybersecurity posture doesn’t support.
For business leaders, the goal shouldn’t be to eliminate every possible cybersecurity risk. That’s unrealistic. The goal is to understand your most important risks, put appropriate protections around them, and verify that the controls you’re relying on actually work.
That means testing backups instead of assuming they’ll restore. It means training employees instead of assuming they’ll recognize every attack. It means reviewing access and authentication instead of assuming MFA solves everything. And it means practicing incident response instead of assuming everyone will know what to do.
That’s what mature cybersecurity looks like.
This October, Replace One Assumption With An Answer
Cybersecurity Awareness Month doesn’t need to mean another checklist or another employee email reminding everyone not to click suspicious links.
Use it as an opportunity to ask a better question:
What are we assuming about our cybersecurity that we haven’t actually verified?
At Orbis Solutions, we help professional services firms throughout Las Vegas and Southern Nevada answer that question. We work with leadership teams to understand their cybersecurity risks, evaluate the protections already in place, strengthen employee awareness, validate recovery capabilities, and develop a clearer picture of where the organization actually stands.
The objective isn’t to make business leaders afraid of what might happen.
It’s to replace assumptions with clarity.
If you’re not sure whether the cybersecurity protections your organization relies on would hold up under real-world conditions, a Cybersecurity Risk Assessment can help identify what’s working, where gaps may exist, and what deserves attention next.
Because when it comes to cybersecurity, knowing you’re prepared is considerably more valuable than assuming you are.