Labeled storage boxes with Myths Busted sign

Subtitle: Cybersecurity starts with understanding where your protection is proven and where you may be relying on assumptions.

By: Dan Roberts on 10/5/26

October is Cybersecurity Awareness Month, which makes it a good time to look at what you know about your business's cybersecurity and what you may simply assume to be true. Some cybersecurity advice has been repeated for so long that it begins to sound like fact, even when technology and the threats facing businesses have changed.

The problem with these assumptions is the false sense of confidence they can create. A business may believe its size makes it less attractive to cybercriminals, employees will recognize phishing attempts, or backups guarantee recovery. Everything can appear to be working until an incident reveals a gap no one knew existed.

The good news is many of these gaps become easier to address once you know where to look. Here are six cybersecurity assumptions worth reconsidering.

Assumption 1: We're too small for cybercriminals to care about.

Cybercriminals do not need your business to be large for it to be worth targeting. If an organization has vulnerable systems or exposed accounts, there may be an opportunity to access valuable data, financial information, customers, or vendors.

For a business owner, the important question is not whether your company is big enough to attract attention. It is whether the protections around your people, systems, and information are appropriate for the risks your business faces.

The reality: Cybercriminals often look for opportunities, regardless of the size of the business.

Assumption 2: Our employees will recognize a phishing email.

Phishing emails are not always filled with spelling mistakes or sent from obviously suspicious addresses anymore. They can be polished, personalized, and designed to look like a legitimate message from someone your employees know and trust.

AI has made it even easier to create convincing messages, which means employees cannot always judge an email by how professional it looks. Instead, they should consider whether the request itself makes sense. Would this person normally:

  • Make an unusual request?
  • Change payment instructions?
  • Request sensitive information?
  • Send a new or unusual login link?

When something does not feel right, taking a moment to verify the request through another trusted method can prevent a much larger problem.

The reality: A professional looking email can still be a scam.

Assumption 3: MFA fully protects our accounts.

Multi factor authentication, or MFA, is an important layer of cybersecurity, but no single security measure provides complete protection. Cybercriminals continue looking for ways to get around authentication methods, including sending repeated approval requests in hopes an employee eventually accepts one.

MFA works best as part of a broader approach to cybersecurity. The goal should not be to find one security tool capable of protecting everything. It should be to create layers of protection that work together and reduce the likelihood of one mistake becoming a serious business problem.

The reality: MFA is important, but it should be part of a broader cybersecurity strategy.

Assumption 4: Our backups have us covered.

Knowing your business has backups is important. Knowing you can recover from those backups is even more important. If ransomware or another disruption affected your business tomorrow, could you confidently say which systems would be restored first and how long recovery would take?

An untested backup leaves an important question unanswered. You know the data was backed up, but you do not necessarily know what recovery will look like when employees are waiting and operations are interrupted. Testing helps replace that assumption with a clearer understanding of how prepared the business actually is.

The reality: Having backups is not the same as being able to recover.

Assumption 5: Cybersecurity is IT's responsibility.

Your technology team or provider plays an important role in protecting the business, but they cannot control every decision employees make throughout the day. Cybersecurity decisions happen across the organization whenever someone opens an attachment, responds to an email, shares information, or approves a request.

Employee security awareness training helps people recognize when something deserves a second look and understand when to ask for help. Cybersecurity becomes stronger when employees understand they have a role in protecting the organization rather than assuming someone in IT is handling everything behind the scenes.

The reality: Employees who know how to make good security decisions are an important part of your cybersecurity strategy.

Assumption 6: We'll know what to do if something happens.

Imagine it is Tuesday morning and several employees suddenly cannot access their files. This is not the time leadership wants to discover no one has answered some basic questions:

  • Should employees shut down their computers?
  • Who contacts the technology team?
  • What happens if normal communication systems are unavailable?
  • When should the insurance company become involved?
  • Who communicates with customers, and how?

Trying to make these decisions while an incident is unfolding creates unnecessary confusion and can slow the response. A documented incident response plan gives employees and leadership a clearer understanding of their responsibilities before they are operating under pressure.

The reality: Your incident response plan should be understood before you need to use it.

Cybersecurity Confidence Comes From Knowing Where You Stand

Cybersecurity Awareness Month is a useful reminder to make sure the assumptions guiding your business decisions are accurate. It is easy to feel protected when everything appears to be working normally, but real confidence comes from understanding which protections are in place, whether they are working as expected, and where gaps may still exist.

At RTS, we help businesses throughout the Cedar Rapids/Iowa City Corridor take a practical approach to cybersecurity. Through proactive planning, employee education, responsive support, and clear communication, we help business leaders better understand their risks and make informed decisions about how to protect their organizations.

If one or two of these assumptions made you stop and think about your own business, let's have a conversation.

Call 319-364-3004 or click here to schedule a discovery call.