Levi, Ray & Shoup, Inc.

Fall Is the Time Not to Fall

10/7/2026 by Chris Hill

Fall brings cooler temperatures, changing leaves, and a busy stretch of business planning. As organizations prepare next year’s budgets and work toward year-end goals, October offers another reason to pause: Cybersecurity Awareness Month.

For businesses, the message is simple: Fall is the time not to fall. Which means, don't fall for a convincing scam, fall behind on security, or fall into a false sense of confidence.

A strong cybersecurity program starts with understanding where your organization is exposed and taking practical steps to address those risks.

Don’t fall for the familiar face

An email from a vendor. A text from an executive. A request to update payment information.

When a message appears to come from someone you trust, it can be easy to act before asking questions. Make verification part of everyday business. Confirm payment changes through a known phone number, question unexpected requests for sensitive information, and give employees a clear way to report suspicious messages.

Build a culture where taking a moment to verify is encouraged—and reporting a mistake quickly is valued.

Don’t fall behind on the basics

Cybersecurity fundamentals deserve attention long after the annual training session ends.

Use this month to ask practical questions: Are important systems receiving timely updates? Is multifactor authentication enabled wherever possible? Have former employees’ accounts been disabled? Do users have only the access they need?

Assign an owner to each identified gap and a date for addressing it. Awareness becomes useful when it leads to a completed action.

Don’t fall into the “we have tools, so we’re covered” trap

Having security technology is one part of protecting your business. Understanding how it is configured, monitored, and supported is just as important.

Who reviews alerts? Who investigates suspicious activity? Are all critical systems covered? Can your team explain how the tools work together?

Before adding another product to next year’s budget, assess your current environment. You may uncover gaps in coverage, opportunities to improve existing investments, or processes that need clearer ownership.

LRS’ Cyber Risk Analysis helps organizations assess areas commonly targeted by attackers, providing a starting point for understanding exposure.

Don’t fall short when recovery matters

Consider this scenario: Your systems are unavailable, your normal email cannot be trusted, and employees are asking what to do next.

Who takes charge? How do you communicate? Which business functions must be restored first?

Review your incident response plan before you need it. Keep an accessible copy outside your production environment, confirm contact information, and walk through a realistic scenario with IT, leadership, and key business teams.

Apply the same scrutiny to backups. Test whether you can restore critical systems and data, and confirm that recovery copies are protected from an incident affecting your primary environment.

Make October the starting point

Cybersecurity Awareness Month is an opportunity to build momentum that continues throughout the year.

Choose a few meaningful actions: review access, test a recovery process, practice incident response, or assess your current security posture. Give each action an owner and follow through.

At LRS IT Solutions, we help organizations strengthen their cybersecurity programs through assessments, consulting, implementation, and managed services—with an approach grounded in business needs.

This fall, take the next step toward a more resilient business. Connect with LRS IT Solutions to discuss where you stand and what to prioritize next.

The leaves may fall. Your cybersecurity readiness should keep moving forward.