• Client Portal
  • Blog
(804) 612-9876
Bastionpoint Technology
  • About Us
    • Blog
    • Press Releases
    • Video Library
  • What You Need
    • An Outsourced IT Department
    • A Partner in Managing IT
    • A Help Desk to Call
    • Cybersecurity and Compliance
  • What We Offer
    • Fully Managed IT
    • Co-Managed IT
    • Remote Helpdesk
    • Cybersecurity
    • Compliance
    • Structured Cabling
    • Wireless Survey
  • Careers
  • Get Started
  • Menu Menu

Back to School Means Back to Business: 5 Security Habits Richmond Companies Should Reset Right Now

Cybersecurity, Tech Tips
Children wearing backpacks run toward school, representing the back-to-school season and a cybersecurity reset for Richmond businesses.

Every August, the same thing happens. Kids go back to school, the routine tightens up, and for a lot of businesses, that “new year” energy quietly bleeds into the office too. New hires are onboarding. Budgets are getting revisited before Q4. Teams are settling back into a schedule after a slower summer.

It’s also, frankly, one of the best times of year for an attacker to catch you off guard.

We say this every year because it keeps being true: the “back to school” mentality is a good excuse to reset a few security habits that get sloppy over the summer. Here’s what we’re telling our clients matters most right now, and how it connects to what we actually do for you day to day.

Not Sure Where To Start? Here’s The Back-To-Business Security Reset At A Glance

Security Habit to Reset What to Check Right Now Why It Matters
Phishing Awareness Training, email filtering, and verification procedures Modern phishing can look polished and highly personalized
Multi-Factor Authentication Email, remote access, admin, and financial accounts Stolen passwords are far less useful when another factor is required
Backups & Recovery Isolation, immutability, and restore testing Attackers increasingly target recovery systems during ransomware attacks
Employee Access New hires, former staff, devices, and unused accounts Access tends to accumulate or get overlooked during staffing changes
Overall Security Posture Patching, permissions, backups, and vulnerabilities Antivirus alone doesn’t show where your larger security gaps are

1. Assume the Phishing Email Is Well Written Now

For years, the advice was “look for bad grammar and weird links.” That advice is outdated.

Modern phishing emails can be polished, convincing, and designed to look like a real message from your bank, a vendor, or even your own CEO. Attackers can also use publicly available information from places like LinkedIn and your website to make a message feel personal and specific.

The FBI’s guidance on business email compromise warns that criminals routinely send messages designed to appear as though they came from a known, legitimate source. Voice impersonation is becoming a concern too. The FBI has documented malicious campaigns involving AI-generated voice messages, making it increasingly important to verify unusual financial or access requests through a trusted channel.

If someone in your business handles money or approves access requests, they need to know this is happening.

What we do about it: Every client gets email filtering and ongoing phishing simulation as part of the baseline, not as an upsell. Our approach to reducing employee cybersecurity risk includes realistic phishing simulations and ongoing security awareness training.

2. MFA Isn’t Optional Anymore, It’s Table Stakes

Multi-factor authentication remains one of the most effective things a business can do against credential theft. Microsoft reports that MFA can block more than 99.2% of account compromise attacks.

If you’ve got any important account left without it, that’s one of the first things to fix this month, not next quarter. At minimum, review MFA protection for:

  • Email accounts, especially leadership and finance users
  • Remote access and VPNs
  • Administrator accounts
  • Financial and accounting platforms
  • Cloud applications containing sensitive business data

The one thing to watch for: attackers have also developed techniques designed to capture or bypass weaker MFA methods in real time. That’s why CISA recommends businesses move toward phishing-resistant MFA whenever possible. MFA isn’t a silver bullet, but paired with strong access controls and monitoring, it creates a significantly stronger barrier between an attacker and your business.

What we do about it: MFA enforcement across email, remote access, and admin accounts is a standard part of Network Fortress. It’s also one of the security controls we regularly address when helping businesses prepare for modern cyber insurance requirements.

3. Backups Get Attacked First Now, Not Last

Ransomware doesn’t work the way it used to. Attackers may steal data before encrypting systems, then use the threat of exposure as additional leverage. They also commonly target accessible backups because destroying your recovery options makes the attack far more disruptive.

CISA’s ransomware guidance specifically warns that ransomware variants may search for and delete or encrypt accessible backups.

That’s why “we have a backup” isn’t a good enough answer on its own anymore. A backup strategy should answer three questions:

  • Is it isolated? An attacker who compromises your network shouldn’t automatically be able to reach every backup.
  • Is it immutable? Critical recovery data shouldn’t be alterable or deletable during an attack.
  • Has it been tested? A backup only matters if you know you can actually restore from it.

What we do about it: This is core to what Network Fortress is built around. We’re not just backing data up, we’re making sure it’s immutable and recoverable, and we test that recovery path so it’s not a surprise on the day you actually need it.

We’ve written more about why immutable backups matter during ransomware recovery and how a strong recovery plan helps minimize downtime after an attack.

4. New Hires and Returning Staff Are Your Biggest Exposure Window

If your business does any kind of seasonal hiring, brings on interns, or has staff coming back from summer schedules, this is the point where access control gets messy.

Old accounts don’t get shut off. New accounts get set up too permissively because someone’s in a hurry. Common access-control gaps include:

  • Former employees whose accounts are still active
  • New hires receiving more access than their role requires
  • Company devices that aren’t fully wiped or decommissioned
  • Shared passwords or accounts nobody technically owns
  • SaaS accounts created outside of IT’s visibility

We see this constantly, and it’s exactly the kind of gap that showed up in the billing dispute work we’ve done, where a departed employee’s device access wasn’t fully closed out for months.

Strong security processes need to start during onboarding and continue through offboarding. Bastionpoint‘s guidance on cybersecurity policies and procedures also emphasizes bringing employees into security processes from the beginning rather than treating training and access management as one-time tasks.

What we do about it: Device and account decommissioning is part of our standard onboarding and offboarding checklist for every managed client. If you’re bringing on new people this fall, now’s the time to make sure that checklist actually gets followed, not just filed away.

5. A Real Assessment Beats Another Antivirus Renewal

Antivirus catches threats on individual machines. It does not tell you whether your patching is current, whether your access controls are tight, or whether your backups would actually hold up under a real attack.

A proper security assessment looks at the whole picture, not just one layer. That means asking questions like:

  • Are critical systems fully patched?
  • Who currently has administrator privileges?
  • Are old or unnecessary accounts still active?
  • Are backups protected and recoverable?
  • Are employees prepared for current phishing tactics?
  • Are there vulnerabilities nobody has looked at recently?

What we do about it: This is the same lens we bring to every hotspot risk assessment and cybersecurity strategic plan we’ve built for clients, from medical practices and law firms to organizations across other industries. Our security assessments look at vulnerabilities, assets, access controls, and the broader technology environment so businesses can understand where their biggest risks actually are.

Make Back-to-School Season Your Security Reset

None of this is about fear. It’s about using the natural reset of this time of year to make sure the systems your business depends on are actually ready for what’s ahead. And you don’t have to figure that out on your own.

Bastionpoint Technology has been serving Richmond businesses since 2007, combining managed IT support with layered cybersecurity protection, proactive monitoring, backup and recovery, strategic technology planning, and access to a 24/7/365 Security Operations Center. That means we’re not just looking at one antivirus license or checking a box for MFA. We look at how your technology works together, your users, devices, network, cloud environment, backups, access controls, and security practices, and help identify the gaps that could create problems later.

If you’re not completely sure how your business would score on these five security habits, start with a free IT assessment. We’ll help you understand where you stand, what deserves attention first, and what can wait.

Defend your castle. Protect your business. Schedule your free IT assessment with Bastionpoint Technology

FAQs

How often should a small business run a cybersecurity assessment? Most businesses benefit from a full assessment at least once a year, with a lighter review any time there’s major staffing change, new software, or a growth spurt. Seasonal transitions, like the back-to-school period, are a natural trigger point since access and routines shift the most then.

What’s the difference between antivirus and a full security assessment? Antivirus protects individual devices from known malware. A full assessment reviews your entire environment, including patching, access controls, backups, and phishing readiness, to find risks antivirus alone can’t detect. Think of antivirus as one lock on one door, not a review of the whole building.

Is multi-factor authentication enough to stop most cyberattacks? MFA blocks the vast majority of credential-based attacks, but it isn’t foolproof on its own. Pairing it with strong access controls, monitoring, and phishing-resistant methods creates a much stronger barrier than MFA alone.

How do I know if my business backups would actually work in a ransomware attack? The only way to know is to test the restore process, not just confirm backups exist. A reliable backup should be isolated from your main network, immutable, and verified through regular recovery testing. If you’re not sure where your backups stand, a free IT assessment can show you exactly where the gaps are.

August 17, 2026/0 Comments/by Eric Clary
Share this entry
  • Facebook Facebook Share on Facebook
  • X-twitter X-twitter Share on X
  • Square-x-twitter Square-x-twitter Share on X
  • Whatsapp Whatsapp Share on WhatsApp
  • Pinterest Pinterest Share on Pinterest
  • Linkedin Linkedin Share on LinkedIn
  • Reddit Reddit Share on Reddit
  • Mail Mail Share by Mail
https://bastionpoint.com/wp-content/uploads/2026/08/rear-view-of-elementary-school-pupils-running-acr-2026-03-10-04-00-12-utc-1-scaled.jpg 1707 2560 Eric Clary https://bastionpoint.com/wp-content/uploads/2020/09/BPLogoTransparentBG-300x251.png Eric Clary2026-08-17 09:00:352026-08-15 20:37:17Back to School Means Back to Business: 5 Security Habits Richmond Companies Should Reset Right Now
0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Pages

  • About
  • Auditing
  • Bastionpoint Technology Featured on 12 On Your Side for $10K Shelter Security Donation
  • Blog
  • Careers
  • Co-Managed IT
  • Compliance
  • Computer Hardware
  • Contact
  • Customer Support
  • Cybersecurity
  • Cybersecurity Policies and Procedures
  • Disaster Prevention and Recovery
  • Email Security
  • Find Your “Furever” Valentine: Bastionpoint Technology’s Adoption Event on CBS6
  • Fully Managed IT
  • Giving Back in Richmond: Bastionpoint Technology’s Toys for Tots Event on CBS6
  • Hardware and Wiring
  • IT Consulting
  • IT Health Survey
  • IT Project Management
  • IT Services
  • Kickers Ticket Rules
  • Kickers Tix
  • Managed IT Services Midlothian, Virginia
  • Managed IT Services Petersburg, Virginia
  • Managed IT Services Richmond, Virginia
  • Midlothian VA Outsourced IT
  • Otter Cam
  • Partner Managed IT Services Richmond, Virginia
  • Phone Systems
  • Privacy Policy
  • Remote Helpdesk
  • Richmond VA Disaster Recovery
  • Richmond VA IT Support
  • Richmond, Virginia Cybersecurity Services
  • Richmond, Virginia Outsourced IT
  • RVA Today – Bastionpoint Compliance and AI
  • RVA Today – Bastionpoint Cybersecurity Tips
  • RVA Today – Bastionpoint Enterprise Security and Growing your Business
  • RVA Today – Bastionpoint In the Community
  • RVA Today – Bastionpoint Polices, Procedures and Best Practices
  • RVA Today – Bastionpoint Technology Intro
  • Sample Blog
  • Strengthen Your Business with the Right IT Partner
  • Structured Cabling
  • Terms and Conditions
  • Thank You
  • Unlimited Flat Fee Support
  • vCIO
  • Video Library
  • Videos
  • We Are Your Full-Service IT Company
  • Why Not Us
  • Williamsburg IT Support Company
  • Williamsburg, Virginia Cyber Security Company
  • Wireless Networks
  • Wireless Survey

Categories

  • artificial intelligence
  • Case Study
  • Cloud Computing
  • Cloud Security
  • Co-Managed IT Solutions
  • Company News
  • Customer Service
  • customer support
  • Cyber-Attacks
  • Cybercrime
  • Cybersecurity
  • Data Back-Up
  • Disaster Recovery
  • From the Desk of the CIO
  • help desk support
  • Information Technology
  • IT helpdesk
  • IT helpdesk support
  • IT risks
  • Managed IT Solutions
  • Managed Services
  • phishing
  • Press Releases
  • ransomware attacks
  • Structured Wiring
  • Tech Tips
  • Technical Notes
  • threat intelligence
  • Uncategorized
  • vCIO
  • Wireless Network Survey

Archive

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • August 2020
  • May 2020
  • April 2020
  • February 2020
  • January 2020
  • November 2019
  • August 2019
  • June 2019
  • February 2019
  • December 2018
  • May 2018

1618 Hull St
Richmond, VA 23224

(804) 612-9876

About Bastionpoint Technology

  • About
  • Blog
  • Why Not Us
  • Contact
  • Careers

Services We Offer

  • IT Services
  • IT Consulting
  • Disaster Prevention and Recovery
  • Hardware and Wiring
  • Computer Hardware
  • Cybersecurity Policies and Procedures
  • Email Security
© 2026 - Bastionpoint Technology. All Rights Reserved.
  • Link to LinkedIn
  • Link to Facebook
  • Link to X
  • Privacy Policy
  • Terms and Conditions
Link to: What Does XDR Stand For? Extended Detection and Response Explained Link to: What Does XDR Stand For? Extended Detection and Response Explained What Does XDR Stand For? Extended Detection and Response ExplainedHooded figure interacting with a glowing digital interface displaying connected user profiles, email icons, and streams of binary code.
Scroll to top Scroll to top Scroll to top