Back to School Means Back to Business: 5 Security Habits Richmond Companies Should Reset Right Now
Every August, the same thing happens. Kids go back to school, the routine tightens up, and for a lot of businesses, that “new year” energy quietly bleeds into the office too. New hires are onboarding. Budgets are getting revisited before Q4. Teams are settling back into a schedule after a slower summer.
It’s also, frankly, one of the best times of year for an attacker to catch you off guard.
We say this every year because it keeps being true: the “back to school” mentality is a good excuse to reset a few security habits that get sloppy over the summer. Here’s what we’re telling our clients matters most right now, and how it connects to what we actually do for you day to day.
Not Sure Where To Start? Here’s The Back-To-Business Security Reset At A Glance
| Security Habit to Reset | What to Check Right Now | Why It Matters |
| Phishing Awareness | Training, email filtering, and verification procedures | Modern phishing can look polished and highly personalized |
| Multi-Factor Authentication | Email, remote access, admin, and financial accounts | Stolen passwords are far less useful when another factor is required |
| Backups & Recovery | Isolation, immutability, and restore testing | Attackers increasingly target recovery systems during ransomware attacks |
| Employee Access | New hires, former staff, devices, and unused accounts | Access tends to accumulate or get overlooked during staffing changes |
| Overall Security Posture | Patching, permissions, backups, and vulnerabilities | Antivirus alone doesn’t show where your larger security gaps are |
1. Assume the Phishing Email Is Well Written Now
For years, the advice was “look for bad grammar and weird links.” That advice is outdated.
Modern phishing emails can be polished, convincing, and designed to look like a real message from your bank, a vendor, or even your own CEO. Attackers can also use publicly available information from places like LinkedIn and your website to make a message feel personal and specific.
The FBI’s guidance on business email compromise warns that criminals routinely send messages designed to appear as though they came from a known, legitimate source. Voice impersonation is becoming a concern too. The FBI has documented malicious campaigns involving AI-generated voice messages, making it increasingly important to verify unusual financial or access requests through a trusted channel.
If someone in your business handles money or approves access requests, they need to know this is happening.
What we do about it: Every client gets email filtering and ongoing phishing simulation as part of the baseline, not as an upsell. Our approach to reducing employee cybersecurity risk includes realistic phishing simulations and ongoing security awareness training.
2. MFA Isn’t Optional Anymore, It’s Table Stakes
Multi-factor authentication remains one of the most effective things a business can do against credential theft. Microsoft reports that MFA can block more than 99.2% of account compromise attacks.
If you’ve got any important account left without it, that’s one of the first things to fix this month, not next quarter. At minimum, review MFA protection for:
- Email accounts, especially leadership and finance users
- Remote access and VPNs
- Administrator accounts
- Financial and accounting platforms
- Cloud applications containing sensitive business data
The one thing to watch for: attackers have also developed techniques designed to capture or bypass weaker MFA methods in real time. That’s why CISA recommends businesses move toward phishing-resistant MFA whenever possible. MFA isn’t a silver bullet, but paired with strong access controls and monitoring, it creates a significantly stronger barrier between an attacker and your business.
What we do about it: MFA enforcement across email, remote access, and admin accounts is a standard part of Network Fortress. It’s also one of the security controls we regularly address when helping businesses prepare for modern cyber insurance requirements.
3. Backups Get Attacked First Now, Not Last
Ransomware doesn’t work the way it used to. Attackers may steal data before encrypting systems, then use the threat of exposure as additional leverage. They also commonly target accessible backups because destroying your recovery options makes the attack far more disruptive.
CISA’s ransomware guidance specifically warns that ransomware variants may search for and delete or encrypt accessible backups.
That’s why “we have a backup” isn’t a good enough answer on its own anymore. A backup strategy should answer three questions:
- Is it isolated? An attacker who compromises your network shouldn’t automatically be able to reach every backup.
- Is it immutable? Critical recovery data shouldn’t be alterable or deletable during an attack.
- Has it been tested? A backup only matters if you know you can actually restore from it.
What we do about it: This is core to what Network Fortress is built around. We’re not just backing data up, we’re making sure it’s immutable and recoverable, and we test that recovery path so it’s not a surprise on the day you actually need it.
We’ve written more about why immutable backups matter during ransomware recovery and how a strong recovery plan helps minimize downtime after an attack.
4. New Hires and Returning Staff Are Your Biggest Exposure Window
If your business does any kind of seasonal hiring, brings on interns, or has staff coming back from summer schedules, this is the point where access control gets messy.
Old accounts don’t get shut off. New accounts get set up too permissively because someone’s in a hurry. Common access-control gaps include:
- Former employees whose accounts are still active
- New hires receiving more access than their role requires
- Company devices that aren’t fully wiped or decommissioned
- Shared passwords or accounts nobody technically owns
- SaaS accounts created outside of IT’s visibility
We see this constantly, and it’s exactly the kind of gap that showed up in the billing dispute work we’ve done, where a departed employee’s device access wasn’t fully closed out for months.
Strong security processes need to start during onboarding and continue through offboarding. Bastionpoint‘s guidance on cybersecurity policies and procedures also emphasizes bringing employees into security processes from the beginning rather than treating training and access management as one-time tasks.
What we do about it: Device and account decommissioning is part of our standard onboarding and offboarding checklist for every managed client. If you’re bringing on new people this fall, now’s the time to make sure that checklist actually gets followed, not just filed away.
5. A Real Assessment Beats Another Antivirus Renewal
Antivirus catches threats on individual machines. It does not tell you whether your patching is current, whether your access controls are tight, or whether your backups would actually hold up under a real attack.
A proper security assessment looks at the whole picture, not just one layer. That means asking questions like:
- Are critical systems fully patched?
- Who currently has administrator privileges?
- Are old or unnecessary accounts still active?
- Are backups protected and recoverable?
- Are employees prepared for current phishing tactics?
- Are there vulnerabilities nobody has looked at recently?
What we do about it: This is the same lens we bring to every hotspot risk assessment and cybersecurity strategic plan we’ve built for clients, from medical practices and law firms to organizations across other industries. Our security assessments look at vulnerabilities, assets, access controls, and the broader technology environment so businesses can understand where their biggest risks actually are.
Make Back-to-School Season Your Security Reset
None of this is about fear. It’s about using the natural reset of this time of year to make sure the systems your business depends on are actually ready for what’s ahead. And you don’t have to figure that out on your own.
Bastionpoint Technology has been serving Richmond businesses since 2007, combining managed IT support with layered cybersecurity protection, proactive monitoring, backup and recovery, strategic technology planning, and access to a 24/7/365 Security Operations Center. That means we’re not just looking at one antivirus license or checking a box for MFA. We look at how your technology works together, your users, devices, network, cloud environment, backups, access controls, and security practices, and help identify the gaps that could create problems later.
If you’re not completely sure how your business would score on these five security habits, start with a free IT assessment. We’ll help you understand where you stand, what deserves attention first, and what can wait.
Defend your castle. Protect your business. Schedule your free IT assessment with Bastionpoint Technology
FAQs
How often should a small business run a cybersecurity assessment? Most businesses benefit from a full assessment at least once a year, with a lighter review any time there’s major staffing change, new software, or a growth spurt. Seasonal transitions, like the back-to-school period, are a natural trigger point since access and routines shift the most then.
What’s the difference between antivirus and a full security assessment? Antivirus protects individual devices from known malware. A full assessment reviews your entire environment, including patching, access controls, backups, and phishing readiness, to find risks antivirus alone can’t detect. Think of antivirus as one lock on one door, not a review of the whole building.
Is multi-factor authentication enough to stop most cyberattacks? MFA blocks the vast majority of credential-based attacks, but it isn’t foolproof on its own. Pairing it with strong access controls, monitoring, and phishing-resistant methods creates a much stronger barrier than MFA alone.
How do I know if my business backups would actually work in a ransomware attack? The only way to know is to test the restore process, not just confirm backups exist. A reliable backup should be isolated from your main network, immutable, and verified through regular recovery testing. If you’re not sure where your backups stand, a free IT assessment can show you exactly where the gaps are.




Leave a Reply
Want to join the discussion?Feel free to contribute!