Sam runs a twelve person CPA firm in Salem. Ask him about cybersecurity and he will tell you, without pausing, that the firm is fine. Small shop, decent antivirus, backups running every night.
He believes every word of it. Most of the owners we talk to do.
October is Cybersecurity Awareness Month, which makes it a fair time to ask a harder question. Not whether you feel covered, but whether the assumptions behind that feeling are still true. Some of them were true ten years ago. A few were never true at all.
10D Tech provides managed IT services and cybersecurity for businesses with 10 to 250 employees across Oregon and southwest Washington, from Portland and Salem through Albany, Corvallis, and Eugene to Bend. These are the six myths we hear most often from the owners we work with, and the straight answer on each.
Myth 1: We are too small for anyone to bother with
This one feels like common sense. Why would a criminal go after a dozen people in Salem when there are banks in Portland?
Because the criminal is not choosing. Most attacks are automated scans looking for an exposed login, an unpatched server, or an email account with a weak password. The scan does not know how big your company is, and it does not care.
A small firm also holds things worth taking. Client tax records, a bank account with signing authority, and trusted email relationships with vendors and customers who will open whatever you send them.
Do cybercriminals really target businesses with fewer than 50 employees?
Yes, though target is the wrong word. They target weaknesses, and small businesses tend to have more of them per employee because nobody is watching full time. The size of your company decides how much damage a breach does, not whether you are exposed to one.
Myth 2: Our people would recognize a phishing email
They would have recognized the ones from 2015. Bad spelling, a strange sender, a link to nowhere.
Today's version is written cleanly, references a real vendor, and lands at 4:30 on a Friday. The text alone will not give it away. What gives it away is the request.
Train your team to look at behavior instead of grammar.
Would this person ask for a wire? Would they change payment details by email? Would they send a new login link out of nowhere? If the request is unusual, verify it by phone before anyone acts.
Myth 3: We have MFA, so our accounts are protected
Multi-factor authentication is one of the best controls you can put in place. It is also a control, not a wall.
Attackers have learned to work around it. One common approach is to flood a phone with approval prompts until the employee taps yes to make it stop. Another is to trick someone into approving a login they never started.
Is multi-factor authentication enough to protect a business account?
No. MFA closes the biggest single gap, which is a stolen password, and every business should have it on email and financial systems. It works best with controls around it: number matching or a physical key instead of a simple approve button, alerts on unusual logins, and a rule that nobody approves a prompt they did not trigger.
Myth 4: Our backups have us covered
Sam's backups run every night. Nobody at his firm has ever tried to restore from one.
That is the gap. A backup that has never been restored is a hope, not a plan. Owners find out the difference during a ransomware event, which is the worst possible time to learn that the backup job has been failing silently since March or that the restore takes four days instead of four hours.
How often should a business test its backups?
Run a real restore at least quarterly, and after any major change to your systems. Restore an actual file, an actual mailbox, and, once a year, an entire server to confirm the full recovery works. Write down how long it took. That number is your real downtime, and it belongs in your planning.
Myth 5: Cybersecurity is the IT department's job
Your IT team, whether internal or outsourced, controls the tools. It does not control the click.
Every employee makes security decisions all day: which link to open, which request to trust, which password to reuse. A team that knows what to look for and who to call is part of the defense. A team that has never been told is a gap the tools cannot close. We wrote a full piece on this, and it is worth the read if you have been leaving it all to IT.
Myth 6: We would know what to do if something happened
It is Tuesday, 8:40 in the morning. Three people cannot open their files. A fourth just got a message on screen demanding payment.
In that moment, most companies discover that nobody has answered the basic questions.
Do people shut their computers off or leave them on? Who calls whom? What happens if email is down? When does the insurance carrier get involved, and who talks to clients?
What should an incident response plan include for a small business?
Four things, on one page. Who to call first, including your IT provider's emergency number and your cyber insurance contact. What employees should do and not do in the first fifteen minutes. How you will communicate with staff and clients if your normal channels are down.
And who has authority to make decisions if the owner is unreachable. Print it. A plan that lives only on the server is useless when the server is the problem.
Awareness starts with the facts
Myths are comfortable. They let you feel covered without looking closely, and most of them come from advice that was reasonable once and never got updated.
Cybersecurity gaps rarely come from a missing product. They come from believing something is handled when it is not. That is what Awareness Month is for: replacing the assumption with a fact.
How do I know if my IT provider is actually protecting my business?
Ask three questions and listen for specifics. When did we last successfully restore from backup, and how long did it take? Which accounts have MFA and which do not? Who gets the call at 8:40 on a Tuesday, and what do they do first? A provider protecting you answers all three in a day with dates and names. Vague reassurance is the finding.
Sam's firm had a good answer on MFA and a bad one on backups. Now he knows which one to fix. That is the whole point of the exercise.
If any of these six sounded familiar, you do not need a lecture. You need a number. A complimentary 15 minute Technology Confidence Score call gives you a clear picture of where your systems stand today, along with your score out of 100. See how the Score works at 10dtech.com/aspirin, then schedule at 10dtech.com/Tech_Confidence_Score. Albany, Corvallis, Eugene, Bend: 541-243-4103. Portland, Salem: 971-915-9103.





