Cyber Resilience

Lean IT Orgs Monthly

No security team? Here are the five things worth doing this month, in plain language, each with a rough time estimate. Do them in order.

Issue: July 2026 · Last updated: 12 August 2026 00:47 UTC

  1. 1Patch anything internet-facing that's on CISA's exploited list~1 hour

    Attackers go after known-exploited bugs first. If a firewall, VPN, email server, or web app you run is on the CISA KEV list, patch it this week.

  2. 2Turn on multi-factor authentication everywhere it's offered~2 hours

    Email, remote access, admin logins, and money accounts. MFA stops most account takeovers even when a password leaks.

  3. 3Make a backup you've actually tested restoringHalf a day

    A backup you've never restored is a guess. Restore one important system to a spare location and confirm the data is really there.

  4. 4Remove admin rights and old accounts you don't need~1 hour

    Every admin account and every ex-employee login is a way in. List who has admin, trim what isn't needed, and disable dormant accounts.

  5. 5Update the firmware on your router, firewall, and Wi-Fi~1 hour

    Network gear is a favorite target and easy to forget. Check each device's admin page for a firmware update and apply it.

That's the month. If you only do the first two, you've already shut the doors attackers use most. Next month we'll build on it.