Cybermois 2026: A 30-Minute Cybersecurity Plan for Small Businesses

Cybermois 2026: A 30-Minute Cybersecurity Plan for Small Businesses
01

Prepare a session with the right people

Cybermalveillance.gouv.fr presents Cybermois as an approach to raising awareness of digital threats and good reflexes. Its page dedicated to the 2026 edition, updated on September 15, links to the organized actions. Our Thirty Minute Plan is an ISS Agency proposal, not an official audit or certification program. It can be used to prepare an exchange with your IT service provider.

Bring together the person who manages the accounts and the person who knows the daily operation. Keep provider contacts, access to email settings and backup information handy. If you do not have the necessary rights, note the questions to send. Don't share passwords in a common table to save a few minutes.

02

Minutes 0 to 5: identify what is blocking activity

List three services whose unavailability would prevent you from working: messaging, cash register, business software, reservations or customer files. For each, indicate who administers access and how to contact support. The exercise often reveals dependence on a former employee, a personal account or a supplier whose contact details no one knows. This information is essential before modifying a configuration.

Fictitious example: a salon uses an online calendar, an email box and a payment terminal. He discovers that the calendar security alerts are coming to an old address. The first action is to have the recovery contact corrected after verification. It’s not about increasing the number of tools, but about making account ownership and management understandable.

03

Minutes 5 to 10: look at sensitive access

Check which accounts have administrative rights and who can still use them. Identify accesses that have become unnecessary and have them removed according to your procedure. For large accounts, review the availability and enablement of multi-factor authentication. Before any change, plan the means of recovery and ensure that an authorized person can regain access in the event of loss of device.

A password shared by the entire team makes it difficult to know who has carried out an action and complicates departures. Favor nominative accounts with the rights necessary for each function. If a migration is required, plan for it rather than cutting off critical access in the middle of the session. The expected result is a clarified access list and assigned priority action.

04

Minutes 10 to 15: check for a useful backup

Ask when the last successful backup was and what folders it covers. A green icon in software does not prove that all important files are included. Also check who can delete the copies and whether they remain exposed to the same incident as the original data. The official sheet on safeguards gives the principles to be explored in greater depth.

Choose a file without particular sensitivity and request a restoration to a separate location, without overwriting the original. If this test takes more than five minutes, schedule it with the provider and write down a date. The short plan is to trigger the check, not to pretend it is complete. Our article on protection of customer files explains why encryption does not replace this recovery capability.

05

Minutes 15 to 20: spot pending updates

Review the devices and software that process your important data. Identify pending updates and versions that are no longer supported. For a site, ask the hosting or maintenance manager what is tracked: system, extensions, dependencies and backups. A hosted service doesn't mean all your responsibilities are gone.

Don't run a major update without checking the backup and the appropriate timing. The priority is to know the deviations and determine their treatment. An urgent correction requires an appropriate assessment by your service provider; a complete overhaul cannot be improvised in this session. The guide to web maintenance packages helps ask for observable commitments rather than a vague promise of security.

06

Minutes 20 to 25: play a scam scenario

Present a fictitious scenario to the team: a message asks to modify a supplier's bank account or to open an urgent document. Ask what everyone would do. The objective is to bring about a common procedure, not to trap a person. Verification through an already known channel is more robust than a call to the number indicated in the suspicious message.

Decide how to report an attempt and who takes over the case. A person should be able to ask for an opinion without fear of being ridiculed. If a click or share has already occurred, rapid reporting helps limit the consequences. Keep the useful elements and get guidance from your service provider or the appropriate support services. Avoid erasing traces before understanding the situation.

07

Minutes 25 to 30: assign three actions

Choose three actions maximum for the following week. Each line includes the issue, who is responsible, the due date, and proof of completion. “Improve cybersecurity” is too vague. “Check the restoration of a test file and keep the result on Friday” allows real control. Rank first what directly threatens critical accounts and services.

Also prepare an accessible emergency form if messaging no longer works. It can indicate useful contacts, internal manager and reporting steps. Do not store this single copy in the service you fear will fail. Have the procedure validated by the service provider when the environment is complex. The session ends with a plan, not a declaration of invulnerability.

08

Review a week later

Go back to the three actions and ask for their proof. Deleted access, a restoration test and a validation procedure for banking changes are concrete results. If an action remains blocked, identify the lack: right of access, budget, information or availability. Turn this blockage into a decision rather than moving the date on the board indefinitely.

Keep this review in your management routine. New employees, new tools and changes in service provider can reopen problems that have already been resolved. Automating monitoring can help, but should not hide the absence of responsibility. Our guide to simple processes for small businesses provides a basis for organizing reminders and validations without multiplying applications.

09

Frequently asked questions

Can we really secure a small business in thirty minutes?

No. This session serves to identify priorities and initiate actions. A complete diagnosis and corrections may require additional time and appropriate skills.

Should you buy a tool before starting?

Not necessarily. Identifying accounts, verifying those responsible, and requesting proof of a restore are already useful actions with your current organization.

What to do if you suspect an attack in progress?

Proceed to the incident procedure and contact competent assistance. The awareness plan does not replace an ongoing incident response.

Where to find Cybermonth events?

Consult the official page of the 2026 edition and its agenda. Check the dates, audience and access arrangements with each organizer.

↗

Official sources

Transform reading into action.

Choose three checks with your IT manager. For your site, ISS Agency can help you clarify access, maintenance and responsibilities.

Site creation in Saint-Brieuc: services, projects and quotes →

Request the audit
Back to blog