- October 9, 2026
- Selina Wilson
- 0
October is Cyber Security Awareness Month and the theme this year is “Don’t Make It Easy For Them”. It got us thinking about some of the security fundamentals organisations can still struggle with. With so much attention on AI, increasingly sophisticated attacks and emerging threats, getting the basics right remains one of the most effective ways to make life harder for attackers.
In Part 1, we’re discussing passwords, working in public, user access and patch management.
Poor password management
Forcing employees to change their passwords every 60 or 90 days can actually encourage predictable password behaviour. Faced with remembering another new password, users may make small changes to one they already know rather than creating something genuinely different.
This is backed up by the NCSC, which advises organisations not to automatically expire passwords, instead requiring a change when there is an indication or suspicion that a password has been compromised. It also recommends reducing the password burden through approaches such as password managers.
PointWire recommends: Move away from relying on regular password changes alone. Consider password managers, MFA and, where appropriate, passkeys and biometrics to strengthen authentication while making it easier for employees to work securely.
Not being aware of your surroundings
Commuting and business travel remain a normal part of working life. Whether it’s checking emails on a train, making finishing touches to a presentation at the airport or opening a document in a café, work doesn’t always happen in the office.
But working in public introduces different risks. Sensitive information may be visible to the person sitting beside you, while connecting through an untrusted network can introduce unnecessary exposure.
The NCSC warns that connecting to public Wi-Fi or insecure networks can allow an attacker on the same network to intercept or modify data.
PointWire recommendation: Give employees clear guidance for working in public. Privacy screens can help prevent information being overlooked, while organisations should have an appropriate secure connectivity approach for employees accessing corporate systems remotely.
Not reviewing user access
Employees need access to data to do their jobs. The problem arises when that access follows them indefinitely.
Someone may move departments, take on a different role or leave the organisation altogether. Without an effective Joiners, Movers and Leavers (JML) process, access that was once necessary could remain long after it’s required.
That can leave employees with access to information and systems that are no longer relevant to their role.
PointWire recommendation: Regularly review access permissions across your environment, particularly when employees change roles or departments. Make removing access part of the leaver process rather than something that happens retrospectively.
Not Patching or slow patching
Patching might be one of cybersecurity’s oldest fundamentals, but that doesn’t make it any less important.
Known vulnerabilities give attackers an opportunity that, in many cases, organisations already know how to close. The challenge isn’t simply identifying patches. It’s understanding which systems need them, prioritising risk and deploying updates without unnecessarily disrupting the business.
The NCSC describes vulnerability management as a critical control and recommends that organisations apply updates as soon as possible, ideally automatically, while prioritising vulnerabilities according to risk.
And this is becoming more pressing. In May 2026, the NCSC warned organisations to prepare for a “vulnerability patch wave”, recommending that organisations prepare to patch quickly, more frequently and at scale.
PointWire recommendation: Make patching part of business as usual. Establish a consistent process for identifying, prioritising, testing, deploying and verifying updates. Where internal resources are stretched, consider whether a managed patching service can help reduce the burden on your security and IT teams.
If you’re not sure where to start with your cyber security, give PointWire a call and we can assess your current environment, make recommendations for improvement and support along the way.

