Opens in a new tab

NEW ARTICLE: The Security Gaps to Fix (Yesterday) Read Now

Supporting organizations across the entire U.S.

The Security Gaps to Fix (Yesterday)

Cybersecurity

Written by

David McBride

Published on

Cybersecurity Awareness Month falls every October, and for most businesses it works out to be the one dedicated moment each year to step back and ask whether their defenses actually hold up. The timing is useful: close enough to year-end that whatever the review turns up can still be fixed before budgets reset and attention moves on to the next twelve months. What that review tends to surface is rarely a sophisticated new threat. It is usually the same handful of ordinary weaknesses that were flagged the year before, and the year before that, and never quite got closed: a login process that still relies on a password alone, a backup nobody has tried to restore from, a server running software that has not been updated since it was installed, an account that still has access it no longer needs, an employee who has not had security training since the day they were hired.

The 2026 Verizon Data Breach Investigations Report puts a number on how often that pattern repeats, and the direction it is moving in. The report found that only 26% of vulnerabilities in the CISA Known Exploited Vulnerabilities catalog were fully remediated by organizations in 2025, down from 38% the year before, and that the median time to fully resolve a vulnerability stretched to 43 days, up from 32. Ransomware, meanwhile, climbed to 48% of all breaches, up from 44%. The data points to a widening gap: known vulnerabilities are taking longer to remediate while threats such as ransomware remain widespread. That gap creates more opportunity for attackers to act before known weaknesses are closed.

None of the weaknesses behind that gap require a specialized attacker or a novel technique. They require only that nobody got around to fixing them.

The CISA Cross-Sector Cybersecurity Performance Goals treat exactly five areas as baseline expectations rather than advanced practices: multifactor authentication, tested backups, patch management, access control, and security awareness training. That framing matters for a business leader deciding where to spend a limited amount of time and budget before year-end. These are not the frontier of cybersecurity. They are the floor, and for a large share of small and midsize businesses, the floor still has gaps in it.

The rest of this article works through each of those five gaps in turn: what the data says about how often it goes unaddressed, why it matters in practical business terms, and what closing it actually requires. Each one is addressable within a matter of weeks, treating a known weakness as something to fix this quarter rather than something to revisit next year.

#1) Multifactor Authentication: Closing the Door Attackers Still Walk Through

Stolen or compromised credentials no longer top the list of ways attackers first get into a network. The 2026 Verhttps://99ten.com/cybersecurity-risk-assessment-discovery-programizon DBIR found that credential abuse as an initial access vector fell to 13% of breaches, down from 22% the year before, partly because this year’s report began tracking pretexting as its own category, pulling some credential-related incidents out of that count. Credentials have not left the picture, though: when every instance of credential abuse across the course of a breach is counted, not just how attackers first got in, the figure rises to 39%, still the most pervasive technique the report tracks. A username and password combination, once obtained through a phishing email, a data breach at another company, or simple guesswork, is often all it takes for an attacker to move deeper into a business’s systems once inside.

Multifactor authentication for small businesses closes that gap by requiring a second form of verification beyond the password itself, and the CISA Cross-Sector Cybersecurity Performance Goals are specific about which forms are strongest: hardware-based options such as FIDO or WebAuthn security keys first, mobile authenticator apps with push notifications second, and SMS text codes only as a last resort, since text messages can be intercepted or redirected more easily than an app-based or hardware-based credential. The goals call for MFA on all IT accounts accessing organizational resources, not a subset chosen for convenience.

The same Verizon report found a related and more specific failure: 37% of organizations had at least one admin account with MFA disabled on a cloud infrastructure platform. An administrator account carries the broadest access in an environment, which makes it the most valuable target and the account where a password-only login is the most expensive mistake to leave in place. Reviewing which accounts, especially administrative ones, still lack a second authentication factor is a short, concrete project, not a multi-quarter initiative.

#2) Backups You Have Never Actually Tested

Ransomware grew to 48% of all breaches in the 2026, up from 44% the year before, making it the single most common type of breach the report tracks. A backup is the difference between a ransomware event that costs a few days of recovery and one that costs a ransom payment, an extended outage, or both.

CISA’s #StopRansomware Guide is direct about why a backup that has never been tested is not a reliable backup at all: organizations should “test backup procedures on a regular basis” and verify that data can actually be restored, not just that a backup job completed without an error message. The guide also warns that many ransomware variants are built specifically to find and delete or encrypt any backup they can reach on the network, which is why it recommends keeping backups offline or in immutable storage, separated from the systems they protect, so that a single compromise cannot reach both the original data and the copy meant to restore it.

For most businesses, the practical fix is a scheduled restoration drill, run at least annually as the CISA performance goals recommend, that confirms a specific system can actually be brought back from a specific backup within a specific amount of time. A drill like that tells a business whether its backup strategy works. Without it, a business knows only that a backup exists.

#3) Patch Management: Closing the Window Before It Closes on You

Cybersecurity patch management has always been described as a race against attackers, but the 2026 Verizon DBIR shows that race tilting further out of businesses’ favor. Only 26% of vulnerabilities in the CISA Known Exploited Vulnerabilities catalog were fully remediated by organizations in 2025, down sharply from 38% a year earlier, and the median time to fully resolve a vulnerability rose to 43 days, up from 32. Both numbers describe organizations falling further behind on exactly the vulnerabilities attackers are already using, not the much larger set that may never be exploited at all.

The CISA Known Exploited Vulnerabilities catalog exists precisely so organizations do not have to guess which vulnerabilities matter most. The Cross-Sector Cybersecurity Performance Goals call for patching every known exploited vulnerability on internet-facing systems within a risk-informed timeframe, prioritizing the most critical assets first, and applying compensating controls such as network segmentation or added monitoring on systems that cannot be patched immediately.

For an SMB, this reframes patching from an endless list to a manageable one. Instead of asking whether every piece of software is current, the more useful question is whether any system exposed to the internet is running a vulnerability that CISA has already confirmed is being exploited. That is a narrower, checkable list, and closing it before year-end addresses the risk that the data shows is actually growing.

#4) Access Nobody Has Revisited

Every employee who joins a business is granted access to the systems their role requires. Far fewer businesses have a routine for removing access once a role changes or an employee leaves, which is how accounts accumulate permissions nobody is actively using and nobody has reviewed.

The Cross-Sector Cybersecurity Performance Goals treat this as a core, checkable control: separate user accounts for administrative actions rather than day-to-day work, unique credentials for every service rather than shared logins, and revocation of a departing employee’s access “by the day of their departure,” not at the next convenient audit. The same admin accounts flagged earlier as missing MFA are a reasonable place to start: the accounts with the broadest permissions are often the ones that go the longest without a fresh look at who still needs them.

Closing this gap before year-end takes a specific, time-bound exercise: listing every account with administrative or elevated privileges, confirming that person still needs that level of access, and removing what nobody can justify. For most SMBs, this single review is one of the more manageable items on a small business cybersecurity checklist, and it is one that directly reduces how much damage a single compromised account can do.

#5) Employee Awareness: The Gap That Touches All the Others

The human element was present in 62% of breaches, up from 60% the year before, whether through a phishing email that succeeded, a password reused across accounts, or a mistaken click. That figure connects directly back to the other four gaps on this list: a phishing email that harvests a password is precisely what multifactor authentication is meant to stop, and an employee who understands why a login request looks suspicious is a second line of defense behind the technical controls a business puts in place.

The Cross-Sector Cybersecurity Performance Goals set a specific, recurring bar here too: annual training for all employees and contractors covering phishing, business email compromise, and password practices, with new hires receiving initial training within 10 days of starting. A single training session delivered once, years ago, does not meet that bar, and it does not reflect how the threats employees actually encounter have continued to change.

Of the five gaps in this article, employee awareness is the one most likely to already have some program behind it. The relevant question before year-end is not whether training exists, but when it last happened, and whether it covered the tactics, such as AI-assisted phishing and business email compromise, that are actually in use today.

Five Fixes, One Deadline

None of the five gaps covered here are complicated to describe: multifactor authentication, tested backups, patch management, access review, and employee awareness training. What the 2026 Verizon DBIR shows is that they remain common anyway, and that on at least two of them, patch remediation and human-element involvement, the trend is moving in the wrong direction rather than the right one.

Addressing all five before year-end means closing the specific, known weaknesses that data shows attackers are already using, before those gaps carry into another year of exposure. A business that fixes these five items has materially reduced its risk, even if its broader security program still has room to grow.

Most SMBs do not have a dedicated security team monitoring which of these gaps has quietly reopened, tracking new employee onboarding against training schedules, or confirming that last quarter’s backup would actually restore a critical system today. A technology partner that specializes in this work can run that assessment, prioritize the fixes that matter most, and confirm each one is actually closed rather than just scheduled.

Cybersecurity: Closes the specific authentication, access, and awareness gaps attackers are already using to get in.

Cloud Solutions: Builds and tests backups that actually restore critical systems when ransomware strikes. 

IT Infrastructure & Management: Tracks which systems are running known exploited vulnerabilities and closes the window before attackers do.

👉 If your organization is ready to close its highest-priority security gaps before the year ends, our team is ready to help you take the next step.