- VanRein Compliance
- Posts
- Cybersecurity Awareness Month Is Here: Securing the Next 250
Cybersecurity Awareness Month Is Here: Securing the Next 250
CISA's core steps for 2026, plus a quick guide to picking the right HITRUST tier.

Cybersecurity Awareness Month:
Securing the Next 250
October is Cybersecurity Awareness Month! Cyber threats are moving faster than ever. New and evolving technology, AI included, is giving bad actors a faster way to find and exploit weak spots in the systems businesses rely on every day. That puts organizations, their customers, and the broader economy at risk.
The good news: most of what actually reduces risk is not complicated. It just requires commitment.
Four Core Steps Everyone Should Take
CISA's baseline recommendations apply to every organization, regardless of size:
Avoid and report phishing scams
Use strong passwords
Use multifactor authentication and a password manager
Keep software updated
If your team is not doing these four things consistently, that is the place to start, not a bigger initiative down the road.
For Organizations Ready to Go Further
Beyond the basics, CISA recommends:
Logging activity across your systems
Backing up data regularly
Encrypting data at rest and in transit
Reporting cyber incidents to CISA
Having a tested incident response plan
Preparing for system disruptions before they happen
The 3 Rs, for Critical Infrastructure and Beyond
For organizations running critical systems, CISA's framework comes down to three moves: reduce your attack surface, replace devices that are past end of support, and recover quickly when something does go wrong. The same logic applies to any organization handling sensitive data, not just critical infrastructure. Smaller attack surface, fewer outdated systems, faster recovery, less damage.
Securing the Next 250 with VanRein
Every item on this list, phishing awareness, MFA, backups, incident response planning, is also a piece of your HIPAA Security Rule obligations. That overlap is not a coincidence. Good cybersecurity hygiene and HIPAA compliance point at the same target: knowing where your data lives, who can touch it, and what happens when something goes wrong.
This is the work we do with our clients year-round, not just in October. A tested backup is also a Security Rule safeguard. An incident response plan is also audit evidence. A reduced attack surface is also fewer findings on your next risk analysis.
Securing the next 250 is not a one-month effort. It is a commitment organizations make and keep. If you want a partner to help you build that commitment into something real, measurable, and ready to show an auditor or a customer, that is exactly where we come in.
HITRUST e1 vs. i1 vs. r2:
Which One Does Your Business Need?
If a customer, health system, or partner has told you that you need to be "HITRUST certified," there's an important follow-up question: which assessment do they actually mean?
HITRUST offers three validated certifications, each a different level of assurance:
e1 | i1 | r2 | |
|---|---|---|---|
Focus | Essential cybersecurity | Broader implemented practices | Comprehensive, risk-based |
Requirements | 44 statements | 182 statements | Risk-based and tailored |
Valid for | 1 year | 1 year | 2 years (with interim check) |
Best fit | Early-stage or lower-complexity organizations | Growing companies facing stronger vendor-risk requirements | Complex environments or contracts that specifically require it |
Picking the right tier matters more than picking the cheapest or the most comprehensive one. Completing an e1 when a customer expects an i1 doesn't solve the problem. Funding an r2 when e1 would have satisfied every requirement is money spent on assurance nobody asked for.
Done right, HITRUST pays for itself: fewer repeated security questionnaires, faster enterprise sales cycles, and no wasted spend on the wrong tier or an assessment you weren't ready for.
That readiness is where we come in. We help you determine which tier fits your actual risk and customer requirements, close gaps before an assessor ever sees your environment, and prepare the evidence you'll need to walk in ready instead of guessing.
If HITRUST has come up with one of your customers, let's talk through which path actually fits.






Reply