Cybersecurity Awareness Month Is Here: Securing the Next 250

CISA's core steps for 2026, plus a quick guide to picking the right HITRUST tier.

Cybersecurity Awareness Month:
Securing the Next 250

October is Cybersecurity Awareness Month! Cyber threats are moving faster than ever. New and evolving technology, AI included, is giving bad actors a faster way to find and exploit weak spots in the systems businesses rely on every day. That puts organizations, their customers, and the broader economy at risk.

The good news: most of what actually reduces risk is not complicated. It just requires commitment.

Four Core Steps Everyone Should Take

CISA's baseline recommendations apply to every organization, regardless of size:

  • Avoid and report phishing scams

  • Use strong passwords

  • Use multifactor authentication and a password manager

  • Keep software updated

If your team is not doing these four things consistently, that is the place to start, not a bigger initiative down the road.

For Organizations Ready to Go Further

Beyond the basics, CISA recommends:

  • Logging activity across your systems

  • Backing up data regularly

  • Encrypting data at rest and in transit

  • Reporting cyber incidents to CISA

  • Having a tested incident response plan

  • Preparing for system disruptions before they happen

The 3 Rs, for Critical Infrastructure and Beyond

For organizations running critical systems, CISA's framework comes down to three moves: reduce your attack surface, replace devices that are past end of support, and recover quickly when something does go wrong. The same logic applies to any organization handling sensitive data, not just critical infrastructure. Smaller attack surface, fewer outdated systems, faster recovery, less damage.

Securing the Next 250 with VanRein

Every item on this list, phishing awareness, MFA, backups, incident response planning, is also a piece of your HIPAA Security Rule obligations. That overlap is not a coincidence. Good cybersecurity hygiene and HIPAA compliance point at the same target: knowing where your data lives, who can touch it, and what happens when something goes wrong.

This is the work we do with our clients year-round, not just in October. A tested backup is also a Security Rule safeguard. An incident response plan is also audit evidence. A reduced attack surface is also fewer findings on your next risk analysis.

Securing the next 250 is not a one-month effort. It is a commitment organizations make and keep. If you want a partner to help you build that commitment into something real, measurable, and ready to show an auditor or a customer, that is exactly where we come in.

HITRUST e1 vs. i1 vs. r2:
Which One Does Your Business Need?

If a customer, health system, or partner has told you that you need to be "HITRUST certified," there's an important follow-up question: which assessment do they actually mean?

HITRUST offers three validated certifications, each a different level of assurance:

e1

i1

r2

Focus

Essential cybersecurity

Broader implemented practices

Comprehensive, risk-based

Requirements

44 statements

182 statements

Risk-based and tailored

Valid for

1 year

1 year

2 years (with interim check)

Best fit

Early-stage or lower-complexity organizations

Growing companies facing stronger vendor-risk requirements

Complex environments or contracts that specifically require it

Picking the right tier matters more than picking the cheapest or the most comprehensive one. Completing an e1 when a customer expects an i1 doesn't solve the problem. Funding an r2 when e1 would have satisfied every requirement is money spent on assurance nobody asked for.

Done right, HITRUST pays for itself: fewer repeated security questionnaires, faster enterprise sales cycles, and no wasted spend on the wrong tier or an assessment you weren't ready for.

That readiness is where we come in. We help you determine which tier fits your actual risk and customer requirements, close gaps before an assessor ever sees your environment, and prepare the evidence you'll need to walk in ready instead of guessing.

If HITRUST has come up with one of your customers, let's talk through which path actually fits.

Reply

or to participate.