October's Cybersecurity Awareness Month provides a timely reminder to revisit security practices, but the planning should start earlier. With many public sector agencies, utilities, and aviation organizations beginning a new fiscal year on October 1, September offers a critical window to identify security priorities and connect them to upcoming budgets before spending decisions are already in motion.
For organizations operating critical infrastructure, public safety systems, or regulated environments, the cost of an unpatched system or an untested incident response plan is measured differently than it is in a typical commercial setting. Below is a practical readiness checklist to work through this September, before Cybersecurity Awareness Month.
1. Inventory and Prioritize Technical Debt
Before adding new security controls, organizations should have a clear picture of what is already exposed. This means:
- Cataloging end-of-life and unsupported software and hardware across both IT and operational technology (OT) environments
- Identifying systems where patches exist but have not been applied, and understanding why
- Ranking exposure by business impact. A legacy asset management system carries different risk than an unpatched public-facing web application
Legacy and operational systems are frequently the blind spot in otherwise mature security programs, particularly where automated compliance and asset-tracking tools create a false sense of complete coverage. A manual review of OT and field systems like SCADA, badge and access control platforms, CAD/RMS environments, and utility CIS systems should not be skipped in favor of dashboard metrics alone.
2. Revisit Your Patch Management Cadence
Recent incidents involving widely used enterprise software underscore the persistent truth that attackers continue to target known vulnerabilities in unsupported or delayed-patch environments rather than relying solely on novel exploits. Organizations should use September to:
- Confirm patch management SLAs are being met across all environments, including remote and field-deployed assets
- Validate that print, imaging, and other frequently overlooked infrastructure is included in patch scope
- Establish or refresh a formal exception process for systems that cannot be immediately patched, with compensating controls documented
3. Put Your Incident Response Plan to the Test
An incident response plan that has not been exercised in the past twelve months should be treated as unverified. A September tabletop exercise, run before the fall budget and planning cycle begins, allows findings to inform both immediate remediation and next fiscal year's investment priorities. Effective exercises should include:
- IT, operations, and executive leadership— not security staff alone
- A scenario relevant to the organization's actual risk profile (ransomware affecting a utility control system, a credential compromise in a public safety records system, or a supply chain incident affecting a shared vendor platform)
- A clear after-action process that feeds directly into budget and staffing requests
4. Reassess Identity, Access, and AI Governance
Zero Trust architecture continues to mature as the baseline expectation for public sector and critical infrastructure environments. Ahead of the new fiscal year, organizations should work to evaluate:
- Multi-Factor Authentication (MFA) coverage across all privileged and remote access points, including OT and field systems
- Access reviews for third-party vendors and contractors with standing system access
- Visibility and governance over AI agents and automation now touching service desk, monitoring, and administrative workflows, which is a newer, often under-governed attack surface that traditional endpoint and network controls were not designed to address
Organizations should ask specifically what data these tools can access, how their outputs are validated, and what governance exists before expanding adoption further.
5. Refresh Workforce Awareness Training
Awareness training loses effectiveness when it becomes routine and predictable. A September refresh — ideally tied to real, recent incidents rather than generic scenarios—better prepares staff for the phishing and social engineering campaigns that historically spike alongside Cybersecurity Awareness Month messaging in October.
Turning Readiness into a Fiscal Year Plan
For SLED agencies, utilities, aviation operators, and commercial organizations alike, the value of this exercise is not the checklist itself, but what the checklist reveals about where next fiscal year's IT and security budget should go. Findings from a September readiness review translate directly into defensible, prioritized budget requests, rather than reactive spending after an incident.
SDI Presence works with public sector, utilities, and aviation clients to assess technical debt, validate patch and access management practices, and align security investment with operational and regulatory requirements across both IT and OT environments. Contact SDI to schedule a readiness assessment ahead of the new fiscal year.














.avif)
