What Every Caribbean Business Should Do Before September: The August Cybersecurity Checklist

By Gregory Lemmon | Managing Director, UBIQUITY Ltd
Cybersecurity & Disaster Recovery Consultants to the Caribbean

August is the month Caribbean businesses cannot afford to ignore.

Historically, the most active period in the Atlantic hurricane season. Peak activity for cybercriminals who target businesses during storm disruption. The last realistic window to close security gaps before the season reaches its most intense phase.

September arrives fast. The businesses that come through the final months of hurricane season operationally intact are not the ones that planned to prepare eventually. They are the ones that used August deliberately, verifying what they had, closing what was open and building the confidence that comes from knowing rather than assuming.

This checklist covers exactly what Caribbean businesses should complete before September. Not a theoretical framework. A practical, actionable set of steps that address the specific vulnerabilities the August through October period creates.

Work through it. Verify each item. Note what needs attention. The gaps identified now are fixable. The gaps identified in October, under pressure, mid-incident, are significantly more expensive.

Section 1: Backup and Recovery

Verify your backup is actually running

Do not assume. Log into your backup platform and confirm that automated backups have been running successfully. Check the logs, not just the status indicator. Many backup failures go undetected because the dashboard shows green while the underlying jobs have been silently failing.

Conduct a restoration test

Select a non-critical system or a sample of files and restore them from backup. Time the process. Document how long it takes and what steps are involved. If you have never done this before, this is the single most important item on this entire checklist. A backup that has never been restored is an assumption. A restoration test turns it into verified capability.

Confirm your backup is offsite

Data backed up to a drive or server in the same physical location as your primary systems faces the same physical risks: flooding, power surge, theft. Confirm that your backup exists in a cloud environment or physical location that a Caribbean hurricane cannot reach simultaneously with your primary office.

Check your Microsoft 365 backup

Microsoft’s built-in retention policies are not a backup. If your business runs on Microsoft 365 and you do not have an independent backup solution in place, email, SharePoint, Teams and OneDrive data is not as protected as you believe. Verify this specifically.

Define your recovery time

How long would it actually take to restore your systems fully following a complete failure? If you do not have a specific, tested answer to this question, you do not have a recovery plan. You have a hope.

Section 2: Access and Identity

Audit every active user account

Pull a full list of active accounts across every platform your business uses email, cloud storage, financial systems, project management tools, CRM, remote access. Cross-reference against your current staff list. Every account belonging to a former employee or contractor that remains active is an uncontrolled access point. Revoke access for anyone who is no longer with the business immediately, not on a schedule.

Verify Multi-Factor Authentication is active on every account

Check every critical business account email, banking, accounting software, cloud platforms, remote access systems. MFA should be active for every user on every platform without exception. A single account without MFA is a single account away from a breach that MFA would have prevented.

Review privileged and administrative access

Who in your business has administrative access to critical systems? Is that access still appropriate for their current role? Administrative accounts should be limited strictly to those who require them for their specific responsibilities. Every additional admin account is an additional attack surface.

Change shared passwords

If any business accounts use shared passwords on platforms accessed by multiple staff members using the same credentials, those passwords should be changed and individual accounts created where possible. Where individual accounts are not available, use a password manager to manage shared access without exposing the underlying credential.

Section 3: Remote Work Security

Test full remote work capability

Before September, run a practical test. Have your entire team attempt to access everything they need to do their jobs from outside the office using the same devices and connections they would use during a hurricane event. Identify what works, what fails and what gaps exist. Finding these gaps during a controlled test costs nothing. Finding them during a storm recovery costs significantly more.

Verify VPN access for every remote worker

Every staff member who may work remotely during or after a storm event should have a working VPN connection to the business network. Test each one individually. Do not assume that because VPN was set up previously, it is still functioning correctly for every user.

Confirm MFA is working on remote access systems

Remote access without MFA is one of the most consistently exploited vulnerabilities in Caribbean businesses during hurricane season. Verify that MFA is active and working on every remote access point not just configured, actively working for every individual user.

Check device security for remote devices

Every device that will be used for remote work should have endpoint security software active and current, the operating system fully patched and device encryption enabled. A personal laptop used for business access during storm recovery that lacks these controls is a significant vulnerability.

Section 4: Cybersecurity Controls

Confirm endpoint protection is active on every device

Endpoint security software should be running on every device that connects to your business network, including devices that are primarily used outside the office. Check that definitions are current and that no devices have fallen out of scope.

Review email security configuration

Email remains the primary attack vector for cybercriminals targeting Caribbean businesses during hurricane season. Confirm that your email security solution is configured to filter not just known threats but behavioural indicators the AI-generated phishing attempts that standard spam filters consistently miss.

Check patch status across all systems

Every operating system and application running in your business should be current. Unpatched software with known vulnerabilities is an open door that requires no sophistication to walk through. Run a patch status check across every system and schedule any outstanding updates immediately.

Review firewall rules

When did someone last review your firewall configuration? Firewall rules accumulate over time: rules added for specific purposes that are no longer relevant, remote access exceptions that were temporary and became permanent. A firewall review before peak season confirms that only the access that should be permitted is permitted.

Section 5: Staff Preparedness

Brief your team on post-storm phishing

Before peak season, every member of staff should receive a specific briefing on what to expect in the days following a storm event. Insurance notification emails. Government relief applications. Supplier banking updates. IT system restoration notices. They need to know what these look like, why they are suspicious and what the procedure is before clicking any link or making any payment.

Establish a payment verification procedure

Any payment instruction received during or immediately following a storm event regardless of who it appears to come from should require voice verification from a known number before being processed. This single procedure stops the majority of business email compromise attempts that target Caribbean businesses in the post-storm window.

Confirm your incident response contacts

Who does your team call if something goes wrong at 2am during hurricane recovery? Make sure that answer is documented, accessible and known to every relevant person in the business before it becomes an urgent question.

Section 6: Cyber Insurance

Review your policy before September

If your business carries cyber liability coverage, review the policy before peak season. Confirm what is covered, what the exclusions are and what security controls are required as conditions of coverage. Many Caribbean businesses discover gaps in their coverage at the point of a claim. Discovering them in August, when there is still time to act, is significantly preferable.

If you do not have cyber liability coverage have that conversation now

The Caribbean insurance market for cyber liability has developed significantly. Coverage is more accessible for small and medium businesses than many assume. The post-storm period is when businesses are most likely to need it which makes August the right time to ensure it is in place.

Before September: A Final Check

Work through this checklist before the end of August. For each item, mark one of three responses:

Verified – confirmed working, documented, tested where applicable.

Needs attention – identified, owner assigned, timeline defined.

Not in place – gap acknowledged, action required before September.

The goal is not a perfect score. The goal is clarity knowing exactly where the business stands rather than operating on assumptions that have never been tested.

The businesses that come through the August through October period operationally intact are the ones that used August to find out what they did not know  while there was still time to do something about it.

UBIQUITY Ltd provides cybersecurity and disaster recovery services to Caribbean businesses. If working through this checklist surfaces questions about your current setup we are available for a direct conversation.

Contact Us- 

Email: info@ubiquityltd.com

Phone: +1 (284) 547-6754

Calendly Link- https://calendly.com/glemmon-wpi/15min?month=2026-07