October’s annual cybersecurity campaign arrives with a familiar message: protect accounts, recognise scams and keep software updated. But the evidence accompanying Cybersecurity Awareness Month 2026 raises a more demanding question for business leaders and public authorities: how much of that advice has become everyday practice?
TheNational Cybersecurity Alliance’s 2026 campaignadopts the theme “Don’t Make It Easy for Them”, encouraging consistent habits that make life harder for cybercriminals. Its core recommendations cover strong passwords and password managers, multifactor authentication, recognising and reporting scams, and software updates.
These are sensible foundations. Yet an awareness campaign achieves little if employees return from training to unsupported software, inadequate account protection, confusing reporting procedures or management that treats security as someone else’s responsibility.
October should provide a public checkpoint for decisions that continue throughout the year. The standard of success should be whether people and organisations become demonstrably harder to compromise, and better prepared to recover.
A Longstanding Campaign Faces a Persistent Implementation Gap
Launched in 2004, Cybersecurity Awareness Month has become an established opportunity to bring online safety into workplaces, schools and communities. The National Cybersecurity Alliance identifies itself and the US Cybersecurity and Infrastructure Security Agency as campaign leaders. Europe has its own October initiative,European Cybersecurity Month, supported by ENISA and the European Commission.
That international reach matters. A stolen account, compromised supplier or fraudulent payment can affect organisations across borders. Awareness therefore needs to translate across languages, working environments and levels of technical confidence.
Recent European findings expose the distance between recognising a problem and giving people the means to address it. In itsworkplace cybersecurity briefing, ENISA reports that 74% of employees surveyed had received suspicious emails, messages or links at work during the preceding six months. Only 45% said their organisation sent regular cybersecurity information or awareness updates.
ENISA also reports that 85% were interested in improving their skills, while 26% identified finding time at work as a training obstacle. These are survey responses, rather than independently verified measures of organisational security. Nevertheless, they challenge the assumption that employee indifference is the central problem.
Employers asking people to learn must make room for learning. Guidance squeezed between competing deadlines, without practical support, is unlikely to become a reliable working habit.
The Statistics Demand Careful Reading—and a Stronger Response
TheUK Government’s Cyber Security Breaches Survey 2025/2026, published in April, found that 43% of businesses and 28% of charities had identified a cybersecurity breach or attack in the previous 12 months. Phishing was reported by 38% of businesses and 25% of charities.
Those figures must not be presented as the percentage of organisations successfully hacked. The survey includes attempted attacks, including the receipt of fraudulent emails. Nor does an organisation reporting no attack necessarily establish that none occurred: the findings concern what respondents identified.
The preparedness figures are particularly revealing. Only 25% of businesses and 19% of charities reported having a formal incident response plan.
The editorial implication is straightforward. Organisations should judge awareness alongside their ability to act when something goes wrong. A worker may recognise a suspicious request but still be unsure whom to contact. A manager may understand ransomware yet lack an agreed process for operating without access to essential systems.
Knowledge becomes useful when it is connected to authority, resources and a rehearsed response.
Employees Need Support, and Systems Need Safeguards
The language used in awareness campaigns deserves scrutiny. Describing people as the weakest link can become an excuse to overlook the conditions in which mistakes happen.
TheUK National Cyber Security Centre’s phishing guidanceexplicitly warns against placing too much emphasis on users spotting malicious emails. It recommends layered defences and cautions that employees who fear reprisals may delay reporting mistakes or fail to report them altogether.
That has practical consequences for October’s activities. Simulations should help reveal where controls and procedures need improvement. Training should give people confidence to report uncertainty, including after clicking a link or disclosing information.
A reporting process should be easy to find, quick to use and supported by a constructive response. Employees should know what happens next, rather than wondering whether they have triggered a disciplinary process.
This does not remove individual responsibility. It makes responsible action easier. An organisation that invites early disclosure gives itself a better opportunity to investigate and contain a problem.
The most useful question after a mistake is what allowed it to become dangerous, and which safeguards could limit the consequences next time.
The Threat Extends Beyond the Inbox
Awareness campaigns often centre on phishing because it is easy to demonstrate. However, the wider evidence makes clear that organisations also need to address weaknesses employees cannot fix.
Verizon’s 2026 Data Breach Investigations Report announcementidentifies vulnerability exploitation as the initial entry point in 31% of breaches, surpassing stolen credentials. It also reports third-party involvement in 48% of breaches.
These findings describe Verizon’s analysed dataset, rather than the likelihood that any individual organisation will be breached. Thereport’s methodology informationstates that in-scope incidents for the 2026 edition occurred between 1 November 2024 and 31 October 2025.
Even with those boundaries, the message for leadership is significant. Employee education cannot compensate for a vulnerable internet-facing system, an unmanaged supplier account or a critical service that nobody has responsibility for maintaining.
October should therefore include questions for technology owners and procurement teams. Which systems are exposed? Who can authorise urgent remediation? Which suppliers have access to sensitive information? What happens if a service provider is unavailable?
Those questions turn a public awareness campaign into a review of operational responsibility.
Account Security Must Move Beyond Slogans
Strong passwords and multifactor authentication remain central to public guidance. But awareness programmes should explain the protection available without suggesting that every authentication method offers identical security.
NIST’s password and account-security guidanceexplains the value of password managers and notes that MFA methods vary in strength. It also describes how passkeys reduce exposure to password phishing.
For organisations, the relevant question is whether people can use stronger protection consistently. Recommending secure authentication has limited value if important systems lack support, administrators retain exceptions or staff are left to navigate enrolment without help.
A useful October exercise would connect education with implementation: help employees protect their accounts, check coverage of essential services and identify systems needing improvement.
Account recovery deserves attention too. Managers should ask how identity is verified when someone loses access, who can approve a reset and whether the process can withstand pressure from an urgent caller.
The objective is a dependable account lifecycle, from initial registration to recovery and removal. A poster about strong passwords covers only part of that responsibility.
AI Makes Practical Guidance More Urgent
Artificial intelligence also needs a place in awareness programmes, with care taken to separate evidence from speculation.
Verizon’s 2026 findings describe attackers using AI to accelerate exploitation and identify unapproved workplace AI use as a data-leakage concern. They also highlight social engineering through mobile messages and voice calls.
The practical response should focus on decisions people actually face. An employee needs to know which AI services are approved, what information may be entered and where to seek advice about a new tool. Broad warnings about AI offer little help when a team is under pressure to work faster.
Organisations should explain how to verify consequential requests received by email, messaging service or telephone. For example, a request to change payment details should follow an established verification process using independently known contact information.
These procedures should apply regardless of whether the attempted deception involves AI. Requiring staff to determine how a message was generated adds complexity without resolving the underlying question of whether the request is authorised.
Good awareness gives people a reliable action to take when authenticity is uncertain.
Boards Should Measure Outcomes
TheNIST Cybersecurity Framework 2.0includes governance alongside identifying, protecting against, detecting, responding to and recovering from cyber risk. That structure provides a useful foundation for executive engagement during awareness month.
Boards should ask for evidence of progress that connects to business exposure. Training completion records are useful, but they cannot establish whether critical accounts are protected, urgent vulnerabilities are resolved or essential services can be restored.
A more meaningful review would examine unresolved security exceptions, the coverage of account protections, response times to credible reports and the results of recovery exercises. Each finding should have an owner and a realistic deadline.
This is an editorial recommendation for how to use October, rather than a universal reporting template. A small charity and a multinational manufacturer require different levels of detail. Both, however, need to understand their essential services and who is responsible for protecting them.
Cybersecurity awareness should reach the people who approve budgets, select suppliers and accept operational risk. Their decisions shape the environment in which everyone else works.
Recovery Must Be Part of the Campaign
Prevention deserves attention, but the ability to recover is equally important. An organisation can understand cyber risk and still discover, during an incident, that its emergency arrangements depend on the very systems it has lost.
TheNCSC’s ransomware guidancerecommends regular backups and testing restoration. Itsransomware-resistant backup principlesalso emphasise monitoring and testing backup health.
For leaders, that should prompt an exercise grounded in business operations. Can teams communicate if corporate email is unavailable? Can essential records be accessed safely? Who decides which services are restored first? How will customers and staff receive reliable information?
Exercises do not need to be elaborate to expose uncertainty. A discussion involving technology, operations, communications and leadership can reveal missing contacts, unclear authority and unrealistic assumptions.
The value comes from correcting those findings. An exercise that produces a report but no changes risks becoming another annual ritual.
Cybersecurity Best Practices: Turning Awareness Into Everyday Protection
Cybersecurity Awareness Month is an opportunity to establish practical safeguards that remain effective throughout the year. Priorities for individuals and organisations include:
- Use strong, unique passwords:Create a different password for every account and use a password manager to generate and store credentials securely. Reusing passwords allows a compromise at one service to put other accounts at risk.
- Enable multifactor authentication:Add protection beyond a password, particularly for email, financial services and business systems. Use phishing-resistant options, such as passkeys or security keys, where supported.NIST’s account-security guidanceexplains why password strength alone is insufficient.
- Keep software and devices updated:Apply security updates promptly and replace products that no longer receive security support. Organisations should maintain an inventory of systems, assign responsibility for patching and verify that updates have been deployed successfully.
- Prioritise exposed and actively exploited vulnerabilities:Give urgent attention to weaknesses affecting internet-facing services and those already being exploited by attackers. Follow theNCSC’s malware and ransomware guidanceto strengthen protection across systems.
- Verify unusual or sensitive requests:Independently confirm unexpected instructions to transfer money, change payment details, disclose information or reset accounts. Use an established contact route rather than details supplied in the suspicious message.
- Make reporting quick and supportive:Give employees a clear way to report suspicious activity, including after clicking a link or sharing information. TheNCSC’s phishing guidancerecommends layered safeguards and warns that a blame-oriented culture can discourage timely reporting.
- Limit access and administrative privileges:Give staff and suppliers only the permissions they need. Review access regularly, remove unnecessary privileges and revoke access promptly when people leave. Keep administrative accounts separate from everyday activity.
- Back up important information and test recovery:Maintain backups protected against attacker interference, and regularly check that essential data can be restored. TheNCSC’s backup guidanceemphasises testing and monitoring; a backup notification alone does not establish recovery readiness.
- Prepare and rehearse an incident response plan:Establish who makes decisions, how employees report incidents and how essential operations will continue during disruption. Exercises should identify gaps and lead to specific improvements.
For leadership teams, these measures should become assigned responsibilities, funded improvements and routine checks. October should end with evidence of stronger protection—and a clear schedule for maintaining it. October Should Leave a Lasting Result
Conclusion
Cybersecurity Awareness Month remains valuable because it creates a shared opportunity to discuss a subject that can otherwise be crowded out by immediate priorities.
Its lasting impact depends on what follows. Individuals need understandable advice and accessible support. Employees need time, suitable tools and confidence to report mistakes. Technology teams need ownership and resources. Leaders need evidence that commitments have become working protections.
Organisations should finish October able to identify specific improvements: stronger account security, clearer reporting, a resolved exposure, a tested recovery process or a supplier risk that now has an accountable owner.
“Don’t Make It Easy for Them” is a useful call to action. Its strongest interpretation places responsibility across the organisation, including those who design systems and make investment decisions.
The test arrives in November, when the campaign materials come down. The protections, habits and accountability should remain.