Four Things Worth Doing in Cybersecurity Awareness Month

October is Cybersecurity Awareness Month. CISA’s 2026 public campaign is built around four actions any shop can finish without a security department: report phishing, use strong unique passwords, turn on multi-factor authentication, and keep software current.

That list is the useful part. You do not need a theme week, a poster contest, or a new product. You need four habits that survive past October 31.

1. Report phishing instead of forwarding it to a neighbor

ESET’s 2026 SMB survey put phishing at the top of reported incidents. The click is only half the problem. The other half is silence. A message that looks like a shipper, a bank, Microsoft, or “the owner needs a gift card” should go to the person who handles IT, not to the group chat.

Pick one reporting path and say it out loud in a staff meeting: the report button in Outlook, a dedicated mailbox, or a call to Solomon IT. The goal is a reported message the same day, not a perfect quiz score.

Add one sentence managers can repeat: we will never call you and ask you to read a code to keep your account active. Voice-phishing crews used that line through 2026.

2. Give each account its own password

Reused passwords turn one leaked shopping site into an open Microsoft 365 mailbox. A password manager — the company vault, not a spreadsheet on the desktop — is how a 20-person firm actually keeps unique passwords.

Start with the accounts that move money or open client, patient, or student files. Bank, payroll, email, the practice system, the accountant’s portal. Retire shared logins that several people know. If two people need the same box, they get two sign-ins or a password manager entry with an owner.

3. Turn on a second step at sign-in

Multi-factor authentication still stops a stolen password from becoming a finished takeover. An authenticator app or a passkey is the right default. A text message is weaker and is going away as a Microsoft-provided option on February 1, 2027.

Do email, remote access, payroll, banking, and every admin portal in the same week. Do not exempt the owner. Owners get phished.

Tell staff what a real prompt looks like. If they did not just try to sign in, they do not approve the prompt. They call IT.

4. Install the updates that are already waiting

Verizon’s 2026 breach report found that exploitation of known vulnerabilities is now the most common way in, at 31 percent of initial access in that dataset. Only 26 percent of items on CISA’s Known Exploited Vulnerabilities list were fully patched in 2025.

You do not need to read that catalog cover to cover. You need Windows, macOS, browsers, and the remote-access client on a schedule, plus an owner for firewall firmware. “Remind me later” is not a schedule.

A one-week version

1.      Monday: name the phishing report path and say it in a 10-minute standup.

2.      Tuesday: turn MFA on for email and admin accounts that still use a password alone.

3.      Wednesday: put bank, payroll, and the main line-of-business app into a password manager and retire shared passwords.

4.      Thursday: check last-update dates on a sample of laptops and on the firewall.

5.      Friday: write who staff call if a prompt appears and they were not signing in.

What this is not

This is not a replacement for backups, monitoring, or the compliance work HIPAA, CMMC, NIST, or PCI already require. Those stay on the calendar. Awareness Month is the week you finish the four habits that make the rest of that work cheaper.

Next
Next

Are Your Endpoints Vulnerable?