Skip to content
Cyber Defense Technologies

Insights

Cybersecurity Awareness Month: Four Habits That Still Stop Most Attacks

October is Cybersecurity Awareness Month. Most successful attacks still begin with a weak password, a missing patch or a convincing message. Four everyday habits, and how organizations can make them stick beyond October.

By Cyber Defense Technologies October 1, 2026 5 min read

Every October, governments, companies and schools mark Cybersecurity Awareness Month. It began in 2004 and is led in the United States by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance. The month is a reminder that security is not only the job of a security team. Most attacks still need a person to make a mistake, reuse a password or delay an update.

The advice can sound basic. That is the point. Advanced attackers exist, but most intrusions still start with something simple: a stolen password, a click on a convincing link, or a system that was never patched. Attackers take the easiest way in, and the four habits below close the easiest ways.

Four habits from CISA's Secure Our World campaign

  • Use strong, unique passwords and a password manager
  • Turn on multifactor authentication, phishing-resistant where possible
  • Recognize phishing and report it quickly
  • Keep software updated, automatically where possible

1. Use strong, unique passwords and a password manager

Reused passwords are one of the most common ways attackers get in. When one website is breached, attackers try the same email address and password everywhere else, a technique called credential stuffing. A password that is long and unique to each account stops that cold.

Nobody can remember dozens of long, unique passwords, which is why password managers matter. A password manager generates and stores strong passwords, fills them in only on the correct websites, and can warn you when a stored password appears in a known breach.

For organizations:

  • Provide an approved enterprise password manager rather than leaving people to choose their own.
  • Check new passwords against lists of known breached passwords, as NIST's digital identity guidelines recommend.
  • Stop forcing frequent arbitrary password changes, which push people toward predictable patterns, and change passwords when there is evidence of compromise.

2. Turn on multifactor authentication

Multifactor authentication (MFA) requires something beyond a password, such as an app prompt, a security key or a smart card. Even if a password is stolen, the attacker still needs the second factor.

Not all MFA is equal. Codes sent by text message and simple push notifications are far better than nothing, but attackers can phish one-time codes in real time or flood a user with push requests until they approve one. Phishing-resistant methods, such as FIDO2 security keys, passkeys and PIV or CAC smart cards, cannot be replayed on a fake website. We cover these in detail in our article on phishing-resistant MFA.

For organizations, start with the accounts that matter most: administrators, remote access, email, and cloud management consoles.

3. Recognize and report phishing

Phishing has improved. Messages are now fluent, personalized and delivered by email, text, phone and collaboration tools. Generative AI makes convincing lures cheap to produce at scale. The warning signs are less about spelling mistakes and more about pressure and process:

  • Urgency or secrecy. "Pay this invoice today," "don't tell anyone yet."
  • A change in a familiar process. New bank details, a different approval route, an unexpected sign-in page.
  • A request that bypasses normal checks. Gift cards, wire transfers or credentials requested outside the usual channels.

The most valuable habit is reporting. A suspicious message reported quickly lets the security team block it for everyone else and look for anyone who already clicked. Make reporting a single click, thank people who report, and never punish someone for reporting a mistake. People who are afraid of blame stay silent, and silence is what attackers need.

4. Keep software updated

Attackers routinely exploit vulnerabilities that already have fixes available. CISA maintains a catalog of Known Exploited Vulnerabilities precisely because so many intrusions use flaws that could have been patched. Turning on automatic updates for operating systems, browsers and applications closes many of those doors without anyone having to remember.

For organizations, updates need ownership and deadlines:

  • Keep an inventory of systems and software, including internet-facing devices such as VPNs and firewalls.
  • Prioritize vulnerabilities that are known to be exploited, especially on systems reachable from the internet.
  • Replace technology that has reached end of support and no longer receives fixes.

Making the habits stick

Awareness campaigns work best when the secure choice is also the easy one. Posters and annual training help, but systems do most of the work:

  • Secure defaults. MFA enforced at sign-in, automatic updates on by default, password managers deployed to every device.
  • Short, relevant training. Brief sessions throughout the year, tailored to the threats people actually see in their roles, instead of one long annual course.
  • Realistic practice. Phishing simulations that teach rather than trick, followed by immediate, constructive feedback.
  • Visible leadership. Executives who use MFA, report phishing and complete the same training set the tone.
  • Measurement. Track reporting rates, MFA coverage and patch timeliness rather than only click rates.

Beyond the basics

The four habits do not stop every attack. Determined adversaries, including nation-state actors targeting defense and critical infrastructure, use techniques that go well beyond phishing and password reuse. But they also take advantage of the basics when they are missing. Strong fundamentals force attackers to work harder, take more risk and make more noise, which gives defenders a better chance of catching them.

Frequently asked questions

Is Cybersecurity Awareness Month only for individuals? No. It is a good time for organizations to review MFA coverage, patching and reporting processes, and to refresh training.

Are text-message codes still worth using? Yes, if nothing stronger is available. They stop many automated attacks. For high-value accounts, move to phishing-resistant methods.

How often should employees receive security training? Short, frequent sessions throughout the year are more effective than a single annual course.

How CDT can help

CDT helps organizations turn awareness into practice. Our cyber training builds skills for technical teams and everyday users, our social engineering assessments measure how people respond to realistic phishing and pretexting, and our system hardening work puts secure defaults in place so the right choice is the easy one.

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.