Cybersecurity Awareness Month

 In Tip of the Week

Cybersecurity Awareness Month (CSAM) is a month-long campaign in October dedicated to encouraging individuals and organizations to prioritize digital security. The central idea is that cybersecurity is a shared responsibility.

Here is an overview of the key information and practical tips for both individuals and organizations.

Core Cybersecurity Tips for Everyone

The campaign often emphasizes four simple, yet powerful actions that drastically improve your online safety.

 

  1. Use Strong Passwords and a Password Manager
  • Create long, unique, and complex passwords (using a mix of letters, numbers, and symbols)  for every online account.
  • NEVER reuse passwords across different services.
  • Use a password manager to securely store, generate, and autofill your credentials, making the entire process easier and safer.

 

  1. Turn on Multi-Factor Authentication (MFA)
  • MFA (also known as two-factor authentication) adds a second layer of security beyond your password.
  • It requires a second step, usually a code sent to your phone or generated by an app, to log in.
  • Enable MFA on every account that offers it, especially email, banking, and social media.

 

  1. Recognize and Report Scams (Phishing)
  • Be vigilant about unexpected emails, text (smishing), or calls (vishing) that ask for personal information, money, or prompt you to click a suspicious link.
  • Red Flags: Urgent language, unexpected requests, grammatical errors, and a sender’s email address that doesn’t match the company they claim to be.
  • Hover your mouse over links before clicking to see the actual destination URL.
  • Validate suspicious requests by contacting the company or person through an official channel (not by hitting “Reply’ to the suspicious message).

 

  1. Update Your Software
  • Regular software updates often include critical security patches that fix known vulnerabilities hackers could exploit.
  • Enable automatic updates for your operating system (Windows, macOS, iOS, Android), web browsers, antivirus software, and all applications. Don’t hit “Update-Later”-do it now!


Tips and Activities for Organizations

Cybersecurity Awareness Month is an excellent opportunity to engage employees and reinforce a security-first culture.


Engagement Activities

  • Host a Phishing Simulation: Run a mock phishing campaign and provide immediate training to employees who click the link, turning a mistake into a learning opportunity.
  • Cybersecurity Games & Contests: Organize a fun, competitive event like Cybersecurity Trivia, Bingo, or an Escape Room to teach key concepts engagingly, offering small prizes for winners.
  • Lunch-and-Learns/Webinars: Host short, informative sessions on relevant topics, such as ransomware, mobile security, or the secure use of AI tools.
  • “Ask Me Anything” (AMA) with the Security Team: Set up open office hours where employees can ask questions directly to the IT or security team, making them more approachable.
  • Internal Communications Campaign: Use your intranet, email banners, and physical posters to share a daily or weekly security tip, focusing on the “Core 4”.
  • Recognize “Cyber Champions”: Publicly thank employees who consistently report phishing attempts or demonstrate excellent security behaviors.


Organizational Best Practices

  • Review Access Controls: Ensure the Principle of Least Privilege (PoLP) is enforced-employees should only have access to the data and systems necessary for their job.
  • Secure Remote Access: Mandate the use of strong MFA and Virtual Private Networks (VPNs) for all remote access.
  • Data Backup Plan: Verify that all critical data is backed up regularly, tested for integrity, and stored securely (ideally offsite or in the cloud). This is your last line of defense against ransomware.
  • Incident Response Plan: Review and practice your organization’s plan for how to detect, contain, and recover from a cyber attack.


Safety Tip Challenge

Which of these protocols, if any, have you implemented? Are there new ones you’re planning to practice with your team? Even if you haven’t implemented protocols before, has this tip made you think about starting? Please share any protocols or ideas that help your employees prevent cyber attacks.

Recent Posts
Contact Us

Please send us an email and we'll get back to you as soon as possible.

Not readable? Change text. captcha txt

Start typing and press Enter to search