How to Run a Cybersecurity Awareness Month Campaign: A Week-by-Week Enterprise Playbook
Read summarized version with

Key takeaways
- Cybersecurity Awareness Month runs every October, and in 2026 it carries two themes, CISA's "Securing the Next 250" and the National Cybersecurity Alliance's "Don't Make It Easy for Them";
- A Cyber Awareness Month campaign can launch within 48 hours, and organizations that start late can compress the plan into two weeks or 10 business days;
- Each week of Cybersecurity Awareness Month works best when it pairs one AI-era cyber threat with one employee behavior, supported by role-based tracks for finance, HR, executives, the IT help desk, and new hires;
- Behavior metrics such as report rate and time to report, compared between a baseline phishing simulation and a retest, show whether Cybersecurity Awareness Month changed employee behavior;
- Adaptive Security's free Cybersecurity Awareness Month toolkit covers all four weeks, and its cybersecurity awareness training platform carries the October habits through the remaining 11 months.
Cybersecurity Awareness Month is the annual October campaign led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance to build safer online habits. For enterprises, a practical approach is a four-week program that pairs each week with one current cyber threat, one employee behavior, and one measurable outcome, starting with a baseline phishing simulation.
According to the National Cybersecurity Alliance's Oh Behave! The Annual Cybersecurity Attitudes and Behaviors Report 2025-2026, 55% of participants report having no access to cybersecurity training. The Oh Behave! cybersecurity attitudes and behaviors report also finds that most employees who use AI tools have received no training on their risks.
Organizations that reach mid-October without a plan risk ending the month with only a completion rate to show leadership. A four-week plan that ends with a retest can start immediately and produce evidence of behavior change. This Cybersecurity Awareness Month guide covers:
- What Cybersecurity Awareness Month is and what its two 2026 themes ask of enterprises;
- How to launch a Cyber Awareness Month campaign within 48 hours;
- Four weekly Cybersecurity Awareness Month plans covering AI-powered phishing, deepfakes, AI-researched spear phishing, and shadow AI;
- Role-based Cyber Awareness Month tracks and compressed schedules for late starters;
- How to measure Cybersecurity Awareness Month results and carry them into a year-round cybersecurity awareness training program.
Organizations that start October without ready content lose week one to planning while cyberattackers keep sending AI-written lures. Adaptive Security provides a free four-week toolkit of videos, posters, and templates.
What Is Cybersecurity Awareness Month, and What Are the 2026 Themes?
Cybersecurity Awareness Month is a public awareness campaign held every October in which government agencies and industry partners promote everyday security habits for individuals and organizations. In 2026, it runs under CISA's theme Securing the Next 250 and the Alliance's theme Don't Make It Easy for Them, and both themes ask enterprises to build small habits that employees repeat daily.
When Did Cybersecurity Awareness Month Start?
Cybersecurity Awareness Month started in 2004, when the National Cybersecurity Alliance launched the campaign in partnership with the US Department of Homeland Security. Every year since, the President of the United States and Congress have declared October to be Cybersecurity Awareness Month, and 2026 marks the 23rd campaign. CISA now co-leads the campaign with the National Cybersecurity Alliance.
Older materials call the campaign National Cybersecurity Awareness Month or NCSAM, and some government campaigns spell it Cyber Security Awareness Month. The shorter name Cyber Awareness Month describes the internal campaign an organization runs during those 31 days.
What Are the Cybersecurity Awareness Month 2026 Themes?
CISA's 2026 theme, Securing the Next 250, recognizes the nation's 250th anniversary and emphasizes the need to build a secure digital future, with a focus on critical infrastructure owners and operators and on state, local, tribal, and territorial governments. CISA's Securing the Next 250 launch announcement pairs the theme with three organizational actions it calls the 3Rs of Cybersecurity:
- Reduce: Organizations shrink the attack surface by applying patches promptly and keeping software current;
- Replace: Organizations upgrade or replace end-of-support software and devices before support ends;
- Recover: Organizations maintain practiced plans that sustain operations and restore them quickly after a cyber incident.
The National Cybersecurity Alliance's 2026 theme, Don't Make It Easy for Them, frames online safety as habits repeated consistently in everyday moments. Its toolkit, available through the National Cybersecurity Alliance campaign page, draws on documented cases of hackers and scammers who were arrested or prosecuted to illustrate password cracking, unprotected accounts, unpatched systems, and phishing scams. Both 2026 themes converge on four simple steps that CISA recommends for individuals:
- Strong passwords: Employees use long, unique passwords stored in a password manager;
- Multifactor authentication (MFA): Employees turn on MFA for every important account;
- Phishing recognition: Employees recognize phishing messages and report them through the approved channel;
- Software updates: Employees install device and application updates promptly.
How AI Changes the Cybersecurity Awareness Month Playbook

AI lowers the cost of producing convincing phishing emails, cloned voices, and personalized outreach, which shifts where employee judgment matters most. The four simple steps remain necessary, yet they leave out three behaviors that AI-era cyberattacks test directly:
- Verification: Employees confirm voice and video requests through a known channel before acting;
- Exposure control: Employees limit the public details that let cyberattackers personalize a lure;
- AI tool discipline: Employees use approved AI tools with reviewed permissions for company data.
According to the FBI Internet Crime Complaint Center's 2025 IC3 Annual Report, the IC3 received 1,008,597 complaints in 2025 reporting $20.877 billion in losses, a 26% increase from 2024. The figure covers only complaints reported to the FBI, so the full cost of cybercrime is likely higher.
The following table summarizes the Cyber Awareness Month plan at a glance, from the baseline before Week 1 through the retest after October.
| Phase | Cyber Threat Focus | Core Employee Behavior | Signature Activity |
|---|---|---|---|
| Before Week 1 | Baseline human risk | Report suspicious messages through one channel | Baseline multi-channel phishing simulation |
| Week 1 | AI-powered phishing and credential cyberattacks | Unique passwords, MFA, and prompt software updates | Spot-the-AI-phish exercise |
| Week 2 | Deepfakes and executive impersonation | Verify voice and video requests through a known channel | Cloned-voice payment tabletop exercise |
| Week 3 | AI-researched spear phishing | Limit public oversharing | Self-OSINT review |
| Week 4 | Shadow AI and unapproved AI agents | Use approved AI tools with reviewed permissions | AI tool amnesty survey |
| After October | Retest and report | Keep reporting | Phishing simulation retest and board summary |
According to ISACA's 2026 Tech Trends and Priorities Pulse Poll, 63% of surveyed professionals name AI-driven social engineering as their top cyber threat. That concern, documented in ISACA tech trends and priorities research, explains why the Cybersecurity Awareness Month plan in the table assigns one AI-era cyber threat to each of the four weeks.
How many employees could name the verification step an AI-era cyberattack tests first? Adaptive Security answers that question with role-based cybersecurity awareness training mapped to current cyber threats.
How to Launch a Cyber Awareness Month Campaign in 48 Hours
A Cyber Awareness Month campaign can start within 48 hours once the security team secures an executive sponsor, runs a baseline phishing simulation, tests the reporting channel, assigns a communications owner, and chooses a content source. Settling those five prerequisites before content reaches employees protects the before-and-after comparison that shows leadership whether behavior changed during October 2026.
Secure an Executive Sponsor for the Cyber Awareness Month Campaign
According to Verizon's 2026 Data Breach Investigations Report, the human element was present in 62% of the breaches Verizon analyzed, up from 60% the previous year. That figure gives an executive sponsor a business case for backing a Cyber Awareness Month campaign aimed at employee behavior.
The executive sponsor sends the kickoff message, approves the time employees spend on weekly activities, and signs off on verification rules for voice and video requests, such as callbacks to known numbers and code words for payment approvals. Those rules carry more weight when employees know a senior leader endorsed them.
Run a Baseline Phishing Simulation Before Cyber Awareness Month
A baseline phishing simulation must run before any Cybersecurity Awareness Month content reaches employees, or the end-of-month retest has nothing to compare against. The baseline should cover email and at least one non-email channel, such as SMS or voice, using multi-channel phishing simulations that mirror how cyberattackers now reach employees.
The security team records three numbers for every employee group:
- Click rate: This metric measures the share of employees who clicked a link or opened an attachment;
- Report rate: This metric measures the share of employees who reported the phishing simulation through the approved channel;
- Time to report: This metric measures the minutes between delivery and the first report.
Each phishing simulation should also carry a difficulty rating from the NIST Phish Scale User Guide, a method from the National Institute of Standards and Technology (NIST) for rating how hard an email is for humans to detect based on its cues and how closely its premise matches the recipient's work. Matching difficulty between baseline and retest keeps the comparison fair.
Test the Cyber Awareness Month Reporting Channel
Employees can only build a reporting habit if the reporting channel works the first time they use it. The security team should confirm that the report button or reporting mailbox works on desktop and mobile email clients before the Cyber Awareness Month kickoff.
Suspicious calls, text messages, and video meetings need a reporting path as well, because deepfake calls and AI-researched spear phishing can reach employees by phone, text message, or video instead of email. A named triage owner reviews every report, and each reporter receives a short acknowledgment that signals the report was noticed and encourages the next one.
Assign a Cyber Awareness Month Communications Owner and Calendar
One communications owner runs the Cyber Awareness Month calendar so messages arrive on a predictable rhythm rather than in bursts. A fixed three-step weekly rhythm keeps the campaign visible without crowding inboxes:
- Monday message: The communications owner sends the weekly message introducing the cyber threat and the behavior;
- Wednesday activity: Employees complete the week's activity, exercise, or short session;
- Friday recap: The communications owner shares anonymized reports and previews the next week's focus.
The communications owner distributes each message across email, Microsoft Teams or Slack, the intranet, and office screens, so employees who skip one channel still see the week's focus. Repeating the same three touchpoints every week also makes each message easier for employees to expect and act on.
Choose the Content Source for Cybersecurity Awareness Month
A ready-made kit is typically the fastest content source for a Cybersecurity Awareness Month campaign. The National Cybersecurity Alliance offers a free Champion toolkit containing a tipsheet, eight printable posters, 16 social media graphics, and 16 Instagram Story graphics, and organizations can also draw on CISA resources, a vendor toolkit, or internal material. Whatever the source, each asset should map to one of the four weekly cyber threats, which are AI-powered phishing, deepfakes, AI-researched spear phishing, and shadow AI.
When a phishing simulation covers only email, weaknesses in voice and SMS stay hidden until cyberattackers exploit them. Adaptive Security runs phishing simulations across email, SMS, voice, and deepfake channels.
Week 1 of Cybersecurity Awareness Month: AI Phishing and Credentials
Week 1 of Cybersecurity Awareness Month prepares employees for AI-powered phishing and credential cyberattacks through password manager use, MFA on every important account, and prompt software updates. Those habits counter password cracking, unprotected accounts, and unpatched systems, which AI now makes faster to exploit, and Week 1 also starts the reporting habit.
The AI-Powered Phishing Cyber Threat in Cyber Awareness Month Week 1
AI-written phishing removes the spelling and grammar mistakes that earlier cybersecurity awareness training taught employees to catch, so a polished message no longer signals a safe one. Employees who still judge an email by its writing quality are applying a test that AI-generated messages pass easily.
According to APWG's Phishing Activity Trends Report, 2nd Quarter 2026, the Anti-Phishing Working Group observed 1,069,681 phishing cyberattacks in the quarter, up 10.1% from the first quarter. Quarterly editions of the APWG phishing activity trends report give security teams a current benchmark for the phishing volume employees face.
Week 1 lures arrive in three forms that deserve attention during the first week of Cyber Awareness Month:
- Credential harvesting pages: Lookalike login screens capture usernames and passwords, and employees often reach them through a link in an urgent message;
- QR codes: Images in emails or printed notices open a credential harvesting page on a phone;
- Collaboration-app messages: Phishing sent through Microsoft Teams or Slack can appear to come from a colleague.
Cyber Awareness Month Week 1 Habits for Passwords, MFA, and Updates
Every employee should adopt three habits during the first week of Cybersecurity Awareness Month:
- Password manager use: Employees store a unique passphrase for every work account, so one stolen password unlocks nothing else;
- MFA on every important account: Employees enable multifactor authentication on email, payroll, finance, and cloud accounts, using phishing-resistant methods where the organization offers them;
- Prompt updates: Employees install software and device updates when prompted and flag end-of-support devices to IT, which supports CISA's Replace step.
Week 1 also introduces the reporting habit that every later week reinforces, asking employees to report any suspicious message within minutes through the organization's approved reporting channel. A report within minutes gives the security team time to warn colleagues before the same message reaches them.
According to Verizon's 2026 Data Breach Investigations Report, exploitation of vulnerabilities is now the most common initial access vector for breaches at 31%, while credential abuse fell to 13%. Prompt updates therefore address the most common entry point, while password and MFA habits address the credential abuse that remains.
Week 1 Cyber Awareness Month Activities for AI-Powered Phishing
Week 1 activities give employees practice with phishing samples drawn from the organization's own inbox. Five activities fit comfortably into the first week of Cyber Awareness Month:
- Spot-the-AI-phish exercise: The security team anonymizes recent messages from the organization's report mailbox, mixes them with legitimate emails, and asks employees to sort them before explaining the cues in each;
- Password manager enrollment drive: IT holds short help desk office hours so employees can install the password manager and move work passwords into it;
- MFA enrollment audit: IT lists accounts still missing multifactor authentication and works through the list with account owners before Friday;
- Device update hour: Employees restart and update laptops and phones together at a scheduled time, and IT records any device that cannot update;
- Collaboration-app example: The Wednesday session shows one anonymized phishing message received through Microsoft Teams or Slack and the steps to report it.
Each activity leaves a record, such as enrollment counts or the list of devices that cannot update, which feeds the end-of-month report to leadership. The spot-the-AI-phish exercise works best with about 10 samples, a 15-minute time limit, and answers shared in the Friday recap, so employees learn the cues while the examples are still fresh.
Week 1 Cybersecurity Awareness Month Message Example for Employees
The communications owner can send the following sample message on the Monday of Week 1, adjusting the reporting instructions to match the organization's channel.
Subject line: Cyber Awareness Month Week 1 | AI Writes Better Phishing Now
Cyberattackers now use AI to write phishing emails that read as clean, confident, and urgent, so a well-written message deserves the same scrutiny as a sloppy one. The security team asks every employee to complete three actions before Friday.
- Enroll in the company password manager and replace any reused work password;
- Turn on multifactor authentication for every work account that offers it;
- Report any suspicious email, text, or chat message within minutes using the reporting button in the email client.
The Friday recap can then report how many employees enrolled in the password manager and how many suspicious messages they reported during the week. Sharing those counts shows employees that the week's actions are tracked and valued.
Use the Week 1 videos, posters, and email template from Adaptive Security’s cybersecurity awareness month toolkit to show employees how AI-written phishing looks before the first lure lands in an inbox.
Week 2 of Cybersecurity Awareness Month: Deepfakes and Impersonation
Week 2 of Cybersecurity Awareness Month addresses deepfakes, the AI-generated audio, images, and video that let cyberattackers imitate a familiar voice or face. Because recognition alone can no longer confirm identity, Week 2 replaces it with verification through a channel the employee already trusts.
The Deepfake Cyber Threat in Cyber Awareness Month Week 2
Deepfakes reach employees through cloned voice calls, voicemails, and video meetings in which a cyberattacker appears as an executive, vendor, or colleague. The FBI warning on AI-generated voice messages, issued on May 15, 2025, reported that since April 2025 cyberattackers had sent text messages and AI-generated voice messages impersonating senior US officials to reach current and former officials and their contacts.
According to Gartner's Gartner Survey Reveals GenAI Attacks Are on the Rise 2025, 62% of organizations experienced a deepfake cyberattack involving social engineering or exploiting automated processes. The Gartner survey on generative AI attacks drew on responses from 302 cybersecurity leaders collected between March and May 2025.
The established evidence for Week 2 consists of survey findings and law enforcement advisories, while estimates of future deepfake fraud losses remain projections. Employee guidance during Cyber Awareness Month should rest on the documented pattern, in which a trusted voice or face delivers an urgent request that verification would expose.
Verification Behaviors for Week 2 of Cybersecurity Awareness Month
During the second week of Cybersecurity Awareness Month, employees treat any unexpected voice or video request involving money, credentials, or data as unverified until confirmed. Three behaviors make that rule practical:
- Callback on a known number: Employees hang up and call the requester back on a number from the company directory or vendor file before acting;
- Code words: Executives, executive assistants, and finance approvers agree on private phrases that a cloned voice cannot know;
- A pause on urgency and secrecy: Employees treat pressure to act immediately or keep a request confidential as a cue to verify.
Employees should report every impersonation attempt, including attempts they stopped, because each report shows the security team which executives and channels cyberattackers are imitating. Executives should announce the callback rule themselves, so employees know that a request to skip verification is itself a warning sign.
According to the FBI Internet Crime Complaint Center's 2025 IC3 Annual Report, business email compromise generated 24,768 complaints and $3,046,598,558 in reported losses. Business email compromise is a fraud scheme in which a cyberattacker impersonates a trusted executive, employee, or vendor to redirect payments, and it relies on the same impersonated authority that deepfakes amplify. The callback rule therefore works as a financial control as much as a security habit.
Week 2 Cyber Awareness Month Activities for Deepfake Awareness
Week 2 Cyber Awareness Month activities let employees experience how convincing synthetic media has become without causing alarm, and each of the three activities reinforces the callback rule:
- AI-or-authentic quiz: Employees review a short set of images, audio clips, and video clips, decide which items are AI-generated, and then see the cues behind each answer;
- Cloned-voice payment tabletop: In a 30-minute exercise, a finance lead receives a cloned-voice call approving an urgent payment, and the room walks through each verification step;
- Consent-based executive demonstration: The security team shows employees a short deepfake of an executive volunteer, created with that executive's written consent, alongside the callback rule.
The cloned-voice payment tabletop produces the most direct evidence of the week, because it shows whether finance staff follow the callback rule under time pressure or approve the payment first. Running the AI-or-authentic quiz before the tabletop gives employees a direct sense of how hard detection by eye and ear has become, which makes the callback rule easier to accept. Security teams preparing these sessions can use a business guide to deepfake threats and synthetic media risks for case studies and defense strategies.
Week 2 Cybersecurity Awareness Month Message Example for Employees
The Monday message for Week 2 introduces the callback rule in terms employees can remember after one reading.
Subject line: Cyber Awareness Month Week 2 | Seeing and Hearing Need Verifying
AI can now imitate the voice and face of a colleague, an executive, or a vendor on a phone call or video meeting. For Week 2, the security team asks every employee to follow three practices.
- Before acting on any call, voicemail, or video request involving money, passwords, or data, hang up and call back on a number from the company directory;
- Treat urgency or a request for secrecy as a signal to slow down and verify;
- Report every impersonation attempt, including attempts that failed, through the reporting channel.
Finance approvers and executive assistants should receive the Week 2 message first, since they handle the requests that impersonation schemes target. Sending it to those teams a day early also lets them test the callback rule before the rest of the organization.
A familiar voice confirms nothing once cyberattackers can clone it, while a callback to a known number confirms who is asking. Adaptive Security's Week 2 toolkit teaches that habit.
Week 3 of Cybersecurity Awareness Month: AI Spear Phishing

Week 3 of Cybersecurity Awareness Month focuses on spear phishing that AI agents research and write at scale using public information about each target. Rather than teaching employees to spot bad messages alone, Week 3 limits what cyberattackers can learn in the first place.
The AI Spear Phishing Cyber Threat in Cyber Awareness Month Week 3
Spear phishing is a targeted form of phishing that uses details about a specific person to make a message believable. AI tools now gather those details from LinkedIn profiles, company press releases, organization charts, and conference talks, and then write outreach that references a current project, a manager's name, or a recent trip.
According to Heiding et al.'s Evaluating Large Language Models' Capability to Launch Fully Automated Spear Phishing Campaigns 2024, fully AI-automated spear phishing emails reached a 54% click-through rate, matching human experts and far above the 12% control group. The study on fully automated spear phishing campaigns involved 101 participants, so its figures describe a small study.
The resulting messages contain details an outsider would not be expected to know, which removes the generic tone that once made phishing easy to spot. Personalization at that level no longer depends on manual research by a human cyberattacker.
According to Anthropic's Disrupting the First Reported AI-Orchestrated Cyber Espionage Campaign 2025, the threat actor used AI to perform 80% to 90% of the campaign, with human intervention required only sporadically. The Anthropic report on an AI-orchestrated cyber espionage campaign, published on November 13, 2025, concerns an espionage campaign against about 30 targets and documents how much of an operation AI can run with limited human direction.
Oversharing Behaviors for Week 3 of Cybersecurity Awareness Month
Week 3 behaviors reduce the raw material that AI-researched spear phishing depends on. Employees should review their public professional profiles during the third week of Cybersecurity Awareness Month for four categories of detail:
- Role and responsibilities: Job titles and duties can reveal who approves payments or manages access;
- Reporting line: Managers and executives named in profiles or posts give cyberattackers names to impersonate;
- Travel: Conference attendance and trip announcements create a pretext for urgent requests;
- Vendors and projects: Named suppliers, tools, and initiatives give cyberattackers a believable sender to imitate.
Employees should also treat highly personalized messages as unverified until the sender is confirmed through a known channel, since personal detail is now evidence of research rather than proof of familiarity. A message that cites a recent conference talk or a manager's name proves only that the sender searched public sources.
Reporting carries particular weight in Week 3, because a highly tailored message often signals research that precedes a wider campaign against the organization. One early report can alert the security team before the same research reaches other employees.
Week 3 Cyber Awareness Month Activities for Spear Phishing Defense
Week 3 Cyber Awareness Month activities turn the research cyberattackers perform into three exercises employees perform on themselves, using public sources the same way an AI agent would:
- Self-OSINT review: Using open-source intelligence (OSINT), the practice of gathering information from public sources, each employee searches for their own name, role, and company, notes what a cyberattacker could use, and restricts what is unnecessary;
- 15-minute team workshop: A facilitator shows what public sources reveal about one volunteer team in 15 minutes, and the team then discusses which details to keep private;
- Executive and new-hire exposure review: The security team checks the public footprint of executives and recent hires, two groups whose details give cyberattackers a ready pretext.
The 15-minute team workshop works best with a volunteer team that has agreed to take part in advance, and its findings should be shared only with that team. Each completed self-OSINT review becomes a measurable output for the month, recorded as the number of profiles employees updated during Week 3. Those updates also shrink the material available to cyberattackers before the next spear phishing campaign begins.
Week 3 Cybersecurity Awareness Month Message Example for Employees
The Week 3 message gives employees one concrete profile-review task and a clear reason to complete it.
Subject line: Cyber Awareness Month Week 3 | What the Internet Knows
Cyberattackers can point AI tools at public profiles and draft a tailored message quickly, using details employees shared without a second thought. Three steps this week reduce what a cyberattacker can learn.
- Review the public professional profile and remove reporting lines, travel plans, and vendor names that are not needed;
- Treat any message that mentions personal or project details as unverified until the sender is confirmed;
- Report highly tailored messages through the reporting channel, even when they seem harmless.
The Week 3 message works best when paired with a two-minute example showing what a public profile reveals about a fictional employee. A fictional example demonstrates the risk without exposing any colleague's information.
Every public detail an employee shares becomes material for an AI agent drafting a spear phishing lure. Adaptive Security's Week 3 toolkit shows employees what AI can find about them.
Week 4 of Cybersecurity Awareness Month: Shadow AI and AI Agents
Week 4 of Cybersecurity Awareness Month addresses shadow AI, the use of AI tools and agents that security teams never approved. The week teaches employees to keep company data inside approved tools and to limit the access they grant to AI agents.
The Shadow AI Cyber Threat in Cyber Awareness Month Week 4
Shadow AI often starts with good intentions, such as an employee pasting meeting notes into a free AI tool for a summary or installing a browser extension that drafts replies. Company data then sits in a tool outside the organization's security controls, retention rules, and contracts, where the security team has no record of what was shared.
According to IBM's Cost of a Data Breach Report 2026, security incidents involving shadow AI more than doubled to 43% from 20% the previous year among the breached organizations IBM studied. The IBM Cost of a Data Breach Report tracks shadow AI as its own breach factor, and the jump in one year shows how quickly unapproved AI use has reached incident data.
AI agents add a second layer of risk because they can act on data as well as read it. An employee who signs up for an agent and accepts every requested permission can give that agent the ability to read email, send messages, and change files on the employee's behalf. Because the permission screen is where that access is granted, the employee's click decides how much company data the agent can reach.
Approved AI Tool Behaviors for Week 4 of Cybersecurity Awareness Month
Week 4 behaviors focus on which AI tool employees use and what access it receives, since the cyber threat comes from unapproved tools and excessive permissions. Three habits anchor the final week of Cybersecurity Awareness Month:
- Approved tools for company data: Employees use only approved AI tools for company information and keep confidential data out of public AI tools;
- Permission review before connection: Employees read the permissions an AI agent requests before connecting it to email, files, or calendars and decline access the task does not need;
- Output checks: Employees review AI-generated content and proposed actions before sending, sharing, or acting on them.
Employees should also report unapproved AI tools they discover, including tools they installed themselves, without fear of blame. A blame-free reporting rule matters in Week 4 because security teams cannot govern AI tools they cannot see. Managers reinforce the habits when they use approved tools in team meetings and route AI questions to the security team rather than improvising answers.
Week 4 Cyber Awareness Month Activities for Shadow AI Governance
Week 4 activities replace guesswork with an inventory of the AI tools employees already use. An AI tool amnesty survey asks employees which AI tools, browser extensions, and agents they use for work, with a guarantee that answers will not trigger discipline.
A survey limited to three questions, covering the tool, the task, and the type of data involved, keeps completion quick and gives the security team the detail it needs. The results then show where approved alternatives are missing.
According to ISACA's 2026 AI Pulse Poll, only 38% of organizations have a formal, comprehensive AI policy, and 25% have no active policy. The ISACA AI Pulse Poll surveyed more than 3,400 professionals, and its findings suggest that many employees work without clear AI rules to follow.
The security team then publishes a one-page approved AI tools list and runs a short permission-review demonstration that shows what an agent can do once an employee accepts every requested permission. Organizations that want continuing visibility after Cyber Awareness Month can add AI governance controls that surface AI tools across the workforce and coach employees in the browser when a policy is broken.
Week 4 Cybersecurity Awareness Month Message Example for Employees
The Week 4 message names the approved tools and makes reporting an unapproved tool feel safe, including for employees who installed a tool themselves.
Subject line: Cyber Awareness Month Week 4 | Which AI Tool Holds the Data
AI tools save time, but company information belongs only in tools the security team has approved, and AI agents should receive only the access a task needs. Every employee has three steps to complete before Friday.
- Check the approved AI tools list on the intranet before using any AI tool for company work;
- Review the permissions an AI agent requests before connecting it to email, files, or calendars;
- Report any unapproved AI tool in use, including one installed personally, through the reporting channel, knowing that reports carry no penalty.
Sharing the amnesty survey totals in the Friday recap shows employees that disclosure led to approved alternatives rather than penalties. Visible follow-through encourages more employees to disclose tools in the months after October.
Adaptive Security's Week 4 toolkit gives employees a picture of how unapproved AI tools and over-permissioned agents expose company data, along with the habits that keep it inside approved systems.
Which Teams Need Role-Based Cyber Awareness Month Tracks?

Finance, HR and recruiting, executives and their assistants, the IT help desk, and new hires need role-based Cyber Awareness Month tracks because cyberattackers choose channels according to role. Each track adds one role-specific behavior and one activity to the four shared weeks.
Finance and Accounts Payable Track for Cyber Awareness Month
Finance and accounts payable teams approve the payments that impersonation schemes target. Two controls form the finance Cyber Awareness Month track.
The approver verifies every payment change request by calling back a number already on file, and a second approver signs off on every new payee or urgent transfer. Repeating the cloned-voice payment tabletop exercise with the full finance team tests both controls under time pressure.
HR and Recruiting Track for Cybersecurity Awareness Month
According to Gartner's Gartner Survey Shows Just 26% of Job Applicants Trust AI Will Fairly Evaluate Them 2025, 6% of the 3,000 candidates surveyed admitted to participating in interview fraud. The Gartner job applicant survey also states a Gartner prediction that one in four candidate profiles worldwide will be fake by 2028, which Gartner presents as a forecast.
A US Department of Justice announcement dated May 6, 2026 describes the Justice Department sentencing in remote IT worker schemes, in which two US nationals hosted laptop farms that let North Korean IT workers using stolen identities appear as local employees. The HR track adds identity checks during video interviews, such as matching the candidate on camera to submitted identity documents, and practices them in a short interview verification walkthrough.
Executive and Executive Assistant Track for Cyber Awareness Month
Executives and executive assistants are frequent impersonation targets because their voices and names carry authority. Their Cyber Awareness Month track combines a public profile review with private code words shared between each executive and assistant. Executives should also decide in advance whether they consent to training that uses their likeness or voice.
IT Help Desk Track for Cybersecurity Awareness Month
According to Google Cloud's M-Trends 2026, voice phishing accounted for 11% of initial infection vectors in the incidents Mandiant investigated during 2025, the second-most commonly observed vector, while email phishing dropped to 6%. Voice phishing (vishing) is a social engineering attack in which a caller impersonates a trusted person to obtain credentials or bypass a security control. The report describes financially motivated groups calling IT help desks to bypass controls and gain initial access to software-as-a-service (SaaS) applications.
The help desk track requires agents to verify a caller's identity through an approved method, such as a callback to the number on file or a manager confirmation, before resetting any password or MFA factor requested by phone. A short reset request drill, in which a colleague calls with an urgent request, lets agents practice the check during Cybersecurity Awareness Month.
New Hire Track for Cyber Awareness Month
New hires are easy targets because their arrival is often announced publicly and their contacts inside the company are still unfamiliar. Onboarding is the natural home for the new hire Cyber Awareness Month track, which adds a self-OSINT review of each new employee's public footprint to the first week on the job. New employees also learn the reporting channel on their first day, before their first suspicious message arrives.
Role-Based Cyber Awareness Month Tracks Compared by Cyber Threat
The following table compares the five role-based Cyber Awareness Month tracks by primary cyber threat, required behavior, and track activity, and organizations can map them to the essential components of cybersecurity training programs as the program matures.
| Role | Primary Cyber Threat | Required Behavior | Track Activity |
|---|---|---|---|
| Finance and accounts payable | Payment impersonation | Callback and dual approval | Payment tabletop exercise |
| HR and recruiting | Fraudulent candidates | Identity checks in video interviews | Interview verification walkthrough |
| Executives and assistants | Voice and video cloning | Code words and profile review | Public profile review |
| IT help desk | Voice phishing for resets | Caller verification before resets | Reset request drill |
| New hires | Onboarding-stage targeting | Early reporting and profile review | Self-OSINT review at onboarding |
For organizations that can run only one track in October, the finance and IT help desk tracks cover the roles whose actions move money or reset access. The remaining tracks can follow in the year-round program.
If finance, HR, executives, and the help desk all receive identical content, the teams cyberattackers target first stay underprepared. Adaptive Security assigns role-based cybersecurity awareness training to each team automatically.
Compressed Cyber Awareness Month Schedules for Late Starters
Organizations that start in mid-October can still cover all four cyber threats by compressing the Cyber Awareness Month plan into two weeks or 10 business days. Both schedules keep the baseline phishing simulation at the start, the reporting habit throughout, and a retest at the end.
A Two-Week Cyber Awareness Month Schedule
The two-week schedule keeps the Monday, Wednesday, and Friday rhythm and pairs the four cyber threats across two weeks of Cyber Awareness Month.
| Timing | Cyber Threat Focus | Activity | Message |
|---|---|---|---|
| First week, Monday | Baseline | Multi-channel baseline phishing simulation | Kickoff from the executive sponsor |
| First week, Wednesday | AI-powered phishing | Spot-the-AI-phish exercise | Message on AI-written phishing |
| First week, Friday | Deepfakes | Cloned-voice payment tabletop | Callback rule recap |
| Second week, Monday | AI-researched spear phishing | Self-OSINT review | Message on public profiles |
| Second week, Wednesday | Shadow AI | AI tool amnesty survey | Message on approved AI tools |
| Second week, Friday | Retest | Retest phishing simulation at matched difficulty | Recap with early results |
Each Friday recap in the two-week version should share the week's reports, because a shorter campaign has fewer chances to show employees that reporting leads to action. Two recaps also give leadership interim results before the retest.
A 10-Day Cybersecurity Awareness Month Schedule for Mid-October
The 10-day schedule suits organizations starting in the third or fourth week of October, with one short action per business day of Cybersecurity Awareness Month.
| Day | Action |
|---|---|
| Day 1 | Baseline phishing simulation across email and one non-email channel |
| Day 2 | Executive kickoff message and reporting channel reminder |
| Day 3 | AI-written phishing examples shared in a five-minute video or post |
| Day 4 | Password manager and MFA enrollment push |
| Day 5 | Callback rule and code words for finance approvers |
| Day 6 | AI-or-authentic quiz |
| Day 7 | Self-OSINT review |
| Day 8 | AI tool amnesty survey |
| Day 9 | Approved AI tools list published |
| Day 10 | Retest phishing simulation and recap |
Every action in the 10-day version fits into a few minutes of an employee's day, which protects participation while the full campaign runs in under half the time of the four-week plan. Organizations with fewer than 10 business days left can publish the approved AI tools list alongside the Day 8 survey results.
What a Compressed Cybersecurity Awareness Month Keeps and Cuts
According to Verizon's 2026 Data Breach Investigations Report, the median successful click rate in mobile-centric vectors such as voice and text messaging is 40% higher than via email. That gap is the reason even the shortest Cybersecurity Awareness Month schedule keeps a voice or SMS channel in its baseline phishing simulation.
A compressed schedule keeps the baseline, all four cyber threats, and the reporting habit, and it cuts optional events, long-form sessions, and extra campaign materials, which can return in the year-round program after October. The two-week schedule suits organizations that want to keep the Monday, Wednesday, and Friday rhythm, while the 10-day schedule suits teams that prefer one short daily action.
What can a security team launch with only 10 days left in October? Adaptive Security's free toolkit supplies ready-to-send videos, posters, and newsletters organized around the same four cyber threats.
How to Measure Whether Cybersecurity Awareness Month Changed Behavior
Organizations measure whether Cybersecurity Awareness Month changed employee behavior by comparing five behavior metrics between the baseline phishing simulation and the end-of-month retest, rather than by counting completed modules. The comparison then feeds a one-page board summary, provided the security team avoids the mistakes that distort results.
Why Completion Rates Mislead Cybersecurity Awareness Month Reporting
According to University of California San Diego researchers' Understanding the Efficacy of Phishing Training in Practice 2025, an eight-month study of more than 19,500 employees at UC San Diego Health found no significant association between annual training and failing a phishing simulation, and over half of training sessions ended within 10 seconds. The same study on the efficacy of phishing training found that training embedded after a failed phishing simulation improved results only modestly.
The UC San Diego study shows that completion is a weak signal of protection on its own. A completed module records attendance, while a lower click rate, a higher report rate, and faster reporting record changed behavior, which is what a Cybersecurity Awareness Month report should lead with. Completion figures still belong in compliance records, provided the board sees which number measures protection.
Behavior Metrics to Compare Before and After Cyber Awareness Month
Five behavior metrics give a fair comparison between the baseline and the end of Cyber Awareness Month, provided each phishing simulation is rated for difficulty with the NIST Phish Scale User Guide so the retest is no easier than the baseline. The following table compares the five metrics by where the baseline value comes from, where the end-of-month value comes from, and what improvement looks like.
| Metric | Baseline Source | End-of-Month Source | What Improvement Looks Like |
|---|---|---|---|
| Report rate | Baseline phishing simulation | Retest phishing simulation | More employees report the message |
| Time to report | Baseline phishing simulation | Retest phishing simulation | The first report arrives sooner |
| Click rate at matched difficulty | Baseline phishing simulation rated with the NIST Phish Scale | Retest at the same NIST Phish Scale rating | Fewer employees click |
| Verification behavior | Week 2 callback drill or tabletop | Repeat callback drill | More staff verify before acting |
| Unapproved AI tool requests | Week 4 amnesty survey | Approval requests after Week 4 | More employees request approval before use |
For measuring behavior under pressure, the click rate at matched difficulty and the callback drill give the most direct evidence, while report rate and time to report show whether the reporting habit took hold. Unapproved AI tool requests show whether Week 4 changed how employees adopt new tools.
A One-Page Cybersecurity Awareness Month Board Summary
A one-page board summary for Cybersecurity Awareness Month should fit three blocks of information:
- Baseline versus retest: The summary places the five behavior metrics side by side, with the difficulty rating for each phishing simulation;
- Top three cyber threats observed: The summary names the attempts employees reported most often during October;
- Next-quarter plan: The summary lists the behaviors that improved least and the activities scheduled to address them.
According to IBM's Cost of a Data Breach Report 2026, the global average cost of a data breach reached USD 4.99 million across the 602 breached organizations in the study, a 12% increase and a record high. The IBM Cost of a Data Breach Report gives board members the financial context for the behavior changes the summary reports.
The board summary should close with one request, such as approval for quarterly phishing simulations, so the board leaves the meeting with a decision to make. Keeping the summary to one page forces the security team to lead with the metrics that changed most.
Common Cyber Awareness Month Measurement Mistakes
Three measurement mistakes commonly distort Cyber Awareness Month results:
- Shifting difficulty: Running an easier phishing simulation at the retest than at the baseline inflates improvement;
- Counting attendance as outcome: Reporting completion rates as evidence that behavior changed overstates the campaign's effect;
- Measuring email only: Ignoring voice, SMS, and collaboration channels misses where deepfake calls, text messages, and chat-based phishing reach employees.
Avoiding all three mistakes keeps the October 2026 results comparable with the baseline of the next campaign. Consistent methods also let the security team show improvement across years instead of within one month.
Completion rates show who sat through training, while report rates and time to report show who would stop a cyberattack. Adaptive Security reports both at the person and team level.
What Should Happen After Cyber Awareness Month Ends?
After Cyber Awareness Month ends, organizations should keep the October habits active through a November to September cadence of monthly micro-campaigns and quarterly phishing simulations. The same habits then become part of a standing cybersecurity awareness training program, because skills practiced for four weeks fade without reinforcement.
A November to September Cadence Built on Cybersecurity Awareness Month
A November to September cadence keeps the Cybersecurity Awareness Month themes active with a light monthly rhythm, and a guide to security awareness training programs covers the program design behind it. Three recurring elements carry the cadence:
- Monthly micro-campaigns: One short message and activity each month rotate AI-powered phishing, deepfakes, spear phishing, and shadow AI, so each cyber threat returns several times before the next October;
- Quarterly phishing simulations: Multi-channel phishing simulations run each quarter at the same NIST Phish Scale difficulty as the October retest;
- Reporting feedback: A monthly note shares anonymized reports and the actions the security team took on them, so employees keep seeing the effect of reporting.
The November to September cadence works best when each monthly message reuses the October subject-line format, so employees recognize the campaign and connect it to the habits they practiced. Familiar formatting also lowers the effort of producing each month's message.
Building a Cybersecurity Awareness Training Program After October
According to KPMG and the University of Melbourne's Trust, Attitudes and Use of Artificial Intelligence: A Global Study 2025, only 47% of surveyed employees say they have received AI training and only 40% say their workplace has a policy or guidance on generative AI use. The KPMG and University of Melbourne global AI study surveyed more than 48,000 people across 47 countries.
Gaps in AI training and AI policy argue for turning Cyber Awareness Month habits into a standing cybersecurity awareness training program. Role-based assignments keep finance, HR, executives, and the help desk on their own tracks, and just-in-time lessons delivered after a risky action, such as a clicked phishing simulation, reinforce the habit at the moment it lapsed.
Setting Next October's Cybersecurity Awareness Month Baseline Now
The final step is archiving the October 2026 metrics, reported cyber threats, and lessons learned in one place while they are current. Next year's Cybersecurity Awareness Month plan should start from the October 2026 retest results, which become the new baseline, so each campaign builds on measured progress. A short note to the executive sponsor in November, summarizing the retest results and the plan for the year, ensures the sponsor enters the next campaign already briefed.
Keep the October habits active through November and beyond by scheduling monthly micro-campaigns and quarterly phishing simulations in Adaptive Security's cybersecurity awareness training platform, which assigns them automatically.
Running a Cybersecurity Awareness Month Campaign With Adaptive Security

By the end of October 2026, Cybersecurity Awareness Month should leave a workforce that recognizes AI-written phishing, verifies cloned voices, limits oversharing, and uses approved AI tools. For security teams that need ready content and measurable results, Adaptive Security provides a free toolkit and a cybersecurity awareness training platform that together support the baseline, the weekly themes, and the retest.
As of October 2026, the free Cybersecurity Awareness Month toolkit gives teams that want the October work done for them a ready-made starting point. It includes eight training videos of three to seven minutes each, 16 posters in vertical and horizontal formats, four plain-language newsletters, a content calendar, five pre-written email templates, and a rollout guide. Adaptive Security customers also receive interactive game modules on the same themes, with completion and engagement reporting built in.
For the other 11 months, Adaptive Security's security awareness training provides the cybersecurity awareness training platform that carries those themes year-round, with role-based assignments, custom deepfake modules built from executive photos and voice samples, and just-in-time lessons after risky actions. Its multi-channel phishing simulations personalize email, SMS, voice, and deepfake scenarios with open-source intelligence and score risk for each person and team, so the October baseline remains the reference point for every quarterly report.
October results fade by spring when nothing reinforces them between campaigns. Adaptive Security keeps the four AI-era cyber threats in front of every employee year-round with personalized cybersecurity awareness training.
Frequently Asked Questions About Cybersecurity Awareness Month
When Is Cybersecurity Awareness Month?
Cybersecurity Awareness Month is an annual campaign held every October that helps individuals and organizations build everyday security habits, such as using strong passwords, turning on multifactor authentication, reporting phishing, and updating software. CISA and the National Cybersecurity Alliance lead the campaign, and the 2026 edition, the 23rd, runs from Thursday, October 1, through Saturday, October 31. The month is also called National Cybersecurity Awareness Month.
Is Cybersecurity Awareness Month Observed Outside the United States?
Yes. Canada runs Cyber Security Awareness Month every October through Get Cyber Safe, a national campaign led by the Communications Security Establishment Canada, and its 2026 theme is "Your best defence is you." In the European Union, ENISA and the European Commission coordinate European Cybersecurity Month throughout October. Multinational enterprises can run one internal Cyber Awareness Month and reference the local campaign in each region.
Why Is Cybersecurity Awareness Month Important for Enterprises?
Cybersecurity Awareness Month gives enterprises a fixed annual moment with executive attention to measure human risk and launch security habits that continue all year. A baseline phishing simulation run in October shows where employees are most vulnerable, and the month's weekly focus lets security teams introduce verification, reporting, and AI tool habits without competing for attention.
How Can an Organization Join Cybersecurity Awareness Month?
Organizations can join Cybersecurity Awareness Month by registering as a free Champion with the National Cybersecurity Alliance and running an internal Cyber Awareness Month campaign for employees. Champion registration is open to individuals and to organizations such as businesses, schools, nonprofits, community groups, and municipalities, and it carries no financial obligation.
What Free Cybersecurity Awareness Month Toolkits Are Available?
Three free Cybersecurity Awareness Month resources suit different needs in 2026. The National Cybersecurity Alliance's Champion toolkit suits general awareness messaging, CISA's published campaign materials suit organizations aligning with federal guidance, and Adaptive Security's four-week toolkit suits teams that want ready-to-send content built around AI-era cyber threats such as deepfakes and shadow AI.
How Can Organizations Prevent Cyber Awareness Month Fatigue?
Organizations prevent fatigue during Cyber Awareness Month by limiting each week to one cyber threat, keeping activities under 15 minutes, and varying formats among short videos, quizzes, and tabletop exercises. Running no more than one phishing simulation per week also avoids the sense of constant testing, and visible responses to employee reports show that participation matters.
How Can Cyber Awareness Month Cover Deepfakes Without Causing Fear?
Cyber Awareness Month can cover deepfakes without causing fear by leading with one concrete verification step employees control, such as calling back on a known number before acting on a voice or video request. Consent-based demonstrations show the risk without targeting anyone, and rewarding reports of attempted impersonation builds confidence instead of fear.
Employees who spot AI-written phishing, verify cloned voices, and report within minutes are the outcome Adaptive Security builds through continuous, role-based cybersecurity awareness training after October ends.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Related articles

PII Removal Checklist: How to Find, Redact, Delete, and Protect Personal Data Across the Data Environment

Executive Risk Monitoring: The Complete Guide to Detecting Digital and Physical Threats Before They Escalate
