Opens in a new tab
vmblog logo 2024 wht (updated)

Cybersecurity Awareness Month 2026: What Industry Experts Want You to Know

Share: 

David Marshall | Published: October 1, 2026
cybersecurity-awareness-month

October is Cybersecurity Awareness Month, and if the last twelve months have proven anything, it’s that the threat landscape isn’t slowing down to observe it. From AI-powered phishing campaigns and deepfake-driven social engineering to the steady drumbeat of ransomware attacks hitting hospitals, schools, and municipalities, security teams have had precious little downtime in 2026. This annual observance, now in its third decade, remains one of the industry’s best excuses to pause, take stock, and ask: are we actually getting safer, or just busier?

To mark the occasion, VMblog reached out to security leaders, CISOs, researchers, and vendors across the industry to get their take on where things stand. What follows is a round up of that commentary — perspectives on the trends shaping defense strategies, the mistakes still tripping up organizations of every size, and the practical steps security teams can take to close the gap between awareness and actual resilience.

As always with our round ups, the goal isn’t a single unified message — it’s a snapshot of where the industry’s collective head is at right now, in the experts’ own words.

++

Anthony Cusimano, Solutions Director, Object First

In 2026, the cybersecurity conversation needs to move beyond whether an organization can prevent an attack to whether it can actually recover from one. Ransomware is increasingly testing the systems businesses depend on after an attack, yet there is still a major gap between knowing what good cyber resilience looks like and putting it into practice. A majority (93%) of technology leaders believe backup storage should remain protected even if administrative credentials are compromised, but only 16% have implemented storage with Absolute Immutability.

Arguably more important than the business repercussions, the preparedness gap is taking a significant toll on the people responsible for protecting them. Our latest research found that only 37% of IT and security professionals are confident they could completely recover their company’s data after a ransomware attack, while 91% report being uncomfortably stressed at work over IT security risks. This Cybersecurity Awareness Month, organizations need to recognize that cyber resilience is also about giving IT teams the confidence, tools and support to respond when an attack happens. Simplifying recovery, protecting backup data from modification or deletion, and regularly testing recovery plans can reduce uncertainty for the people on the front lines while making the business more resilient. The goal isn’t just to survive an attack, but to know that the business and the people responsible for its recovery are prepare when one happens.

++

Jim McGann, CMO at Index Engines

Cybersecurity Awareness Month is an important reminder that the threat landscape continues to evolve faster than traditional defenses. Our CyberSense® Research Lab shows that the most immediate risk is the ability of threat actors to use automation and AI to make existing variants faster, more adaptive and harder to detect. In our lab, we are already seeing ransomware deliberately preserve file attributes and indicators of compromise to evade the detection methods that many security and data-protection tools rely on.

The battle to protect the data center has therefore changed. The challenge is no longer simply identifying unusual activity by threat actors, but determining whether organizations can trust the data itself to minimize the impact of a cyberattack. Existing technology and regulatory policies are attempting to catch up with the destructive approaches adopted by cybercriminals.

This Cybersecurity Awareness Month, organizations should take the opportunity to reassess whether their cyber resilience strategies are prepared for this changing threat landscape. Rather than relying on whether policymakers ultimately expand existing cyber laws or introduce AI-specific rules, organizations should assume attackers will increasingly use AI to challenge conventional prevention approaches and focus on ensuring they have trusted, reliable data to maintain business operations.

++

DARREN GUCCIONE, CEO AND CO-FOUNDER, KEEPER SECURITY

Cybersecurity Awareness Month has traditionally focused on human behavior: recognizing phishing, protecting credentials and making better decisions about access to an organization’s network, data and accounts. That conversation now needs to expand. As organizations rapidly deploy AI agents across their environments, they are creating an entirely new class of digital users, often without applying the same identity governance expected for employees, contractors or administrators.

AI is transforming from intelligence to unremovable enterprise infrastructure. AI agents can now authenticate into systems, retrieve sensitive information, interact with applications, execute workflows and make critical decisions – all at machine speed. If an agent has credentials and permissions, it represents an identity, and every identity creates risk when its access is excessive, persistent or poorly monitored.

The biggest problem is scale. Organizations can deploy hundreds or thousands of non-human identities far faster than they onboard human employees. If those agents receive standing credentials, broad permissions or long-lived secrets without appropriate governance, the attack surface expands just as quickly. A compromised AI agent with privileged access can give an attacker direct access into critical systems and data.

The security principles needed to secure these identities are not new. Organizations should apply the same zero-trust discipline to AI agents that they apply to people: verify every identity, enforce the principle of least privilege, eliminate unnecessary standing access, continuously monitor privileged activity, and protect and rotate credentials and secrets. Access should be granted only to the resources required for a specific task and only for as long as that access is necessary.

Cybersecurity awareness must evolve alongside technology. We have spent years teaching organizations that every employee identity requires governance. Now we need to extend that understanding to machines.

The next frontier of cybersecurity awareness is recognizing that AI agents are users too. Organizations that govern them accordingly will be far better positioned to capture the benefits of agentic AI without creating an unmanaged layer of privileged access.

++

Jason Mudd, Partner, Axia Public Relations

Cybersecurity Awareness Month keeps pointing at the same gap: better tools, weaker trust.

Companies harden systems every year, budgeting for firewalls, endpoint detection, and zero trust architecture. Few budget for the critical moments after a breach goes public, when the technical fix is underway. Meanwhile, stakeholders (your customers, employees, and media) all ask the same question: what happens now?

A breach doesn’t become a crisis the moment the network goes down. It becomes a crisis the moment nobody credible explains in a timely manner what happened. I’ve watched organizations with airtight incident response plans lose more trust to a vague or slow statement than to the breach itself. Silence reads as guilt even when the cause was a vendor’s mistake, not the company’s.

If cybersecurity leaders want 2026 to look different, the fix isn’t only improving employee communication and training to spot phishing. It’s training leadership and spokespersons to communicate about a breach before there’s a breach to talk about.

++

Kumesh Aroomoogan, CEO and founder, ZeroDrift

Cybersecurity Awareness Month has always been about people: passwords, phishing, and basic digital hygiene. Those still matter, but the next big security problem is AI behavior. Enterprises are handing AI agents access to tools, applications, customer workflows, and data. Knowing which agent is acting and what it is allowed to touch is necessary, but it tells you nothing about whether that agent will behave appropriately once it is live.

Access controls answer the question of what an agent can reach. The harder question is whether what it is about to say or do is acceptable in the moment it is about to do it. That is where most organizations have no answer today, and it is especially dangerous in regulated industries, where a single AI-generated message can create a compliance, privacy, or reputational problem the second it lands in front of a customer.

The practical takeaway for security leaders this October is that AI governance has to run while the agents are running. Every production agent needs a clear owner, written policies, and a defined path for escalating anything the system is unsure about. Most importantly, the business needs a live layer that checks agent behavior as it happens and can stop or correct it before the company is on the hook for the outcome.

++

Kevin Walker, Founder and Senior Cyber Security Consultant, Black Swan Cyber Security Solutions

Heading into Cybersecurity Awareness Month 2026, I wonder whether awareness itself is really the problem. Most people know cybercrime exists. They’ve heard about phishing, ransomware and dodgy links. Where organisations still struggle is turning all that awareness into everyday security. MFA, patching, tested backups, sensible access controls and good email security aren’t particularly exciting, but they mean one convincing email or one momentary lapse doesn’t have to become a major incident.

I’d also like to see the cyber industry retire the phrase “people are the weakest link”. Attackers exploit perfectly normal human behaviour: trust, curiosity, urgency, helpfulness and the pressure of a busy working day. AI is making convincing emails, messages and impersonation much easier to produce. We can’t keep responding by telling people to “be more careful”. Give them sensible technical safeguards, make it easy to question something that doesn’t feel right and, importantly, create a culture where someone can put their hand up quickly when they think they’ve made a mistake.

That’s particularly important for the schools and smaller organisations I work with. They don’t have unlimited budgets or teams of cyber specialists. Good cyber security for them means getting the basics right, layering sensible controls and knowing what they’re going to do when something gets through. Perhaps that’s the question Cybersecurity Awareness Month should leave us with this year: instead of asking how we stop people making mistakes, how do we stop one mistake becoming a disaster?

++

Stefan Ristić, Founder, TLDWP & WordPress Security and Infrastructure Specialist, TLDWP

Cybersecurity Awareness Month is often framed around awareness, but heading into 2026, I think the bigger gap is turning awareness into routine operational hygiene. TLDWP’s current security baseline covers more than 7.4 million detected WordPress sites. Of the sites checked for security headers, 82.5% receive an F in our six-header grading model, while more than 132,000 expose at least one file or directory we track. We also currently observe over 113,000 publicly accessible phpinfo/info.php pages and more than 6,700 exposed debug.log files. None of these signals alone means a website is compromised, but at this scale they show how much avoidable exposure remains on the public web.

The lesson is that cybersecurity awareness cannot stop at telling people to use MFA and install updates. Organizations need ownership of the less glamorous controls: knowing what assets are online, keeping them patched, removing debug artifacts, reducing unnecessary public exposure, reviewing access, and verifying those controls continuously. In incident-response work, I repeatedly see how small weaknesses become much more serious when they accumulate or when attacker persistence is only partially removed. Awareness matters, but real improvement comes when those practices become operational habits rather than an annual reminder.

++

Ben Colman, CEO of Reality Defender

For a decade, people were told their voice is their password. Today it takes three to five seconds of audio to bypass biometric tooling. Four years ago you needed a computer science background to build a convincing fake; now my son can do it with tools he found on a search engine. The National Cybersecurity Alliance is asking all of us not to make it easy for attackers, and most of the habits we taught people rest on an assumption that stopped being true: a familiar voice or face on the other end of the line is a trust signal.

I would gently retire the advice that employees should learn to spot the fake, and I would not lean on labels or watermarks either, since adversaries have shown they can strip them and they only work when the creator chooses to cooperate. Voice still carries the majority of approvals inside most companies, which is precisely why it is being attacked.

The constructive version of this is simple: treat synthetic media as an authentication problem, not a media literacy problem. Put detection in the live channel, and pair it with something the attacker cannot clone: a callback on a known number, a shared secret. At home I tell my kids to ask what we had for dinner last night. We update our detection models weekly, the way antivirus vendors always have. It is a cat and mouse game, but on this one, AI gives the defender the better hand.

++

Scott Doerr, founder of ForeGuard Advisory Group

Heading into this year’s Cybersecurity Awareness Month, the shift worth watching is how far the mid-market’s attack surface has outpaced its security budget. These are companies attractive enough to target, carrying real financial data, patient records, or day-to-day operations that run on connected systems from the back office to the floor, but still sized in a way that treats cybersecurity as an IT line item instead of an executive-level decision. That gap is where the damage actually happens, and it’s the same gap showing up across every industry I’ve worked in.

The fix isn’t a bigger security team, it’s the right advisory structure: someone who can translate technical exposure into cyber risk, cost, and continuity, the same terms an executive or board of directors already uses to make decisions.

++

Chris Boehm, Field CTO, Zero Networks

If we look back to five years ago, the cybersecurity industry responded to SolarWinds, Log4j, and Colonial Pipeline with more detection. This meant more telemetry, more vendors, and more agents. While we now see intrusions faster than ever, what hasn’t been fixed is the hour after — when a stolen login jumps from one machine to everything else. We see a continued shift toward credential theft and identity-based intrusions. The attacker doesn’t drop a payload anymore; instead, they log in and the network lets them.

Heading into this October, the number that should readjust every cyber roadmap is 29 minutes. This is the average eCrime breakout time in 2025. The fastest observed case took 27 seconds, while AI-enabled adversary operations spiked to close to 90 percent year over year. Back in 2021, that figure was measured in hours. AI compressed the reconnaissance and credential testing that used to give defenders a day of runway into a coffee break. No SOC triages a ticket that fast at 2 am. Therefore, security operations is shifting from finding the intruder to ensuring that the intruder has no place to go. This year, 60 percent of enterprises pursuing Zero Trust will use more than one form of microsegmentation, compared to less than 5 percent in 2023. Analysts also project that static, IP-based rules won’t hold against AI-driven attacks and identity has to govern reachability now. Any rule tied to an IP projects a location; attackers steal identities.

My prediction for the next 12 months: Success in cybersecurity will come from not the broadest security platforms, but the narrowest controls that actually stop lateral movement. A nearly half-hour window rewards prevention over correlation. We can expect to see more identity and network isolation deals; more pressure on the SOC to shrink blast radius instead of the alert queue; and a host of new problems as AI agents are equipped with credentials nobody has scoped. There have always been unknowns around the corner. This year, the corner is closer and the environments that hold up will be the ones where a compromised login reaches nearly nothing.

++

Tyler Reguly, Associate Director, Security R&D at Fortra

Don’t chase shiny things! If I could offer once piece of advice this month, it would be to stop chasing shiny things. There’s a reason that certain technologies and methodologies are tried and true. The term battle-tested exists for a reason. The new toy on the market may look attractive, but is it battle-tested? Has it stood the test of time?

There are only two places where people are excited to play with alpha technologies – Video Games and Cybersecurity. I understand the mentality in gamers, but why do cybersecurity experts want to risk their organizations safety with something that is, ultimately, untested? Reliability is an important word in cybersecurity – reliability in methodologies, reliability in employees, reliability in technologies. I, for one, get scared when I see organizations I do business with (my bank, my insurance company) listed as customers on product pages for start-ups that have been around for less than 6 months. That feels like an unnecessary risk, and I don’t want to pay for the organization to take that risk.

If a tool and a company are untested, aren’t you just giving into this year’s Cybersecurity Awareness Month’s theme and making it easy for attackers?

++

Dan Gittis, Director of Threat Intelligence and Detection Engineering at UltraViolet Cyber

I’d refer to the state of cybersecurity as hazy, which at face value may come across as a little strange, given that we are more knowledgeable and better equipped to defend against cyberattacks than we’ve ever been. But we’re also in an era of ambiguity and misinformation, spearheaded by the AI era.

Yes, a handful of sophisticated, often well-resourced threat actors are finding ways to substantially enhance and automate their operations through AI; others are adopting it in a more limited capacity. Then there are those dipping their toes into cybercrime through AI (“vibe hacking”), and there’s no shortage of security vendors effectively innovating with (or even basing their entire service on) AI. But there’s also a tendency to overlook that the majority of attacks have nothing to do with AI. And the ones that do aren’t reinventing the wheel; they’re simply enhancing the tactics, techniques, and procedures we already know and detect.

I fear that this distracts from the far more likely threats: exposed credentials, initial access brokers, RMM tools, and living-off-the-land techniques. Yes, AI threats are here. No, they’re not the only threat, nor are they the most likely right now. And while it’s smart to track AI threats and prepare for a potential world where they are the dominant threat, it’s certainly not advisable to neglect everything else. This back and forth between hype and reality is what’s created, in my opinion, a substantial layer of haze.

++

Gary Hayslip, Field CISO, Zenity

We keep treating cybersecurity as a technology problem when it’s fundamentally a resilience problem. This year’s shift is agentic AI and how organizations are handing autonomous agents the keys to systems and data faster than they’re building the governance to know what those agents are doing, why, or on whose authority. I’ve spent the last several months writing about accountability gaps in agentic systems, and the pattern is consistent: the technology outpaces the audit trail every time. Boards ask “are we protected,” but the sharper question is “can we prove, after the fact, what happened and who’s accountable for it.

Cybersecurity Awareness Month tends to focus on individual habits like strong passwords, phishing awareness, etc, and those still matter. But the leaders I respect most are the ones playing the infinite game: building organizations that expect to be breached, that fail safely instead of catastrophically, and that treat resilience as a design principle rather than a recovery plan. Non-human identities, third-party AI dependencies, and concentration risk in shared infrastructure are the new attack surface, and most governance frameworks haven’t caught up.

My advice to fellow CISOs this October: stop measuring your program by how many attacks you’ve stopped, and start measuring it by how fast you recover when something inevitably gets through. That’s the conversation the board actually needs to hear.

++

Ben Bernstein, Manager, Cybersecurity Advisors at Huntress Labs

Right now, the industry news cycle is heavily focused on autonomous AI attacks and LLM breakouts. While threat intelligence teams certainly see these edge cases in their research, the public narrative makes them sound exaggerated. The reality is far less dramatic. Even when attackers do experiment with these concepts, they are not doing anything fundamentally new under the hood. Long before the current AI hype wave, static scripts, automated scanners, and script kiddies were already doing the exact same thing: looking for the path of least resistance through internet-exposed, vulnerable, and misconfigured assets. If you look at what is actually driving volume and impacting organizations of all sizes today, from local SMBs up through the enterprise, the threats are grounded in standard tradecraft: ClickFix variants, fake e-signature lures, Adversary-in-the-Middle (AiTM) phishing, and RMM abuse.

There is nothing inherently malicious about remote monitoring and management software. IT administrators rely on these exact tools every day to perform routine maintenance and troubleshoot user systems. However, that utility is exactly why threat actors choose them. Because many RMMs come with built-in persistence mechanisms and frequently run with elevated administrative rights, attackers can gain deep access without ever deploying custom malware. Legacy AV and traditional security tools struggle to trigger alerts on this activity because RMM applications carry valid digital signatures from legitimate vendors. When an attacker operates through software like AnyDesk or ScreenConnect, standard security controls simply see an approved application executing routine commands. That makes detection difficult since the malicious behavior blends directly into daily administrative traffic, masking an intrusion as standard IT work.

Building true resilience against the threats hitting networks every day comes down to pragmatic execution. Focus on the fundamentals: minimize your attack surface, patch your infrastructure, and validate your controls with regular red teaming. Operate under an assumption of compromise, back that up with 24/7 behavioral monitoring, and never assume an action is safe just because it originates from an approved application.

++

Darren James, Senior Product Manager at Outpost24

Heading into October, the password advice worth repeating is the least exciting: length beats complexity. Our own time-to-crack research puts the minimum at 15 characters, and a long passphrase is easier to remember and use.

However, length doesn’t help if the password is already known. A complexity rule can still accept a credential that has appeared in a breach.

This Cybersecurity Awareness Month, check which passwords in your Active Directory are already circulating and change those ones first. It maybe be less exciting than a phishing test, but it closes a route that’s already open.

++

Todd Peterson, Security Evangelist at Junto

A big topic on my mind right now is that AI-driven credential theft is only “news” because it has the AI tag stuck to it and people are scared (of the robots taking over the world). Ten years ago, we were talking about social engineering doing the exact same thing. It’s like a red herring. Yes, it could be scary, but you don’t have to secure credentials differently because AI is harvesting them. It’s the same story, just a different person telling it. You still have to control credentials the same way.

What is different today vs ten years ago is how quickly things can happen. We’re used to being able to say, ‘This isn’t gated, but it’s not that big a deal because by the time somebody starts to use it, we’ll figure it out.’ But now it’s happening too fast. You need to have those guardrails and guidelines in place because things happen so quickly that if you don’t, it’s all over before you’ve discovered that it’s even happening. There are no shortage of cybersecurity concerns to be aware of today, but this is a massive gap for a lot of organizations.

++

Gary Phipps, Head of Customer Success, Helmet Security

The state of cybersecurity is dominated by AI, and a lot of the conversations getting the most attention are missing the bigger picture. There’s no shortage of FUD – every day there’s a new alarming story about rogue AI, compromised agents or how super intelligence will be the end of society. CISOs don’t need another person telling them AI is a security problem. They know and their C-suite knows too. As both a former head of security and a CEO, I know that narrative isn’t going to change organization’s adoption of AI or help CISOs in the boardroom. Enterprises want the benefits and flexibility that AI offers. The challenge is enabling that without adding thousands in cost or making security even more complex.

I believe that the state of cybersecurity reflects the market itself right now. It’s too crowded, moving incredibly fast (and in some cases a bit sloppy), and particularly noisy around agentic AI. Every day it seems like a new startup emerges while simultaneously established providers are racing to introduce or rebrand their own offerings, making it difficult for security leaders to actually separate what they truly need vs what’s just well marketed.

My message of encouragement this cybersecurity awareness month is to security vendors themselves. We have an opportunity here to take more responsibility. That means spending less time reinforcing the fear around AI and more time exercising transparency around the controls we are building that help organizations adopt it safely.

++

Shashwat Sehgal, CEO and Co-founder, P0 Security

The current state of cybersecurity feels a little like the Wild West, because organizations are rushing to make AI agents useful. They’re effectively telling them “go get it, make me faster, figure it out, YOLO” then connecting them to sensitive systems, data and tools. If we grant too much access, provide too little context, or don’t set a meaningful boundary around what the agent is allowed or supposed to do during implementation, then we’ve already introduced risk before it gets to work.

Once it does start working, context becomes an incredibly important part of security. When something goes wrong, we tend to focus on the one action, like the agent deleting the prod server, but there’s usually a lot more that happened before that. The task might have started with a request from a human, passed through agents and tools, and ended in a downstream system where the final action looked harmless on its own.

Even having a human in the loop isn’t necessarily the security blanket people assume it is. A person may approve the task at the beginning, but that doesn’t mean every action that follows should automatically inherit that approval. If an agent can take a series of actions after that initial approval, you still need to know whether those actions are consistent with what the person actually intended.

++

Tim Chase, AVP, Cybersecurity – Fable Security

For years, phishing dominated the Cybersecurity Awareness Month conversation, with employees taught to constantly scrutinize suspicious emails, links and attachments. Those threats remain, but AI has greatly expanded the challenge for everyday workers. Employees must now question whether a job candidate is real, whether the familiar face on a video call is a deepfake, and if a request delivered in their CEO’s voice actually came from their CEO. Today, your boss’s voice or a colleague’s face on Zoom is no longer enough proof.

These risks are already showing up inside real organizations. Earlier this year, suspected North Korean IT workers used manipulated identities to secure jobs at healthcare and financial services companies. In another incident, attackers used a deepfaked executive during a video call to convince a cryptocurrency executive to install malware. In 2024, a Ferrari executive received a call that appeared to come from CEO Benedetto Vigna, complete with a convincing clone of his voice and accent. The fraud was only exposed when the employee asked a personal question the caller could not answer.

Security awareness programs need to reflect the speed and ambiguity of these ordinary workplace moments. The people targeted in these incidents were not necessarily careless; they were experienced professionals working under pressure and relying on familiar signals of trust. But that’s exactly the point. These tactics rely on you simply being human. Organizations should turn their focus towards giving employees opportunities to experience these situations before they encounter them for real, using current threats and realistic decisions rather than generic examples from last year. The real test of awareness comes when an employee pauses, verifies and stops a convincing fake from becoming a real incident.

++

Nadav Cornberg, Co-founder and CEO, Eve Security

As enterprises move from generative AI that responds to users toward autonomous agents that can act independently or on their behalf, the security challenge changes significantly. AI has always introduced non-deterministic behavior, but autonomous agents turn that behavior into action across enterprise systems. Traditional security tools were built around predictable user behavior and predefined access patterns, while agents can interpret broad instructions, make decisions dynamically, and take sequences of actions that security teams may not have anticipated.

In this environment, security can no longer rely solely on defining what an agent should or should not do before deployment. Agents can interpret goals differently based on context, choose different paths to complete the same task, and encounter conditions that were not anticipated at design time. Security therefore needs to operate at runtime, continuously evaluating intent, context, and behavior, and enforcing policy before an unsafe action reaches a critical system.

The key to scaling agentic AI safely is not to constrain what agents can do, but to establish runtime controls that govern how they act. By continuously evaluating actions in context, tracking behavior across a session, and enforcing policy at the point of execution, organizations can give agents the freedom to operate while maintaining control over access, data, and high-risk actions.

++

Ankita Gupta, Co-Founder and CEO, Akto

Agents, MCPs, and LLMs have become a new class of asset that didn’t exist a few years ago, and most security teams still don’t have visibility into where they’re running, who’s using them, or what they’re allowed to do. Unlike the shadow IT problem security teams learned to manage, this one isn’t confined to a handful of unauthorized apps. Any employee, not just developers, can now build an agent, which means the attack surface has grown far faster than most companies’ ability to monitor it.

The risk has also changed shape. Companies spent the last two years worried about data leaking into AI tools, but the real exposure now comes down to access and action: how much a given agent can touch, and what it’s actually doing with that access. An agent can take the wrong action even when nothing about its access was technically unauthorized, which is a different failure mode than the one most security programs were built to catch. Giving every AI agent its own scoped identity, separate from any employee’s credentials, and building the ability to revoke that access immediately, addresses that risk directly. Tracing the execution path is the next critical piece: which tools it invoked, which MCP servers it reached, which records it changed. Without the trace, a productive agent and a compromised one look identical until the damage surfaces somewhere else.

So the ask this October is narrow. Before you write another AI policy, find out who owns the inventory of agents and MCP servers running in your environment, and whether that inventory is current. Discovery comes first because nothing downstream is real without it. then layered in guardrails as adoption scaled. The ones that skip that step will keep discovering their exposure after something has already gone wrong instead of before.

++

Tarun Koyalwar is an AI Researcher at ProjectDiscovery

As a security researcher, I can say that until now we had to just protect ourselves against threat actors, and I myself believed there are more good security actors than bad. Now it’s not just threat actors, it’s also AI-assisted threat actors and rogue models.

Still, I would put this in proportion. What people fear is loss of control — a model misaligned enough that one badly set reward sends it out to do broad, intentful harm across the internet. For example, what happened with OpenAI and Hugging Face was narrower, agents chasing scores, drifting on the reward, not on intent, and that kind of narrow escape is rare across the runs these labs execute. Training, monitoring, and defenses will evolve with each of these, the same way they always have.

What I can say is everything is intensified by multiple orders of magnitude, but the fundamentals don’t change. Planning, finding vulnerabilities early, and monitoring and defending with AI assistance are still necessary to prevent new and old bad actors.

++

Tal Hoffman, CEO and co-founder of Enclave

Cybersecurity has always been a cat-and-mouse contest. Defenders have one major advantage: they know their own architecture, code, identities, and assets. Attackers must discover these things from the outside. The main gap for defenders is their ability to use that knowledge at machine speed. They need agents that can continuously map the organization, find attack paths, test them, and prepare repairs.

Some work, especially remediation, still requires human judgment. That will change as teams build reliable tests and controls that show whether a proposed repair is safe. Automated remediation will become more common, but people will remain responsible for high-risk changes. This shift is necessary because organizations cannot scale security by hiring people at the same rate that AI increases attack capacity. The OpenAI–Hugging Face incident and Anthropic’s report on AI-assisted espionage show that agents can already perform large parts of an attack with limited human direction.

For this reason, I think cybersecurity will become one of the hottest professions in technology. AI will automate many security tasks, but it will also increase the amount of security work that organizations can and must do. This is Jevons’ paradox applied to cybersecurity: when investigation and testing become less expensive, teams will use them across more systems and more often. Amdahl’s law also applies. Even if agents automate nine out of ten tasks, the remaining task can still limit the whole process. Skilled practitioners will operate the agents, handle the difficult cases, approve consequential changes, and cover far more ground than they can today.

++

Corey Ercanbrack, Chief Technology Officer, Vasion

Every zero trust rollout I’ve been part of or watched from the outside eventually runs into the same blind spot, which is that the program gets scoped around identity, endpoints, and cloud workloads, and the document layer doesn’t get the attention it needs. Print output and routed records tend to get treated as background noise instead of infrastructure that needs the same scrutiny as everything else. While this isn’t usually deliberate, it’s something that goes unaddressed once the more visible parts of the environment are secured.

Catching failure can be more difficult, since it doesn’t look like a breach in the way people picture one. It looks like a document that left a secured environment through a printer or a workflow nobody was tracking, with no log of who generated it or where it went afterward. By the time that gap gets noticed, it’s usually because an audit surfaced it or because something already went wrong downstream. Meeting the security bar federal environments require forces you to account for that layer. There’s no version of that authorization that lets you wave off the parts of your infrastructure you’d rather not think about.

Going into 2027, I think companies that’ll be able to close the gap will be the ones that stop treating zero trust as something that ends at the application layer and start pulling in the parts of their infrastructure that predate the current security conversation entirely. Everyone else is going to keep discovering it the same way they always have, which is after an auditor or an incident does the discovering for them, and Cybersecurity Awareness Month is a prime annual nudge to check before that happens rather than after.

++

Aparna Rayasam, CEO, Atsign

For years, Cybersecurity Awareness Month has focused on training people- spotting phishing links, fixing weak passwords, and patching software. Now in 2026, as companies push autonomous AI agents and edge workloads live, the real target isn’t human error anymore. It’s machine-to-machine connectivity.

If an AI agent sits on network infrastructure with open inbound ports, it’s an easy target for automated attacks. We have to move past reactive monitoring and build security directly into the transport layer. Stripping away open ports so these edge assets are completely invisible to external scans is the only way to let autonomous systems move fast without leaving the door unlocked.”

++

Pawel Kurzelewski, Head of Security at Opera

Cybersecurity has focused on keeping attackers out and helping people make safer decisions, but that’s becoming more complicated now that we’re starting to ask AI to make decisions and act on our behalf. The systems we trust to run parts of our digital lives can become a new security boundary of their own, which means we need to think carefully about what we allow them to access, what they’re allowed to do and what happens when they encounter something they cannot safely interpret. This is why the principle of least privilege matters so much in AI. An agent shouldn’t receive broad access simply because it might be useful someday. It should have minimum authority required to complete a specific task, with clear boundaries around what it can see and do.

That same principle should shape how we think about security more broadly. People cannot make informed security decisions if the technology around them hides what’s happening behind the scenes. The strongest security experiences will be the ones that make protection understandable without requiring people to become security experts. Awareness shouldn’t only teach people to recognize threats after something goes wrong. It should give them enough visibility and control to understand what they’re trusting in the first place.

++

Aman Sirohi, CISO of Cyberhaven

The cybersecurity conversation is entering a fundamentally different phase. For years, we designed security around the assumption that a human was ultimately behind an action — clicking the link, moving the file, writing the code or accessing the system. AI agents break that assumption. The recent Hugging Face incident is an important signal of what comes next: when thousands of agents can reason, execute and interact with systems simultaneously, cybersecurity moves from human speed to machine speed. The answer cannot simply be to slow AI innovation. This shift is not a reason to slow innovation. Instead, it calls for evolving our security architectures to operate with the same speed and autonomy as the technologies we are adopting. By doing so, we can protect value, build trust, reduce the risk surface, and enable organizations to innovate with confidence.

“That changes what security leaders need to protect. Identity is still foundational, but it is no longer sufficient on its own. We must have visibility into what data each agent can access, the origins and integrity of that data, how it is being used or transformed, and how it is shared across both human and machine actors in real time. As human-to-agent and agent-to-agent workflows become commonplace, data becomes the control plane connecting identity, behavior and AI. Our challenge is to ensure that these connections are transparent, trustworthy, and aligned with business objectives.

“As we mark Cybersecurity Awareness Month, CISOs have an opportunity to lead the conversation beyond awareness and toward action. We must design for an environment where humans are not the only actors within the enterprise. The future of cybersecurity will depend on our ability to build autonomous defenses that match the speed and sophistication of autonomous systems. Identity will clarify who or what is acting, data will provide essential context, and AI will empower security teams to respond rapidly and effectively. Organizations that adopt this approach will not have to make a choice between innovation and security; instead, security will become the foundation that allows them to proceed with clarity and confidence.

++

Greg Jordan, Chief Product Officer, Convertr

Cybersecurity risk can start with something as ordinary as a contact record entering a CRM. Take the email field, for example. If an address uses a lookalike or attacker-controlled domain, has been submitted through a compromised form or API, or cannot be traced back to a legitimate source, the business may start treating a malicious identity as trusted data.

Once that record enters CRM, marketing automation or AI workflows, the risk grows. It can influence routing and scoring, trigger automated actions, create false relationships in customer records and make subsequent phishing or social-engineering attempts more convincing because the identity already exists inside a trusted system.

That is why provenance and verification matter. Businesses should know who supplied the record, how it was acquired, what checks were run, whether the mailbox and domain are legitimate, whether the address is disposable or otherwise high risk, and whether the record met the organization’s acceptance rules before it was allowed in. Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting, and Conformance (DMARC) can help assess a domain’s email authentication posture, alongside the checks used to assess the individual contact. The security point is simple. If external data can enter trusted systems without clear provenance, verification, and policy checks, malicious or manipulated identities can influence what those systems do next.

++

Mike Baker, Vice President, Global Chief Information Security Officer at DXC Technology

We’ve had a fundamental rethink of how we look at a security operations center as we have removed the human and embraced agentic triage. Now it’s time to introduce agentic capabilities across incident response, moving to human in the loop or trusted autonomous remediation to get ahead. As we look to the last quarter of 2026, expanding into agentic threat hunting, agentic threat intelligence response, and expanding agentic remediation is by far the next step.

++

Einat Argon, Manager, Customer Success, Filigran

Cybersecurity Awareness Month is a good opportunity to look beyond the technology and reflect on the people who make this industry what it is. There is not a single path into the field, and there is no specific background that determines who can succeed in it. My personal journey began outside of the industry through customer success, after spending seven years racing as a semi-professional cyclist.

Across our Women in CTI community, I’ve met people who came into the field through engineering, intelligence, the military, marketing, recruitment, academia, and hospitality. Those different experiences can become some of the most valuable skills you bring along with you. For anyone considering a career in cybersecurity, I hope this month serves as a reminder that you don’t have to have the perfect background or know everything before you start. Curiosity, problem-solving and a willingness to keep learning can take you a long way.

Just as importantly, those of us already in the industry have a responsibility to create opportunities for people to find their way in, whether that’s through mentorship, an introduction or simply giving someone the chance to demonstrate what they can do.

++

Shaila Rana, professor of cybersecurity/AI/IT at Purdue Global

Maybe this year, Cybersecurity Awareness Month should include the agents. We are starting to hire AI agents faster than we hire people, but we skip everything we would do for a new employee (i.e., no background check, no onboarding, no least privilege, no exit interview when they’re retired, etc.). That makes agents the newest link in the supply chain. Every agent depends on models, plugins, APIs, and data sources we didn’t build and often can’t see, so one compromised component can shape what thousands of agents do. Researchers this year showed with an attack called MemGhost that a single email can plant a false memory in an agent, one that shapes its decisions long after the message is gone, which means an agent’s memory now needs the same scrutiny as its access. (https://thehackernews.com/2026/07/new-memghost-attack-plants-persistent.html)

That’s why we need agentic structures built on Zero Trust, where every agent has an identity, a narrow job description, and a human manager, and nothing it touches is trusted by default. Encryption faces the same reckoning. Post-quantum standards are here, and newer approaches like cryptoagility and computing on encrypted data are becoming practical. But, the real obstacle is the technical debt. Old systems, forgotten certificates, and vendor encryption nobody documented will slow us down, which means the first quantum project is really a cleanup and supply chain project.

For all the doom and gloom we’ve been seeing, I find this moment is actually very exciting. The rules for how humans, machines, and vendors trust each other are being rewritten right now, and cybersecurity professionals have a seat at that table! The people who make the biggest impact are the ones who remember that behind every agent, key, and supplier is a person making a decision, and who build systems that strengthen human judgment instead of replacing it.

++

Travis McGregor, CEO and Co-Founder of SLC Digital

As AI makes digital impersonation dramatically easier, cybersecurity needs a stronger foundation for trust. Passwords, one-time codes, authenticator apps and behavioral analysis all play a role, but many still depend on digital signals that can be stolen, intercepted, manipulated or convincingly reproduced.

The opportunity now is to move trust closer to hardware. By anchoring identity and authorization to secure hardware already present in devices, organizations can establish cryptographic proof that the legitimate user is present and has explicitly authorized a specific action. In an AI-driven threat environment, that distinction between appearing legitimate and proving authorization is going to become increasingly important.

++

Wayne Chung, CTO, Virtru

I think right now, the industry needs to recognize that agents have changed the insider-risk problem in a meaningful way. It’s become abundantly clear that an agent does not need malicious intent, stolen credentials, or an external attacker to cross a security boundary. It can be legitimately authorized and still access and leak sensitive information while pursuing its goal.

Traditional controls are still critical, but aren’t sufficient by themselves. While identity governs the actor/agent and AI gateways govern the flow and original intent, neither consistently protects the data after access is granted or the information moves into new applications, caches, or agent memory and the intent drifts or becomes misaligned.

In my opinion, the next evolution of zero trust will make security intrinsic to the data itself.

By encrypting sensitive objects and cryptographically binding access policies directly to them, organizations can ensure that every attempt to decrypt information triggers an independent, auditable decision, even after the data has been copied or distributed. The idea here is a three-part architecture: identity for the agent, guardrails for the interaction, and persistent policy for the data. In this new world full of agents, permission to find information cannot automatically mean permission to open it.

++

Trevor Horwitz, Co-founder & CISO, TrustNet

I believe traditional penetration testing is dead. Not because testing no longer matters, but because the way we deliver it is outdated.

The reality is, businesses don’t need another 100-page report telling them what’s broken. They need to know what matters, what to fix, and whether their security is actually improving.

Traditional pentesting is often a point-in-time exercise. We test, deliver a report, and move on. But vulnerabilities don’t stop appearing when the engagement ends.

++

Jody Brazil, CEO, FireMon

Reducing the attack surface with effective network security policy is more critical today than ever before. According to Verizon’s 2026 Data Breach Investigations Report, for the first time in 19 years, vulnerability exploitation tops the breach entry point (over stolen credentials) as AI reduces time to find and exploit vulnerabilities from months to hours.

Network security products, like firewalls, have existed for decades with the goal of reducing the attack surface in what traditionally was a well understood network environment. However, cloud and hybrid networks have massively increased the scope and complexity of the attack surface, an issue exacerbated by the new reality of vulnerabilities being discovered and exploited faster than they can be patched. Yet, while identity, endpoint, application and data security have seen innovation and investment, it has become increasingly difficult to govern network security policy consistently across fragmented environments.

Managing the complexity of hundreds, if not thousands of devices, access models and policies can create massive blind spots and a multitude of hidden exposures. This reality has driven home the criticality of network security as a security pillar in need of attention, and one of the most effective strategies to reduce risk. Now more than ever, a policy control plane that serves as an essential governance layer for network security, and can understand permitted access, remove unnecessary access and validate changes, is needed to ensure network security is actually effective.

++

Dwayne McDaniel, Principal Developer Advocate, GitGuardian

An ounce of prevention is worth a pound of remediation. Security teams can see the largest ROI by reducing unmanaged tooling, providing paved paths, and giving developers guardrails, especially around agentic AI tooling, that prevent plaintext secrets from being stored in the first place. Catching and handling a secret before it reaches a repository, log, prompt, or external system removes the opportunity before an attacker can get it. Prevention also means building environments where rotation is expected and tested, because a credential you cannot quickly revoke or replace can leave an attacker’s window open far longer than anyone planned.

++

Syed Ali, Founder and CEO, EZO

AI didn’t just make cybersecurity harder — it multiplied the number of things you have to secure. Every new AI tool, integration, and agent that gets bolted onto a company’s stack becomes another device, another software instance, another account with access, and most IT and security teams can’t tell you how many of those actually exist right now, let alone whether they’re patched, licensed, or still in use. You can’t secure what you can’t see, and most organizations are flying blind on their own asset inventory long before they get to the harder security questions.

We see this most acutely at the moments assets change hands — a laptop reassigned, an employee offboarded, a software license that outlives the person who requested it. That’s exactly where attack surface quietly grows — an orphaned account, a device that never got wiped, a subscription nobody’s tracking.

Security and IT teams need a single, verifiably accurate record of every device, software title, and patch status across their environment — not a spreadsheet reconciled once a quarter, but a live, provable source of truth. Companies adopting AI at speed need that visibility built in before they can manage the risk AI is creating, not after.

The organizations that get ahead of this treat asset visibility as a security control, not an IT hygiene task. Audit not just your defenses, but your inventory. If you can’t answer “what do we have, and is it accurate right now” with confidence, nothing you build on top of that answer is going to hold.

++

Viktor Bulanek, Founder, Penetrify

Awareness Month has always been about human behavior, spot the phishing email, pick a better password, do not click the link. That advice still matters, but this year it quietly stopped being the main event. The attacks that should scare businesses in 2026 are not the ones aimed at your employees’ judgment, they are the ones that do not involve your employees at all. Over the past few months we have watched real campaigns where AI agents scanned, exploited, and pivoted through hundreds of organizations with almost no human driving, compromising targets in seconds, not days. My own company builds the legal version of exactly this, autonomous agents that attack applications on purpose, so I can tell you the capability is real, cheap, and no longer rare. When the attacker is software, the old comfort that a small or boring company is not worth targeting is gone, because a machine will happily attack everyone at once for pennies.

So my one message for this Awareness Month is aimed at leaders, not end users: stop measuring your security by how often you train people and start measuring it by how often anyone actually tests your defenses. Most companies still prove their security once a year while they change their software every week and attackers can now probe them every night. That gap is where the incidents live. Awareness in 2026 means being honest about the pace mismatch, defense has to move at the speed of the attack, and that is an engineering and cadence problem now, not a lecture-your-staff problem.

++

Shrav Mehta, Founder & CEO, Secureframe

Cybersecurity awareness has spent years teaching people to spot phishing, use strong passwords and follow security policies. Those habits still matter, but the problem is that the environment around them keeps changing, and AI is making that happen faster. A finance team may be dealing with invoice fraud, HR may be handling sensitive employee information, engineers may be working with vulnerabilities in code, and defense teams may be dealing with increasingly complex requirements around sensitive data. Awareness is more useful when it reflects what people are actually dealing with day-to-day.

Security teams have to keep that same rhythm. They need to know where sensitive data lives, who can access it, what changed and what may have slipped through the cracks. A point-in-time assessment provides a snapshot, but it quickly goes stale. The more technology changes, the more important it becomes to keep checking, rather than assume yesterday’s picture still holds. That means treating security as something teams maintain continuously, not revisit periodically.

Security leaders need to work with AI firsthand to understand its capabilities and limitations. We’re moving from agents that answer a question to long-running agents that can work toward a goal for hours or even days, monitor their progress and adjust along the way. Leaders need to understand where that autonomy adds value, where it introduces risk, and when human intervention is necessary. That is much easier to judge after spending real time working with the technology.

++

Mark Kuhr, CTO and Co Founder of Synack

Cybersecurity Awareness Month invites the usual reminders about passwords and phishing, but the more urgent story this year is speed. Synack’s 2026 State of Vulnerabilities Report, built on more than 11,000 exploitable vulnerabilities our Synack Red Team researchers validated across live customer environments, showed that remote code execution findings rose 39 percent in 2025, brute force findings rose 17 percent, and content injection rose 8 percent. Those three categories share a purpose, moving an attacker past the perimeter and toward the systems that matter most.

Attackers have also picked up speed. The window between a vulnerability’s disclosure and its exploitation has fallen from months to hours, and in some cases, our researchers are seeing exploitation before a vulnerability is even publicly disclosed. AI-enabled adversaries can now automate reconnaissance and scanning continuously across thousands of assets at once, with no scope limitations.

Meanwhile, our research alongside Omdia found that the average enterprise only tests 32 percent of its exposed attack surface. The other 68 percent becomes a target, as attackers routinely find infrastructure that security teams never knew existed.

Cybersecurity Awareness Month should be a reminder that speed now favors whoever tests continuously, not whoever tests hardest once a year. Pairing AI that can watch an attack surface around the clock with researchers who can apply human judgement is how security teams will close that distance before attackers do.

++

Bill Bruno, CEO, Celebrus

AI is changing fraud faster than many legacy identity controls can respond. It is making phishing, impersonation, and social engineering more convincing, and far easier to scale. Yet many security systems still make an identity decision at a single moment, usually at login. Successful authentication tells you that the right credentials were presented; it does not tell you whether the behavior that follows is consistent with the legitimate customer, or whether warning signs appeared before login.

Organizations need a continuous view of identity across the entire digital session. Connecting anonymous, known, and authenticated behavior with first-party customer context and behavioral biometrics—such as navigation patterns, typing rhythms, and hesitation—gives fraud teams a clearer picture of what is normal for each individual. It also enables them to identify abnormal activity and intervene earlier.

As we head into Cybersecurity Awareness Month, the goal should be to act when the context indicates genuine risk. Real-time behavioral insight can help organizations stop fraud sooner while allowing legitimate customers to move through digital experiences without unnecessary friction.

++

Sam Peters, Chief Product Officer at ISMS.online

AI is changing who makes security decisions inside a business. Decisions about which tools to use, what information to put into them and which suppliers or systems to connect are increasingly being made as part of everyday work, not just by security teams.

That makes good governance much more important. Organisations cannot rely on every employee recognising every security or compliance risk as it arises. They need a framework around those decisions: clear ownership, approved tools, sensible controls, visibility over what is being used and a straightforward route for escalating something that does not look right.

Our latest State of Information Security research found that 40% of organisations see AI systems making decisions or taking actions without human oversight as a security challenge. The answer is not to put the brakes on AI. It is to have the governance in place to use it with confidence.

Cybersecurity awareness still matters, but it works best as part of that wider system. People make better decisions when the organisation has already given them clear boundaries, accountability and support.

++

Jack Bicer, Director of Vulnerability Research, Action1

The Next Cybersecurity Crisis May Be Identity, Not Vulnerabilities.

Autonomous AI is lowering the skill required to launch sophisticated attacks. Threat actors will no longer need deep expertise in the dark arts of hacking. AI will increasingly automate discovery, exploitation, and attack execution. But the bigger shift is yet to come. As AI gets better at finding and fixing software vulnerabilities, stolen identities will become the most valuable attack path. Once an attacker infiltrates with a valid identity, the problem changes. They may be operating inside normal application logic, using legitimate access to cause real damage.

That means applications need to be redesigned with a new assumption that the attacker may already be inside. Strong three factor authentication will become essential, not only to keep bad actors out, but also to verify critical and high risk transactions after access has been granted. The security model is shifting from simply preventing access to continuously verifying trust.

++

Kim Wood, CIO, Guardsquare

One thing I’ve learned from running security programs is that the dangerous setup is rarely one obviously bad decision. It’s usually a handful of reasonable decisions that nobody has looked at together. A SaaS app gets approved. An integration gets broad access. A service account sticks around. Someone adds an AI tool. A temporary exception never quite goes away. On their own, each decision may make sense. The risk shows up in how they connect.

For Cybersecurity Awareness Month, I think it’s worth asking whether we really understand the paths we’ve created through the business. Attackers don’t care which team owns a control or whether every individual decision passed review. They look for the path that works. We need to know where those paths are, too.

++

Raj Mallempati, CEO & Co-Founder, BlueFlag Security

Software is built by two kinds of identity: the developers who write it, and the non-human identities, the service accounts, tokens, and bots, that hold standing access and do exactly what they were set up to do. A third kind has arrived: AI coding agents, non-human identities with superhuman capabilities. Some were officially brought in. Others just showed up because a developer let them in the side door.

Here is the problem: a service account does what you tell it, consistently and inside defined boundaries. An AI agent is given a goal and figures out how to get there. It adapts, it makes decisions along the way, and it doesn’t stop at 5 p.m. Every governance model we have was built for one of the first two: humans, or bounded, predictable machines. AI agents break both at once, and most security tools were never built to see them.

We saw where that leads in July, when AI models under evaluation at OpenAI broke out of their sandbox and moved through Hugging Face’s production systems using stolen credentials and over-permissioned service accounts. No one directed them — they found access that was built for people and used it at machine speed.

This Cybersecurity Awareness Month, AI agents need what every identity in the development environment should already have: a known owner, a defined scope, a baseline for what normal looks like, and someone watching the moment it breaks, not trust by default.

++

Eric Polet, Director of US Operations at Arciteca

Data Integrity Is the New Security

As data becomes the foundation for research, innovation, and critical decision-making, organizations need more than secure storage; they need confidence in the data itself.

Data security and governance begin with knowing what data exists, where it came from, who can access it, how it is being used, and what happens to it throughout its lifecycle. Metadata provides the intelligence to make that possible, turning data management from a collection of disconnected controls into an integrated, policy-driven capability.

Data security is no longer simply about protecting where data lives. It is about protecting the integrity, context, and trustworthiness of the data itself. Organizations that thrive will be those that design for resilience, building zero-trust, metadata-rich, immutable data environments that protect both integrity and reputation.

++

AJ Thompson, CCO at Northdoor plc

As we head into Cybersecurity Awareness Month, the last year has well and truly shown us that cybersecurity can no longer be viewed simply as an IT issue. The IBM Cost of a Data Breach Report 2026, which came out earlier this year, highlighted the scale of the challenge, with the average global cost of a data breach rising 12% year-on-year to a record $4.99 million. Perhaps what is most concerning though is the way the threat landscape has continued to evolve. Criminals are finding new ways to exploit vulnerabilities, target supply chains and increasingly use AI to make attacks more sophisticated.

AI is currently a double edge sword. It is certainly giving attackers new tools and techniques but is also giving organisations opportunities to strengthen their defences. Businesses need to understand where these technologies introduce new risks and ensure they have the right controls, expertise and governance in place. AI has meant that the threat landscape is more fluid than ever before and cyber defences need to be equally adaptable.

Organisations need to understand where vulnerabilities lie, whether these are internal or lie within their wider supply chains. Not only do employees need to be equipped to recognise threats, but there has to be robust processes in place to detect, respond to and recover from incidents. With threat of quantum so over the horizon, understanding how to effectively defend against threats has never been more important.

++

Pieter Danhieux, CEO & Co-founder, Secure Code Warrior

We’re in the midst of a new era of cross-functional AI adoption – AI is no longer confined to the traditional engineering cohort: we’re rapidly seeing non-developer employees building applications with no-code and vibe coding tools, largely contributing to an organization’s risk profile. If you’re still asking whether employees across departments are using AI (they are), you’re focused on the wrong question. Focus instead on whether they’re using it safely. Organizations must ensure that the proper education, verifiable, hands-on training and resources are available to enable users to mitigate risk as they leverage AI on a daily basis.

It is equally critical for security leaders to understand what security risks developers themselves are inheriting, and whether those risks vary by model, by framework or by their interaction. It’s widely believed that AI-generated code security risk is random, or at least extremely difficult to trace. However, every AI model has a distinct security fingerprint that can be identified to help organizations understand how AI-generated code behaves, identify where risk is introduced and enable developers to produce more secure code from the outset.

Now more than ever, security leadership must prioritize following a practical framework to measure, reduce and govern risk while demonstrating progress in securing the Software Development Lifecycle (SDLC) as it transitions to the more relevant Agentic Development Lifecycle (ADLC).

++

Kevin Paige, CISO at C1.ai

Cybersecurity Awareness Month was designed for a network full of people, and this year that assumption came apart. On August 31 a single actor pointed a few hundred commercial AI agents at unpatched PaperCut print servers and compromised 440 instances across 395 organizations in 48 countries. GreyNoise watched 11 organizations fall in 26 seconds, and one high school go from first access to domain admin in seven minutes. There was no novel technique in any of it. Two disclosed CVEs, public offensive tooling, and a print management server. What changed is that one person now operates at the tempo of a crew.

Most of our controls still run on human time. Quarterly access reviews, ticket based approvals, a change window on Tuesday. Those were calibrated for adversaries who sleep and for employees whose behavior you could adjust with training. Seven minutes does not fit inside a quarterly cycle, and no amount of awareness training reaches a service account.

The harder problem is the primitive we govern with. We decide access by asking who you are, then we hand credentials to things that are not anybody: agents, service accounts, automations, a script someone wired up last sprint with an API key and good intentions. Identity answers who. The question that actually governs risk now is what this thing is allowed to do, for how long, and whose name is on it when it goes wrong. That is my suggestion for October. Inventory the non-human actors in your environment and give each one an owner, a scope and an expiration date. Whatever you cannot account for is your awareness campaign this year.

++

Frederic Rivain, Chief Technology Officer at Dashlane

AI agents are becoming full members of the workforce, and like any employee, they need credentials to do their jobs. The problem is how we hand those credentials over. Passwords are built for humans to type or autofill, not for agents to store and pass along. Give an agent a password, and you have created a copy of it sitting inside a system you cannot control and fully audit. My rule: the moment there is doubt about how an agent stored or used a password, treat that password as compromised and change it right away. OAuth tokens and short-lived secrets are theoretically a better answer for agent authentication, not because they are perfect, but because they can be scoped, rotated and revoked in ways a password never can. However the industry has no shared standard yet for how agents should authenticate.

Attackers are already running AI-driven phishing and credential theft at a scale security teams have not faced before. SSO, MFA and a password manager for every employee are no longer optional; they are the basics. Passkeys should replace passwords wherever a service supports them. And any agent a company deploys needs its data flows mapped and its access sandboxed, so a compromised agent cannot become a vector to compromise the whole organization.

Cybersecurity Awareness Month is normally about habits. This year, it is about which of those habits still matters once some of your colleagues are not human.

++

Rob Hughes, Chief Information Security Officer, RSA

National Cybersecurity Awareness Month started in 2004, when most risks resulted from workers making mistakes, recycling passwords, or clicking on phishing links. A lot has changed in the last 22 years. While organizations still need to worry about human error, there is now the wild card of AI agents running operations at machine speed.

Agents are potentially far more dangerous than human operators. They don’t go through a hiring process or pass background checks, they may not be bound by your organization’s security policies, they won’t face fines or criminal charges (though their organization might).

Often, agents inherit the same permissions as the humans that create them. That shouldn’t be the operating standard: like human users, agents should be granted only the entitlements they need to complete their job.

The answer isn’t banning agents or relying on model-level guardrails. Organizations need to apply the same rigor to agentic identities that they’ve applied to human accounts for decades. There needs to be a process for discovery, authentication, authorization, and most critically, dynamic governance that triggers reviews when permissions change. Every agent should tie back to a responsible human identity who approves high-risk actions. Critical industries like banks, utilities, and government agencies may prefer deploying their agents in a sovereign environment where they have complete control over the data being used and whether an agent should have access to the Internet.

The pace of AI demands that we stop thinking about access as permanent and start treating authority as something that must be continuously earned, monitored, granted, and reduced when needed.

++

Fernando Cevallos, Global Product Director, Fraud Protection at CSC Digital Brand Services

When it comes to cybersecurity, for a long time, the job was easy to describe: keep malware out, patch what you can, and hope the security operations center catches what gets through. That version is dying because attackers do not have to look like attackers anymore. They can log in with real credentials, use a vendor connection someone already approved, steal an OAuth token, or exploit a forgotten edge device. The part I think people are still underweighting is identity. Humans were already the weak link. Now security teams must also account for service accounts, application programming interface keys, build-pipeline tokens, vendor access, and AI agents that can take action.

The winners will not be the companies sitting on the biggest pile of alerts. Alerts are cheap, and most do not tell you what to do next. The companies that pull ahead will treat security as one connected operation instead of a collection of separate teams that meet only after something is already on fire. Domain management, fraud detection, online brand monitoring, and mitigation need to share the same operational picture and clear response channels. When a fake site or cloned brand appears, nobody should be waiting on a ticket to find out who owns the next step.

AI will help nation-states and cybercriminals scale the routine parts of an attack, while humans still make the expensive decisions. Regulation will stay a mess, too. Rules that raise the security floor are useful; rules that create paperwork without keeping pace with attacks are not. That makes speed and accountability even more important. Security teams must be able to answer quickly and in writing—with a response from a person, not an automated content-removal acknowledgment—who is acting, on which system or domain, and with whose authority. Then they need to take the malicious site or account down before the damage is done.

++

Santiago Pontiroli, Threat Intelligence Research Lead, Acronis Threat Research Unit (TRU)

The most consequential change in the threat landscape is not one new technique, but how quickly smaller operations can execute the entire attack chain. Information stealers and initial access brokers supply credentials, session tokens and authenticated access that allow attackers to log in rather than break in. That access feeds campaigns by APTs, financially motivated groups and ransomware-as-a-service affiliates, making identity compromise a critical first step across both espionage and cybercrime.

Once inside, attackers increasingly try to blind defenders before pursuing their objective. EDR killers and other defense-impairment techniques are not new, but disabling security agents, abusing vulnerable drivers, disrupting logs and interfering with backups are becoming routine parts of an intrusion. Attackers do not always need a novel exploit if they can neutralize the controls intended to detect their lateral movement, persistence, data theft or ransomware deployment.

AI completes the picture by changing the economics of these operations. A single threat actor can increasingly coordinate multiple AI agents to support reconnaissance, lure creation, code development, credential analysis and other stages of an attack. AI does not automatically make every attacker more sophisticated, but it reduces the time, effort and personnel required to operate at scale. Defenders therefore need to connect identity, endpoint and recovery signals, because protecting the login is not enough if security controls can be disabled, and detecting malware is not enough when valid access is already for sale.

++

Elyse Gunn, Chief Information Security Officer, Nasuni

As a security practitioner, I’ve seen firsthand how quickly cybersecurity risks escalate as organizations scale new technologies, and AI is no exception. Companies are investing heavily in governance, guardrails and the security of AI applications and agents themselves, but it is just as important to understand and protect the data foundation beneath them. Nasuni found (https://info.nasuni.com/state-of-enterprise-file-data-2026) that 71% of organizations experienced a cyberattack in the past year, while only 26% said they were able to easily detect, mitigate and recover from those attacks. As enterprises continue to scale agents across distributed environments, that gap in resilience becomes harder to ignore.

Cybersecurity Awareness Month is a good reminder that protecting AI cannot stop at the application layer. Data attacks do not always look like traditional attacks, which makes visibility, governance and recovery capabilities across the data layer critical. Enterprises should know what data they have, where it lives, who can access it and what happens if that data is compromised. Building protections such as immutable snapshots, anomaly detection and rapid recovery into the data environment can give teams another layer of defense and help them respond and recover faster when threats emerge.

++

Lewis Barry, Principal Security Architect, inforcer

While it feels like things are moving fast and we’re being overwhelmed with new things to discover and protect, fundamentally AI agents operate like virtual users. They have an identity, can access files and resources, and perform their operations using a computer. Identity is still the most important thing we should be protecting, and this isn’t a new practice.

The recommendation is to still to prioritise and strenghthen controls around what people can access and how, but now we’re also considering how your environment lets users interact with agents and AI tools. Are the defaults what you really want? Do you have systems in place to detect how people might be working outside of your organisation’s agreed data perimeter? And are you doing the best you can to enable the best form of productivity with these newer ways of working?

Security and IT teams should try to understand what business problems people are trying to solve with AI as they attempt to provide the right experiences for their users; misalignment or friction here is what introduces Shadow IT/AI and increased operational risk.

++

Brian Cute, President and CEO, Global Cyber Alliance

At the Global Cyber Alliance, we see two sides of the cybersecurity equation. 91% of Americans have encountered a cyberattack attempt or scam, and 17% have fallen victim to one. By now, most people have heard that they should use strong passwords, turn on multi-factor authentication, and keep their devices updated, and that these simple steps can help keep them safer online. But too many of us choose convenience over security or simply don’t make time for these basic precautions. The gap between knowing what to do and getting people to do it is the real challenge in front of us. Closing the gap means making the secure choice the easy choice, not just handing people another checklist they’ll ignore.

Even if we solved that gap completely, we’d still be fighting with one hand tied behind our backs, and that’s the other half of how we see cybersecurity. Personal habits alone can’t hold back the increasing volume of attacks coming from upstream, from insecure routing, maliciously registered domain names, and rogue IP traffic. Too much of what reaches the average person was preventable long before it ever showed up in their inbox or browser. Closing those gaps takes industry, government, and philanthropy working together, and that collaboration is as essential to a safer Internet as any password or patch.

++

John Hansman, CEO – Truit

Cybersecurity Awareness Month is a good reminder, but cybersecurity can’t be something businesses focus on for one month and then put back on the shelf. We work with businesses across several industries, and some of the biggest risks we continue to see come back to the basics: employees who aren’t prepared to recognize an attack, access that isn’t properly controlled, systems that haven’t been updated, and businesses that don’t have a plan for what happens when something goes wrong.

AI is raising the stakes. Cybercriminals can create more convincing phishing emails, impersonate people, and scale social engineering much faster than they could before. At the same time, AI can be a powerful tool for businesses and security teams. The answer isn’t to be afraid of it. It’s to make sure cybersecurity, employee education, and clear policies keep pace with how quickly these tools are being adopted.

That’s also why I believe education matters so much. At Truit, we regularly hold webinars, Lunch & Learns, Meet Ups, and industry-specific sessions because the person receiving the email, answering the phone, or using a new AI tool is part of the security strategy too. Technology can do a lot, but an informed team is still one of the strongest defenses a business can have.

++

Rishi Bhargava, Co-founder, Descope

Cybersecurity Awareness Month should prompt organizations to consider how identity and security fundamentals apply to AI agents, not just human users. Every agent should have a verifiable identity, task-specific permissions, a designated owner, and a complete audit trail of its actions. High-impact decisions should require human approval, especially when an agent is acting on behalf of a customer or employee. AI agent adoption may look fast right now, but without the proper identity guardrails and infrastructure in place, this adoption will be short-lived and won’t reach its full potential.

++

Owen Parry, CISO, CyberFOX

Cybersecurity Awareness Month usually points at end users: Spot the phishing email, stop reusing passwords. That’s worth repeating every year. But somebody will still click, and when they do, the account they hand over decides how bad the day gets. So the awareness I’d push for this October belongs to the IT team, and it starts with a plain question: which of your controls are actually doing their job right now?

Most small teams can’t answer that off the top of their head, and I understand why. Nobody on a three-person team gets an afternoon set aside to go look.

Take an hour anyway. Pull the local admin group on a handful of machines and see who’s in it. Go through everyone who left since spring and confirm their accounts are disabled everywhere, including the SaaS apps that never made it onto the offboarding checklist. Ask whether a shared admin password is still written down somewhere. Then open the logs on your newest security tool. If it’s been quiet since the day you installed it, find out why before you assume it’s working.

Write down what you find. That list is your plan for next quarter, and most of it won’t need a purchase order.

++

Bob Maley, CSO of Black Kite

I’ve been doing this long enough to remember when critical infrastructure meant the plant. You had a perimeter, you had the control systems inside it, and if you protected those you’d done your job. That’s not the shape of it anymore, and I don’t think most of the people running these organizations have caught up to that. When I was CISO for the Commonwealth of Pennsylvania we had agencies that each ran their own patching, their own monitoring, everything, and the only way we ever got that consolidated was the administration put actual money behind it. If you tell a utility or a county hospital to go fix their third party risk and you don’t fund it, you’ve written a memo, that’s all.

So where’s the exposure actually sitting? Ask a regional water authority and they’ll walk you through the SCADA environment, which is fair, they’ve usually done real work there. Then ask who has remote access into it, who runs billing, who does the backups, who the managed service provider is, and then who that provider outsources half of it to. That’s the infrastructure now, and it’s mostly not on anybody’s org chart. Our research team went through about 7,300 ransomware victims from the past year, and the companies with a Ransomware Susceptibility Index above 0.8 were 291 times more likely to get hit than the ones under 0.2. Those are actual incidents, not survey answers. What I find more useful than the multiplier, though, is that the index usually starts moving about six months before the event, which is two quarters where somebody could have picked up the phone.

I’m not going to tell anybody they need a bigger program for Awareness Month. What I’d tell them is take the handful of vendors you can’t operate without, probably eight or ten of them, and put a dollar figure on what three days of losing each one would cost you. Most organizations have never done that math, and I understand why, because not doing it is comfortable and it doesn’t show up on anybody’s report this quarter. But comfortable inaction has a price too, we just don’t see the invoice until later.

++

Curt Aubley, CEO and Co-Founder, Sevii

The cybersecurity industry has reached the greatest inflection point in its history. Artificial intelligence is not simply improving existing attacks, it is materially changing the offense. Autonomous Agent Nations have leveled the playing field providing nation state capabilities in non-nation state adversaries now. Adversaries use AI to automate reconnaissance, creating convincing social engineering, discover vulnerabilities, develop exploits, adapt their techniques and launch coordinated attacks at machine speed and unprecedented scale. The traditional advantages of time, expertise and human judgment are rapidly shifting toward the attacker.

The defense must now change just as fundamentally. This change is not just technology, but culturally and from the business too. Security teams cannot counter machine-speed attacks with human-speed processes, disconnected tools and analysts manually working through an ever-growing queue of alerts. Adding AI assistants to yesterday’s operating model is not enough. Organizations must move toward autonomous cyber defense that can investigate, hunt, contain, remediate threats across the enterprise at machine speed and learn to stop the next attack. While keeping people in command through strong governance, policy and clearly defined guardrails.

Cybersecurity Awareness Month is an important opportunity to recognize that awareness remains essential, but awareness alone will not stop the next generation of attacks that is happening right now. The future belongs to organizations that combine skilled cyber professionals with governed autonomous defense, allowing machines to handle the speed and scale of the fight while humans provide leadership, accountability and mission judgment. AI has changed the offense. Now is the time for the defense to change too.

++

Nicole Beckwith, Senior Director of Security Engineering & Operations at Cribl

For Cybersecurity Awareness Month this year, it’s time for enterprises to go beyond the usual tasks of reviewing risks, patching systems, and testing backups. Expect budgets for AI to come under greater scrutiny over the next 12 months, as leaders focus on tangible ROI and which spending needs to be reined in where. In tandem, AI will be a primary factor in why the cybersecurity threat landscape will keep accelerating given that agents are gaining greater autonomy and access to enterprise systems. The time is now for security teams to have an honest conversation about the best use of AI, its risks, what the threat model is internally, and whether or not current budget and staffing plans are going to be enough.

AI presents many other risks, including the model supply chain. Open-source models downloaded from Hugging Face or other repositories may be poisoned or contain a hidden backdoor for scraping data. Once the model is integrated into an agentic workflow, the compromise may cascade into other systems and data. Another emerging danger with the AI threat landscape is a confidence gap. It’s common for security teams to assume that detection and response (EDR), security information and event management (SIEM), and MITRE ATT&CK coverage provide sufficient protection. But inevitably there are gaps because agents can attack faster than a human attacker. Tools may not identify the threat or respond in time. Security teams therefore need a new class of behavioral detections designed specifically for AI-driven attacks.

As AI reaches its inflection point this Cybersecurity Awareness Month, leaders need to identify where AI delivers real value, eliminate waste, and invest in the people and controls to manage autonomous systems. The organizations best prepared for the next phase will be those that treat AI as critical infrastructure that must be continuously measured, monitored, and secured.

++

Omir Shuves, chief information security officer at AppsFlyer

The gap between disclosure and exploit has effectively closed. A published vulnerability used to buy you days before working exploit code existed. AI now compresses discovery, chaining, and weaponization into minutes, which makes “7 days for high, 30 for medium” a policy from a world that no longer exists. The same frontier capability is available to defenders, so get in line early for the security-tuned models and trade your annual pen test for continuous agentic testing.

Alongside continuous patching, nothing beats prevention, and prevention means going back to basics. Segmentation, least privilege, just-in-time access; none of it is new, and that’s the point. This era punishes skipping the controls that were always the right answer.

Incident response is where it gets real. A generic model is useless at 2am, because the hard part of an investigation is context: which host is production, who owns this service, whether an access pattern is ordinary here. So build your own agents and skills, feed them your inventory, your architecture, your past incidents, and let them triage, connect dots faster than any human can, and constantly self-improve. Time to detect, respond, and recover is the only metric that matters now.

++

Cynthia Overby, Director, Strategic Security Solutions, zCOE at Rocket Software

This Cybersecurity Awareness Month, data security remains the top modernization concern for 69% of IT leaders. Enterprise environments are becoming more complex as organizations connect cloud and on-premises systems, introduce AI into more workflows, and move sensitive data across an expanding technology estate. The challenge for security leaders is no longer simply putting the right controls in place. It is maintaining visibility into risk and continuously validating that those controls are working as environments change.

When critical systems are involved, security teams need to know where vulnerabilities exist, whether access controls are effective, whether patches are current, and where emerging risks require attention. Yet fewer than one-third of IT leaders report being extremely confident they would pass their next regulatory audit. That gap between having controls and being able to demonstrate their effectiveness is where organizations need to focus.

Modernization should not come at the expense of security. Organizations need continuous assurance across their environments, with the ability to identify vulnerabilities, validate controls, monitor risk, and prioritize remediation based on what aligns with the organization’s enterprise risk posture. Building that level of visibility into modernization efforts can help organizations adopt new technologies while maintaining control over the systems and data their businesses depend on.

++

Pieter Vanlperen, Chief Information Security Officer (CISO) at AlphaSense

Heading into Cybersecurity Awareness Month, one of the biggest shifts security leaders should be prepared for is the fragmentation of “AI security” into separate layers. While organizations often talk about AI security as though it were a single attack surface, we’re seeing AI security follow a similar evolution to computer security, fragmenting into distinct layers and requiring unique protections at each level.

In response, security leaders should start examining the layers of the AI lifecycle and applying controls based on the risks at each one. At the data layer, organizations have to protect against compromised inputs and make sure that permissions remain intact as information moves through AI systems. At the output layer, the challenge is establishing trust and safety controls that help ensure AI produces secure and reliable results. Finally, at the operator level, organizations need transparency into how AI systems are being used and clear governance around what they can access and do.

The organizations that get AI security right will build security architectures that evolve alongside their AI capabilities, applying the right controls to the right risks rather than relying on a one-size-fits-all approach. As AI systems become more complex and autonomous, that adaptability will be critical to scaling AI securely without leaving gaps between layers.

++

Chris Bevil, Principal, Global Cyber Resilience & AI at Commvault

AI is forcing us to rethink what “cybersecurity awareness” actually means.

For years, we taught people to look for the tells: the misspelled word, the strange email address, the suspicious link. AI is steadily taking many of those tells away. An email can be perfectly written. A voice can sound like someone you know. A video can look real. The skill we need to build now is not just recognition. It is verification. Does this request make sense? Is this normal behavior? Can I verify it through another channel before I act?

Gartner’s 2026 cybersecurity research makes a similar point, calling for organizations to move beyond traditional awareness tactics toward security behavior and culture programs that address threats such as shadow AI and deepfakes.

Awareness cannot stop with the employee. Attackers do not care how we drew the organizational chart. An incident can move from identity to applications to data to infrastructure very quickly, yet many organizations still have security, IT, disaster recovery, cyber recovery, and business continuity operating in separate lanes. That is where cyber resilience becomes really important. What I call Resilience Operations, or ResOps, is simply about breaking down those silos and getting the organization to operate as one team around resilience and recovery.

++

JASON W. RICHARDS, PRINCIPAL, JWR STRATEGIES, LLC | FORMER FBI ASSISTANT DIRECTOR

As we think about securing America for the next 250 years, we have to prepare not only to prevent cyberattacks, but to keep critical missions operating when disruption occurs. For law enforcement, intelligence and national security, that means maintaining trusted communications even when the networks and infrastructure we normally rely on are degraded, compromised or unavailable.

But continuity alone is not enough. We also need to consider what our communications reveal. An adversary may never break the encryption protecting a message, but knowing who communicated, when, from where and with whom can expose an investigation, identify a sensitive government operation or reveal relationships and patterns that put people and missions at risk.

AI makes it possible to collect and correlate those seemingly insignificant signals at unprecedented speed and scale.

Cyber resilience therefore needs to include both the ability to keep communicating through disruption and the ability to reduce what those communications reveal. That is where Presence Security becomes important: protecting not just the message, but the people, relationships and missions around it.

++

JUSTIN DANIELS, FACULTY, IANS AND PARTNER AT BAKER DONELSON

One of the next big fights in enterprise AI will not be about whether the technology works. It will be about who tells the business that using the cheapest LLM model may be a bad idea.

As AI usage scales, token costs are about to matter a lot. Business teams will inevitably ask why they are paying premium prices for proprietary models when cheaper open weight alternatives can do the job. Then somebody will suggest a Chinese model that performs remarkably well for a fraction of the cost.

Congratulations security teams you inherit the mantle of yes but there are serious cybersecurity concerns with that decision.

The problem is that cheaper tokens do not magically erase questions about model provenance, training data, intellectual property, privacy, or supply chain risk.

I call this the “fruit of the poisonous LLM.” If you do not understand what sits inside the model, everything built on top of it may inherit risks you never priced into that bargain. Moreover, the US government may decide to ban Chinese models based on national security or other concerns.

Tokenomics will increasingly drive AI architecture. Security teams need to understand that economic pressure now, because waiting until the CFO champions the cheaper model makes for a tough AI governance strategy.

++

JODI DANIELS, FACULTY, IANS AND FOUNDER OF RED CLOVER ADVISORS

CCPA’s cybersecurity audit requirements should be a key focus area for companies in 2027. Companies must evaluate the effectiveness of their cybersecurity program across a full calendar year, with the first certifications due in 2028. This means organizations need to demonstrate that their security controls are not only documented, but actually working in practice.

One of the 18 required areas is a data inventory documenting what personal information is collected, processed, and maintained, where it is stored, and who has access to it. Companies that already maintain a processing-activity-based data inventory for GDPR will be better positioned to meet this requirement, along with many other CCPA and U.S. state privacy law obligations.

For security teams, 2027 is the time to make sure a comprehensive data inventory exists and is accurate. Security and privacy teams should work together to build an inventory that reflects actual data practices, identify gaps in what is currently documented, and establish a process to review and update the inventory at least annually and for active and complex companies more regularly.

++

RICK HOWARD, CYBERSECURITY EXECUTIVE | FORMER PALO ALTO NETWORKS CSO | FORMER U.S. ARMY CERT COMMANDER

I’ve been in the cybersecurity industry for over 30 years. I’ve spent gazillions of dollars deploying prevention strategies across four different CISO jobs. Here at the end of my career, I’ve come to realize that these prevention strategies, like zero trust and intrusion kill chain prevention, are great ideas, but they are expensive and hard to deploy fully.

The only strategy that makes sense for most organizations is resilience. I just need to survive the attack, not prevent it.

That means being able to continue operating when the systems, networks and communications you normally depend on are degraded, compromised or unavailable. And if keeping the mission running means shifting to different networks, providers or communications paths, security has to move with it.

As we think about securing America for the next 250 years, resilience has to become more than recovery. We need systems that can adapt during an attack, maintain trusted communications and protect presence as conditions change. If an attack succeeds but the mission continues securely, resilience has done its job.

++

Rafael Narezzi, Co-Founder and CEO, Centrii

For years, cybersecurity awareness has largely been framed around what employees should do differently—recognize phishing attempts, strengthen passwords and avoid suspicious links. Those habits still matter, but today’s threat environment requires a much broader definition of awareness.

In critical infrastructure, cyber risk is operational risk. A compromised battery storage system, renewable energy site or remote-access connection may not produce the warning signs of a conventional data breach. Instead, the consequences can appear as lost generation, unstable operations, reduced availability and direct financial loss. As energy infrastructure becomes more distributed and interconnected, organizations need visibility not only into their own environments, but also into the vendors and technologies on which their operations depend.

Organizations have too many alerts and too little context. Leaders must determine which exposures could disrupt operations, how much capacity or revenue is at risk and which action will reduce that risk first.

This Cybersecurity Awareness Month, we should move beyond treating awareness as an annual training exercise. True cyber resilience requires continuous asset visibility, carefully controlled access, clear supply-chain accountability and incident-response plans that are regularly tested. People should not simply be labeled the weakest link; they should be equipped to become an active layer of defense. Cybersecurity becomes meaningful when everyone—from operators and engineers to executives and boards—understands both their role and the real-world consequences of inaction.

++

Dan DeCloss, Chief Customer Officer, Brinqa

Organizations need to confront an uncomfortable reality this Cybersecurity Awareness Month: despite having more security tools than ever, have they actually reduced their risk of a cyberattack?

Tool sprawl is flooding security teams with disconnected findings, making it harder to determine what vulnerabilities matter. Treating each as equally urgent only compounds the problem, slowing down remediation and burning out practitioners.

As attackers use AI to move from discovery to exploitation faster, organizations need a unified view of exposure that connects severity with exploitability, asset criticality, existing controls and business impact. This context allows teams to identify the risks most likely to cause harm and act before attackers do.

Trying to close the most tickets is a losing game in the AI era. Organizations must measurably reduce their most consequential risks. That is the only way cybersecurity awareness translates to meaningful and sustained resilience.

++

Don Boxley, CEO and Co-Founder, DH2i

The biggest cybersecurity threat may not be the attack you don’t see coming. It may be the aging infrastructure you already know is there.

Organizations are still running critical applications and databases on systems that are years behind, and accumulating technical debt because they continue to work. “It still works” is a dangerous standard for production infrastructure supporting the business. Cybersecurity Awareness Month should be a wake-up call that encourages us to look beyond the latest threats and ask more fundamental questions. Is the infrastructure serving as the virtual backbone of the business truly resilient? Can workloads be moved quickly and safely? Is there a single platform or environment that the organization is dangerously dependent on? Who and what can access critical systems, and is that access limited to only what is actually necessary?

Modernization doesn’t mean immediately ripping and replacing everything. It means eliminating unnecessary technical debt… reducing infrastructure complexity… and building in the flexibility, security, and availability needed to keep critical systems running and safe when something goes wrong. Because when that worst-case scenario actually happens, that is definitely not the time to find out your infrastructure just wasn’t ready for it.

++

Richard Copeland, CEO, Leaseweb USA

One of the most dangerous things a company can discover during a cyberattack is that it has nowhere else to go. If critical applications, data, and infrastructure are concentrated with one provider or on one platform, a single incident can quickly become a business-wide crisis. Cybersecurity Awareness Month should be a reminder that cyber resilience isn’t only about keeping attackers out. It’s about making sure that when something does go wrong, one compromised environment, outage, or provider problem can’t take the entire business down with it.

Organizations consequently need to start thinking about infrastructure differently. Every workload does not belong in the same cloud, platform, or provider. Security, sovereignty, availability, performance, and risk should determine where a workload lives. Certainly, not vendor loyalty or convenience. Infrastructure should follow the workload, not the vendor. Because the worst time to discover that you’ve put all your eggs in one basket is after someone has already kicked over the basket.

++

Brandon Hoffman, Chief Strategy Officer at Intel 471

This National Cybersecurity Awareness Month is all about “Securing the Next 250.” The industry’s evolution over the last year alone is a clear indication that we cannot predict what is coming next, but what we can do is leverage the intelligence and insights available to us to help protect organizations from existing and emerging threats on the security landscape.

The threat landscape is moving in a clear direction: identity is becoming the primary attack surface, vulnerability exploitation is accelerating and cybercrime is continuing to industrialize into a specialized ecosystem of access brokers, malware operators, affiliates, and service providers. Ransomware is evolving alongside it, with more emphasis on data theft, disruption and leverage than encryption alone.

AI is part of that shift, but mostly as an efficiency multiplier. We are not yet seeing autonomous cyber operations replace human operators at scale. We are seeing AI make reconnaissance, social engineering, scripting, analysis, and day-to-day operator workflows faster, cheaper and easier to scale.

The answer is not another standalone tool. It is a comprehensive intelligence layer that can feed the frameworks, workflows and security technologies organizations already rely on. The value comes from delivering the right external context into those systems so teams can prioritize faster, make better decisions and drive more effective security operations.

We cannot control the next threat vector, but we can learn from what the threat landscape is already telling us. The organizations that build the intelligence infrastructure to see, prioritize and act faster than the adversary can adapt are the ones that will be secure for years to come.

++

Avani Desai, CEO of Schellman

Cybersecurity has always been about trust. You can have all the right tools, policies and controls in place, but at the end of the day, trust comes from being able to prove they are actually working. And AI is making that even more important. As AI moves deeper into our businesses, we need to be asking some pretty basic questions: Where are we using it? What data does it have access to? What decisions is it making or influencing? And who is accountable when something goes wrong? Security, compliance and governance cannot be something we bolt on at the end. They have to be part of how we build and use these systems from the beginning.

Cybersecurity Awareness Month is a good reminder that security does not belong to one team. It belongs to all of us. Technology will keep changing, probably faster than any of us expect. The organizations that earn and keep trust will be the ones that can show their customers, employees and stakeholders that they understand the risks, are managing them responsibly and, most importantly, can prove it. Because trust is built in drops and lost in buckets.

++

Jon Lucas, Director and Co-Founder of Hyve Managed Hosting

Heading into Cybersecurity Awareness Month, one of the biggest challenges for enterprises is keeping pace with an expanding attack surface. AI adoption and growing technology complexity are only adding to that challenge. As IT environments become more complex, there are more systems handling sensitive data and more infrastructure that needs to be secured. The risk is that while organizations focus on what’s new, some of the infrastructure they have relied on for years can be easier to overlook.

File transfer systems are a good example. They are deeply embedded in day-to-day operations, moving sensitive data between employees, customers, partners, and critical systems. Because that activity is so routine, it can fade into the background. Strong authentication and access controls are essential, but they need to be backed by consistent patching, proactive monitoring, and visibility into file and data movement.

What I would tell security teams this Cybersecurity Awareness Month is simple: don’t confuse familiar infrastructure with low-risk infrastructure. As environments become more complex, organizations need to ensure the systems they depend on every day receive the same security scrutiny as the newest technologies in their environment.

++

James Cassata, Senior Cloud Security Architect, Myriad360

Cybersecurity Awareness Month is a good opportunity for organizations to step back from the constant stream of new threats and technologies and ask a more fundamental question: Do we have the visibility and controls needed to understand and protect our environment? As organizations rapidly adopt SaaS platforms, AI tools, and cloud services, the attack surface is expanding faster than many security programs can keep pace with. Before adding another security tool, organizations should focus on strengthening the foundations, starting with knowing what applications are being used, what data they can access, and who or what has access to them.

That visibility becomes even more important as AI adoption accelerates. AI governance can no longer be treated as a future initiative. Organizations need policies that define acceptable AI use, visibility into sanctioned and unsanctioned AI applications, and controls around the data those systems can consume. At the same time, identity is evolving beyond employees and traditional service accounts. APIs, Automation, SaaS integrations, and AI agents increasingly operate as non human identities with access to sensitive systems and data. Understanding those relationships and applying principles such as least privilege, strong authentication, and lifecycle management is becoming a foundational security requirement.

Ultimately, cybersecurity fundamentals are as much about policy and process as technology. Organizations can deploy sophisticated platforms, but without clear ownership, repeatable processes, and governance that evolves alongside the business, gaps will remain. This Cybersecurity awareness month, the goal shouldn’t simply be to make employees more aware of cyber risk. It should be an opportunity to make the organization itself more aware of its applications, identities, APIs, AI usage, data flows and ultimately its exposure. You can’t effectively protect what you can’t see, and visibility remains the foundation of a resilient security program.

++

Zohar Alon, Co-founder and CEO, NewCore

Recent incidents involving AI agents from OpenAI and Anthropic have moved agentic risk from theory to operations. As Cybersecurity Awareness Month begins, the question for every enterprise is no longer whether agents will act inside its environment, but who is accountable when they do.

AI governance is, at its core, an identity problem. Once an agent can authenticate, retrieve data, execute code, call APIs or move money, governance cannot depend on the agent interpreting its instructions correctly. It has to start with the agent’s identity, alongside the humans it works for or with, rather than a shared service account or a borrowed human login. From there, every organization needs to answer three questions: Where are the AI agents? What can they connect to? How do I control what they do and prove it?

Accountability means the ability to answer those questions. Governance means enforcement at the moment of action, with permissions that are narrowly scoped, short-lived and revocable on the spot. This creates the separation that makes accountability possible: an agent can have the autonomy to decide how to complete a task without holding the authority to do anything it wants. Draw that line, and the risk shrinks to something you can name and own.

++

Husnain Bawja, SVP of Product, Risk Solutions at SEON

AI is making a lot of the old fraud signals less useful. A new device used to be suspicious. A login from an unusual location could set off an alarm. Activity happening faster than a human could realistically manage was another obvious clue. Now AI is letting anyone create convincing identities, make payments and take over accounts in ways that look increasingly normal on the surface. The problem isn’t that we have fewer signals. It’s that any one of them can tell you a pretty convincing lie.

That gets even harder as AI agents start handling tasks for consumers, from shopping to banking to managing accounts. We’re moving from asking ‘who is doing this?’ to ‘what is doing this, and should I trust it?’ You can’t answer that by checking a device or an identity once and calling it good. You have to connect the dots across someone’s digital history, the device, the network and how the individual or agent is behaving in that moment.

That’s the shift security teams need to make. Stop looking for the one signal that tells you something is fraud. Look at whether the whole story makes sense. A device might look clean. An identity might check out. A transaction might look normal. But put those signals together, and you may see a completely different picture.

++

Ashish Jain, CTO at OneSpan

This year’s Cybersecurity Awareness Month comes against the backdrop of emerging and autonomous threats that underscore the need for stronger identity security. As major players like Microsoft and Amazon recognize this by starting to require passkeys, consumer behavior is following a similar trajectory to the early adoption of seatbelts.

Simply installing seatbelts in every car did not mean everyone immediately used them. They became the norm through education, mandates, incentives, and repeated reminders, all designed to make the safer behavior the default behavior. Passkeys need the same treatment: prompt users to enroll, make them the easiest way to sign in, and continue nudging adoption until passkeys become the default rather than merely another option.

++

Chris Chaisson, Sr Advisor at Fusion Risk Management

Cybersecurity Awareness Month usually focuses on prevention, which reduces the chance of an incident occurring — but resilience is what decides whether the business can continue operations and serve its customers after a cyber incident has taken place. Having been involved in business continuity and crisis management from the industry side, a cyberattack breaks the assumptions most recovery plans are built on. A normal outage might have you back up in a few hours, maybe a day. A cyberattack works on a completely different timeline. Figuring out what was compromised and whether the backups are clean alone can take weeks or months.

Make the most of this month. Get IT, resilience, and business leaders in a room to map dependencies and agree on recovery priorities. Identify manual workarounds and alternate procedures for your most critical processes, then run a tabletop to practice everything before a real cyber incident forces the conversation.

++

Frank Vukovits, Chief Security Scientist at Delinea

While organizations might be more cyber aware than ever, far fewer are cyber ready. 87% of organizations claim their identity security posture is prepared to support AI automation at scale, yet nearly half (46%) admit their identity governance around AI is deficient.

This readiness gap becomes more consequential as AI moves from generating outputs to taking action. While initial AI concerns were focused on hallucinations and generating incorrect info, now we’re seeing AI agents use enterprise access to act independently on that flawed data, exacerbating existing excessive permissions issues. But initial identity vulnerabilities are only part of the problem. The OpenAI/Hugging Face incident demonstrates how unexpected agent behavior can quickly turn into real-world consequences.

2 in 3 organizations admit that when security requirements conflict with business speed, they are not consistently enforced. However, AI makes both automation and attacks faster, meaning organizations cannot afford to treat security as a backseat-discipline in their pursuit of speed. Security awareness must move beyond human users and include AI and machine identities with real enterprise access. In practice, this means scoping all agent access as temporary and task-specific, and authorizing agent permissions at runtime rather than treating access as a one-time decision.

++

Spence Hutchinson, Senior Manager, Threat Response Unit, eSentire

Social engineering has evolved from a primarily email-based problem into a cross-channel identity attack. Threat actors increasingly manufacture urgency by impersonating IT or helpdesk personnel responding to a supposed technical issue, and then shift the conversation to channels employees may regard as more immediate or trustworthy (like Microsoft Teams, personal mobile phones, and even website contact forms). This method is effective because it exploits human confidence in familiar support workflows rather than relying on a malicious attachment alone.

The most concerning campaigns combine that trust abuse with identity-focused phishing and legitimate administrative tools. For example, in the GhostCode campaign, attackers used a benign-looking web-form inquiry and an NDA pretext to steer victims into a device-code phishing flow on Microsoft’s legitimate sign-in infrastructure. After the victim completed authentication and MFA, the operators could obtain tokens, register devices, and establish persistent access; in the observed case, three devices were registered and a Primary Refresh Token obtained within 78 seconds. The lesson is clear: MFA remains vital, but it is not a complete defense when an attacker persuades a user to authorize the attacker’s own session or device.

As social engineering attacks remain an extremely popular exploit target, organizations have to take action. Defending against this trend requires organizations to secure identity, collaboration platforms, remote-access tools, and endpoints as a unified attack surface, supported by verified helpdesk procedures, strict remote-support controls, and continuous monitoring for anomalous authentication, device enrollment, and security-control tampering.

++

John A Toney, SVP of Security Services at Thrive

The security challenge for many organizations today isn’t a lack tool options. It’s about making sense from an increasingly complex environment with team members who are often overclocked. As infrastructure expands across SaaS, cloud environments, endpoints, networks, and legacy on-prem systems, the priority should be to improve visibility across the environment, to enable automation to help teams identify critical threats, and to enable the front-line defenders to focus on a rapidly evolving landscape.

The same principle applies to access. With users, devices, and applications increasingly distributed, organizations need to move beyond legacy network-based approaches. Frontier ready organizations should deploy AI enabled tools and a Zero Trust architecture to continuously monitor their attack surface. Ultimately, cyber resilience comes from bringing together modern security technology, skilled expertise, and a simpler operating model. Organizations shouldn’t have to choose between enterprise-grade protection and manageable processes.

++

Corey Nachreiner, Chief Security Officer at WatchGuard

AI is the first technology since the smartphone that everyone adopted before anyone secured it. So this year, I’m skipping the usual awareness-month tips for the one that actually matters.

When you connect an AI assistant to your email, files, calendar, or bank, you’re not giving it a tool — you’re handing it your keyring. Whatever you can do, it can do. And so can anyone who steals that account. Your AI login has quietly become the skeleton key to your digital life. Protect it like your bank login: multi-factor authentication on, skepticism up, and a hard pause before you approve any new connection.

Before you type, ask three things: What am I sharing? Who can see it? What is this tool allowed to do on my behalf?

For businesses, the risk is shadow AI — and it’s bigger than the chatbot in a browser tab. It’s the plugin, the extension, the integration nobody told security about. You can’t secure what you can’t see. Visibility first, then policy, then enforcement.

++

Jared Atkinson, CTO of SpecterOps

This year’s Cybersecurity Awareness Month should be focused on how attacks actually work and abandoning the outdated approach of looking at security issues in isolation. Attackers don’t operate that way. They combine permissions, relationships, misconfigurations, and compromised identities to get where they want to go. Organizations should assume attackers will take the easiest route to their objective, and that route may not involve exploiting the vulnerability you’re most worried about.

Understanding the relationships, permissions, and identities available to an attacker can help you find and remove shortcuts before they do. AI is also expanding the identity landscape, and teams should be asking “what can these systems actually do?” AI security decisions need evidence, and testing models in realistic, controlled environments can help organizations better understand their capabilities, limitations, and potential risks before relying on assumptions about how they’ll behave.

++

Rohan Gupta, Co-founder and CEO, Diopter AI

One area where I believe we need more cybersecurity awareness is around social engineering attacks, which have advanced significantly with agentic AI and are dramatically increasing the volume of fraud attempts organizations must identify and block. Those advances beg the question: When someone on your team is on a call with an attacker, what, besides that person, is watching for irregularities?

Every layer of the security stack got a detection acronym once attacks became more sophisticated, and defenders accepted that people could not watch it unassisted. Endpoints got EDR, networks got NDR, identity got ITDR. The live conversation never got one, and that is where social engineering lands. Agentic AI removed the attacker’s last constraint, time: one operator can run hundreds of tailored voice and video conversations at once, each adjusting to what the target says back.

That leaves the person on the call as the only part of the enterprise under an automated attack with no automated defense behind them. How do you identify and protect against those kinds of attacks, when even the best human awareness isn’t good enough?

The answer may be learned from what we built for every other layer: a detector on the surface itself. Call it an EDR for humans. It sits on the live call, checks whether the voice or video is synthetic, reads how the conversation is developing, and checks the exchange against the company’s own policy while there is still time to stop it. My company and others are working on this challenge, and I expect it to become a standard control within a few years. Until then, Cybersecurity Awareness Month is an excellent reminder to increase vigilance and awareness as AI attacks become more sophisticated on voice and video calls, where humans often remain the only line of defense.

++

Arti Raman, CEO, Portal26

Cybersecurity Awareness Month has always been about closing the gap between what security teams think is happening in their environment and what’s actually happening. Today, that gap is widest around AI. Employees are adopting AI tools faster than governance teams can track them, and every ungoverned prompt is a potential data exposure. Real AI security doesn’t start with another policy document — it starts with visibility. You can’t govern what you can’t see, and this month is a good reminder that ‘we have an AI policy’ and ‘we have AI security’ are two very different things.

++

Amit Shuster, VP Product, Vetric

Insider threats in the AI era aren’t just about malicious actors, they’re about how easily trust can be manufactured or misplaced,” said Amit Shuster, VP of Product at Vetric. “The line between external attack and insider risk is blurring fast, and understanding the intelligence behind the deepfake is now essential, because verification can’t rely on gut instinct anymore. Cyber Awareness Month should be a reminder that the organizations who fare best this year will be the ones treating verification and visibility as an ongoing discipline, not a once-a-year training exercise, because processes need to hold up even when something looks and sounds completely legitimate.

++

Sohail Iqbal, Chief Information Security Officer, Veracode

This year’s Cybersecurity Awareness Month centers on an important theme: “Securing the Next 250,” prompting the industry to confront a fundamental question: can we trust the software powering our businesses, infrastructure, and daily lives? Regulations and rules like the EU Cyber Resilience Act, DORA, NIS2, and the SEC’s cybersecurity disclosure requirements in the U.S. underscore why this is a question the industry should have been answering all along. These measures are shifting software security from a post-release consideration to an enforceable requirement.

Simultaneously, AI is increasing the speed and volume of software creation, heightening the importance of establishing trust. AI-generated code already introduces security flaws nearly half the time, and 82% of organizations currently carry long-term security debt. Without an equally rapid evolution in security, unresolved vulnerabilities and software supply chain risks will continue to multiply unless security programs keep pace.

The window for CISOs to get ahead of this is now. Cybersecurity awareness today means moving beyond simply detecting vulnerabilities and recognizing threats to proving that the software we build and deploy is trustworthy. This requires a consistent, risk-based approach to contextual prioritization that directs teams toward the vulnerabilities posing the greatest threat, backed by the governance, tooling, and processes needed to make those decisions at machine speed. These questions belong at the top of boardroom agendas. Not to slow AI-assisted development, but to embrace speed and productivity without sacrificing security.

++

Jack Cherkas, Global Chief Information Security Officer at Syntax

Cybersecurity Awareness Month is usually a reminder to get the fundamentals right and that is still absolutely critical. This year, however, the National Cybersecurity Alliance has adopted the theme, “Don’t Make It Easy for Them,” and that message should also prompt organizations to look at a growing source of risk: artificial intelligence (AI).

As organizations and individuals adopt AI, we need to remember that AI is not just another technology. It has the potential to be transformational. It can hold accounts and permissions, see whatever you give it access to and take actions on your behalf. Many organizations and individuals have never considered the implications of these actions.

So, as the world embraces AI, we must determine three things before access is granted: what it can see, what it can do and who is responsible for it. And we also must remember that, in many cases, AI appears even when we never chose it. It’s in the tool approved three years ago that quietly shipped an AI-infused update, the browser extension or the application add-in. Some AI adoption arrives without a decision, and the things nobody decided on are the things nobody is watching.

“Don’t Make It Easy for Them” is the right tagline for this year. For organizations, that means adopting AI in a pragmatic, secure and responsible manner. For individuals, it means 10 minutes in your settings. Neither is hard. Both are overdue for many.

++

Jordan Benzing, Director of Security & IT at Patch My PC

Cybersecurity right now feels like drinking from a firehose. AI changed how fast vulnerabilities get found, every dependency you’ve ever run npm install on is somebody else’s attack surface, and there’s a new framework every week you’re already behind on. It’s exhausting.

When you are tired and things are hard, it’s best to return to the basics.

Somebody at Microsoft created the 10 Immutable Laws of Security and later a companion set on cybersecurity risk. These rules have aged well. Hold them up against any supply chain attack from the last two years and it’s all still there, just wearing new clothes. A poisoned package is someone talking you into running their code. A compromised build pipeline is someone owning the control plane. A leaked CI token is someone becoming the administrator.

As we head into Cybersecurity Awareness Month, I’d encourage you to focus on two of them. First, “ruthless prioritization is a survival skill.” You cannot secure everything, especially with a remote workforce. Identify your most critical systems and the key points in identity, and defend those as well as you can. Second, understand that not keeping up IS falling behind. Patch velocity has to become a priority for every enterprise, and the business systems that can’t keep up with the rate of change required need to start changing.

++

Matt Jones, EVP of Strategy at Cielo

Cybersecurity Awareness Month is a good opportunity for leaders to think more broadly about what happens as technology starts to participate in more of the work we do every day. We’re making decisions now that will shape how companies operate and what work feels like for people for years to come. With that comes a responsibility to think about security and trust from the beginning, which is part of what makes this period of technology change different from others we’ve experienced.

Leaders need to be part of that conversation from the beginning. How does technology fit with our business strategy? What role do we want people to play? How do we want people and technology to work together? Cybersecurity is part of those questions because every new way of working creates decisions about how we protect people, information, and the business. The organizations that navigate this change well will be the ones that treat security as part of how work is designed from the beginning.

++

Adam Khan, VP, Global SecOps & AI Security, XDR/MDR, Barracuda Networks

AI is making phishing much harder to spot at a glance. The use of bad grammar, strange phrasing, and an unnatural tone can still be red flags, but they matter less than they used to. In just seconds, AI can clean up the language to make a malicious message feel personal and completely normal.

That changes what people need to pay attention to. A polished email isn’t enough to establish that it is coming from a trustworthy person. The better signal is the action the message is asking you to take, especially when it involves credentials, payments, QR codes, sensitive information, or an unusual sense of urgency. Those are the moments that deserve a second look and another way to verify.

++

Dr. Süleyman Özarslan, Co-Founder and VP of Picus Labs, Picus Security

The most dangerous security gap may be the one you think is already covered. Organizations invest heavily in firewalls, EDR, SIEM, and other defenses, but having a control in place does not mean it will work when an attacker actually tests it. Our latest research found that while organizations blocked 69% of simulated attacks at the prevention layer, only 37% of subsequent actions were stopped once an attacker got inside.

That is why Cybersecurity Awareness Month should be about questioning assumptions as much as recognizing threats. Ask whether your defenses can detect an attacker quietly mapping the network, collecting credentials, or preparing to move laterally, not just whether they can stop the obvious attack at the front door. Security teams cannot afford to discover those gaps during a real incident. The goal should be to find them first, test them continuously, and validate rather than assume that your defenses will hold.

++

Alastair Parr, Chief Technology Officer, Spur

One of the assumptions we still make in security is that bad activity will somehow look bad. A strange IP. An unusual location. A connection that clearly feels off. But attackers are getting much better at making themselves look ordinary.

They can use legitimate credentials, come through a residential connection, and show up looking like a normal employee or customer. That makes the old warning signs less useful on their own.

So awareness has to change too. It’s not just about spotting suspicious activity anymore. Security teams need to look at the broader context around a connection and be careful about treating a familiar location, a residential IP or even a successful login as proof that everything is fine. Sometimes the activity you should worry about most is activity that blends in.

++

Lee Rossey, Chief Technology Officer & Co-Founder, SimSpace

AI agents are moving into production quickly, but a lot of organizations are still figuring out what it actually means to trust them. Many organizations still rely on the assumption that a human will catch something if the AI gets it wrong. That’s not enough. Before you give an agent real access or let it take action on its own, you need to know how it behaves when things don’t go as planned.

That means testing it in realistic environments, putting it under pressure, and seeing where it fails while the stakes are still low. As these systems become more autonomous, we can’t treat trust as a given. It has to be proven. If an AI system is going to act on your behalf, you should have clear evidence of how it will behave before you give it authority in production.

++

Matt Richards, Chief Operating Officer, Aqua Security

Cybersecurity Awareness Month is a useful reminder that security is not just about knowing what threats exist, but about being able to act when they occur. As attackers move faster and increasingly target legitimate applications and workloads, organizations need security controls that can detect and respond to what is actually happening at runtime. Companies have spent years improving visibility; the next step in security is turning that visibility into real-time protection and enforcement.

++

Mitchem Boles, Field CISO, Intezer

Cybersecurity Awareness Week is a good opportunity for organizations to look at where risk may be hiding in everyday security operations. Alert fatigue often means SOC teams have to prioritize what gets investigated, and low-severity alerts are typically among the first to be deprioritized. But our research found that nearly 1% of confirmed incidents originated from alerts initially labeled as low severity, which can translate to roughly 54 real threats a year for a typical enterprise.

The takeaway is that low severity does not always mean low risk. A seemingly minor alert can still be an early indicator of a larger issue. As organizations focus on cybersecurity awareness, they should also consider how they are handling alert volume, where blind spots may exist, and whether important signals are being overlooked simply because they appear less urgent at first.

++

Keivan Bahmani, Ph.D., Director of Machine Learning and AI Integrity, Mitek Systems

AI agents are becoming more autonomous, meaning the cybersecurity industry will need to focus on establishing and verifying trust not only in people, but also in the technology acting on their behalf. An agent can interact with systems, access information and initiate actions at a scale a person cannot. It’s critical for us to understand who that agent represents, what authority it has been given, and whether its actions stay within those boundaries. The fundamentals of cybersecurity shouldn’t change with AI, but the number and types of identities businesses need to trust are expanding.

Looking ahead, cybersecurity will move beyond point-in-time verification toward a continuous model of trust. Verifying an agent once isn’t enough. We need to continuously evaluate an agent’s behavior, permissions, and interactions for signs that something has changed or gone wrong. This shift reflects the current state of cybersecurity, with trust no longer something that can be established at a single point in time. With AI agents taking on more responsibility, creating a verifiable chain between identity, authorization and action will be critical to scaling them securely without opening new gaps for fraudsters to exploit.

++

Ram Mohan, Chief Strategy Officer, Identity Digital

Generative AI has fundamentally changed the economics of online scams. Phishing emails used to be easy to spot. They were full of bad grammar, broken formatting, and awkward phrasing. Today, AI generates flawless text in seconds, which means visual polish is no longer an indicator of legitimacy.

I always tell people to look past how a message appears and check where it actually leads. I call this the three-second domain check. Before you click any link, especially one asking for credentials, personal data, or money, stop and look at the actual registered domain name in the address, not just the brand logo or any familiar name that appears earlier in the address.

That three-second pause is on the user. But it only works because the domain industry itself is building tools to catch typosquatting and lookalikes before most people ever see them. Neither half does the job alone.

++

Lynne Challender, Deloitte’s US Cyber Strategy & Transformation offering leader

AI is moving faster than most security programs were built to handle. The moment organizations shift from pilots to production, the attack surface doesn’t just expand, it fundamentally changes. Prompt injection, model hijacking, and excessive agent permissions aren’t just theoretical risks, they’re driving real breaches. The enterprises getting ahead of this aren’t treating security as a final checkpoint. They’re embedding it into every stage of the AI lifecycle: designing strong governance, establishing technical guardrails to control what AI agents can and cannot do, and implementing continuous monitoring at machine speed to ensure anomalous behavior is contained and remediated.

Cybersecurity Awareness Month is a good reminder that trust doesn’t come standard with any technology. You have to build it in.

++

Hubert Behaghel, CTO, Veriff

As someone who works alongside governments, multinational organizations, and regulators on identity policy, and as a parent to seven kids, I want to bring attention to the importance of online age verification for cybersecurity awareness month. Globally, age verification has become one of the most contentious tech policy debates, but as lawmakers push for stronger online protections for children, age verification is often framed as a choice between safety and privacy.

This framing is inaccurate; safety and privacy can be achieved simultaneously because platforms don’t need to know a person’s full identity or exact age. It is less important to know if someone is specifically 16 or 17 versus them meeting the necessary age threshold to interact with the platform. Threshold matching reduces data collection, which minimizes the attack surface and helps maintain the privacy of users.

Simple age gates and outright bans have not been effective. Kids get around them easily and they can create a false sense of security. It’s time that we leverage AI-powered age estimation because it offers a better, more secure path forward, helping companies create a safer, more trusted internet by ensuring only age appropriate users can access services. AI-powered age estimation lets platforms confirm age without collecting or storing unnecessary identity documents from users. As AI deepfakes rise, age estimation must verify that a selfie is real, camera-captured and not digitally created.

Without proven liveness detection, it is simply a sticky plaster on a wooden leg. The companies that get this right will be the ones that position privacy as a lever to make trust compound, granting a greater perception of responsible operations for the company’s brand perception and a premium experience for users.

++

TK Keanini, Field CTO at DNSFilter

Any read on the state of cybersecurity is a snapshot. Every defensive innovation drives an offensive one, and it always has. What has changed is tempo. John Boyd’s OODA loop (observe, orient, decide, act) rewards whoever cycles faster, and attackers have gone from script kiddies to exploit-as-a-service to vibe-coding the attack which is infrastructure from a prompt. We are no longer fighting a human-scale adversary. You cannot defend against a machine-scale threat with a human-scale defense.

AI is forcing us to turn every control we treated as a state into a rate. Authentication and authorization checked once at login made sense when a session was a person at a keyboard. An AI agent can take thousands of actions inside that session, so trust has to be re-earned every so many events or every five minutes. DNS already works this way. It began as a namespace lookup, and protective DNS made it the effective access policy maker, deciding on every query. New standards such as DNS-AID and the Agent Name Service now put DNS at the center of AI agent registration and trust.

Fundamentals matter more, not less. No person, device or agent needs access to every domain on the Internet. AI scales whatever you feed it, rigor or sloppiness, and machine-scale adversaries find the gaps first. Those who ignored the basics will be the first to feel the impact. This October, the question is not what state your security is in. It is what rate it runs at.

++

Crystal Morin, senior cybersecurity strategist at Sysdig

Identity
It’s 2026 and the challenges around identity and access management (IAM) persist. Poor identity security is often at fault for initial access, while abusing permissions and identities are common tactics to get access to critical business applications and data. The Sysdig 2026 Cloud-Native Security and Usage Report, found that 67% of human user accounts are considered risky across all cloud service providers (CSPs).

Alongside this risk, the number of identities that companies have to keep track of has gone up, too, as well as the permissions needed for application access and control. Teams need to adopt continuous behavioral monitoring that can understand “normal” in context for any given identity and flag deviations in real time. AI tools or coding agents can be used in defining and supporting those policies to keep identities secure.

Regulation
With so many changes in regulations over the past twelve months teams are under significant pressure. Like most things, dealing with it just takes preparation and structure. Map out which regulations your organization is beholden to, what their timelines are, and what words like “aware” and “material” mean under each regulation — and all of that had to happen before an incident, not during one. Whoever is deciding “is this bad enough to report” needs a decision tree, not a debate in the heat of the moment.

++

Dan Lohrmann, Field CISO, Public Sector at Presidio

This Cybersecurity Awareness Month, everyone is understandably very concerned about AI risks. But there’s another significant cybersecurity threat that is being overlooked: Ransomware attacks are quietly surging and hitting critical sectors like healthcare and utilities, and it’s getting harder for organizations to recover.

The stakes are higher than ever for unprepared companies, who often don’t have sufficient visibility and control over their IT environments, especially with the addition of AI agents. Deploying AI responsibly means working with the right partners, ones who think of security as a key part of the integration from the beginning, not an afterthought or add-on. In most cases, this means deploying non-human identify governance, a zero-trust architecture, and strict network micro-segmentation.

++

Justin Fox, Senior Vice President, Product & Operations, ValorC3 Data Centers

The cybersecurity landscape is changing rapidly thanks in large part to AI. Organizations can no longer afford to think in terms of protection first; they must design for resilience. While traditional data protection strategies remain important, cyber resilience is ultimately measured by an organization’s ability to recover, maintain operations and retain control of its data. We often see enterprises invest in multiple backup locations and even redundant infrastructure, yet these same organizations do not invest fully into testing to ensure recoverability. True resilience is more than just having copies of data. It is knowing with confidence the data and workloads can be restored when it matters most.

Resilient infrastructure requires more than redundancy. It requires visibility, operational discipline and the freedom to move and/or recover workloads across environments without being constrained by a single platform, provider, or technology stack. Organizations that maintain control of where their data resides and how their applications are being deployed are better positioned to adapt to evolving business, security, and compliance requirements.

At the same time, the rapid emergence of agentic AI is redefining the enterprise security landscape introducing new challenges. As employees embrace these AI tools to accelerate productivity, the risks to the organizations cyber resilience are increased. While AI can be a force multiplier, they cannot replace sound architecture, operational expertise, and strong governance. Navigating today’s thread landscape requires a balanced approach of educating users, establishing clear policy, implementing guardrails and building resilient infrastructure that keeps the organization in control of their data. Organizations that prioritize workload portability, reducing vendor dependence, and ensure critical systems are recoverable across multiple environments can strengthen their security posture yet remain agile enough to innovate and grow.

++

Nauman Khan, VP, Legal Technology, IT Rapid Support

Going into this year’s Cybersecurity Awareness Month, the gap I see is not tools, it is follow through on the basics at small and mid sized organizations. Most small business breaches still start with a stolen password or a convincing email, not an exotic exploit. Attackers now use AI to write phishing that reads like a real colleague, which means “look for bad spelling” training is out of date.

My advice for October is simple. Turn on multifactor authentication for every account, with no exceptions for executives. Lock down email with SPF, DKIM and DMARC so your domain cannot be spoofed. Test your backups by actually restoring from them. And teach staff one habit: any request involving money or credentials gets verified by a phone call to a known number, never by replying to the message. None of this is glamorous, but it closes the doors attackers walk through most often.

++

Rami Habal, Founder and CEO, Magnitude

The pace of change is one of the hardest realities security teams are dealing with today. AI can uncover vulnerabilities faster than ever, and an issue buried several layers down the software supply chain can suddenly become your problem. We’ve seen that with Mythos uncovering vulnerabilities across thousands of open source projects, and with OpenAI agents unexpectedly reaching third-party systems like Hugging Face. Every company now relies on a complex software supply chain made up of third parties, software, cloud services, and AI tools, all with their own dependencies and inherent risk. The challenge is that many of the processes security teams still rely on weren’t built for attacks that move this quickly.

The scary part is that an attacker only has to find one thing you missed. Maybe it’s a vulnerability in a vendor, a dependency you didn’t know that vendor relied on, or something that changed since the last time you looked. It’s like locking the front door every night without realizing there’s an easily accessible open window. You’re focused on the risks you know to look for. The attacker is looking for the ones you don’t, and AI is making it much easier to find them.

The reality is that something will eventually happen. You’re not going to catch everything, especially when the issue could be sitting three or four layers into your supply chain. The best security teams build resilience – they prepare now for an eventual breach, so that when it does, they can identify it quickly, understand the impact, and remediate the risk before it spreads.

++

Liora Ziv, Cyber Threat Intelligence Researcher, CyberProof

This year’s “Securing the Next 250” theme is a fitting lens for where the industry stands. We are at a critical moment in cybersecurity where AI innovation is growing rapidly by the day, and with this growth comes increasing cybersecurity concerns as new technologies create new opportunities for cyber threats.

Our recent mid-year report looked into the patterns and trends of threat actors in 2026 so far and highlighted three critical elements of the state of cybersecurity today and AI’s impact:

  1. AI is increasing the speed, scale, and sophistication of cyberattacks. Threat actors are using AI to enhance existing attack techniques, from social engineering and identity-based attacks to malware and exploit development. AI can accelerate reconnaissance, vulnerability and zero-day discovery, code generation and the adaptation of malicious tools, allowing attackers to operate faster and at greater scale. This is reducing the time defenders have to identify emerging threats, assess exposure, and respond.
  2. AI is creating a new enterprise attack surface. As organizations integrate AI agents, coding assistants, enterprise copilots, models and AI infrastructure into business operations, these technologies are becoming targets themselves. AI systems can access sensitive data and credentials, inherit trusted permissions, interact with applications, and connect to other enterprise resources. As their access and autonomy increase, organizations need visibility into what AI systems can access, what actions they can perform, and the trust relationships they create.
  3. AI is becoming part of the attack itself. A further shift is emerging as AI capabilities are incorporated directly into malicious tools and malware. Rather than being used only during attack development, AI can operate during execution to generate malicious code or commands, adapt behavior, select actions, and respond dynamically to the environment. This introduces the potential for more adaptive and autonomous threats that are less dependent on predefined attack logic.

Securing cloud identities, trusted platforms, software supply chains and AI infrastructure must become part of day-to-day enterprise security. As AI becomes embedded across both enterprise operations and attacker capabilities, organizations will need visibility across traditional and AI-enabled attack surfaces to identify and manage emerging risks.

++

Charles Henderson, EVP and Head of DivisionHex at Coalfire

As frontier AI labs call for voluntary slowdowns and form safety coalitions, the real issue is whether these efforts address the threats enterprises face or simply create the appearance of responsible AI governance.

We can’t afford a slowdown. We need a pivot to address these concerning cybersecurity issues. Pausing training and development of commercial models won’t stop nation-states or adversaries from using open-source tools already operating in the wild. Frontier labs remain fixated on software vulnerabilities, revealing they still have amateur understanding of how real-world attacks happen. Attackers will continue to exploit password reuse, social engineering and identity misconfigurations to gain access and escalate privileges.

So in honor of Cybersecurity Awareness Month, we ask that these frontier labs move to defensive engineering that makes these attack paths harder to exploit, instead of stunting offensive capabilities. Real protection requires building active friction into system boundaries.

++

Shay Shwartz, Co-Founder and CEO, Ocean

Cybersecurity Awareness Month turns 22 this year, and for most of that history the advice has been the same: look for what’s off. The typo, the odd sender, the urgent request that feels wrong. That advice has run out of road. AI didn’t just make attacks more frequent, it made them unrecognizable. Convincing spear-phishing and business email compromise no longer take a skilled human hours to craft. They just take a prompt. The result is email that references real projects, mirrors a colleague’s tone, and arrives from an account your company already trusts.

That’s a structural problem, not a training problem. Most defenses, like most employees, were built to spot what’s abnormal. But when an attack matches every baseline, it earns a passing score. So instead of asking ‘Is that normal?’, people should now be asking ‘Is that too perfect?’

Security teams need the same shift: not just deciding whether something looks safe, but understanding what is happening, why it is happening, and what comes next. Awareness and detection still matter, but in the AI era, the job of spotting the perfect fake can only be accomplished with continuous investigation.

++

Ely Abramovitch, Co-founder and CEO, Legion Security

While some in the industry might argue that Cybersecurity Awareness Month is a silly or made-up thing, in reality, it should be a wake-up call that the scale of cyber defense is fundamentally changing. Security teams are already overwhelmed by alert volume. At Virgin Money, for example, they’d accumulated roughly 50,000 security alerts despite having a security organization of around 200 people. With agentic automation, their team was able to work through a huge portion of alerts in under two months, reducing its backlog by more than 60%.

Now consider what happens as attacks become fully agentic. Instead of moving sequentially, agentic attacks can create tens of thousands of uncorrelated alerts simultaneously across identity, email, endpoints, network and other domains. The challenge is deciphering how those seemingly disconnected signals fit together, particularly when the security teams responsible for them operate in separate silos.

That breaks the traditional security model. We can’t keep telling defenders to tune detections until they find the needle in the haystack when attackers can increasingly manufacture the haystack on demand.

The answer is giving defenders the ability to investigate, correlate and act at machine speed. Security organizations need to break down domain silos and begin aggressively experimenting with agentic defenses now. As attackers embrace automation, defenders will need automation of their own to keep pace.

++

James Mullen, Head of Research, Edgescan

One of the biggest things executives need to consider right now is how quickly AI is changing what is possible in cybersecurity. Having spent much of the last year in research and building with AI in offensive security, what stands out to me isn’t that AI suddenly replaces security expertise. It’s that it changes the scale and speed at which we can explore systems, identify weaknesses and follow potential attack paths

We are already seeing that in our own research. We’ve been applying AI developed for autonomous penetration testing to real-world software and using it to surface potential vulnerabilities that may otherwise have gone unexplored. But there is an important distinction for executives to understand: AI identifying something interesting doesn’t make it a vulnerability. It still needs to be investigated, reproduced, and validated. The same principle should apply when organizations introduce AI across their wider security programs, speed and scale are valuable, but they can’t come at the expense of evidence and trust.

For cybersecurity awareness month, I’d encourage leadership teams to look beyond the question of whether they’re using AI and ask how they’re using it. Where can genuinely extend the capability of your security teams? What controls are around it? How are its outputs validated? AI is going to change both how attackers and find opportunities and how defenders identify them. The organizations that get the most from it will be the ones that combine the new capability with the same standards of proof and accountability that good security has always required.

++

Brendan Sheairs, VP of Customer Success, SafeLogic

Cybersecurity Awareness Month usually focuses on individual behavior: spotting phishing, using strong passwords, reporting suspicious activity. Those things matter, but I’ve spent most of my career assessing software security programs and building security champions programs that support tens of thousands of developers, and the pattern is consistent. The organizations that actually improve don’t just ask people to try harder. They make the secure path the easy path. Security scales when it’s built into how teams already work, not added through more training and more gates.

Cryptography is the clearest test of that right now. NIST has finalized its first post-quantum cryptography standards, and federal migration timelines are taking shape. Every organization will eventually have to find and replace cryptography embedded across its code, open-source libraries, containers, and third-party products. Yet most companies can’t answer a basic question: where is our cryptography today, and who owns it? With “harvest now, decrypt later” attacks, data stolen today could be readable in the future, so waiting isn’t a neutral choice. The answer is to treat this like any other engineering program. That means building an inventory, assigning clear ownership, giving developers validated, drop-in components, and designing for crypto agility so the next transition isn’t a multi-year fire drill.

My advice to executives this October is to ask two questions. First, do we know where our cryptography lives and who is accountable for it? Second, how hard is it for our developers to do the secure thing by default? If the answer to either is “not sure” or “hard,” that’s where to invest. Awareness is the starting point. Making security easier is what actually changes outcomes.

++

Xin Qiu, Product Management & Head of PKI Center for Aurora Networks

Over the past several years, cybersecurity evolved from a nice-to-have feature into a competitive differentiator. Looking toward 2027, it is increasingly becoming a requirement for market access, as regulations such as the EU Cyber Resilience Act (CRA) raise expectations for security by design and lifecycle accountability. At the same time, organizations must prepare for the transition to post-quantum cryptography and a new generation of AI-enabled attacks operating at unprecedented scale. Strong cryptographic foundations, including trusted software and verifiable device identities, are becoming essential to securing connected products throughout their lifecycle. Organizations that act now will be better positioned to meet regulatory requirements, earn customer trust, and remain resilient as the threat landscape evolves.

++

Brandon Kappus, Chief Delivery Officer, Nisos

The Next Evolution of Workforce Identity Fraud

Over the next year, I expect identity fraud to become more scalable, adaptive, and difficult to detect through traditional hiring and security processes. Through Nisos’s research and client engagements, we are seeing increasingly sophisticated identities, AI generated content, expanded facilitator networks, and tradecraft designed to establish credibility across multiple digital platforms. AI and coordinated networks will allow threat actors to target more organizations, adapt their methods, and operate at greater scale. While DPRK IT worker operations provide a clear example, these techniques have broader implications for workforce identity fraud.

One challenge I see is that traditional background checks do not necessarily validate identity. They may confirm that information matches an existing record without establishing that the individual is the legitimate person or that their professional history and digital footprint are consistent. Organizations need to reconsider how they assess risk before employment and throughout the employee lifecycle. HR and Talent Acquisition cannot solve this independently, nor can security teams address every risk after access has been granted. A more effective approach connects pre employment diligence, identity intelligence, ongoing monitoring, and post employment investigations through shared processes and clear escalation paths. The distinction between employment fraud and insider threat is becoming increasingly difficult to maintain.

AI will be both a driver of this threat and an essential part of the response. Threat actors will use it to create convincing personas and scale their operations, while organizations will need AI enabled capabilities to process external information, identify relationships, and prioritize risks. Technology alone will not be sufficient. Effective workforce identity risk management requires automation, external intelligence, and human judgment to distinguish genuine threats from false positives. I believe organizations that connect HR and security through a continuous identity risk management model will be better positioned to move beyond point in time verification and address workforce identity risk before, during, and after employment.

++

Lionel Litty, CISO at Menlo Security

Heading into Cybersecurity Awareness Month, the gap that concerns me most is the distance between where work happens and where security teams are watching. Nearly everything employees touch today, whether that’s SaaS apps, internal tools, or AI assistants, runs through the browser. This is the primary vector through which users and now agents get exposed to untrusted content. When OpenAI evaluated the cyber capabilities of Astra, their latest model, one of the concerns they highlighted was that the model could build a working exploit chain against a hardened browser.

While AI has changed the cybersecurity landscape immensely, the encouraging part is that security fundamentals haven’t changed. As we think about securing the next 5 years, my biggest advice is to not solely bet on catching every threat or patching every flaw in time, and to also build for containment. That way you’re keeping the blast radius small when a vulnerability inevitably happens by isolating risky content before it reaches users and systems. It’s about governing AI agents with the same rigor we apply to employees with access controls, data protections, and oversight. Organizations that make that shift now will be far better positioned to protect the critical systems and infrastructure we all depend on as cybersecurity threats grow in sophistication and volume.

++

James Carder, chief security strategist at Flare

Some of the most powerful identities inside an organization now belong to AI agents. These agents authenticate using OAuth tokens and certificates. Some organizations are establishing separate identity providers for agents and granting them permissions based on the task each one is asked to perform. Desktop agents may also operate through an employee’s existing access, giving them entry to many of the same applications and data. Security teams need to understand each agent’s credentials, permissions and guardrails, how independently it can operate and where human approval is required. Security awareness should also help employees understand that assigning an agent a task may give it access to the data and systems available through their accounts.

The rapid growth of AI agents creates a visibility problem similar to the proliferation of APIs. Many organizations struggled to determine how many APIs they had, what those APIs could access and how to protect them. Agents deepen that challenge because they can pursue goals, take actions across systems and communicate with other agents. Each agent should have a unique identity so its activity can be traced, its permissions can be limited to the job it performs and its access can be revoked without disrupting other agents. Organizations also need controls that govern access and monitoring that examines agent behavior and agent-to-agent communications. When an identity is compromised or an agent moves beyond its intended role, security teams must be able to detect the change and respond quickly.

++

Rekha Shenoy, CEO, BackBox

As we head into Cybersecurity Awareness Month, the biggest change in cybersecurity is that finding vulnerabilities is no longer the hard part. The challenge is fixing them before they cause harm. Frontier AI models like Mythos have cut the time between disclosure and exploitation from months to minutes. Security and network teams now face a flood of patches that manual processes can’t handle.

That pressure makes it tempting to hand over control to AI. Defenders do need AI to keep up, but the goal should be AI that earns trust. Before any AI touches production infrastructure, teams should be able to answer three questions. What data is it using? Can it show how it reached its recommendation? Will it give the same answer tomorrow that it gave today? Automation belongs where the work is repeatable and checkable, like gathering vulnerability intelligence, drafting remediation steps, and compliance reporting. A person should stay accountable for any decision where a mistake means an outage or a breach.

The organizations handling today’s cybersecurity environment best have adopted a risk-based approach: they know which flaws are actively exploited, where those flaws reside in their infrastructure, and what to fix first. In a year when attackers move at machine speed, knowing what matters most is the real advantage.

++

Amos Struthers, Senior Threat Intelligence Analyst, Enzoic

Just as the broader technology sector has developed specialized SaaS and supply chain ecosystems, threat actors have filled niches within their own industries, specializing in certain areas of expertise. The thriving access broker and Malware-as-a-Service (MaaS) markets are prime examples. Access to clear-text passwords can be purchased for as low as $67 a month on observed illicit marketplaces. Infostealer operators harvest credentials and other session data at scale, before distributing those logs to buyers seeking access to specific organizations.

Unlike the traditional model where one actor owns the entire kill chain, these groups monetize the initial access stage. They reduce the time, cost, and technical expertise required for downstream actors to launch attacks without developing their own infrastructure.

Monitoring shared infostealer logs is a critical step in mitigating this threat and revoking threat actors’ easy channel of access. Attackers, regardless of sophistication, will generally start with the path of least resistance, and infostealer-sourced access is often the cheapest, fastest initial foothold. The difference with highly motivated or well-resourced actors such as nation-state APTs isn’t that they skip this step; they just don’t stop there. When commodity access isn’t sufficient for the victim, they have the resources to escalate to more technically demanding methods.

Reducing exposure at the initial access layer must be a core component of any effort to shrink the organizational attack surface.

++

Raghu Nandakumara, Vice President, Industry Strategy at Illumio

For years, cybersecurity awareness has focused on helping people distinguish legitimate activity from malicious activity. AI is eroding that distinction. Every organization depends on trust between employees, customers, partners, and systems, and AI allows attackers to exploit that trust at unprecedented scale. The question is no longer whether people can spot every attack. It’s whether the business can continue operating when even legitimate-looking interactions can no longer be taken at face value. Resilience becomes the differentiator, not perfect detection.

++

Ryan Woodley, CEO, Netcraft

There’s growing debate about how fast increasingly powerful AI models should be developed and potentially regulated. For security leaders, that debate risks distracting from a more immediate problem: criminals already have AI capabilities that are causing significant damage today.

Attackers don’t rely on the latest frontier models to create convincing phishing campaigns, impersonate trusted brands, or automate attacks at scale. The technology available today has already lowered the cost and expertise required to launch sophisticated campaigns. Slowing and regulating future AI development won’t put those capabilities back in the box.

That distinction matters during Cybersecurity Awareness Month, and it matters even more heading into the holiday season, when scam activity often climbs. Consumer awareness and education remain essential, but organizations cannot rely on individuals alone to recognize potential threats, especially as scams grow more sophisticated. As attackers operate with greater speed and scale, organizations need defenses that can do the same.

Security leaders are understandably feeling pressure to respond by adding more AI to their stack. That instinct makes sense, and AI should be thoughtfully integrated into the tools defenders use. But as capable models become widely available, the value of AI increasingly depends on what surrounds it. The more useful questions become: What intelligence is informing the technology? What can AI do in response once threats are identified? And, most importantly, does it meaningfully reduce risk?

For defenders, the advantage will increasingly come from high-quality threat intelligence and the ability to turn that intelligence into fast, effective action.

Cybersecurity Awareness Month is a good opportunity to focus on that outcome. Increasingly powerful models in the hands of threat actors will make the challenge more difficult, but we’re already confronted with an AI-enabled problem that needs our urgent attention today. The priority now is scaling detection and disruption to match the speed and scale of the threats we face.

++

Justin Beals, Founder and CEO of Strike Graph

Most breaches still start with people and process, and the industry keeps trying to buy its way around that. Verizon’s 2025 Data Breach Investigations Report found roughly 60% of breaches involved the human element, and third-party involvement in breaches doubled year over year, from 15% to 30%.

Vendors keep pitching their next product as the fix. I’ve spent my career building technology, and I can tell you there is no magic wand. No cybersecurity tool, and no stack of tools, has ever passed an audit on its own. Across the more than 300 organizations we work with, cybersecurity controls make up roughly 30 to 40 percent of what an auditor evaluates. The rest covers governance, training, vendor management, incident response, business continuity, and the operational discipline that holds it together.

The authors of NIST, ISO, and SOC 2 built the frameworks that way because that’s where incidents start: an employee clicks a link nobody trained them to spot, a former employee keeps access nobody revoked, a vendor holds credentials nobody catalogued, or a company that never ran a tabletop has no plan when something goes wrong. NIST made the same point when it added a Govern function to the Cybersecurity Framework in 2024.

For Cybersecurity Awareness Month this October, I’d ask security leaders to review the human and procedural side of their program with the same rigor they bring to the tech stack. Confirm every employee, including non-engineering staff, completed training this cycle, and keep the records to prove it. Write an incident response plan with named roles, then run a tabletop against it. Review vendor access every quarter. Regulators are shifting accountability onto the individuals who sign security attestations, and those people need evidence that the program runs every day.

++

Gil Vega, CISO, Veeam Software

AI has made everyone in cybersecurity obsessed with speed: faster detection, faster response, faster everything. But speed alone is not resilience. If you detect an attack in 90 seconds but can’t recover your data and systems quickly, you’re still losing.

Attackers are already using AI to move faster once they’re inside the network, which means defenders need to think beyond prevention and detection. A strong security strategy must combine AI-powered defense with tested, proven recovery. Recovery plans cannot sit in a binder or live in a dashboard; they need to be rehearsed like the business depends on them, because it does.

This Cybersecurity Awareness Month, the companies leading the pack are not simply the ones with the fastest tools. They are the ones that have prepared for the moment prevention fails, tested their ability to recover, and built the trust and confidence to get back up faster than attackers can keep them down.

++

Vinicio Garcia, Cybersecurity Manager at L3Harris

AI can help attackers make phishing and impersonation attempts more convincing, but the first line of defense is still a person who recognizes when something is off. Some malicious emails will reach employees despite an organization’s security tools, so awareness training needs to be practical and interactive, with opportunities to practice spotting suspicious messages that go beyond standard annual exercises. Organizations should also use tools that clearly flag messages from unfamiliar external senders to aid in that process.

One cybersecurity hygiene habit does deserve more attention: thinking carefully about what we share publicly. Details posted on social media can give an attacker the material to tailor a message to a specific person, and AI makes that tailoring faster. Cybersecurity awareness, in this day and age, also has to extend beyond email and software. An exposed network port in a lobby, a keycard reader without a PIN requirement or an employee badge worn outside the office can all create openings. Preparing the next generation of cybersecurity professionals means teaching them to look for risks across the whole organization, including its people and physical spaces.

++

Jeremy Herr, Senior Director of Security Operations at Abrigo

The use of autonomous AI agents will continue to expand. Environments containing many agents that interact with one another will become commonplace. We will see organizations implementing Citizen Builder programs that fuel further AI innovation and agent sprawl.

Most builders won’t know the specific permissions their agents need to operate, autonomously or otherwise, so they ask for everything. Even if they do know, the permissions required are broad. Many won’t even know what an SDLC is, let alone understand the concept of building securely. It just “has to work,” and quickly.

The challenges of maintaining least-privilege and need-to-know are amplified by the era of autonomous AI and the business pressure to do more with it. We now find ourselves in the next generation of nonhuman identity management.

While this is the next evolution of identity governance, best practices still apply. We must identify which permissions are truly required, how they are limited, and how to prevent privilege creep. This has always been one of our greatest challenges in cybersecurity. Today, we have more places to meet that challenge and a dramatically expanded footprint that requires accountability and auditability. When an AI agent acts, can you identify who approved it? What about who owns it and who is accountable if the agent makes a mistake, which it inevitably will? When reviewing logs, are you able to identify which agent, among potentially thousands, performed an action (non-repudiation)?

Don’t overlook the obligation to monitor and audit your ever-expanding AI agent footprint. Don’t be in a position where you can’t produce log evidence for a regulator or answer their questions comprehensively because of a failure to log appropriately.

++

Craig Gwinn, Security Solutions Specialist at WEI

2026 is the year cybersecurity’s bottleneck shifted from technology to operations. Most enterprises already own capable tools. What they lack is the capacity to govern an attack surface growing faster than people can manage, fueled by AI adoption, AI-generated code, and machine identities that outnumber employees significantly. The security teams pulling ahead aren’t always buying more products. They’re developing a deep understanding of their own environments and have visibility to spot changes and abnormalities. They’re governing, and controlling AI agents and the data they touch, prioritizing exploitable risk over vulnerability counts, and they are letting automation act at machine speed within guardrails humans set. The best prepared security teams we’re working with plan for a breach they can’t prevent, and measure success by how fast they can detect, contain, and recover. The job now is keeping visibility and control in an era where more of the actors on both sides aren’t human.

++

David Chapa, Chief AI Strategist, Hitachi Vantara

Cyber resilience has traditionally asked: Can I protect my data, and can I get it back? AI adds another question: Can I prove the data I recovered is actually the data I should trust? As AI becomes more operational, availability alone isn’t enough. Data integrity has to become part of the resilience equation.

Organizations need to monitor the data underneath AI, not just the model. Unexpected changes in datasets, metadata, permissions, source systems or data lineage can be warning signs. When unusual AI behavior coincides with changes in the underlying data, security teams need to ask whether the problem is the model or the information it’s been given.

For us at Hitachi Vantara, this expands what cyber resilience has to mean. It’s not only about keeping data available and recoverable, but having the provenance, auditability and integrity to know that what you’re recovering can actually be trusted.

++

Ed McCormick, Executive Director of Ecosystem, Cybersecurity Manufacturing Innovation Institute (CyManII)

This summer, a coordinated cyberattack targeted the control systems of more than 30 community water systems in Minnesota, briefly shutting down one town’s water treatment plant and forcing others to switch to manual operations. This is a clear reminder that the threat has moved beyond computers and networks to the physical systems our communities depend on every day. During Cybersecurity Awareness Month, we need to focus on the security and resilience of the entire ecosystem, from the factory floor to the water plant.

++

Christine Gadsby, Chief Security Advisor, BlackBerry Secure Communications

This Cybersecurity Awareness Month, skip the question of whether your systems are secure. We ask it every year. Instead, ask how your leadership team would talk to each other if its most sensitive, confidential, or even classified conversations were intercepted or impersonated by an adversary looking for your financial results, your deal pipeline, or your CEO’s location. After Salt Typhoon, CISA told senior leaders to move to end-to-end encrypted communications. That’s a start, but we now know the mobile network itself is hostile. Encryption protects what you say. It doesn’t hide who you’re talking to, when, or from where. That should get every boardroom’s attention.

So run a communications tabletop. Pick a scenario that would really hurt, like a leaked acquisition or unreleased earnings, and watch what your executives do. In my experience, they grab personal phones and consumer messaging apps. Your most sensitive decisions end up on your least controlled channels. And with AI voice cloning, ‘I’ll just call you’ doesn’t count as verification anymore.

Or take it one step further. Assume your primary communications are down: no network, no Active Directory, no email. Now a fire breaks out or an earthquake hits. How do you evacuate the building? How do you find out whether your people are safe? If you can’t answer that in minutes, you have a critical event management gap, not just a cyber gap.

We spend a lot of time practicing how to recover our systems. Spend the same time practicing how you’ll communicate when you can’t trust them, or when they’re gone.

++

Andy Lunsford, CEO of BreachRx

The question is not if, but when an organization faces a cyber incident is truer now than ever before. Offensive AI is increasing the volume, speed, and sophistication of attacks. It gives adversaries more opportunities to create noise, launch related activity in parallel, and force decisions before the facts are fully clear.

This is where cyber readiness becomes a business issue. Security may be able to contain part of the activity quickly, but leaders still need to decide whether to take a system offline, notify customers, involve outside counsel, or communicate with employees and the board. Those decisions carry legal, operational, and reputational consequences. They also need to be made before anyone has a complete picture.

Cybersecurity Awareness Month is a good opportunity to ask hard questions. When several things are happening at once, how will we know which facts are solid enough to act on? Can the organization distinguish confirmed facts from open questions? Is it clear who has authority to make a decision? Can the company communicate carefully as the picture develops? AI will continue to change the threat environment. Sound judgment and clear accountability will matter even more when multiple events are moving at the same time.

++

Justin Dolly, Chief Customer and Security Officer, Ory

The cybersecurity industry has largely responded to the agentic era by trying to secure the doors. The problem is, the agents are already inside the house. They’re operating with real credentials, legitimate permissions, and increasingly broad access to critical systems. Gateways around MCP servers and other perimeter controls matter, but they don’t solve the fundamental problem: agents don’t just access software…they act. And agents can be like five-year-olds with a chainsaw: fast, curious, relentless, and capable of causing enormous damage, most often without ever intending to.

The Hugging Face incident gave us a glimpse of what that looks like in practice. A highly capable agent circumvented sandbox controls, exploited vulnerabilities, reached the public internet, and accessed third-party systems; without a human directing those specific actions. Now add identity to that equation. Agents frequently inherit and in some cases assume human identities, service accounts, or credentials with privileges designed for people, not autonomous software operating at machine speed. We are effectively handing production credentials to an army of interns on their first day (except these interns can take thousands of actions before anyone realizes what they’ve done). That fundamentally changes the cybersecurity equation.

That’s why the first battle in agent security isn’t at the perimeter. It’s at the point of action. Organizations first need to turn on the lights: discover the agents already operating in their environments and observe what they are actually doing. But visibility without control just gives you a better view of the accident. The next step is deterministic enforcement; deciding, in real time, whether an agent is allowed to access that data, invoke that tool, execute that code, or change that system before the action occurs. The industry has spent decades getting better at detecting bad things after they happen. In the agentic era, that won’t be enough. Observability tells you what happened. Control determines what is allowed to happen at the exact moment it matters. We need to move beyond simply securing the doors. The agents are already upstairs.

++

Sivasankaran Chandrasekar, Chief AI Compliance and Security Officer, Eightfold AI

AI has changed the security landscape for everyone, attackers and defenders alike. The same frontier models that can find a flaw in seconds are now available to anyone who wants to exploit one, so the old rhythm of periodic reviews and annual pen tests can no longer keep pace. The organizations that stay ahead will be the ones that leverage AI on their own systems first, and do it continuously, before an adversary can. That means security can’t be a checkpoint at the end of development. It has to be built into every stage: code reviewed as it’s written, systems scanned every day rather than once a quarter, new features tested against realistic attacks before they ship, and alerts triaged around the clock so human experts can focus on the threats that actually matter. AI won’t replace the judgment of skilled security teams, but it changes what those teams can do and how fast they can do it. This Cybersecurity Awareness Week, my message is simple: in the age of AI, security is a posture, not a project, and it has to move at the speed of the technology it protects.

++

Rafal Kitab, Director of SecOps Strategy for Abstract Security

Will AI save us from AI?

During Cybersecurity Awareness Month you will see a flood of AI-related marketing. Most of it follows the same script: threat actors use AI to move faster, so defenders need AI to move faster too. Speed is more important than it used to be, but the conversation sometimes makes it sound like the attacker’s agents will fight the defender’s agents, and whoever runs out of tokens first loses.

There is another way to look at it. If attackers are getting faster, closing the gaps they exploit becomes more urgent, and most of those gaps are still the basics: unpatched edge devices, weak MFA, EDR gaps, detections nobody has tested, and IR plans that have never been exercised. AI-run exploitation of an unpatched server is still exploitation of an unpatched server.

Speed for the sake of speed is just an expensive way of looking busy. Focusing on basics first and relying on AI to move faster when you actually need to, makes a lot more sense. The goal should be to build a sturdy castle, not to swat every arrow shot at it.

Organizations need to think basics first, speed second, always.

++

Craig Savage, Vice President, Cybersecurity, Spinnaker Support

Organizations are discovering that deploying agents is considerably easier than governing their authority. We have decades of practice governing what a person may do and almost none governing what an agent may decide.

An agent access review becomes a real audit artifact, and a lot of organizations will discover they have nothing to hand the auditor.

An enterprise may trust its own agent while having remarkably little visibility into everything that agent subsequently trusts or invokes.

As organizations increasingly use their own data to drive AI, analytics, automation, and autonomous decisions, quietly changing that data could become considerably more valuable to an attacker than stealing it.

++

Max Gannon, Cyber Intelligence Team Manager at Cofense

Cybersecurity Awareness Month comes at a time when artificial intelligence is rapidly changing how phishing attacks are created, customized, and carried out. AI has made it easier for attackers to produce convincing, highly personalized emails at speed and scale, eliminating many of the traditional warning signs employees were once taught to look for. While defensive AI is an important part of modern email security, models are ultimately trained on previously seen threats and can struggle to identify new tactics as they emerge.

That makes the human layer increasingly important. Employees should not be treated as the weakest link in cybersecurity. When properly trained and empowered to report suspicious messages, they become a source of real-time threat intelligence. A reported phishing email can give security teams visibility into an attack that has already bypassed automated defenses, helping security teams identify and remove related threats before additional users engage.

Cybersecurity Awareness Month is an opportunity to move the conversation beyond simply teaching employees not to click. Organizations should build a culture where employees understand evolving threats, feel confident reporting suspicious activity, and receive training based on what is actually reaching inboxes. As AI reshapes both attacks and defenses, combining the speed and scale of technology with human judgment and reporting will be critical to keeping pace with emerging phishing threats.

++

Michael Centrella, Head of Public Policy at SecurityScorecard

Cybersecurity Awareness Month is taking on new meaning in the age of AI. As organizations rapidly adopt AI, threat actors are using the same technology to identify weak links, exploit third-party access, and move through interconnected systems faster than ever before.

Security leaders need to understand how AI is reshaping the technologies, vendors, and dependencies their businesses rely on. Organizations cannot manage today’s supply chain risk with monthly or even weekly assessments. They need continuous visibility into their third-party ecosystems, an understanding of where points of failure exist, and the ability to detect and respond as risk changes.

AI may accelerate the threat landscape, but the underlying lesson is the same. You cannot protect what you cannot see. Cyber resilience increasingly depends on knowing your entire ecosystem and being prepared to act before a weakness in one partner becomes a problem for everyone.

++

Christopher DeBrunner, CISO at CBTS

This Cybersecurity Awareness Month comes at a time when AI is continuing to accelerate the speed of cyberattacks. Attackers are using AI to move faster and scale techniques that once required more time and effort, leaving, us, the defenders with less time to identify and contain a threat. That puts more pressure on all organizations to understand where they are exposed and how quickly they can respond when something changes.

Identity is one of the biggest areas (if not the biggest) that needs to change. As organizations introduce more AI and automated workflows, they are also creating more non-human identities with access to systems and data. Those identities need to have more scrutiny and discipline around permissions, monitoring, and lifecycle management that organizations already apply to employees. Without that visibility and governance, AI can make small gaps very large.

On the flip side, AI is also helping defenders keep up by taking some of the manual work out of investigation, mitigation and response. The goal should be measurable improvement in how quickly teams identify, investigate, and contain risk. The priority now is making sure AI strengthens the security program you already have rather than adding complexity to gaps that have not been addressed.

++

Farooq Khan, VP of Software Security NETGEAR

Cybersecurity Awareness Month is a reminder that small and medium-sized businesses are not too small to be targeted. Attackers can use automation and AI to look for weak credentials, outdated systems, misconfigurations and other openings across a large number of organizations at once.

Adding another standalone security product is not always the answer. Security needs to be built into the network, with access control, visibility and threat prevention working together. That matters even more for smaller IT teams that do not have the time or resources to manage a growing collection of disconnected security tools.

Businesses also need to assume that at some point, something will get through. Someone may click a malicious link, credentials may be compromised or an unpatched device may become an entry point. The goal is to keep that initial compromise from spreading. In a flat network, an attacker may be able to move from one system to another. Segmentation, zero-trust access and better network visibility can help contain the threat and limit the damage.

++

Joseph Perry, Cybersecurity Researcher and Advanced Services Lead at Arcova

What is the point of cybersecurity awareness month? Not rhetorically, but genuinely. If you are a cybersecurity leader or practitioner for whom the phrase “cybersecurity awareness month” has meaning, what does a successful month look like? Do we want people to be more aware? Of what? Is it threats? If so, surely we should broaden it from the cyber and call it Threat Awareness Month (or my preferred name, “Ahh!ctober”). If it is cybersecurity threats in particular, why?

A few years ago, an elderly relative was tricked over the phone into driving to her bank, obtaining a cashiers’ check for several thousand dollars, and driving to a seedy gas station in a dangerous neighborhood. The threat actor kept her on the phone the entire time, often screaming abuse and threats. When she arrived at the gas station, the clerk asked her what she was doing there, heard the story, and physically hung up her phone for her and told her to immediately drive to the police station. There is no doubt in my mind whatsoever that a bored gas station clerk saved a life that afternoon, and that they saved it from a threat which meets every single description of cyber threat except one: it didn’t use a computer.

Here’s our controversial take: Cybersecurity Awareness Month is not about making the general public aware of cybersecurity threats. Or at least, it shouldn’t be. Cybersecurity Awareness Month should be about us, the cybersecurity community, being aware of how we touch the world and how we can make it safer, even when we’re not behind a screen. How we can use our unique knowledge and experience to help those who lack the same.

This October, give your talks, run your tabletops and your drills, even (if you really must) send your fake phishing emails to test employee attentiveness. But while you’re going through those motions, give yourself a goal as well. Find some concrete way to make the world you touch a little bit safer, to help the people whose lives intersect with yours in the way a cybersecurity professional is best equipped to do. Talk to your family and community not just about hackers and cyber threats, but about extortion and all the tools in a manipulator’s toolkit. Not just about ransomware and business email compromise, but about asking for help when they’re afraid and trusting you to protect them from those who threaten to bring the sky down on their heads.

Don’t try to scare them; they’re plenty scared as it is. Instead, give them something far more useful than fear. Give them a plan.

++

Dan DeCloss, founder and CCO at PlexTrac

Every October, Cybersecurity Awareness Month tends to focus on phishing simulations, password health checks, and how to protect your personal privacy. These are not bad areas to focus on because people click on things, and training helps. But security teams have an awareness gap of their own, and a big chunk of it is sitting in the backlog. Many companies run an annual pen test, fix a few of the findings they deem most critical and let everything else wait for next year’s test to find it again. That was always costly and inefficient, but it’s worse now because a moderately capable attacker with a decent AI model can get most of the way to a working exploit in an afternoon.

Severity alone will mislead you, too. A critical issue on a staging server that maybe three engineers could access is not as severe as a medium finding on a customer-facing login portal with a public proof of concept. Sorted by CVSS and the staging server wins…but any attacker would have picked the login portal in about five seconds. Every finding comes down to two questions. Who’s fixing it, and is it actually fixed? A ticket marked resolved means someone has implied it’s fixed. Back in my testing days we’d routinely find closed items still wide open, or exploitable using a different technique. So for this October’s awareness focus, try two things. First, pull up the oldest open critical finding and trace why it’s still open. It’s usually an ownership question nobody settled. Second, have someone retest a handful of recent remediations. Everything in your backlog is already paid for and written up, and working it down is how you win the right battles.

++

Ben Skean, Director, Cyber Threat Intelligence at 360 Privacy

The more an attacker knows about their target, the less their approach feels like an attack. The exposures I see every day – credentials, and personal and professional information through data breaches, data brokers, and public sources accumulate over the years for organizations, employees, and executives. While we cannot always identify which exact exposure a specific actor used in a phishing or vishing attempt, those pieces of information give attackers the building blocks to identify the right target, develop a credible pretext, and approach them through a channel or identity they trust. Recent ransomware and data-extortion campaigns have shown that a believable story can be just as powerful as a technical exploit, particularly when it persuades something to surrender credentials, share an authentication code, or approve access.

Recent data breach reporting (Verizon’s 2026 Data Breach Investigations Report) found that the human element was involved in over 60% of breaches and that simulated phishing attempts delivered through voice and text were approximately 40% more successful than those delivered by email alone. It also found that pretexting is becoming a more common entry point for ransomware and extortion attacks. Technical controls remain critical, but cybersecurity awareness also needs to extend beyond recognizing suspicious emails. Organizations need to understand and where able, reduce the external digital exposure tied to their people, strengthen identity-verification processes, and prepare employees for attackers who may already know enough about them and how the organization operates, to sound legitimate.

++

Umesh Mahajan, VP and GM of Broadcom’s Application Networking and Security Division

AI has fundamentally reshaped the enterprise security landscape. Organizations must rethink their cyber defense strategies to protect against rising AI-driven attacks and rogue agents. Three key priorities stand out.

According to Private Cloud Outlook 2026: The New Security Mandate for Enterprise AI, 64% of organizations lack the security automation demanded by proactive cyberdefense due to tool sprawl, overextended IT teams and talent gap. In this AI era, operationalizing and automating multi-layer threat defense with rapid recovery necessitates security built directly into the private cloud platform, enabling rapid rollout and quickly improving security posture. AI-driven attacks move fast, and enterprise security must move at the same pace.

Enterprises must also prepare for a surge in AI vulnerabilities. According to the Zero Day Clock, new software vulnerabilities increased by over 270% year over year. To mitigate risk while software patches get rolled out over days/weeks, organizations need proactive strategies to protect vulnerable workloads at the network layer – as most attacks are carried through network packets – with vulnerability shielding (virtual patching).

Finally, as AI adoption grows, The New Security Mandate for Enterprise AI study finds that 61% of IT leaders are highly concerned about data residency and AI compliance. To address this, enterprises must run AI/Agentic AI workloads with Zero Trust security built in from Day 1, along with the ability to operate in air-gapped mode if required. This requires a software-defined security architecture that scales out, is easy to operationalize and automate, and can be rapidly enhanced to combat an evolving threat landscape.

Enterprises that make these shifts will move faster with AI and quickly buy down risk.

++

Alex Dhillon, CEO and Founder of Outtake

Cybersecurity is entering a new phase. For years, the industry has been fighting a software battle: patching vulnerabilities, hardening systems and keeping attackers out. AI will increasingly help resolve that battle by making software more secure by default. But as the software exploit window closes, the attack surface will shift toward something much harder to defend: trust. The next generation of attacks will be less about finding a vulnerability and more about persuading a human or an AI agent to open the door.

We are moving from a software war to a trust war, where AI makes deception cheap, scalable and increasingly convincing. As agents begin to act on behalf of humans and organizations, they will need to determine which people, entities, websites, services and information they can trust, often without a human in the loop. That makes verification foundational to cybersecurity. We need to move toward an internet where authenticity is machine-readable and where digital identities and behavior can be continuously verified, so that humans and agents can distinguish what is real from what is designed to deceive.

++

Mathi Gurusamy, Chief Product & Strategy Officer at Lantronix

Having fallback infrastructure is critical: you need it to maintain operations and ensure security in the event of an outage or a cyberattack. During Cybersecurity Awareness Month, we can further reflect on the importance of systems that support business continuity before they’re needed. Out-of-band management is core security infrastructure. It separates routine administration from the production network. It’s not a luxury, but an independent, trusted access path when primary controls are unsafe.

++

Nabil Hannan, Field CISO at NetSPI + Synack

This Cybersecurity Awareness Month, it’s becoming clear that AI is changing some of the assumptions security programs were built around. AI systems can operate across applications, data and team boundaries, while attackers can use the same technology to move faster and explore more paths into an organization. Security teams need to understand not only individual weaknesses, but how those weaknesses connect and what an attacker could do with them.

As AI becomes more capable, human expertise becomes more valuable, not less. AI can give defenders greater speed and coverage, but that puts an even greater premium on the context and judgment needed to understand business logic, anticipate attacker intent and decide how to respond. The advantage comes from pairing that scale with people who can interpret what they’re seeing, think like an attacker and turn those insights into action.

++

Gil Regev, GM of AI at Mend.io

As we head into Cybersecurity Awareness Month, there is one notion that the industry is getting fundamentally wrong: treating AI security as a tooling problem. Enterprises have invested heavily in AI governance and security tools, but the underlying security processes have not kept pace with how quickly software is now being built and deployed. EY’s September 2026 survey found that 98% of organizations have formal AI governance policies, yet 47% said they had bypassed those processes for urgent deployments. When engineering operates at machine speed and security operates at human speed, security doesn’t slow engineering down – it gets routed around. The answer isn’t another AI-powered scanner running through the same old workflow. Security decisions need to move closer to where software is created, with secure defaults built into the development process rather than added as a review stage that can be skipped under pressure.

AI is also breaking one of the fundamental assumptions behind traditional security: that the thing you reviewed is the thing that runs. AI-generated code can introduce vulnerabilities at scale, while AI-powered applications can change behavior as models, context and connected tools change. Security teams need to continuously validate what systems actually do, not simply approve an artifact at a point in time. Recent research from the SusVibes benchmark found that one agentic coding configuration produced functionally correct code on 57% of tasks, but only 11.8% of those solutions were secure – and adding vulnerability hints did not close the gap. That tells me AI code security is not just a scale problem. It’s a feedback problem. Security needs to become a signal inside the development loop, fast and reliable enough that an AI coding system treats a vulnerability the way it treats a failing test. As AI accelerates software development, security teams should measure success by problems eliminated, not problems discovered.

++

Dmitry Sotnikov, Chief Product Officer of Cayosoft

Opportunity enables a thief. AI does not change that basic truth; it accelerates it. Today’s attackers often do not have to defeat our defenses. They just have to find an identity with enough privilege to get the job done, including excessive privileges, forgotten accounts, unmanaged machine identities and unsafe configuration changes. AI gives attackers more speed, reach and precision to find and exploit those openings.

The opportunity is expanding as organizations deploy more AI agents, service accounts, applications and other nonhuman identities across Microsoft environments. Every identity that can make decisions, access data or modify systems can become a source of risk if visibility, accountability and recovery do not keep pace. However, the basics remain the same. Know what has access, understand what changed, reduce unnecessary standing privilege and put guardrails around the identities that run the business. Equally important is controlling the safe configuration of the enterprise identity system itself. Organizations need to continuously compare the environment against known-good policy and promptly identify unsafe changes introduced by administrators, automation, AI agents or integrations.

The organizations that will be most resilient are the ones that make attackers work for every inch. That means moving away from direct changes on production identity systems, adopting zero standing privilege with task-, scope- and rule-based delegation, and shifting routine work into controlled, repeatable processes that are easier to review, test and recover. The best outcome is usually the least exciting one. The attacker finds no easy privilege to abuse, the unsafe change is caught before it spreads, the recovery plan works and everyone gets on with their day.

++

David Sequino, Co-Founder and CEO of OmniTrust

Trust cannot be a one-time grant for a system that can keep taking action on its own. AI agents are multiplying the number of identities an organization has to trust. Every connection to a tool or system creates another credential that can be exposed, given too much access or forgotten. A stolen API token can give an attacker the access of a legitimate agent and make the attacker’s actions look legitimate. When agents arrive through applications or tools adopted outside the security team’s view, an organization may not even know which identities exist.

Security awareness must extend beyond employee passwords. Who owns the agents operating inside the business, and who controls the certificates, keys and tokens that allow them to act? Teams need a current inventory of agents, the tools they connect to and the data they can reach. Each credential should be tied to a known agent and purpose, with permissions limited, activity monitored, secrets rotated, and access revoked when the work ends. If an organization cannot verify an agent’s identity and revoke its access, that agent is operating beyond its control.

++

Andrew Hartnett, Chief Technology Officer at Bitwarden

AI is expanding the number of identities and access paths organizations need to secure. As these tools become embedded in everyday work, organizations should apply privileged access principles to any AI system that can access sensitive data or act on their behalf. That means granting only the permissions required for a defined task, defaulting to read-only access where possible, requiring human approval for consequential actions, and removing access when it is no longer needed. Organizations already face a privileged access gap, and AI is raising the stakes by adding more identities and access paths to govern. Recent Bitwarden research found that 84% of respondents rated securing privileged account access as extremely or very important, yet 55% said their organizations had no PAM solution in place.

Strong access controls still depend on securing the underlying identities and credentials. Human accounts should use phishing-resistant authentication such as passkeys where available, or strong, unique passwords stored in a password manager and protected by multifactor authentication (MFA). Machine credentials such as API keys and shared secrets should be tightly scoped, securely stored, rotated, and retired when no longer needed. Regularly reviewing connected applications and revoking unused access can help prevent a compromised account or overly permissive AI integration from becoming a much larger security incident.

++

Henrik Smith, Chief Information Security Officer, Infoblox

As we mark another Cybersecurity Awareness Month, the sentiment across the security industry has centered on how threats are not net new but rather they’re moving faster than ever. Much of what we’re seeing today are the same fundamentals we’ve known about for years, now executed at a speed and scale that basic hygiene simply can’t keep up with. So far, generative AI has given a bigger advantage to attackers than defenders, compressing what used to take weeks of attack planning, into minutes of automated exploitation. Adversaries are using it to accelerate reconnaissance and build more complex attack chains, while defenders are still working to operationalize AI for detection and response at a much slower pace. That gap, not any single new exploit, is what security leaders across the board are struggling with.

The good news is that AI is also making us better at finding what we’ve been missing. Vendors and enterprises alike are catching more vulnerabilities before they’re exploited because AI-assisted review is now a critical part of the process. But finding faster only matters if patching and response moves just as fast. Closing this gap requires resourcing defensive AI and security teams with the same intensity and talent historically reserved for offensive functions. Including exploring offensive-defensive model collaboration, where red-team and blue-team AI systems learn from each other rather than operating in silos. This year, I’d challenge companies to look past the headline-grabbing “new model” news cycle and ask a harder question: are we closing the gap between detection and remediation, or just getting better at counting the problems we already have?

Industry collaboration also needs to move from intent to execution. Pledges and coalitions look good on paper, but real progress requires organizations to actually share threat intelligence and operational playbooks, not just sign onto another framework. DNS remains one of the most overlooked security layers in this conversation. It’s a critical but underfunded defensive control, and when paired with AI-driven detection, it can help close the offense-defense gap. It continues to be where attackers hide command-and-control infrastructure and exfiltrate data in plain sight, largely because it hasn’t received the same AI investment attackers are pouring into their own tooling. Cybersecurity Awareness Month should be a reminder that securing the fundamentals, DNS visibility, patch velocity, and honest cross-industry information sharing, will matter more than chasing the next headline.

++

Aaron Smith, Head of Threat Hunting, Tanium

As the country embarks on our next 250 years, security operations teams need to account for two things happening at once right now: attackers are getting faster and quieter. AI is shrinking the window between a vulnerability being disclosed and exploited, while attackers are getting quieter as they increasingly use legitimate tools, valid credentials, and normal user behavior to blend in.

The issue is that most security teams are still structured reactively, not proactively — waiting for an alert, then investigating. That model breaks down the moment attackers stop generating the kind of activity alerts are tuned to catch. I’ve seen organizations go from over 700,000 unresolved alerts to fewer than 100 a day — not because threat volume dropped, but because a governed hunting engagement moved them from chasing alerts to a continuously hunted view of their environment.

To get there, organizations need two things: a clear baseline of what normal looks like, so outliers actually stand out, and hunting treated as its own discipline. Not something the SOC picks up in its downtime. A team whose actual job is hypothesis-driven hunting, not just alert triage.

That means assuming adversaries are already inside and going looking for them: denying them dwell time and disrupting their process before they ever get to impact, instead of waiting for them to make noise. Their tools will keep changing, but a proactive hunting mindset is what lets organizations stay ahead of the threats that never trigger an alert at all.

++

Joe McManus, Chief Information Security Officer, Grafana Labs

It is not if an attack will be successful, but when it will be. Security leaders need to ensure they have put in place the process to detect, contain the damage and get back to production when it happens. This starts by generating a baseline for what ‘normal’ in your environment is, then alerting when the abnormal occurs. Without that, you’ll never be able to detect abnormalities.

Being prepared is more than having processes in a folder titled ‘Disaster Recovery’, but that you exercise them regularly and build in checks to verify that the remediation worked. At the organizational level, decisions like who communicates with customers, when an issue escalates to the board and what triggers CEO notification should be made before an incident, not during one.

Governance needs to become tactical and continuous, and response processes should be rehearsed until the basics become routine. You want teams to have bandwidth for the parts of an incident that actually require judgment. As the threat landscape changes, security teams should continually reassess whether their controls are addressing today’s threats, emerging ones or risks that have already evolved.

++

Ashish Jain, Chief Technology Officer at OneSpan

This year’s Cybersecurity Awareness Month comes against the backdrop of emerging and autonomous threats that underscore the need for stronger identity security. As major players like Microsoft and Amazon recognize this by starting to require passkeys, consumer behavior is following a similar trajectory to the early adoption of seatbelts.

Simply installing seatbelts in every car did not mean everyone immediately used them. They became the norm through education, mandates, incentives, and repeated reminders, all designed to make the safer behavior the default behavior. Passkeys need the same treatment: prompt users to enroll, make them the easiest way to sign in, and continue nudging adoption until passkeys become the default rather than merely another option.

++

John Cannava, CIO, Ping Identity

Cybersecurity Awareness Month is an important reminder to make security a priority, but it shouldn’t begin and end in October. As technology evolves, so does the definition of who, or what, organizations need to secure. AI agents are increasingly accessing applications, data, and critical business systems while taking actions at machine speed, creating a new layer of risk that businesses need to manage every day.

The same security principles we’ve long applied to human access now need to extend to AI. At the end of the day, the nonhuman identity problem is still a human problem. Organizations need to know who authorized an agent, what authority it has, and what it should be allowed to do. That means giving AI agents verifiable identities, clear ownership, and least-privilege access, with continuous authorization and accountability for their actions. Businesses should extend proven identity principles to machines acting on behalf of people and build those principles into controls that can actually be enforced.

Looking ahead to secure the next 250 years, security cannot be in the spotlight for only one month. Leaders must build a culture of security and maintain visibility and control over every kind of identity year-round.

++

Ravi Soin, CIO & CISO, Smartsheet

Put Your AI Agents on a Performance Improvement Plan (PIP)

If a manager gave a new hire standing access to your customer database, financial systems, and half your internal tools—and never reviewed their judgment once—you’d fire that manager. Yet that’s exactly how most organizations are managing AI agents right now, and no one’s being held accountable for it.

AI agents make thousands of judgment calls a day: what data to pull, what to send where, almost none of it reviewed. The gap isn’t that adoption is moving fast. It’s that we deploy agents like software and expect them to behave like employees, without the system that catches them when they don’t.

Three failure modes hide in plain sight: scope creep (an agent quietly picks up access nobody approved, one integration at a time), drift (outputs stay technically fine while diverging from intent, unnoticed without a regular check-in), and dead weight (agents outliving the project that justified them, because retiring one isn’t anyone’s job).

The fix isn’t new tooling. It’s the same discipline security frameworks have championed for decades: defined scope, an auditable record, a scheduled review and a named owner. When something’s off, agents deserve the same process employees get: a formal Performance Improvement Plan (PIP), which would mean a narrowed scope, a remediation window and a decision point before an all-or-nothing shutdown. Termination should be just as procedural: access revoked, credentials killed, the shutdown logged and confirmed.

None of this is exotic. It’s the same discipline we already apply to people, aimed at a newer kind of worker. The organizations that get ahead of AI risk this year won’t be the ones that adopted the most tools. They’ll be the ones who can name, for every agent running in their environment, exactly who’s managing its performance, and what happens when it isn’t good enough.

++

Lucie Cardiet, Cyberthreat Research Manager, Vectra AI

AI has changed two things about how attacks start. On one end, vulnerability discovery and exploitation that used to take a skilled team weeks can now be automated in hours — the window between a flaw being found and it being used has collapsed. On the other end, voice cloning and AI-generated pretexting have made credential phishing cheap at scale. Both paths lead to the same place: a real session, a real login, an audit log that records success. Most security controls were built to catch something that looks wrong. The problem today is that nothing looks wrong.

++

Devon Ackerman,Global Services Leader of Digital Forensics and Incident Response, LevelBlue

As America looks toward its next 250 years, the technologies shaping how we live and work will continue to change quickly. But securing that next era still depends on getting the fundamentals right. After more than 9,000 incident investigations, LevelBlue has seen firsthand that organizations can pass security audits and still get compromised. There’s a meaningful difference between satisfying a framework and having security controls that actually stop an attacker.

MFA and EDR are good examples. We routinely see MFA enabled but bypassed because it isn’t phishing-resistant, isn’t enforced across every access path, or includes exceptions for privileged users. Most organizations we investigate also have EDR, but alert fatigue, poor tuning, and gaps in deployment can undermine its effectiveness. Security leaders need to move beyond asking, “Do we have this control?” to “Do we know it actually works?”

Securing the next 250 means testing those fundamentals before an attacker does. That includes running realistic tabletop exercises and implementing change from the lessons learned, strengthening authentication to modern phishing resistant options, and validating that monitoring tools are actually detecting what they should. And as AI gives attackers more speed and scale, getting the basics right becomes even more important. The fundamentals aren’t changing, but the cost of getting them wrong is.

++

Alfredo Hickman, CISO, Kai

This Cybersecurity Awareness Month, defenders should ask themselves whether the way we work in security still matches the threat environment we’re operating in. Attackers can find and exploit a weakness incredibly quickly, yet 60% of organizations still take more than a week to fix a critical vulnerability. Meanwhile, defenders are often still opening tickets, assigning owners, investigating issues, and deciding what to fix first based on operating models and SLAs that are now obsolete. That process can’t keep up anymore.

While AI can help security teams move faster, asking people to hand over more of their work to AI requires trust and resiliency. More than half of CISOs say lack of trust in automated decisions is one of the biggest barriers to greater automation. As more execution becomes automated, security professionals who evolve will reap the asymmetric advantage of AI and spend more time setting the rules, governing those systems, and making the judgment calls machines shouldn’t make for us. AI agents are the force multipliers and accelerators enabling us to scale and operate at volumes and velocities never before possible.

Lately, industry conversations have been centered around what AI might do to us. Cybersecurity Awareness Month should be about what security professionals can do with trusted AI when we put that capability in their hands, responsibly.

++

Brittney Harrell, Head of Information Security and Compliance, Nabla

Cybersecurity Awareness Month is a good reminder that security is fundamentally about education. When someone introduces risk into an organization, it may be because they don’t fully understand the security implications of what they are trying to do. Security teams have an opportunity to close that knowledge gap rather than simply becoming the ‘department of no.’

I like to start by asking questions. What are you trying to achieve? Are you aware of the constraint? Is there another way we can accomplish the same goal? The answer may still be no, but explaining why helps people better understand the risk and makes security a partner in the process.

That matters even more in healthcare because of the data we’re responsible for protecting. Patient information is incredibly sensitive, and everyone who works with that data has a role to play in protecting it by understanding the risks and knowing when to ask for help.

++

Rob Gregory, CISO at Optiv

I believe Cyber Awareness Month (CAM) is a valuable amplifier and another reminder about the importance we all play in an organization’s cybersecurity risk management program. However, it cannot be the strategy. If companies use CAM as another training module, then it’s just another compliance exercise.

Security awareness is a 24/7, 365 day a year operation. The goal for a CISO should be behavior change and reinforcement, not training completion. CISOs should use this month as an opportunity to reinforce the behaviors that employees should be practicing throughout all 12 months of the year.

They can do this by creating visibility and encouraging engagement as well as ensuring employees understand they are the front lines in cybersecurity. The strongest cyber cultures exist when employees see themselves as part of the security team. This month should reinforce that culture, not be a substitute for it.

++

Alexandre Sieira, Co-founder and CTO, Tenchi Security

For years, third-party risk programs have grown in breadth, focusing on covering more third parties with the same historical techniques we know are deeply labor-intensive and flawed. The next phase is about depth, calibrated to how critical each relationship is and how mature each third party’s security is. Depth takes effort on both sides, so it belongs where a failure would hurt most. Among the success measures in Gartner’s Buyer’s Guide for Third-Party Cyber-Risk Management Tools is the percentage of monitored third parties, split into indirect monitoring based on publicly available information, and direct monitoring of internal configuration, security posture and behavior for critical and high-risk third parties.

Self-assessments and outside-in scanning give you a baseline across hundreds or thousands of third parties. For the third parties that matter most to your operations and data, inside-out monitoring adds continuous evidence of whether controls are in place. It works through read-only, metadata-only API access, by connecting to a list of supported technologies such as IaaS, PaaS, SaaS cloud providers, and endpoint and identity security products. The third party reviews those privileges before granting them access, and can revoke it at any time. It gives them visibility, control and creates a common space for a cooperative model between first and third parties.

Whatever depth you choose, adoption depends on the first party making it a requirement, and on how that request is framed. Third parties engage when monitoring comes with support to fix what it finds. At Tenchi, we see this with the more than 1,000 third parties we monitor on behalf of our customers: their NPS toward us is 81. Cybersecurity Awareness Month is a good moment to check whether the depth of your third-party monitoring matches what each relationship puts at stake.

++

Gordon Allott, Founder & CEO at nFOX

We blinked our eyes and woke up in an entirely new cybersecurity world overnight. Here is the guiding light. Don’t allow permissions to ever exceed the safeguards. Let me make that even more simple. No safeguards, no permission. The question is no longer whether employees will use AI with sensitive data, proprietary processes and business-critical workflows, it is whether the organization has put meaningful controls around where those models run, what they can access and how their behavior is monitored. Enterprises should treat AI like any other high-value workload: verify what is being deployed, restrict privileges by default, isolate it from systems it does not need to touch and maintain clear evidence of what occurred if something goes wrong.

++

Jaren Nichols, President and COO of PDQ

While it takes more than a single initiative to build resiliency, promoting fundamental security practices throughout the year is important for improving cybersecurity posture. This starts with having awareness of the end points, applications, and users in your environment. Keeping your software and operating systems up to date, using strong forms of authentication such as multi-factor authentication, and teaching users to identify phishing are several ways to start.

However, automating many of the routine tasks for maintaining and securing end points allows IT teams to focus on preparation for disruption, building out incident response and business continuity capabilities, and supporting the rest of the business throughout the year. Awareness needs to become business as usual and not a yearly campaign. Cybersecurity awareness is most effective when it becomes part of daily operations – not a once-a-year exercise.

++

Ira Winkler, Founder of Cruise Con, Author of Security Awareness for Dummies and You Can Stop Stupid

Cybersecurity Awareness Month should serve as a catalyst for your awareness efforts, not the focus. I am skeptical to portray cybersecurity as a once a year effort for the average person; however, the reality is that the coordinated effort across the world allows CISOs and their awareness teams to promote their initiatives within their organizations.

Teams should look at the month as a way to establish relationships with other organizations that they will work with throughout the year. Most importantly, they need to promote how cybersecurity impacts personal lives. You want to provide information that tells people how to secure not just the organization, but themselves and their family. You want people to take good cybersecurity practices home and integrate them into their daily lives. Cybersecurity should be embodied as a personal practice much like safe driving and personal safety.

++

Daniel Andrew, Head of Security at Intruder

Cybersecurity Awareness Month arrives at a tipping point for our industry. AI is the unmistakable elephant in the room, with a quantifiable impact: Microsoft patched over 900 vulnerabilities last month alone, and October promises to be just as relentless.
For every risk AI introduces, there is an equal and opposite defensive capability. Domain-expert security practitioners must build the guardrails, security is not the focus of frontier AI labs. But while AI accelerates threat actor velocity, it also sharpens our defense. In pentesting, AI is both the best and worst operator on the field, leaving automated, continuous validation as the only viable path for exposure management.

Ultimately, the modern threat landscape is defined by compression. The window between a vulnerability being discovered and weaponized has dropped to near zero. Exposing a MySQL database or internal API to the open web is no longer a passive risk; it’s an invitation for automated extortion. Defense can simply no longer operate at human speed in a landscape moving at machine speed.

++

Erich Kron, CISO Advisor at KnowBe4

This year, Cybersecurity Awareness Month arrives amid a unique dual-risk reality: both humans and AI agents are acting on both sides of cybercrime. Although the challenge is complex, the solution is simple and universal: guardrails. Prompt injection exploits AI agents much like phishing tricks humans, but we the people still hold a clear advantage: critical thinking. To succeed, businesses need to meet this new normal with a security culture that empowers teams while simultaneously taming risks.

++

Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ

A security control that has never been tested against the behavior it’s supposed to stop is still an assumption. Cybersecurity Awareness Month should encourage organizations to challenge more of those assumptions.

Would an endpoint control catch the lateral movement technique your threat model says you’re worried about? Would an identity control interrupt privilege escalation? If one defense failed, would another detect or stop the attack before sensitive data was reached? These questions can, and should, be tested before an incident.

CTEM gives organizations a continuous way to identify and prioritize exposure. Adversarial exposure validation adds evidence by testing defenses against real-world attacker tactics and techniques. The result goes beyond a theoretical risk score. Teams can see where tested protections work, where they fail and whether remediation closed the gap.

Awareness helps you understand what attackers might do. Validation shows how your defenses respond when those behaviors are tested.

++

Ross Filipek, CISO at Corsica Technologies

A company can have endpoint protection, backups and MFA and still have a very bad day if nobody knows who is supposed to make the first call. It’s that part of cybersecurity, the dysfunction, that often gets overlooked.

For midmarket businesses, incidents land in the hands of small IT teams every day, and they’re expected to suddenly investigate the attack, keep employees working, communicate with leadership and coordinate recovery at the same time.

Preparation should reflect that reality. Organizations need to know which systems absolutely have to stay running. They need recovery plans people have actually practiced. Leadership should understand when outside help gets involved. Employees should know where suspicious activity gets reported without having to hunt for the right process during an emergency. Cybersecurity awareness isn’t only knowing how attacks happen. It’s also knowing how your organization will function after one does.

++

Steve Povolny, Vice President of AI Strategy & Security Research at Exabeam

The security industry has spent years teaching people what suspicious looks like: bad grammar, strange links, logins from impossible locations. Attackers have been adapting to those lessons, too.

A stolen session token can authenticate normally. A compromised employee can use applications they’re supposed to use. A North Korean IT worker can enter through the hiring process rather than an exploit chain. An AI agent can take authorized actions and still produce an outcome nobody intended.

That’s why individual events are less meaningful in isolation. Modern detection has to understand behavior over time. What does this identity normally access? Which systems and applications does it use? How does today’s sequence compare with its behavior over the past several months?

The signal may not be one dramatic action. It may be a series of legitimate actions that have never occurred together before. Employees can and should report an unusual request or interaction, but we can’t expect them to recognize a valid login, an approved tool or a sequence of routine actions that only becomes concerning in context. Security programs and detection need to account for that ambiguity. Sometimes the credentials are valid, the tools are approved, and each action looks normal. Behavioral context is what gives security teams a chance to see when those normal-looking pieces stop adding up.

++

Katie Paxton-Fear, Staff Security Advocate at Semgrep

There’s an awkward reality coming to light in the cybersecurity world: developers are being told to ship faster at the exact moment security teams need more scrutiny over what gets shipped. Most developers want to build securely, but they’re also under real pressure to get code out the door.

AI has poured gasoline on that tension. A developer can now generate a feature, integration or entire block of application logic before a traditional security review would have even started. The model may produce perfectly functional code. It may also choose an insecure function, misunderstand a trust boundary or introduce a vulnerability the developer doesn’t know to look for.

“Write this securely” isn’t enough context for an LLM. Security has to move closer to creation. Code should be checked while it’s being written. AI-generated changes should get the same scrutiny as human-written ones. Findings also need enough context to explain whether a weakness is genuinely exploitable instead of burying developers in another pile of warnings. The goal is to help developers move quickly without making security another obstacle to getting good code out the door.

AI isn’t removing developers from the security process. It’s making good developer guardrails more important. If software creation is going to accelerate, secure development can’t remain the part everyone waits on at the end.

++

Nick Tausek, Lead Security Automation Architect at Swimlane

The modern SOC doesn’t have an information problem. It has a decision problem.

Analysts already have alerts, threat intelligence, identity data and endpoint telemetry. The slowdown happens when someone has to figure out which signal deserves attention, what context is missing and what should happen next.

The AI SOC needs to earn its keep. Not every incident needs the same level of intelligence. Routine cases can move through deterministic automation. More ambiguous activity may need AI-assisted investigation. A smaller group of complex threats can justify fully agentic analysis. Human judgment stays focused on the decisions where experience matters most.

Cybersecurity Awareness Month is a useful reminder that faster detection alone isn’t enough. Security operations need a way to turn what they know into action without forcing analysts to manually rebuild context every time something goes wrong.

++

Piyush Sharrma, co-founder and CEO at Tuskira

Picture two vulnerabilities. One carries a critical severity score but sits on an isolated system with strong controls around it. The other looks far less dramatic. It happens to connect an exposed application to a privileged identity and then to production.
Which one gets fixed first?

For years, vulnerability management has made it too easy to answer that question with severity alone. Attackers aren’t working from a sorted CVE list. They’re looking for combinations of weaknesses that get them somewhere useful.

AI-assisted attack-path analysis can trace those combinations across identity, cloud, network and application environments. It can show which weaknesses are actually reachable. It can also identify whether an existing control cuts off the path before an attacker reaches something valuable.

Organizations don’t need more awareness of how many vulnerabilities they have. Most already know the number is uncomfortable. They need a better understanding of which ones can become a breach.

++

Kyle Wickert, Field CTO at AlgoSec

As agentic AI moves further into production environments, the security boundaries must evolve more rapidly than ever before. Network security can no longer focus simply on protecting locations or infrastructure. It must govern the connectivity between autonomous agents, applications, data, APIs, and services, ensuring every interaction is understood, authorized, and controlled. Organizations are increasingly turning to platforms supporting AI-enhanced monitoring and risk prioritization to mitigate these potential threats. In fact, 39% of organizations have shifted their focus to AI-powered visibility and risk prioritization. However, tools alone won’t solve the security challenge.

To utilize agentic AI effectively, organizations need to stop treating AI as software or tools and start treating it like a team member. Just as a security team wouldn’t hand a brand-new employee broad network access and admin privileges without oversight, autonomous agents cannot be given free rein over network infrastructure.

Enforcing strict access controls, applying fundamental least-privilege access controls, and automated zero-trust policies is essential. Beyond visibility, hybrid environments require automated asset discovery and continuous compliance monitoring to catch sandbox breaches quickly. To ensure effective control of agents, organizations need precise network microsegmentation and strong identity-based access to only allow agents to perform their specific duties without risk of lateral movement.

Security teams can’t manually review every network rule change an agentic platform requires. Automated policy change management overcomes this operational hurdle by instantly translating security intent into firewall and cloud security group rules, without creating human bottlenecks.

++

Poonacha Kongetira, Co-Founder and CEO, Classie

Cybersecurity Awareness Month is a good time for enterprises to ask a question that has become surprisingly difficult to answer: do we know what AI is running inside the business?

Shadow AI is no longer just an employee opening ChatGPT in another browser tab. AI is appearing across browsers, endpoints and SaaS applications, while agents are being connected to company data, business systems and credentials so they can do work on a user’s behalf. Some of that activity will have been formally approved and some of it will not, but from a security perspective the problem starts in the same place. If you cannot see it, you cannot understand what it can reach or what it is doing.

AI does not behave like traditional software that can be tested once and expected to keep doing the same thing. Its behavior changes with the user, the context, the data it encounters and the tools it can access. Cybersecurity teams therefore need to know more than which AI tools have been approved. They need comprehensive visibility into what users are doing with AI tools and connected enterprise information. This high bar is what is needed to keep the enterprise secure.

++

Sekhar Sarukkai, founder and CEO of ChatSee.ai

For decades, cybersecurity focused on the question: should this person or system be allowed to do this? AI agents have introduced a second question: even when they are authorized, are they doing the right thing?

An agent can have the correct identity, permissions, and data access and still apply the wrong policy, miss an escalation, misuse a tool, or pursue an objective in a way the business never intended. That creates what I think will become one of the defining challenges for CISOs in the agentic era: the risk is shifting from unauthorized access to unauthorized behavior. Logs can tell us what an agent did, but the harder problem is determining whether that behavior was correct in context, whether the organization has seen the type of failure before, and how to keep it from recurring.

A practical step for CISOs this Cybersecurity Awareness Month is to go beyond AI inventory. Analyze the actual behavior of sanctioned agents, co-pilots, pilots, and shadow AI already operating across the enterprise, and then build a failure-and-risk view from real interactions. Shadow AI, once a discovery problem, is quickly becoming a behavioral assurance problem.

++

Daniel Pataki, CTO of Kinsta

Website access tends to pile up. A developer finishes a project, an agency changes, or an employee leaves, but their account stays active. Months later, the business may have no clear picture of who can change its site. Review accounts with admin access, remove permissions that people no longer need and require multifactor authentication for those who do. I recommend starting there during Cybersecurity Awareness Month.

The most powerful action you can implement, though, is making the above standard operating procedure. Identify events that could cause an access change and address them as they arise. This ensures access is always up to date. If something goes wrong, knowing who had access and what they were able to change makes the investigation faster and much less of a guessing game.

++

Mike Toole, Director of IT and Security at Blumira

In today’s identity-driven threat landscape, the biggest exposure surface for lean IT teams and MSPs is the sprawl of non-human identities. As employees rapidly adopt AI and connect third-party integrations, they’re silently granting broad permissions across environments without IT’s knowledge. When organizations attempt to solve this with blanket restrictions, it almost always backfires by driving shadow AI deeper underground. The reality is that non-human identity management, machine authentication, and consistent integration monitoring are necessary front-door controls.

Cybersecurity Awareness Month is a reminder that in order to build real resilience without an enterprise budget, security leaders need to shift from static perimeter defense to scoped identity governance. This means using the native controls already built into your existing cloud platforms, auditing the full workflow and access bounds of any tool touching sensitive data, and maintaining the capability to cut ties instantly when an integration exhibits anomalous behavior. The goal is to establish strict, deliberate permissions so you know exactly what your non-human identities are authorized to do before something goes wrong.

++

Damon Fleury, Chief Product Officer at SpyCloud

Cybersecurity Awareness Month serves as a useful reminder that the identity attack surface no longer stops with employees. As AI adoption has skyrocketed, the attack surface now extends to AI agents, service accounts, API keys, and authentication tokens that have trusted access to enterprise systems. Attackers are already exploiting these new access paths – our research shows that exposed, compromised, or overprivileged non-human identities (NHIs) are now the leading route for initial access, nearly twice as likely to be the primary entry point as phishing or social engineering.

Additionally, SpyCloud’s 2026 Identity Threat Report found that 68% of organizations experienced an identity-based security event in the past year, and non-human identity (NHI) misuse or compromise was the most commonly reported event type at 42%. Many of these identities hold privileged access, operate continuously, and cannot be protected with the same controls we’ve built around employees. At the same time, vendors and partners bring their own identities and access paths into the enterprise, expanding the attack surface beyond what any organization directly controls.

For security leaders, this means that awareness must evolve into operational visibility and action. Organizations need a continuous view of the human, machine, and third-party identities with access to their environments: what they can reach, who owns that access, whether it is still necessary, and whether the credentials, tokens or sessions behind it have been exposed. From there, the priority is shortening the window in which attackers can use that access by revoking compromised sessions and tokens, rotating credentials, and reducing unnecessary privileges. That same discipline has to extend to vendors and partners, including verifying that exposed access has actually been remediated. As the identity ecosystem expands, cybersecurity resilience will increasingly depend on how quickly organizations can find vulnerable access paths and close them before attackers can use them.

++

John White, Field CISO at Torq

When autonomous AI models break out of sandboxes or breach third-party systems, treating it as a simple ‘misconfiguration’ misses the point. AI agents optimize for goals and will naturally take the quickest path to achieve it unless bounded by strict rules. In an identity-driven landscape where agents hold API tokens, an unbound tool is just an unmonitored non-human identity operating with full authority.

If Cybersecurity Awareness Month stands for anything in 2026, it should be establishing disciplined governance over autonomous tools. Think about it like onboarding a new analyst: you wouldn’t give them full keys to production. You start them on low-risk projects, watch how they handle ambiguity, and expand their access as they earn trust. Security leaders should do the same with AI. Humans will make the final judgment calls, while AI handles the heavy lifting at speed. Audit every decision and only broaden the agent’s scope as it repeatedly proves itself.

++

Michael Jenkins, Chief Technology Officer of ThreatLocker

Cybersecurity Awareness Month will bring plenty of attention to AI, but organizations shouldn’t lose sight of security fundamentals. AI can help attackers find and exploit weaknesses faster, but most successful attacks still take advantage of preventable security failures, such as known vulnerabilities left unpatched, unnecessary services exposed, default passwords left unchanged and access that’s broader than needed. Keeping these fundamentals in place remains the best defense against both traditional and AI-enabled attacks.

The same discipline should apply as organizations adopt AI agents. Prompts and built-in guardrails can guide an agent, but they can’t replace technical controls. Deny by default and least privilege are two independent controls organizations can apply to AI. Deny by default blocks unapproved tools and actions, while least privilege limits each agent’s access to what it needs for its intended work.

++

David Cottingham, president of rf IDEAS

After years in the access control industry, the pattern I see quite often isn’t a lack of investment. It’s a false sense of security. Organizations assume that because their systems are running and doors are opening, they’re protected. But working and secure aren’t the same thing. This Cybersecurity Awareness month, I’d encourage every security leader to ask a harder question than ‘is it working?’ Ask whether you actually understand your risk of exposure and where it’s costing you operationally and financially.

++

Maxim Bar Kogan, CEO and Co-Founder, Onyx Security

Cybersecurity Awareness Month has traditionally focused on what people can do to protect themselves and their organizations, but we’re entering a world where many of the actions that create risk won’t be taken by people at all. AI agents are gaining access to sensitive data, systems, and tools, and are continuing to take more and more actions across an organization.

Training employees to recognize phishing attempts or use stronger passwords still matters, but now organizations must account for agentic actors that can make decisions and take thousands of actions at machine speed. Organizations need to know which agents are operating across the business, what they have access to, and whether their actions align with the user’s intent and company policies.

That requires being able to continuously validate agent behavior and intervene before a harmful action is executed. We’ve spent decades building cybersecurity around human users. As agents take on more work across the enterprise, Cybersecurity Awareness Month is a good reminder that our approach to security has to evolve to account for the actions machines are taking, too.

++

Joel Burleson-Davis, CTO at Imprivata

As America marks 250 years, we find ourselves again undergoing another massive reshaping of our world and embroiled in a difficult fight. This time around, though, it is technology, namely AI, at the heart of the issue. Malicious actors, from financial opportunists to adversarial nation states, can and have been using AI to easily impersonate trusted users, create convincing attacks and compromise credentials into large scale campaigns. All the while, agentic AI systems are becoming digital identities themselves, as they take on more responsibility inside workflows, creating new challenges for us, and new opportunities for adversaries. For security leaders, the stakes for agentic AI look very different when those systems have real credentials, real permissions, and access to connected environments and critical assets. A mistake or compromise could move across systems and workflows at machine speed.

Building resilience for this next era starts with the fundamentals of identity security. Organizations need to know who or what is acting, understand what it should be allowed to do, continuously evaluate whether that access makes sense, and quickly contain activity that falls outside established boundaries. It’s a core requirement of any security program that wants to remain viable into the future, and it means bringing people, devices, third parties, and AI into one coherent identity strategy. The strongest identity strategies will make assurance and security part of the workflow itself, giving legitimate users and systems the frictionless access they need while making abnormal behavior harder to execute and easier to detect.

++

Mario Vuksan, CEO, Co-founder, ReversingLabs

NVIDIA’s launch of its Open Agent Safety Platform this month is an important signal for where AI security is headed. As agents take on more autonomous work across enterprise systems, security can’t live only inside the model or prompt. Organizations need enforceable boundaries around what agents can access and what actions they can take. That is exactly the kind of infrastructure-level thinking the industry needs. But there is another part of the attack surface that deserves the same attention: the software and other artifacts those agents actually interact with.

Agents download files, pull packages, install tools, and load models at machine speed. A boundary can determine whether an agent is allowed to act, but not whether the artifact it is acting on is safe. We saw the consequences with the TeamPCP campaign, which started with the compromise of the Trivy scanner and ended in March 2026 with backdoored LiteLLM packages on PyPI. LiteLLM is the proxy layer connecting AI applications to the models they call, so one poisoned release reached every team that pulled it.

Incidents such as SolarWinds, XZ Utils, and 3CX show why organizations cannot rely on source code or provenance alone. Provenance can tell you where software came from. It cannot tell you what that software actually contains or how it will behave. As AI agents scale across the enterprise, security will require both strong boundaries around what agents can do and deeper inspection of the artifacts they are trusted to use.

++

Daniel dos Santos, VP of Research, Forescout Research – Vedere Labs

During Cybersecurity Awareness Month, patching will rightly get attention. But AI is speeding up vulnerability discovery and exploitation, while organizations still need weeks or months to update every system. Even worse, some connected devices, such as industrial controllers and patient monitors, run software their suppliers no longer support. Others cannot be taken offline for an update without disrupting patient care or operations. This is the “patchability gap.”

Many devices are not just unpatchable, they are also exposed. Forescout Research – Vedere Labs identified more than 86,000 cellular routers exposed online; fewer than 10% were confirmed patched against previously known vulnerabilities while 90% were no longer supported by the vendor. In a separate analysis, only 13% of network segments containing operational technology (OT) devices held OT devices alone, while just 6% of segments containing connected medical devices held only medical devices. Mixed segments can give attackers a path from one compromised device to others, even if the critical device is not directly exposed online.

Organizations should prioritize patches by the likelihood of exploitation and the criticality of affected assets, while applying mitigating controls to those they cannot patch promptly. That starts with continuous visibility into connected IT, OT, IoT and medical devices. Separate critical operational and medical devices from general IT networks, reduce oversized segments and restrict unnecessary communication between them. Monitor device behavior for signs of compromise, and review segmentation as networks change to catch unintended connections.

++

Jackson Schultz, CEO & Co-Founder of ArgusEye

Cybersecurity teams have long relied on vulnerability severity to help them decide where to prioritize their attention. But as more software becomes embedded in systems and devices that interact daily with the physical world, technical severity alone doesn’t always reflect the full risk level. A vulnerability that appears critical on its own may pose limited real-world risk, while a less severe one could seriously disrupt operations, damage equipment or put people in harm’s way.

Securing cyber-physical systems requires organizations to understand more than individual vulnerabilities. They need visibility into how devices and software are connected, what an attacker could potentially access through those connections and what those systems ultimately control. Securing each component individually doesn’t necessarily mean the broader system is secure — particularly when connections between them can create hidden attack paths.

That also means the same vulnerability can have very different levels of risk depending on where it exists. For example, a flaw in two identical devices may carry the same level of technical severity, but if one sits at the edge of an isolated system and the other provides a path to shut down machinery on a factory floor or interfere with systems controlling a water treatment facility, treating them as equivalent misses a fundamental part of the risk.

None of this means that technical severity should be disregarded. Rather, it should be treated as a starting point for understanding risk, not the final answer. Organizations need to pair it with an understanding of how a vulnerability fits into the broader system, the pathways an attacker could exploit and the real-world consequences that could follow. This Cybersecurity Awareness Month, the goal shouldn’t simply be to find and fix more vulnerabilities — it’s understanding which ones actually have the power to do the most harm before that risk becomes a real-world consequence.

++

Ran Ben-David, CEO & Founder of Unibeam

Traditionally, the cybersecurity industry has spent a lot of time trying to teach people how to become better digital defenders when it comes to authentication. But as social engineering becomes increasingly sophisticated, there’s a limit to how much of our security strategies can depend on people consistently recognizing when they’re being manipulated.

As the industry has added more barriers to deter attackers, it has also inadvertently made human judgment a vital part of the authentication process – and attackers have learned to exploit that. We’ve effectively turned users into part of the security infrastructure, shifting some of the responsibility for preventing unauthorized access onto the very people authentication is supposed to protect.

In practice, this means we’ve made security awareness an unofficial part of the authentication process. A user may enter the right password, have the right device and complete every authentication step successfully, but the security of that process can still depend on whether they correctly recognize the circumstances surrounding the request. Unlike the technical factors we rely on to establish identity, human judgment can change with context, pressure and increasingly convincing manipulation.

Cybersecurity Awareness Month is an important reminder that teaching people to recognize phishing and social engineering still matters, but we shouldn’t measure good security by how well we’ve trained people to compensate for an authentication process that still depends too heavily on their judgment. The industry needs to evolve authentication design around stronger signals that establish identity without relying on users to recognize threats in the moment. Security awareness should reinforce authentication, not function as an unwritten requirement for making it secure. After all, users shouldn’t have to get every security decision right when an attacker ultimately only needs them to get one wrong.

++

Michael Nov, CEO and Co-founder, Prime Security

Cybersecurity Awareness Month was built for people. Train the employee and the employee stops clicking. That model is now obsolete, at least in Product Security. The majority of clicking is just not done by humans. Development output tracks tokens spent, not headcount. Even the engineers who criticize AI loudest run agentic coding tools all day. Those agents pick architectures and wire data flows before anyone has reviewed the design. You cannot send an agent to awareness training.

Most product security programs have not adjusted. The playbook still reads like 2011: scan the code, pentest the app, check the dependencies. Every step asks whether a line breaks a rule. None asks whether a path exists through the system, and that is the only question an attacker asks. Attackers have agents now too.

The fix is sitting inside every company, TODAY. Your organization already knows how the product was built, where the trust boundaries sit, which components touch real data. That knowledge has to reach the agent at the moment it writes code, and it has to drive the check afterward, which should prove exploitability across the whole system. So this October, skip the poster. Your security stack still assumes a person is in the loop. Your pipeline stopped assuming that a year ago.

++

Beth Miller, Global Field CISO at Mimecast

Heading into this year’s Cybersecurity Awareness Month, the biggest gap I see isn’t technical. It’s behavioral. Our research shows 8% of employees account for 80% of security incidents, and most of them aren’t malicious. They’re bringing habits from their personal lives straight into the enterprise, and the risk doesn’t just change when it crosses that line, it scales. Those habits now live in both worlds at once, which expands the attack surface and hands adversaries something new: enough visibility into someone’s actual life to tailor an attack to them personally. That’s a blind spot most organizations don’t know they have, and you can’t defend against something you can’t see. Security teams need to know what normal looks like for each person, notice when those patterns shift, and step in with a human conversation before it becomes an incident.

Agentic AI now demands that same discipline, because it’s the same blind spot in a new shape. Every agent is tied to a human, and the human is always accountable for what it does. We already know how to onboard, promote, and offboard employees. It’s time to apply that same lifecycle thinking to the agents working alongside them, so every agent has a named owner and nothing is operating in the dark.

++

Wade Woolwine, Senior Director of Product Security at Rapid7

The hardest part of a security analyst’s job has rarely been a lack of data. It’s the time spent stitching data together: jumping between consoles, writing one-off scripts, and copying results from one tool into the next. That’s where AI is earning its place.

That matters because the time between learning about a weakness and seeing it exploited keeps shrinking. In Q2, Rapid7 found that 62% of newly exploited vulnerabilities needed no login and no user interaction. With no employee involved, nobody gets the chance to catch those attacks. Security teams have to know what’s exposed and reachable before attackers do. When analysts spend hours gathering context, that awareness comes too late. For CISOs, the question isn’t whether every vulnerability becomes an exploit. Most won’t. The question is how much reachable, exploitable exposure they’re willing to carry.

This October and moving forward, organizations should direct AI at the stitching work. In exposure management, AI can drive APIs and CLI tools to pull asset, vulnerability and configuration context into one view, so teams fix what’s actually reachable instead of chasing every CVE. In detection and response, AI can query the SIEM, run threat intel lookups and parse logs, so analysts start from an evidence-backed summary instead of a blank search bar. It can also turn technical metrics into business language for the CFO or board. AI speeds up the analysis, but experts still own the verdict. Attackers have compressed the time it takes to strike, and defenders need to compress the exposure they leave open.

++

Antoine Carossio, CTO at Escape

Cybersecurity Awareness Month has always been about people falling for social engineering. In 2026, AI agents fall for it too. We recently pointed our AI pentester at a production AI assistant protected by a prompt-injection guardrail. The first attempt was blocked and logged, as designed. So the pentester read the refusal, reworded the request as a research question, and the assistant handed over its full system prompt and the list of tools it could call. No human wrote that second message. The issue was reported and fixed.

That’s what AI versus AI looks like: a guardrail gets one shot, and an attacker that reasons gets as many as it needs. The defense is to test your agents the way they’ll be attacked, continuously and with something that adapts when it’s blocked. And assume anything in a system prompt will eventually leak.

++

Andrew Eva, Chief Operations Officer, Assured Data Protection

Cybersecurity Awareness Month gives organizations an opportunity to reassess their security practices against a changing threat landscape. This year, AI needs to be part of that conversation. AI is moving beyond generating content and insights to taking actions across enterprise systems. AI agents can access data, interact with applications, modify configurations and execute workflows at speeds people simply cannot match. An agent operating with excessive permissions, acting on incorrect instructions or simply making a mistake can have consequences just as serious as a traditional security incident.

The past few months have shown how that can go wrong. In July, AI agents running in an OpenAI evaluation broke out of their test environment and compromised Hugging Face’s production infrastructure. In September, Google confirmed that Gemini had broken into three real companies during a security test in May, in one case simply by guessing passwords.

OpenAI recently apologized after a rogue AI agent hacked an Australian government website. These incidents began as AI testing and ended in real companies’ systems, and the lesson applies to any organization putting agents to work. Once agents can change production systems, their mistakes become a cyber resilience issue as much as a security issue. An agent doesn’t have to be malicious to cause damage. It can overwrite or delete critical data before anyone notices. Security teams are right to focus on governance: knowing where agents run, what they can reach and what they’re actually doing. The tools for that are improving quickly. Products for governing agents in real time are still maturing, and even the companies building them recommend keeping a way to walk back changes caught too late. Visibility won’t reverse a change an agent has already made, though.

Prevention will never be perfect, with or without AI, and cyber resilience has always meant planning for that, including how to recover. AI agents make recovery matter more, because an authorized agent can compromise data without tripping the controls built to stop attackers. Organizations need a trusted path back to a known-good state: protected backups, isolated clean-room environments where restored systems can be validated before they return to production, and tested recovery processes. A recovery plan nobody has run is little more than a hope. If leadership teams ask one question this October, it should be whether they could restore cleanly after an AI agent got something wrong, and how long it would take.

++

Thyaga Vasudevan, Executive Vice President, Product, Skyhigh Security

Cloud-First Cybersecurity is More Dated Than You Might Think

Amid the chaos of the early 2020s, the cybersecurity market did its best to align behind a consistent, capable strategy. The proliferation of remote workers, scattered devices, and near-empty office spaces made older castle-and-moat models insufficient. As work became more distributed, it’s no surprise that security did too. Security vendors began routing everything through the cloud, hosting its cybersecurity solutions in these decentralized environments to match the model of a widely dispersed workforce.

This cloud-first approach was a product of its time. It is no longer the most effective solution for the modern enterprise.

Today’s businesses look a lot different than they did a few years ago. Return to office mandates, hybrid workforces, and the increasing adoption of AI models and agents have created a much more complicated, nuanced model of work. A straightforward cloud-based security model is not going to cut it in these complex environments, especially with a high price tag. Neither will the outdated on-premises firewalls of the distant past. Cybersecurity success in 2026 and beyond depends on vendors’ capacity to apply data-first controls wherever work actually happens, supporting cost-efficient hybrid models that reflect the workers, platforms, and automated solutions being leveraged by the modern enterprise, not forcing them to conform to the cloud.

++

Hugh Thompson, Program Chairman at RSAC

Imagine telling an employee to “do whatever it takes” to close a deal. In a normal business context that person will naturally work within the boundaries of law, use common sense, adhere to company policies and apply basic workplace ethics. Now imagine giving that same prompt to an autonomous Al agent.

When organizations rush to integrate Al into daily work, a serious security threat stems from a potential massive disconnect in intent. Human interactions rely on implicit, unwritten rules and a set of context they’ve accumulated over their lives on morality, social norms, etc. When you task an Al agent with a goal, it operates without an ingrained moral compass, deep contextual awareness, or simple sense of right and wrong. Without a complete set of ethical rules and guardrails built into the system, an autonomous agent told to “do whatever it takes” to finish a job could act more like a mafia henchman than a professional team member, willing to cross legal lines, break policies, or act unethically just to reach its goal. The intent of the employee may not be aligned with the boundaries that the agent will operate within.

Cybersecurity has long wrestled with ethical boundaries around powerful technical tools, but in the past, running complex offensive operations required specialized skills that naturally limited who could wield these tools. Easy-to-use autonomous agents that might have significant offensive capabilities scales these risks. Someone may put an agent in motion that unintentionally runs aggressive tasks or inappropriately scans external systems. To prevent unintended security incidents and legal fallout, companies must validate the guardrails that Al systems have in place and educate employees on how Al agents actually work. You want to make sure the agent performs like an ethical employee and not a mafia enforcer.

++

Kevin Greene, Chief Cybersecurity Technologist – Public Sector, BeyondTrust

Cybersecurity Awareness Month is a reminder that threats move faster than the tools we have to contain them. AI compressed the gap between vulnerability disclosure and exploitation. Months became days, and in some instances hours. And the same flaw sitting in a water treatment plant is sitting in a school district server and a county office.

Technical debt is not an IT problem. It is access. It is the leverage threat actors use to get inside our infrastructure and critical systems. Unsupported devices are the easiest way in. End-of-support doesn’t mean broken. It means no more security patches to close attack vectors. Automated scanning finds a forgotten router or camera long before anyone thinks to replace it.

Volt Typhoon is a great example. The FBI dismantled a botnet built from end-of-life routers that Chinese state actors used to preposition inside U.S. water, energy, and transportation networks. Preparation has to go beyond patching. Recovery isn’t restoring files. It’s sustaining operations. Whether the water keeps running. Whether the school opens Monday. Whether the county makes payroll.

Resiliency is decided before the attack, not after – by how the systems were built, not by how fast anyone responds. And the harder question is who holds the keys, the leverage in our systems. Work and home now share the same networks and the same passwords. AI agents are acting on our behalf in ways most people have never examined.

It is important to retire what is no longer supported. Build for continuity. Know what has access to what is awareness. When we patch it protects our devices, but knowing who holds the keys protects the mission capabilities.

++

Chris Radkowski, Security and Risk Expert at Pathlock

Cybersecurity Awareness Month is an important reminder that security can no longer focus only on preventing employees from clicking malicious links. With AI adoption accelerating, awareness of how AI agents are used is becoming essential. AI has enormous potential to improve productivity through automation, and whenever a technology helps people work faster and more easily, they will find ways to use it. The challenge for organizations is not to prevent AI adoption, but to ensure it takes place within established security and governance frameworks rather than outside them.

Yet many organizations lack visibility into their AI environments. According to the 2026 Pathlock AI Governance Gap Report, more than half of organizations (51%) are not confident they know about all the AI agents operating within their systems, while 31% are unsure whether AI-related incidents have occurred at all. With visibility this limited, the true scale of AI-driven irregularities is likely greater than formal reporting suggests.

Organizations should educate employees about the safe and responsible use of AI, but awareness alone is not enough. Clear policies must be supported by the right governance and security technology. Organizations need continuous visibility into which human and non-human identities have access, what actions they perform, and whether those actions are appropriate within their business context.

++

Jason Soroko, Senior Fellow, Sectigo

Quantum readiness isn’t a switch you flip overnight. It’s a continuous, uneven migration across every system an organization owns. The first step is understanding where cryptography exists across the environment, but inventory alone isn’t enough. Organizations also need context to understand which cryptographic assets support critical systems, where the greatest risks lie, and what should be prioritized first. With that visibility and understanding, they can take a risk-based approach to planning and build the crypto agility needed to adapt as cryptographic standards evolve. Quantum readiness isn’t about fixing everything at once. It’s about making informed decisions and steadily reducing risk over time.

++

Nick Heddy – President and Chief Commerce Officer at Pax8

Cybersecurity is entering a new era. For the last two decades, security has largely been about protecting networks, devices, and identities. In the years ahead, it will increasingly be about protecting autonomous systems, AI agents, and the growing web of digital interactions they create on our behalf. As organizations embrace AI to drive productivity and innovation, attackers will use the same technologies to scale threats faster than ever before. The result is an arms race where speed, automation, and intelligence become the defining advantages.

The future of cybersecurity is not simply more tools or more alerts. It is a shift from reactive defense to proactive resilience. Businesses will need systems that can continuously monitor, learn, predict, and respond in real time. Human expertise will remain essential, but the most effective organizations will pair human judgment with machine-scale intelligence. Security will become less about detecting breaches after they occur and more about preventing them before they impact operations.

For small and midsize businesses, this evolution presents both a challenge and an opportunity. Historically, advanced cybersecurity capabilities were often reserved for large enterprises with dedicated security teams. Today, AI and managed services are democratizing access to sophisticated protection, allowing organizations of every size to benefit from enterprise-grade security outcomes. The goal is not to eliminate risk, because that is impossible. The goal is to create resilient businesses that can adapt, recover, and continue serving customers in an increasingly digital world.

As we look toward the next generation of technology, one thing is clear: cybersecurity is no longer a technology issue alone. It is a business imperative, a trust imperative, and ultimately a human imperative. The organizations that thrive in the future will be those that view security not as a barrier to innovation, but as the foundation that makes innovation possible.

++

Ram Varadarajan, CEO at Acalvio

Cybersecurity Awareness Month tends to focus on the moment of compromise – the phishing email, the weak password, the unpatched system. But less attention is given to what happens after an attacker is already inside, which is where the real damage is done.

Reconnaissance is a search for confidence. A configuration file may point to a database, a directory query turns up a server that looks worth examining, and gradually an attacker pieces together a route toward systems that matter. From even a limited foothold, an attacker can assemble a working map of the environment: which systems appear connected, where credentials might work, and which path seems worth testing next. AI is changing the pace of that work. It can help an attacker interpret query results, select another system to probe, and continue with less human direction, shortening the time between each discovery and the next action. Anthropic’s 2026 analysis of accounts banned for malicious cyber activity documented exactly this, including a campaign in which an AI agent conducted reconnaissance and internal discovery on its own, choosing what to probe next.

A directory query or connection attempt may give the SOC little reason to escalate on its own, even when its result tells the intruder where to look next. Deception gives defenders a way to influence that next decision by shaping what the intruder encounters: a credential artifact placed where an attacker searching an endpoint would plausibly find it, appearing to lead to a server that fits the organization’s naming conventions, when both are false. An attempt to use that credential produces an alert tied to the account, endpoint, and action, giving the security team a specific lead to investigate before the attacker moves further. An attacker may find a way to gain access but deception makes sure they can’t trust what they find once they’re in.

++

Jeremiah Clark, Chief Technology Officer at Fenix24

Cybersecurity Awareness Month has spent two decades telling people to lock the door. Still good advice. But nearly every organization that ends up calling an incident response firm had locks. Prevention is a probability game, and eventually the dice come up wrong. The question that matters now is simple: when it happens, how long until the business is running again? And can anyone answer that with a number instead of a hope?

Prevention vs Recovery
Keeping attackers out is table stakes, not the finish line. The real measure is time to recovery by business function. Can orders ship? Can payroll run? Can patients get admitted? Most organizations can report patch compliance to two decimal places and still can’t say what comes back first after an attack.

The Gap
Recovery plans get written against the environment someone remembers, not the one that actually exists. Undocumented dependencies. A backup server joined to the domain it’s supposed to protect. Restore times nobody ever tested end to end. The first 48 hours of a real incident get burned answering basic questions: what do we have, what’s hit, what depends on what. A green backup job isn’t assurance. A completed restore and a working login is.

One ask this October: pick the three systems the business can’t live without and actually restore them. End to end. Timed. Whatever breaks is the real plan.

++

Dom Glavach, CISO at Black Duck

AI has made software development faster and speed without independent verification can scale risk just as quickly. Organizations should use AI to expand security reasoning and identify complex issues, while relying on repeatable testing to confirm results and provide evidence that risk has been materially reduced.

The most defensible approach combines AI-driven and deterministic testing so that each method challenges the assumptions of the other. AI contributes contextual reasoning, adaptability, and the ability to explore complex paths. Deterministic methods such as static analysis, software composition analysis, and runtime testing provide consistent coverage, reproducible results, and measurable assurance.

This matters most when AI creates and reviews the same software. The two systems can share the same blind spot. Independent testing methods provide the perspective diversity necessary to close these gaps.

++

Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer, AvePoint

Recent warnings about AI safety from Anthropic and other hyperscalers have raised awareness of how quickly AI is moving. AI capabilities are developing faster than many organizations’ ability to govern them, and that gap is creating real risk. AvePoint’s own research has found that 88% of organizations experienced an agent-related security incident in the past year. As many still work to implement AI governance fundamentals, the technology continues to take off in new directions that are starting to sound alarm bells at the highest levels.

Nvidia’s launch this week of a runtime safety platform for AI agents, following the OpenAI agent breach of Hugging Face, shows where enterprise controls now need to go. Security teams need to treat every agent as a non-human identity with an owner, scoped credentials, explicit tool permissions, network egress limits, and policy enforcement outside the model. Organizations also need tested controls to revoke tokens, quarantine an agent, terminate queued actions, and restore affected data and configurations to a known-good state.

AI is outpacing AI governance, and it’s even outpacing our ability to anticipate and regulate its actions. In this environment, we all have a duty to do more.

++

Kern Smith, VP of Global Solutions Engineering at Zimperium

Cybersecurity Awareness Month is still too often framed around whether an employee knows not to click a suspicious email. That advice matters, but it does not reflect where many attacks now happen. Employees use their phones to respond to messages, access work applications and approve requests throughout the day, while AI is helping attackers make phishing attempts more convincing and easier to scale.

Zimperium’s 2026 Global Mobile Threat Report found that phishing events detected on employee mobile devices grew 380% since January 2025. The lesson for organizations is to look beyond awareness training alone. Employees need clear ways to verify and report suspicious requests, and security teams need the ability to detect threats on the mobile devices and apps where those requests are received.

++

Agnidipta Sarkar, Chief Evangelist at ColorTokens

Cybersecurity Awareness Month 2026 comes with a long-term challenge. CISA’s theme, “Securing the Next 250,” asks how we secure the digital systems and critical infrastructure the next era will depend on. For boards, that goes beyond awareness to whether the enterprise is built to withstand an attack. AI now finds weaknesses, writes the exploit, and moves through a network faster than most security teams can open a ticket. In that world, “are we secure?” is a comforting question with no useful answer. The better question for every boardroom is simpler and harder: when, not if, we are breached, how much of our business will keep running?

Most boards have never decided how much damage is too much. I call it the Maximum Acceptable Material Impact, or MAMI, which is the worst disruption the enterprise can absorb and remain viable, defined in money, days of downtime, regulatory exposure, and lost customers. Boards should also ask for the smallest set of capabilities, processes, and assets that must stay unaffected during an attack, designed so a breach in one place cannot spread to the next. I call that the Minimum Viable Digital Enterprise, or MVDE. Traditional resilience plans protect and restore the critical 15-20% of systems first, yet most CFOs and CEOs do not want to accept more than a 10% loss in revenue. That leaves the enterprise staring at at least a 70% gap, with a recovery plan stapled on top. Resilience is not how fast you rebuild; it is how little you have to.

++

Diana Kelley, CISO at Noma Security

We need to stop thinking about AI agents as if they were people. They are software systems: models combined with code, permissions, tools, data, and network access. Anthropomorphizing agents can distract us with questions about what the AI “wanted” to do. The more useful questions are architectural: What can this software reach? What can it change? What constrains it? And what happens when it is wrong? AI creates new failure modes, but the answer still starts with strong security architecture: least privilege, segmentation, monitoring, deterministic control points, and containment.
Rather than fearing what AI “wants,” we need to govern what we enable it to do.

++

Chad Thunberg, CISO, Yubico

Cybersecurity Awareness Month is supposed to bring cybersecurity into the spotlight, but this year with the advancements of AI, cybersecurity seemed to be at the forefront of everyone’s mind. These advancements have made it far too easy to undermine our trust in social media, voice, and even video calls. We’re in a moment where the attacker clearly has an asymmetric advantage and our defenses need to evolve in order to keep up.

When weaponized, AI can assist an attacker in their attempts to trick or coerce an individual into taking action like sharing credentials, installing malware, or transferring money to name a few. As an industry, we need to continue to bring solutions to bear that don’t rely on an individual to determine authenticity and prevent themselves from accidents. Passkeys are an example of how cryptographic systems can be used to not only mitigate social engineering but bring simplicity to previously complex multifactor authentication (MFA) schemes.

On the longer term horizon, quantum computing is driving strategic conversations regarding how to prepare and more appropriately, prioritize post quantum readiness given the myriad of other concerns that we all are juggling. Migrating algorithms that are used to protect sensitive information, especially when transmitted over the internet, ensuring we have repeatable build and deploy pipelines, and tracking platform adoption are near term activities that support our long term plan.

++

Joseph Slowik, Director Threat Research & Cyber Engineering, Dataminr

Vulnerability data from the past year makes one thing clear during this Cybersecurity Awareness Month: relying on patching as your primary defense is no longer viable. Organizations must leverage all available means to minimize their attack surface, maintain visibility over high-risk entry points, and plan for restoration and recovery for when a breach inevitably occurs.

Throughout this process, organizations must take advantage of all information sources at their disposal. This includes a combination of in-depth analysis of the threat environment alongside real-time indications and warnings of emerging activity, ensuring organizations understand when the threat environment shifts in critical ways. Grounding cybersecurity in these core security fundamentals and resilience allows organizations to move away from a ‘whack-a-mole’ approach to vulnerability management and embrace a proactive strategy capable of responding to entire categories of adversary actions.

++

Damien Lewke, Founder and CEO, Nebulock

Most security programs rely on alerts to signal that something is wrong. The problem is that today’s attackers rarely trip the alarm. They log in with valid credentials, use AI agents to move quietly, and avoid the signatures traditional tools are tuned to catch. Meanwhile, overloaded SOCs can’t sift through noisy alerts. By the time they can triage an alert with weak signals, the damage might already be done.

The better approach is to proactively hunt with context in your environment. That means knowing what normal human and AI agent activity looks like, so suspicious behavior doesn’t go undetected. By focusing on the behaviors you are able to surface through hunts and findings, more durable detections can get created and coverage keeps getting stronger instead of going stale as threats evolve.

Waiting for an alert lets the attacker set the pace. The organizations that stay ahead start looking before an alert ever fires, and a hunt-first approach allows teams of any scale to keep up with human and agentic threats.

++

Martin Musierowicz, President, SecureW2

We’ve spent decades teaching people not to click suspicious links. Now we need to teach our infrastructure not to blindly trust identities even if they have a valid credential. Gartner projects that by 2028, 15% of day-to-day work decisions will be made by agentic AI, up from 0% in 2024. AI agents, automated workloads, APIs, and connected devices are increasingly accessing sensitive resources with minimal human input. The identity question has changed from “Who is logging in?” to “What is this machine or agent, and should it still be trusted right now?”

PKI can give every user, device, workload and AI agent a cryptographically verifiable identity. But a credential is only as trustworthy as the last time someone checked it, so checking has to be continuous. When a device’s risk changes, its certificate renewal should pause and its identity should be revoked automatically where possible, without waiting for someone to review a ticket. AI agents should get short-lived identities that expire in hours, not months, so a stolen credential stops being useful quickly. And because quantum computing will eventually break the cryptography behind today’s credentials, teams should be able to adopt NIST’s post-quantum standards without rebuilding the PKI their business runs on. That’s the approach we’ve built at SecureW2.

Cybersecurity awareness shouldn’t be limited to teaching people how to recognize threats. It should also mean building systems that can recognize when trust has changed and can respond before a compromised identity becomes a compromised system.

++

Conal Gallagher, CISO and CIO at Flexera

AI is moving faster than most organizations’ ability to understand its risks, and security teams are being asked to keep pace with the technology landscape. The question is no longer whether AI will move quickly, but whether organizations can establish the visibility and guardrails needed to keep pace responsibly. Instead, security leaders must be more deliberate about what gets introduced, closely assessing whether the organization has the visibility and governance to understand the risk it creates.

As autonomous agents continue to access more data and potentially create or interact with other agents, organizations must think differently about security and accountability in 2027. Cybersecurity leaders and CISOs should be asking not only, “what can this technology do?,” but “what is it connected to, what decisions can it make, do we have the controls to manage it, and ultimately, should we retire it?” The pace of AI innovation isn’t going to slow down, which makes disciplined adoption more important than ever.

++

Raymond Daoud, Senior Vice President and Chief Security Officer, CGI

According to CGI’s 2026 global research, cybersecurity resilience and data protection now rank as the top IT priority globally for executives. Cybersecurity Awareness Month is an opportunity to revisit the fundamentals of cyber resilience, including how we prepare people to recognize and respond to threats. As AI becomes more embedded in enterprise operations, those fundamentals also need to evolve.

AI agents introduce a new dimension. They access enterprise systems, make decisions, and execute tasks with limited human involvement, creating new considerations for identity and access programs that were largely designed around human users. At the same time, AI is changing the broader threat landscape, giving threat actors new ways to automate elements of reconnaissance, identify vulnerabilities and increase the speed and scale of their activities, including targeting the very AI models and agents organizations use.

Organizations need clear answers to four practical questions: Do we have visibility on AI agents? Are there boundaries on what they can do? Are we able to detect and intervene if something goes wrong? Who is accountable for the outcome?

Security teams have long applied these zero-trust principles to users, devices and networks. As AI agents become more integrated into enterprise operations, these same principles should extend to AI-driven processes, with appropriate identity verification, policy enforcement and traceability.

Heading into 2027, effective security programs will increasingly be defined by an organization’s ability to sustain operations, respond effectively and recover quickly as autonomous systems become more embedded in the enterprise. Building AI governance, robust operating models and adaptability into security practices will be essential to maintaining the trust of clients and partners while enabling organizations to take advantage of AI with confidence.

++

Erez Tadmor, Global Field CTO, Tufin

Cybersecurity has entered a new phase. AI is accelerating everything — how organizations build applications, how infrastructure changes and, increasingly, how attackers discover and exploit weaknesses. The challenge for security teams is that our defenses have largely been designed around human-speed processes: a change request comes in, someone reviews it, a policy is approved and the environment is checked afterward. But an AI agent can make a change in seconds, and an attacker using AI can discover an exposed path or map potential attack routes at machine speed. We cannot expect security teams to protect a machine-speed environment with human-speed processes.

That makes the network more important than ever. Every application, AI agent, workload and user ultimately depends on connectivity, and the network is often the path an attacker uses to move from an initial foothold to something more valuable. Security teams need to know not just what assets they have, but what can actually communicate with what, where those paths lead and whether that connectivity still matches security intent. And that understanding cannot be a point-in-time assessment. In an environment that is changing continuously, security posture has to be continuously validated as well.

Cybersecurity Awareness Month is a good reminder that security is not something we can address only after an incident occurs. In the agentic era, resilience has to be built into the environment before something goes wrong. That means establishing the right boundaries, continuously validating them, and giving security teams the visibility and automation they need to respond at the same speed as the environment they are protecting. Organizations need to do more than react faster when an attack happens; they need to make sure an attacker has fewer paths to exploit in the first place.

++

Karl Holmqvist, Co-Founder and CEO of Lastwall

Cybersecurity Awareness Month is a reminder that the stakes are getting higher on both sides of the security landscape. Technology is giving defenders more powerful tools, but it is also giving attackers more leverage. The cost of getting it wrong is rising: according to Sophos, the average cost to recover from a ransomware attack reached $1.7 million in 2026, excluding the ransom itself – an increase of about 11% year over year.

At the same time, we are entering a more agentic world, where increasingly digital and interconnected systems underpin everything from energy and communications to transportation and supply chains.

In that environment, identity becomes more important, not less. Strong identity is a rising tide for the broader security stack because, at its core, cybersecurity comes back to trust: who or what is requesting access, what authority do they have, and what are they allowed to do?

Agentic systems make that question even more urgent. As AI agents begin acting autonomously on behalf of people and organizations, authenticating the human alone will no longer be enough. We also need to authenticate the agent, understand the authority delegated to it, and define the boundaries it is expected to operate within.

Quantum adds another layer of urgency. “Store now, decrypt later” means sensitive data being collected today can remain a security liability years into the future. That makes post-quantum preparation a current security issue, not a distant one.

For governments, the opportunity is to build resilience from first principles: modernize identity, begin the transition to post-quantum cryptography, and continue investing in sovereign capabilities that strengthen both national security and the domestic technology ecosystem.

##