As October 2025 unfolds, National Cybersecurity Awareness Month takes on unprecedented urgency. Twenty-two years since its inception, this annual initiative arrives at a pivotal moment when artificial intelligence is reshaping both cyber offense and defense, while traditional security perimeters continue to dissolve.
The cybersecurity landscape has evolved dramatically over the past year. AI-powered attacks are becoming more sophisticated, supply chain vulnerabilities are multiplying, and the hybrid workforce has permanently altered how we think about network boundaries. Meanwhile, cybercriminals are leveraging everything from deepfakes to quantum-resistant encryption bypass techniques, making 2025 a year of both remarkable innovation and escalating risk.
But with challenge comes opportunity. Organizations that embrace proactive security strategies—from zero trust architectures to AI-enhanced threat detection—are not just surviving but thriving in this complex environment.
This year’s expert roundup brings together seasoned cybersecurity professionals, technology leaders, and industry executives who are navigating these challenges firsthand. Their insights reveal practical strategies for building resilient security postures, fostering security-aware cultures, and staying ahead of emerging threats.
The conversation starts here, but the responsibility to act belongs to all of us.
++
Jim McGann, CMO at Index Engines
The use of AI has turbocharged the evolution of ransomware, enabling cybercriminals to craft more sophisticated and targeted attacks that result in unprecedented levels of organizational disruption and downtime. The barrier to carrying out coordinated, high-impact cyber extortion has never been lower, and enterprises must prepare for adversaries that can rapidly adapt and automate every step of an attack.
++
Drew Bongiovanni, Technical Product Marketing Manager, Index Engines
AI has become a double-edged sword in cybersecurity. Attackers are using it to automate reconnaissance, uncover weaknesses, and modify attacks so they’re tailor-made for a victim’s environment. They’re even applying AI to elevate basic tactics like phishing and social engineering, making entry points smarter and harder to defend.
On the other side, AI is also being used by organizations to strengthen defenses, detect advanced attack methods and, if hit, recover quickly and confidently. Cybersecurity Awareness Month is a reminder to take a hard look at your environment and ensure your posture and technology are built for this new era and able to keep pace with how quickly attacks are evolving.
++
Darren Guccione, CEO & Co-Founder, Keeper Security
Cybersecurity is national security. Since 2004, Cybersecurity Awareness Month has served as a reminder that protecting our nation’s digital infrastructure is inseparable from protecting our physical infrastructure. Nation-state adversaries and organized cybercriminals are launching more frequent and more sophisticated attacks than ever before, making agencies like the Cybersecurity and Infrastructure Security Agency (CISA) vital to our collective defense.
The majority of U.S. digital infrastructure is owned and operated by the private sector, placing businesses directly on the front lines of this battle. Public-private collaboration is no longer optional – it is essential. By sharing real-time threat intelligence, advancing zero-trust security models and implementing modern Privileged Access Management (PAM) solutions, organizations can support our government agencies in strengthening our digital borders and protecting the systems that power our society.
A unified approach – with government and private industry working side by side – is the only way to stay ahead of today’s adversaries and tomorrow’s unknown threats. By embracing this collaboration and prioritization of cybersecurity as a national security imperative, we can build a more resilient future for all.
++
Dr. Adam Everspaugh, Cryptography Advisor, Keeper Security
Quantum computers won’t just change technology – they will upend the digital world, and the current forms of security that protect it. Once mature, quantum computing will have the power to shatter the encryption that safeguards personal data, financial transactions, healthcare systems, cloud platforms, government operations and critical infrastructure. The immediate risk comes from a strategy called “harvest now, decrypt later,” better described as a “time-capsule attack.” Right now, cybercriminals are capturing encrypted traffic as it traverses the internet and stashing it away with the intent of unlocking it years later when quantum machines are commonplace. Any organization with sensitive information of long-term value – such as financial, health or intellectual property records – is at risk of this attack.
Cybersecurity Awareness Month poses a prime opportunity to spotlight this immediate and serious concern. All of today’s widely used public-key algorithms can be cracked using Shor’s algorithm when run on a sufficiently capable quantum computer. This includes RSA and the elliptic curve cryptographic algorithms. Symmetric cryptographic schemes like the Advanced Encryption Standard (AES) and the Secure Hash Algorithm (SHA-2 and SHA-3 family) are still secure, as are the new breed of lattice and hash-based quantum resistant cryptographic algorithms recently standardized by the US National Institute of Standards and Technology (NIST).
The timeline for realizing these quantum computers capable of breaking public-key cryptography is uncertain. Conservative estimates place it decades away, but technological progress is non-linear and notoriously difficult to predict. The recent standardization by NIST of quantum-resistant cryptographic algorithms, including Kyber, Dilithium, and Sphincs, underscores the importance to organizations of planning their transition now.
Governments are also starting to take note. Regulators are urging enterprises and public-sector bodies to inventory cryptographic systems, prepare for migration and adopt “crypto-agility” strategies. The likes of Apple, Google and Cloudflare have already begun piloting hybrid deployments for a quantum-resistant cryptography, combining classical and quantum-resistant algorithms to get the best of both worlds in the near term.
Security leaders must act decisively. There are several practical steps to prepare for quantum disruption. Start by identifying and classifying high-value, long-term sensitive data, evaluate vendor quantum-resistance and start transitioning to hybrid cryptography. This Cybersecurity Awareness Month is an opportunity to take action, as tomorrow’s resilience is built on today’s response.
++
Anthony Cusimano, a tech developer, cybersecurity thought leader and solutions director at Object First
Ransomware attacks are no longer just about disrupting operations—they’re increasingly targeting backups. In fact, 96% of attacks hit backup data, yet securing backups is often overlooked in cybersecurity strategies. Simply having backups isn’t enough anymore; organizations must adopt storage that ensures Absolute Immutability to prevent tampering, encryption, or deletion, ensuring recovery is always possible. The rise of AI-generated data makes immutability even more critical. AI produces massive volumes of essential data, yet 65% of organizations back up less than half of it, leaving it vulnerable to cybercriminals.
This Cybersecurity Awareness Month, organizations must treat data protection as a core cybersecurity responsibility. Disaster recovery plans should minimize downtime, safeguard critical assets, and align backup strategies with Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs). Regular testing, monitoring, and threat simulations ensure readiness for ransomware, insider threats, and emerging cyberattacks. Investing in modern, immutable storage and comprehensive recovery plans strengthens organizational resilience, reduces cyber risk, and ensures critical data remains secure. Protecting data is no longer optional, it’s a strategic cybersecurity imperative.
++
Lori MacVittie, Distinguished Engineer & Chief Evangelist at F5
AI has entered the chat. Literally. While most are aware of prompt injection emerging as a new class of security risk, they are less aware that traditional defenses are not designed to catch them. Oh, we’ve got AI security services and AI gateways now that search for prompt injection, but these are often just the application of traditional techniques that rely on rules and regex to catch malicious content.
Increasingly, prompt injection attacks hide malicious instructions inside ordinary-looking content like documents, emails, chat messages, and LinkedIn bios. When an AI system processes that content, it can be tricked into following those hidden instructions that reveal sensitive data, bypass controls, or generate inappropriate output. It’s the same principle as social engineering but targeted at machines instead of people.
Prompt injection isn’t about code; it’s about language and meaning. Attackers can rephrase malicious instructions endlessly, slipping past pattern-based filters. That’s why we need to treat this as the next evolution of threat detection: semantic scanning. Instead of asking “does this match a known pattern,” semantic scanners ask “is this text trying to manipulate the system prompt or override its instructions?” Detecting hidden instructions before they reach the model is the only way to stop prompt injection at the source and to keep AI from becoming an unguarded back door into sensitive systems.
++
Aimei Wei, CTO and Founder, StellarCyber
The State of Cybersecurity Today
Cybersecurity is at an inflection point. Attackers are faster, more automated, and increasingly creative, while defenders are often weighed down by siloed tools, alert fatigue, and talent shortages. At the same time, organizations are moving to hybrid and cloud-first environments, expanding the attack surface. AI has already entered both sides of the fight — adversaries use it to craft convincing phishing lures, automate attacks, and probe defenses, while security teams deploy AI to correlate data, detect anomalies, and accelerate response. The current state is a tense balance: the tools are stronger than ever, but so are the threats.
How GenAI Is Changing the Game
Generative AI is already reshaping the security landscape. For attackers, GenAI lowers the barrier to entry, making it easier to launch sophisticated social engineering campaigns, polymorphic malware, and adaptive exploits. For defenders, the same technology enables faster investigations, automated case summaries, and intelligent triage that removes hours of manual effort. We are beginning to see a shift from reactive, alert-driven security toward proactive, AI-assisted operations where SOC teams can focus on strategy instead of sifting through noise. In this early stage, the key challenge is trust: ensuring AI outputs are accurate, explainable, and integrated into the human decision-making loop.
The Next Five Years
Looking ahead, GenAI will become fundamental to cybersecurity. Expect agentic AI systems that don’t just summarize but actively investigate, recommend, and even orchestrate responses across multi-vendor environments. Security operations will evolve from fragmented toolchains into unified, AI-augmented platforms that enable small teams to deliver enterprise-grade protection. At the same time, regulation and compliance will mature around AI usage, creating standards for transparency, auditability, and accountability. By 2030, cyber defense will be defined by human-AI collaboration: people setting strategy and judgment, AI executing at machine speed. For defenders, the mission is clear — embrace AI to stay ahead, or risk falling behind attackers who already have.
++
Karl Holmqvist, Founder and CEO at Lastwall
“Secure Our World” lands differently this year. Allied security agencies have dropped the euphemisms. Adversarial state actors are pre-positioning in critical infrastructure and on the edge gear we forget to watch. The job this year should be about moving the few levers that bend risk fastest under real-world constraints.
As we vector into 2026, try to start where the adversary does. Require routers, VPNs, and firewalls to produce forensically capable logs and prove you can pull them.
Harden identity, especially where friction pays. Make phishing-resistant MFA mandatory for admins and all critical systems. Shorten token lifetimes and bind sessions to devices. Where you need to, allow exceptions, but log and expire them quickly.
Build or maintain a live cryptography register, make sure you plan your cutovers to NIST’s post-quantum cryptography (FIPS 203/204/205), and have plans to practice rollouts so you know how various networks and systems react.
To borrow a phrase, measure what matters. Build and then improve change-latency metrics. Awareness is the start, but readiness is proof.
Organizations that practice identity integrity, edge evidence, and cryptographic agility will have an easier time navigating 2026. For most, there is a lot to change. For many, it won’t be easy to do all these things, which is why it is important to start taking the action you can now. Don’t wait until it’s too late.
++
Jeremy Fong, VP of Product at OPSWAT
As the 22nd annual Cybersecurity Awareness Month urges us to “Secure Our World,” the speed at which data moves is as important as the integrity with which it is managed. File transfers remain one of the most common—and most vulnerable—points of exposure. In the AI era, where adversaries weaponize automation to embed malicious content or bypass traditional defenses, organizations cannot afford to treat this as routine infrastructure.
Managed File Transfer (MFT) should be seen not as legacy technology but as a strategic control. Its value lies in verifiable security: encryption, access policies, and auditable trails that demonstrate accountability. These capabilities are increasingly non-negotiable, as regulators from the SEC to the EU’s DORA demand provable safeguards.
To “Secure Our World” year-round, leaders should take three actions:
1. Elevate secure file transfer to the boardroom—it is a trust and resilience issue, not just an IT concern.
2. Mandate consistent controls across cloud, hybrid, and on-prem environments.
3. Continuously test and adapt processes to anticipate AI-driven threats.
Securing how data moves is securing how business operates. In an era defined by speed, complexity, and growing cyber risk, MFT is not optional but foundational to long-term resilience and trust—exactly the kind of proactive measure Cybersecurity Awareness Month urges every organization to adopt.
++
Kyle Wickert, Field CTO, AlgoSec
With 60% of organizations now managing at least 250 business applications across hybrid multi-cloud environments, relying on traditional firewall policy-based network security is no longer effective. Building security around networks and infrastructure creates blind spots, inconsistent policies, and a higher risk of misconfigurations and downtime. These challenges only intensify as more applications are deployed and existing applications require updates. Applications are the backbone of modern business, and security strategies need to be aligned accordingly.
To address this, security teams must shift to strategies that start from the application outward rather than the network inward, beginning with mapping and identifying their existing business applications and connectivity flows. Application-centric security enables teams to identify and prioritize risks in real time, reducing the likelihood of breaches and downtime while expediting remediation and streamlining delivery and updates often slowed in traditional security. This approach not only protects applications, but also accelerates their rollout and improvements over time.
At the same time, there is a growing trend of convergence between cloud and network security teams, a shift that requires a unified approach to risk management. Application-centric security makes this possible with consistent visibility and policy enforcement across environments, teams and tools. The result is greater clarity and control, empowering organizations to manage security holistically while staying aligned with modern business needs.
++
David Cottingham, President of rf IDEAS
Technology migrations are complex, but with 83% of organizations having faced at least one account takeover attack in the past year, it’s crucial to reassess outdated credentials and authentication methods. All it takes is one compromised access point — physical or digital — for bad actors to infiltrate company systems. These breaches can cost an average of $4.8 million and cause business operations to slow down or halt completely.
This Cybersecurity Awareness Month is a reminder that the best way to combat these risks is through phased migrations to more secure technologies like smart cards, mobile credentials or passkeys. Encrypted credentials provide a path for companies to future-proof their physical and logical access systems while also promoting a more user-friendly experience. The future of access control lies in technologies that combine security, convenience, and interoperability, empowering businesses to stay ahead of evolving cyber risks.
++
Prakash Mana, CEO of Cloudbrink
As we head into Cybersecurity Awareness Month it’s imperative we highlight the latest trends and its impact on cybersecurity. AI is the next big hurdle for security teams, especially on the software development side. Companies need to make sure that users don’t use AI to create hacking bots either on purpose or accidentally. They also need AI access controls so that AI can only access the services it should. Otherwise you leave yourself open to bad actors who could force agents to access bad sources. Visibility into AI activity is key to safe use.
Agentic AI adoption is increasing at breathtaking speed due to the huge efficiency improvements, but it also throws challenges like shadow AI, AI access controls and of course AI-targeted security attacks like zero-day threats, etc. For both Agentic AI developers, vendors and AI consumers (enterprises using AI agents), it is imperative to give visibility into shadow AI, protect their networks and infrastructure, and do all these without compromising performance of the AI Agents.
Most AI agent developers are focused on efficiency, not security. The first step for security teams is to create visibility. Establish a way to monitor AI to see what it’s accessing, which users are using it, and what they’re using it for. If you don’t have an AI policy already, you need to create one now.
++
Arun Shrestha, CEO of BeyondID, an MISP recently acquired by KeyData Cyber
Identity is now the economy of cybercrime. Protecting it isn’t just an IT task — it’s a business imperative for resilience, trust, and compliance. Cybercrime today is less about breaking in and more about logging in. Stolen credentials including usernames, passwords, tokens, and access rights are the number-one entry point into breaches, with 92% of organizations reporting identity-related attacks in the past year. These “digital keys” are traded on underground markets like commodities, granting attackers access to critical systems and fueling billions in losses across every industry.
The weak spots aren’t exotic zero-days but everyday cracks: inactive accounts without MFA, poorly managed service credentials, or misconfigured single sign-on. Non-human identities like APIs, bots, even AI agents add new risk, often overlooked in governance programs.
AI raises the stakes on both sides, helping attackers craft convincing phishing campaigns and automate credential stuffing, while enabling defenders to spot anomalies, enforce least privilege, and clean up dormant accounts at scale. The organizations that win will treat identity as a board-level priority, pairing AI-driven detection with disciplined governance: mapping every identity, enforcing just-in-time access, adopting phishing-resistant MFA, and continuously authenticating users.
++
Brent Johnson, CISO, Bluefin
Cybersecurity Awareness Month is a reminder to look at the evolving risks in the space and how rapidly tactics are advancing. Two threats that have stood out are quantum computing and the rapid adoption of AI embedded in security defenses. Quantum may still be years away, but there is real concern about how it could be used against legacy encryption, with state-sponsored actors suspected of exfiltrating data now to decrypt later, creating active risks for sectors like healthcare, higher education and finance.
At the same time, AI is being embedded in security operations, often without the same level of scrutiny applied to other tools. This will create significant gaps in how sensitive data is handled and fuel a tendency to trust their outputs blindly. Both trends show that risks are evolving faster than defenses, and it’s best to prepare early before the gap grows wider.
++
Bill Bruno, CEO of Celebrus
For too long, digital identity and fraud prevention have been managed in silos. Marketing teams have treated identity as an after-the-fact exercise, often piecing together disparate data sets to guess who a person is across channels while fraud detection has focused on catching threats only after authentication. In today’s environment, that divide is a liability.
AI-driven operators are now capable of mimicking legitimate customer behavior, which means brands can no longer wait until login to decide whether an interaction is trustworthy. The moment someone lands on an app or website, organizations need to know: is this a real customer, or is it a malicious bot trained to act like one?
The solution requires bridging marketing and fraud data to build a persistent, accurate view of every interaction in real time. Brands that collapse this divide won’t just protect themselves against new forms of cybercrime; they’ll also strengthen customer trust and deliver safer, more seamless digital experiences. Security and customer experience can’t be treated as separate priorities; they are two sides of the same coin.
++
Dr. Phil Tee, Head of AI Innovations at Zscaler
Across the industry, we are seeing an over reliance on AI-generated code. Without rigorous review, that is becoming a key driver of architectural flaws and privilege escalation risks. Teams are assuming AI-generated code is inherently reliable, which it is not. Organizations must enforce strict guardrails, such as limiting the size of code changes, to ensure quality and security. This disciplined approach prevents AI-generated code from bypassing critical checks, reducing the likelihood of introducing systemic vulnerabilities.
At Zscaler, we’re helping organizations navigate these concerns by advancing AI-driven innovations that address the complex challenges of today’s digital age. As we recognize Cybersecurity Awareness Month, we’re reminded of the importance of proactive defense and responsible innovation. By fostering a culture of security awareness and empowering employees with the right tools, organizations can better protect themselves against evolving threats. With industry-first capabilities like AI-driven threat detection and automated segmentation, we’re enabling teams not only to adopt and scale AI responsibly and securely, but also to innovate with confidence, supported by a workforce that is informed, vigilant, and resilient.
++
Tom Findling, co-founder and CEO of Conifers.ai
Cybersecurity Awareness Month is a reminder that security is a collective responsibility. For many years, the focus has been on end-user habits like strong passwords and phishing awareness. Those remain important, but another challenge occurs within the security operations center (SOC). Security teams are buried in signals from identity, endpoint, and cloud systems, and the sheer volume can overwhelm even the best teams.
Adversaries can adapt rapidly, combining different attack methods and using stolen legitimate accounts that blend in with normal activity. Defenders need technology that can match that speed and complexity. Agentic AI technology provides a solution, automatically taking the initial investigative steps, connecting signals across systems, adding context to the story, and retaining those details that are often lost to give them a clearer starting point.
Cybersecurity Awareness Month spotlights resilience. Individual awareness helps, but the greater impact comes from how organizations support their teams. When teams combine human expertise with agentic AI technology, they build operations that can sustain modern threats. This shift helps to take awareness from a campaign that lasts a month to something that’s incorporated into how organizations operate every day.
++
Hüseyin Can Yüceel, security research lead, Picus Security
One of the biggest risks organizations face is a false sense of security. Too often, there’s an assumption that because tools are deployed, defenses will hold. However, like many other tools, security tools need updates and maintenance to perform against thousands of threats. Always remember, incidents don’t just happen to other people. Every organization is a target, and attackers thrive on overlooked weaknesses.
Cybersecurity Awareness Month is a time to push back on that way of thinking. Organizations need to test their ability to respond to real threats rather than assume they’re protected. Doing that exercise will help them identify threats before attackers can, and it will give them the confidence that they can count on their teams and technology to perform when it matters most.
++
Douglas McKee, Executive Director of Threat Research at SonicWall
Misconfigurations and authentication bypasses remain the easiest way in for attackers. Default passwords never changed, admin panels exposed on the internet, patches that lingered too long, identity systems cobbled together rather than properly built. Around 90% of the misconfigurations I encounter fall into three buckets. Directory access exposure, authentication failures, and data accidentally left in the open. Most organizations have the right tools and people but lack the operational consistency to make security stick.
The numbers from early 2025 tell a story. Nearly 70% of organizations faced at least one authentication bypass attempt. These weren’t random bot scans but targeted campaigns by attackers who knew exactly what they were hunting for.
These problems don’t require the latest expensive solution. The fundamentals still work.
- Start with identity. Single sign on and multi factor authentication block most credential abuse. Consolidate around a unified identity provider, use role-based access controls to prevent privilege creep, and monitor login patterns for anomalies.
- Build security into applications from day one. Input validation, server-side access checks, and proper session management hold the line. At the network edge, web application firewalls remain essential for blocking injection attempts, providing virtual patches, and catching suspicious behavior.
- Treat configuration management as an ongoing discipline, not a one-time task. Automate baseline enforcement, catch unauthorized changes in real time, and make audits routine.
- Be realistic about capacity. Breaches often happen not because technology is missing, but because no one has time or expertise to manage it properly. Self-managed environments demand constant attention, skilled teams, and documented procedures. If that’s beyond reach, co-managed or fully managed services can bridge the gap.
Attackers aren’t smashing through locked doors. They’re walking through the ones we forgot about. That’s where we need to focus first.
++
Sam Peters, CPO, IO (formerly ISMS.online)
A recent report revealed businesses spent 73% more on information security during the last year, and yet nearly half admitted to lacking a clear, integrated framework to make those investments effective. Organizations frequently acquire security tools to address specific vulnerabilities without evaluating their compatibility with existing tools and systems. This approach to information security yields duplicate solutions and rising expenses, while cyber teams face ongoing challenges in handling risks as a unified system.
Brands can achieve better results when they view technology as a single component within their overall information security strategy. Linking security tools to established governance structures such as ISO 27001 can create unified discipline across departments, ensuring defined roles, scheduled risk assessments, and executive accountability. Those that move beyond piecemeal investments to embed security as an organization-wide practice will see their tools perform better, budgets go further, and awareness translates into lasting resilience.
++
Tamara Nolan, Managing Director, Cyber and Operational Resilience, MorganFranklin Cyber
My specialty is helping organizations continue critical business functions and services if faced with an adverse event, such as a data breach, natural disaster, insider trading, civil unrest, etc. – any event that disrupts key technology, third parties, or locations/facilities. Our team works with every level of the organization (executive, operational, technology, site/facility) to manage negative financial, reputational, operational, and regulatory impacts caused by an adverse event. We do this through crisis management, business continuity, disaster recovery, cyber resilience, and emergency response planning/capability building. Cyber and Operational Resilience is a lot about ensuring those with responsibilities during an adverse event are trained on their roles. Security awareness is critical because people are often the first line of defense for a cybersecurity or other adverse event.
++
Ellen Boehm, SVP, IoT & AI Identity Innovation at Keyfactor
This Cybersecurity Awareness Month, enterprises face a growing risk that wasn’t on the radar just a year ago: rogue AI agents. With agentic AI now moving into production, autonomous systems are capable of making decisions, transacting, and executing tasks without human oversight. Without strong identity and trust controls, these agents can quickly become shadow AI, acting outside policy, spoofing identities, or initiating fraud at machine speed.
The challenge is clear. Most organizations can’t yet answer the fundamental question: Is this AI agent authentic? Legacy authentication methods like API keys and static tokens are easily compromised and offer no cryptographic proof of identity. If not addressed, this gap opens the door to breaches, data loss, and trust breakdowns, far faster than human-led security teams can respond.
To counter this, digital trust must be embedded at the identity layer. Certificate-based machine identity management allows organizations to verify every agent, enforce policies, and revoke trust instantly if compromise occurs. This approach ensures visibility, accountability, and control over AI behavior in real time.
As agentic AI becomes part of the enterprise, securing it isn’t optional, it’s foundational. This Cybersecurity Awareness Month is a reminder that new threats demand new trust models.
++
Jared Atkinson, Chief Technology Officer, SpecterOps
As we mark Cybersecurity Awareness Month and urge everyone to ‘Stay Safe Online,’ it’s critical to focus on protecting identities in transit – not just those stored at rest. Too often overlooked, these moving identities remain a prime target for attackers.
Identities don’t simply sit in directories or vaults. They move, authenticate, and persist in active sessions. Users generate browser cookies, Kerberos tickets, and other temporary credentials that travel across environments. An identity in transit represents realized access – already authenticated and ready to be exploited.
For adversaries, these active identities can be even more valuable than static credentials. Passwords may be hashed, vaulted, or protected by MFA – but there’s no need to crack a password if an attacker can hijack a live session.
++
Kavitha Mariappan, Chief Transformation Officer, Rubrik
As AI drives the next wave of digital transformation, Cyber Awareness Month reminds us that cyber resilience—not just visibility—is key to securing our digital future. AI is forcing leaders to transform their infrastructure and applications, and adopt more cloud, which makes cyber resilience the number one priority for cyber security.
AI also is increasing identity and credential-based attacks – now the most prevalent type of cyber attack. Rather than hacking into systems, attackers are now simply logging in, leveraging unauthorized access to credentials. Enterprises need to focus on Identity Resilience, which is designed to secure the entire identity landscape alongside data and protect the most common entry points for attackers – human and non-human identities (NHIs).
++
Julie Davila, VP of Product Security, GitLab
A survey we recently conducted found that many organizations are adopting AI without prioritizing AI governance. While agentic AI can benefit development teams, security must evolve simultaneously.
Cybersecurity Awareness Month is a great reminder to reevaluate how your organization is prepared to adapt as the AI landscape inevitably shifts. Specifically, I’d recommend implementing SLSA-aligned controls for AI components to track provenance of models and training data, establish build integrity for AI pipelines, and verify AI agent behaviors before production deployment. Create “paved roads” for AI adoption with pre-approved models, secure integration patterns, and the same security controls applied to AI-generated code as human-written code, just earlier in the workflow.
When you focus on building clear, fast paths for safe AI adoption, you’ll find that security becomes an enabler of software innovation, rather than a blocker.
++
Paul Walker, field strategist, Omada
When we think about identity in cybersecurity, we instinctively think of people. But that picture has shifted dramatically. In most organizations today, non-human identities — service accounts, APIs, bots, workloads, and increasingly AI agents — outnumber human identities by a huge margin. Research shows the ratio is roughly 82 to one. That’s not just a matter of scale; it’s a structural change in how identity works.
One of the biggest accelerators is the rise of Agentic AI. These autonomous or semi-autonomous agents carry out decisions and actions on behalf of a user or an organization, and need their own identities to authenticate, authorize and interact across systems and data. Each one is effectively a new kind of actor in your digital ecosystem, and it has to be governed accordingly.
But non-human identities don’t behave like human ones. They’re created at high speed, live across hybrid and multicloud environments, and often connect directly into sensitive systems. They don’t follow typical joiner–mover–leaver processes. They’re dynamic and woven into orchestration, pipelines, and business decisions. Traditional IAM simply wasn’t built for this complexity and unpredictability. That gap creates blind spots and an expanded attack surface. And with regulations like DORA and NIS2 demanding accountability for all identities, not just human ones, the urgency is clear.
Cybersecurity Awareness Month is a reminder: identity governance must now extend beyond people. Securing the vast, fast-moving ecosystem of non-human identities, especially AI-driven ones, is becoming central to resilience and trust.
++
Shachar Menashe, VP, Security Research at JFrog
Open source continues to be a huge driver of today’s digital infrastructure and software innovation, but the Shai-Hulud attack was another reminder of the fragility of the software supply chain. Attackers are increasingly targeting under-resourced open-source maintainers, as seen with the xz-backdoor attack on XZ Utils.
The speed of compromise is alarming: once a trusted package is breached, it spreads rapidly through CI/CD pipelines. A zero-trust approach is vital—popularity alone shouldn’t dictate trust. Implementing two-factor authentication is essential, though enforcement varies across repositories. For example, npm and PyPI already utilize two-factor authentication, but other repositories such as Maven and NuGet do not.
Governance frameworks like ISO 27001 encourage discipline, but because it is a guideline vs. a regulation, companies don’t need to comply. Therefore, they aren’t enough to guarantee open-source risk is addressed effectively, as enforcement is uneven and security controls may be poorly implemented.
To strengthen defenses, organizations must curate packages with strict vetting criteria and analyze all dependencies. Our research shows delaying upgrades for at least 14 days allows time to identify and remove hijacked packages.
The key takeaway from the Shai-Hulud incident is that cautious adoption is vital for supply chain resilience. Upgrading to the latest version of a package immediately as it comes out is an unnecessary risk, which is usually caused by convenience and lack of governance. Either by automated or manual means – organizations and users should always employ a delay before upgrading to the latest version, especially with popular packages, which have recently become high-value targets for even novice attackers.
++
Cary Vidal, VP of IT & Security, Exclaimer
Cybersecurity Awareness Month is a timely reminder that organizations must remain vigilant about all aspects of their digital footprint. Email signatures are often overlooked, yet can introduce unnecessary risks when they’re unmanaged. Unsecured or inconsistent signatures can be exploited, whether through unauthorized changes, inaccuracies, or failure to meet regulatory standards.
Rather than viewing them as a branding tool, organizations should see email signatures as being both a professional touchpoint and part of their broader security posture. Centralized management of signatures means they remain consistent, accurate, and tamper-proof, reducing the risk of human error and misuse.
For companies undergoing wholesale change, such as through mergers and acquisitions, this becomes even more important, as unmanaged signatures can expose the business to compliance gaps, reputational damage, or legal liabilities. By using a secure, centralized email signature management platform, organizations can maintain control, safeguard stakeholder trust, and strengthen their security posture without leaving this detail to chance.
++
Craig Birch, Technology Evangelist & Principal Security Engineer at Cayosoft
As we observe National Cybersecurity Awareness Month this October, organizations must confront a sobering reality: 88% of cyber-attacks involve Active Directory, yet identity security remains dangerously overlooked. Active Directory’s 25-year legacy has created a perfect storm of vulnerabilities through misconfigurations, shadow admin permissions, and toxic attack path combinations that provide attackers with multiple entry points. The recent evolution of ransomware from simple encryption to sophisticated cyber extortion demonstrates that threat actors have shifted their focus to the identity layer, where a single user’s LinkedIn post can initiate a chain reaction leading to complete domain compromise.
Traditional perimeter defenses are insufficient in our cloud-first, remote work reality. When Active Directory fails, business operations come to a halt, making comprehensive identity protection strategies essential. Organizations need continuous monitoring, secure delegation, and clean, reliable, and instant recovery capabilities that can eliminate standing privileges and provide rapid, validated recovery. Standard backup solutions often restore the very persistence mechanisms attackers embed, making this October a critical time to move beyond awareness to action.
++
Elizabeth Nammour, CEO and Co-Founder of Teleskope
This October marks the 22nd annual ‘Cybersecurity Awareness Month’. As we think about the cybersecurity space, we must think about the rapid acceleration of AI adoption and the massive amounts of sensitive information increasingly ingested and exposed in unexpected ways.
IDC projects global data volume will reach 181 zettabytes by 2025, meaning this rapid data sprawl is now one of the most urgent challenges in cybersecurity. Organizations now store petabytes of data across hundreds of fragmented systems, with limited visibility into what exists, where it resides, who can access it, or how it’s being used. Furthermore, many of the data security tools designed to solve this problem stop at visibility without offering any context or solution behind the countless threats these security teams, who are often stretched-thin, face each day.
Cybersecurity Awareness Month is a good reminder of the community’s responsibility to making solutions that are equipped to not only solve the problems of today, but tomorrow as well. This means going beyond basic visibility and ineffective security alerts and focusing on giving security teams what they need — accurate discovery, immediate enforcement, and scalable automated remediation, so enterprises can not only see their risks but resolve them at scale.
++
Barry Mainz, CEO, Forescout
Cybersecurity Awareness Month has in many ways become commercialized, but its core purpose remains vital: helping people outside our industry understand how deeply cybersecurity impacts our lives and our national security. When a hospital is hit with ransomware, patient care is delayed. If a water treatment facility is compromised, an entire community could lose access to clean water. Should a dam or power grid be hacked, lives could quite literally be lost. Cybersecurity has to move from a twice-a-year phishing test for employees to a well-known, well-taught public safety issue.
And if today’s threats feel overwhelming, the risks posed by quantum computing are exponentially greater. Quantum promises breakthrough innovation, but it also threatens the foundation of digital security. The encryption that protects our financial systems, healthcare records, and national defense could be broken in minutes. Preparing now is critical—not only by accelerating the transition to post-quantum cryptography, but also by ensuring that everyday people understand the risks and push the organizations they trust to take quantum seriously.
Here’s what that means in practice:
- People: Recognize that cybersecurity protects your data, your healthcare, your finances, your family, and your community.
- Leaders and influencers: Use your platform to educate and advocate—making cybersecurity and quantum readiness part of the broader national and economic security conversation.
- Cyber leaders and professionals: Leverage your expertise to educate others on the urgency of preparing before it’s too late, and drive your organizations to adopt quantum-safe encryption.
If cybersecurity isn’t everyone’s conversation, we cannot succeed.
++
Grayson Milbourne, Security Intelligence Director, OpenText Cybersecurity
To get the upper hand, organizations need to invest in security layers that communicate together rather than adding additional point solutions. Being able to triage threat intelligence and events between security layers improves visibility. This in turn results in more meaningful alerts, faster response times and more effective defenses.
Four ways defenders can reduce risk and improve resilience:
- Start with identity: As AI becomes more integrated, identity has become new perimeter. Securing who has access to what is essential to every defense strategy. Agentic identities are expected to outnumber humans 100 to 1 in the coming years making identity and access management a critical foundation layer for cyber resilience.
- Integrate security tools: Being able to triage information between security layers helps security teams see threats earlier and act faster. Prioritize new solutions based on their ability to integrate with other layers within your cybersecurity solution stack.
- Build a culture of security awareness: Training should go beyond checklists. When people understand how their actions impact risk, they become part of the defense, not just a liability.
- Use AI: Security teams face more alerts than they can handle. AI can filter through the noise helping security teams leverage limited resources efficiently.
++
Bojan Simic, CEO of HYPR
October is Cybersecurity Awareness Month, and it’s time we talk about one of the biggest failures in enterprise security: the IT help desk.
If your help desk relies on security questions, SMS codes, or employee IDs, you’re not just failing to defend your enterprise—you’re actively handing attackers the keys. Social engineers are expertly exploiting the pressure and urgency of help desk operations, and they are succeeding because too many organizations continue to stake their security on methods that were compromised a decade ago.
The help desk shouldn’t be the weakest link; it should be the first line of defense. That means moving beyond guesswork and adopting identity verification that confirms who someone is, versus what they know or the device they’re using. With phishing-resistant, standards-based verification built into support workflows, agents stop being human lie detectors and start being defenders.
Cybersecurity Awareness Month is about raising the bar. If we continue to treat the help desk as a cost center instead of a security control, attackers will keep walking through the front door. The companies that win are the ones that stop gambling with outdated methods and start demanding certainty at every point of access, and beyond the initial request.
++
Mike Walters, President and Co-founder of Action1
Cybersecurity Awareness Month reminds us that awareness alone is not enough—organizations need action to stay protected. With today’s surge in exploited vulnerabilities, even a temporary expansion of automated patching capacity can make a lasting difference by helping IT teams catch up on older, yet still highly exploitable weaknesses. To support this effort, Action1 is doubling endpoint coverage for all customers and free-tier users throughout October, giving them the opportunity to eliminate long-standing security gaps at no additional cost.
++
Jimmy Mesta, Co-founder and CTO of RAD Security
Cybersecurity Awareness Week tends to focus on consumer safety, and that’s important, but it’s only part of the story. Behind every phishing warning or software update prompt, there’s a security team under pressure to make those defenses work at scale. That’s where awareness breaks down: not at the user level, but in the complexity of the systems that support them.
The truth is, many security teams already know what needs fixing. The problem is bandwidth. They’re overwhelmed with alerts, stuck reconciling disconnected tools, and buried under compliance work that’s growing faster than their teams are.
I believe that awareness has to include that layer too: the people behind the platform, not just the people using it. That means helping defenders focus on what matters, eliminate wasted motion, and translate technical insight into business action—before it ends up as a headline.
++
Anthony Woodward, CEO of RecordPoint
Data governance is the core of both cybersecurity and AI governance. The same foundation that secures data also makes AI trustworthy and governed.
Your risk, cost, and AI outcomes are all results of how you manage data. Good data management — clear inventory, classification, lineage, least-privilege access, and defensible retention — shrinks your attack surface for security and supplies trustworthy, traceable inputs for AI. One foundation, two domains, three outcomes: lower risk, lower cost, and higher trust.
Organizations today face two intertwined challenges: protecting data from threats and using it responsibly in AI. Both cybersecurity and AI governance succeed or fail based on the same principle: disciplined data management. Cybersecurity is only as strong as the data practices behind it. This applies equally to AI governance.
++
Sandy Kronenberg, CEO and Founder, Netarx
Social engineering has always been a bad actor’s most reliable weapon. Now AI has supercharged it. Phishing emails, smishing texts, vishing calls, and deepfakes are no longer isolated; they are now blended into coordinated attacks that overwhelm employees and exploit trust across multiple channels.
We’ve seen a 900% increase in deepfake-related cybercrime in the past year. At the same time, phishing remains the primary entry point for the majority of breaches, and voice-clone scams are growing at a rate of 66% year-over-year. Attackers stitch these together: a phishing email primes an employee to expect a call, the call comes from a voice-cloned “executive,” and a smishing text with a malicious link reinforces it. This choreography leaves little room for doubt, unless the proper defenses are in place.
Traditional tools aren’t designed for this. Malware scanners won’t detect a video puppeteering your CFO. Secure email gateways can’t flag a convincing message that passes authentication checks. Awareness training, while valuable, can’t prepare someone for a synthetic voice that sounds exactly like their boss giving urgent instructions. The gap is at the human layer of trust.
Cybersecurity Awareness Month is the time to move beyond awareness alone. Leaders need to close that gap with real-time, AI-powered validation that cuts across email, messaging, voice, and video. Fraud losses tied to deepfakes are projected to exceed $25 billion annually by 2026. The cost of waiting is far higher than the cost of acting now.
++
Dr. Srinivas Mukkamala,CEO, Securin
As artificial intelligence continues to accelerate bad actors’ skills, organizations are finding themselves outpaced by this growing threat. Adversaries are now using AI to identify weaknesses, automate phishing campaigns and chain exploits at a scale that manual operations never allowed. Defenders cannot afford to respond with yesterday’s playbook. As I have said before, you must fight AI with AI; you must fight machine speed with operational speed.
Traditional security models often fixate on individual flaws. AI changes that equation by amplifying what I call “toxic combinations;” linked CVEs, CWEs and misconfigurations that may seem minor in isolation but, when combined, form critical points of failure. Addressing these requires secure-by-design engineering, systematic AI red teaming to uncover hidden vulnerabilities, and clear labeling frameworks that give organizations visibility into how AI systems function.
Cybersecurity Awareness Month is not just about awareness. It is a reminder that resilience comes from adaptation, and that adaptation must keep pace with the AI-driven threats shaping today’s digital landscape.
++
Mike Anderson, VP, Partnerships, Abstract Security
I’ve always reminded myself that relationships formed in trust are a cornerstone of cybersecurity awareness. Technology infused with AI can replicate workflows, but it will struggle to replace the discipline & strength people build in each other. That kind of power emerges when organizations invest in their people, creating cultures that amplify protection in ways security tools alone can’t fully mirror.
++
TK Keanini, CTO, at DNSFilter
In today’s rapidly evolving digital landscape, attackers are targeting both humans and technology. With AI now deeply integrated into daily workflows, security must become a collective responsibility. It’s no longer just about protecting software and hardware; it’s about securing the very decision-making processes of people and machines. As we adopt AI tools in every aspect of business, we must build a culture where security is everyone’s job. However, this new focus on AI-driven threats gives us no license to ignore the fundamentals of cybersecurity. This cultural shift must be built upon a mastery of basic security hygiene, from secrets management to protective DNS to broader end user awareness. Zero Trust principles are crucial here, ensuring that even if a breach occurs, it remains small and contained. By empowering individuals and enforcing these principles, we can significantly reduce our attack surface and mitigate the risks posed by increasingly sophisticated adversaries.
++
Roland Palmer, VP of Security & Compliance at Sumo Logic
The most important thing we can all do is to make sure we’re doing the basics of cybersecurity consistently. If everyone performs the small things in the correct way and sustains that effort across 12 months every single year, that’s a very solid baseline for safeguarding everything from identity to data. Use training and awareness as a culture builder. It sounds small, but it’s the most impactful work that you can do, especially as people are increasingly bringing their own AI tooling. We need to keep empowering people to make the best choices they can for security, day after day.
If I have one piece of advice for October’s cybersecurity awareness month, I’d say to pick something this month that you can implement. Do one extra thing this month to improve your security posture and stick with it for the rest of the year. See how that improves your security a year from now!
++
Jim Doggett, CISO of Semperis
For too long, the industry has operated under a false sense of security, believing that if we just buy enough tools, we can prevent every attack. That mindset is fundamentally flawed and, frankly, dangerous.
This is especially true when it comes to preventing and recovering from ransomware attacks. Within the past 12 months, nearly 80% of organizations have been targeted by ransomware, with 40% of attacks involving a physical threat of some kind. The stakes have never been higher.
Cybersecurity leaders, particularly CISOs, must operate under the assumption that ransomware attacks are not a matter of if but when. To prepare, they need a proactive disaster recovery plan centered on clear communication to keep the business running smoothly during an attack. Ransomware can shut down critical operations across the organization, everything from WiFi and phones to Active Directory. A solid communication plan ensures CISOs and their teams can minimize costly downtime.
This Cybersecurity Awareness Month, let’s commit to shifting our focus. Let’s stop selling cybersecurity as an avoidance tool and start championing it as a business enabler built on the foundation of resilience.
++
Ginny Spicer, Threat Analyst, Netcraft
It’s a difficult pill to swallow; convenience beats security, and attackers exploit it. Shadow IT, vibe coding, and the proliferation of “smart” devices are typically added to save time, which creates an opportunity for threat actors. When someone chooses speed over rigor, the path of least resistance becomes the potential path of compromise.
For business owners, this is more than an IT issue; it’s a reputation and trust issue. The key is to build a process where the secure option is the convenient option; easier said than done, right? But there are tactics that satisfy both: normalizing multi-factor authentication, using password managers, integrating patching and monitoring as a standard part of operations, and training that promotes positive behavior.
Brand protection is another critical part of addressing this challenge. Many scams don’t require breaching a corporate perimeter. Instead, adversaries impersonate trusted brands to directly cheat their users out of money. Fraudulent websites, fake social media accounts, and phishing campaigns take the scam directly to the consumer and exploit the trust brands have built. This is why automated and effective takedown of those threats is essential to prevent adversaries in your space from inflicting real damage on your customers and your brand.
++
Corian (Cory) Kennedy, Chief Threat Intelligence Officer at SecurityScorecard
‘Is my organization hacked right now?’
How confident is your answer? Cybersecurity Awareness Month is a call to action for every organization to validate their cyber defenses, to make time to understand the confidence in their answer to that question. Threats are very good at evolving quickly, working tirelessly to catch you off guard. Awareness is an important phase of a larger process to pivot from reacting to successful threats to defensive action.
Many factors drive cyber risk, one blind spot stands out: your pipeline of vendors, suppliers, and partners. Each of these introduces a unique risk, but many organizations still lack a clear view into where those vulnerabilities exist and what their risk appetite truly is. By seeing their own security posture and the risk levels of connected vendors, businesses can prioritize fixes, reduce exposure, and drive accountability across the supply chain.
This month is a chance for every business to commit to taking meaningful action. Start by prioritizing the real-time insight into their cyber posture, including third-party risk. This clarity allows for faster decisions, stronger defenses, and measurable progress. Once you can see the risk, you can reduce it.
++
Matt Richards, CMO, Aqua Security
Cybersecurity Awareness Month is a reminder that security must never be an afterthought. This is especially true as organizations accelerate their adoption of AI. Moving fast fuels innovation and differentiation, but when security lags, the business is exposed to significant risk. While building a comprehensive AI security strategy takes time, the path forward is clear: start with the foundation, secure your infrastructure, and expand protections over time. Incremental steps reduce exposure without slowing down innovation.
Generative AI and large language models (LLMs) are predominantly deployed in containers due to their portability, scalability, and efficiency. Containers have become the backbone of the AI revolution, but that reliance introduces new risks. AI models process sensitive data, evolve rapidly, and require constant updates. Adversaries are already targeting these dynamics with attacks such as model poisoning, prompt injection, and data exfiltration. Without proper safeguards, container environments become a primary avenue for exploitation.
If AI runs in containers, then AI security must begin with container security. This requires a full-lifecycle approach, including scanning code and infrastructure for unsafe model use, validating container images before deployment, enforcing least-privileged access, and continuously protecting workloads at runtime. Runtime protection is especially critical. Aqua Nautilus research shows that nearly half of cloud-native attacks are engineered to remain hidden until execution, making runtime detection and defense essential. For AI workloads, late detection doesn’t just compromise an application; it undermines the integrity of the model itself.
By treating container security as the cornerstone of AI protection, organizations gain the visibility and control needed to innovate with confidence. With Aqua’s full-lifecycle platform, enterprises can secure AI workloads from code to cloud to prompt, reducing business risk while enabling safe adoption of transformative technologies. The organizations that embed security into their AI strategies will be the ones to scale innovation responsibly, preserving trust, compliance, and competitive advantage.
++
Miguel Sian, Senior Vice President of Technology, Merlin
The U.S. government is a prime target of cybercriminals and nation state actors. Shoring up cyber defenses is critically important to prevent incidents and mitigate the impact of cyberattacks. At the same time, many budgets remain flat, leaving Federal IT and security leaders with a nearly impossible task: modernize technology environments to improve cybersecurity and future-proof their agencies without new funds.
The U.S. Department of Homeland Security declared October “Cybersecurity Awareness Month” in 2004, a time to recognize cybersecurity’s critical role in national security and prioritize ways to secure our world. As we look at the current landscape, how should Federal IT and security leaders approach this high-stakes, challenging situation, where they’re faced with stagnant or shrinking budgets, skyrocketing costs to manage legacy technology and support services, and increasing demands to advance cyber capabilities?
Today, forward-leaning agencies are taking an innovative cost-neutral approach to immediately fund their modernization initiatives. This approach, self-funded modernization, enables agencies to reclaim funding from costly enterprise IT support contracts and reinvest those dollars into modern, compliant infrastructure.
Self-funded modernization can yield positive results for agencies that have found themselves locked into legacy support agreements or dependent on appropriations to fund new projects involving technology. Self-funding can also help to accelerate modernization efforts like zero trust, quickly align with Executive Orders, strengthen cybersecurity and facilitate regulatory compliance.
As we reflect on the past 20 years of Cybersecurity Awareness Month and prepare for the future, it’s crucial to prioritize initiatives that keep the U.S. secure, competitive, innovative and ready for the digital future. Initiatives like self-funded modernization provide a practical, budget-conscious path forward for agencies to modernize IT infrastructure. It provides a clear way to free up funds and resources to build a cyber strong and resilient America.
++
Kern Smith, VP of Global Solutions, Zimperium
Cybersecurity Awareness Month has become increasingly important as cybercriminals adopt a mobile-first attack strategy. Smishing now represents nearly 70% of all mobile phishing attacks, showing how attackers are exploiting everyday communication channels. At the same time, over half of mobile devices run outdated operating systems, leaving them exposed to vulnerabilities that can be easily exploited. Too often, organizations focus their awareness efforts on traditional phishing via email, while mobile threats, text messages, malicious apps, and risky Wi-Fi, are overlooked.
Businesses must adapt awareness programs to reflect where employees actually work and connect today: their mobile devices. Enforcing on-device protection across both managed and unmanaged devices, coupled with education around mobile-specific risks, is one of the most effective ways to reduce exposure. Looking ahead, organizations that prioritize mobile security in their awareness initiatives today will be better prepared for the AI-driven phishing and zero-day exploits of tomorrow.
++
Jason Schmitt, CEO, Black Duck
As we observe Cybersecurity Awareness Month, it’s clear that every month should be treated as a reminder that the cybersecurity landscape has irrevocably shifted. The old software world is giving way to a new reality defined by AI-driven complexities.
The average application has three times more code than it did 4 years ago and this trend will continue in the years to come. By 2030, there will be three times more applications than there are today.
As global cyberattacks continue to proliferate, with a 30% increase last year alone, there were an average of over 1,600 attacks per organization each week. Add to that AI generated code, which is projected to grow by 400% by 2030, the risks are only going to accelerate and compound.
This new reality renders traditional security tradeoffs ineffective. However, by adopting true scale application security, security and business leaders can access the resources needed to make informed decisions and drive business innovation with confidence. This approach empowers organizations to navigate the evolving cybersecurity landscape effectively.
++
Diana Kelley, Chief Information Security Officer, Noma Security
Cybersecurity Awareness Month gets more important every year. As all of our business and personal data moves online, the digital threat surface rapidly expands through cloud, hybrid work, and now AI. Traditional awareness campaigns have taught employees to spot basic phishing, but today’s attackers are using generative and agentic AI to launch far more convincing scams, everything from highly customized and automated spear phishing to deepfake executive voices to automated invoice fraud. The biggest gap I see is that many awareness efforts are still anchored in yesterday’s risks, leaving staff unprepared for the speed and scale of AI-driven threats. Looking ahead two to three years, businesses must adapt by running scenario-based “AI risk drills,” just as they would fire drills, so all employees can recognize AI powered risks.
Just as important, incident response must evolve for the AI era, where threats spread faster and often hide inside autonomous agent workflows and connections. Without strong observability and audit platforms purpose-built for AI, investigations can quickly stall because it becomes difficult to trace vulnerable connection points, how an agent reached a decision, or which data was access because an action was executed. Building that visibility into AI systems today will be the difference between a quick containment and a costly, prolonged breach tomorrow. Cybersecurity Awareness Month is a great time to reassess security training and governance. The threat landscape is shifting in real time, and organizations need to raise awareness not just about phishing emails or weak passwords, but also about how to detect, contain, and learn from incidents involving AI systems to ensure all areas of their business are covered.
++
Kunal Modasiya, Senior Vice President, Product, GTM and Growth at Qualys
Recent research reveals a troubling gap: while nearly half of organizations have formal cyber risk programs, only 30% align those efforts with business objectives. This disconnect leaves companies vulnerable, not just to technical breaches, but to cascading impacts across operations, finances, and reputation. To close this maturity gap, security leaders must move beyond legacy metrics like CVSS scores and adopt a unified risk framework such as a Risk Operations Center (ROC) – one that continuously correlates vulnerability data, asset context, and threat exposure. This will enable smarter prioritization and faster, more meaningful remediation.
Cybersecurity Awareness Month is a timely reminder: resilience is not just about tools and frameworks. It’s about context, clarity, and collaboration. Business leaders must ensure their 2026 cybersecurity strategy reflects this shift, investing in workforce enablement, governance, and technologies that align security with what truly matters to the business.
++
Devin Ertel, Chief Information Security Officer at Menlo Security
The browser is the most critical, and vulnerable, application in today’s enterprise. Menlo Security’s latest report highlights that web traffic to generative AI sites surged 50% year-over-year to 10.53 billion visits in January 2025, with 80% of that activity happening directly in browsers. This makes the browser not just the primary gateway to AI tools, but also the main channel through which sensitive data and potential threats now flow. At the same time, 68% of employees are using free AI tools with personal accounts, and more than half are pasting sensitive corporate data into them, creating major risks of data leakage.
AI is amplifying both opportunity and risk. While employees rely on it to be more productive, attackers are using the same technology to spin up convincing phishing sites, fake domains, and ransomware delivery mechanisms at scale. With more than 6,500 GenAI domains and 3,000 apps already active, the browser has become the frontline battleground for security teams.
That’s why this year’s Cybersecurity Awareness Month theme, “Stay Safe Online”, resonates so strongly. Security leaders can’t stop AI adoption, but they can govern it responsibly, deploying secure browsers, enforcing true zero trust access, and eliminating shadow AI with sanctioned, safe tools. Modernizing browser security isn’t just about compliance, but about protecting the workforce where they live and work today, which is online.
++
Derek Manky, Chief Security Strategist and Global Vice President, Threat Intelligence, Fortinet
In a year where threats have grown more automated, opportunistic, and relentless, two fundamentals remain critical: protecting against phishing and keeping software updated. These aren’t new ideas, and Fortinet’s 2025 Global Threat Landscape Report reveals why these basic actions continue to be the foundation of resilience. The report highlights a record surge in automated cyberattacks over the previous year. Attackers are increasingly using bots and machine-speed tools to scan for vulnerabilities and launch phishing campaigns at scale. This shift has made phishing more dangerous than ever.
The value of Cybersecurity Awareness Month is that it reminds us to take the time to turn research into action. Here are two practices reinforced by Fortinet’s findings that we recommend everyone implement:
- Strengthen phishing awareness. Employees should be trained to pause before clicking, verify sender details, and report suspicious messages. And remember, multifactor authentication (MFA) provides an additional safety net when credentials are compromised.
- Automate software updates where possible. Organizations should implement centralized patch management. For individuals, enabling automatic updates on personal devices helps eliminate the lag time between patch releases and applications.
++
Edwin Covert, Vice President of Advisory Services at Fenix24
Cybersecurity Awareness Month has grown in importance each year since its inception by the federal government in 2004. This growth is a direct result of the increasing importance cybersecurity plays in today’s information systems and technologies. Without an understanding of risk management for these systems and technologies, and the related cybersecurity management, operational, and technical controls to mitigate or transfer those business risks, organizations are unlikely to meet their overall objectives or missions. Determining realistic threat frequencies and internal susceptibilities to threat actor activity along with both primary and secondary loss magnitudes creates both a meaningful picture of risk and mitigation strategies allowing organizations to stay safer online.
++
Matthieu Chan Tsin, SVP and General Manager of CRS at Cowbell
Modern cyber attacks are on the verge of turning 50 years old; and they have been evolving with increasing speed. Today, AI is inserting itself into our professional and personal lives which poses new risks that we would like to highlight this cybersecurity awareness month. Phishing is much harder to spot, and cyber attacks can be deployed with greater range and speed.
Companies have to include cybersecurity as a daily consideration. Security solutions such as MFA, regular data backups, the principle of least privilege, and a robust standalone cyber insurance policy are just a few of the must-haves for businesses in 2025.
Reach out to your cyber insurance or cybersecurity provider to discuss your cyber hygiene and ensure you’re well equipped for the risks of today – and tomorrow.
++
Agnidipta Sarkar, Vice President – CISO Advisory, ColorTokens
Studies show that cybersecurity awareness initiatives that focus solely on educating individuals are one of the most misleading indicators of cyber resilience, as they give a false sense of accomplishment without being truly effective. Being breach ready requires everyone to understand how they can contribute to preventing breaches from escalating into crises. Cybersecurity Awareness Month should be a culmination of a year’s effort, where cybersecurity awareness initiatives and participating teams would be rewarded for their effectiveness in evangelizing cybersecurity to meet the organization’s intent to be breach ready. Regular cybersecurity awareness needs to extend beyond phishing simulations to empower every team member by engaging in role-playing exercises that simulate real-world cyberattacks, enabling them to understand potential threats and respond effectively. The CISO’s office also has a role in turning every internal breach into an opportunity for awareness without naming and shaming. And the true value is embedding awareness in the culture of the organization, and not a flash in the pan, one day in a year.
Craig Jones, Chief Security Officer, Ontinue
Cyber threats are evolving faster than ever. From MFA-bypassing identity attacks to the resurgence of USB malware, the findings in Ontinue’s 1H 2025 Threat Intelligence report show that attackers are exploiting both advanced techniques and overlooked basics.
Defending against this landscape requires more than tools. It demands a balance of fundamentals, intelligence, agility and it requires raising cybersecurity awareness across the entire organization. Every employee plays a role in reducing risk, whether by recognizing phishing attempts, following access policies, or avoiding unsafe practices like plugging in personal USB devices.
Strong cybersecurity is no longer just an IT issue; it is a business differentiator. Customers, regulators, and partners all expect organizations to demonstrate resilience and transparency. A company-wide culture of security helps build trust while protecting operations.
Here are five best practices every organization should prioritize:
- Fortify Identity Controls: MFA alone is no longer enough. Implement phishing-resistant MFA, revoke stale tokens, and continuously monitor for anomalous login behavior.
- Audit Cloud Persistence: Adversaries are layering persistence in Azure and tampering with diagnostics to extend dwell time. Continuous auditing of app registrations, automation jobs, and privileged roles is essential.
- Reinforce the Basics: A 27% rise in USB malware shows that unfortunately old attack methods still work. Restrict removable media, reduce local admin privileges, and strengthen configuration hygiene.
- Manage Third-Party Risk: Nearly 30% of breaches stemmed from vendor compromise. Enforce strict partner standards and continuously monitor external access to your environment.
- Find the Right Managed Security Partner: Automation accelerates detection and response, but it cannot replace human judgment. The right managed security partner combines AI-driven capabilities with expert analysts, helping organizations close the gap between the speed of attack and the speed of defense. This ensures security can scale as the business grows..
Cybersecurity is not a static project. It is a continuous process that requires adapting defenses as quickly as adversaries evolve their attacks. By focusing on these five priorities, organizations can build resilience against today’s most pressing risks.
++
John Prisco, Quantum Consultant at Toshiba
China’s Quantum Sprint: Why it’s a Cybersecurity Wake-Up Call
October marks Cybersecurity Awareness Month, a time when we’re reminded that digital security isn’t just a tech issue, it’s a national priority. One area that deserves more attention right now is the global race in quantum technology especially between the U.S. and China. This rivalry could shape the future of security and national strength.
Here’s why it matters: quantum technology has the power to completely reshape how we secure our data and information. While the U.S. has made strides – largely thanks to the Quantum Act of 2018, which expired in 2023 – China has been investing 10 times more and is already ahead in building Quantum Key Distribution (QKD) networks. QKD uses quantum mechanics to create virtually unbreakable encryption keys, making it one of the most secure ways to protect sensitive data. The U.S. currently leads in quantum computing hardware, but that could change quickly. The government should act now, not just by funding research, but by rolling out projects at scale and using both post-quantum cryptography (PQC) and QKD together. The U.S. administration could potentially re-enact the Quantum Act before the end of the year, which would be ideal, or in 2026.
What is worrisome is that right now the U.S. administration is focused solely on deploying PQC in government systems, which is an important piece of the puzzle, but PQC alone isn’t enough. Various sectors such as energy, telecommunications and financial networks, don’t have the capability to cater to PQC. This is exactly where a hybrid QKD and PQC approach is most critical. Without QKD, even a “quantum-safe” algorithm could be cracked.
Cybersecurity Awareness Month is about being proactive, not reactive. For the U.S., that means renewing investment in quantum technology and scaling real-world deployments before the gap with China widens. Congress has the opportunity to act by reenacting the Quantum Act and making sure American innovation and national security don’t fall behind in the quantum race.
++
Nigel Tan, Director, Delinea
The attack surface is changing, and the rise of machine identities is at the center of it. From chatbots to APIs and autonomous agents, they already outnumber humans 46 to 1 – yet they’re too often overlooked. Securing these identities is now just as critical as protecting human ones.
The recent Salesloft breach proved the risk. Attackers didn’t go after staff logins – they exploited an AI-powered chatbot’s privileged access, moving into systems like AWS and Slack. With less than half of organizations (44%) across the globe reporting that their security architectures are equipped to fully support secure AI, the gap is clear.
Cybersecurity Awareness Month is the moment to act. As machine identities increasingly become entry points for attackers, start with visibility into where they are and what they can access. Then shorten credential lifespans so stolen details quickly expire and restrict each identity’s access to only what it truly needs. Treating machine identities with the same priority as human ones is essential to business resilience.
++
Chris Mierzwa, Sr. Director, Global Resilience Programs at Commvault
As we approach another Cybersecurity Awareness Month, it serves as a stark reminder that enterprises must get ‘back to basics’ and focus on creating stronger security foundations. Among the many different threat vectors, I implore business leaders to pay close attention to social engineering – the increasingly dangerous Achilles’ heel of every organization.
Enterprises are underestimating threat actors’ ability to understand the more formidable adult psyche. With the help of AI, cybercriminals can now alter their voices, accents, and launch social engineering attacks in multiple languages with real-time translation, leaving employees with no cues to suspect malicious intent. On top of that, threat actors recognize that employees only receive minimal cybersecurity training, meaning they don’t have the knowledge or skillset to recognize the newest and most sophisticated threats.
++
Ravit Sadeh, VP Product Management, CTERA
Cyberattacks unfold in seconds, while our distracted, fast-paced routines often leave us exposed. It’s not that people ignore cybersecurity — most of us know the basics of avoiding suspicious links and shady websites. The real risk comes when we’re multitasking: replying instantly to what looks like a boss’s urgent email, downloading a new AI tool in the rush to finish a presentation, or skimming messages while on the move. In 2025, impulsivity has become the new vulnerability.
Awareness programs can no longer focus only on the “focused office worker” scenario. The real challenge is helping employees build habits that hold up in the messy reality of daily life — when attention is divided and time is scarce. At CTERA, for example, we run simulated phishing campaigns that catch people off guard. Nobody likes being “fooled,” but it builds muscle memory and proves awareness can’t be an annual exercise.
In a distracted century, cybersecurity awareness isn’t a campaign — it’s a habit.
++
David Primor, CEO, Cynomi
Too many organizations treat cybersecurity as a checklist-focusing only on compliance requirements to “tick the box.” But compliance alone doesn’t guarantee real protection. True resilience means building the ability to anticipate, withstand, and recover from cyber threats. At Cynomi, we help service providers take their customers beyond frameworks and audits, translating compliance gaps into actionable roadmaps that strengthen defenses in practice. The result: companies don’t just meet regulations-they gain measurable, lasting cyber resilience.
++
Pavel Bykov, co-founder and CEO of IP Fabric
Future-Proof Security Is a Myth
Every October, Cybersecurity Awareness Month reminds us to challenge assumptions. One of the most dangerous assumptions in IT is the idea of “future-proof” networks. The second you deploy, reality takes over. New technologies emerge, workloads shift, and the design no longer matches what runs in production — opening up gaps for threat actors to slip through. AI expands these gaps even further, generating relentless traffic on top of existing workloads.
Documentation alone can’t keep pace with this level of complexity, nor with the pace of change. The only reliable source of truth is the live network itself. Network digital twins are the key to proactively uncovering gaps in your security strategy; on top of identifying dependencies, digital twins can be used to pinpoint bypassed firewalls, misconfigured security controls, and other risks before threat actors can leverage them. But not all digital twins are created equal; some rely on predictive modeling or limited protocols like SNMP, which can leave blind spots. To deliver real security value, a digital twin must draw from the most complete and accurate data available.
The lesson for Cybersecurity Awareness Month is simple: don’t chase the promise of a “future-proof” network. Build on solid architecture, validate against what the network is actually doing, and treat visibility as the foundation of security.
++
Mike Geehan, Head of Security, Compliance, and Corporate IT at Cockroach Labs
Yes, Cybersecurity Awareness Month can serve as a reminder to reset passwords and brush up on the latest in phishing best practices, but it’s an equally important time to revisit your organization’s approach to resiliency. Availability is one of the core pillars of the information security triad, so resiliency is vital to a business’ security strategy. Outages, cyberattacks, unexpected vulnerabilities, or other events that cause unplanned downtime, can test your defenses and expose any weaknesses in your infrastructure. Executives should take a step back and ask some simple questions: how resilient is our technical infrastructure under stress, where are the weak spots, and are we testing them on a regular basis?
Building scalable infrastructure is critical, but equally important is ensuring that scalability doesn’t introduce new vulnerabilities. Take a traditionally security-specific concept, zero trust. Apply the concept holistically across an organization’s entire architecture. Assume failure and breaches will happen, and build resilience at all levels of the ecosystem. Cybersecurity Awareness Month, as a lead into the new year, is the perfect time, yesterday aside, to review compliance requirements, stress test your architecture and continue to reinforce resilience. Prepare your organization to respond, not react to whatever 2026 has in store.
++
Phil Swain, CISO at Extreme Networks
Cybersecurity Awareness Month is about more than revisiting best practices; it’s about recognizing how dramatically the security landscape has evolved. In an era where AI is being used to automate and scale attacks, security leaders must rethink their strategies to stay ahead. Security has always been foundational, but today it requires tighter integration across the business processes, the supporting networking, AI, and security to build resilience well beyond October. Organizations must embed security-first thinking into every decision, year-round, to safeguard their data, operations, and people.
++
Raed Albuliwi, CPO, Xona
As we reflect on Cybersecurity Awareness Month, it’s time we move beyond awareness and toward architectural accountability, especially for the systems that run our critical infrastructure. For too long, remote access has relied on outdated systems like VPNs, jump servers, and RDP gateways that prioritize convenience over security. These tools were never designed to handle the reality of today’s distributed, high-risk OT and cyber- physical environments. The real vulnerability isn’t just malware or misconfigured firewalls, it’s access: who’s allowed in, from where, and for how long. Every connection is a potential conduit for ransomware or lateral movement, particularly when unsecured or 3rd party endpoints are involved. Modern secure access must break the traditional network path, isolate endpoints from critical systems, and enforce zero-trust principles without relying on perimeter-based assumptions. This isn’t theory, it’s now a requirement across regulatory frameworks from NERC CIP to IEC 62443 to NIS2 to Saudi OTCC-1. As attackers increasingly target OT and critical infrastructure through remote access vectors, we must design systems where access is inherently untrusted, auditable, and short-lived. That’s not just awareness; it’s engineering for resilience.
++
Tim Erlin, Security Strategist, Wallarm
In lieu of standard cybersecurity advice, I want to suggest a different approach. First, let’s address the cybersecurity practitioners instead of the general public. If your job isn’t in cybersecurity, this advice isn’t for you. Cybersecurity Awareness Month is often used to foster awareness in the general public or even in other technology sectors, but the people who can have the most material impact are the practitioners themselves. Let’s make this month an occasion to take some specific actions. Teach one person something new about cybersecurity. Maybe this is a coworker that you can teach about a recent incident. Maybe you want to take it further and reach out to a local school and offer to do a guest talk on scams or digital safety. The point is, make it your mission to do some education this month. Dedicate some time to your own education. We’re all busy and it can be hard to stay on top of new things. Read a threat report, and I mean really read it. Go learn about a new API protocol and how to secure it. The point here is to increase your own awareness. Build something! Implement an open-source or free product, try a new vulnerability scanner, create a custom GPT or AI agent. The point here is to get your hands dirty in a new way. If cybersecurity practitioners can accomplish these three things in the month of October, we’ll all be better off in terms of Cybersecurity Awareness.
++
Gary Brickhouse, SVP, CISO, Guidepoint Security
While I love this time of year and appreciate the spotlight cybersecurity receives, it is also an opportunity to move past the usual checklists of “use complex passwords” or “don’t click suspicious links” and focus instead on the consequences when risks are realized. Ransomware has consistently shown its ability to cause massive operational disruption, with downtime translating directly into financial loss. Ingram Micro, for example, was recently estimated to have lost $135 million in sales per day during its outage. And now, with threat actors leveraging AI to scale attacks faster than defenders can respond, the urgency to expand our approach has never been greater.
This should drive our conversation from simply awareness to resilience. The NIST 800-172 definition of cyber resiliency includes “the ability to anticipate, withstand, recover from…attacks, or compromises on systems”. For cybersecurity teams, this means a holistic strategy is needed to help prevent attacks as well as withstand and recover from them without crippling operations or losing trust. This can only be achieved through the integration of cybersecurity and broader business continuity planning. Integration may include investing in automated detection and recovery capabilities, ensuring cyber risks are included in resilience planning, unified incident response playbooks, and strengthening employee behavior through better security integration into business workflows.
Awareness is the foundational starting point but leveraging efforts to help drive resiliency will best position the business to anticipate, withstand, and recover with confidence.
++
Rishika Desai, Threat Researcher and Writer, BforeAI
I think, every year for Cyber Security Awareness Month, we are reminded of how far we’ve come and how far we still need to go in terms of being threat resilient. Today’s digital audience is definitely more aware and cautious compared to a few years back. But here’s the catch, every time we think we’ve understood the cyberthreats, a new and more sophisticated form of cybercrime enters the picture.
Phishing is a good example. It was a hot topic years ago, and it still is. But now we’re dealing with AI-generated phishing kits, ready-made templates, and convincing formats that can fool even the most alert individual, sometimes even researchers! Add to that AI-generated malware, which can be built in seconds, and you realize that “being aware” or “being updated” isn’t a one-time thing. By the time we learn to defend against one attack, another variation is already out there.
That’s why awareness cannot just be steady, it has to keep pace with the speed of evolving threats. For organizations, this means making a pivotal shift from being reactive, to start being proactive. A state of readiness in which we don’t just act after the breach, rather look for indicators that hint at an attack being staged.
This is where AI, if applied correctly, can be a real game-changer. It can map historical data, identify patterns, and even predict potential attack vectors. The goal isn’t just to defend faster, but to prepare earlier, and help spread the right awareness before the threat reaches thousands of victims.
So yes, awareness is improving, but speed and preventive measures are the real needs of the hour, both for organizations and individuals!
++
Jeff Williams, co-founder & CTO, Contrast Security
Cybersecurity reality is way out of line with public expectations. We trust software with the most important things in life—finances, healthcare, utilities, government, defense, even our social lives. But the truth is, most companies aren’t anywhere near the level of security you expect. That’s why every breach sparks outrage and knee-jerk blame, even though every company is in the same boat. The real issue is that the software market is broken: buyers can’t make informed decisions about security and have no recourse. We could fix this, but we don’t. Companies chase shiny new features, politicians protect funding streams, and despite incredible efforts by developers, security pros, and operations teams, little has changed in decades. Our software ecosystem is so interconnected that no single company can do much better than the rest of the market. We won’t escape this cycle with best practices, yet another standard, hyping another buzzword, blaming others, or doing the same old things harder. Real change means fixing the market—either by mandating transparency, or by following the EU’s lead and treating software like every other product, where vendors are liable for defects that cause harm. Be aware—cybersecurity won’t change unless we change the incentives.
++
Bob Maley, CSO, Black Kite
I have been in the field a long time, and Cybersecurity Awareness Month always felt like checking the fire alarm batteries, something necessary, but who really cared? (Although preventing that incessant chirp in the middle of the night is a good thing) We need to see it differently now. Cybersecurity awareness should not be just about posters, webinars, or forced enthusiasm and participation. It should be about changing how we think and act, sparking that moment when people stop seeing security as someone else’s job and start owning it. It should be all about how you react when a weird link appears, or a sketchy email slides into your inbox. When you think that’s not “someone’s” problem, it’s mine, that’s the opportunity to rise to the occasion, to become the first responder. It is your click, or your recognition of the threat, that will decide if it will turn into a full-blown breach headline or not. Sitting back is comfortable, but it’s also expensive. We can’t afford to be comfortable. We need sharp, fast, and switched-on people as our frontline defense. Stephen Hawking said it well: “However difficult life may seem, there is always something you can do and succeed at.” That “something” is taking action, the right action, before it becomes a crisis.
++
Grant Leonard, Field CISO, Lumifi Cyber
CAM tends to be a time of simply repeating “use strong passwords” and “don’t click on links,” yet true security is about building secure habits and a security-first culture. Much like any industry there is some kind of failure to heed repetitive messages — the burnout employees feel from constant, unengaging security training. Sure, some teams use strategies like gamification, making secure actions the path of least resistance, and personalizing security education to an individual’s role and skill level.
One approach might be to humanize the impact by focusing on tangible, real-world consequences for individuals and businesses. For individuals, this could be the inability to access medical records during an emergency due to a healthcare system ransomware attack or the emotional and financial toll of identity theft. For businesses, the focus can be on operational disruption, reputational damage that outlasts the attack itself, and the steep legal and financial penalties that follow a data breach. What, for example, is the impact on critical infrastructure, or what happens when there are attacks that disrupt fuel supply or power grids. Yet this also feels lacking, it’s just another method that lends itself to repetitive messaging burnout.
Can we go beyond just saying “patch your systems in a timely fashion” and talk about the importance of continuous vulnerability management and the role of automation. What about the role of AI here? If we are thinking in terms of “zero-trust” architecture, where no user or device is trusted by default, why aren’t we already thinking about using AI to further vet the trust extended to users, accounts and devices on the network? We know the importance of supply chain security, given how many modern attacks target vendors and third-party suppliers. Why not extend AI here as well? What if we used AI, not just to uncover oddities occurring, but to handle the totality of access control? Orwellian as it might seem, we know the largest points of failure tend to be users tricked into doing something. This URL alone will get many in a phishing scenario ‘rnicrosoft.com’ due to kerning or font alteration, but it should not get past an AI. What if the AI was aware of the user’s passwords age and aware of count of failures over time per user and squashed the inbound password request before reaching their inbox because it knows no such thing is possible?
Moving to supply chain monitoring and zero trust, we can ask an AI to help with UEBA as we see in SIEM platforms, but consider if it was embedded into the ethos of the company platforms? Some of the more promising AI platforms emerging now, do just that. Platforms today are beginning to alert and alter risk on 3rd parties that have been compromised, consequently altering risk for your company or detailing where to focus on newly uncovered concerns. Think about the recent Drift Oath concern from Salesloft and the expanse with which it impacted tools (if you aren’t aware of the insane reach this one had, please contact us). As employees go all in on using AI and LLMs, it’s time for the AI or LLM to tell the employee “you can’t actually ask me that question or give me that prompt” as a component of Zero Trust mentality. CAM might then evolve from the banality of cartoon drawings about passwords, to a company funded meal or outing as risk has been seriously shifted away from the user and into the hands of that cool new tech that can see everything, everywhere, all at once.
++
Matt Mullins, Head Hacker and Offensive SME, Reveal Security
Some of the biggest breaches this year weren’t about malware or zero-days — they came from attackers using stolen credentials and logging into SaaS platforms. What makes this even more dangerous is that it’s not just human accounts at risk. Non-human identities like service accounts, automation tokens, and even AI agents have become prime targets, giving attackers powerful ways to blend in once inside. Defenders need to shift focus from perimeter controls to SaaS and what happens after authentication. That means building visibility into the behavior of both human and non-human identities, and spotting misuse before it turns into large-scale data loss or disruption. Cybersecurity Awareness Month is a timely reminder that identity — not infrastructure — is now the true front line.
++
Eran Barak, CEO, MIND
Cybersecurity Awareness Month is a valuable moment to recognize the dedication of security defenders. They work tirelessly and deserve the spotlight. But let’s be clear: awareness isn’t keeping data safe. According to ESG research, over half of organizations experienced two or more unstructured data loss events in the past year. At the same time, less than 27% of sensitive data has been fully discovered and classified. That means most companies don’t even know what they’re losing, until it’s too late.
The problem isn’t a lack of awareness. It’s a lack of effective, sustainable protection. Legacy DLP tools create noise, false positives and manual work that leave teams exhausted and data exposed.
So what should companies do?
- Start with visibility: build a living inventory of sensitive data across SaaS apps, endpoints, file shares and GenAI tools. You can’t protect what you can’t see.
- Classify with context: don’t rely on regex alone. Use classification that understands the difference between a random number and a payroll file.
- Prioritize by risk: not all alerts matter equally. Focus on data movement and user behavior that actually signal risk.
- Automate the manual: remediation shouldn’t be a fire drill. Automate blocking, coaching and policy enforcement so your team can focus on what matters.
The long-term impact of Cybersecurity Awareness Month should be more than applause. It should be a commitment to safeguarding the data that is the lifeblood of every business.
Awareness is good. Action is better.
++
Neil Carpenter, Principal Solution Architect, Minimus
Writing reflections on Cybersecurity Awareness Month feels a lot like the movie “Groundhog Day” in the sense that cybersecurity luminaries spend late September penning the same advice each year only to see little progress made in the other 11 months of the year.
This would be a good year to think about how to make lasting changes instead. In at least two cases, I believe we should let go of conventional wisdom and reëxamine new guidance to make a lasting change.
It’s been nearly a decade since Microsoft updated their password guidance to move away from complexity requirements and regular password expiration; in the intervening years, even august organizations such as NIST have updated their guidance to match. These changes accurately reflect the threat landscape but many organizations remain stuck on user-hostile approaches to passwords. Yet, I still run into many organizations that require me to have upper and lower case, numbers and special characters, and that insist on expiring my password every X days. The evidence is that these requirements lead to worse user outcomes without measurably improving security. Changing your organization’s approach to reflect more modern guidance encourages good user behavior year-round.
I also frequently run into conventional wisdom in enterprise vulnerability management, an area where research has shown that most organizations only patch a fraction of all of the vulnerabilities that the organization has in deployed software. Vulnerability management teams continue to pour more time, energy, and resources into identifying the right 10% to patch but never seem to get ahead of the game. However, companies that embrace strategies that reduce the number and scope of deployed components, thus reducing the absolute number of vulnerabilities, are finding that they’re able to get much better outcomes resolving vulnerabilities in their ecosystems.
++
Gary Schwartz, SVP Marketing, NetRise
One of the biggest cybersecurity challenges I see today is the blind trust we place in the software that powers the devices across our enterprises. We purchase network gear, IoT devices, and applications with the assumption that the software inside is secure—and that vendor-supplied vulnerability data tells the full story. Too often, it doesn’t. Critical risks live outside the CVE system: misconfigurations, embedded credentials, outdated libraries, and hidden build-time inclusions that no one ever documented. These non-CVE exposures can quietly expand the attack surface of every device we deploy.
Even when vulnerabilities are catalogued, gaps persist. Common Platform Enumerations (CPEs) are supposed to link software to vulnerabilities, but when identifiers are missing—or when code is statically linked or buried inside vendor-supplied binaries—whole classes of risk never show up in dashboards. That means enterprises may be unknowingly running devices with exploitable software, even when the official records look clean. The result is a dangerous disconnect between what we think we’re running and what is actually running in production.
This Cybersecurity Awareness Month, I encourage every security and risk leader to ask tougher questions of the devices entering their environment. Don’t take vendor attestations at face value. Demand transparency into what’s inside, validate what’s truly running, and treat non-CVE risk with the same seriousness as published vulnerabilities. Our security posture is only as strong as the unseen code we inherit from others—and awareness starts with shining light on those blind spots.
++
Rebecca Krauthamer, Co-founder & CEO, QuSecure
Over the last month, we’ve seen the timeline for Q-Day accelerating. The quantum threat that many thought was a decade away is now projected to be closer to five years. Quantinuum and IBM for example, is accelerating both its quantum computing development and its timeline to be post-quantum secure. The era of ‘wait and see’ is over.
Everyone should be paying attention to CNSA 2.0, which states that after January 1, 2027, no new national security system can be acquired unless it supports post-quantum cryptography (PQC).
The biggest shift is recognizing that cryptography is no longer a static, one-time decision. It must be agile, upgradeable, and future-proof. For most organizations, the first step is simple: focus on your high-impact systems starting with your web apps, APIs, and customer data pipelines, and start layering in post-quantum protections now. Waiting until the deadline is not a strategy.
++
Bert Kashyap, CEO, SecureW2
Building a cyber strong America starts with trust decisions that align with current conditions. Modern certificate-based security can integrate with enforcement logic that responds to real-time signals: device posture, user context, risk indicators. When conditions change, access policies adjust immediately. A device that fails a posture check doesn’t wait for an arbitrary timeline to lose access. Interoperable systems deliver what validation schedules can’t: trust that reflects actual state rather than assumed state based on the customer’s security stack.
We all know authenticated doesn’t mean trustworthy forever. Adversaries understand timing gaps and exploit them. They compromise devices after authentication succeeds and move laterally while certificates still grant access. The industry’s been tightening validation timelines in response, but the intervals themselves remain somewhat arbitrary. What actually addresses this is moving from scheduled checks to continuous assessment. Organizations that control their trust logic through cloud-native architecture can pull from multiple telemetry sources and respond as their environment changes rather than waiting for the next rotation.
Here’s what that enables in practice. Faster detection when something goes wrong, because access controls respond to the same signals your monitoring sees. Reduced dwell time, because compromised credentials or devices lose access as conditions change. Access decisions that align with actual risk instead of assumed risk. I’ve seen this pattern hold across different implementations: organizations that tie certificate-based authentication to continuous validation through modern, interoperable infrastructure respond faster and break less often. A cyber strong America gets built on systems where trust reflects current reality, not periodic snapshots.
++
Mike Britton, Chief Information Officer, Abnormal AI
While security education and training should, of course, be an ongoing initiative, Cybersecurity Awareness Month presents a unique opportunity for security leaders to emphasize the behaviors, tools, and resources that can help employees support the organization’s security year-round. To combat increasingly sophisticated threats—like those powered by generative AI—training must focus on the personal value of security for employees. Security leaders can also make education memorable and fun through gamification, contests, or inviting guest speakers. The goal is to maximize October’s momentum to establish an ongoing culture of security awareness that keeps employees engaged and cyber-focused throughout the remainder of the year, thereby protecting the organization.
++
Benjamin Harris, CEO & Founder of watchTowr
Attackers are moving faster than ever. The time from disclosure to in-the-wild exploitation has never been shorter — in most cases, measured in hours, not days. That speed gives adversaries a huge advantage: they can slip in, drop backdoors, and establish persistence before security teams have even finished testing and rolling out a patch.
That’s why patching alone is no longer a measure of resilience. If your only defense is “how quickly can we patch,” you’re already playing catch-up. Think about it: fixing the lock on your front door doesn’t help if an intruder has already made a copy of the key and is coming and going as they please.
Cybersecurity resilience today means the ability to react rapidly to emerging threats, not just patch, but detect compromise attempts, contain intrusions, and neutralize backdoors before attackers can fully capitalize. The organizations that succeed are the ones that treat rapid reaction to emerging threats as a broader capability and incident response rather than patching alone.
++
Lindsay Kaye, VP of Threat Intelligence, HUMAN Security
As we celebrate Cybersecurity Awareness Month, one encouraging trend is that increased awareness and smarter defenses are helping organizations stay ahead of AI-powered fraud. In our SlopAds investigation, we identified 200+ apps with millions of downloads that could have gone unnoticed, but careful monitoring and layered defenses helped uncover their hidden sophisticated behavior. Similarly, our latest AI crawler study showed that nearly 6% of all traffic was spoofed. This serves as a reminder that understanding these patterns gives us the power to protect users more effectively.
With Agentic e-commerce being on the rise this holiday season, businesses should consider investing heavily in enabling visibility into AI crawlers and agent activity to help them navigate, understand and govern the agentic behaviour rather than simply block it. This Cybersecurity Awareness Month, let’s focus on proactive strategies, informed vigilance, and collaboration. This proves that with the right knowledge, we can outsmart sophisticated threats, and allow businesses and consumers to meet each other in trusted and safe digital environments.
++
Jadee Hanson, CISO, Vanta
One of the most important themes we should focus on this Cybersecurity Awareness Month is how AI is both an advantage and disadvantage of security. Recent research from Vanta shows that the majority of business and IT leaders today feel like AI risk outpaces their expertise. But those same leaders are seeing amazing benefits from adopting AI into their security program. For CISOs, the job is no longer about being a technical gatekeeper—it’s about flipping the switch with AI to turn it from a threat into an asset. We have to become business enablers who understand and strategically manage AI risk, while also leveraging new tools to keep up with the emerging threats that AI brings to the table.
++
Gary Orenstein, Chief Customer Officer, Bitwarden
Cybersecurity Awareness Month reminds us that strong security habits keep everyone safe online. However, security isn’t just seasonal. The same risks occur year-round, and those habits must persist every day, far beyond October.
Tools like password managers, autofill, and passkeys make securing accounts easier and more seamless. Yet attackers continue to exploit familiar flaws, including weak or reused passwords, phishing, and social engineering. These risks can be addressed by pairing modern tools with proven security practices, such as multifactor authentication (MFA), strong and unique credentials for every account, identifying and avoiding scams, and keeping software up to date.
That’s why the fundamentals remain critical. Just as seatbelts became second nature for drivers, good security habits must become second nature for everyone online. Cybersecurity Awareness Month is a launchpad, not a finish line. This ongoing security push underscores that vigilance and action empowers individuals and organizations to build resilience, reduce risk, and strengthen trust in their daily digital tools.
++
Thom Langford, EMEA Chief Technology Officer, Rapid7
Data has become both our greatest asset and our biggest liability. For security teams, the challenge isn’t just managing the volume of threats – it’s managing the sheer scale of information they face every day. Organizations are often flooded with proactive signals and intelligence, but often struggle to turn them into practical action. At the same time, attackers are exploiting this reality, driving unprecedented levels of data exfiltration and stockpiling stolen information for future attacks. Understanding not just what data is exposed, but how it can be used against organizations, is now a core part of resilience.
New technologies like AI-driven browsers, chatbots, and wearables are only accelerating this challenge. They enable flexibility and innovation, but also generate industrial levels of personal and corporate data that often slip beyond teams’ control. Security teams must work to build a strong security infrastructure – building itself into a connected, collaborative workforce that can safely operate beyond traditional boundaries without increasing exposure to risk.
Cybersecurity Awareness Month is a reminder that building resilience starts with people. Organizations need to rethink how they hire and develop talent, valuing passion and potential over rigid qualifications, so teams are ready to handle the realities of data at scale. Teams cannot lose sight of the horizon: with quantum computing on the way, even old, stolen data could become a weapon. Preparing now by strengthening identity practices and investing in adaptable teams is one of the most critical ways to stay ahead.
++
Mike Toole, Director of Security, Blumira
Security is an industry that seems to always have eyes on the next big thing that will be the answer to keep our environment secure. It’s a tempting idea, since threats are always evolving and new attacks emerging — but the newest and shiniest toys can distract us from what matters most: the fundamentals.
No matter what vendors promise, there’s no magic silver bullet that will keep digital infrastructure 100% secure . Cybersecurity Awareness Month is a timely reminder that building on a foundation of basic strategy like asset management, strong authentication and authorization, logging and monitoring, naming and managing risk, patching, and detection will make a much bigger difference.
You wouldn’t build a house on a shaky foundation (and if you did, good luck finding someone willing to insure it!). You also can’t effectively tackle more complex security challenges if you haven’t mastered the essentials. Building onto core principles creates a robust framework that protects you from current threats and can quickly adapt as the security landscape evolves. After those base practices are in place, you can mature the program and layer on more advanced solutions targeting specific risks and emerging threats.
++
Kevin O’Connor, Director of Threat Research, N-able
Even as new cyber threats emerge every day, we’re seeing a surge in threat tactics that continue to haunt organizations and individuals year after year, such as job offer text scams and email phishing campaigns. With the proliferation of AI tools, these attacks are increasingly sophisticated, highly personalized, and alarmingly convincing. Threat actors are exploiting job seekers’ trust and urgency, mimicking real recruiters, HR platforms, and even known organizations to extract personal data, steal credentials, or distribute malware.
The revival of this threat underscores the importance of exercising vigilance and verifying before you click. Organizations must implement strong email and SMS filtering, educate employees to recognize modern social engineering tactics, and deploy behavioral analytics to flag anomalies early. Meanwhile, individuals should treat unsolicited job offers or messages with caution, especially those that seem too good to be true.
++
Raghu Nandakumara, Vice President of Industry Strategy, Illumio
The industry’s long-held confidence in prevention-at-all-costs is no longer viable in today’s threat landscape and has forced a necessary evolution in strategy. While prevention will always be an important piece of cyber best practices, its limits are becoming increasingly evident. A containment-first approach acknowledges the reality that some cyber attacks will succeed, while ensuring that damage is minimized.
This shift towards resilience and containment means prioritizing two key areas: comprehensive visibility and microsegmentation. When an attack occurs, the ability to instantly see the lateral movement of a threat and quickly isolate affected systems is the difference between a minor incident and a corporate crisis. For the C-suite, this means recognizing that effective containment is the highest form of prevention—allowing business to continue even in the midst of a breach. This Cybersecurity Awareness Month, leaders need to think about shifting their resources and mindset from trying to keep attackers out and instead focusing on minimizing their impact once they are inside.
++
David Sequino, CEO of INTEGRITY Security Services (ISS)
Life can get pretty hectic, and it’s easy to put cybersecurity on the back burner. Between work, kids, bills, and the endless to-do lists, nobody has time to obsess over staying safe online. The good news is, you don’t have to. Our decades of experience protecting over 2 billion devices shows that smart security begins by starting simple. Change your default settings, set strong passwords, and make sure your devices come from trusted places. Then, keep things current. Updates are like your regular oil change – easy to ignore, but dangerous to skip. Use multi-factor or Face ID for authentication where you can and retire old tech before it turns into a security risk. These little habits add up, and they make a big difference in keeping yourself safe online.
++
Eran Kinsbruner, Vice President of Portfolio Marketing at Checkmarx
This Cybersecurity Awareness Month, it’s critical to recognize that the age of AI-generated software has fundamentally changed the threat landscape. Code is no longer just written, it’s generated at unprecedented speed by AI coding assistants, vibe coding workflows, and autonomous engineering agents. Such generated code is being pushed sometimes automatically and frequently to online web applications. While this accelerates innovation, it also expands the attack surface with risks like LLM poisoning, package hallucinations, prompt injections, and malicious open-source packages that can bypass traditional defenses and put at risk both the business and their audience. That is why this year marks a shift in the sense that security can no longer be bolted on later, it must be embedded at the very point where code is created – the sooner, the better.
One way to address this growing online risk is by embracing Agentic AI in AppSec. This isn’t just about shifting security left, it’s about evolving security to keep pace with how modern software is built. By combining prevention with context-aware guidance, AI security agents empower developers to move fast without compromising resilience, therefore securing online applications in the new AI Era.
Cybersecurity Awareness Month is also a great reminder that security is not just an engineering challenge, it’s a shared responsibility. Developers, AppSec teams, CISOs, and business leaders alike must understand the risks of unchecked AI-generated code and the strategies to defend against them. Equipping teams with knowledge of AI-native threats, and the right tools to counter them, not only strengthens enterprise security but also builds skills employees can use in every aspect of their digital lives.
In 2025 and beyond, software development with AI is inseparable from security with AI.
++
Nimrod Partush, VP of AI & Innovation at CYE
While headlines are filled with sophisticated cyberattacks, the truth is that most breaches begin with something far simpler. CYE’s 2025 Cybersecurity Maturity Report reveals that the leading cause of security incidents isn’t a sophisticated zero-day but a failure to handle the basics, like leaving sensitive interfaces exposed online and/or a lack of multi-factor authentication to avoid attackers logging with stolen credentials bought on the dark web. This lack of basic security hygiene creates an open door for attackers.
The report states that 81% of breaches involve weak or stolen passwords, and those credentials often give adversaries the foothold they need to move laterally and reach critical data. While advanced defenses are valuable, they can’t compensate for lacking basic practices like strong access control and solid configuration management.
Our research also shows that half of organizations lack a business continuity plan (BCP), leaving them unprepared to respond and recover quickly from a cyberattack. Without a tested plan, companies risk great impact on customers, partners, employees and investors.
Cybersecurity Awareness Month is the perfect time to reinforce the basics–strong access controls, sound configuration and preparedness; however, true cyber resilience is a year-round effort. Organizations must treat it as a continuous effort, investing in capabilities and processes, testing their exposure and ensuring they can sustain operations through any incident.
++
Mario Villatoro, Chief Information Security Officer, Jamf
Looking ahead to 2026, organizational leaders face a stark reality: traditional security strategies simply won’t cut it anymore. With AI amplifying attack capabilities and adversaries weaponizing vulnerabilities at lightning speed, cybersecurity must transform from a defensive position into a strategic business driver.
The solution starts with mastering the basics: robust authentication, disciplined credential management, systematic patching, and security-first culture. But today’s reality demands more—zero-trust network models, intelligent threat detection, and comprehensive security education and awareness across all teams.
The winning formula combines human expertise with machine intelligence. As digital footprints expand and security talent remains scarce, success requires seamlessly blending proactive human-led initiatives with automated defenses while breaking down silos between security, IT, and business teams.
As security-minded organizations and individuals, the question isn’t whether we can afford to transform—it’s whether we can afford not to.
++
Shikha Sangwan, Senior Threat Researcher, Securonix
Cybersecurity Awareness Month is the perfect time to talk about a simple truth: the wall between our work and personal digital lives has all but crumbled. The phone we use for online banking is the same one we use to answer work emails, and the laptop our kids use for homework might be the same one we use to connect to the company network. While businesses invest millions in security software, attackers know it’s often far easier to trick a person than to break through a complex digital defense.
This is why the theme “Stay Safe Online” is so important. It reminds us that good security isn’t a product you buy; it’s a habit you build through the small decisions you make all day long. We need to move beyond just thinking about password length and start applying a “zero-trust” mindset to our daily routine. That sounds technical, but it just means we can’t blindly trust every message that lands in our inbox. We must treat unexpected emails, urgent requests, and unfamiliar links with healthy skepticism. Taking thirty seconds to call or text someone to verify a strange request isn’t being paranoid; it’s being smart.
If there is one action everyone should take, it’s enabling multi-factor authentication (MFA) on every important account. Think of it as the digital equivalent of deadbolting your front door. Even if a thief manages to steal your key (your password), they still can’t get inside without your phone or fingerprint.
When we practice these simple, consistent habits at home, we are doing more than just protecting our family photos or financial data. We are building security muscle memory. We train ourselves to be the first and best line of defense, transforming from the weakest link into the strongest part of our organization’s security posture. True cyber resilience doesn’t start in the server room; it starts with us.
++
Andrew Woolnough, EVP, Corporate Affairs, ISC2
Cyberattacks are an escalating threat to the global economy, and meeting them requires a workforce that is skilled, adaptable, and ready for evolving risks. This will take greater investment in cybersecurity workforce development and training from both the public and private sectors and the creation of more pathways into the profession.
ISC2’s Hiring Trends Report shows this need clearly: 89% of security managers would consider a candidate with a foundational certification over one with only a degree. Employers increasingly value demonstrable skills and hands-on experience over formal education alone.
This Cybersecurity Awareness Month, leaders have an opportunity and a responsibility to build a resilient workforce. Accessible certifications, continuous training and clear career pathways will be critical. While smart habits, policies and technology remain essential, lasting security will be forged by the people equipped to defend it.
++
Mark St. John, Co-Founder and COO, Neon Cyber
At a technical level, we have to meet users where they are at, which includes our non-technical friends & family. The industry has had everyone’s best intentions in mind when trying to encourage everyone to adopt complex passwords/phrases for every site. We quickly realized that this led to password reuse. Getting the average person to use MFA is trending upward, but for me, the best bang for the buck is still the password manager. Password managers, with their seamless functionality across devices, sites, and authentication methods, are designed with user-friendliness in mind. These tools have kept pace with the times and offer several suites for managing personal and family accounts, some even providing data scraper removal and other identity protection methods to offer basic operational security to the least technically inclined among us. As we shift towards passkeys and more advanced authentication types, we can’t pretend that the legacy methods aren’t still the main use case for our neighbors!
++
Dan Candee, CEO of Cork Protection
Why we need to think less about making clients “aware” and more about making them [and ourselves] truly ready for a fight. Here are a few things to keep top of mind:
1. Forget the Posters, Run a Fire Drill.
Those generic awareness campaigns are basically useless. Instead of sending another “Don’t Click That Link!” email, run a real-life “war game” for your clients.
Pretend the worst has happened: A hacker is in. Now what? Who gets the first call? What’s the step-by-step plan? How quickly can you actually restore from your backup? Test the entire chain of events. It’s one thing to talk about a disaster recovery plan; it’s another to see how it holds up under pressure. This single exercise will show your clients the real gaps in their defenses way better than a hundred newsletters ever could.
2. Look in the Mirror, You’re the Biggest Target.
Before you point fingers at your clients’ employees, we need to have a frank conversation. Hackers know that the ultimate prize isn’t a single small business; it’s the IT provider who serves hundreds of them. A breach of your RMM tool is their golden ticket.
This month is the perfect time to get your own house in order. Take a hard, honest look at your own security. Are you truly following the best practices you preach to your clients? Is your own tech stack locked down tight? You can’t credibly sell protection if you’re vulnerable yourself. Your clients’ survival depends on you being the most secure link in the chain.
3. Talk Money, Not Tech.
This is your golden opportunity to get in front of your client’s leadership team. But don’t you dare walk in there talking about firewalls and endpoint detection. They’ll tune you out.
Instead, talk about the one thing they absolutely care about: money.
Frame the conversation around their cyber insurance policy. Offer to do a “Readiness Review”. Sit down with them and read the fine print. Point out all the loopholes and requirements their insurance carrier will use to deny a claim. You can say, “This isn’t an IT problem; this is a financial risk. Let’s make sure you’re in a position to actually get paid if the worst happens.
++
Elisa Yanez, Solutions Engineer, Assured Data Protection
In cybersecurity, no two challenges look the same. Having a range of perspectives on a team helps us analyze threats differently and design stronger defenses. As women in cyber, we add to that diversity of thought, which is critical when protecting systems and data that organizations rely on every day. As Solutions Engineers, we not only help identify these challenges but also design and implement tailored solutions, bridging the gap between complex technologies and the real-world needs of the organizations we support.
++
Sandeep Singh, Senior Director, Security Strategy and Operations at HackerOne
Across the cybersecurity industry, researchers are evolving just as quickly as the risks they face, driven in large part by the use of AI. As we observe Cybersecurity Awareness Month, it’s important to recognize that AI isn’t replacing human expertise; it’s amplifying it.
With the rise of AI, we’re seeing the emergence of the ‘bionic hacker’ – a security researcher who uses AI to amplify human creativity and skill. These security researchers aren’t being replaced by AI; they’re harnessing it to supercharge reconnaissance, triage, pattern recognition, and exploration of complex attack surfaces.
HackerOne research found that 70% of researchers now describe themselves as AI-native, leveraging AI tools to enhance their hunting abilities and accelerate testing, making it possible to identify risks and threats more efficiently than ever before. At the same time, AI adoption across industries is surging. In the past year alone, the number of AI systems included in security testing grew by 270%.
The stakes have never been higher, and human expertise remains as crucial as ever. Cybersecurity Awareness Month is no longer just about spotting phishing emails or practicing online safety. It is about preparing for a future where human creativity and AI work side by side to secure the internet.
++
Averell Gatton, Director of GenAI, Protegrity
Generative artificial intelligence has entered widespread enterprise adoption, but its security architecture remains underdeveloped. Large language models and multi-agent systems process substantial volumes of sensitive information. Their ability to accelerate research, automate decision workflows, and generate insights has expanded rapidly, yet the increase in functionality comes with a massive increase in attack surface from potentially jail broken agentic systems. In this context, data security has become an essential tool in the GenAI age.
Recent research underscores the scale of these concerns. Enterprises are reacting by blocking 18.5 percent of AI and machine learning transactions, a 577 percent increase over a nine-month period, according to Zscaler. This pattern illustrates growing caution as many companies adopt defensive measures in the absence of formalized AI governance policies.
Security integration into the development pipeline is emerging as an essential ingredient in production AI systems. Techniques such as field-level encryption, tokenization, and privacy-preserving design allow rapid development of AI systems while reducing exposure of regulated data. Embedding protection at every stage of the model lifecycle provides a foundation for building systems that are both operationally useful and compliant with regulatory standards.
Cybersecurity Awareness Month highlights how rapidly the balance between innovation and protection is shifting. The effectiveness of AI technologies will increasingly depend on whether security is treated as an inseparable part of their design.
++
Richard Bird, CSO, Singulr AI
Cybersecurity Awareness Month should be much more than a reminder about phishing emails. In 2025, awareness should mean visibility into how employees are actually using AI, guardrails and security controls to keep autonomous systems from running amok, and promoting a culture that balances responsible decisions with innovation.
The details on why these steps matter are in the data: the 2023 Verizon DBIR found that 74% of breaches still involved the human element, 83% involved external actors, and 95% were financially driven.
Traditional awareness programs haven’t gone far enough to shift those numbers, and now the risks have increased exponentially. Agents that can act at machine speed, combined with employees adopting AI tools without oversight, means that small mistakes can turn into significant exposures at velocities and volumes we’ve never experienced before.
Awareness can’t stop at PowerPoint slides and click-through training exercises. Organizations need modern governance and oversight that adapts to how work is being done inside their organizations today, particularly with AI in the mix. Without it, we’ll continue to recycle the old approaches while the risks continue multiplying faster than we can respond.
++
Lynsey Wolf, Investigations Manager, DTEX
AI continues to fuel insider threats, making it harder for organizations to detect and deter threats before they become attacks. At its worst, we’re tracking nation-state actors that leverage U.S. organizations to funnel salaries back to fund their weapons programs, as seen in the ongoing threat of DPRK groups, which infiltrate companies by having operatives secure high-paying remote IT jobs.Developers and security teams should watch for behavioral red flags: unusual login patterns, long session times, abnormal hours), non-work related activities on corporate devices (i.e. access to crypto sites, unauthorized AI tool use), job searching combined with elevated access, and misuse of AI tools by uploading sensitive data. Threat actors are using AI to enhance these attacks through improved social engineering, enabling them to ace interviews, and by acting as a “technical equalizer,” allowing non-technical bad actors to execute sophisticated attacks.Now, more than ever before, organizations must recognize cybersecurity as a human behavior problem. Effective insider risk management requires cross-functional collaboration between security, HR, legal, and forensics teams, focusing on proactive behavioral monitoring rather than just reactive incident response.
++
Mike Baker, CISO, DXC Technology
As organizations confront the complexities of escalating cyber threats, they need people with the right skills to protect their data and systems.
The global cybersecurity skills gap is widening, leaving many organizations vulnerable to increasing cyber threats.
Companies can broaden the candidate pool by bringing junior candidates into the fold and growing them with on-the-job training. This can include candidates who might not have the specialized skills required, but come with analytical potential, problem-solving skills, and technical promise. And by providing proper training to existing employees, organizations can empower them with career mobility and to become the first line of defense against potential threats.
In addition, AI and machine learning can work as a force multiplier for smaller security teams, which gives organizations a better chance against the newest strains of malware.
++
Chaim Mazal, Chief AI & Security Officer (CAISO), Gigamon
As adversaries weaponize AI to evade detection, security leaders must respond with equal force. The priority now is twofold: to gain real-time visibility into the growing volume of AI-driven network traffic and to establish clear governance over how AI is adopted within the enterprise. As AI workloads expand, CISOs are grappling with rising data volumes, hybrid cloud complexity, and visibility gaps that leave organizations exposed. Many are now turning to packet-level data paired with metadata as the foundation for restoring visibility, strengthening defenses, and ensuring AI tools operate on trusted information. This month is a reminder that the role of security leaders has shifted. We are now responsible for both defending against AI threats and guiding its safe, strategic use across the business.
++
Georgeo Pulikkathara, CIO& CISO at iMerit
Cybersecurity is about safeguarding the critical pillars of our national infrastructure. Medical systems that deliver care, agricultural supply chains that feed our people, and mobility networks that facilitate commerce cannot afford to be compromised. Building a cyber-strong America means embedding resilience into every sector that Americans rely on daily.
The future of our cybersecurity infrastructure depends on how quickly we can integrate AI responsibly: pairing machine speed with expert human judgment, embedding AI into security operations, and ensuring transparency and governance in its use. AI is now both our greatest risk and our greatest opportunity. Threat actors are already using generative AI to automate phishing, accelerate reconnaissance, and exploit vulnerabilities at scale. The U.S. has seen ransomware surge nearly 150% in the past year, with AI-driven tactics fueling much of that growth. At the same time, AI offers unprecedented capabilities in defense, from real-time anomaly detection to automated response and resilience building. A proactive stance ensures both compliance and trust, paving the way for responsible AI innovation.
++
Ram Mohan, Chief Strategy Officer, Identity Digital
The growth of e-commerce has unlocked incredible opportunities, connecting people and businesses around the world like never before. With rapid expansion, new challenges naturally arise, such as the increase in fake online shops that can erode consumer trust and impact legitimate brands. The encouraging news is that solutions to address these challenges are evolving just as quickly.
Cybersecurity Awareness Month serves as a timely reminder that as the internet evolves, so do our defenses, and we have the ability to adapt and strengthen them. Domain registries play an important role in keeping the digital ecosystem safe, though their impact is often underestimated. This year, 76% of security leaders reported they are only “somewhat confident” in mitigating domain attacks. By investing in preventative technologies early, businesses can create a secure foundation for their brands online. One of the most effective strategies is stopping harmful domains before they’re ever registered. Services like the Domains Protected Mark List (DPML), combined with trusted notifier partnerships, empower organizations to act quickly and decisively, preventing cybersquatters from claiming brand-matching domains. This kind of proactive shield makes brand protection both simpler and more powerful. Ultimately, domains are more than web addresses. They’re the cornerstone to secure, trusted online experiences. By working with reliable registries and taking advantage of preventative tools, organizations can build confidence, protect their reputation, and help create a safer, more connected internet for everyone.
++
Carl D’Halluin, CTO of Datadobi
Cybersecurity Awareness Month is a powerful reminder that protecting data isn’t just about firewalls, it’s about having a company data strategy. Every organization should maintain a ‘golden copy’, a secure, immutable backup that defends against ransomware and data loss. But that’s just the start. With data flowing from every corner of the business, often in silos, visibility is critical. You can’t protect what you don’t know exists. By investing in intelligent data management and building a strategy that helps you discover, classify and govern whilst remaining compliant, organizations can reduce risk and build true resilience.
++
Darryl Jones, Vice President of Consumer Segment Strategy, Ping Identity
With only 23% of consumers feeling very confident in their ability to determine whether something is legitimate or a scam, and 39% citing AI-driven phishing as the modern scam that concerns them most, it’s clear that people feel increasingly vulnerable online. The rise of AI-powered scams makes it harder than ever for the average person to distinguish fact from fiction, creating a dangerous gap in trust that bad actors are eager to exploit.
To counter this, organizations must move beyond traditional defenses and leverage the powerful combination of biometric authentication and verifiable credentials. These technologies give people the tools to quickly and securely prove who they are, while ensuring businesses can validate trust at every interaction. By putting identity at the center of our digital lives, we can dramatically reduce the success of scams and take meaningful steps toward creating a more secure digital world.
##






