According to the Palo Alto Networks 2026 Global Incident Response Report, attack speeds increased 4-fold with growing complexity as attackers increasingly target multiple surfaces simultaneously. Attackers are moving fast, exploring more paths, and blending into normal activity. Defenders are drowning in tool sprawl, identity risk, and an expanding universe of human-plus-machine accounts.
This year demands awareness that can curb these numbers. To address this, we will be sharing insights in a two-part series. The experts below explore this new reality from every angle: identity security, AI governance, ransomware resilience, operational hardening, digital exposure, agentic risk, and the widening gap between cyber awareness and true cyber readiness. Their perspectives present a practical, unvarnished look at what organizations must confront, and what they can do today to build resilience that lasts beyond October.
Addressing Tool Sprawl
Organizations need to confront an uncomfortable reality this Cybersecurity Awareness Month: despite having more security tools than ever, have they actually reduced their risk of a cyberattack? Tool sprawl is flooding security teams with disconnected findings, making it harder to determine what vulnerabilities matter. Treating each as equally urgent only compounds the problem, slowing down remediation and burning out practitioners.
As attackers use AI to move from discovery to exploitation faster, organizations need a unified view of exposure that connects severity with exploitability, asset criticality, existing controls and business impact. This context allows teams to identify the risks most likely to cause harm and act before attackers do. Trying to close the most tickets is a losing game in the AI era. Organizations must measurably reduce their most consequential risks. That is the only way cybersecurity awareness translates to meaningful and sustained resilience.
Dan DeCloss, Founder, PlexTrac
Looking at the Readiness Gap
While organizations might be more cyber aware than ever, far fewer are cyber ready. 87% of organizations claim their identity security posture is prepared to support AI automation at scale, yet nearly half (46%) admit their identity governance around AI is deficient.
This readiness gap becomes more consequential as AI moves from generating outputs to taking action. While initial AI concerns were focused on hallucinations and generating incorrect info, now we’re seeing AI agents use enterprise access to act independently on that flawed data, exacerbating existing excessive permissions issues. But initial identity vulnerabilities are only part of the problem. The OpenAI/Hugging Face incident demonstrates how unexpected agent behavior can quickly turn into real-world consequences.
2 in 3 organizations admit that when security requirements conflict with business speed, they are not consistently enforced. However, AI makes both automation and attacks faster, meaning organizations cannot afford to treat security as a backseat-discipline in their pursuit of speed. Security awareness must move beyond human users and include AI and machine identities with real enterprise access. In practice, this means scoping all agent access as temporary and task-specific, and authorizing agent permissions at runtime rather than treating access as a one-time decision.
Frank Vukovits, Chief Security Scientist, Delinea
Identity Security to Think About
Identity security cannot end when a user successfully logs in. Stolen credentials, compromised vendor accounts, and excessive permissions can give an attacker legitimate-looking access to highly sensitive information. Organizations should combine multifactor authentication with least-privilege access, role-based permissions, expiration controls, detailed activity records, and rapid access revocation. Sensitive documents should be shared through controlled environments rather than ordinary email attachments or unrestricted links.
Security teams should also treat external collaboration as part of their identity-risk program. During transactions, audits, and other cross-company projects, access requirements change quickly as participants and responsibilities evolve. Companies should regularly review who can see each category of information, restrict downloading where appropriate, and monitor unusual viewing or sharing behavior. The practical objective is not merely confirming who someone is, but continuously limiting what that identity can do and preserving an audit trail when activity must be investigated.
Greg Brinson, CEO, CapLinked
Working Login Incidents
Many incidents I hear about now involve someone who got in with a working login. A contractor’s password turns up for sale on a forum, or a laptop gets left unlocked in the back seat of an Uber. An employee gives two weeks’ notice and still has a company machine during the return window. None of these produce an alert, because to the system they still look normal. It’s an uncomfortable realization, since the standard answer to data risk has been encryption, and encryption assumes the wrong adversary. Full-disk encryption protects a powered-off device from a thief, but it does very little against a legitimate session.
Businesses that weather these situations tend to have layered encryption managed above the operating system, meaning protection that travels with the data instead of stopping at the disk. Files stay unreadable after they’ve left the building. A departing employee’s access ends the day their employment does, on the hardware itself, whether or not the laptop ever comes back. Here’s a question to put in front of your team during October. If a laptop walked out the door tomorrow with a valid login on it, how long would it take to cut that machine off from anything sensitive, and would you need the device in hand to do it?
Cam Roberson, VP, Beachhead Solutions
Refining Your Awareness Training
If your awareness training still teaches staff to spot phishing by its spelling mistakes, it is training them for a threat actor who no longer exists. Gen AI writes flawless, on-brand emails in any language, and voice cloning means the “CFO” on the phone asking for an urgent payment sounds exactly like the CFO. The attacks we see in engagements now are clean, personalised, and aimed at identity: a convincing MFA reset request to the service desk, a fake SharePoint login that captures the session token, a supplier “changing bank details” from a genuinely compromised mailbox. The question for staff is no longer “does this look wrong?” but “is this request normal, and have I verified it through a channel the sender does not control?” Awareness plans built around red flags need rebuilding around verification habits: call back on a known number, never approve an MFA prompt you did not start, and treat any change to payment or access details as suspicious by default, however polished it looks. The second problem is treating October as the awareness season. One month of posters and a quiz turns security into an annual event, and staff learn that it is something that happens to them once a year rather than something they are accountable for every day. The organisations that get this right run short, frequent touchpoints tied to real work: a two-minute debrief when a phishing attempt hits the business, recognition for the person who reported it, and service desk scripts that make identity checks routine rather than awkward. Use Cybersecurity Awareness Month to relaunch the programme, not to deliver it. If the only time your people think about security is October, attackers have the other eleven months to themselves.
Harman Singh, Director, Cyphere
The Identity Risk Hiding in The Way Work Gets Done
During Cybersecurity Awareness Month, I’d challenge IT leaders to ask a different question: *If a trusted employee’s account were taken over tomorrow, what could an attacker do before anyone noticed?* The answer often lives outside the security dashboard. A shared login may keep a field team moving. A former contractor may still have access because no one owns the offboarding step. An AI tool may have been connected to company data by someone trying to solve a real problem. Each decision made sense to the person making it. Together, they reveal how the organization actually operates. At BISBLOX, our DNA approach examines a business across its technology, team, product, market, financials, and needs. I’d apply that same lens to identity security: trace a few critical workflows from start to finish, identify who and what can access each system, then test whether those permissions still match the work. The resulting story would give CISOs and MSPs a practical way to find identity risks that an annual training campaign or access report can miss, and to fix the business conditions that keep recreating them.
Shawn Riley, Co-Founder, BISBLOX
Stolen Credential Breaches
Most breaches this year didn’t start with malware, they started with a valid login. As an Information Security Analyst working in threat intelligence and threat hunting, I keep seeing the same pattern: attackers aren’t breaking in anymore, they’re logging in, using stolen credentials, session tokens, or compromised service principals that never trigger a traditional alert. AI agents make this worse, as most are authorized through the same shared service accounts or static API keys teams have used for years, so an agentic login shows up in the logs looking exactly like routine service account activity, with no way to tell whether it was the agent, a script, or a person behind it. For Cybersecurity Awareness Month, I’d like to pitch a piece on why identity has quietly become the primary battlefield, and what actually works to catch it, like watching for anomalous sign-in patterns in Entra ID and AAD logs, scoping down service principal permissions, and treating every authentication event, human or agentic, as something that needs its own identity and its own audit trail. The second angle I can include, if useful, is aimed at MSPs on how the same identity-based tactics scale across client environments, and why credential hygiene is usually the highest-leverage fix a security team can make this quarter.
Shubham Paikrao, Information Security Analyst, EXL
Confirming Requests
Most identity-driven attacks do not look like attacks. They look like Tuesday. A message from a senior name, a supplier asking to update bank details, a Teams message that sounds right, a voice note that sounds like the boss. The person on the other end is not making a security decision. They are trying to finish a task before lunch. That is why “watch out for scams” is such weak advice. For Cybersecurity Awareness Month, IT leaders and MSPs should build one simple habit into the moments that matter: if a request involves money, access, sensitive data or unusual urgency, confirm it through a second channel before acting. A call to a known number, a message in a different app, a word with someone in person. It is not sophisticated, but it targets the exact point where most of these attacks succeed: a believable request, at a bad moment, handled by someone doing their job.
Sandor Lachazi, Founder, SmartSec Academy
Identity as an Operational Security Control
Cybersecurity Awareness Month is a good time to move beyond “use strong passwords” and focus on identity as an operational security control. In real-world incident response, some of the hardest compromises to contain aren’t driven by an exotic zero-day — they come from attackers using valid administrator credentials, inherited access, or over-privileged accounts that were never reviewed. Once an attacker operates as a legitimate admin, they can often install plugins, change configuration, create persistence, and blend into normal application activity. Practical controls are straightforward, but they need to be continuous: require MFA for privileged users, remove stale accounts, enforce least privilege, review active sessions, rotate credentials after incidents, and monitor authentication and administrative activity for anomalies. Identity hygiene should be treated like patch management — as an ongoing operational process, not a once-a-year checklist.
Stefan Ristić, WordPress Security Engineer, TLDWP
Doing Your Due Diligence For Password Protection
In short, keeping your password and credentials safe has become the most crucial issue in recent years, and yet companies are only auditing them in three months’ time, according to Excel sheets. During my observation of hacks this year, I noticed that hackers were not doing anything special to hack companies. The hackers stuck to things such as: an account of a contractor which was not disabled though the person left two years ago, a super account which has never been audited, a person clicking “yes” in the middle of the night because he or she was tired of alerts, or a password being the same across several computers. A new issue has emerged with robots and AI systems, as the devices possess passwords that were created with excessive privileges during the testing phase and remain unchanged during the live operation. As a result, these robot accounts are sometimes more than human accounts in many organizations without any checks performed. In a scenario where a hacker manages to obtain a key to a robot, it opens doors to all internal systems with no password change or security checks required at any instance. The solution should be obvious: you should only give people and robots access when they need it. Make an inventory of all accounts that can log in: user accounts, robot accounts, any API keys – basically everything – and make sure there is a person who actually owns each account. If nobody owns an account, then nobody will disable it. Always create temporary passwords instead of permanent ones. For accounts with sensitive data, configure better security features like physical keys instead of just tapping “approve” on your phone. Set expiration dates for accounts that can be accessed by contractors and test users from the beginning. This work should be done every three months by a company that manages the assets of other organizations. It’s a boring job, but that is why companies spend money on security alarms rather than fixing the locks.
Stanislav Kazanov, Head of GRC, Cybersecurity & Sustainability, Innowise
Asking Who and What Can Actually Do What Across Your Linux Estate
Most Awareness Month advice is still written for people: use a password manager, turn on MFA, don’t click the link. Good advice, for a minority of your identities. Machine identities now outnumber human ones 109 to 1, according to Palo Alto Networks’ 2026 Identity Security Landscape report, and they never attend the training, can’t be phished and never hand in their notice. An identity programme can look complete at the directory level and still leave gaps on the Linux hosts that run payments, trading and core infrastructure, where the identities that matter live outside the directory: local service accounts, long-lived SSH keys, sudoers rules, credentials with no clear owner.
Most organisations now have an AI policy that says no, or not much. Most also have a curious engineer, or someone with a deadline and a tutorial, who launches an agent anyway. That agent runs with whatever access its launcher has. If the engineer’s rights are too broad, the agent’s are too, and in every log you own the agent is the engineer. Few have anything in place that can tell the two apart. So, this October, ask one practical question: who and what can actually do what across your Linux estate? Pull the accounts, keys and privilege rules into one view and give each one an owner and an expiry date. For anything nobody can account for, check what depends on it before you remove it, because something usually does. If an MSP runs the estate, ask for the list, not the report. Unglamorous work, and the whole difference between the access your identity policy describes and the access that really exists.
Peter Cummings, Founder & CTO, LinuxGuard
Don’t Make It Easy For Them
Cybersecurity Awareness Month is usually a reminder to get the fundamentals right and that is still absolutely critical. This year, however, the National Cybersecurity Alliance has adopted the theme, “Don’t Make It Easy for Them,” and that message should also prompt organizations to look at a growing source of risk: artificial intelligence (AI).
As organizations and individuals adopt AI, we need to remember that AI is not just another technology. It has the potential to be transformational. It can hold accounts and permissions, see whatever you give it access to and take actions on your behalf. Many organizations and individuals have never considered the implications of these actions.
So, as the world embraces AI, we must determine three things before access is granted: what it can see, what it can do and who is responsible for it. And we also must remember that, in many cases, AI appears even when we never chose it. It’s in the tool approved three years ago that quietly shipped an AI-infused update, the browser extension or the application add-in. Some AI adoption arrives without a decision, and the things nobody decided on are the things nobody is watching.
“Don’t Make It Easy for Them” is the right tagline for this year. For organizations, that means adopting AI in a pragmatic, secure and responsible manner. For individuals, it means 10 minutes in your settings. Neither is hard. Both are overdue for many.
Jack Cherkas, Global Chief Information Security Officer, Syntax
More Security News
Related News:
Cequence Launches Agent Trust to Detect and Control AI Agents