We hope our Cybersecurity Awareness Month Part 1 article gave you insights you can apply to your security practices. Read below for our ongoing cybersecurity advice from industry experts.
Who’s Fixing It? Is It Actually Fixed?
Every October, Cybersecurity Awareness Month tends to focus on phishing simulations, password health checks, and how to protect your personal privacy. These are not bad areas to focus on because people click on things, and training helps. But security teams have an awareness gap of their own, and a big chunk of it is sitting in the backlog. Many companies run an annual pen test, fix a few of the findings they deem most critical and let everything else wait for next year’s test to find it again. Severity alone will mislead you, too. A critical issue on a staging server that maybe three engineers could access is not as severe as a medium finding on a customer-facing login portal with a public proof of concept. Sorted by CVSS and the staging server wins…but any attacker would have picked the login portal in about five seconds. Every finding comes down to two questions. Who’s fixing it, and is it actually fixed? A ticket marked resolved means someone has implied it’s fixed. Back in my testing days we’d routinely find closed items still wide open, or exploitable using a different technique.
So for this October’s awareness focus, try two things. First, pull up the oldest open critical finding and trace why it’s still open. It’s usually an ownership question nobody settled. Second, have someone retest a handful of recent remediations. Everything in your backlog is already paid for and written up, and working it down is how you win the right battles.
Dan DeCloss, founder and CCO at PlexTrac
Working Effectively Alongside AI
Cybersecurity Awareness Month gives organizations an opportunity to reflect on how cybersecurity is changing and whether we are adequately preparing people for what comes next. Attackers are getting better at using compromised credentials and legitimate access to move through organizations, while AI is increasing the speed and scale at which they can operate.
For security teams, this puts even more emphasis on understanding how an attacker thinks, spotting unusual behavior early and knowing what to do when an attack is already underway. AI will increasingly become part of that work too, with practitioners working alongside it to investigate, respond and make decisions faster. As roles evolve, people need regular opportunities to practice against the kinds of situations they will face, make decisions for themselves, and learn from what happens. That experience builds the human judgement, creativity and attacker mindset practitioners need to work effectively alongside AI and strengthen their defenses as threats continue to evolve.
Haris Pylarinos, Founder and CEO, Hack The Box
Ransomware Attacks Are Quietly Surging
This Cybersecurity Awareness Month, everyone is understandably very concerned about AI risks. But there’s another significant cybersecurity threat that is being overlooked: Ransomware attacks are quietly surging and hitting critical sectors like healthcare and utilities, and it’s getting harder for organizations to recover.
The stakes are higher than ever for unprepared companies, who often don’t have sufficient visibility and control over their IT environments, especially with the addition of AI agents. Deploying AI responsibly means working with the right partners, ones who think of security as a key part of the integration from the beginning, not an afterthought or add-on. In most cases, this means deploying non-human identify governance, a zero-trust architecture, and strict network micro-segmentation.
Dan Lohrmann, Field CISO, Public Sector, Presidio
Can Your Organization Recover?
In 2026, the cybersecurity conversation needs to move beyond whether an organization can prevent an attack to whether it can actually recover from one. Ransomware is increasingly testing the systems businesses depend on after an attack, yet there is still a major gap between knowing what good cyber resilience looks like and putting it into practice. A majority (93%) of technology leaders believe backup storage should remain protected even if administrative credentials are compromised, but only 16% have implemented storage with Absolute Immutability.
Arguably more important than the business repercussions, the preparedness gap is taking a significant toll on the people responsible for protecting them. Our latest research found only 37% of IT and security professionals are confident they could completely recover their company’s data after a ransomware attack, while 91% report being uncomfortably stressed at work over IT security risks. This Cybersecurity Awareness Month, organizations need to recognize that cyber resilience is also about giving IT teams the confidence, tools and support to respond when an attack happens. Simplifying recovery, protecting backup data from modification or deletion, and regularly testing recovery plans can reduce uncertainty for the people on the front lines while making the business more resilient. The goal isn’t just to survive an attack, but to know that the business and the people responsible for its recovery are prepared when one happens.
Anthony Cusimano, Solutions Director, Object First
The Scale Of Cyber Defense Is Fundamentally Changing
While some in the industry might argue that Cybersecurity Awareness Month is a silly or made-up thing, in reality, it should be a wake-up call that the scale of cyber defense is fundamentally changing. Security teams are already overwhelmed by alert volume. At Virgin Money, for example, they’d accumulated roughly 50,000 security alerts despite having a security organization of around 200 people. With agentic automation, their team was able to work through a huge portion of alerts in under two months, reducing its backlog by more than 60%.
Now consider what happens as attacks become fully agentic. Instead of moving sequentially, agentic attacks can create tens of thousands of uncorrelated alerts simultaneously across identity, email, endpoints, network and other domains. The challenge is deciphering how those seemingly disconnected signals fit together, particularly when the security teams responsible for them operate in separate silos.
That breaks the traditional security model. We can’t keep telling defenders to tune detections until they find the needle in the haystack when attackers can increasingly manufacture the haystack on demand.
The answer is giving defenders the ability to investigate, correlate and act at machine speed. Security organizations need to break down domain silos and begin aggressively experimenting with agentic defenses now. As attackers embrace automation, defenders will need automation of their own to keep pace.
Ely Abramovitch, co-founder and CEO, Legion Security
Hardening: Going Through Credentials With A Fine-Toothed Comb
Attackers who get into a Microsoft 365 or Google Workspace tenant today often don’t need the password. They put a fake login page in front of the real one and steal the session token after the user signs in, or they trick a user into approving a third-party app that asks for access to mail and files. Push-notification MFA stops neither. So use October on one small project to prove out a substantial change for hardening. Move the accounts that can change everything, meaning global admins and any account your MSP uses to get in, onto phishing-resistant sign-in with hardware security keys or passkeys. That is far less work than a company-wide rollout, and it covers the accounts an attacker wants most. Then look at what is already connected and verify. Pull the list of third-party apps that users have granted access to mail and files, and remove anything nobody can explain. In the same pass, turn off user consent for new apps so an admin has to approve them. Standing admin rights will require the same review. An admin role that gets used twice a month should be requested when needed and expire afterwards, rather than sit on someone’s everyday account. Give one named person ownership of this review and repeat it every quarter; there is no need for new tools.
Marcus Tommy, Co-founder, MALTO Cyber
AI is Changing Assumptions Security Programs Were Built Around
This Cybersecurity Awareness Month, it’s becoming clear that AI is changing some of the assumptions security programs were built around. AI systems can operate across applications, data and team boundaries, while attackers can use the same technology to move faster and explore more paths into an organization. Security teams need to understand not only individual weaknesses, but how those weaknesses connect and what an attacker could do with them.
As AI becomes more capable, human expertise becomes more valuable, not less. AI can give defenders greater speed and coverage, but that puts an even greater premium on the context and judgment needed to understand business logic, anticipate attacker intent and decide how to respond. The advantage comes from pairing that scale with people who can interpret what they’re seeing, think like an attacker and turn those insights into action.
Nabil Hannan, Field CISO, NetSPI + Synack
The Danger Of Digital Exposure
The more an attacker knows about a target, the less the interaction feels like an attack. That’s what makes digital exposure so dangerous.
Credentials, personal details, professional information, breach data, and data-broker records accumulate over time. Attackers can use that information to identify the right person, build a credible pretext, and approach them through a channel or identity they trust. They don’t need to know everything. They just need to know enough to sound legitimate.
Verizon’s 2026 Data Breach Investigations Report found that the human element was involved in 62% of breaches. And the email inbox isn’t the only way in. In Verizon’s simulation data, mobile-based phishing (voice and SMS) drew 40% higher engagement than email phishing. That’s why cybersecurity awareness has to go beyond spotting suspicious emails.
Organizations need to understand how much of their people’s information is exposed online, and reduce it. They need to strengthen identity-verification processes. And they need to prepare employees for phishing, vishing, and impersonation attempts from attackers who may already know a surprising amount about them.
Ben Skean, Director, Cyber Threat Intelligence, 360 Privacy
Update Your Picture of The Attackers
Cybersecurity Awareness Month is a good moment to update our picture of the attackers. They now use AI to explore applications the way a pentester would: logging in, mapping what each user can reach, and trying what they shouldn’t. What they find is rarely exotic, just an API that accepts a valid token and returns someone else’s data (what is generally classified as a BOLA, a broken object level authorization). Scanners miss it, and an annual pentest checks it once while the code changes daily. The defense is the same technology pointed the other way: AI pentesting on every release, so you find the broken authorization check before someone else’s agent does.
Antoine Carossio, CTO at Escape
Shifting From Targeting Vulnerabilities to Trust
Cybersecurity is entering a new phase. For years, security teams have fought a software war: patching vulnerabilities, hardening systems and keeping attackers out. AI will increasingly help close that window by making software more secure by default. But as software defenses improve, attackers will shift toward a harder target: trust. The next wave of attacks will be less about exploiting code and more about exploiting confidence, convincing a human or AI agent that something is legitimate when it is not.
We are moving from a software war to a trust war, where AI makes deception faster, cheaper and harder to detect. As AI agents begin acting on behalf of people and organizations, security teams will need to verify not just devices and credentials, but the people, entities, websites, services and information those agents interact with. Verification can no longer be an afterthought. Security teams need an internet where authenticity is machine-readable and identity and behavior can be continuously verified, giving humans and AI agents the signals they need to detect deception before it becomes an attack.
Alex Dhillon, CEO and Founder, Outtake
AI Agents Reshaping Risk
As organizations deploy AI agents, agents become another identity with access to your systems and data. Traditional automation follows a fixed set of rules and steps to reach a known outcome. With agents, you give them a goal, and they determine how to get there. Without explicit rules about what’s off-limits, agents can easily go rogue in the eye of a security team, ultimately widening an organization’s potential risk.
This Cybersecurity Awareness Month, we must recognize how dramatically AI agents have reshaped risk. Any external connection an agent can reach is now part of the attack surface. Whatever resources, systems, and data the agent doesn’t need to complete its task, it shouldn’t be able to reach. Begin with a ‘deny all’ mentality and carefully enable access from there only as needed. Then test your controls for efficacy, continuously. Knowing a control exists isn’t the same as knowing if it would stop a major breach.
Todd Humphreys, Cybersecurity GTM Leader, WEI
Confronting the Recovery Gap
Frontier AI models have given attackers unprecedented speed and scale. Enterprises are now forced to move beyond asking if they will be breached to preparing for when it happens. The most damaging window can open immediately after intrusion, when attackers target sensitive data and the recovery infrastructure organizations depend on during a breach. Sophisticated adversaries increasingly recognize that disrupting recovery can be as damaging as the initial breach itself.
This new reality is forcing enterprises to confront the recovery gap. Boards want to know when critical operations will be back online, and “weeks” is no longer an acceptable answer. Getting recovery down to hours or days requires preparation work long before an incident occurs: continuously validating recovery readiness and preserving a healthy-state blueprint of the entire environment outside an attacker’s reach. It also means eliminating handoffs and communication gaps between security, IT, legal, and communications that can cost organizations valuable time during and after an incident. Breach recovery is not solely a security function; it is an enterprise capability that requires teams to work from shared, trusted information about the incident and recovery.
IT and Security teams need to emphasize individual vigilance, prevention techniques, and vulnerability patching. But awareness must also extend to organizational readiness. Enterprises should regularly assume compromise, test their ability to respond and recover, and measure how quickly they can restore critical operations.
Ron Newman, Co-Founder and CEO, Cydelphi
24/7, 365 Days-a-year Security Awareness
I believe Cyber Awareness Month (CAM) is a valuable amplifier and another reminder about the importance we all play in an organization’s cybersecurity risk management program. However, it cannot be the strategy. If companies use CAM as another training module, then it’s just another compliance exercise.
Security awareness is a 24/7, 365 day a year operation. The goal for a CISO should be behavior change and reinforcement, not training completion. CISOs should use this month as an opportunity to reinforce the behaviors that employees should be practicing throughout all 12 months of the year.
They can do this by creating visibility and encouraging engagement as well as ensuring employees understand they are the front lines in cybersecurity. The strongest cyber cultures exist when employees see themselves as part of the security team. This month should reinforce that culture, not be a substitute for it.
Rob Gregory, CISO, Optiv
Protecting and Ensuring Data Availability
Over the last year, cyber risks have increased as AI capabilities have become more sophisticated, giving threat actors new ways to identify vulnerabilities faster and launch attacks on a broader scale. At the same time, data governance is taking on greater importance amid sovereignty concerns and international regulations like DORA, NIS2 or GDPR. Protecting that data and ensuring it remains available and recoverable needs to be the top priority for any board or leadership team. This requires organizations to think beyond prevention and prepare for how they will maintain business continuity and recover trusted data when an attack occurs.
Octavian Tanase, Chief Product Officer, Hitachi Vantara
Staying on Top of an Evolving Security Environment
Cybersecurity awareness has spent years teaching people to spot phishing, use strong passwords and follow security policies. Those habits still matter, but the problem is that the environment around them keeps changing, and AI is making that happen faster. A finance team may be dealing with invoice fraud, HR may be handling sensitive employee information, engineers may be working with vulnerabilities in code, and defense teams may be dealing with increasingly complex requirements around sensitive data. Awareness is more useful when it reflects what people are actually dealing with day-to-day.
Security teams have to keep that same rhythm. They need to know where sensitive data lives, who can access it, what changed and what may have slipped through the cracks. A point-in-time assessment provides a snapshot, but it quickly goes stale. The more technology changes, the more important it becomes to keep checking, rather than assume yesterday’s picture still holds. That means treating security as something teams maintain continuously, not revisit periodically.
Security leaders need to work with AI firsthand to understand its capabilities and limitations. We’re moving from agents that answer a question to long-running agents that can work toward a goal for hours or even days, monitor their progress and adjust along the way. Leaders need to understand where that autonomy adds value, where it introduces risk, and when human intervention is necessary. That is much easier to judge after spending real time working with the technology.
Shrav Mehta, Founder & CEO, Secureframe
Applying Privileged Access To AI
AI is expanding the number of identities and access paths organizations need to secure. As these tools become embedded in everyday work, organizations should apply privileged access principles to any AI system that can access sensitive data or act on their behalf. That means granting only the permissions required for a defined task, defaulting to read-only access where possible, requiring human approval for consequential actions, and removing access when it is no longer needed. Organizations already face a privileged access gap, and AI is raising the stakes by adding more identities and access paths to govern. Recent Bitwarden research found that 84% of respondents rated securing privileged account access as extremely or very important, yet 55% said their organizations had no PAM solution in place.
Strong access controls still depend on securing the underlying identities and credentials. Human accounts should use phishing-resistant authentication such as passkeys where available, or strong, unique passwords stored in a password manager and protected by multifactor authentication (MFA). Machine credentials such as API keys and shared secrets should be tightly scoped, securely stored, rotated, and retired when no longer needed. Regularly reviewing connected applications and revoking unused access can help prevent a compromised account or overly permissive AI integration from becoming a much larger security incident.
Andrew Hartnett, Chief Technology Officer, Bitwarden
A Trust Problem Hiding in Plain Sight
Cybersecurity Awareness Month is a reminder that security starts with people, but the industry has a trust problem hiding in plain sight. Organizations are being told to verify identities, validate access and scrutinize third parties, yet when it comes to finding the people they trust with their most sensitive systems and security challenges, credentials and expertise can still be surprisingly difficult to validate.
As cyberthreats become more sophisticated, organizations spin up new products at extreme AI speeds and the demand for specialist expertise grows, we need to apply the same ‘trust but verify’ mindset to cyber talent and services that we apply everywhere else in security. Whether you’re hiring a professional or bringing in external support, knowing that the person on the other side has been properly verified should be the baseline. In an industry built on trust, we can’t afford to leave the people protecting us as an unchecked part of the security chain.
Laurent Halimi, CEO and founder, Cyberr and Heelr
The Gap Between Discovery and Remediation
Frontier AI models can now uncover vulnerabilities at enormous scale, yet our recent Road to AI in IT research found that 79% of organizations take more than a day to deploy critical security patches. That gap between discovery and remediation is only going to become more dangerous as AI capabilities accelerate.
This Cybersecurity Awareness Month, organizations should consider if they can actually keep pace with this new reality. AI can help defenders understand endpoint state, prioritize remediation and ultimately respond faster, but speed without control creates its own risk. The goal should be an operating model where AI can move quickly while changes remain visible, reviewable and reversible. In the AI era, good cyber hygiene is knowing what needs fixing and having the infrastructure to safely fix it before an attacker gets there.
Zach Wasserman, Co-founder, Fleet Device Management
Building Cyber Resilience into Infrastructure
Cybersecurity Awareness Month offers a valuable opportunity to reassess whether cybersecurity is keeping pace with AI adoption. As the technology becomes embedded across applications, networks and devices, IT environments become increasingly complex; making it harder to maintain visibility and control. This gap is growing within US businesses; while 39% of U.S. organizations piloting agentic AI say they’re prepared in risk, security and governance, a staggering 70% of U.S. leaders say they don’t feel they can adequately trust and govern AI agents.
Addressing this disconnect means building cyber resilience into infrastructure from the outset. Businesses need visibility across networks, applications and devices so teams can identify unusual activity and respond quickly when something goes wrong. But visibility alone is not enough. Security and operations teams need to work more closely together, sharing intelligence and context across the same infrastructure rather than operating in isolation. As AI becomes more distributed, this joined-up approach will be critical to maintaining control and supporting the technology securely at scale.
Frank Cotto, Field CTO of Infrastructure Management & Operations, Progress Software
Moving From Patches to Continuous Stewardship
To prepare for AI-driven risks of God-mode (a real term in AI dev) to control recently introduced agentic swarms, leaders must move beyond technical patches to a foundation of continuous stewardship, recognizing that the power to create autonomous agents carries a profound moral obligation to govern them with wisdom and prioritize a “human-in-the-loop” architecture that reflects the divine principle of accountability, ensuring no system operates without a designated steward to provide oversight and correction. Security protocols should emphasize sovereign containment and least-privileged access, treating sensitive systems as sacred trusts that require vigilant guarding against boundary-crossing because AI agents lack a moral compass and will deceive and steal when necessary to achieve goals. By implementing real-time oversight rooted in a commitment to truth and order, organizations can ensure AI serves as a tool for flourishing rather than a source of chaotic disruption, mirroring the theological principle that power without accountability leads to disorder.
Dr. David Utzke, CEO & CTO, MyKey Technologies
More Security News
Related News:
Cybersecurity Awareness Month Part 1