Cybersecurity Awareness Month 2026: Don’t Make It Easy For Them

OCTOBER 2026 CYBERSECURITY AWARENESS MONTHDo not make iteasy for themFour habits that stop most attacks ✓ Passwords✓ MFA✓ Scams✓ Updates

Short answer: October is Cybersecurity Awareness Month, and the 2026 theme is Don’t Make It Easy for Them. The idea is simple: attackers go for the easiest target, so build habits that make you the hardest. Here is what it means for a UK small business, and a four-week plan to put it into practice.

23rdAnnual campaignheld every October since 2004.
4Core habitspasswords, MFA, scams and updates.
>99%MFA blocks itof identity-based attacks, per Microsoft.
52%Money-drivenof attacks with a known motive were extortion or ransomware.

The four habits at a glance

1Strong passwordsLong, unique, stored safely2Turn on MFAAdmins and email first3Spot and report scamsPause, verify, then report4Update softwareSwitch on automatic updatesThe four core behaviours promoted by the National Cybersecurity Alliance

1. Strong passwords and a password manager

Make guessing pointless

Microsoft’s 2025 Digital Defense Report found over 97% of identity attacks are password spray or brute force.

Password spray / brute force
97%+
  • Use long, unique passphrases for every account, never reused.
  • Give everyone a business password manager so nobody has to remember them.
  • Check staff are not reusing work passwords on personal sites.

2. Turn on multifactor authentication

The single biggest win

Microsoft reports MFA blocks over 99% of identity-based attacks.

Identity attacks stopped by MFA
99%+
  • Start with email, Microsoft 365 and every admin account.
  • Prefer phishing-resistant methods such as passkeys or security keys.
  • Block old sign-in methods that skip MFA entirely. More in our Digital Defense Report briefing.

3. Recognise and report scams

AI has made scams more convincing

AI-automated phishing reached a 54% click rate against 12% for standard campaigns.

12%
54%
Standard phishingAI-automated phishing
  • Pause on anything urgent, and check unusual requests by phone.
  • Be wary of pages that tell you to paste a command to fix a problem.
  • Make reporting easy, and thank people who do.

4. Keep your software updated

Patch fast, retire what is unsupported

Cyber Essentials expects high and critical security fixes to be applied within 14 days.

  • Switch on automatic updates for operating systems and apps.
  • Prioritise anything facing the internet, such as firewalls and VPNs.
  • Replace software that no longer receives security updates.

Bonus: back up and test it

Your safety net against ransomware

Over half of attacks with a known motive are about extortion or ransomware, so recovery matters as much as prevention.

  • Keep a copy that ransomware cannot reach, such as an immutable or offline backup.
  • Test a restore, not just the backup job.
  • Write a one-page plan: who to call and what to do first.

A four-week plan for October

  1. Week 1: MFA. Turn it on for email, Microsoft 365 and all admins.
  2. Week 2: Passwords. Roll out a password manager and retire reused passwords.
  3. Week 3: Scams. Run a 15-minute phishing refresher and agree how to report.
  4. Week 4: Updates and backups. Check patching, remove unsupported kit and test a restore.

How this fits Cyber Essentials

These habits line up with the five Cyber Essentials controls: firewalls, secure configuration, security update management, user access control and malware protection. If you want proof for customers and insurers, see our Cyber Essentials FAQs or take the free readiness quiz.

Frequently asked questions

What is Cybersecurity Awareness Month?

It is an annual campaign held every October since 2004, led by the National Cybersecurity Alliance with the US Cybersecurity and Infrastructure Security Agency. It encourages individuals and businesses to adopt simple habits that make them harder to attack. 2026 is the 23rd year.

What is the 2026 theme?

The 2026 theme is Don’t Make It Easy for Them. The message is that security comes from consistent daily habits rather than one perfect decision, and that small actions multiplied across millions of people make life harder for criminals.

Is it relevant to UK businesses?

Yes. The campaign is US-led, but the habits are the same ones that UK guidance and Cyber Essentials are built on, and the threats are global. October is a good prompt for any UK business to review its basics.

What are the four core behaviours?

Use strong, unique passwords with a password manager, turn on multifactor authentication, recognise and report scams, and keep your software updated.

Where should a small business start?

Start with multifactor authentication on email and admin accounts, because it blocks the vast majority of identity attacks. Then roll out a password manager, run a short phishing refresher and check that updates and backups really work.

Sources: National Cybersecurity Alliance, Cybersecurity Awareness Month; Microsoft Digital Defense Report 2025; IASME Cyber Essentials guidance.

Your next step

Do not just read it. Act on it.

Reading is the easy part. Book a free IT review and we will tell you, in plain English, where your business stands and what to fix first.

Related guides and services

Scroll to Top
Free 3-minute quiz · No sign-up for your score

Is your team using AI you don’t know about?

Score your Shadow AI risk across policy, data, tools, people and detection, then get the three controls to fix first.

Take the Shadow AI Check10 questions · about 3 minutes