International Cyber Expo International Cyber Expo
  • About Us
Monday, 5 October, 2026
IT Security Guru
International Cyber Expo
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

by Lara Joseph
October 5, 2026
in Featured
Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability
Share on FacebookShare on Twitter

Every October, security teams roll out refreshed training, posters and phishing simulations. But according to Rob Gregory, CISO at Optiv, organizations that treat the month as the centerpiece of their awareness efforts are missing the point. “I believe Cyber Awareness Month (CAM) is a valuable amplifier and another reminder about the importance we all play in an organization’s cybersecurity risk management program. However, it cannot be the strategy,” he says. “If companies use CAM as another training module, then it’s just another compliance exercise.”

Rafael Narezzi, co-founder and CEO of Centrii, argues that the very definition of awareness needs to broaden. “For years, cybersecurity awareness has largely been framed around what employees should do differently – recognize phishing attempts, strengthen passwords and avoid suspicious links,” he says. “Those habits still matter, but today’s threat environment requires a much broader definition of awareness.”

Sandhya Arun, Chief Technology Officer at Wipro, reads this year’s theme in the same spirit. “This theme of this year’s Cybersecurity Awareness Month, ‘Don’t Make It Easy for Them,’ is not just a call for greater awareness, but a call to build consistent, day-to-day habits that make life difficult for cyber criminals. This applies to both individuals in their personal lives and to organizations.”

From completion rates to behavior change

For Gregory, the metric that matters is not how many people finished a course. “Security awareness is a 24/7, 365-day-a-year operation. The goal for a CISO should be behavior change and reinforcement, not training completion,” he says. “CISOs should use this month as an opportunity to reinforce the behaviors that employees should be practicing throughout all 12 months of the year.”

“They can do this by creating visibility and encouraging engagement as well as ensuring employees understand they are the front lines in cybersecurity,” Gregory adds. “The strongest cyber cultures exist when employees see themselves as part of the security team. This month should reinforce that culture, not be a substitute for it.”

Narezzi agrees that people should be treated as an asset rather than a liability. “This Cybersecurity Awareness Month, we should move beyond treating awareness as an annual training exercise. True cyber resilience requires continuous asset visibility, carefully controlled access, clear supply-chain accountability and incident-response plans that are regularly tested,” he says. “People should not simply be labeled the weakest link; they should be equipped to become an active layer of defense.”

When cyber risk is operational risk

Narezzi’s perspective is shaped by critical infrastructure, where the consequences of an attack look very different from a typical data breach. “In critical infrastructure, cyber risk is operational risk. A compromised battery storage system, renewable energy site or remote-access connection may not produce the warning signs of a conventional data breach,” he explains. “Instead, the consequences can appear as lost generation, unstable operations, reduced availability and direct financial loss.”

That means awareness has to extend beyond an organisation’s own walls. “As energy infrastructure becomes more distributed and interconnected, organizations need visibility not only into their own environments, but also into the vendors and technologies on which their operations depend,” he says.

It also means helping leaders focus on what matters. “Organizations have too many alerts and too little context,” Narezzi warns. “Leaders must be able to determine which exposures could disrupt operations, how much capacity or revenue is at risk and which action will reduce that risk first.”

Cyber agility as an organizational capability

Arun notes that AI is reshaping both sides of the contest. “As AI becomes more widely adopted, attackers and defenders alike are gaining access to new capabilities. AI-enabled techniques can automate reconnaissance, generate convincing content, and increase the scale at which cyber operations are conducted,” she says. “For organizations, this raises the imperative to strengthen detection and response, reducing the time between identifying a threat and acting on it.”

Crucially, she cautions that AI is not a silver bullet. “At the same time, no one can safely assume that every attack can be prevented. AI will strengthen cyber defense, but it will not make organizations breach-proof,” Arun says. “‘Don’t Make It Easy for Them’ therefore requires organization-wide systems to focus on both prevention and resilience. The defining capability is cyber agility: the ability to detect compromise early, contain its spread, recover quickly, and adapt from the event.”

Achieving that, she argues, depends on getting the balance between automation and people right. “The strongest cyber defense combines machine speed with human judgment. Organizations need clear policies that define the role of automation, establish decision rights, and preserve accountability,” she says. “Cyber awareness must be embedded into the organizational operating model, linking workforce behavior, technology, and response. Ultimately, cyber agility is not just a security objective; it is an organizational responsibility spanning architecture, operating models, and governance.”

Everyone has a role

Narezzi believes awareness only becomes meaningful when it reaches every level of an organization. “Cybersecurity becomes meaningful when everyone – from operators and engineers to executives and boards – understands both their role and the real-world consequences of inaction.”

Arun leaves leaders with a clear call to action. “The imperative for leaders is clear: make cyber agility an organizational capability,” she says. “Cybersecurity Awareness Month shines a spotlight on cyber risk and demands attention, but it does not create resilience. Resilience is built every day and will be tested when an organization can least afford to fail.”

ShareTweet
Previous Post

A familiar face is no longer proof: rethinking social engineering defence for the deepfake era

Next Post

Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access

Recent News

Q&A With Oliver Simonnet at CultureAI: AI Security In 2026: Most Organisations Deploy AI And Hope For The Best

Q&A With Oliver Simonnet at CultureAI: AI Security In 2026: Most Organisations Deploy AI And Hope For The Best

October 5, 2026
Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple

Prime Big Deal Days: scammers stock up early as Amazon impersonation attacks nearly triple

October 5, 2026
Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access

Denmark’s CPR breach exposes 8.8 million people as experts warn over trusted third-party access

October 5, 2026
Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

Cybersecurity Awareness Month “cannot be the strategy”: why awareness must become a year-round capability

October 5, 2026

Eskenzi PR banner ad

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2026 IT Security Guru - Website Managed by Dessol