Every October, organisations and individuals across the world mark Cybersecurity Awareness Month, an opportunity to strengthen cyber defences and build safer everyday habits.
This year, Integrity360’s campaign focuses on four areas of human cyber risk: phishing and social engineering, AI safety and deepfakes, data security and passwords, and incident reporting. Together, these themes address the decisions people make every day, whether they are responding to an unexpected request, sharing a document, using an AI assistant or reporting something suspicious.
Social engineering exploits trust, fear, urgency and curiosity to persuade people to share information, provide access or transfer money. An attacker might impersonate a supplier requesting new payment details, an IT colleague asking for a login code or a senior executive demanding urgent action.
These requests can arrive through email, text messages, phone calls, social media and workplace collaboration tools. Familiar branding, accurate personal details and a professional tone can all make a fraudulent approach appear credible.
Awareness training should help employees question what a message is asking them to do. Does the request bypass an established process? Is someone pushing them to act before they can check? Are they being asked to disclose information the sender should not need?
Verifying unusual requests through a separate, trusted channel gives people a practical way to respond. For example, a call to a supplier using an existing contact number can help establish whether a request to change bank details is legitimate.
AI adds another layer to deception. Generated text can make phishing messages sound polished and natural, while cloned voices and manipulated video can make an impersonation attempt harder to recognise. A familiar face or voice should not, on its own, be enough to authorise a payment or the release of confidential information.
Employees need clear verification procedures that apply even when a request appears to come from someone they know. Pressure to keep a conversation secret, ignore normal approvals or act immediately should prompt further checks.
AI safety also involves how people use these tools in their own work. Pasting customer information, internal documents or other sensitive material into an unapproved AI service can expose data beyond the organisation’s control. Employees should understand which tools they can use, what information they can share and when an AI-generated answer needs checking.
Clear guidance helps people use AI confidently while keeping responsibility for decisions and information handling firmly in human hands.
Protecting data depends on everyday choices about where information is stored, who can access it and how it is shared. Sending a file to the wrong recipient, creating an unrestricted sharing link or using a personal account for work can put sensitive information at risk.
Employees should know how to recognise confidential data, use approved storage and sharing tools, and check recipients and access permissions before sending information. Those expectations need to be straightforward enough to follow during a busy working day.
Strong, unique passwords and an approved password manager help protect accounts, alongside multi-factor authentication. People should also know to reject and report authentication prompts they did not initiate, and never share passwords or verification codes in response to an unexpected request.
These habits work best when organisations support them with appropriate access controls and clear processes, so employees can carry out their roles without unnecessary access to sensitive systems or data.
Recognising a threat is useful only if people know what to do next. Employees need a clear route for reporting suspicious messages, unexpected authentication requests, lost devices, accidental disclosures and other potential security incidents.
Reporting should be encouraged even when someone is unsure whether anything is wrong. A person who has clicked a suspicious link or shared information by mistake needs to feel comfortable raising the issue promptly. Fear of blame can delay the information security teams need to investigate and contain a problem.
Make reporting instructions easy to find and explain what details will help, such as when the event happened and what the employee noticed. People should understand that they do not need to investigate or prove an attack has occurred before asking for help.
For Cybersecurity Awareness Month 2026, Integrity360 has teamed up with KnowBe4 to provide a free resource kit containing Specialist character cards, tabletop exercises, a weekly training planner and security awareness modules.
Our dedicated campaign page also brings together practical guidance, educational videos, webinars and downloadable resources covering this year’s four focus areas. These materials can support internal campaigns, team discussions and training sessions throughout October.
Organisations can explore phishing prevention, deepfake threats, secure AI adoption and incident reporting, with resources that help employees connect the guidance to situations they may encounter at work.
Cybersecurity Awareness Month provides a useful starting point, but lasting improvement requires regular reinforcement. Short training sessions, relevant examples and opportunities to practise can help employees apply what they have learnt when a real situation arises.
Managers have an important role in making those behaviours normal. Supporting an employee who pauses to verify a request, follows an approval process or reports a mistake shows that security matters in practice.
The aim is to give people the knowledge, confidence and support to make safer decisions throughout the year.
Visit our Cybersecurity Awareness Month 2026 landing page to download your free KnowBe4 resource kit and explore our videos, webinars, blogs and practical guidance.
Whether you are planning your first awareness campaign or refreshing an established programme, use this October to help your people recognise deception, use AI safely, protect information and report concerns promptly.
To find out how Integrity360 can help strengthen your organisation’s cyber security, get in touch with our experts.
Cybersecurity Awareness Month takes place throughout October. It encourages individuals and organisations to improve their understanding of cyber threats and adopt safer habits at work and at home.
Integrity360’s 2026 campaign covers four areas: phishing and social engineering, AI safety and deepfakes, data security and passwords, and incident reporting. Our resources help employees recognise threats, protect information and respond when something goes wrong.
Treat unexpected requests for money, sensitive information or access with caution, even if you recognise the person’s voice or face. Verify the request through a separate, trusted channel, such as calling an established contact number, and follow normal approval procedures.
Use tools approved by your organisation and follow its rules on sharing information. Avoid entering confidential documents, customer data, passwords or other sensitive material unless explicitly authorised. Check AI-generated content for accuracy before using it to inform decisions or sharing it with others.
Report it immediately through your organisation’s designated IT or security channel and follow their instructions. Explain what happened, including whether you entered credentials, downloaded a file or approved an authentication request. Prompt reporting helps the security team assess the risk and respond.
Visit Integrity360’s Cybersecurity Awareness Month 2026 page to access the free KnowBe4 resource kit, alongside webinars, videos and practical guidance. Use these materials to plan training, start team discussions and reinforce safer behaviours throughout October and beyond.