Federal cybersecurity officials are using Cybersecurity Awareness Month to emphasize basic security practices, incident response planning and preparation for outages as threats become more sophisticated.
The National Cybersecurity Alliance kicked off the annual campaign today in partnership with the Cybersecurity and Infrastructure Security Agency (CISA). The month starts with a yearly webinar, and Thursday’s event opened with recorded remarks from CISA Acting Director Nick Andersen.
Andersen said that rapidly advancing technologies — AI and quantum computing — are changing the threat landscape while nation-state-backed actors continue looking for opportunities to steal data and disrupt operations. This year’s awareness month theme is “Securing the Next 250,” tying it to the nation’s 250th anniversary.
For state and local governments as well as critical infrastructure organizations, CISA continues to recommend familiar cybersecurity basics: train employees to recognize phishing, require strong passwords and multi-factor authentication, and keep software updated. Andersen said organizations should also use system logging, maintain backups, encrypt data and report cyber incidents to CISA. Finally, eligible government entities should move to a .gov domain.
And CISA also added two actions to its guidance this year. Organizations need to maintain and regularly exercise incident response plans as well as prepare for system disruptions. Incident response exercises should cover scenarios such as ransomware and include organizational leadership, legal counsel and technical personnel, Andersen said. Organizations should also have plans for restoring critical systems and assets following a cyber incident.
“At CISA, we see too many breaches because these basic steps are overlooked,” Andersen said.
The National Cybersecurity Alliance, meanwhile, is also placing emphasis on translating awareness into action.
That organizations own 2026 theme, “Don’t Make It Easy for Them,” encourages the public to adopt a handful of basic behaviors rather than become cybersecurity experts. Findings from the alliance’s forthcoming cybersecurity attitudes and behaviors report illustrate the gap between perception and behavior, said Executive Director Lisa Plaggemier. The full report will be released later this year.
The National Cybersecurity Alliance surveyed 5,000 adults in the United States, United Kingdom, India, Brazil and Singapore. While 83 percent said digital security is a top priority, and 73 percent said they know how to create a strong password, 46 percent still use dictionary words as passwords and 38 percent use personal information. More than half said they do not regularly use multi-factor authentication.
The survey also found growing security and privacy questions around AI use. Eighty percent of respondents said they use AI tools, while more than half of those users had received no security or privacy training. Nearly one-third of employees using AI at work said they had shared sensitive company information with an AI tool without their employer knowing.
Training appears to make a difference. Among respondents who received cybersecurity training, 54 percent said they improved at recognizing phishing, 49 percent enabled multi-factor authentication and 46 percent began using a password manager.
The campaign runs throughout October, with both organizations emphasizing that cybersecurity improvement depends less on perfect security than on consistently applying basic protections.
