All articles

Cybersecurity

Cybersecurity Awareness Month 2026:
A 5-Step Security Checklist

October Cybersecurity Awareness Month: a padlock on a glowing circuit-board chip

Every October, Cybersecurity Awareness Month is a reminder that most successful attacks need nothing sophisticated. Far more often, all it takes is an email account without multi-factor authentication, or a laptop that skipped last month's update.

This checklist covers the five steps we recommend to everyone, from individuals to small businesses. Rather than inventing our own list, we have followed the public recommendations of the U.S. Cybersecurity and Infrastructure Security Agency. Links to the original sources are at the end.

This article is general educational information. It is not a security assessment of your situation, and it is not professional advice for it.

What Cybersecurity Awareness Month is

Cybersecurity Awareness Month has run in the United States every October since 2004. It is led by CISA and the National Cybersecurity Alliance, and the point is unglamorous: to get people and organisations to take a handful of simple, effective steps. The 2026 theme, "Securing the Next 250," ties into the nation's 250th anniversary and looks at building resilience for the years ahead.

Step 1: Turn on multi-factor authentication

Multi-factor authentication adds a second check at login beyond your password — a code from an authenticator app, a fingerprint, or a physical security key. It means a stolen password on its own is no longer enough to get into your account.

Where to start

Your email account comes first, because it is the key used to reset every other password. Then your bank, social media, online shopping, and your password manager. In settings, look for "2-step verification", "two-factor authentication" or "security keys".

Which method to choose

Any MFA is far better than none. If you have a choice, an authenticator app is stronger than SMS codes, and passkeys or security keys — step 5 — are stronger still.

Step 2: Keep your software updated

Updates fix security flaws that criminals actively look for. An unpatched phone, browser or router is one of the easiest ways in.

Turn on automatic updates for your operating system, apps and browser. When you see "restart to update", don't postpone it for days. And don't forget the devices nobody thinks of as computers: home routers, smart TVs, network storage.

Step 3: Use a password manager

When one website is breached, attackers try the same email and password everywhere else. This is called credential stuffing, and it only works if you reuse passwords.

Use a password manager to generate and store a long, random, unique password for every account. You then only have to remember one strong master password — and you should protect the password manager itself with MFA.

Step 4: Recognise and report phishing

Phishing messages try to get you to click a link, open an attachment, or hand over personal information. They increasingly look polished and personal, and the era of obvious spelling mistakes is behind us.

Warning signs

  • Urgent pressure — "your account will be closed today"
  • Unexpected attachments
  • Requests for passwords or payment details
  • Sender addresses or links that are almost, but not quite, right

What to do

Don't use the contact details in the suspicious message. Reach the company through its official website, or a phone number you already had. Use the "report phishing" option in your email app, and at work, tell whoever handles IT.

Step 5: Go further with phishing-resistant MFA

Standard MFA stops an attacker who only has your password. But one-time codes and push notifications can still be talked out of people through convincing fake login pages, or approved by accident after a flood of prompts — what the industry calls MFA fatigue.

What phishing-resistant MFA means

It uses the FIDO2/WebAuthn standard, found in passkeys and hardware security keys. The login is cryptographically tied to the real website's address, so a look-alike phishing page simply cannot use it. CISA describes FIDO/WebAuthn as the only widely available form of phishing-resistant authentication, and calls it the gold standard.

Passkeys or security keys?

A passkey lives on your phone, computer or password manager and is unlocked with your fingerprint, face or PIN. A hardware security key is a small USB or NFC device you carry. Both use the same FIDO2 standard.

Check whether your email provider, bank or password manager offers passkeys or security keys, and add one to your most important accounts. If you use hardware keys, register two, so that losing one does not lock you out.

Frequently asked questions

Is SMS two-factor authentication still worth using?

Yes. It is considerably better than a password alone. If the account also offers an authenticator app or passkeys, take those instead.

Are passkeys safer than passwords?

Yes. A passkey cannot be reused on another site, guessed, or typed into a fake website — which removes the most common ways passwords get stolen.

What should a business prioritise?

The same steps, applied consistently to everybody, with priority on phishing-resistant MFA for email, administrator and remote-access accounts — and a secure account recovery process, which is the route attackers take once the front door is locked.

When the checklist is not enough

These five steps cover the basics. Some situations need more than a checklist, and it is worth knowing which is which.

  • If you think someone already has access to your accounts or your phone, adding MFA now may not remove them, and changing a password can tell them you know. That is a different problem — see monitoring software detection.
  • If something is going wrong right now — files encrypted, an account being used by somebody else — the checklist comes later. See incident response.
  • If you are rolling this out across a team, the hard parts are enforcement, account recovery and the people who cannot use the standard method. That is network and endpoint security work.
  • If a regulator, insurer or contract requires you to show all this is in place, the evidence matters as much as the controls. See data protection and compliance.

If you are not sure which of those describes you, call us. The first fifteen minutes cost nothing, and a fair number of those calls end with us saying you are already fine.

Sources

  • MFA
  • Passkeys
  • FIDO2
  • Phishing
  • Passwords
  • CISA
  • Small business
Call now Email