By J. Mesa
The Cybersecurity and Infrastructure Security Agency (CISA) is the US government’s lead agency for cyber defense. Its public campaign, Secure Our World, became the theme of Cybersecurity Awareness Month in 2023 and has carried through each October since.
The campaign asks everyone to adopt four habits. They are simple and free, and together they block the most common attacks. This post explains each one and how to put it in place at home and at work.
What is Secure Our World?
Secure Our World is CISA’s cybersecurity awareness program for the public, small businesses, and families. It replaces a long list of advice with four actions:
- Use strong passwords and a password manager.
- Turn on multi-factor authentication.
- Recognize and report phishing.
- Update your software.
CISA chose these four because most successful attacks exploit one of them. A weak password, a missing second step at login, a convincing email, or an old piece of software gives an attacker the way in.
Step 1: How do I use strong passwords?
A strong password is long, random, and unique to one account. CISA’s guidance sets the bar at 16 characters or more.
Nobody can remember dozens of passwords like that, so use a password manager. It creates a strong password for each account, stores them, and fills them in for you. You remember one long passphrase that unlocks the manager.
- Make the master passphrase four or more unrelated words.
- Never reuse a password across accounts.
- Change a password when a site reports a breach.
Step 2: What is multi-factor authentication, and why turn it on?
Multi-factor authentication (MFA) asks for a second proof that you are you. After your password, you approve a prompt in an app, enter a code, or touch a security key.
MFA matters because passwords leak. With MFA on, a stolen password alone does not open the account.
The options rank like this, from strongest to weakest:
- A physical security key or a passkey
- An authenticator app
- A code sent by text message
Any of them beats a password alone. Turn MFA on first for email, banking, and social media, then for every account that offers it.
Step 3: How do I recognize and report phishing?
Phishing is a message built to trick you into clicking a link, opening a file, or giving up information. It arrives by email, text, phone call, or direct message.
Look for these signs:
- Pressure to act right now
- A request for a password, a code, or a payment
- A sender address that is close to a real one and slightly off
- A link that goes somewhere other than what the text says
- An attachment you did not expect
When you spot one, don’t click and don’t reply. Report it with the “Report phishing” button in your email program, tell your IT contact at work, and then delete it. Reporting helps your email provider block the same message for other people.
If a message claims to come from your bank or a vendor, contact them through a phone number or website you already trust.
Step 4: Why do software updates matter?
Software has flaws. Vendors fix them with updates. Attackers read those update notes too, and they build tools to attack anyone who has not installed the fix.
- Turn on automatic updates for your computer, phone, and browser.
- Update apps, routers, and smart devices as well.
- Replace devices that no longer receive security updates.
- Restart when an update asks you to. Many fixes don’t take effect until you do.
How does this apply to a small business?
The same four steps work for a company. They need a little structure.
- Passwords. Give every employee a password manager and set a minimum length.
- MFA. Require it for email, payroll, banking, and remote access.
- Phishing. Train your team at least once a year and make reporting easy and blame-free.
- Updates. Assign one person to check that devices and software are current each month.
CISA also offers small businesses free resources, including guides and a vulnerability scanning service for internet-facing systems.
What is Cybersecurity Awareness Month?
Cybersecurity Awareness Month takes place every October. The President and Congress first declared it in 2004, and CISA leads it with the National Cybersecurity Alliance. Schools, businesses, and agencies use the month to teach safe online habits.
You don’t have to wait for October. The four steps work on any day of the year.
Do these four steps stop every attack?
No. They stop the common ones. A determined attacker has other methods, and businesses with sensitive data need more: backups, access controls, monitoring, and an incident response plan. The four steps are the floor. Build on them.
Where can I learn more?
CISA publishes tip sheets, videos, and a toolkit at cisa.gov/secure-our-world. The materials are free to share with your staff, your family, and your community.
What mistakes do people make with these four steps?
- Using a strong password twice. One breach then exposes both accounts.
- Approving an MFA prompt they did not start. Attackers send repeated prompts and hope you tap “Approve” to make them stop. Deny any prompt you did not trigger, then change that password.
- Trusting a message because it looks polished. Criminals copy logos and signatures. Judge the request, not the design.
- Postponing the restart. An update that waits for a restart protects nothing.
How long does it take to set up all four?
Plan on an hour for one person. Install a password manager and move your most important accounts into it, which takes about 30 minutes. Turn on MFA for email and banking in 10 minutes. Switch on automatic updates in 5. Spend the rest learning where your email’s “Report phishing” button lives.
Your next step
Pick one of the four steps and do it today. Turning on MFA for your email takes five minutes and blocks the attack I see most often.
If you want training for your team built around these habits, Cerberus Cybersecurity offers cybersecurity training for every audience, from the sales floor to the executive team. Contact us to set up a session.

Leave a Reply