By J. Mesa
October is Cybersecurity Awareness Month, a time to raise awareness about cybersecurity and to encourage people and organizations to protect themselves online. It is a great opportunity to learn and to turn good intentions into habits.
If you want to take part and don’t know where to begin, here are twelve activities that work for a business of any size.
What is Cybersecurity Awareness Month?
Cybersecurity Awareness Month runs every October. It began in the United States in 2004 and is led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance. Organizations use the month to run activities and events that teach people about current threats and how to guard against them.
Why should my business take part?
- Most attacks begin with a person, and awareness changes behavior
- A dedicated month gives you a reason to start
- Shared activities build a culture where people report problems
- Free materials make it low cost
How do I plan the month?
- Pick one person to coordinate.
- Choose four themes, one per week: passwords, multi-factor authentication, phishing, and updates.
- Pick two or three activities from the list below.
- Tell your team the schedule in advance.
- Keep each activity short.
1. Kick off with a message from the owner
Start with a short note or talk from leadership. Explain why security matters to the business and to each person’s job. When the owner takes part, everyone else does too.
2. Send a weekly tip
Email one practical tip each Monday. Keep it to three or four sentences with one action to take. Examples: turn on a screen lock, check your email’s “Report phishing” button, update your phone.
3. Run a phishing drill
Send a harmless simulated phishing email. Afterward, share the warning signs it contained. Praise the people who reported it, and teach the ones who clicked without naming them.
4. Hold a lunch-and-learn
Spend 30 minutes on one topic with real examples. Show actual scam emails your business received. Invite questions. Food helps attendance.
5. Host a password manager day
Help every employee install a password manager and move their most important accounts into it. Set aside an hour and have someone available to assist. This one activity fixes weak and reused passwords across the company.
6. Run a multi-factor authentication check
Ask each person to confirm that multi-factor authentication is on for work email and any system that handles money or customer data. Turn it on where it is missing.
7. Hold an update and cleanup day
Have everyone install pending updates on computers and phones and restart them. Use the same day to:
- Delete files and apps nobody needs
- Remove accounts for former employees
- Review who has access to shared folders
8. Test your backups
Restore a file from backup and time how long it takes. A backup you have never tested is a hope, not a plan.
9. Walk through an incident
Run a 30-minute tabletop exercise. Describe a scenario, such as ransomware on a Monday morning, and ask the team what they would do. Write down the gaps you find and fix them.
10. Play a quiz or a game
Use a short quiz with a small prize. Friendly competition between teams raises interest. Keep the questions practical.
11. Share family resources
Give employees tips they can use at home: setting up a child’s device, spotting scam calls aimed at older relatives, freezing credit. People who practice security at home bring the habits to work.
12. Recognize a security champion
Thank the employee who reported the most suspicious emails or helped coworkers the most. Recognition tells everyone that reporting is valued.
How do I keep activities engaging?
- Keep them short
- Use real stories, not abstract warnings
- Stay positive. Fear makes people hide mistakes.
- Vary the format: email, video, discussion, hands-on
- Involve managers
Where can I find free materials?
- CISA publishes a toolkit, tip sheets, and videos for its Secure Our World campaign at cisa.gov.
- The National Cybersecurity Alliance offers guides and sample communications at staysafeonline.org.
- The Federal Trade Commission publishes small business cybersecurity guides at ftc.gov.
All of them are free to use and share.
What are this year’s core messages?
CISA’s campaign centers on four habits:
- Use strong passwords and a password manager.
- Turn on multi-factor authentication.
- Recognize and report phishing.
- Update your software.
Build your activities around these and you cover the attacks that hit small businesses most.
How do I measure results?
- How many people took part in each activity
- The click rate and report rate on your phishing drill
- How many accounts gained multi-factor authentication
- How many devices were updated
- What your tabletop exercise revealed
Record the numbers and compare them next year.
What if my team is small or remote?
Every activity on this list works for a team of three. For remote staff, hold sessions by video, send tips by chat or email, and give people a set time to complete the password manager and update tasks at home.
What about the rest of the year?
One month is a start. Keep two habits going after October: a short monthly tip and a quarterly phishing drill. Schedule formal training at least once a year.
How do I get leadership support?
Present it in business terms. One wire fraud or one ransomware incident costs far more than a month of short activities. Many insurers and clients also ask whether you train your staff, and this month gives you an answer and a record.
What should I avoid?
Skip the hour-long slide deck and the scare tactics. Avoid any activity that singles out a person who made a mistake. People remember how the month made them feel, and you want them to feel capable.
Your next step
Pick three activities from this list and put them on the calendar for October. This month is a chance to learn more about cybersecurity and to protect yourself and your organization from attacks. If you want a live session for your team, Cerberus Cybersecurity offers cybersecurity training for every audience. Contact us to book one.

Leave a Reply