Why most awareness months achieve very little
The usual pattern is familiar. A message goes out at the start of October, a phishing simulation runs mid-month, a click rate gets reported, and on 1 November nothing is different. The activity is measured by participation rather than by what it changed.
That is a design problem, not an effort problem. A campaign built around communication produces communication. Build it around four specific questions and you finish the month with four answers.
The four weeks below assume a mid-sized organisation with a small internal team and no dedicated security function.
Week one: establish where you actually stand
Start with the estate, because most of what follows depends on knowing what you have. The questions for week one are narrow and answerable: what is exposed to the internet, who holds administrative rights, what is running without current patches, and where personal or regulated data sits.
The NCSC’s Cyber Essentials Readiness Tool is a reasonable structure for this if you do not already have one. It walks through the five technical controls and produces an action list, and it does not require certification to be useful.
Write the answers down even where they are uncomfortable. A documented gap is a manageable position. An undocumented one is not.
Week two: test the human layer, and read the result properly
A phishing simulation is the obvious week two activity, and it is worth running. What matters is how the result is read.
A click rate on its own is not a finding. The finding is which teams clicked, which pretext worked, and whether anyone reported it. Reporting rate is the more useful number, because an organisation where people click but report quickly is in better shape than one where nobody clicks and nobody says anything.
If the reporting route is a shared mailbox nobody monitors out of hours, that is the thing week two has told you. Fix that before running another simulation.
This matters because the human element is involved in a large share of breaches. Verizon’s 2026 Data Breach Investigations Report put it at 62 per cent, up from 60 per cent the year before, covering credential reuse, phishing and social engineering. Technology catches most of it. People catch what gets through, but only if they know where to send it.
The pretexts are also better than they were. IBM’s 2026 breach research found that around one in four malicious breaches now involve AI, and that those incidents cost more than those that do not. In practice this means the tells people were trained to look for, poor grammar and clumsy formatting, are disappearing. Train people to question the request being made rather than the spelling it is written in.
Week three: look outside your own estate
Supply chain risk is well understood in principle and harder to get visibility of in practice. You are exposed through the suppliers who hold your data, connect to your systems or provide services you could not operate without.
A realistic week three is not a full third-party risk programme. It is a list of your ten most critical suppliers and a small number of questions put to each: what of ours do you hold, how would you tell us about an incident, and how quickly. The answers, and the silences, are both informative.
Where a supplier cannot answer how they would notify you of a breach, you have found something to escalate.
Week four: rehearse the response
Response plans are often written once and rarely read again. Week four is a tabletop exercise with the people who would actually be in the room, which usually means IT, legal, communications and someone who can authorise spending at short notice.
Exercise in a Box, also from the NCSC, covers ransomware, phishing, supply chain, passwords and vulnerabilities. It includes what you need to set up, run and capture the actions afterwards, and it is designed to be run without external help.
Run one scenario properly instead of three superficially. What you want at the end is a short list of things that did not work: a contact that could not be reached, a backup that had never been tested, a decision no one was sure they were allowed to make.
What to keep after October
The month only pays for itself if something survives it. Four artefacts to hold on to:
- A current picture of what is exposed, who has privileged access and what is unpatched, with dates against each item.
- A reporting rate for suspected phishing, and a route that is monitored when people are most likely to use it.
- A supplier register with recorded answers on data held and incident notification, including the suppliers who did not respond.
- A response plan that has been rehearsed once, with named owners and the gaps the rehearsal exposed.
Put a date in the diary to revisit each of them. The value decays quickly, and a picture of the estate taken in October is of limited use by the following summer.
One thing worth adding to the agenda beyond October
Everything above deals with the risk in front of you. While you have people’s attention, add the risk that arrives later. Data taken today can be stored and decrypted once quantum computing matures, which turns anything with a long confidentiality life, legal records, health data, intellectual property, into a present-day decision rather than a future one.
That is not a week four task. It belongs on the roadmap, with a first step of knowing where your long-lived sensitive data sits and what protects it. We are running a webinar with IBM on 14 October, with IBM distinguished engineer Professor Andy Stanford-Clark, on what becoming quantum safe involves in practice. It falls inside Awareness Month, which makes it a straightforward thing to put in the diary now.
What this means for your organisation
Cyber Security Awareness Month is a hook, not a programme. Its value is that it gives you a reason to ask questions that normally sit behind more urgent work. People will give you an hour in October that they would not give you in March.
Used that way, four weeks produces a documented position, a tested response and a short list of things to fix. That is a defensible answer when a board, an insurer or a client’s due diligence team asks what you are doing about cyber risk.
If the constraint is capacity rather than intent, that is the gap our managed security services are built around. Tell us where yours is.