Skip to main content

Most organisations mark Cybersecurity Awareness Month with one email, sent by IT, that nobody reads past the subject line. That’s a shame, because the campaign was never designed to be a compliance chore. It was built to change behaviour, and done properly, it produces exactly the evidence an ISO 27001 or NIS2 auditor spends half a Stage 2 visit looking for.

October is a few weeks out. This is what the campaign actually is, where it came from, what other organisations do with it that goes beyond a single email, and why it’s worth treating as more than a box to tick.

Key takeaways

  • Cybersecurity Awareness Month started in the US in October 2004 (DHS and the National Cyber Security Alliance) and expanded to the EU in 2012 via ENISA’s European Cybersecurity Month, run in parallel with national campaigns including Ireland’s NCSC.
  • 2026 is the 23rd year of the US campaign. Current messaging, “Don’t Make It Easy for Them,” builds on several years of “Secure Our World” behavioural pillars: strong passwords, MFA, recognising and reporting phishing, and keeping software current.
  • The organisations that get value from it run small, structured activities across the month, phishing simulations, short targeted sessions, tabletop exercises, executive-specific briefings, rather than a single long session in one sitting.
  • ISO 27001 Annex A control 6.3 and NIS2 Article 20 both expect ongoing security awareness activity with evidence it worked, not a policy that says training happens.
  • The evidence that actually satisfies an auditor is a trend, click and report rates on phishing simulations over time, not a single “100% completion” attendance figure. Treat the campaign as a chance to generate that trend, not just tick a box.

Where it actually came from

Cybersecurity Awareness Month began in October 2004, a joint initiative between the US Department of Homeland Security and the National Cyber Security Alliance (a non-profit founded in 2001, now the National Cybersecurity Alliance, or NCA), launched in response to a threat landscape that was outpacing public awareness even then. It’s now co-led in the US by CISA and the NCA, and 2026 marks its 23rd consecutive year.

The campaign went international in 2012, when the EU Agency for Cybersecurity (ENISA) launched European Cybersecurity Month (ECSM) as the EU-wide counterpart, run every October in coordination with national bodies across member states. Ireland’s National Cyber Security Centre (NCSC) has run its own ECSM programme for several years, aimed squarely at businesses and the public rather than only operators of critical infrastructure. If your organisation is Irish or EU-based, ECSM and the NCSC’s material are the more directly relevant reference point than the US campaign, though the themes and behavioural advice largely overlap.

Messaging has evolved over the years from broad, generic warnings toward specific behaviours. The NCA’s “Secure Our World” campaign, running for several years, distilled the whole subject into four actions: use strong, unique passwords (ideally via a password manager), turn on multi-factor authentication everywhere it’s offered, recognise and report phishing, and keep software updated. This year’s theme, “Don’t Make It Easy for Them,” is a continuation of that logic rather than a departure from it, framing security as making an attacker’s job incrementally harder rather than achieving some unattainable “unhackable” state.

What other organisations actually do with it

The organisations that get something real out of the month treat it as a structured campaign, not a single event, and lean on a handful of ideas that turn up repeatedly.

A phishing simulation with a visible result, not just a test. Running a phishing simulation during October is common; running one that reports back department-level click and report rates, without naming individuals, is what actually moves behaviour. A leaderboard rewarding the fastest and most accurate reporting works better than a shame list of who clicked.

Short, spaced sessions instead of one long one. A single 45-minute annual training video is easy to sit through and forget by lunchtime. Splitting the same content into four short weekly sessions, one behaviour per week, matching the “Secure Our World” structure, produces noticeably better retention and gives you four dated touchpoints instead of one.

A role-specific session for leadership. Most awareness content is written for general staff and skips the people with the most access and the most exposure to targeted social engineering, business email compromise and deepfake-enabled fraud in particular. A short, separate session for the leadership team, covering the current shape of those attacks, is worth more than adding executives to the general staff rollout. It also happens to be close to what NIS2 Article 20 explicitly asks for from management bodies.

A tabletop exercise timed to the month. October is a convenient, recurring slot to run an incident response tabletop exercise rather than letting it lapse to “whenever we get to it.” Scheduling it inside the campaign also means the year’s awareness messaging and the incident response walkthrough reinforce each other while they’re both fresh.

Visible, low-effort reminders. Posters, desk cards, and short internal newsletter items sustain attention between the more structured activities without requiring anyone to block out real time. CISA and the NCA both publish free toolkits with ready-made material for exactly this, and ECSM material is available through ENISA and most national cybersecurity centres, including the NCSC in Ireland.

A visible, blame-free reporting culture. The single most repeated piece of advice across every version of this campaign is also the simplest: make reporting a suspicious email fast, easy, and consequence-free, and say so explicitly during the month. A workforce that reports promptly is worth more than one that never clicks anything in a test but stays quiet about a real one.

Why this is genuinely useful for compliance and audits

Annex A 6.3 wants evidence of effect, not just a schedule. ISO 27001’s control on information security awareness, education, and training doesn’t just ask whether training happened. Auditors interview staff and compare what they say against what training records claim, a pattern we’ve covered before in common ISO 27001 audit findings , where a frequent finding is that “training records show completion, but interviews reveal staff don’t understand key policies or their responsibilities.” A structured October campaign with varied formats and a follow-up quiz or discussion produces a materially stronger answer than a single video with a tick-box at the end.

NIS2 Article 20 specifically wants management involved. Member states must ensure entities provide cyber risk management training to their management bodies, and encourage the same for the wider workforce. An October session built specifically for leadership is close to a direct, dated answer to that requirement, and it’s evidence that’s straightforward to produce if you plan for it rather than scrambling for it during an audit.

Trend data beats attendance data. This is the same principle we set out in past the vanity metrics : a dashboard that shows “100% training completion” describes activity, not protection. A phishing simulation click rate and report rate tracked over several campaigns, ideally improving, is outcome evidence. If October is the one time of year you run a simulation, use the opportunity to start (or continue) that trend line deliberately, rather than treating each year’s result as a standalone number.

It gives internal audit something concrete to sample. Five recurring themes in ISO 27001 findings map awareness gaps directly to Annex A 6.3, clause 7.4 (communication), and clause 10.2 (corrective action). A documented campaign, with dates, attendance, simulation results, and any follow-up action taken on people who struggled, gives your internal audit programme a clean, self-contained thing to sample against all three at once.

Practical questions to ask now

  • Is this year’s campaign a single email, or a structured set of activities spread across October with something to show for each one?
  • Does anyone senior get security content built for their specific risk profile, or does leadership sit through the same generic deck as everyone else?
  • Are you tracking phishing simulation click and report rates as a trend across campaigns, or treating each simulation as a one-off number?
  • Is there a dated tabletop exercise on the calendar this month, or has it quietly slipped for another year?
  • If an auditor asked to see evidence that awareness training changed behaviour, not just that it happened, what would you actually show them?

Closing

The campaign’s origin story, a 2004 US initiative that grew into an EU-wide effort coordinated by ENISA and national bodies like Ireland’s NCSC, is mostly trivia. What matters is that it’s a free, recurring, well-supported excuse to run the awareness activity your ISMS needs anyway, and to generate the kind of dated, outcome-based evidence that a single afternoon can’t produce after the fact. Organisations that use it well aren’t doing anything exotic. They’re just running several small, real activities instead of one forgettable one, and keeping the results.

If you’d like help planning this year’s campaign, running phishing simulations, or building the awareness evidence your next ISO 27001 or NIS2 audit will ask for, get in touch . Our Technical Security and ISO 27001 services both cover this ground.

Common questions

What is Cybersecurity Awareness Month, and when is it?
An annual campaign held every October to raise awareness of cyber risk and encourage better security habits among individuals and organisations. In the United States it runs as National Cybersecurity Awareness Month; the equivalent EU-wide campaign is European Cybersecurity Month (ECSM). 2026 is the 23rd year of the US campaign.
Where did Cybersecurity Awareness Month come from?
It started in October 2004 as a joint effort between the US Department of Homeland Security and the National Cyber Security Alliance (now the National Cybersecurity Alliance, NCA), in response to a fast-growing threat landscape. In 2012 the EU Agency for Cybersecurity (ENISA) joined the effort, launching European Cybersecurity Month, coordinated with national bodies including Ireland’s National Cyber Security Centre (NCSC).
Is there a European or Irish equivalent, or is this just a US thing?
Both. European Cybersecurity Month runs in parallel every October, coordinated by ENISA with EU member states running local activities, webinars, and awareness material. Ireland’s NCSC has run its own ECSM programme for several years, aimed at businesses and the public rather than only critical infrastructure operators.
What's the 2026 theme?
The National Cybersecurity Alliance’s 2026 messaging centres on ‘Don’t Make It Easy for Them,’ encouraging small, deliberate friction against attackers rather than a single big fix. It follows on from the multi-year ‘Secure Our World’ campaign, built around four core behaviours: strong passwords, multi-factor authentication, recognising and reporting phishing, and keeping software updated. Some US government material this year also references ‘Securing the Next 250,’ tied to the country’s 250th anniversary.
Does running an awareness campaign actually help with ISO 27001 or NIS2 compliance?
Yes, directly. ISO 27001 Annex A control 6.3 requires ongoing information security awareness, education, and training, and auditors specifically look for evidence it happened and had an effect, not just a policy stating it should. NIS2 Article 20 requires member states to ensure organisations provide cyber risk management training to their management bodies. A documented, dated October campaign, with before-and-after metrics, is exactly the kind of evidence both expect.

Ready to discuss your requirements?

Let's have a conversation about how we can help your organisation.

Let's talk