TRAINING & CULTUREOCTOBER 1, 2026By Nate Medeiros, CEO & Founder

How to Make Cybersecurity Awareness Month Last All Year

October brings posters, quizzes, and a training module. By spring, most of it has worn off. Here is what the research says about awareness that fades, and a plan for using this October to build security habits that still work in March.

Key takeaway

Cybersecurity Awareness Month is most useful as the start of a year-round program, not the program itself. A randomized study of more than 19,500 employees found no link between recently completing annual awareness training and falling for phishing, and other research shows phishing awareness fades within about six months. Use October to turn the four core habits into defaults, make reporting easy and celebrated, replace the annual module with short and frequent practice beyond email, schedule the follow-ups now, measure report rates instead of completion rates, and protect employees in the browser, where the decision to click actually happens.

A large calendar with one brightly lit day, followed by a dotted path of smaller calendars, each with one softly lit day, continuing across the months

Today is October 1, which means Cybersecurity Awareness Month has started. Over the next few weeks, employees will see posters in the break room, a phishing quiz in their inbox, a lunch-and-learn on passwords, and a training module with a completion deadline. Security teams will report participation numbers, and leadership will feel good about them.

Then November arrives, and most of it fades. Not because anyone did the month wrong, but because a month is the wrong unit. Attackers do not run a campaign in October and take the rest of the year off. The question worth asking this October is not how to run a great awareness month. It is how to use this month to start something that is still working in March.

What Is Cybersecurity Awareness Month 2026 About?

Cybersecurity Awareness Month has run every October for more than two decades, led by the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance. CISA’s 2026 theme is “Securing the Next 250” (https://www.cisa.gov/cybersecurity-awareness-month), tied to the country’s 250th anniversary, and it warns that AI is speeding up how fast attackers find and exploit weak spots.

The National Cybersecurity Alliance’s 2026 campaign, “Don’t Make It Easy for Them” (https://www.staysafeonline.org/cybersecurity-awareness-month), makes the more useful point for anyone running a program. In its words, staying safe online “isn’t about making one perfect decision. It’s about building habits and repeating them consistently in the small moments that happen every day.” It recommends four steps to start with:

  • Use strong passwords and a password manager.
  • Turn on multifactor authentication.
  • Recognize and report scams.
  • Update your software.

Notice what that list has in common. None of the four is a fact to memorize. Each one is a habit. That distinction is the whole difference between an awareness month that works and one that does not.

Does a Month of Security Awareness Training Actually Change Behavior?

On its own, the evidence says not much. The largest real-world test so far comes from researchers at UC San Diego, who ran an eight-month randomized experiment with more than 19,500 employees at UC San Diego Health (https://today.ucsd.edu/story/cybersecurity-training-programs-dont-prevent-employees-from-falling-for-phishing-scams). They found no significant relationship between whether someone had recently completed their annual security awareness training and whether they fell for a simulated phishing email. The short training page shown after a simulated click helped, but only reduced the failure rate by about 2 percent. One reason: 75 percent of employees spent a minute or less on that training, and a third closed it immediately.

Even good training wears off. A field study published at SOUPS 2020 tracked employees at a German public-sector organization after an in-person phishing awareness program. Their ability to tell phishing from legitimate email was still significantly better after four months, but not after six (https://www.usenix.org/conference/soups2020/presentation/reinheimer). By that measure, a program that runs once in October has worn off by April, months before the next one begins.

A row of lightbulbs that starts with one glowing brightly and grows dimmer from left to right, with phishing emails arriving beneath the faded bulbs

Meanwhile, the threat does not fade on the same schedule. Verizon’s 2026 Data Breach Investigations Report (https://www.verizon.com/business/resources/reports/dbir/) found the human element in 62 percent of breaches, up slightly from 60 percent the year before. Some of the busiest phishing months of the year come right after October, when open enrollment and bonus lures hit inboxes and awareness from the month before is already starting to slip.

Why Doesn’t Security Awareness Turn Into Secure Behavior?

Because knowing and doing happen at different times. Training happens on a quiet afternoon, when the employee is paying attention and expects a test. The attack happens on a busy Tuesday, between meetings, in a message that looks like the ten legitimate ones before it. Nobody fails a phishing email because they forgot that phishing exists. They fail because, in that moment, the message did not look like phishing to them.

Annual programs also tend to train for last year’s attack. Most awareness content is still built around email, but the 2026 DBIR found that the median click rate on simulated voice and text message attacks was about 40 percent higher than on simulated email phishing. Attackers calling employees directly, fake CAPTCHA pages that talk people into running commands, and AI-written lures without typos do not match the examples in a typical October module.

And when the culture around security is built on completion deadlines and phishing tests that feel like gotchas, people learn the wrong lesson. They learn to finish the module and to hide mistakes. As we have written before, shame does not teach, and trying to make employees care about cybersecurity works less well than making the secure choice the easy one.

What Should You Do This October That Will Still Work in March?

Treat October as the launch of a year-round program, not the program itself. Here is a plan that uses the month’s attention to set up habits that last:

A continuous loop of arrows connecting four habits, a password key, a phone with multifactor authentication, a report flag, and a software update symbol, around a shield that deflects a phishing hook
  • Turn the four habits into defaults. Instead of teaching password tips, roll out a password manager. Instead of encouraging multifactor authentication, require it, and use passkeys or security keys on email, finance, and HR systems where you can, since a fake sign-in page cannot relay them. Turn on automatic updates. A habit the system enforces does not wear off after six months.
  • Make reporting the one behavior you celebrate. The DBIR’s advice on social engineering is to make it “as painless as possible” for people to tell you when they fall for something, so you can contain the damage before it escalates. Use October to give everyone a single, one-click way to report a suspicious message, and thank people publicly when they use it, including when they report a simulation.
  • Replace the annual module with short, frequent practice. If awareness fades within about six months, a once-a-year program is always running on empty. Small touchpoints every few weeks keep it fresh. Our guide on how often to run phishing simulations covers how to find a cadence that builds skill without causing fatigue.
  • Practice beyond the inbox. Include text message, voice, and help desk scenarios alongside email, and give the teams who handle money, payroll, and password resets clear verification rules for requests that arrive by phone.
  • Coach instead of punish. Decide in advance what happens after someone fails a phishing simulation. A short, private explanation of what they missed builds skill. Public lists of “clickers” teach people to stop reporting.
  • Put the follow-ups on the calendar now. Before October ends, schedule the next touchpoints: a refresher on HR lures in November, a gift card and bonus scam reminder in December, a W-2 and tax scam warning in January, and a check-in on your metrics in March. If they are not on the calendar by Halloween, they usually do not happen.

How Do You Know If Your Security Awareness Program Is Working?

Completion rates tell you who clicked through a module. They do not tell you whether anyone will recognize the next attack. Click rates help, but they can mislead. The 2026 DBIR puts the median click rate on simulated email phishing at 1.4 percent. That sounds small, but in a 500-person company it still means about seven clicks per campaign, and an attacker only needs one. Better signals to track from October onward:

  • Report rate. The share of people who report a suspicious message, real or simulated. This is the number that most directly measures a security culture.
  • Time to report. How quickly the first report arrives after a phishing campaign lands. Fast reports let you pull a message from every inbox before most people open it.
  • Repeat clicks. Whether the same people, teams, or lure types keep catching people out. That tells you where to focus coaching instead of retraining everyone.
  • Real threats caught. How many genuine phishing pages, calls, and messages were stopped or reported, not just simulated ones.

If you want a simple baseline, have your team take a short scenario-based quiz this month and again in the spring. Our free cyber savviness quiz lets you share one link with your team and see which scenarios the group found hardest, which makes a useful before-and-after snapshot.

Where Does Awareness Stop and Protection Start?

Even the best year-round program will not get the click rate to zero, and it should not have to. Awareness is one layer. The other is protection that is present at the exact moment an employee lands on a fake sign-in page or a malicious download, which is where the research shows training is weakest. That moment is in the browser, after every email filter has already let the message through, and it is why phishing protection cannot end at the inbox.

Pairing the two also fixes the problem the UC San Diego study found with training after the fact. A lesson that appears at the moment someone is stopped from entering their password on a real attack page is relevant, specific, and remembered, in a way a module assigned in October is not.

Cybersecurity Awareness Month is a good thing. It gets leadership attention and gives security teams a reason to talk to everyone at once. The organizations that get the most out of it are the ones that treat October 31 as the start, not the finish.

How SavvyShield helps: SavvyShield turns awareness into a year-round habit instead of an annual event. Our browser extension analyzes pages in real time and steps in when an employee reaches a phishing page, so protection is there at the moment of decision, and each blocked attempt becomes a short, relevant lesson. Realistic in-browser simulations and bite-sized training keep skills fresh all year, while adaptive human risk management focuses coaching on each person’s weakest points automatically. Want a baseline to start the month? Try our free cyber savviness quiz.