Cybersecurity Awareness Month: The Four Habits That Actually Stop Breaches
Author: Marie Strawser, UMSA Managing Director
October 1, 2026
Every October, CISA runs the same campaign it has for years: four things you can do to keep yourself cyber-safe. Turn on multifactor authentication. Update your software. Recognize and report phishing. Use strong, unique passwords. It reads like the kind of checklist that gets pinned to a breakroom bulletin board and ignored by everyone who already knows better.
Then the 2026 Verizon Data Breach Investigations Report (DBIR) came out, and the data made an uncomfortable case for taking the checklist seriously after all. For the first time in the report’s 19-year history, exploiting software vulnerability overtook stealing a password as the leading way attackers get in 31% of breaches started with an exploited flaw, up from 20% the year before, while credential abuse dropped from 22% to 13%. The median time to resolve a critical vulnerability increased from 32 days to 43 days. Only 26% of vulnerabilities on CISA’s own Known Exploited Vulnerabilities list were fully remediated by the organizations tracked, down from 38% the year prior. Third-party involvement in breaches jumped 60% year-over-year and now touches nearly half of all incidents.
None of those points to some novel, unforeseeable threat. It points back to the same four basics CISA has repeated for over a decade, except this year’s data pinpoints exactly where organizations are backsliding on them rather than improving. That’s the right way to spend Cybersecurity Awareness Month: not rehashing a beginner’s checklist but auditing four categories where the latest breach data shows that the gaps are real, and widening.
Multifactor Authentication: But Not Just Any MFA
The baseline case for Multifactor Authentication (MFA) is still overwhelming. Microsoft’s own measurement of Azure Active Directory accounts found that MFA reduces the risk of account compromise by 99.22% overall and still blocks 98.56% of attacks even when the underlying password has already leaked. If an organization has any accounts without MFA in 2026, that’s the first gap to close, full stop.
But “MFA enabled” and “MFA that holds up” are no longer the same claim. Adversary-in-the-middle phishing kits now defeat one-time codes and push approvals by proxying the login and stealing the session cookie issued after the user approves the MFA prompt. Even when the MFA prompt is satisfied honestly, the attacker still ends up with a valid session. Traditional MFA factors were never designed to bind that session to a specific website, so a well-built phishing proxy can sit in the middle without either the user or the MFA system noticing anything wrong. Phishing-resistant methods like FIDO2 and passkeys close exactly this gap, because the credential is cryptographically bound to the site’s origin and can’t be replayed through a proxy. Adoption is moving faster than most security teams probably assume. Google reports that passkeys have now been used more than a billion times across over 400 million accounts, already ahead of SMS and app-generated codes combined.
The DBIR gives a reason this matters beyond theory: third-party involvement in breaches is up 60% year-over-year and now touches 48% of breaches. Separately, Verizon found that only 23% of organizations fully remediated MFA deficiencies identified in its dataset. Having MFA somewhere in the environment isn’t the same as having closed the specific gaps that an incident or an audit can actually surface.
What good MFA looks like this Awareness Month
Every account has some form of MFA; phishing-resistant MFA is the default for privileged and high-value accounts specifically, and known MFA gaps from a prior incident or assessment have an owner and a deadline, not just a ticket.
Software Updates: Patch What’s Exploited, Not Just What’s Announced
“Keep your software updated” has always been uncontroversial advice and consistently under-executed advice. The 2026 DBIR is the clearest evidence yet of why blanket patching programs are losing ground: median time to resolve a critical vulnerability grew from 32 to 43 days in a year where vulnerability exploitation became the single most common way attackers got in. Remediation of CISA’s own Known Exploited Vulnerabilities (KEV) catalog, the list of flaws confirmed to be under active attack actually fell, from 38% fully remediated to 26%.
That’s not simply a story about teams patching more slowly. It’s a sign that “patch everything, ranked by CVSS score” doesn’t scale to the current volume of disclosed vulnerabilities, and that treating every CVE as equally urgent means the ones attackers are actually using get lost in the queue behind those that aren’t. The organizations closing this gap are the ones prioritizing by exploitation status patching what’s on the KEV list first, immediately, regardless of severity score, rather than working a backlog in the order it was filed.
What good patching looks like this Awareness Month
A patch service-level agreement tied to exploitation status, not just CVSS severity; the KEV catalog checked and cross-referenced against the environment on a standing schedule, not only after an incident; and a documented answer for how a newly listed KEV vulnerability gets prioritized above whatever the patching team was already working on.
Recognize and Report Phishing: The Channel Is Shifting Under the Training
CISA’s phishing guidance still centers on email: suspicious links, spoofed senders, trusting your instincts before you click. That instinct is well-trained in most workforces at this point, which is exactly why the DBIR shows attackers achieving greater success with voice- and text-based social engineering than with email. Pretexting, fabricating a scenario to manipulate a target directly, often over the phone, is showing up increasingly often in ransomware and extortion campaigns specifically, not just in isolated fraud attempts.
The practical problem this creates is that most phishing awareness training and most reporting workflows are built around the inbox. An employee who’s been trained for years to forward a suspicious email to security has a well-worn path to doing so. The same employee fielding a convincing phone call from “IT” asking them to reset a credential, or a text message impersonating an executive requesting an urgent action, often has no equivalent instinct or reporting path because the training never covered it.
What good phishing awareness looks like this Awareness Month
Training and simulated tests that cover voice and text, not just email; a reporting path for a suspicious phone call or text that’s as fast and as well-known as the “report phishing” button already is for email; and messaging that explicitly tells employees that pretexting over the phone is now a common precursor to ransomware, not just an inconvenience.
Strong Passwords: Because the Credential Pipeline Still Feeds Ransomware
Credential abuse dropped as an initial access vector this year, but that’s a shift in ranking, not a sign the problem solved itself. Among ransomware victims that had an associated infostealer or credential-leak event in the preceding year, half experienced that event within 95 days before the ransomware attack. Credentials increasingly arrive as a downstream consequence of a vulnerability exploit or a third-party breach, rather than as the attacker’s first move. With third-party breaches up 60% year-over-year and accounting for nearly half of all incidents, organizations are absorbing credential exposure they didn’t create and often don’t know has occurred until it shows up in a stealer log or a dark-web listing months later.
CISA’s core advice here hasn’t changed long; unique passwords generated and stored by a password manager rather than invented by a person, and it’s still correct. But the more durable fix sits one level above it: removing the reusable password from the equation entirely wherever passkeys are supported, since a credential that can’t be typed, phished, or reused also can’t show up in someone else’s breach dump six months later.
What good credential hygiene looks like this Awareness Month
Password managers as the default rather than the exception, passkeys enabled everywhere they’re supported, and a standing practice of checking for the organization’s own credentials in breach and stealer-log monitoring rather than waiting to learn about exposure from an incident.
The Cybersecurity Awareness Month Takeaway
The breakroom bulletin board version of this campaign treats the four habits as a finish line: check the box, hang the poster, move on until next October. The 2026 DBIR treats them as a moving target: the attackers on the other side of these numbers are adapting faster than the habits are being enforced, which is exactly why the same four things that felt basic a decade ago now separate the organizations that hold up from the ones that end up as next year’s case study.
None of the four items on this list needs replacing. What needs replacing is the assumption that having them in place once is the same as maintaining them under pressure. MFA needs to be phishing-resistant where it matters most, not just present. Patching needs to follow exploitation, not a queue. Phishing training needs to follow attackers into the channels they’ve actually moved to. And password hygiene needs to assume the organization’s credentials are already circulating somewhere it hasn’t checked.
That’s the version of Cybersecurity Awareness Month worth running this October, not a reminder of what to do, but a hard look at whether it’s actually holding.
Sources consulted: CISA — 4 Things You Can Do To Keep Yourself Cyber Safe, Help Net Security — Verizon 2026 DBIR: Vulnerability exploitation is the dominant initial access vector, Tech Insider — Verizon DBIR: Exploits Overtake Credentials at 31%, Security Scientist — How Effective Is MFA? An Evidence Review

