Cyber Security Awareness Month 2026

October marks the start of Cyber Security Awareness Month, and as always throughout the month TwentyFour will be sharing practical advice, educational content and simple ways businesses can strengthen their cyber security. Make sure to check back here, on our website and across our social channels as we provide a range of resources to help your business and your employees to stay cyber secure. 

Because cyber security is not just an IT department issue. Everyone within your business has a part to play in forming a crucial first line of defence against the latest cyber threats. 

From recognising a suspicious email and using strong passwords, to keeping software up to date and knowing what to do if something goes wrong, small everyday actions can make a big difference. 

 

Cyber Security Starts With Your People 

Technology plays a huge role in protecting a business, but employees interact with emails, accounts, applications and business data every day. 

That is why cyber security awareness is so important. 

The Government’s 2025/26 Cyber Security Breaches Survey found that only 19% of businesses carry out staff cyber security training or awareness activities. 

Throughout October, we will be sharing advice around creating secure passwords, using Multi-Factor Authentication (MFA), recognising phishing attacks and understanding risks such as email spoofing, malicious links and unsafe public Wi-Fi. 

The aim is not to turn everyone into a cyber security expert. But it helps employees recognise when something does not look right and understand what they should do next. 

 

Controlling Access to Your Business 

One important area of keeping your employees and the data they access secure is Identity and Access Management. Not everybody within a business needs access to everything. 

Technologies and approaches such as Identity and Access Management, Privileged Identity Management and Privileged Access Management help businesses control who can access systems and data, while providing additional protection around accounts with higher levels of access. 

We will also look at Zero Trust, which works on the principle that users, devices and access requests should be appropriately verified rather than automatically trusted. 

Combined with strong passwords, multi-factor authentication, single sign on, and policies of zero trust access, these controls can make it considerably harder for an attacker to gain access, even if an employee’s password is compromised. 

 

Phishing, Malware and Modern Cyber Threats 

Phishing continues to be one of the most common ways attackers target businesses, with 93% of UK businesses and 95% of charities stating that they experienced phishing a part of a cyber crime. 

A convincing looking email, fake login page, impersonated supplier or compromised external account can be enough to trick someone into sharing information, providing access or even providing payments. 

That is why we will be looking at phishing, spoofing, malware, ransomware, malvertising and more throughout Cyber Security Awareness Month, alongside the security tools that can keep businesses protected from these modern attacks. 

We will also explore why traditional anti-virus alone is no longer enough for many businesses and how Endpoint Detection and Response (also known as EDR), Zero Trust and cyber security monitoring tools can provide greater visibility into suspicious activity across business devices. 

 

Shadow IT and AI 

AI is becoming part of everyday working life, but its rapid adoption is also creating new cyber security and data protection considerations. 

The UK Gov Cyber Security Breaches Survey 2025/2026 found that among businesses using, adopting or considering AI, only 24% have cyber security practices or processes in place to manage AI-related risks. 

Employees need to understand what information can safely be entered into public AI services, how they can keep data secure with AI, which tools are approved and where business data should ultimately be stored and accessed for business data security. 

This links closely with Shadow IT, where employees are often using their own unapproved and unmonitored Third-part AI solutions, they also often use applications, software or online services without the knowledge of the people responsible for IT and cyber/data security. 

What may start as a quick workaround for an employee to accomplish a specific task… it can create risks around data security, access and compliance. 

A simple rule can help: work on the rule of zero trust.  

If you are unsure about a tool, ask before you download, upload or share. No tool or service should be trusted until it is assessed by qualified IT, Cyber Security and Data Security professionals. 

 

Could Your Business Respond and Recover? 

Good cyber security is not only about preventing an attack. Businesses also need to know how they would respond if one managed to break through their defences. 

According to the latest Cyber Security Breaches Survey, only 25% of UK businesses have a formal Incident Response Plan in place. 

An Incident Response Plan provides clear guidance around who needs to act, who should be contacted, how an incident should begin to be contained, and ultimately how the business can begin to recover. 

Throughout October, we will also look at Disaster Recovery, Business Continuity, the 3-2-1 Backup Strategy, and how these tools can work together to form a resilient foundation and enable your business to quickly recover. 

Because if systems or data become unavailable, the important question quickly becomes: how quickly can your business recover? 

For many businesses, even one hour of downtime could cause significant financial, operational and reputational damage. 

 

Cyber Security Awareness and Compliance 

Many of the areas covered during Cyber Security Awareness Month are also closely connected with cyber security compliance. 

Cyber Essentials focuses on five core technical controls: firewalls, secure configuration, security update management, user access control and malware protection. 

These are not just certification requirements. They are practical foundations that can help businesses reduce their exposure to many of the most common cyber threats. 

Cyber Essentials Plus builds on the same controls with an independent technical assessment to confirm that they are operating effectively. 

TwentyFour is an official IASME Licenced and Accredited Cyber Essentials and Cyber Essentials Plus Certification Body, meaning we can support businesses end-to-end through their cyber essentials journey, from understanding the requirements and assessing/addressing technical gaps, through to assessment and certification. 

Our wider Compliance Management service ensures that businesses can continue to maintain those standards as the business grows, as people join or leave, and as standards evolve over time, while also supporting wider requirements such as the data security controls and documentation associated ISO 27001. 

 

How Cyber Secure Is Your Business… Really? 

Cyber Security Awareness Month is the perfect opportunity to look beyond whether your technology appears to be working and ask how prepared your business actually is if you were targeted in a cyber attack. 

  • Would your team recognise a phishing attempt?  
  • Is MFA enabled?  
  • Are devices properly protected and updated?  
  • Do employees have appropriate access?  
  • Do you know which AI tools are being used?  
  • Are your backups tested?  
  • And would everyone know what to do if a cyber incident happened tomorrow? 

Throughout October, we will be helping businesses answer these questions with practical advice designed to make cyber security easier to understand and easier to put into practice. 

Because when it comes to cyber security, awareness really is your first line of defence. 

 

Get Your FREE Cyber Security Health Check 

Don’t wait for a cyber criminal to discover where the gaps are, because by then… it will be too late! 

As part of Cyber Security Awareness Month, speak to members of the TwentyFour team to see get your FREE Business Cyber Security Health Check to better understand your current cyber security position, identify potential areas of risk and highlight practical steps you can take to strengthen your protection. 

 

Enquire Here

Recent Insights

Cyber Security Awareness Month 2026

28 September 2026

What is Endpoint Management? And How Can It Benefit Your Business?

21 September 2026

How often should your team take Cyber Security Awareness Training?

14 September 2026

How can your business securely share files?

7 September 2026

View All