October is Cybersecurity Awareness Month, now in its 23rd year. The campaign began in 2004 and is led by the nonprofit National Cybersecurity Alliance (NCA) and the federal Cybersecurity and Infrastructure Security Agency (CISA).
The NCA’s theme for consumers this year is blunt: “Don’t Make It Easy for Them.” The idea is that most attacks succeed not through movie-style hacking, but because someone left an easy way in.
The four habits
The NCA is focusing on four basics, each aimed at a common threat — password cracking, unprotected accounts, unpatched systems and phishing:
- Use strong, unique passwords. Reusing one password means a single leak can unlock several accounts. A password manager makes unique passwords practical.
- Turn on multifactor authentication (MFA). A second step, such as a code or an app prompt, can stop someone who has your password.
- Keep devices updated. Updates often patch security holes that attackers already know about. Turning on automatic updates is the easiest way.
- Pause before you click. Scrutinize unexpected messages, especially ones that create urgency or ask for login details or payments.
“Cybersecurity is a daily practice, not a one-time fix,” said Lisa Plaggemier, executive director of the NCA. The campaign also notes that AI is putting more sophisticated tools in the hands of scammers, which makes the “pause before you click” habit more important.
For small businesses: check the basics actually work
An NCA survey of small and midsize businesses, summarized by SecureWorld, found gaps between having protections and using them. While 86.8% had deployed MFA, only 51.1% required it across all key accounts. And 88.4% had backups, but only 61.4% had tested them.
CISA’s own campaign, “Securing the Next 250,” ties into the nation’s 250th anniversary and focuses on critical infrastructure. Its advice to organizations includes replacing devices that no longer get security support, backing up and encrypting data, and testing incident response plans.
One small step this week
Pick one account that matters most — usually your primary email, since it can reset everything else — and make sure it has a unique password and MFA turned on. Then do the same for your bank. That alone makes you a much harder target.
More on Contoh
- How to Set Up a Passkey for Your Google Account
- How to Freeze Your Credit (and Unfreeze It When You Need To)
- How to Check Your Credit Reports for Free (Every Week)