top of page

Cyber Security Awareness Month 2026 Theme: teach a decision, not a fact

20 hours ago
7 min read
Dark purple ICA Consultancy banner promoting Cyber Awareness Month 2026 guide, with Download the guide button and campaign details.

The two most expensive cyber events in British history didn't begin with clever code.

On current public reporting, they began with conversations. That is the starting point for how we've built our Cyber Security Awareness Month 2026 theme, and it points somewhere quite different from the usual October checklist.


The Cyber Monitoring Centre assesses the August 2025 attack on Jaguar Land Rover as the most economically damaging cyber event ever to hit the UK, around £1.9bn, with more than 5,000 UK organisations caught in the wake of it. Marks & Spencer separately flagged an operating profit impact of roughly £300m, and 46 days without online orders. In the M&S case, initial access has been publicly linked to social engineering of a third-party IT service desk.


Exactly what was said, and by whom, has not been confirmed in public. Be wary of anyone telling you otherwise; a lot of confident detail has been written about both incidents that nobody has actually stood behind.


But the shape isn't in dispute. Somebody was persuaded to help.


No perimeter was defeated. The attackers went at the one control no product on the market fully covers, and it worked twice, at a scale that kept both companies on the front page for weeks. Both also arrived through the edges of the organisation rather than the middle, which is its own conversation about third-party and supply chain risk.


Here's the part that doesn't fit the story most people tell about it.


The threat picture isn't getting worse. It's getting less predictable.


The obvious reading is that attacks are escalating and everyone should be more frightened than last year. The national data doesn't support it.


DSIT's Cyber Security Breaches Survey 2025/26 has 43% of businesses reporting a breach or attack, flat on the previous year. Phishing sits at 38%, down from 42% two years ago. Impersonation attacks are at 12%, down from 17% in 2023. Ransomware is at 1%, down from 3%. Charities are flat too.


Phishing is still named the most disruptive attack type by 69% of those affected. It just isn't happening more often.


So the honest headline for 2026 isn't "attacks are up".


It's this: over half of breached businesses, 51%, up from 45%, report phishing and nothing else. No follow-on, no consequence worth recording. Meanwhile the NCSC handled 204 nationally significant incidents in the year to August 2025, a 130% increase, of which 18 were highly significant.


Both of those are true at the same time, and the tension between them is the whole story.

Volume is flat. Variance has exploded.


The same email, the same phone call, now has a far wider range of outcomes than it did three years ago, from nothing at all, to a nine-figure write-down and a factory standing still.


And what decides which end of that range you land on is almost never the technology. It's what one person does in the first ten minutes.


The gap isn't knowledge any more


This is where most security awareness training is still aimed at the wrong target.


Dark infographic with the headline The gap isn’t knowledge any more and three stats: 83% found training useful, 66% spot phishing, 43% limit online activity

CybSafe and the National Cybersecurity Alliance's Oh, Behave! 2025-26 report surveyed 7,000 people across seven countries. 66% are confident they can spot a phishing email. Fewer than 45% always or very often check for the signs, or report what they see.

83% said their security training was useful. Fewer than half changed any behaviour as a result.


Read those two pairs of numbers together and the diagnosis is uncomfortable. People aren't short of information. They have plenty. They liked the training. They just didn't do anything differently afterwards.


Then there's the number I find hardest to ignore: 43% now say they limit what they do online because security feels overwhelming, up six points. The five-year trend in the same research describes rising fatalism, a deepening sense that staying secure isn't worth the effort.

That isn't ignorance. That's exhaustion.


And the standard response to it is another ten facts. A new module on a new threat. A longer list of things to watch out for, delivered to people who already know most of them and are already tired.


You can't fix an action problem by adding more knowledge to it. The knowledge problem has largely been solved. We keep solving it again because it's the easiest thing to produce and the easiest thing to report on.


That's a culture problem, not a curriculum problem.


So teach one decision, five times: our Cyber Security Awareness Month 2026 theme


Which is why our theme is a single behaviour rather than a topic list.


Prove it. Before you act on a message, a call or a request, prove it is what it claims to be, through a second channel you chose, not one they gave you.


The last clause is the entire thing. Ring the number you already had, not the one in the email. Open the site yourself rather than clicking through. Ask the person another way. Anything the sender supplied can be faked. Anything you already held cannot.


We teach that one decision in five contexts across October:

  • Prove the sender — email, display names, lookalike domains, QR codes

  • Prove the voice — vishing, the call from "IT", voice cloning

  • Prove the request — payment changes, business email compromise, manufactured urgency

  • Prove the source — AI-generated content, fake sign-in pages, what your colleague pasted into a chatbot

  • Prove you're covered — what to do when you didn't check, and reporting without blame


Five weeks, one habit, practised somewhere new each time.


The advantages are practical rather than philosophical. It's a decision people can actually rehearse, unlike "be vigilant". It survives contact with attacks we haven't seen yet, because it doesn't depend on recognising a specific trick. It travels home, which is where most people get their reps in. And it's measurable in a way that a topic list isn't, report rate, and time-to-report, rather than click rate.


Click rate measures avoidance. Report rate measures the behaviour you actually asked for.


Where "Don't Make It Easy for Them" fits


The official theme for Cybersecurity Awareness Month 2026, from the National Cybersecurity Alliance and CISA, is "Don't Make It Easy for Them".


Their framing is worth quoting, because it's better than most banner themes: staying safe online isn't about making one perfect decision, it's about building habits and repeating them consistently in the small moments.


That's the same argument we've arrived at from the UK evidence, which is convenient. If you want to run under the official banner and keep the global campaign materials, Prove It sits underneath it as the specific habit you're asking people to repeat. One is the poster. The other is the instruction.


One caveat, and it's a real one


This only works if the second channel exists.


Before October, you need to be able to answer four questions. How does someone report something suspicious, one route, named, two clicks away? What are your known-good numbers, published somewhere reachable without using the message you're checking? What happens when a supplier's bank details change? And how does your own service desk verify a caller?


That last one isn't hypothetical. Both headline UK incidents of the last two years involved persuading a help desk, and the NCSC and CISA have both urged organisations to review account-recovery and password-reset verification. Check your questions aren't answerable from LinkedIn. Consider three-way verification through the line manager.


If any answer is "we don't have one", say so openly during the month and use October to build it.


An honest "here's the route we're putting in place" lands far better with staff than pretending one already exists. They know whether it does.


Running Cyber Awareness Month 2026 in your organisation


We've written the whole month up as a free guide, the five-week arc, kick-off and closing comms, ten short-form posts, phishing guidance and platform mapping. It's built to be run by an internal team with no help from us, and it's genuinely the same theme we're delivering to clients, not a watered-down version.


Dark purple ICA Consultancy promo for Cyber Awareness Month 2026 free guide, with download button and guide mockup.

Our Culture360° managed awareness service clients get it delivered, tailored and measured: verification routes written into the copy, audiences targeted from their own behaviour data rather than blanket sends, a vishing exercise alongside the phishing simulation, and a baseline and endline that shows whether the confidence-versus-behaviour gap actually narrowed.


The difference is depth and evidence, not argument. The argument above is the one we're running either way.


If you want a view of where your verification routes actually stand before you plan October, our free security and privacy assessments are a reasonable place to start.


Frequently asked questions


  • What is the theme for Cyber Security Awareness Month 2026?

    The official theme from the National Cybersecurity Alliance and CISA is "Don't Make It Easy for Them", focused on building consistent everyday security habits. ICA Consultancy's theme for 2026 is "Prove It": before you act on a message, call or request, verify it through a second channel you chose, not one the sender gave you.


  • When is Cyber Security Awareness Month 2026?

    Cyber Security Awareness Month runs throughout October 2026, from Thursday 1 October to Saturday 31 October. The month falls into a clean five-week grid: 1–2, 5–9, 12–16, 19–23 and 26–30, which suits a campaign built around one behaviour taught weekly.


  • Why doesn't security awareness training change behaviour?

    Because most of it solves a knowledge problem that's already largely solved. Research from CybSafe and the National Cybersecurity Alliance found 83% of people considered their training useful, but fewer than half changed any behaviour. 66% are confident they can spot phishing while fewer than 45% regularly check or report. The gap is action under pressure, not information.


  • How do you measure a cyber awareness campaign properly?

    Report rate and time-to-report tell you more than click rate. Click rate measures avoidance; report rate measures whether people did the thing you asked. Pair those with a baseline and endline behaviour measure, and track repeat clickers separately from first-time clickers, they need different interventions.


One final question worth sitting with before you plan October: if someone in your organisation decided right now to verify a suspicious request through a second channel, could they? And would they know where to go?


 
 
 

Comments


bottom of page