Cyber Security Awareness Month Plan: One Habit, Four Weeks
Most Cyber Security Awareness Months fail the same way. They try to cover everything: a topic a day, a poster for each, a quiz at the end. People get busy, the calendar fills up, and by the second week the programme is running on guilt. If you are building a cyber security awareness month plan with a small team and not much time, the answer is not more content. It is less, chosen carefully.
Pick one habit
We have built Cyber Security Awareness Month 2026 around a single habit: prove it. Before you act on a message, a call or a request, check it through a channel you chose, not the one you were given. Ring the number you already hold. Open the site yourself. Ask the person another way. It works against attacks nobody has seen yet, because it does not depend on recognising a particular trick. The reasoning is in our theme post.
However, we realise that many organisations do not have the resources to manage the level of engagement we discuss in our main pack, and moreso they do not have the time to plan. That is why we have simplified our plan - into four learning prompts and some associated phishing templates.
One short nudge a week
A nudge is a short message, three or four lines, sent through whatever people already read: Teams, email, the intranet. One a week, on a Monday, each on a single situation. Here is what ours look like, for the four situations we are covering on this blog.

Week of 5 October, prove the sender. “A caller says they are from IT and there is a problem with your account. They know your name, team and manager, all findable online. Say you will call back on the service desk number you already have, not one they give you.”
Week of 12 October, prove the request. “A supplier emails to say their bank details have changed. The thread looks genuine and only the account number differs. Confirm it by phone, on a number you already hold, before anything is paid.”
Week of 19 October, prove the source. “A web page says ‘verify you are human’, then asks you to paste a command into your computer. That is ClickFix, and the paste is the attack. Close the page and report it.”
Week of 26 October, prove you are covered. “If you clicked, entered a password, paid an invoice or shared something you should not have, tell us straight away. The first hour matters far more than blame, and nobody is in trouble for reporting.”
Each one gives the reader a situation they recognise, one thing to do and one place to report. Nothing else.
What to cut
Cut the topic list. A habit practised four times beats twenty threats mentioned once. Cut the extras until the core is running: a training module, a video or a blanket phishing simulation each add something, but none of them is the plan.
Pick one default a week and treat everything else as a bonus. And cut the quiz. It measures recall, which is not what you asked people to do.
Fix the route before you send anything
The habit only works if the second channel exists. Before the first nudge goes out, be able to answer four questions.
Where does someone report something suspicious, and is it one named route, two clicks away?
Where are the known-good phone numbers, somewhere people can reach without using the message they are checking?
What happens when a supplier’s bank details change?
How does your service desk verify a caller?
If any answer is “we don’t have one”, say so and use October to build it. Staff know whether it exists.
Add one targeted phishing simulation

If you run a phishing simulation in October, make it targeted rather than a blanket send. Pick three groups and give each a scenario that matches a theme you have just covered, so the habit is tested on something people have recently been told about. Send one a week, a few days after the nudge it matches.
Finance and procurement, prove the request. A supplier emails updated bank details ahead of a payment run, with a genuine-looking invoice reference. The safe response is to ring the supplier on the number already on file, then report it.

Leadership and assistants, prove the sender. An urgent request from a senior colleague to approve a document before a meeting, with “I can’t take calls” in the message. The safe response is to ask them another way before acting, then report it.

Customer-facing and project teams, prove the source. A shared data pack that asks for a work-account sign-in and expires in 48 hours. The safe response is to open the portal yourself in a new tab, or report it.

Anyone who clicks or enters details lands on a short page that says this was a simulation, that nobody is named and nobody is in trouble, and gives three steps: check another way, confirm before you act, report it.
Agree the guardrails before launch. Report results by group, never by named individual. Keep pretexts away from pay, redundancy, bonuses and health. Agree the wording with HR and legal, and agree the use of any leader’s name with that leader first. Allowlist the sending infrastructure so the emails arrive. If you want to test the same habit by phone, a controlled vishing exercise does it, and we can arrange one through a delivery partner.
Measure the behaviour
Report rate matters, but no single number tells you enough. A click measures whether someone avoided a trap. A report measures whether they did the thing you asked. Read them together, and add speed. Someone who clicks, pauses and reports is a security win hiding inside what looks like a failure. Someone who submits credentials within seconds needs a different response from someone who hesitated first.
Track how quickly people submit and how quickly they speak up, and thank reporters whether or not the email was a test. Treat the first month as your baseline and set targets afterwards. We explain how to read these numbers together in Your phishing simulation metrics are lying to you.
Run your cyber security awareness month without the overwhelm with our Cyber Security Awareness Month Plan
Talk to us: if October is when you would rather have this run for you, with training, phishing simulation and reporting workflows in one place, see our Culture360° managed security awareness service.
Get the full guide: we have written the full plan up as a free guide, with the five-week arc, kick-off and closing comms, short-form posts and phishing guidance. Get the CAM26 guide.





Comments