Details in this content are from the Cybersecurity and Infrastructure Security Agency's (CISA) Cybersecurity Awareness Month campaign.
Cybersecurity is an everyday safety measure for everyone. This October, CISA has announced its 2026 theme "Securing the Next 250," highlighting the need to strengthen the country's infrastructure against cyber threats, ensuring resilience and security. The theme focuses on building a secure digital future for America’s next era, aligning with the Freedom 250 celebration.
Essential Steps to Protect Yourself, Your Business, and Your Government Organization Online
- Teach Employees to Avoid Phishing Scams: Phishing tricks employees into opening malicious attachments or sharing sensitive information. Train staff to recognize and report suspicious activity.
- Require Strong Passwords: Strong passwords are a simple but powerful way to block criminals from accessing your accounts through guessing or automated attacks. Make them mandatory for all users.
- Require Multifactor Authentication: MFA adds an extra layer of security beyond passwords. Require it to make accounts significantly safer. Use phishing-resistant MFA where available.
- Update Business Software: Outdated software can contain exploitable flaws. Promptly install security updates and patches to keep your systems protected.
Build on the basics and level up with these additional practices.
- Use Logging on Your Systems: Log activity so your team can monitor signs that threat actors may be trying to access your systems. Learn how to monitor key information.
- Back Up Data: Incidents happen, but when you back up critical information, recovery is faster and less stressful. Put a backup plan in place that aligns with your organization’s recovery-point objective to protect your systems and keep things running smoothly.
- Encrypt Data: Encrypting your data and devices strengthens your defense against attacks. Even if criminals gain access to your files, information stays locked and unreadable. Make encryption part of your security strategy.
- Share Cyber Incident Information with CISA: When organizations and CISA share threat information, everyone is safer. Report incidents to help CISA warn others and get information in return to help you stay ahead of threats: cisa.gov/report
Building Resilience with the 3Rs
For critical infrastructure providers, staying ahead of threats means mastering the 3Rs:
- Reduce: Minimize exposed entry points and systemic vulnerabilities.
- Replace: Phase out outdated, end-of-support devices.
- Recover: Maintain robust business continuity plans to ensure rapid restoration.
CISA also highlighted two new actions for 2026 in its cyber performance goals.
- Have an incident response plan and use it: Organizations should develop, maintain, update, and regularly exercise IR plans for common threat scenarios such as ransomware attacks. Ensure drills are realistic and include all relevant stakeholders, such as organizational leadership and legal counsel, in addition to technical personnel. IR plans should be reviewed and exercised at least annually. Cybersecurity Performance Goals 2.0 (CPG 2.0) | CISA
- Be prepared for system disruptions: Organizations should develop and execute plans to recover and restore service to critical assets or systems that might be impacted by a cybersecurity incident. Consider including the ability to execute mission-essential functions without access to critical assets or even internet access (e.g., shift to paper-based operations, radio communications, etc.) Cybersecurity Performance Goals 2.0 (CPG 2.0) | CISA
As America hits its 250th milestone, taking control of our cyber hygiene helps build a safer digital environment for everyone.
Learn how to safeguard your information at cisa.gov/cybersecurity-awareness-month.