top of page

Cybersecurity Awareness Month: Cover Down the Basics

2 days ago
3 min read

Welcome to the first week of Cybersecurity Awareness Month! This week, we’ll cover four foundational practices everyone can perform—even if you’re not a cybersecurity professional!

Cybersecurity awareness month banner

1. Identifying Phishing & Social Engineering

The most vulnerable target of the cybersecurity defense layer is people! According to Verizon’s Data Breach Investigations Report for 2026, this has translated to 62% of breaches involving a human element: most commonly, a phishing or social engineering tactic to steal credentials. Both external and internal forms of communication can be susceptible to adversaries attempting to obtain information which should remain confidential.

So how do you identify these threats? Some red flags to look for are unexpected senders, strange attachments, and attempts to create urgency. Avoid clicking on suspicious links or replying to unknown senders. With the advancement of artificial intelligence, phishing emails have become harder to detect based on red flags like spelling and grammatical errors. Always be especially cautious of where you are inputting credentials: is that really a Microsoft login page or does it just look like one?

If you aren’t sure about a message, report it to professionals who can review it before you take any other action.

2. Set Strong Passwords

The next tip is having strong credentials for your accounts! Long passwords are key here more than making them look like illegible gobbledygook that’s impossible to remember. Instead, use passphrases which are much easier to remember like Cybersecurity#Awareness#Month#2026!

If your organization provides one, use the approved password manager (or consider investing in a personal one) to store a plethora of complex passwords so you don’t have to memorize them all. If you do use a password manager, it’s important to set a complex master password (or passphrase) with a minimum of 14 characters including numbers and special characters. If you don’t have a password manager, always store passwords in secure locations such as an encrypted spreadsheet—not a plain text file!

Lastly, don’t reuse the same password for multiple applications. Doing this means that if someone cracks one account password, they’ve just opened the door to all the others!

3. Configure Multi-Factor Authentication

To level up your account defenses, it’s crucial to have multi-factor authentication (MFA) to include the human factor in the authentication process. Set up multi-factor authentication for both organizational and personal accounts (generally found in account settings). If using MFA software such as Duo Mobile or Microsoft Authenticator, never authenticate login prompts that you did not trigger. If an unexpected prompt appears, deny and report it.

Having two-factor authentication prevents almost all automated account takeovers. Automated systems used by attackers can attempt thousands of logins per minute, so MFA creates an additional barrier if one of your passwords is exposed!

4. Update Software Regularly

Lastly, outdated software on your device means it has not been updated to protect against current cyber threats! If your organization provides a software center, either automated or manual updates can be performed with a click of a button. For operating system updates, systems will generally show alert for system updates, so don’t ignore them!

Regardless, it’s good practice to check for updates yourself from time to time. To help keep your devices secure, be sure to enable automatic updates and restart your system at least once per week!

Cybersecurity Awareness—This Month and Every Month!

Whether it’s as part of a company or just your day-to-day life, cybersecurity starts with the individual. These four simple practices greatly reduce the risk that you end up being the low-hanging fruit that hackers love!

It may seem trivial, but this basic cyber hygiene does more than meets the eye. In a digital world that’s constantly evolving, keeping up to date with cybersecurity practices is crucial. Stay tuned for next week’s post as we dive into how organizations stay can stay protected!

About Triumvirate Cybersecurity

Triumvirate Cybersecurity is a CyberAB Registered Practitioner Organization (RPO) which specializes in cyber compliance for small and mid-size government contractors. Based in Dayton, Ohio, we help organizations make sense of requirements, implement effective security programs, and achieve compliance with confidence so they can get back to what they do best!

Ready to level up your journey towards compliance? Reach out through our Contact page or directly via email to info@triumviratecyber.org.

 
 
_edited.jpg

Sign up for our newsletter to get exclusive updates

By submitting this form, you are providing your consent for Triumvirate Cybersecurity to contact you about its products and services. We will not sell your information to third parties, per our Privacy Policy.

Recent Posts
LinkedIn
CyberAB-RPO-Badge.png
Navigation

Home    About    Services    Pricing    Insights

31 S. Main Street, Suite 040, Dayton, OH 45402

(937) 203-8443    CAGE: 9ZW92

© Triumvirate Cybersecurity 2026

bottom of page