cybersecurity awareness monthsecurity awareness programawareness campaign

    October 6, 2026 · 10 min read · By Fensivo Team

    Cybersecurity awareness month: how to plan October

    Leer en español

    October is only worth running if, on November 1, you can prove that someone changed their behavior, and the first step toward that is counterintuitive: before the first talk, the first poster and the first motivational email, you send a real phishing simulation to get a measured baseline. Without that starting number, the whole month has nothing to compare against, and the only thing you can take to the board is how many people attended. With it, the calendar stops being a list of activities and becomes an experiment with a beginning and an end.

    We propose it this way because the month has an advantage the rest of the year does not: a start date and an end date that everyone accepts. Four weeks are enough to measure, remediate and test again. They are exactly what the job requires.

    The conclusion in one sentence: October only counts if you can prove someone changed

    Cybersecurity awareness month is built in four weeks, in this order: week 1 measures real behavior with a phishing simulation before any activity, weeks 2 and 3 deliver specific training only to the people who failed, and week 4 repeats the test with a different email of comparable difficulty to verify whether the person learned the lesson or simply remembered a message. The indicator you report at the close is not attendance or course completion, it is the difference between week 1 behavior and week 4 behavior in the same people.

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment

    We call this the October calendar with a retest close, and its mechanics rest on one fortunate coincidence: the recommended window for testing someone again after a failure is around three weeks, long enough for the novelty of the lesson to fade so that what remains is behavior. If the baseline is taken in week 1, that window lands exactly in week 4. Without anyone designing it that way, the month happens to be the length of a full validation cycle.

    Why awareness month turns into theater: activities with no baseline and no validation

    The calendars that circulate every September share a pattern: they are lists of activities. A talk, a newsletter, a password contest, a video, a quiz, a trivia game with prizes. All of them can be good, and none of them answers the question that matters, which is whether the company was less exposed on October 31 than it was on October 1.

    The problem is not the activity, it is the order. When training comes first and measurement comes later or not at all, you lose the only chance all year to have a clean before and after on the same population. And with no before, any number from the after can be read however you like.

    There is an underlying reason to insist on this, and it is not methodological, it is financial. According to IBM's Cost of a Data Breach 2026, the global average cost of a data breach reached 4.99 million dollars, a 12 percent increase over the previous year and a record high. So awareness month is being celebrated while the consequence of ignoring the human factor hits its own maximum. A month that ends in an attendance list is an expensive answer to a problem that just got more expensive.

    The direction the evaluation criteria are heading is clear too. Analyst firm Gartner predicts that by 2030, all widely adopted cybersecurity control frameworks will focus on measurable behavior change, rather than compliance-based training, as the critical measure of efficacy for human risk management. In other words, a calendar that measures behavior is not a requirement of this year: it is how the program will be judged a few years from now.

    Week 1: the baseline, a real simulation before any talk

    The first week is not announced. If you tell everyone October is awareness month and then send the simulation, what you measure is the alertness of a warned population, which is not the state people are in when a real attack arrives.

  1. Send a phishing simulation to every employee, on a normal business day during working hours. Not to a pilot group: the baseline loses its value if it does not cover everyone who will later appear in the report.
  2. Declare the difficulty of the email before sending it, against a written criterion: which cues the message contains (errors, suspicious sender, excessive urgency) and how well its premise aligns with the actual work of the person receiving it. A click rate with no declared difficulty cannot be interpreted and, worse, cannot be compared to anything.
  3. Record three results per person, not one: who clicked, who submitted credentials and who reported the message. The third is the one that measures the desired behavior, and it is the one almost nobody measures.
  4. Segment by role and department from day one. Finance, the executive team and anyone with vendor access do not carry the same risk or respond to the same effective pretext, and the November report will need that breakdown.
  5. Communicate nothing yet. Week 1 ends with a number and a list of people, not with an announcement.
  6. It is worth remembering why the test runs over email rather than as a knowledge survey. More than 90 percent of successful cyber attacks start with a phishing email, according to CISA, so the simulation channel is the same one the real attack arrives through. Asking someone whether they know what phishing is measures what they know. Sending them a credible email measures what they do.

    Weeks 2 and 3: microlearning goes to whoever fails, not to the whole company

    This is where the traditional calendar wastes the month. Training the entire company on a risk most of it does not carry creates fatigue in the people who did not fail and dilutes the message for the ones who did. The two middle weeks are for targeted remediation.

  7. Deliver training to whoever failed, in minutes rather than weeks, and specific to the attack they fell for: what that email asked for, which cues it carried and what to do the next time a similar one arrives.
  8. Keep it short and conversational. The attention an employee gives a mandatory training module is brief, so a twenty-minute course is not consumed, it is dispatched.
  9. Set an explicit, published passing criterion. Three questions about the scenario the person fell for, with two out of three correct to pass, is enough and it is verifiable. What matters is not the number, it is that the criterion exists in writing before you start.
  10. Escalate what went unresolved, not the fact of having failed. If someone has not completed their lesson after a couple of reminders, their direct manager gets the open task. Someone who clicks and does the lesson right away never reaches their manager, and that distinction is what keeps October from being remembered as the month a list of culprits went around.
  11. Save the general content for the people who did not fail. Those two weeks are the moment for talks, the newsletter and the open material, with one difference: they stop being the center of the month and become the accompaniment.
  12. Week 4: the retest, the only activity of the month that proves anything

    A retest means testing the same people who failed again, with a different email in the same category and a difficulty comparable to week 1. It is not the same template with a new subject line. If you resend the same message, what you verify is memory, and the memory of one specific email does not protect anyone from the variant that arrives next month.

  13. Choose a different template in the same deception category (executive authority, financial pretext, urgent paperwork) at equivalent difficulty, using the same written criterion from week 1.
  14. Send it only to the people who failed and completed their training. Everyone else stays out: their week 1 baseline is already the data point.
  15. Compare person by person, not in aggregate. The monthly average can improve because different people failed, and that is not learning, it is the failure rotating.
  16. Flag anyone who falls again as elevated risk, with a written exit condition: they leave that state after passing several consecutive simulations without clicking, not after completing another course.
  17. Close the data on October 31. The retest is the end of the month and the input for the report, so it does not slide into November.
  18. The month in one table: what you do, what you measure and what you report each week

    WeekWhat you doWhat you measureWhat you report
    1Phishing simulation to every employee, unannounced, with declared difficultyClicks, credential submission and reports, by person, role and departmentNothing yet: this is the baseline
    2Immediate, specific microlearning only for those who failed; general content for everyone elseLesson delivery and pass rate, against a written criterionRemediation progress, no names
    3Reminders and manager escalation for incomplete lessonsOpen tasks closed and escalatedRemediation coverage by area
    4Retest for those who failed, different template in the same category at comparable difficultyWho resists and who falls again, compared against their own week 1 resultBehavior change by person and by area

    What the board gets on November 1: the report that is not an attendance list

    An October report that holds up in front of a board has four lines, and none of them is the number of attendees.

  19. The week 1 baseline, with its declared difficulty, broken out by role and department.
  20. The week 4 retest result on the same people, with the share that resisted and the share that fell again.
  21. The list of areas where behavior did not move, which is what decides where November and December go.
  22. The people left in elevated risk and the written condition for leaving that state.
  23. That report has a property the attendance report does not: you can repeat it in April with the same method and compare. An attendance number can only be celebrated.

    How October connects to the program for the rest of the year

    October is not the program, it is the measured start of the program. The month leaves behind three things the rest of the year needs and that are hard to come by in an ordinary quarter: a clean baseline across the whole company, a written criterion for difficulty and for passing, and a map of which areas and roles concentrate the risk.

    From November on, the same cycle becomes continuous and stops depending on the date. Simulations spread across the year instead of bunching into four weeks, the retest keeps happening around three weeks after each failure, and the quarterly report compares back to the October baseline. The difference between an awareness month that works and one that does not is whether November inherits a method or is left with a memory. Why training alone does not move behavior is laid out in our analysis of why your security training program is not working, and the signals that a program has already become a compliance checkbox are in seven signs your security awareness is just a checkbox.

    At Fensivo we build that cycle into the product: email phishing simulations from curated templates matched by role, past behavior and the company's real context, conversational microlearning that reaches whoever fails within minutes, and a retest three weeks later with a different template in the same category and sophistication. It is the same four-week calendar, running all year instead of only in October. To see how it applies to a specific situation, you can review the use cases.

    If someone asked you on November 1 how many people in your company changed their behavior during October, would you have a number to defend or an attendance list?

    Sources and references

    • CISA, "4 Things You Can Do To Keep Yourself Cyber Safe". https://www.cisa.gov/news-events/news/4-things-you-can-do-keep-yourself-cyber-safe
    • IBM, Cost of a Data Breach Report 2026. https://www.ibm.com/reports/data-breach
    • Gartner, "4 Tactics to Achieve Secure Employee Behaviors", prediction to 2030. https://www.gartner.com/en/publications/employee-behaviors

    Human risk is managed automatically.

    Turn human risk into your first line of defense.

    Book a demo

    Free demo · 30 minutes · No commitment