Insights



Insights

News - Stories - Insight - New Products

Discover updates, insights and stories that reflect what we’re working on and why it matters.

 

 

Cyber Awareness Month is Coming: Is Your Organisation Ready to Rethink Human Risk?

Introduction

Every October, Cyber Awareness Month provides organisations with an opportunity to shine a spotlight on cyber security, engage employees, and reinforce the behaviours that protect critical systems and information. However, the most successful organisations are increasingly recognising that cyber awareness is not a once-a-year campaign. It is an ongoing risk management discipline that requires evidence, measurement, and continuous improvement. [ncsc.gov.uk], [ncsc.gov.uk]

As we approach October, now is the perfect time to ask a simple but important question:

How confident are you that your cyber awareness programme is genuinely reducing risk?

Moving Beyond Compliance-Driven Awareness

For many organisations, cyber awareness has historically consisted of annual training sessions, a signed policy acknowledgement, and perhaps an occasional phishing exercise.

While these activities remain important, cyber threats have evolved significantly. Attackers continue to exploit human behaviour through phishing, social engineering, credential theft, and business email compromise. Even organisations with strong technical controls remain vulnerable if employees are not equipped to recognise, report, and respond appropriately to threats. [ncsc.gov.uk]

Modern cyber awareness programmes should therefore focus on more than simply delivering training. They should help organisations understand:

  • Where human risk exists
  • Which individuals or teams require additional support
  • Whether awareness levels are improving over time
  • How effectively policies are understood and followed
  • Whether employees can identify and report suspicious activity

The objective is no longer just awareness. It is measurable risk reduction.

The Challenge of Assurance

One of the biggest questions security leaders face is how to obtain assurance that awareness initiatives are actually working.

Boards, auditors, regulators, and customers increasingly expect evidence rather than assumptions. Simply confirming that employees completed a training course does not necessarily demonstrate behavioural change or reduced cyber risk.

Effective assurance typically combines several elements:

  • Security awareness training
  • Phishing and social engineering simulations
  • Policy management and acknowledgement
  • Risk assessments
  • Incident reporting metrics
  • Behavioural and engagement reporting

Together, these provide meaningful insight into how people interact with cyber security requirements and where vulnerabilities may remain.

This approach helps security teams move from a "tick-box" exercise to a data-driven understanding of human cyber risk.

Supporting ISO 27001 Objectives

For organisations pursuing or maintaining ISO 27001 certification, an effective awareness programme is more than good practice.

ISO 27001 places clear emphasis on information security awareness, education, responsibilities, and the ongoing development of security culture across the organisation. Training should be regular, relevant, and linked to identified business risks. Organisations are also expected to demonstrate continual improvement and maintain appropriate records of awareness activities. [arsen.co], [phishcare.com]

A mature awareness strategy can support key ISO 27001 objectives by:

  • Demonstrating employee security education
  • Reinforcing information security responsibilities
  • Providing evidence of continual improvement
  • Supporting risk treatment activities
  • Helping identify and address human vulnerabilities

Importantly, awareness should be treated as a core component of the Information Security Management System rather than a standalone activity.

Aligning with NCSC Cyber Assessment Framework Expectations

For organisations using the NCSC Cyber Assessment Framework (CAF), the importance of people and culture is equally clear.

The CAF encourages organisations to manage cyber security as an organisational risk and implement measures that improve resilience against threats, including phishing and social engineering attacks. The NCSC consistently advocates a layered approach that combines technology, processes, and user education rather than relying solely on employees spotting malicious messages. [ncsc.gov.uk]

Awareness programmes contribute to CAF-aligned outcomes by helping organisations:

  • Develop a positive cyber security culture
  • Improve detection and reporting behaviours
  • Reduce the likelihood of successful social engineering attacks
  • Support governance and risk management activities
  • Generate evidence that controls are operating effectively

When linked to risk management and measurable outcomes, awareness activities become an important source of assurance for senior leaders.

October is the Ideal Catalyst for Change

Cyber Awareness Month often prompts organisations to refresh training content, launch awareness campaigns, or conduct phishing exercises.

But rather than viewing October as a standalone event, organisations should use it as a catalyst for long-term transformation.

The most effective programmes:

  • Deliver continuous learning throughout the year
  • Tailor content to different risk profiles
  • Measure behavioural outcomes
  • Reinforce policies at relevant moments
  • Use reporting and analytics to guide improvement
  • Focus on reducing risk rather than increasing training completion rates

By embedding awareness into everyday business operations, organisations can make meaningful improvements that extend far beyond a single month.

It's Not Too Late

With October approaching, many organisations may feel that significant change will need to wait until next year.

The reality is quite the opposite.

There is still time to transform your approach by focusing on the fundamentals:

  • Understand your human risk landscape
  • Review the effectiveness of current training
  • Assess how awareness is being measured
  • Evaluate policy engagement and compliance
  • Improve assurance reporting for stakeholders
  • Establish a strategy for continuous improvement

Even incremental changes made today can deliver substantial benefits over the coming months.

Cyber Awareness Month should not simply be a reminder to deliver training. It should be an opportunity to build a stronger security culture, improve assurance, and demonstrate that cyber risk is being actively managed across the organisation.

Those who act now can enter October with more than a campaign plan. They can enter with a roadmap for lasting cyber resilience.

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.