Cybersecurity Awareness Month 2026

The Trends Worth a Security Leader's Actual Attention

Cybersecurity Awareness Month 2026

Cybersecurity Awareness Month 2026 arrives with two official themes this year: CISA’s “Securing the Next 250,” aimed at infrastructure resilience, and the National Cybersecurity Alliance’s “Don’t Make It Easy for Them,” aimed at everyday habits. Both are reasonable. Neither is going to tell a security leader much they don’t already know, and most of the content published under this banner each October repeats the same break-room-poster advice regardless of what’s actually changed in the threat landscape that year.

This isn’t that piece. Below are five trends from the current data, not the advice circuit, including one that cuts against what the industry’s own training vendors are telling you.




Does Security Awareness Training Actually Work?

This is the question Awareness Month exists to answer, and the honest answer is more complicated than the statistic you’ll see cited everywhere this month. KnowBe4’s 2025 Phishing by Industry Benchmarking Report, drawn from 67.7 million phishing simulations across its own platform, found a global phishing simulation click rate of 33.1 percent before training, dropping to 4.1 percent after 12 months of continuous training, an 86 percent reduction.

Phishing simulation click rate before and after 12 months of continuous training. This is single-vendor platform data; see the independent research discussed below. Source: KnowBe4, 2025 Phishing by Industry Benchmarking Report.
Figure 1. Phishing simulation click rate before and after 12 months of continuous training. This is single-vendor platform data; see the independent research discussed below. Source: KnowBe4, 2025 Phishing by Industry Benchmarking Report.

That number is worth a direct caveat: it’s self-reported by a company that sells security awareness training, measured on its own platform, using its own customers. It isn’t independently audited, and it isn’t the only research on this question. A 2025 University of Chicago study of phishing training completion found no meaningful reduction in phishing susceptibility, and separate peer-reviewed research presented at USENIX found that training effects, where they exist, fade within roughly six months without reinforcement. Both findings can be true at once: training probably does something, and the dramatic, uncomplicated number getting repeated across every Awareness Month listicle this October is coming from the company with the clearest financial interest in that number being as large as possible. Treat vendor-reported training statistics the way you’d treat a vendor-reported false-positive rate: directionally useful, not independently verified.




AI Is Changing Both Sides of the Fight

Microsoft’s 2025 Digital Defense Report found that AI-generated phishing emails get clicked at roughly 4.5 times the rate of human-written ones, a 54 percent click-through rate compared to an estimated 12 percent baseline.

Click-through rate by phishing email authorship. The human-written baseline is derived from the reported 4.5x ratio. Source: Microsoft Digital Defense Report 2025.
Figure 2. Click-through rate by phishing email authorship. The human-written baseline is derived from the reported 4.5x ratio. Source: Microsoft Digital Defense Report 2025.

This has a direct implication for the training conversation above: even a well-designed awareness program trained against last year’s phishing patterns is being tested against a meaningfully more convincing threat this year, which is a reasonable part of why training effects documented in older research might not hold up against current attack quality. The same AI-assisted escalation shows up in voice and video channels specifically. Deepfake-enabled vishing, voice-cloned or otherwise AI-assisted phone calls, surged roughly 1,633 percent quarter-over-quarter in a measurement period spanning late 2024 into 2025, according to CrowdStrike data. Separately, peer-reviewed research on human deepfake detection accuracy has found it averages barely above chance even among people actively trying to spot a fake, and worse than chance for high-quality deepfake video specifically. The defensible response to that specific finding isn’t more detection training; it’s verification procedures that don’t depend on recognizing a voice or face at all.




The Pipeline Has Replaced the Inbox as a Target

CISA’s “Securing the Next 250” theme is aimed at infrastructure resilience, and the most concrete current data on that front isn’t about email anymore. GitGuardian’s 2026 State of Secrets Sprawl report found that 59 percent of machines with compromised credentials in 2025 were CI/CD runners, not developer workstations, a reversal of where this kind of compromise has traditionally concentrated.

Share of machines with compromised credentials, by type, 2025. Source: GitGuardian, State of Secrets Sprawl 2026.
Figure 3. Share of machines with compromised credentials, by type, 2025. Source: GitGuardian, State of Secrets Sprawl 2026.

The same report found 64 percent of secrets confirmed valid in 2022 were still valid and unrevoked as of January 2026, and real-world incidents have followed the pattern: the March 2025 tj-actions/changed-files compromise exposed secrets across more than 23,000 repositories, and a March 2026 campaign publicly tracked as TeamPCP exfiltrated more than 78,000 secrets from over 2,100 organizations in five days. If your Awareness Month training budget is entirely aimed at employee inboxes this year, it’s aimed at a shrinking share of where credential compromise is actually concentrating.




The Window to React Has Shrunk From Months to Days

Separate from where attacks originate, the speed at which a disclosed vulnerability becomes an active exploit has compressed sharply. Research on vulnerability exploitation timing found the median time between disclosure and active exploitation fell from roughly 63 days to about 5 days.

Median time between vulnerability disclosure and active exploitation. Source: Mondoo, 2026 vulnerability exploitation research.
Figure 4. Median time between vulnerability disclosure and active exploitation. Source: Mondoo, 2026 vulnerability exploitation research.

This is the backdrop for CISA’s recommendation that organizations maintain an incident response plan they’ve actually tested, one of the few concrete asks buried in this year’s otherwise general awareness messaging. A five-day window doesn’t accommodate a response plan that exists only as a document; it requires one that’s been rehearsed enough to execute quickly, under pressure, without a meeting to figure out who’s responsible for what.




Compliance Enforcement Is Catching Up to the Gap Between Certified and Secure

The clearest evidence that certification and actual security have diverged is coming from regulators themselves. Every one of the first ten HIPAA settlements HHS’s Office for Civil Rights announced in 2025 cited the same root finding: failure to conduct an accurate, thorough risk analysis, and all four of OCR’s ransomware-related settlements in April 2026 found that same failure had existed before the ransomware ever arrived. In parallel, Deloitte’s compliance survey of European financial institutions under DORA, fully enforceable since January 2025, found full compliance varying from 48 percent on incident management down to just 8 percent on resilience testing and third-party risk management, more than a year after the regulation’s own deadline passed. Regulators in both sectors are no longer accepting a certification or a policy document as evidence of security; they’re asking for the underlying analysis, and increasingly finding it wasn’t actually done.




What This Adds Up To

None of these five trends are really about October specifically. They’re about a gap between what most organizations’ security programs were built to defend against and what’s actually happening now: training programs calibrated against last year’s phishing, infrastructure trust models built before the pipeline became the primary target, incident response plans untested against a five-day reaction window, and compliance programs treating certification as the finish line regulators themselves no longer accept as sufficient. Awareness Month is a reasonable prompt to check which of these gaps applies to your organization specifically. It’s a less reasonable place to find the answer, since most of what gets published under its banner is advice calibrated for a general audience, not the specific, current data a security leader actually needs to prioritize against.




Frequently Asked Questions

The most commonly cited figure, an 86 percent reduction in click rates after 12 months of training, comes from a single vendor’s self-reported platform data. Independent research is more mixed: a 2025 University of Chicago study found no meaningful reduction from training completion, and separate peer-reviewed research found training effects fade within about six months without reinforcement.
Microsoft’s 2025 Digital Defense Report found AI-generated phishing emails get clicked at roughly 4.5 times the rate of human-written ones, likely because AI-generated text eliminates common quality and language tells that both training and informal pattern recognition have historically relied on.
CI/CD runners concentrate significant standing privilege and access to secrets in one place. GitGuardian’s 2026 research found 59 percent of machines with compromised credentials in 2025 were CI/CD runners rather than developer workstations, a reversal of where this kind of compromise has traditionally concentrated.
Research on vulnerability exploitation timing found the median time between disclosure and active exploitation fell from roughly 63 days to about 5 days, which has direct implications for how quickly an incident response plan needs to be executable, not just documented.
They remain a useful baseline, but regulators are increasingly treating them as insufficient on their own. HHS OCR has cited risk analysis failure as the root cause in nearly every recent HIPAA settlement, and DORA compliance data shows wide gaps between certification and actual operational readiness more than a year after the regulation’s enforcement deadline.
Rather than generic advice, prioritize whichever current gap applies most directly to your organization: updating training assumptions against AI-generated phishing quality, auditing CI/CD credential and runner trust boundaries, stress-testing incident response timelines against a multi-day rather than multi-week exploitation window, and verifying that compliance documentation reflects an actual, current risk analysis rather than a point-in-time certification.