October is Cybersecurity Awareness Month

Oct 26, 2021 | Cyber Security, IT News

October is officially designated as National Cybersecurity Awareness Month. If you didn’t know, that’s quite alright, because today we’ll be delving into its history, why it exists and how you can best observe it, no matter what month of the year it is.

When did Cybersecurity Awareness Month begin?

National Cybersecurity Awareness Month started back in 2004. It was first launched by the National Cyber Security Alliance and the U.S. Department of Homeland Security in October of that year as a broad effort to help all Americans stay safer and more secure online.

How did Cybersecurity Awareness Month begin?

NCAM originally had slightly more humble beginnings. When it first started, the awareness efforts centered around simple advice like updating your antivirus software twice a year in the same way you might change batteries in smoke alarms during Daylight Saving time. Small, generic tips like that make little sense today of course. But since then, NCSA and DHS have combined efforts, and the month has grown in both reach and participation. It now includes multiple industries that engage customers, employees and the general public in awareness — as well as college campuses, nonprofits and other various groups.

How do you observe Cybersecurity Awareness Month?

In order to observe National Cybersecurity Awareness Month, the Cybersecurity and Infrastructure Security Agency (CISA) would like everyone in the U.S. to take heed of the following:

Cybersecurity at Work

Businesses face significant financial loss when a cyberattack occurs. Cybercriminals often rely on human error — employees failing to install software patches or clicking on malicious links — to gain access to systems. From the top leadership to the newest employee, cybersecurity requires everyone to keep their data, customers and capital safe and secure.

Cybersecurity while Traveling

In a world where we are constantly connected, cybersecurity cannot be limited to the home or office. When you’re traveling, whether domestic or international, it is always important to practice safe online behavior and take proactive steps to secure internet-enabled devices. The more we travel, the more we are at risk for cyberattacks.

Identity Theft and Internet Scams

Today’s technology allows us to connect around the world, to bank and shop online, and to control our televisions, homes and cars from our smartphones. With this added convenience comes an increased risk of identity theft and internet scams.

Multi-factor Authentication

You should be using multi-factor authentication, also called strong authentication, or two-factor authentication. This technology may already be familiar to you, as many banking and financial institutions require both a password and one of the following to log in: a call, email or text containing a code. By applying these principles of verification to more of your personal accounts, such as email, social media and more, you can better secure your information and identity online.

Online Privacy

The internet touches almost all aspects of our daily lives. We can shop, bank, connect with family and friends, and handle our medical records all online. These activities require you to provide personally identifiable information (PII) such as your name, date of birth, account numbers, passwords and location information. Beware the types of sites you allow to have this information.

Passwords

Creating a strong password is an essential step to protecting yourself online. Using long and complex passwords is one of the easiest ways to defend yourself from cybercrime.

Phishing

Phishing attacks use email or malicious websites to infect your machine with malware and viruses in order to collect personal and financial information. Cybercriminals attempt to lure users to click on a link or open an attachment that infects their computers, creating vulnerability to attacks. Phishing emails may appear to come from a real financial institution, e-commerce site, government agency, or any other service, business, or individual. The email may also request personal information such as account numbers, passwords or Social Security numbers. When users respond with the information or click on a link, attackers use it to access users’ accounts.

Cybersecurity needs to be practiced all year long, rather than simply one month a year. But October is a great time to remember the basics. And for year-round guidance and 24/7 protection, you can rely on us.

Since 1995, Manassas Park, VA-based V2 Systems has employed local systems administrators, network engineers, security consultants, help desk technicians and partnering companies to meet a wide range of clients’ IT needs, from research, to implementation, to maintenance. Concentrate on your VISION…We’ll handle the TECHNOLOGY!

More From V2 Systems

CMMC Update: What Government Contractors Need to Know as of August 2026

The Department of War announced the immediate suspension of CMMC Phase II requirements on July 13, 2026, pausing upcoming third-party assessment mandates. However, Phase I self-assessments, NIST SP 800-171 Rev. 2, DFARS 252.204-7012, and core cybersecurity obligations remain active. This blog explains what government contractors need to know as of August 2026 and how to stay prepared during the review period.

Summer Cyber Risks: Why Attacks Spike When Teams Are Short-Staffed

Summer vacations, lighter staffing, remote work, and busy schedules can create cybersecurity gaps for small businesses and government contractors. This blog explains why attackers take advantage of short-staffed teams and what organizations can do to reduce risk during the summer months.

Why Security Awareness Training Fails and How to Fix It

Security awareness training often fails because it is too generic, too infrequent, or too disconnected from how employees actually work. This blog explains why annual training alone is not enough and how small businesses and government contractors can build a more practical, ongoing approach to cybersecurity awareness.

Cybersecurity Fatigue Is Real: How to Keep Employees Engaged Without Burnout

Employees play a critical role in cybersecurity, but constant warnings, training reminders, password prompts, and security alerts can lead to fatigue. This blog explains how small businesses and government contractors can keep employees engaged with cybersecurity without overwhelming them.

How Government Contractors Can Stay Secure During Disruptions and Staffing Gaps

Disruptions are unavoidable, but security gaps do not have to be. For government contractors, staffing shortages, PTO, turnover, shutdowns, and contract transitions can create real cybersecurity and compliance risk. This blog explains how GovCons can maintain security, protect sensitive data, and keep operations moving when key people are unavailable.

Free
Small Business Cybersecurity Checklist

cybersecurity checklist graphic