The Problem with CISA’s 2026 Cybersecurity Awareness Month Recommendations

As it does every year, the Cybersecurity and Infrastructure Security Agency (CISA) issued its Cybersecurity Awareness Month recommendations a few weeks ago. The recommendations provide a useful baseline for reducing everyday cyber risk. Unfortunately, they are insufficient for defending against the modern identity-based attacks that large organizations face today.
Attackers increasingly rely on impersonation, combining a broad range of tactics and technologies to exploit trust. Strong passwords, phishing training, and even multi-factor authentication (MFA) were not designed to contend with infostealer logs, fraud-as-a-service platforms, deepfake impersonations, synthetic identities created with valid Social Security numbers and AI-generated documentation, AI-powered phishing, social engineering, SIM swaps, and session hijacking.
If organizations do not go beyond CISA’s recommendations, they leave attackers with a substantial advantage.
Organizations need to gather evidence about who should control an account and monitor risk signals that indicate when confidence in that identity should change. Those risk signals must be aggregated, evaluated in context, and converted into risk-aware access decisions.
CISA’s 2026 Recommendations and Why the Current Threat Landscape Demands More
CISA’s 2026 Cybersecurity Awareness Month recommendations include the following:
- Avoid and report phishing scams.
- Use strong passwords.
- Use MFA and a password manager.
- Update software.
These actions do reduce exploitable exposure. Employee awareness can interrupt a phishing attempt, while unique passwords limit the damage caused by password reuse. CISA’s 2026 campaign toolkit also recommends phishing-resistant MFA where available. This is an important distinction from authentication methods that remain vulnerable to phishing.
However, organizations that have made basic investments in cybersecurity have generally already trained employees to recognize phishing attempts and implemented stronger authentication controls. Phishing-resistant MFA adoption remains far from universal. Even where organizations have adopted stronger authentication, processes surrounding MFA, including enrollment and recovery, can remain vulnerable.
Ultimately, phishing-resistant authentication still depends on the enterprise assigning the authenticator to the right person.
Attackers understand this. Rather than attacking MFA directly, they can target processes with weaker identity controls, such as the service desk, account recovery, or authenticator enrollment.
CISA’s recommendations also do not address what happens when a valid credential or authentication factor has been compromised. Password strength does not reveal that a valid credential has been stolen and used to log in. Employee vigilance alone cannot detect when a compromised account uses excessive permissions to retrieve sensitive records.
Nor do the four recommendations define how an enterprise should evaluate a newly registered authentication factor alongside unusual account activity. They do not specify when evidence from another system should override the confidence implied by a successful login. These decisions remain essential even when an organization carefully follows the underlying recommendations.
In a September 9, 2026, investigation, Microsoft’s Krithika Ramakrishnan and fellow researchers described intrusions involving unusual sign-ins followed by attacker-added authentication methods. Subsequent activity included the collection of cloud-hosted data. Some lures invoked passkeys while directing employees into other authentication flows.
The findings did not show that attackers had broken passkey cryptography. Instead, they demonstrated the importance of understanding how an identity acquired access and what happened afterward.
Those observations show that while CISA’s recommendations are not obsolete, organizations cannot treat them as sufficient. An authentication control can accept an enrolled factor without establishing that the enrollment itself was legitimate. A business application can then honor the resulting access without recognizing the warning signs that preceded it.
Each Identity Layer Needs to Answer a Different Question
Organizations need a way to connect identity evidence before an attacker completes a sensitive action. Identity threat detection helps determine whether the person attempting to use personally identifiable information (PII) is the person to whom that information genuinely belongs. Risk mitigation turns that determination into a decision about access.
Identity verification can provide evidence about who a person is. However, an organization still needs to connect that verified identity to the account being claimed. Confirming someone’s identity provides no basis for handing over an unrelated employee account. Similarly, a valid identity document cannot establish that an existing session remains under that person’s control.
The relationship that authorizes access matters as well. A former contractor, for example, may prove their identity perfectly while no longer being entitled to access the organization’s systems.
Consider an employee who loses a phone and requests a replacement authentication method from an unfamiliar device. That sequence can be entirely legitimate. However, it also removes some of the evidence the enterprise previously relied on to recognize the employee.
Now suppose the phone number associated with the account has recently been transferred to a different device. Sending a code to that number provides limited reassurance about who currently controls it. The National Institute of Standards and Technology’s Authentication Guidance recommends considering device changes, SIM changes, and other risk indicators before delivering an authentication secret through the telephone network.
The enterprise now must decide whether to permit enrollment of a new authentication factor. Treating every device change as malicious would create unnecessary friction for legitimate employees. Ignoring the change would discard evidence directly relevant to the proposed verification method.
An additional layer should address that uncertainty. Repeating verification through the same suspect channel adds activity without resolving the underlying question of ownership. An independently established route back to the account holder may provide the missing assurance. If no such route is available, pausing enrollment may be appropriate while the organization resolves the claim.
A useful risk model also examines whether apparently separate signals are measuring the same underlying fact. An unfamiliar device and a short-observed device history, for example, may both reflect the first time a provider has encountered that device. Counting them as independent indicators of risk could overstate the evidence. A short-observed history also differs from proof that the device itself is new.
Combining signals requires rules about what evidence cannot simply be traded away. A history of trusted device activity should not offset confirmed evidence that an attacker enrolled in an authentication factor. A model that averages contradictory findings into a reassuring score can obscure the very event that should stop an account change.
These distinctions determine whether a layered approach improves security decisions. More signals do not necessarily provide more certainty. Their value depends on their relevance to the requested action and what the enterprise can reasonably infer from the available evidence.
The Bottom Line on CISA’s Recommendations
CISA’s recommendations reduce common exposure, but they leave organizations with a harder problem: deciding whether to continue trusting an identity when the evidence changes. A successful login cannot settle that question on its own.
Organizations need to connect risk signals across a multitude of interactions and use them to continuously reassess identity risk before a compromised account completes a sensitive action. This requires a multi-layered approach that connects identity threat detection with risk mitigation, so changes in risk lead to appropriate changes in access.
Cybersecurity hygiene remains important. But in an environment where attackers increasingly exploit legitimate credentials, authentication processes, recovery workflows, and trusted identities, organizations need to move beyond asking whether someone successfully authenticated. They also need to determine whether that identity can still be trusted.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







