Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity Leadership and ManagementLogical Security

The Problem with CISA’s 2026 Cybersecurity Awareness Month Recommendations

By Mouhamad Mbacke
Closed padlock on keyboard
Sasun Bughdaryan via Unsplash
October 1, 2026

As it does every year, the Cybersecurity and Infrastructure Security Agency (CISA) issued its Cybersecurity Awareness Month recommendations a few weeks ago. The recommendations provide a useful baseline for reducing everyday cyber risk. Unfortunately, they are insufficient for defending against the modern identity-based attacks that large organizations face today.

Attackers increasingly rely on impersonation, combining a broad range of tactics and technologies to exploit trust. Strong passwords, phishing training, and even multi-factor authentication (MFA) were not designed to contend with infostealer logs, fraud-as-a-service platforms, deepfake impersonations, synthetic identities created with valid Social Security numbers and AI-generated documentation, AI-powered phishing, social engineering, SIM swaps, and session hijacking.

If organizations do not go beyond CISA’s recommendations, they leave attackers with a substantial advantage.

Organizations need to gather evidence about who should control an account and monitor risk signals that indicate when confidence in that identity should change. Those risk signals must be aggregated, evaluated in context, and converted into risk-aware access decisions.

CISA’s 2026 Recommendations and Why the Current Threat Landscape Demands More

CISA’s 2026 Cybersecurity Awareness Month recommendations include the following:

  • Avoid and report phishing scams.
  • Use strong passwords.
  • Use MFA and a password manager.
  • Update software.

These actions do reduce exploitable exposure. Employee awareness can interrupt a phishing attempt, while unique passwords limit the damage caused by password reuse. CISA’s 2026 campaign toolkit also recommends phishing-resistant MFA where available. This is an important distinction from authentication methods that remain vulnerable to phishing.

However, organizations that have made basic investments in cybersecurity have generally already trained employees to recognize phishing attempts and implemented stronger authentication controls. Phishing-resistant MFA adoption remains far from universal. Even where organizations have adopted stronger authentication, processes surrounding MFA, including enrollment and recovery, can remain vulnerable.

Ultimately, phishing-resistant authentication still depends on the enterprise assigning the authenticator to the right person.

Attackers understand this. Rather than attacking MFA directly, they can target processes with weaker identity controls, such as the service desk, account recovery, or authenticator enrollment.

CISA’s recommendations also do not address what happens when a valid credential or authentication factor has been compromised. Password strength does not reveal that a valid credential has been stolen and used to log in. Employee vigilance alone cannot detect when a compromised account uses excessive permissions to retrieve sensitive records.

Nor do the four recommendations define how an enterprise should evaluate a newly registered authentication factor alongside unusual account activity. They do not specify when evidence from another system should override the confidence implied by a successful login. These decisions remain essential even when an organization carefully follows the underlying recommendations.

In a September 9, 2026, investigation, Microsoft’s Krithika Ramakrishnan and fellow researchers described intrusions involving unusual sign-ins followed by attacker-added authentication methods. Subsequent activity included the collection of cloud-hosted data. Some lures invoked passkeys while directing employees into other authentication flows.

The findings did not show that attackers had broken passkey cryptography. Instead, they demonstrated the importance of understanding how an identity acquired access and what happened afterward.

Those observations show that while CISA’s recommendations are not obsolete, organizations cannot treat them as sufficient. An authentication control can accept an enrolled factor without establishing that the enrollment itself was legitimate. A business application can then honor the resulting access without recognizing the warning signs that preceded it.

Each Identity Layer Needs to Answer a Different Question

Organizations need a way to connect identity evidence before an attacker completes a sensitive action. Identity threat detection helps determine whether the person attempting to use personally identifiable information (PII) is the person to whom that information genuinely belongs. Risk mitigation turns that determination into a decision about access.

Identity verification can provide evidence about who a person is. However, an organization still needs to connect that verified identity to the account being claimed. Confirming someone’s identity provides no basis for handing over an unrelated employee account. Similarly, a valid identity document cannot establish that an existing session remains under that person’s control.

The relationship that authorizes access matters as well. A former contractor, for example, may prove their identity perfectly while no longer being entitled to access the organization’s systems.

Consider an employee who loses a phone and requests a replacement authentication method from an unfamiliar device. That sequence can be entirely legitimate. However, it also removes some of the evidence the enterprise previously relied on to recognize the employee.

Now suppose the phone number associated with the account has recently been transferred to a different device. Sending a code to that number provides limited reassurance about who currently controls it. The National Institute of Standards and Technology’s Authentication Guidance recommends considering device changes, SIM changes, and other risk indicators before delivering an authentication secret through the telephone network.

The enterprise now must decide whether to permit enrollment of a new authentication factor. Treating every device change as malicious would create unnecessary friction for legitimate employees. Ignoring the change would discard evidence directly relevant to the proposed verification method.

An additional layer should address that uncertainty. Repeating verification through the same suspect channel adds activity without resolving the underlying question of ownership. An independently established route back to the account holder may provide the missing assurance. If no such route is available, pausing enrollment may be appropriate while the organization resolves the claim.

A useful risk model also examines whether apparently separate signals are measuring the same underlying fact. An unfamiliar device and a short-observed device history, for example, may both reflect the first time a provider has encountered that device. Counting them as independent indicators of risk could overstate the evidence. A short-observed history also differs from proof that the device itself is new.

Combining signals requires rules about what evidence cannot simply be traded away. A history of trusted device activity should not offset confirmed evidence that an attacker enrolled in an authentication factor. A model that averages contradictory findings into a reassuring score can obscure the very event that should stop an account change.

These distinctions determine whether a layered approach improves security decisions. More signals do not necessarily provide more certainty. Their value depends on their relevance to the requested action and what the enterprise can reasonably infer from the available evidence.

The Bottom Line on CISA’s Recommendations

CISA’s recommendations reduce common exposure, but they leave organizations with a harder problem: deciding whether to continue trusting an identity when the evidence changes. A successful login cannot settle that question on its own.

Organizations need to connect risk signals across a multitude of interactions and use them to continuously reassess identity risk before a compromised account completes a sensitive action. This requires a multi-layered approach that connects identity threat detection with risk mitigation, so changes in risk lead to appropriate changes in access.

Cybersecurity hygiene remains important. But in an environment where attackers increasingly exploit legitimate credentials, authentication processes, recovery workflows, and trusted identities, organizations need to move beyond asking whether someone successfully authenticated. They also need to determine whether that identity can still be trusted.

KEYWORDS: CISA cybersecurity awareness identity identity challenges identity security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Mouhamad mbacke headshot

Mouhamad Mbacke is an Identity Security Evangelist at ID Dataweb, where he specializes in translating complex identity security concepts into clear, actionable insights for security professionals. With a focus on emerging cyberthreats and the evolving importance of identity threat detection and risk mitigation in enterprise defense, Mouhamad helps organizations understand how identity-centric security strategies can address the growing sophistication of credential-based attacks, account takeover, and synthetic identity fraud. His work explores how adaptive identity proofing, real-time threat detection, and continuous risk assessment are reshaping enterprise approaches to access management and zero-trust architectures. Image courtesy of Mbacke

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Leadership and Management
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

Healthcare supplies

3 Healthcare Breaches in Quick Succession Raises Concerns

Security's Most Influential people 2026

Security’s Most Influential People in Security 2026

Man driving

150M Driver’s Licenses Exposed, Security Experts Discuss

Police lights

Family of Fatally Shot Security Guard Seeking Answers

Stressed woman

Ransomware Doesn’t Just Break Systems. It Breaks People.


AlertMedia sponsored webinar

Events

October 7, 2026

Modernizing Travel Risk Management: How Security Teams are Strengthening Duty of Care

LIVE: October 7, 2026 at 2 PM EDT Learn how security teams have strengthened travel risk management for a global workforce. Move beyond manual monitoring to earlier, verified awareness and a more defensible approach to security operations.

October 20, 2026

Beyond the Camera: How AI Is Transforming Physical Security

LIVE: October 20, 2026 at 2 PM EDT AI can connect security systems to detect threats earlier, validate incidents in real time, & accelerate response. Move from passive monitoring to proactive, intelligence-led security while maximizing existing tech investments.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • cybersecurity-graphic

    CISA kicks off 20th Cybersecurity Awareness Month

    See More
  • cyber security

    Going back to the basics this Cybersecurity Awareness Month

    See More
  • purdue

    Purdue University Global to commemorate Cybersecurity Awareness Month with variety of activities

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • Risk Analysis and the Security Survey, 4th Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing