Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecurityCybersecurity News

Password month? How we can make CSAM work for everyone

By Ian McShane
cybersecurity-awareness-fp1170x658v4.jpg

Image via Freepik

October 3, 2022

Cybersecurity Awareness Month may not be everyone’s favorite holiday, but for the cybersecurity industry, it can inspire the same love-hate relationship that most people have with their chosen festivities throughout the holiday season.


The month serves as an opportunity for cybersecurity companies around the world to gain extra exposure for their work in sectors beyond their typical customer base through pithy media comments and a heavy slate of conferences. But the celebrations also bring pressure for companies to sell new cybersecurity tools and services, drowning out more altruistic efforts to raise real awareness about the problems and causes in cybersecurity. Similarly, reaching an audience who actually needs to become more aware of the importance of cybersecurity has historically been a struggle for technical-minded practitioners during the month of October.


The security community needs Cybersecurity Awareness Month, but we need to do it better in order to advance our mission of keeping people safe online and helping them understand why that safety matters.


The first step to creating a more effective awareness campaign is improving the way industry people disseminate information to those who are not in the industry. Too often in October, I see colleagues online shaming or mocking outdated security practices, like keeping your passwords in a physical notebook, or insinuating that good-faith cybersecurity awareness campaigns are too elementary in their teachings to make a difference. Whether you think that you’re too knowledgeable to participate in Cybersecurity Awareness Month or not, it ultimately doesn’t matter if cyberattacks continue to rise every year, in virtually every sector.


It takes all of my Zen not to respond by telling these industry professionals that they are not, nor should they ever be, the intended audience for Cybersecurity Awareness Month. Our industry has a real problem with communicating in general with non-technical people, and nothing will slow our progress quite like inferring that the general public is too blockheaded to adopt proper security practices. For example, there’s no reason it should have taken 10 years, so far, to fail at convincing the general public to use unique passwords everywhere. Technology is available to help them, notebooks are available to help them, but they won’t know that if we as an industry continue to do a terrible job of communicating the benefits of basic cybersecurity hygiene.


Another drawback of Cybersecurity Awareness Month is the emphasis on selling, rather than educating, the market. The month could play a huge role in showcasing the benefits of adhering to basic measures like using unique passwords, password managers and multifactor authentication, but too often vendors use the month as a sales opportunity to push a new product instead of pushing better information about security practices. A more meaningful sales pitch might be if every security company gave away a service for free in October, enabling customers to learn for free why they should invest in cybersecurity before an attack happens rather than after.


But even absent an industry-wide freebie program, programming around the month is getting better, thanks to the celebration’s tremendous growth in popularity in the last five years. Government agencies in the United States and the United Kingdom are participating in exercises dedicated to this year’s theme, which is “See yourself in Cyber.” The Cybersecurity and Infrastructure Security Agency plans on doubling down on highlighting the importance of using MFA, strong passwords, recognizing phishing attempts and updating software regularly in order to empower the average person into taking ownership of their security posture. This is an admirable goal, and it’s one that I think we can run back next year, and the year after, and the year after that.


Until those basics are accomplished, we should probably call it password month.

KEYWORDS: authentication cyber security password risk management

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Ian McShane is Vice President of Strategy at Arctic Wolf and is a former Gartner analyst.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Top Cybersecurity Leaders
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Popular Stories

Man on laptop

Healthcare Executives Face a New Era of Personal Risk

Man walking with briefcase

The Rising Tide of Executive Protection: Corporations Ramp Up Security in an Era of Heightened Threats

Stadium

Physical Security in Global Arenas: How AI Improves Security at Scale

Digital Information Protected Secured

Taming the Threat Beast: Building a Threat-Led Cybersecurity Program

Chatbot prompt screen

8 in 10 AI Chatbots Likely to Help Plan Attacks, Hate Crimes

SEC 2026 Benchmark Banner
SEC 2026 Benchmark Banner

Events

April 21, 2026

The Blind Spot in Enterprise Security: Managing Workforce Risk Post-Hire

Organizations continuously monitor their networks and systems for risk, yet the people with legitimate access are often the least monitored part of the model. Discover a Workforce Risk Intelligence Framework that adds a dedicated layer focused on workforce risk.

April 30, 2026

Building a Campus-Wide Culture of Security and Shared Responsibility

In today’s higher education environment, where institutions face evolving and multifaceted incidents, safety must be embedded into the fabric of campus culture. Learn strategies for generating collective buy-in from faculty, staff, students and senior leadership. 

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
SEC 2026 Top Cybersecurity Leaders

Related Articles

  • hacker

    How to Work with Hackers to Make Your Company More Secure

    See More
  • Is Your Vendor Risk Management Program Working? - Security Magazine

    Quantifying Risk & Security Funding: How Everyone Can Get What They Want

    See More
  • cyber security freepik

    How women can break the cybersecurity glass ceiling - And why we need to help them

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • school security.jpg

    School Security: How to Build and Strengthen a School Safety Program

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing