Cybersecurity Awareness Month: Does October Actually Make Us Safer?
By Thoughtful India Staff
Cybersecurity Awareness Month: Does October Actually Make Us Safer?
Every October, corporate inboxes fill with phishing drills and password posters. The attackers work all twelve months. The research on whether the ritual makes anyone safer is messier than the posters admit, and for India, where digital fraud now runs into the tens of thousands of crores, the question is not academic.
The short answer: Cybersecurity Awareness Month does not, by itself, build year-round vigilance. One-off October campaigns mostly produce completion reports, not safer employees, while continuous, behavior-focused programs measurably reduce susceptibility. The smart play is to treat October as a launchpad for a twelve-month program, not a twelve-month program compressed into thirty-one days.
Where did the October ritual come from?
In October 2004, the U.S. Department of Homeland Security's National Cyber Security Division and the nonprofit National Cyber Security Alliance launched the first National Cybersecurity Awareness Month. The advice was humble by today's standards: keep your antivirus software updated (Wikipedia). In September 2023, for the campaign's 20th anniversary, the Cybersecurity and Infrastructure Security Agency (CISA) gave it an enduring theme, "Secure Our World," built around four everyday habits: strong passwords, multi-factor authentication, recognizing and reporting phishing, and keeping software updated (CISA via GovDelivery).
CISA's own framing is telling. The agency says it has spent "more than 20 years" spotlighting "the importance of taking daily action to reduce risks when online," and adds that "cyber threats don't take time off" (CISA). Former CISA director Jen Easterly framed it as a civic duty: "we need everyone to do their part to combat the growing threats our nation faces in cyberspace" (CISA, 2021). Notice the tension inside the official story. The institutions that invented the month insist the threat is daily and year-round. The open question is whether a month-long campaign produces anything that survives into November.
What the numbers say about people
Verizon's Data Breach Investigations Report, the industry's most cited breach census, tracks the "human element": phishing, errors, stolen credentials, misuse of access. The share of breaches involving people fell from 82% in the 2022 edition to 74% in 2023, 68% in 2024 and 60% in 2025 (PhishingBox summary of the DBIR). In the 2025 edition, that 60% breaks down into credential abuse (32%), social actions like phishing and pretexting (23%), and malware needing a human click (7%) (Optery, citing the 2025 DBIR). The 2026 edition put the human element at 62%, and for the first time vulnerability exploitation (31%) overtook stolen credentials as the top initial-access vector (SecurityWeek).
Two readings are possible. The optimistic one: the trend is falling, so something (training, MFA adoption, better tooling) is working. The cautious one: the attack mix is shifting (third-party involvement in breaches doubled to 30% in 2025), and the human share may be shrinking because other doors are opening faster. Part of the 74%-to-68% drop is also definitional: the 2024 edition stopped counting malicious privilege misuse, which alone explains much of the fall (Security Scientist). Either way, most breaches still run through a person. One bright, specific finding stands out: summaries of the 2025 report note that organizations with regular security training saw employees' phishing reporting rates improve fourfold (Keepnet Labs; Bluefin).
The training industry's own numbers are dramatic but vendor-reported: KnowBe4's 2025 benchmarking study of 67.7 million simulated phishing emails found a 33.1% baseline "phish-prone" rate falling 86% after twelve months of ongoing training, to 4.1% (KnowBe4 via Business Wire).
The independent science is more conflicted, and more interesting. In 2007, Carnegie Mellon researchers led by Ponnurangam Kumaraguru published "Protecting People from Phishing," showing that embedded training (intervening at the moment someone falls for a simulated phish, with a short explanation) beat the standard practice of emailing security notices (ACM CHI 2007, doi:10.1145/1240624.1240760). The logic was elegant: teach people in the moment of failure, when the lesson stings.
Fifteen years later, ETH Zurich researchers ran the idea at industrial scale and got a shock. Daniele Lain, Kari Kostiainen and Srdjan Capkun followed more than 14,000 employees through 15 months of simulated phishing in their normal working context ("Phishing in Organizations," 2022 IEEE Symposium on Security and Privacy). Their finding, in the paper's own words: "embedded training during simulated phishing exercises, as commonly deployed in the industry today, does not make employees more resilient to phishing, but instead it can have unexpected side effects that can make employees even more susceptible to phishing" (arXiv:2112.07498). Their positive finding pointed elsewhere: employees with a reporting button functioned as a fast, practical collective detection system for new phishing campaigns.
The debate has not settled since. A large-scale 2025-26 reproduction study titled "Anti-Phishing Training (Still) Does Not Work" found training efficacy evaporating when measured against the NIST Phish Scale's difficulty gradings (arXiv:2506.19899). Yet a late-2025 European corporate study found that continuous exposure with immediate feedback nearly halved phishing success rates within six months, after which the gains stabilized (arXiv:2510.27298).
The largest test of all landed in 2025: an eight-month randomized controlled trial across more than 19,500 employees at UC San Diego Health. It found no significant relationship between having recently completed mandatory annual cybersecurity training and the likelihood of falling for a phish; employees who completed multiple static training sessions were 18.5% more likely to fall for one. The authors' verdict: "anti-phishing training programs, in their current and commonly deployed forms, are unlikely to offer significant practical value in reducing phishing risks" (Ho et al., IEEE Symposium on Security and Privacy 2025; UC San Diego).
Read together, the honest conclusion is not "training works" or "training fails." It is that design and frequency matter more than existence. Continuous, well-designed programs move the needle; annual compliance modules mostly move a checkbox. October-only training sits at the weakest end of that evidence.
The check-the-box machine
Ask practitioners and the critique sharpens. "Everyone passes. Leadership gets a report showing 100 percent completion. Compliance checks the box. Risk is declared 'managed.' Then someone clicks a phishing email the following Tuesday," writes security practitioner Travis Ray Caverhill (Medium, Dec 2025). Gary Brickhouse, CISO at GuidePoint Security, draws the line precisely: "There's a big difference between being compliant and being secure. When compliance becomes the end goal, that's when security theater thrives" (Dark Reading). One human-risk columnist admits that after twenty-plus years, the October drumbeat is "inescapable" and "getting kind of annoying" for the very teams running it (Business Reporter). The field's counter-prescription: "Security awareness isn't a box to check but a mindset to cultivate," built on continuous, role-based, interactive programs rather than annual events (Resultant). Oz Alashe put the October question most bluntly in an open letter to CISOs: "Every October, the industry comes together to raise awareness of cybersecurity. Yet, every year attacks continue to surge. If this 'awareness' celebration is having an impact, where are the improvements?" His conclusion: "Cybersecurity awareness, in isolation, doesn't work. It's dead" (Infosecurity Magazine). FedTech's verdict on the month lands in the same place: "Awareness is still essential, but it is insufficient… Awareness has opened the door. Now, it's time for action" (FedTech Magazine, Oct 2025).
The SANS Institute's Security Awareness Maturity Model, built with input from more than 200 awareness officers, gives this critique a formal shape. Its five stages run from "nonexistent" through "compliance focused" (training only to satisfy audit, annual or ad hoc) up to sustained culture change and a metrics framework (SANS). Stage two is the October-only trap: the box gets checked, employees remain unsure of their actual role, and the program stalls. Escaping it is slow; SANS practitioners put the horizon at a minimum of three to five years to genuinely change culture (ISACA Journal). The programs that do mature share two traits, per SANS's 2023 report: visible leadership support and a real team behind the effort.
In the 2013 Target breach, attackers entered through credentials stolen from a small HVAC contractor with remote network access, via a phishing email. A U.S. Senate analysis concluded the contractor could have disrupted the attack by "training its staff to recognize and report phishing emails." The breach exposed about 40 million payment cards and 70 million customer records, roughly halved Target's fourth-quarter profit, and ended the careers of both the CIO and the CEO (Senate Commerce Committee analysis).
India's October looks different, and the stakes are higher
India runs its own October campaigns, and its fraud problem dwarfs most countries'. The National Crime Records Bureau's "Crime in India 2023" counted 86,420 registered cybercrime cases, up 31.2% from 2022, with fraud the motive in 68.9% of them (Vajiram & Ravi summary of NCRB data). The Finance Ministry told Parliament in March 2026 that digital-payment frauds were 28.22 lakh cases worth Rs 4,403 crore in FY 2023-24, 27.56 lakh cases worth Rs 4,824 crore in FY 2024-25, and 24.17 lakh cases worth Rs 3,775 crore in FY 2025-26 up to January (Rajya Sabha Q. 3596, via Sansad). Against that, the Home Ministry reported that the citizen cyber-fraud reporting system has helped save over Rs 7,130 crore since 2021 across 23 lakh complaints (Asia Insurance Post).
The institutional calendar is crowded. MeitY's reply to Parliament lists National Cyber Security Awareness Month every October alongside Safer Internet Day (Rajya Sabha Q. 2288); CERT-In's October 2025 campaign was reported to include 95 sessions covering 91,065 participants (Digital Terminal). The Home Ministry's cybercrime coordination centre runs "Cyber Jaagrookta Diwas" on the first Wednesday of every month since October 2021, taking cyber-hygiene themes into schools, colleges and municipalities (CIET-NCERT).
Then there is the law. The Digital Personal Data Protection Act passed in August 2023; the final DPDP Rules were notified on 13 November 2025, with consent-manager provisions from November 2026 and the core obligations (notice, consent, breach notification, data-principal rights) from May 2027 (Bar & Bench). Indian companies are entering a long compliance runway, and October campaigns will increasingly be sold internally as DPDP readiness, which is exactly the compliance-versus-security trap Brickhouse warns about. A workforce trained to satisfy a regulator is not the same as one that reports a suspicious email at 11pm.
One Indian example points the other way. HDFC Bank's "Vigil Aunty," a fictional influencer character built as a standing anti-fraud education platform with over 2.2 million followers, has run for years as continuous programming, most recently a seven-episode comedy special on JioHotstar in August 2026 (MediaBrief). It is the opposite of a one-month poster drive: a permanent channel that meets people where they already are.
How a CISO should actually use October
The evidence and the practitioners converge on the same playbook. October is not the program; it is the annual moment to renew the program.
1. Treat October as a launch, not a finale. New theme, visible executive sponsorship, onboarding cohorts, then run the actual program for the other eleven months. This is CISA's own logic taken seriously: daily action, not daily posters.
2. Measure reporting, not just clicks. The strongest consistent signal in the research is that a workforce which reports suspicious email is a functioning detection layer. The ETH Zurich study showed crowdsourced detection working at enterprise scale; Verizon's data links regular training to a fourfold rise in reporting. When a South African telecom ran a sustained program, employees submitted over 8,000 reports through a phishing-alert button, exposing real gaps the security team then fixed (KnowBe4 case study, vendor-reported).
3. Train in the moment, continuously. The Kumaraguru finding and its 2025 European successor agree on the mechanism: immediate feedback, repeated exposure, failure rates halved within months. One industry case study (industry-reported) describes click rates falling from 50% to 5% in twelve months with threat-aligned simulations (Heliocentrix).
4. Reward the report; don't punish the click. Shaming creates the compliance theater the critics describe. Positive reinforcement for reporting builds the habit that actually shows up in breach data.
5. Staff it like it matters. SANS's mature programs had leadership backing and dedicated people. A program owned by nobody is an October poster owned by nobody.
6. Make it role-based and short. Finance faces invoice fraud; developers face supply-chain lures; executives face whaling. Generic annual modules teach everyone equally little.
October is a good month to start taking humans seriously as a security layer. It is a terrible month to stop. The threats, as CISA itself notes, don't take time off. Neither, it turns out, can the training.
Frequently asked questions
Does security awareness training actually work? The evidence is mixed but directional: one-off annual training shows little durable effect in peer-reviewed studies, while continuous programs with immediate feedback and reporting metrics measurably reduce phishing susceptibility. Design and frequency matter more than the fact of training.
Is simulated phishing effective? Simulated phishing plus embedded, in-the-moment training outperformed standard security notices in early research (Kumaraguru et al., 2007). A large 2022 field study of 14,000-plus employees found embedded training alone did not build resilience and could backfire, while employee reporting buttons proved highly effective as collective detection. A 2025 randomized trial of 19,500-plus employees found no significant benefit from annual training at all.
How should companies measure security awareness? Track behavior over time: phishing report rates, click and credential-submission rates across repeated simulations, and time-to-report. Completion percentages alone measure compliance, not security.
What is India doing about cyber awareness? India observes National Cyber Security Awareness Month each October, runs the monthly Cyber Jaagrookta Diwas since 2021, funds the ISEA education project, and is phasing in the DPDP Act's data-protection obligations through 2026-27.
Related Stories
The 2026 Enterprise Innovation Benchmark: Accelerators vs. Venture Client Units vs. Curated Adoption Desks
Executive Summary: The Five-Year AI Re-Buy Window Over the next 60 months, the core software and operational systems of the Fortune 500 and Global 1000 will undergo their most aggressive capital replacement cycle in deca...

The Tutoring Trap: Why Worksheets and Gamified Apps Are Failing Our Children—and How Adaptive Socratic AI Is Changing the Math
Executive Summary: The Modern Learning Paradox If you walk into the living room of an ambitious suburban household at 6:30 PM on a Tuesday, the scene is almost universally the same: an exhausted child sitting over a stac...
The Startup Winter: Which Startups Survived the Downturn?
From 2021 to early 2023, Indian startups received venture capital at unprecedented scale. 2021 saw ₹49,000 crore ($5.9 billion) invested—exceeding the total capital deployed in all of 2019-2020 combined. The money flowed...