October brings Cybersecurity Awareness Month, and this year’s message gets straight to the point: “Don’t Make It Easy for Them.”
The National Cybersecurity Alliance’s (NCA) 2026 theme encourages everyone to make life harder for cybercriminals through consistent, everyday security habits. Launched in 2004, the annual campaign brings organizations and individuals together to improve online safety. For legal and eDiscovery professionals, October offers a timely opportunity to examine how those habits protect client information and sensitive case data.
The 2026 campaign emphasizes four familiar actions: 1) creating strong passwords and using a password manager, 2) enabling multifactor authentication, 3) recognizing and reporting scams, and 4) keeping software updated. Each presents an opportunity to reinforce good security practices. The familiarity of these actions should make it easier to practice them consistently – though may of the security incidents we hear about still result because of failure to adhere to one or more of them.
Several activities and resources provide ways to participate in 2026:
- October 1: NCA’s virtual kickoff. The Cybersecurity Awareness Month 2026 Virtual Kick-off brings together government and industry leaders. Its announced agenda includes federal cybersecurity initiatives, critical infrastructure protection, collaboration around emerging technologies such as artificial intelligence, and the relationship between cybersecurity and national security.
- October 15: NCCoE Cybersecurity Connections. The National Institute of Standards and Technology’s National Cybersecurity Center of Excellence is hosting a special awareness-month event from 11 a.m. to 1:30 p.m. Eastern. Attendance is available in person or virtually, and registration closes October 7. The event provides an opportunity to connect with the cybersecurity community; the in-person program includes a networking lunch.
- October 19–24: Cybersecurity Career Week. NIST encourages participation in this year’s career-awareness activities, which promote exploration of cybersecurity careers. Its participation resources also suggest workplace discussions, community events, training, and other ways to engage employees and students.
Organizations can also register as a Cybersecurity Awareness Month Champion through the NCA campaign page. Registration provides a free toolkit containing an actionable tipsheet, printable posters, and graphics for social media and Instagram Stories. These materials offer a convenient starting point for an internal campaign, particularly for smaller organizations with limited communications resources.
For law firms, corporate legal departments, and service providers, the next step should be to make that campaign relevant to employees’ actual responsibilities. A short exercise could ask participants how they would respond to an unexpected production-download link, a request to change payment instructions, or an urgent message seeking access to a matter workspace. Give employees a clear reporting channel and an opportunity to practice using it. Discuss what to do when they have already clicked, shared information, or approved a suspicious request.
Cybersecurity Awareness Month provides an important annual reminder of what we should all be doing to protect our organizations from security incidents, especially when deadlines are tight, requests seem urgent, and one more click feels easier than stopping to check. Given how AI models have ramped up the threats organizations face exponentially – even from “the good guys” – that reminder message is more important than ever. “Don’t Make It Easy for Them” has never been more important.
So, what do you think? Does your organization recognize Cybersecurity Awareness Month? Please share any comments you might have or if you’d like to know more about a particular topic.
Image created using ChatGPT, using the term “robot hockey goalie trying to stop a puck that says ‘data breach’ on it”.
Disclaimer: The views represented herein are exclusively the views of the author, and do not necessarily represent the views held by my employer, my partners or my clients. eDiscovery Today is made available solely for educational purposes to provide general information about general eDiscovery principles and not to provide specific legal advice applicable to any particular circumstance. eDiscovery Today should not be used as a substitute for competent legal advice from a lawyer you have retained and who has agreed to represent you.

