Every October, somebody in your industry sends around a poster about strong passwords. Your staff glance at it and go back to work. That is most companies’ entire Cybersecurity Awareness Month, and it changes nothing.

Here is a version that does. It takes four questions, one a week, asked by the person who runs the business to whoever runs the technology. You do not need to know the answers. You need to notice when nobody does.

What the month is

Cybersecurity Awareness Month has run every October since 2004. In the United States it is led by the National Cybersecurity Alliance, a nonprofit, and the Cybersecurity and Infrastructure Security Agency, the federal agency. For 2026 the National Cybersecurity Alliance’s theme is “Don’t Make It Easy for Them,” and the argument behind it is that most break-ins are not clever. They walk through the same four doors: a phishing email that worked, a password that was guessed or reused, an account with no second step at sign-in, and a machine that stopped getting updates.

Those four doors are the four questions. Each one below comes with what a good answer sounds like, and a link to the longer explanation if the answer you get is a shrug.

Week 1: Would we catch a fake email from ourselves?

The question. “If someone sent an email that looked like it came from our own domain, asking accounts payable to change a vendor’s bank details, what would stop it?”

A good answer names two things. First, the three DNS records that prove your email is really yours, so a message forging your domain gets rejected or flagged before anyone reads it. Second, a rule that no bank detail change happens without a phone call to a number already on file. The records are explained in our guide to SPF, DKIM, and DMARC. The callback rule matters just as much for the phone version of the same fraud, where the caller now sounds exactly like your boss.

A bad answer is “our spam filter handles it.” Filters catch most of it. The one that gets through is the one that costs money.

Week 2: Are we still making people change passwords every 90 days?

The question. “What does our password policy actually require, and when was it last looked at?”

A good answer is short passwords out, long ones in, forced resets gone, and a password manager for everyone. That is what the federal standard, NIST SP 800-63B, has said since its 2025 revision. Most businesses still enforce the opposite, because the policy was written once and never revisited. Our guide on the updated NIST password guidelines covers what changed and what a current policy says.

A bad answer is a policy that requires a symbol, a number, and a change every quarter. That policy produces “Autumn2026!” on every third desk.

Week 3: Who here still gets a text message code?

The question. “How many of our people sign in with a code sent by text, and what is the plan to move them?”

A good answer has a number and a date. Text-message codes are the weakest form of the second sign-in step, because a fake login page can ask for the code and relay it in seconds. Microsoft made passkeys the default for Microsoft 365 on September 1, 2026, and it stops sending its own SMS and voice codes on February 1, 2027. Anyone still on text codes that morning hits a wall. Our guide on Microsoft retiring SMS and voice MFA explains the dates and the migration.

A bad answer is “everyone has MFA.” Everyone having MFA is where this started. The question now is which kind, and whether it is the kind that still works.

Week 4: How many of our computers are still on Windows 10?

The question. “Which of our machines stopped getting security updates, and who is tracking that?”

A good answer is a list. Windows 10 stopped receiving updates in October 2025. A business machine still on it is either enrolled in Microsoft’s paid extended updates, or it has been accumulating unpatched holes for a year. On October 13, 2026, the paid program’s second year begins at roughly double the price. The free extension to 2027 you may have read about is for personal PCs only. Our guide to Windows 10 and Server 2016 end of support has the dates and the decision for each machine.

A bad answer is “I think we upgraded most of them.” Most is the problem.

What a well-run October looks like

  1. One question a week, asked in writing so the answer is in writing too.
  2. A number in every answer. How many domains, how many people on text codes, how many machines. “Most” and “I think” go back for a real count.
  3. One fix chosen by the end of the month, the worst of the four, with a date attached.
  4. A place to report things. Tell staff, once, who to email when they click something they should not have. No blame, no forms. The companies that hear about the click in ten minutes are the ones that stay small incidents.
  5. The same four questions next October. Awareness that happens once is a poster.

Where this leaves you

Two things to check this week, before October starts: do you know who you would ask these four questions, and would you understand the answers? If either is a no, that is the finding.

Everything in this guide is the free layer. When a business wants the four answers checked against its actual tenant, its actual machines, and its actual DNS, that is what our cybersecurity service does in a quarterly review. Get in touch and we will tell you where you stand.