The 2026 Cybersecurity Awareness MonthĀ Kit
Four short videos and four quick exercises your team can complete in 15 minutes a week, built to close the gaps most security awareness training leaves open.
Why Security Awareness Training Is Not Working
In Verizon's 2026 Data Breach Investigations Report, 62% of breaches involved a human. Attackers find it easier to trick a person than to hack a system, and it keeps working, even at businesses already doing awareness training.
The reason is simple. Most training teaches people what to do once something looks suspicious but most attacks today neverĀ appear to beĀ suspicious.
They show up in normal conversations and normal processes, often from the real account of a client, vendor, or coworker who has been compromised. Security tools catch the obvious threats, so the ones that reach your team are the hardest to spot.
What This Series Covers
- Understand the threat. How attackers blend into everyday work and why they are so hard to catch.
- Develop your cyber-sense. A simple formula for noticing when something might be off.
- Know what to do when it goes off. Safe ways to check a message and who to tell.
- Plan for when it never goes off. Habits and verification steps that protect you even when nothing seems wrong.
How to Use This Kit
Each week in October, send your team one short video and one quick exercise. The whole activity takes 15 minutes or less.
- Watch the video first. Each one is about 8 minutes, so you know what your team will see.
- Copy the email below it. Paste it into a new email, adjust it as needed, and send it to your team.
- Your team watches and tries the exercise. Each exercise takes about 5 minutes.
- Talk about it if you can. A minute at your next team meeting goes a long way. It is optional.
Good to Know
- Each week builds on the one before. If someone skips a week, the next exercise tells them how to jump back in.
- Nothing gets emailed around the office. Team members save their Week 1 exercise as a draft email and do not send it, so it will not trip your security tools or confuse coworkers.
- Week 3 asks you to add your reporting process to the email. Check that you know it before then.
- These videos are unlisted. Please share them only with your team.
WEEK 1
The Current Threat Landscape
Attacks today do not look suspicious. This video opens with a real story of how one helpful phone call gave an attacker a way into a small office, then explains why the threats that reach your team are the ones built to blend in.
Your Team Will Learn
- How social engineering works and why it is so effective
- How AI and voice cloning have removed the old red flags
- Why attacks can go undetected for months
Email to Your Team
Copy this email, adjust it as needed, and send it to your team.
Subject: Cybersecurity Awareness Month: 15 minutes a week
Hi team,
October is Cybersecurity Awareness Month. Each week, I will send a short video and a quick exercise. It should take about 15 minutes.
Cyberattacks today are designed to look like normal work, so this series focuses on how attackers think and what we can do about it.
Watch "The Current Threat Landscape" (8 min):
https://youtu.be/NiJaQUI2cQM
Then try this (5 min):
Write a short phone call or email message that could fool someone on our team. Make it look completely normal. Decide what you want them to do: click a link, open a file, share information, send money, change payment details, or call you back. Use only information someone could find online or learn by asking a friendly question.
Keep what you write. Save it as a draft email (do not send it) so you can find it later. We will use it again in the coming weeks.
Thanks,
Leader Notes
- Want to talk about it? Add a line asking people to share which detail made their message believable at your next team meeting.
- Remind your team not to send their messages to anyone. A realistic fake message sent around the office can trip security tools or fool a coworker for real.
WEEK 2
Developing Your Cyber-Sense
We are wired to notice physical danger, but not digital threats. This video introduces the Am I Being Phished formula, a simple way to spot the patterns behind phishing, text, and phone scams, even when nothing looks obviously wrong.
Your Team Will Learn
- The three parts of the formula: a false scenario, a call to action, and urgency or emotion
- Why an emotional reaction is one of the best warning signs
- How practice and feedback sharpen your ability to spot a threat
Email to Your Team
Copy this email, adjust it as needed, and send it to your team.
Subject: Cybersecurity Week 2: Developing Your Cyber-Sense
Hi team,
Here is Week 2 of our Cybersecurity Awareness Month series.
Watch "Developing Your Cyber-Sense" (8 min):
https://youtu.be/lL15spay2EU
Then try this (5 min):
Open the draft you saved last week. If you did not write one, pick a recent message from your inbox (do not forward it). Check it for the three signs from the video:
- A scenario that might be false
- A call to action
- Urgency or emotion
Now imagine it came from the real email account of a coworker, client, or vendor you trust. Would anything tell you it was not really them?
If the answer is no, that is the point. The next two weeks cover what to do about it.
Thanks,
Leader Notes
- Many people notice that real, legitimate messages score high on the formula too. That is expected. The formula is a signal to slow down, not proof of an attack.
- For a quick discussion, ask the team whether anyone could tell their message came from a compromised account. The usual answer is no, and that is the lesson.
WEEK 3
Safe Curiosity
Many people check a suspicious message by clicking the link, assuming their security tools will protect them. This video explains why that is risky, shows safer ways to find out if something is real, and covers why reporting quickly matters, even after a mistake.
Your Team Will Learn
- Why clicking, opening, or even replying can put you at risk
- How to verify by going directly to the source or switching channels
- Why fast reporting limits the damage of an attack
Before You Send This One
Fill in your reporting process. The "Our process" line in the email has two blanks in capital letters: who to report to, and how. Replace both with your own details. If you are not sure what goes there, ask your IT provider before sending. Finding that gap is the point of this week.
Email to Your Team
Copy this email, fill in your reporting process, and send it to your team.
Subject: Cybersecurity Week 3: Safe Curiosity
Hi team,
Here is Week 3 of our Cybersecurity Awareness Month series.
Watch "Safe Curiosity" (8 min):
https://youtu.be/b9r9AI3d8wQ
Then try this (5 min):
Using your saved draft from Week 1, or a recent message from your inbox, answer two questions:
- How would you check whether it is real without clicking, replying, or using a phone number in the message?
- If it seemed suspicious, or you had already clicked, who would you tell and how?
Could you do both right now without looking anything up? If not, now is the time to find out.
Our process: If something seems suspicious, or you think you may have clicked, report it right away to [WHO TO REPORT TO] by [PHONE, EMAIL, OR OTHER METHOD]. Reporting quickly will never get you in trouble.
Thanks,
Leader Notes
- Keep the line about not getting in trouble only if it is true in your office. It is the most important sentence in the email, because fear of blame is what keeps people from reporting.
- If you have an incident response plan, this is a good week to point your team to the part that applies to them.
WEEK 4
Safer Digital Habits
No one catches every attack. This final video covers simple habits and verification steps that protect your team even when nothing seems suspicious, plus ways to help clients and coworkers confirm your messages are real.
Your Team Will Learn
- Why trust but verify belongs in every high-risk process
- Small habits that make a big difference, like locking your screen every time
- How the way you communicate can help others stay safe
Heads Up!
This email asks your team to reply to you. The last line asks each person to tell you which process they circled. Keep it if you want to see where your team sees risk, or change it to sharing at your next team meeting.
Email to Your Team
Copy this email, adjust it as needed, and send it to your team.
Subject: Cybersecurity Week 4: Safer Digital Habits
Hi team,
Here is the final week of our Cybersecurity Awareness Month series.
Watch "Safer Digital Habits" (8 min):
https://youtu.be/BXfEvWg46A0
Then try this (5 min):
- List three things you do regularly at work, like processing payments, updating client or vendor information, resetting passwords, sharing files, or approving requests.
- Circle the one where a mistake would cause the most damage.
- Look at your saved draft from Week 1. Could someone use a message like it to slip into that process?
- Write down one step you will take every time that process happens, even when nothing seems off. For example: call back on a known number, go directly to the website, or ask for a second set of eyes.
Reply and let me know which process you circled.
Thanks for taking part this month,
Leader Notes
- The replies show you where your team sees risk. If several people circle the same process, that is a good place to consider an office-wide verification step.
- Want to go further? Review the answers together at a team meeting and agree on one verification step for your highest-risk process.
Want Help Taking This Further
Join us for a free Cyber Readiness Assessment. We will answer your questions about resources like this kit and help you find what else can keep your business safer.
Book Your AssessmentOr email us at info@readystatecyber.com