Cybersecurity Awareness Month 2026: Your September Prep

Why September Is Your Real Deadline
Every October, Cybersecurity Awareness Month gives security teams the one thing they struggle to get the rest of the year: organizational permission to talk about security everywhere, loudly, for four straight weeks. But the programs that actually move behavior are never assembled in October - they are locked in during September. If your plan starts on October 1, you have already spent the month's first week planning instead of campaigning.
A note on themes: organizers publish official themes and toolkits each year, and as of this writing the National Cybersecurity Alliance says its updated 2026 theme is on the way - its 2025 theme was 'Stay Safe Online'. On the government side, CISA ran 2025 under 'Building a Cyber Strong America', focused on critical infrastructure, state and local government and small businesses, and publishes a reusable Cybersecurity Awareness Month toolkit with ready-made materials. The practical lesson: build your program theme-agnostic in September, then slot in the official 2026 messaging and toolkit assets when they land. Your goals, baseline and calendar do not need to wait for a slogan.
The Four-Week September Plan
Week 1: Set Goals and Run Your Baseline
Start with the question October should answer: what do we want to be measurably different in November? Pick two or three concrete goals - for example, raise the share of employees who report suspicious emails, cut the simulation click rate, or get every manager to hold one security conversation with their team.
Then measure your starting point. A baseline phishing simulation in early September tells you exactly where your workforce stands before the campaign, which is what makes your October results meaningful rather than anecdotal. The benchmark data shows why baselines matter: according to KnowBe4's 2026 Phishing by Industry Benchmarking Report, untrained users have a global Phish-prone Percentage of 33.2%, falling to 4.2% after twelve months of continuous training. Those numbers carry two messages for your planning: first, an untrained baseline is genuinely alarming and will get leadership's attention; second, the big reduction comes from sustained, continuous training - so design October as the launchpad for a year-round program, not as the program itself.
Week 2: Build the Content Calendar
Map all four October weeks before the month starts. A proven structure is one focus topic per week - phishing and social engineering, passwords and MFA, safe data handling, reporting and incident response - each supported by short, varied touchpoints: a two-minute video, a quiz, a poster or intranet banner, a simulation, a team discussion prompt. Pull ready-made assets from the CISA toolkit and the NCA materials once the 2026 versions are published, and schedule everything in advance so October runs itself. With empowsec you can queue the month's training assignments and simulation campaigns in September and let automated enrollment handle who gets what, when.
Week 3: Secure Executive Sponsorship and Champions
Campaigns that open with a message from the CEO or managing director get treated as business priorities; campaigns that open with an email from a shared security mailbox get treated as noise. Use week three to book the executive kickoff message, brief department heads with talking points, and recruit security champions - one volunteer per team who relays content, answers questions and keeps momentum going in week three of October when attention naturally dips.
Sponsorship is also the moment to set expectations about tone. October works best as a positive, participatory campaign - recognition for employees who report suspicious emails, visible leadership participation, a little friendly competition between departments - rather than a month of warnings. People who associate security with blame disengage; people who see their team's report rate climbing lean in. Brief your sponsors and champions on that framing explicitly, because they will set the tone in every conversation the campaign triggers.
Week 4: Lock Logistics and the Measurement Plan
The final week is operational: confirm the communication channels and send dates, load the calendar invites, test that links and training assignments work, and - critically - write down how you will measure success before the campaign starts. Decide now which metrics you will compare against the week-one baseline: click rate, report rate, time-to-report, training completion. Committing to the metrics in advance keeps the November review honest.
Finally, book the November retrospective and the first post-campaign follow-up simulation now. The campaign's real deliverable is the year-round rhythm it establishes, and follow-up dates are the easiest thing to lose once October's momentum fades.
One October, Two Frameworks: CSAM Meets ECSM
If your organization operates in Europe or on both sides of the Atlantic, remember that October is simultaneously European Cybersecurity Month (ECSM), coordinated by ENISA with national campaigns across EU member states, including Germany. The two frameworks share a month and a mission but publish separate themes and materials.
For multinational teams this is an opportunity, not a conflict: anchor your internal program on your own goals and calendar, then localize - use ECSM and national campaign materials for European offices and CISA/NCA assets for North American ones. The internal metrics stay unified; only the supporting content varies by region. German organizations in particular should watch their national ECSM activities, which give local language hooks that make campaign content feel less imported.
Key Takeaways
- Treat September as the deadline. A four-week prep sprint - goals and baseline, content calendar, sponsorship, logistics and measurement - is what separates a campaign from a poster on the wall.
- Do not wait for the theme. Organizers publish 2026 themes and toolkits on their own schedule; build theme-agnostic and slot official materials in when they arrive.
- Baseline first, always. An early-September phishing simulation turns October from an activity report into a measured before-and-after.
- October is a launchpad, not the program. The benchmark drop from 33.2% to 4.2% Phish-prone Percentage comes from twelve months of continuous training - use the month's momentum to lock in the year-round program.
- Align both frameworks. CSAM and ECSM share October; unify your goals and metrics internally and localize the supporting content by region.


