Home    |   News & Events   |   Cybersecurity Awareness Month: What Business Leaders Should Know About Today’s Risks
cybersecurity
October 01, 2026

Cybersecurity Awareness Month: What Business Leaders Should Know About Today’s Risks

Cyber risks keep evolving, so complacency isn’t an option. October is Cybersecurity Awareness Month, making it a good time to learn about current threats, reflect on your cybersecurity practices and identify vulnerabilities that could put you, your family or your business at risk.

How Cyber Threats Are Changing

Cyber threats are always evolving. As people learn how to spot and avoid one attack, cybercriminals develop new tactics. For example, many people have learned how to spot phishing emails and texts, so some cybercriminals have started using calendar phishing tactics, sending calendar invitations with malicious links. Cybersecurity company Panda says calendar phishing has increased over the past 24 months. Cybercriminals have also learned to exploit the hectic nature of travel; Check Point says 47,318 fake travel domains were registered in May 2026, a year-over-year increase of 19%.

Emerging technologies have given cybercriminals many new options. Cybercriminals can use AI to create convincing phishing messages, or they can use voice cloning to mimic the voices of loved ones. CNN says voice cloning scams are on the rise, and scammers only need a few seconds of real audio to create a convincing replica.

Cybercriminals can use technology to conduct automated cyber reconnaissance, continuously monitoring systems for weaknesses that can then be exploited. According to the FortiGuard Labs 2025 global threat landscape report from Fortinet, automated cyber reconnaissance increased 16.7% year over year. Many attacks target old vulnerabilities that have not been patched, highlighting how important regular software updates are.

Everyday Practices Can Create Cyber Risk

Everyday habits can increase your exposure to cyber incidents.

For example, if you use public Wi-Fi or charging stations, you could be exposing your data. The University of British Columbia warns that cybercriminals sometimes tamper with public charging stations to steal data or install malicious software, a technique known as juice jacking. To avoid this risk, bring a portable power bank or use your own wall charger and cables.

Growing generative AI adoption is creating new cyber exposures, especially when people put sensitive information in AI prompts while using insecure platforms. This can be a problem for both individuals and businesses. According to Check Point, “Every new tool adopted without a governance framework in place is another surface where credentials, intellectual property, and internal data can slip out quietly.” Check Point warns that one in 25 generative AI prompts from enterprise networks carries a high risk of sensitive data leakage. This makes clear policies around approved AI tools, acceptable use and sensitive data increasingly important.

Can You Spot Modern Phishing?

Many cyberattacks start with phishing. However, phishing has evolved over the years. Messages can come via any channel, including email, phone, text, social media, messaging apps and even calendar apps. Phishing messages also look more convincing now that cybercriminals can use AI to generate them. In the past, if you avoided emails with obvious spelling and grammar mistakes, you could often stay safe, but that’s no longer the case.

Any messages that encourage urgent action should be treated with suspicion, especially if they ask you to click on a link or provide information. Look for incorrect or shortened URLs and email addresses. If you aren’t sure whether a message is legitimate, don’t reply, click on any links or use the contact information provided in the message. Instead, you can follow up by contacting the company or accessing your account the way you normally would. For example, if the message is about your credit card, call the number on the back of your credit card for help.

If you get a suspicious email, don’t click on any “unsubscribe” links. You can use your email platform’s system to report it as spam. Otherwise, just delete the email.

Cybersecurity Steps for Individuals and Businesses

The Cybersecurity and Infrastructure Security Agency (CISA) recommends several steps to reduce cyber risk:

  • Everyone should use strong passwords, multifactor authentication and a password manager. Keep your software updated, learn how to avoid phishing scams and report any phishing scams you see.
  • Organizations should do everything above and also use logging on their systems and back up and encrypt their data. Have an incident response plan ready to use, be prepared for system disruptions and report cyber incidents to CISA. Eligible government and public-sector entities are also encouraged to get a .gov domain.
  • Organizations that own or operate critical infrastructure can also follow the Reduce, Replace and Recover approach to cybersecurity: reduce vulnerabilities, replace end-of-support devices and recover quickly to sustain operations.

You can report cyber incidents to CISA, suspected fraud to the Federal Trade Commission and internet crime to the FBI’s Internet Crime Complaint Center (IC3).

With ongoing vigilance, you can decrease the risk of a cyberattack, but no organization or individual can eliminate cyber risk entirely. Cyber insurance can provide another layer of protection, helping businesses and individuals manage the financial consequences of certain cyber incidents. Heffernan Insurance Brokers can help you explore commercial cyber insurance as well as personal cyber and identity theft coverage. Contact Heffernan Insurance Brokers to learn more.

    Stay Informed!

    Receive Expert Advice, Industry Updates and Event Invitations

    Pin It on Pinterest

    Heffernan Insurance Brokers
    Privacy Overview

    This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.