Library Header Image Library Header Image

Pause. Verify. Report. Your Guide to Cybersecurity Awareness Month 2026


Posted on by Erik Dierks

Key Takeaways:
  • Pause: If a message pressures you to act fast, slow down.
  • Verify: Check unusual requests through a channel you already trust.
  • Report: Tell Security about anything suspicious, even if you're not sure.

Happy Cybersecurity Awareness Month! October is a great opportunity to refresh a few simple habits that help protect all of us.

Cybercriminals do not only target large companies or specific industries. Every organization is a potential target, regardless of size or industry, because attackers are looking for opportunity: an account they can access, a payment they can redirect, a person they can impersonate, or information they can steal.

The good news is that we do not need everyone to become a cybersecurity expert. We just need to recognize when something feels unusual, slow down when we are being rushed, and know when to ask for help.

Our theme this month: PAUSE. VERIFY. REPORT.

1. Phishing Is Getting Much More Convincing

Phishing is no longer limited to badly written emails. Attackers now use convincing copies of Microsoft login pages, shared-document notifications, voicemail alerts, QR codes, electronic signatures, and even legitimate Microsoft authentication pages.

  • “A document has been shared with you.”
  • “Your password expires today.”
  • “You have a new voicemail.”
  • “Scan this QR code to continue.”
  • “Go to Microsoft and enter this code.”

Protect yourself: If you were not expecting the message, do not use the link or code it provides. Open Microsoft 365, Teams, SharePoint, or the application normally and check from there. Never enter a Microsoft device code that someone unexpectedly sends you.

2. Attackers May Pretend to Be IT, a Coworker, or an Executive

Attackers can learn a surprising amount from LinkedIn, company websites, conference pages, social media, and public information. That makes impersonation much more convincing.

  • “Hi, this is IT. We’re having trouble with your account.”
  • “I just sent you an MFA request. Please approve it.”
  • “I’m boarding a flight. Can you handle this payment for me?”

The person may know your name, title, coworkers, or current projects. That does not mean they are legitimate.

Protect yourself: Never provide your password or approve an MFA request you did not initiate. Verify unusual requests using a communication method you already trust. Call a known number or contact IT through the normal company channel. Verification is not rude — it is good security.

3. Unexpected MFA Prompts Are a Warning Sign

If your phone suddenly asks “Approve sign-in?” and you are not signing in, do not approve it. Repeated MFA requests may mean someone already has your password and is hoping you will eventually click approve.

  • Decline the request.
  • Report it to Security.

4. Be Careful With AI Tools, Downloads, and Browser Extensions

Attackers follow trends, and AI is currently one of their favorite themes. Malicious websites and downloads may advertise AI desktop applications, ChatGPT or Claude plugins, coding assistants, new AI models, or browser extensions.

Protect yourself: Install software only from approved or official sources. Appearing in Google, Bing, GitHub, or an app marketplace does not automatically make something safe. If you are not sure, ask IT.

5. Never Run a Command Because a Website Tells You To

One increasingly common attack displays a fake CAPTCHA or security check and tells you to open PowerShell, Terminal, Command Prompt, or the Run box, then paste or execute a command. This is sometimes called ClickFix.

The rule is simple: No legitimate CAPTCHA needs you to run PowerShell, Terminal, Command Prompt, or a pasted command. Close the page.

6. Watch for Payment and Vendor Fraud

One of the most damaging scams is also one of the simplest. A vendor appears to say, “Our bank information has changed,” or an executive appears to request an urgent payment. Attackers may even compromise a real email account and insert themselves into an existing conversation.

Changes involving the following should always be independently verified:

  • Bank accounts or wire instructions
  • Payments or payroll
  • Gift cards
  • Vendor contact or payment information

Protect yourself: Call a phone number you already know. Do not rely on contact information included in the suspicious message.

7. Voice and Video Are No Longer Proof of Identity

AI can imitate voices and faces surprisingly well. Even if something sounds or looks like someone you know, unusual requests involving money, credentials, or sensitive information should still be verified.

“No problem — I’ll call you back on the number I already have.”

That small step can defeat a very sophisticated attack.

8. Be Cautious With Unexpected Shared Documents

Organizations like ours work with speaker materials, vendor and sponsor documents, spreadsheets, contracts, RFPs, invoices, and marketing assets. Attackers understand that, so malicious messages often look completely normal.

  • “Updated sponsor list.”
  • “Please review this RFP.”
  • “New presentation attached.”

Ask one simple question: Was I expecting this? If not, verify before opening unusual attachments, signing in, or downloading anything.

9. Take Extra Care When Traveling

Airports, hotels, conferences, and public Wi-Fi create additional opportunities for attackers. Be suspicious if public Wi-Fi unexpectedly asks you to verify your Microsoft account, install an application or certificate, or enter a device code.

Protect yourself: Use approved connectivity and VPN options when required. If something feels strange, your phone hotspot may be a safer choice.

One Pattern Connects Almost Every Scam

Attackers often try to create an emotional reaction:

  • Fear: “Suspicious activity detected!”
  • Urgency: “Do this in the next 10 minutes!”
  • Authority: “The CEO needs this now.”
  • Secrecy: “Don’t tell anyone else.”
  • Curiosity: “Confidential information attached.&rdquo

If something makes you feel like you need to act immediately, that is often exactly when you should slow down.

Reporting Is a Win

If you clicked something suspicious, entered a password, approved an MFA request, downloaded something, or simply are not sure — tell us.

Security would much rather investigate something harmless than miss the one message that matters. Reporting something that turns out to be safe is not a mistake. It means the process worked. And if something really did happen, early reporting gives us the best chance to protect you and the organization.

REMEMBER THREE THINGS

PAUSE

VERIFY

REPORT

Urgency is one of an attacker's favorite tools. Use a trusted second method when something seems unusual. If something does not feel right, tell Security.

 

EVERYONE IS A TARGET. EVERYONE IS PART OF THE DEFENSE.

Attackers will keep changing their tools and tactics, but most attacks still need one thing: our trust. PAUSE. VERIFY. REPORT.

We protect one another. We’ve got this.

Contributors
Erik Dierks

Director, IT Security, RSAC

Blogs posted to the RSAConference.com website are intended for educational purposes only and do not replace independent professional judgment. Statements of fact and opinions expressed are those of the blog author individually and, unless expressly stated to the contrary, are not the opinion or position of RSAC™ Conference, or any other co-sponsors. RSAC Conference does not endorse or approve, and assumes no responsibility for, the content, accuracy or completeness of the information presented in this blog.


Share With Your Community

Related Blogs