{"id":22619,"date":"2026-10-01T22:34:16","date_gmt":"2026-10-01T22:34:16","guid":{"rendered":"https:\/\/8657085.xyz\/?p=22619"},"modified":"2026-10-01T22:34:16","modified_gmt":"2026-10-01T22:34:16","slug":"cybersecurity-awareness-month-why-organisations-must-move-beyond-awareness-to-resilience-in-the-ai-era","status":"publish","type":"post","link":"https:\/\/8657085.xyz\/?p=22619","title":{"rendered":"Cybersecurity awareness month: Why organisations must move beyond awareness to resilience in the AI era"},"content":{"rendered":"<p> <div style=\"display: grid; grid-template-columns: 300px 160px; gap: 2px; width: 460px; background: #eee; padding: 2px;\">\r\n\r\n  <!-- \u6574\u884c\u5bbd\u5e7f\u544a -->\r\n  <div style=\"grid-column: 1\/-1; width: 460px; height: 250px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876674\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n  <div style=\"grid-column: 1\/-1; width: 460px; height: 90px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876676\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n\r\n  <!-- \u5de6\u4fa7\u7ad6\u6392 -->\r\n  <div style=\"height: 250px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876672\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n  <div style=\"height: 500px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876680\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n\r\n  <!-- \u53f3\u4fa7\u6469\u5929\u697c\uff08\u548c\u5de6\u4fa7\u5b8c\u5168\u5bf9\u9f50\uff09 -->\r\n  <div style=\"grid-row: 3\/5; height: 750px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876678\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n  \r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e6\" data-zoneid=\"5876682\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n<\/div><br \/>\n<\/p>\n<div style=\"padding-right:0;padding-left:0\">\n<p class=\"wp-block-paragraph\">Cybersecurity Awareness Month is underway in October 2026. During this period, organisations are facing a paradox. For years, awareness programmes have focused on helping employees recognise suspicious emails, malicious links and other signs of attack. Yet advances in artificial intelligence, identity compromise techniques and cloud-based infrastructure mean that many modern cyberattacks no longer look obviously malicious.<\/p>\n<p class=\"wp-block-paragraph\">According to the U.S. Cybersecurity and Infrastructure Security Agency\u2019s (CISA Cybersecurity Awareness Month initiative), cybersecurity awareness remains an important foundation for reducing risk. However, a growing number of security professionals argue that awareness alone is no longer sufficient. Instead, organisations need stronger validation, behavioural analysis, secure development practices and risk-based security operations.<\/p>\n<p class=\"wp-block-paragraph\">The shift reflects a broader reality. Artificial intelligence is accelerating both innovation and cybercrime. Attackers increasingly exploit identities rather than software vulnerabilities, chain together multiple seemingly low-risk weaknesses, and use AI-generated content to evade traditional detection methods. As a result, cybersecurity programmes must evolve from simply educating users to continuously measuring and improving resilience.<\/p>\n<p class=\"wp-block-paragraph\"><em>Digital Journal<\/em> has heard from a variety of experts, covering different, and important, aspects of cybersecurity governance and practice.<\/p>\n<h2 id=\"h-testing-assumptions-instead-of-trusting-them\" class=\"wp-block-heading\"><strong>Testing assumptions instead of trusting them<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">For Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ, one of the biggest challenges is the gap between assumed security and proven security. \u201cA security control that has never been tested against the behaviour it\u2019s supposed to stop is still an assumption,\u201d Costis explains.<\/p>\n<p class=\"wp-block-paragraph\">This perspective aligns with the growing adoption of Continuous Threat Exposure Management (CTEM), a methodology that focuses on the ongoing identification, assessment and validation of security exposures. Rather than relying solely on theoretical risk scores, exposure validation allows organisations to test whether security controls can actually detect or disrupt real-world attacker techniques.<\/p>\n<p class=\"wp-block-paragraph\">The concept reflects a broader shift within cybersecurity: organisations are increasingly expected to demonstrate that defences work under realistic conditions rather than simply verifying that controls have been deployed. As Costis notes, awareness may help organisations understand what criminals might do, but validation demonstrates how their defences respond when those tactics are actually used.<\/p>\n<p class=\"wp-block-paragraph\">Awareness training frequently concentrates on preventing attacks. Ross Filipek, Chief Information Security Officer at Corsica Technologies, argues that organisations must also prepare for what happens after a breach occurs. \u201cA company can have endpoint protection, backups and MFA and still have a very bad day if nobody knows who is supposed to make the first call,\u201d Filipek says.<\/p>\n<p class=\"wp-block-paragraph\">Many mid-sized organisations operate with relatively small information technology and security teams. During an incident, these teams may be expected to investigate the attack, maintain business operations, communicate with senior leadership and coordinate recovery simultaneously.<\/p>\n<p class=\"wp-block-paragraph\">Consequently, resilience planning becomes as important as prevention. Critical business systems need to be identified in advance, restoration priorities established and response procedures rehearsed. Recovery plans should not simply exist on paper; they need regular testing and executive visibility. This emphasis on operational preparedness mirrors lessons learned from previous ransomware campaigns, where organisations with mature incident response capabilities often recovered more effectively than those possessing strong technical controls alone.<\/p>\n<h2 id=\"h-why-behavioural-context-matters-more-than-individual-alerts\" class=\"wp-block-heading\"><strong>Why behavioural context matters more than individual alerts<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">Traditional cybersecurity awareness advice has taught users to recognise suspicious behaviour. However, Steve Povolny, Vice President of AI Strategy and Security Research at Exabeam, believes modern attackers increasingly exploit legitimate credentials and authorised tools. \u201cThe signal may not be one dramatic action,\u201d Povolny explains. \u201cIt may be a series of legitimate actions that have never occurred together before.\u201d<\/p>\n<p class=\"wp-block-paragraph\">This development highlights the growing importance of behavioural analytics. Rather than focusing solely on individual events, security platforms increasingly analyse patterns over time, examining how users, systems and applications normally interact. For example, a stolen session token may allow an attacker to log in without triggering conventional authentication alerts. Likewise, AI-powered attacks may exploit legitimate access rights while pursuing unintended objectives.<\/p>\n<p class=\"wp-block-paragraph\">The challenge is that each activity may appear perfectly normal in isolation. Only by understanding behavioural context can security teams recognise that something unusual is occurring. As AI-generated deception becomes increasingly convincing, contextual analysis may prove more valuable than many traditional indicators of compromise.<\/p>\n<p class=\"wp-block-paragraph\">Artificial intelligence is also reshaping software development. Katie Paxton-Fear, Staff Security Advocate at Semgrep, highlights an emerging tension between development speed and application security. Developers today can use generative AI tools to create functions, integrations and substantial sections of application code within minutes. While this can dramatically accelerate innovation, it may also introduce vulnerabilities that developers fail to recognise.<\/p>\n<p class=\"wp-block-paragraph\">The challenge is not necessarily malicious code generation. Instead, AI systems may select insecure libraries, misunderstand trust boundaries or inadvertently introduce exploitable weaknesses. This reality reinforces the importance of secure-by-design development practices. The U.S. National Institute of Standards and Technology\u2019s Secure Software Development Framework (SSDF) emphasises integrating security throughout the development lifecycle rather than treating it as a final-stage review.<\/p>\n<p class=\"wp-block-paragraph\">Paxton-Fear argues that security controls must move closer to the point of creation. AI-generated code should receive the same scrutiny as human-written code, supported by developer-friendly security tooling that provides meaningful context rather than overwhelming teams with alerts.<\/p>\n<h2 id=\"h-rethinking-the-modern-security-operations-centre\" class=\"wp-block-heading\"><strong>Rethinking the modern security operations centre<\/strong><\/h2>\n<p class=\"wp-block-paragraph\">The growing volume of security telemetry presents another challenge. Nick Tausek, Lead Security Automation Architect at Swimlane, argues that modern security operations centres do not suffer from a lack of information. Instead, they face a decision-making problem.<\/p>\n<p class=\"wp-block-paragraph\">Security teams already possess extensive data streams, including threat intelligence, endpoint monitoring, identity information and network telemetry. The bottleneck emerges when analysts must determine which signals matter and what actions should follow.<\/p>\n<p class=\"wp-block-paragraph\">Tausek advocates a layered approach to automation. Routine incidents can move through deterministic workflows, while ambiguous situations benefit from AI-assisted investigation. Human analysts remain focused on incidents where judgement, experience and business context add the greatest value. This model reflects a growing consensus within the industry that artificial intelligence should complement, rather than replace, human decision-making inside security operations.<\/p>\n<p class=\"wp-block-paragraph\">Piyush Sharma, co-founder and CEO of Tuskira, believes vulnerability management itself requires rethinking. For decades, organisations have prioritised remediation largely according to severity scores. Yet attackers rarely focus on individual vulnerabilities in isolation. Instead, adversaries combine weaknesses across cloud services, applications, identities and networks to create exploitable attack paths.<\/p>\n<p class=\"wp-block-paragraph\">Recent developments in AI-assisted exposure analysis are helping organisations visualise these pathways and identify weaknesses that genuinely contribute to breach scenarios. The objective is not simply to count vulnerabilities, but to understand which weaknesses provide meaningful routes to critical assets. This approach recognises an uncomfortable reality. Most organisations already know they have too many vulnerabilities to fix immediately. The more important question is which vulnerabilities actually matter.<\/p>\n<p class=\"wp-block-paragraph\">Cybersecurity Awareness Month continues to play an important role in educating organisations and employees about digital risks. Yet the message emerging from security leaders this year is that awareness alone is no longer enough. In an environment shaped by AI-generated attacks, identity compromise, behavioural manipulation and increasingly complex attack paths, resilience depends upon continuous validation, context-aware detection, secure software development and intelligent decision-making. The objective is no longer simply recognising threats. It is building security programmes capable of adapting to them. As attackers become more sophisticated, organisations must evolve from knowing what cybercriminals might do to proving they can withstand it when it happens.<\/p>\n<\/div>\n<p><!-- \u603b\u5bb9\u5668\uff1a\u6700\u5927\u5bbd908px Grid\u7d27\u51d1\u5e03\u5c40 -->\r\n<div style=\"display: grid; grid-template-columns: 728px 160px; gap:2px; width:908px; background:#eee; padding:2px;\">\r\n\r\n  <!-- \u901a\u680f\u9876\u90e8\uff1a\u6700\u5927\u6a2a\u5e45 908x258 \u8de8\u6574\u884c -->\r\n  <div style=\"grid-column:1\/-1; height:258px; background:#ff6b6b; display:grid; place-items:center;\">\r\n    <!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114307\" data-width=\"908\" data-height=\"258\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114307});<\/script>\r\n<!--JuicyAds END-->\r\n  <\/div>\r\n\r\n  <!-- \u7b2c\u4e8c\u901a\u680f\uff1a728\u00d790 \u901a\u680f -->\r\n  <div style=\"grid-column:1\/-1; height:90px; background:#4ecdc4; display:grid; place-items:center;\">\r\n    <!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114300\" data-width=\"728\" data-height=\"90\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114300});<\/script>\r\n<!--JuicyAds END-->\r\n  <\/div>\r\n\r\n  <!-- \u5de6\u4fa7\u4e3b\u680f\uff1a\u591a\u5e7f\u544a\u5806\u53e0 -->\r\n  <div style=\"display:grid; gap:2px;\">\r\n    <div style=\"height:60px; background:#45b7d1; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114308\" data-width=\"468\" data-height=\"60\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114308});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:250px; background:#ffe066; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114299\" data-width=\"300\" data-height=\"250\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114299});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:250px; background:#ff9ecd; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114305\" data-width=\"250\" data-height=\"250\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114305});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:139px; background:#c792ea; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114302\" data-width=\"133\" data-height=\"139\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114302});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:125px; background:#91e7ac; display:grid; place-items:center;\">\r\n\t\r\n<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114303\" data-width=\"125\" data-height=\"125\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114303});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n  <\/div>\r\n\r\n  <!-- \u53f3\u4fa7\u7ad6\u680f\uff1a160\u00d7600 \u6574\u5217\u9ad8\u5e7f\u544a -->\r\n  <div style=\"grid-row:3\/8; height:600px;  display:grid; place-items:center;\">\r\n    <!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114301\" data-width=\"160\" data-height=\"600\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114301});<\/script>\r\n<!--JuicyAds END-->\r\n  <\/div>\r\n\r\n<\/div><br \/>\n<br \/> Cybersecurity awareness month: Why organisations must move beyond awareness to resilience in the AI era<br \/>\n<br \/>#Cybersecurity #awareness #month #organisations #move #awareness #resilience #era<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity Awareness Month is underway in October 2026. During this period, organisations are facing a&#8230;<\/p>\n","protected":false},"author":1,"featured_media":15224,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[13457,6341,1816,5642,1566,16229,13372],"class_list":["post-22619","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-stories","tag-awareness","tag-cybersecurity","tag-era","tag-month","tag-move","tag-organisations","tag-resilience"],"featured_image_urls":{"full":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1.jpg",768,512,false],"thumbnail":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1-150x150.jpg",150,150,true],"medium":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1-300x200.jpg",300,200,true],"medium_large":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1.jpg",640,427,false],"large":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1.jpg",640,427,false],"1536x1536":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1.jpg",768,512,false],"2048x2048":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1.jpg",768,512,false],"covernews-slider-full":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1.jpg",768,512,false],"covernews-slider-center":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1-768x500.jpg",768,500,true],"covernews-featured":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1.jpg",768,512,false],"covernews-medium":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1-540x340.jpg",540,340,true],"covernews-medium-square":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/06\/94322df63250178908fab4e1b2452da7c4b292d1-400x250.jpg",400,250,true]},"author_info":{"display_name":"admin","author_link":"https:\/\/8657085.xyz\/?author=1"},"category_info":"<a href=\"https:\/\/8657085.xyz\/?cat=7\" rel=\"category\">Stories<\/a>","tag_info":"Stories","comment_count":"0","_links":{"self":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/posts\/22619","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=22619"}],"version-history":[{"count":0,"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/posts\/22619\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/media\/15224"}],"wp:attachment":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=22619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=22619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=22619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}