Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Cybersecurity Awareness Month: are your controls actually working?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Cybersecurity Awareness Month centres on four practical controls, strong passwords, MFA, phishing reporting, and prompt patching, while CISA also stresses support for SMBs and SLTT governments that sit in critical supply chains, according to Cymulate. The real governance issue is not awareness alone but whether organisations can validate that these controls work continuously.

NHIMG editorial — based on content published by Cymulate: Cybersecurity Awareness Month: Secure Our World

Questions worth separating out

Q: How should organisations reduce MFA-related account takeover risk?

A: Start by replacing the weakest factors on the highest-risk accounts, then remove recovery paths that depend on shared secrets or easily intercepted delivery channels.

Q: Why do password policies fail even when teams believe they are sufficient?

A: They fail when policy exists without evidence of enforcement.

Q: What do security teams get wrong about phishing awareness training?

A: They often treat training as a replacement for technical containment.

Practitioner guidance

  • Validate MFA coverage across every access path Check interactive logins, privileged workflows, recovery mechanisms, and legacy integrations for MFA gaps.
  • Test phishing controls beyond training completion Run simulations that measure reporting speed, repeat-click rates, and downstream containment.
  • Prioritise exploitable vulnerabilities, not just visible ones Use exposure validation to identify which missing patches or misconfigurations are reachable and weaponisable in your environment.

What's in the full article

Cymulate's full article covers the operational detail this post intentionally leaves for the source:

  • Practical mapping of the CISA Secure Our World guidance to continuous exposure validation workflows.
  • Examples of how SMBs can test MFA, phishing defence, and patching without expanding headcount.
  • Guidance on prioritising exploitable weaknesses for SLTT environments with constrained budgets and legacy systems.
  • Operational framing for turning awareness goals into measurable security checks.

👉 Read Cymulate's Cybersecurity Awareness Month analysis of Secure Our World →

Cybersecurity Awareness Month: are your controls actually working?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Validation is now the control, not the slogan. Awareness campaigns still matter, but the article’s deeper point is that organisations need evidence that passwords, MFA, phishing reporting, and patching work under real conditions. That is a governance shift from policy compliance to control assurance. For identity teams, the lesson is simple: if you cannot validate enforcement, you cannot claim resilience.

A question worth separating out:

Q: Who is accountable when patching gaps create avoidable exposure?

A: Accountability sits with the team that owns remediation prioritisation, change coordination, and risk acceptance. In practice, that usually spans security, infrastructure, application owners, and governance leadership. Frameworks such as the NIST Cybersecurity Framework and NIST SP 800-53 expect organisations to track and address known exposure with clear ownership.

👉 Read our full editorial: Cybersecurity Awareness Month puts validation at the center of resilience



   
ReplyQuote
Share: