Cyber Security Awareness Month (Cyber Month) is an internationally recognized campaign held each October to help the public learn more about the importance of cyber security. The campaign helps people stay secure online by teaching them simple steps to protect themselves and their devices.
Eric Polet, Director of U.S. Operations at Arcitecta:
Data Integrity Is the New Security
As data becomes the foundation for research, innovation, and critical decision-making, organizations need more than secure storage; they need confidence in the data itself.
Data security and governance begin with knowing what data exists, where it came from, who can access it, how it is being used, and what happens to it throughout its lifecycle. Metadata provides the intelligence to make that possible, turning data management from a collection of disconnected controls into an integrated, policy-driven capability.
Data security is no longer simply about protecting where data lives. It is about protecting the integrity, context, and trustworthiness of the data itself. Organizations that thrive will be those that design for resilience, building zero-trust, metadata-rich, immutable data environments that protect both integrity and reputation.
Don Boxley, CEO and Co-Founder, DH2i (https://dh2i.com/):
“The biggest cybersecurity threat may not be the attack you don’t see coming. It may be the aging infrastructure you already know is there.
Organizations are still running critical applications and databases on systems that are years behind, and accumulating technical debt because they continue to work. “It still works” is a dangerous standard for production infrastructure supporting the business. Cybersecurity Awareness Month should be a wake-up call that encourages us to look beyond the latest threats and ask more fundamental questions. Is the infrastructure serving as the virtual backbone of the business truly resilient? Can workloads be moved quickly and safely? Is there a single platform or environment that the organization is dangerously dependent on? Who and what can access critical systems, and is that access limited to only what is actually necessary?
Modernization doesn’t mean immediately ripping and replacing everything. It means eliminating unnecessary technical debt… reducing infrastructure complexity… and building in the flexibility, security, and availability needed to keep critical systems running and safe when something goes wrong. Because when that worst-case scenario actually happens, that is definitely not the time to find out your infrastructure just wasn’t ready for it.”
Richard Copeland, CEO, Leaseweb USA (https://www.leaseweb.com/):
“One of the most dangerous things a company can discover during a cyberattack is that it has nowhere else to go. If critical applications, data, and infrastructure are concentrated with one provider or on one platform, a single incident can quickly become a business-wide crisis. Cybersecurity Awareness Month should be a reminder that cyber resilience isn’t only about keeping attackers out. It’s about making sure that when something does go wrong, one compromised environment, outage, or provider problem can’t take the entire business down with it.
Organizations consequently need to start thinking about infrastructure differently. Every workload does not belong in the same cloud, platform, or provider. Security, sovereignty, availability, performance, and risk should determine where a workload lives. Certainly, not vendor loyalty or convenience. Infrastructure should follow the workload, not the vendor. Because the worst time to discover that you’ve put all your eggs in one basket is after someone has already kicked over the basket.”
Estelle Azemard, CEO, Leaseweb Canada (https://www.leaseweb.com/):
“For Canadian organizations, Cybersecurity Awareness Month should raise a question that is becoming increasingly difficult to ignore: do you actually know where your critical data is, who ultimately controls the infrastructure underneath it, and what laws could reach it? A cyberattack is frightening enough. Discovering during a crisis that your most important workloads are tied to a single provider, governed by another jurisdiction, or difficult and expensive to move can turn a security incident into a much larger business problem. Canadian companies need to think about cybersecurity not simply as protecting data, but maintaining control over it.
That means resisting the idea that every workload should automatically go to the same cloud or provider. Some applications may belong in public cloud, while sensitive data may be better suited to private or Canadian-based infrastructure, and other workloads may require dedicated environments. The point is having the freedom to make that decision based on security, sovereignty, compliance, performance, and business requirements — and to change it when those requirements change. Infrastructure should follow the workload, not the vendor. For Canadian businesses, maintaining that independence isn’t simply an infrastructure strategy anymore. Increasingly, it’s part of protecting the business itself.”
Gina Cardelli, Principal Security Strategist at Fortra:
“Most attackers still succeed through the old, familiar weaknesses: compromised credentials, excessive privileges, exposed systems, and poor security hygiene. AI may make attackers faster and more scalable, but it doesn’t make those fundamentals less important. If anything, it raises the cost of ignoring them.
“Organizations should assume something will eventually go wrong and focus on limiting the blast radius. Whether the entry point is phishing, stolen credentials, prompt injection, or an abused AI agent, the goal should be containment. Understand what your AI can reach and do, and consider the worst-case scenario for each use case. Least privilege, segmentation, human approval for actions, logging, and continuous monitoring can make every step of an attack harder, noisier, and less consequential.”
Nicole Beckwith, Senior Director of Security Engineering & Operations, Cribl:
- “For Cybersecurity Awareness Month this year, it’s time for enterprises to go beyond the usual tasks of reviewing risks, patching systems, and testing backups. Expect budgets for AI to come under greater scrutiny over the next 12 months, as leaders focus on tangible ROI and which spending needs to be reined in where. In tandem, AI will be a primary factor in why the cybersecurity threat landscape will keep accelerating given that agents are gaining greater autonomy and access to enterprise systems. The time is now for security teams to have an honest conversation about the best use of AI, its risks, what the threat model is internally, and whether or not current budget and staffing plans are going to be enough. As AI reaches its inflection point this Cybersecurity Awareness Month, leaders need to identify where AI delivers real value, eliminate waste, and invest in the people and controls to manage autonomous systems. The organizations best prepared for the next phase will be those that treat AI as critical infrastructure that must be continuously measured, monitored, and secured.”
Chris Bevil, Principal, Global Cyber Resilience & AI, Commvault:
- “AI is forcing us to rethink what ‘cybersecurity awareness’ actually means. For years, we taught people to look for the tells: the misspelled word, the strange email address, the suspicious link. AI is steadily taking many of those tells away. The skill we need to build now is not just recognition; it’s verification. But I would also take Cybersecurity Awareness Month one step further. Awareness cannot stop with the employee. Attackers do not care how we drew the organizational chart. An incident can move from identity to applications to data to infrastructure very quickly, yet many organizations still have security, IT, disaster recovery, cyber recovery and business continuity operating in separate lanes. That is where cyber resilience becomes really important.
- “For 2027, I would be thinking seriously about two things: the rise of the machine workforce and the ability to prove recovery. Agentic AI is creating a new class of identity inside the enterprise. We have spent decades thinking about what employees, administrators, and service accounts should be allowed to do. Now we have AI agents that may be able to access data, interact with applications, use credentials, and take actions on our behalf. I would treat an AI agent much like a privileged employee. Know who it is. Know what it can touch. Know what it is allowed to do. Watch what it actually does. And have a way to take away the keys when something goes wrong. The other investment I would make is in recovery that can be proven, not assumed.”
Vidya Shankaran, Field CTO – Head of Americas, Commvault:
- “In the AI context — smart and robust identity resilience is core to protecting your estate against both humans and agents looking for vulnerabilities in your armor to penetrate. Discovering gaps in identity, such as identifying systems that have unfettered access to high value data, need to be remediated as soon as possible. This level of audit-ability and remediation will decide which enterprises can survive this decade and thrive in the next decade. Security leaders must also budget for PQC preparation, which includes evaluating a C-BOM (cryptography bill of materials) and creating a crypto inventory, as well as ensuring that certificate lifecycle management and crypto agility are top priorities for businesses in the new year. 2029 PQC readiness, per the White House Executive Order, makes it highly critical and preparation needs to start sooner than later.”
Rishi Bhargava, Co-Founder, Descope:
- “Cybersecurity Awareness Month should prompt organizations to consider how identity and security fundamentals apply to AI agents, not just human users. Every agent should have a verifiable identity, task-specific permissions, a designated owner, and a complete audit trail of its actions. High-impact decisions should require human approval, especially when an agent is acting on behalf of a customer or employee. AI agent adoption may look fast right now, but without the proper identity guardrails and infrastructure in place, this adoption will be short-lived and won’t reach its full potential.”
Chris Boehm, Field CTO, Zero Networks:
- “The number that should reset every roadmap heading into October is 29 minutes. Average eCrime breakout time fell to 29 minutes in 2025, the fastest observed case took 27 seconds, and AI-enabled adversary operations rose 89% year over year. In 2021 that figure was measured in hours. AI compressed the reconnaissance and credential testing that used to give defenders a day of runway into a coffee break, and no SOC triages a ticket that fast at 2 a.m. So security operations are shifting from finding the intruder to making sure the intruder has nowhere to go. That’s why network and identity segmentation moved from the project nobody wanted to the one on every zero trust plan. Analysts project that by 2026, 60% of enterprises pursuing zero trust will use more than one form of microsegmentation, up from less than 5% in 2023. They’re also saying static, IP-based rules can’t hold against AI-driven attacks and that identity has to govern reachability now. A rule tied to an IP protects a location. Attackers steal identities.
- “Where this goes next is consolidation, and it’s overdue. Buyers announced 426 cybersecurity acquisitions in 2025, with disclosed value reaching $92.5 billion, an 82% jump over the prior year, and the first half of 2026 logged 219 deals, the fastest half on record. My prediction for the next twelve months: the winners won’t be the broadest platforms but the narrowest controls that actually stop lateral movement, because a 29-minute window rewards prevention over correlation. Expect more identity and network isolation deals, more pressure on the SOC to shrink blast radius instead of the alert queue, and a new class of problems as AI agents get provisioned with credentials nobody scoped. We’ve always had unknowns around the corner. In 2026 the corner is closer, and the environments that hold up will be the ones where a compromised login reaches almost nothing.”
Nicholas DiCola, Chief AI Security and Customer Officer, Zero Networks:
- “AI is turning many things on its head including cybersecurity from a few perspectives. One, Mythos / Glasswing is producing a high number of vulnerabilities that companies need to respond to, adding unexpected work and a backlog of vulnerabilities to fix, hopefully before someone else finds it. Two, AI is changing the way security analysts work, enabling enhanced investigation and response, but human-in-the-loop continues to slow AI ability to help. Three, attackers are using AI to speed up attacks. This means attackers still have the advantage when looking across these three.”
Max Gannon, Cyber Intelligence Team Manager at Cofense:
“Cybersecurity Awareness Month comes at a time when artificial intelligence is rapidly changing how phishing attacks are created, customized, and carried out. AI has made it easier for attackers to produce convincing, highly personalized emails at speed and scale, eliminating many of the traditional warning signs employees were once taught to look for. While defensive AI is an important part of modern email security, models are ultimately trained on previously seen threats and can struggle to identify new tactics as they emerge.
That makes the human layer increasingly important. Employees should not be treated as the weakest link in cybersecurity. When properly trained and empowered to report suspicious messages, they become a source of real-time threat intelligence. A reported phishing email can give security teams visibility into an attack that has already bypassed automated defenses, helping security teams identify and remove related threats before additional users engage.
Cybersecurity Awareness Month is an opportunity to move the conversation beyond simply teaching employees not to click. Organizations should build a culture where employees understand evolving threats, feel confident reporting suspicious activity, and receive training based on what is actually reaching inboxes. As AI reshapes both attacks and defenses, combining the speed and scale of technology with human judgment and reporting will be critical to keeping pace with emerging phishing threats.”
Michael Centrella, Head of Public Policy at SecurityScorecard:
“Cybersecurity Awareness Month is taking on new meaning in the age of AI. As organizations rapidly adopt AI, threat actors are using the same technology to identify weak links, exploit third-party access, and move through interconnected systems faster than ever before.
Security leaders need to understand how AI is reshaping the technologies, vendors, and dependencies their businesses rely on. Organizations cannot manage today’s supply chain risk with monthly or even weekly assessments. They need continuous visibility into their third-party ecosystems, an understanding of where points of failure exist, and the ability to detect and respond as risk changes.
AI may accelerate the threat landscape, but the underlying lesson is the same. You cannot protect what you cannot see. Cyber resilience increasingly depends on knowing your entire ecosystem and being prepared to act before a weakness in one partner becomes a problem for everyone.”
Christopher DeBrunner, CISO at CBTS:
“This Cybersecurity Awareness Month comes at a time when AI is continuing to accelerate the speed of cyberattacks. Attackers are using AI to move faster and scale techniques that once required more time and effort, leaving, us, the defenders with less time to identify and contain a threat. That puts more pressure on all organizations to understand where they are exposed and how quickly they can respond when something changes.
Identity is one of the biggest areas (if not the biggest) that needs to change. As organizations introduce more AI and automated workflows, they are also creating more non-human identities with access to systems and data. Those identities need to have more scrutiny and discipline around permissions, monitoring, and lifecycle management that organizations already apply to employees. Without that visibility and governance, AI can make small gaps very large.
On the flip side, AI is also helping defenders keep up by taking some of the manual work out of investigation, mitigation and response. The goal should be measurable improvement in how quickly teams identify, investigate, and contain risk. The priority now is making sure AI strengthens the security program you already have rather than adding complexity to gaps that have not been addressed.”
Farooq Khan, VP of Software Security NETGEAR:
“Cybersecurity Awareness Month is a reminder that small and medium-sized businesses are not too small to be targeted. Attackers can use automation and AI to look for weak credentials, outdated systems, misconfigurations and other openings across a large number of organizations at once.
Adding another standalone security product is not always the answer. Security needs to be built into the network, with access control, visibility and threat prevention working together. That matters even more for smaller IT teams that do not have the time or resources to manage a growing collection of disconnected security tools.
Businesses also need to assume that at some point, something will get through. Someone may click a malicious link, credentials may be compromised or an unpatched device may become an entry point. The goal is to keep that initial compromise from spreading. In a flat network, an attacker may be able to move from one system to another. Segmentation, zero-trust access and better network visibility can help contain the threat and limit the damage.”
Joseph Perry, Cybersecurity Researcher and Advanced Services Lead at Arcova:
“What is the point of cybersecurity awareness month? Not rhetorically, but genuinely. If you are a cybersecurity leader or practitioner for whom the phrase “cybersecurity awareness month” has meaning, what does a successful month look like? Do we want people to be more aware? Of what? Is it threats? If so, surely we should broaden it from the cyber and call it Threat Awareness Month (or my preferred name, “Ahh!ctober”). If it is cybersecurity threats in particular, why?
A few years ago, an elderly relative was tricked over the phone into driving to her bank, obtaining a cashiers’ check for several thousand dollars, and driving to a seedy gas station in a dangerous neighborhood. The threat actor kept her on the phone the entire time, often screaming abuse and threats. When she arrived at the gas station, the clerk asked her what she was doing there, heard the story, and physically hung up her phone for her and told her to immediately drive to the police station. There is no doubt in my mind whatsoever that a bored gas station clerk saved a life that afternoon, and that they saved it from a threat which meets every single description of cyber threat except one: it didn’t use a computer.
Here’s our controversial take: Cybersecurity Awareness Month is not about making the general public aware of cybersecurity threats. Or at least, it shouldn’t be. Cybersecurity Awareness Month should be about us, the cybersecurity community, being aware of how we touch the world and how we can make it safer, even when we’re not behind a screen. How we can use our unique knowledge and experience to help those who lack the same.
This October, give your talks, run your tabletops and your drills, even (if you really must) send your fake phishing emails to test employee attentiveness. But while you’re going through those motions, give yourself a goal as well. Find some concrete way to make the world you touch a little bit safer, to help the people whose lives intersect with yours in the way a cybersecurity professional is best equipped to do. Talk to your family and community not just about hackers and cyber threats, but about extortion and all the tools in a manipulator’s toolkit. Not just about ransomware and business email compromise, but about asking for help when they’re afraid and trusting you to protect them from those who threaten to bring the sky down on their heads.
Don’t try to scare them; they’re plenty scared as it is. Instead, give them something far more useful than fear. Give them a plan.”
Ben Bernstein, Manager, Cybersecurity Advisors Team, Huntress
Right now, the industry news cycle is heavily focused on autonomous AI attacks and LLM breakouts. While threat intelligence teams certainly see these edge cases in their research, the public narrative makes them sound exaggerated. The reality is far less dramatic. Even when attackers do experiment with these concepts, they are not doing anything fundamentally new under the hood. Long before the current AI hype wave, static scripts, automated scanners, and script kiddies were already doing the exact same thing: looking for the path of least resistance through internet-exposed, vulnerable, and misconfigured assets. If you look at what is actually driving volume and impacting organizations of all sizes today, from local SMBs up through the enterprise, the threats are grounded in standard tradecraft: ClickFix variants, fake e-signature lures, Adversary-in-the-Middle (AiTM) phishing, and RMM abuse.
There is nothing inherently malicious about remote monitoring and management software. IT administrators rely on these exact tools every day to perform routine maintenance and troubleshoot user systems. However, that utility is exactly why threat actors choose them. Because many RMMs come with built-in persistence mechanisms and frequently run with elevated administrative rights, attackers can gain deep access without ever deploying custom malware. Legacy AV and traditional security tools struggle to trigger alerts on this activity because RMM applications carry valid digital signatures from legitimate vendors. When an attacker operates through software like AnyDesk or ScreenConnect, standard security controls simply see an approved application executing routine commands. That makes detection difficult since the malicious behavior blends directly into daily administrative traffic, masking an intrusion as standard IT work.
Building true resilience against the threats hitting networks every day comes down to pragmatic execution. Focus on the fundamentals: minimize your attack surface, patch your infrastructure, and validate your controls with regular red teaming. Operate under an assumption of compromise, back that up with 24/7 behavioral monitoring, and never assume an action is safe just because it originates from an approved application.
Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ:
“A security control that has never been tested against the behavior it’s supposed to stop is still an assumption. Cybersecurity Awareness Month should encourage organizations to challenge more of those assumptions.
Would an endpoint control catch the lateral movement technique your threat model says you’re worried about? Would an identity control interrupt privilege escalation? If one defense failed, would another detect or stop the attack before sensitive data was reached? These questions can, and should, be tested before an incident.
CTEM gives organizations a continuous way to identify and prioritize exposure. Adversarial exposure validation adds evidence by testing defenses against real-world attacker tactics and techniques. The result goes beyond a theoretical risk score. Teams can see where tested protections work, where they fail and whether remediation closed the gap.
Awareness helps you understand what attackers might do. Validation shows how your defenses respond when those behaviors are tested.”
Ross Filipek, CISO at Corsica Technologies:
“A company can have endpoint protection, backups and MFA and still have a very bad day if nobody knows who is supposed to make the first call. It’s that part of cybersecurity, the dysfunction, that often gets overlooked.
For midmarket businesses, incidents land in the hands of small IT teams every day, and they’re expected to suddenly investigate the attack, keep employees working, communicate with leadership and coordinate recovery at the same time.
Preparation should reflect that reality. Organizations need to know which systems absolutely have to stay running. They need recovery plans people have actually practiced. Leadership should understand when outside help gets involved. Employees should know where suspicious activity gets reported without having to hunt for the right process during an emergency. Cybersecurity awareness isn’t only knowing how attacks happen. It’s also knowing how your organization will function after one does.”
Steve Povolny, Vice President of AI Strategy & Security Research at Exabeam:
“The security industry has spent years teaching people what suspicious looks like: bad grammar, strange links, logins from impossible locations. Attackers have been adapting to those lessons, too.
A stolen session token can authenticate normally. A compromised employee can use applications they’re supposed to use. A North Korean IT worker can enter through the hiring process rather than an exploit chain. An AI agent can take authorized actions and still produce an outcome nobody intended.
That’s why individual events are less meaningful in isolation. Modern detection has to understand behavior over time. What does this identity normally access? Which systems and applications does it use? How does today’s sequence compare with its behavior over the past several months?
The signal may not be one dramatic action. It may be a series of legitimate actions that have never occurred together before. Employees can and should report an unusual request or interaction, but we can’t expect them to recognize a valid login, an approved tool or a sequence of routine actions that only becomes concerning in context. Security programs and detection need to account for that ambiguity. Sometimes the credentials are valid, the tools are approved, and each action looks normal. Behavioral context is what gives security teams a chance to see when those normal-looking pieces stop adding up.“
Katie Paxton-Fear, Staff Security Advocate at Semgrep:
“There’s an awkward reality coming to light in the cybersecurity world: developers are being told to ship faster at the exact moment security teams need more scrutiny over what gets shipped. Most developers want to build securely, but they’re also under real pressure to get code out the door.
AI has poured gasoline on that tension. A developer can now generate a feature, integration or entire block of application logic before a traditional security review would have even started. The model may produce perfectly functional code. It may also choose an insecure function, misunderstand a trust boundary or introduce a vulnerability the developer doesn’t know to look for.
“Write this securely” isn’t enough context for an LLM. Security has to move closer to creation. Code should be checked while it’s being written. AI-generated changes should get the same scrutiny as human-written ones. Findings also need enough context to explain whether a weakness is genuinely exploitable instead of burying developers in another pile of warnings. The goal is to help developers move quickly without making security another obstacle to getting good code out the door.
AI isn’t removing developers from the security process. It’s making good developer guardrails more important. If software creation is going to accelerate, secure development can’t remain the part everyone waits on at the end.”
Nick Tausek, Lead Security Automation Architect at Swimlane:
“The modern SOC doesn’t have an information problem. It has a decision problem.
Analysts already have alerts, threat intelligence, identity data and endpoint telemetry. The slowdown happens when someone has to figure out which signal deserves attention, what context is missing and what should happen next.
The AI SOC needs to earn its keep. Not every incident needs the same level of intelligence. Routine cases can move through deterministic automation. More ambiguous activity may need AI-assisted investigation. A smaller group of complex threats can justify fully agentic analysis. Human judgment stays focused on the decisions where experience matters most.
Cybersecurity Awareness Month is a useful reminder that faster detection alone isn’t enough. Security operations need a way to turn what they know into action without forcing analysts to manually rebuild context every time something goes wrong.”
Piyush Sharrma, co-founder and CEO at Tuskira:
“Picture two vulnerabilities. One carries a critical severity score but sits on an isolated system with strong controls around it. The other looks far less dramatic. It happens to connect an exposed application to a privileged identity and then to production.
Which one gets fixed first?
For years, vulnerability management has made it too easy to answer that question with severity alone. Attackers aren’t working from a sorted CVE list. They’re looking for combinations of weaknesses that get them somewhere useful.
AI-assisted attack-path analysis can trace those combinations across identity, cloud, network and application environments. It can show which weaknesses are actually reachable. It can also identify whether an existing control cuts off the path before an attacker reaches something valuable.
Organizations don’t need more awareness of how many vulnerabilities they have. Most already know the number is uncomfortable. They need a better understanding of which ones can become a breach.”

Comparitech: Which countries are seeing the fastest growth in data centres?
Posted in Commentary with tags Comparitech on October 1, 2026 by itnerdComparitech researchers have published a new study looking at which countries are seeing the fastest growth in data centers.
Data centers are, for the first time, being targeted in military conflicts as a means to disrupt daily life and damage economies. A Russian attack recently hit a Datagroup facility in Ukraine. A series of strikes by Iran in March damaged AWS facilities in both Bahrain and the UAE. A month later, an Oracle data centre in Dubai was damaged.
To find out how the data centre landscape was changing – and where these changes were concentrated – Comparitech analysed the concentration of and increases in data center numbers of 143 countries between 2023 and 2026.
Key findings include:
Read more here: https://www.comparitech.com/news/which-countries-are-seeing-the-fastest-growth-in-data-centres/
Leave a comment »