Ayliea Awareness Series · CAM-2026-01

Cybersecurity Awareness Month Toolkit

A practical, four-week campaign for small organizations that need useful security habits without a full-time security team.

Choose one owner, keep training to 5–15 minutes, make reporting easy, and track the operational fixes the campaign exposes.

01

Week 1 — Protect Accounts

Focus: Identity & access

  • Require MFA wherever supported and prioritize phishing-resistant methods for high-value accounts.
  • Use unique passwords and a password manager.
  • Action: Inventory administrator, email, financial, cloud, and remote-access accounts. Mark which lack MFA or still use shared credentials.
02

Week 2 — Recognize & Report

Focus: Phishing & social engineering

  • Inspect unexpected requests, urgency, payment changes, credential prompts, QR codes, and unusual attachments.
  • Verify sensitive requests through a known second channel.
  • Action: Publish one reporting method and run a short phishing-spotter exercise.
03

Week 3 — Think Before You Paste

Focus: AI & data security

  • Treat AI tools like any external service.
  • Do not submit credentials, regulated data, customer confidential data, proprietary code, or internal records unless the organization has approved the tool and use case.
  • Action: List approved AI tools and define what data classes may or may not be entered.
04

Week 4 — Recover Well

Focus: Patching, backups & incident readiness

  • Enable automatic updates where appropriate and maintain tested backups.
  • Make sure staff know what to do when something goes wrong.
  • Action: Test one restore and run a 15-minute incident tabletop with leadership or operations.
05

Ready-to-send employee messages

  • Week 1: Protect your accounts. Turn on MFA, never approve a sign-in prompt you did not initiate, and avoid reusing passwords.
  • Week 2: Slow down suspicious messages. Verify unexpected urgency, payment changes, credential requests, QR codes, and unusual attachments.
  • Week 3: Think before you paste into AI. Do not place restricted information into an AI tool unless the tool and use case are approved.
  • Week 4: Prepare to recover. Install updates, protect backups, and report unusual device behavior quickly.
06

Manager checklist

  • Review MFA coverage for high-value accounts.
  • Make a password manager available and eliminate shared accounts.
  • Document and test the suspicious-message reporting channel.
  • Include critical systems in the patch/update process.
  • Test at least one restore of critical data.
  • Review vendor/contractor access.
  • Document incident contacts and escalation paths.
  • Document approved AI tools and restricted data categories.
  • Assign an owner to every unresolved gap.
← All awareness resourcesPrint or use your browser’s “Save as PDF” option for a clean copy.