I have a confession, and it may not win me many friends in my own industry. I don't like Cybersecurity Awareness Month. Not even a little bit.
Every October my inbox fills up with webinar invites, phishing quizzes, branded stickers and top ten tip lists. Coffee shops roll out pumpkin spice, and we roll out awareness. And just like the lattes, it all quietly disappears on November 1.
I get the intent. I really do. But after years of working alongside nonprofits on their security, I worry that a month makes cybersecurity feel like a special event instead of part of how they run every day.
Security on a calendar
Cybersecurity Awareness Month started in October 2004, a joint effort between the National Cyber Security Alliance and the U.S. Department of Homeland Security (Living Security). The internet was moving into most homes, and a national nudge made some sense. One of the early tips? Update your antivirus software twice a year, timed to changing the smoke alarm batteries at daylight saving time.
Read that again. We started by teaching people that security is something you do on a calendar.
Twenty-two years later, we're still doing it. But cybersecurity isn't new. It has been part of our world since we first started using technology and moving information across networks. Our data, our devices and our own behavior don't take eleven months off. So why does our attention?
The special snowflake problem
Let me be clear. Awareness months matter. They put a spotlight on causes that might otherwise go unseen, and many of them do real good. Cybersecurity is different. It isn't sitting off to the side waiting for its turn in the spotlight. We, the collective society of technology users, live in it almost every waking hour of every day. Giving it a month sends a quiet message that it's a special topic with a season, the way July belongs to ice cream. So what does a month actually gain us for something we never step away from?
For cybersecurity, the research on short bursts of attention isn't kind. Researchers at the University of Chicago and UC San Diego found no evidence that annual security training reduces phishing failures (Pistachio). A study presented at USENIX SOUPS found people could still spot phishing four months after training, but the effect faded after that (Security Boulevard). One awareness provider even saw a busy October lower click rates for a while, then bring security fatigue and fewer phishing reports (Beauceron).
So we throw a party in October and spend the next several months forgetting what we celebrated.
Nonprofits don't need another special thing
Nonprofits already juggle grant reports, board meetings, volunteer schedules, fundraising deadlines and a mission that never stops. Adding a themed month to that list doesn't make security a priority. It makes it a seasonal project.
What nonprofits need is to see how security connects to the work they already do every day. When a program team collects intake forms, that's a data decision. When development picks a new donor database, that's a technology decision. When someone texts a password to a colleague because it's faster, that's a behavior choice. None of those happen only in October.
This is the heart of how we work at Sightline. When we sit down with a nonprofit for a KickStart, we don't start with threats. We start with the mission, then ask what has to be protected for that mission to keep running. Security that's tied to the mission doesn't need a month. It needs a place in how the organization runs.
What's still standing on November 1?
So here's my question for those of us who work with nonprofits, whether as volunteers, board members, consultants or vendors. If we strip away the stickers, the themed trainings and the social posts, what is still standing on November 1? If the honest answer is "not much," the month isn't the solution. It might be part of the problem.
I'm not saying skip October. By all means, run the October webinar for the nonprofit you support. Just don't let it be the finish line. What we can do is lean into making security accessible, manageable and real for every kind of user, from quantum computing experts to 90-year-olds on Facebook. With the nonprofits we support, that can be as simple as helping them carve out ten minutes for security at every staff meeting, add a data question to every new program plan, or put security on the board agenda more than once a year.
Pumpkin spice gets to be seasonal. Cybersecurity doesn't.
