Cybersecurity Awareness Month 2026 asks everyone not to make cybercrime easy. For a business, one easy opening is an email domain that anyone can forge. This month, pair the campaign's four core habits with a fifth: publish SPF, sign mail with DKIM and move DMARC to enforcement, so it's much harder for criminals to send email as you.
Key takeaways
- The National Cybersecurity Alliance's 2026 theme is "Don't Make It Easy for Them." CISA is framing its campaign as "Securing the Next 250," marking the nation's 250th anniversary.
- On September 25, two former US Air Force members were sentenced to a combined 189 months for a scheme that used stolen email logins and spoofed addresses to divert payments, according to the Justice Department.
- The campaign's four core behaviors (strong passwords, MFA, recognizing and reporting scams, updating software) all apply directly to business email.
- Business owners should add a fifth: lock your domain with SPF, DKIM and DMARC at quarantine or reject.
- DMARC stops forgery of your exact domain, not lookalike domains or hijacked mailboxes, so keep verifying payment changes by phone.
What is Cybersecurity Awareness Month 2026 about?
Every October, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance co-lead Cybersecurity Awareness Month. This year they are using two taglines:
- "Don't Make It Easy for Them" is the Alliance's 2026 theme. It focuses on small, everyday habits that make life harder for criminals. The Alliance holds a virtual kickoff today, October 1.
- "Securing the Next 250" is CISA's framing, marking the nation's 250th anniversary. It is aimed mainly at critical-infrastructure owners and operators and the organizations that support them.
The Alliance's campaign centers on four core behaviors: use strong passwords and a password manager, turn on multifactor authentication (MFA), recognize and report scams, and update your software. Below, we translate them for business email and add one step only a domain owner can take.
Why does this matter for your business right now?
Last week's sentencing in Iowa shows criminals combining easy openings. On September 25, 2026, Chijioke Timothy Odimegwu, 25, and Harafat Mogaji, 26, both of Delaware and both members of the US Air Force at the time, were sentenced to a combined 189 months in federal prison, according to the US Attorney's Office for the Southern District of Iowa. Odimegwu received 111 months and $366,617.59 in restitution; Mogaji received 78 months and $995,680.45 in restitution.
According to the Justice Department and local coverage, the scheme worked like this:
- Spam and phishing campaigns stole usernames and passwords for victims' employee email accounts.
- The conspirators used those stolen logins, along with spoofed email addresses mimicking the victims or their business partners, to redirect payments to accounts controlled by co-conspirators.
- A wire of more than $1.68 million from a victim in Iowa City went to a Chicago bank account controlled by the conspiracy, and a wire of more than $720,000 from a victim in Ohio was also diverted.
How do the four core behaviors apply to business email?
| Core behavior | What it means for business email | Recent reminder |
|---|---|---|
| Use strong passwords and a password manager | A unique password for every mailbox and admin account, with no shared or reused logins | The Iowa scheme started by phishing employee email passwords |
| Turn on MFA | Prefer phishing-resistant MFA (passkeys or FIDO2 security keys) for email, admin and finance accounts | In September, CloudSEK reported that the BigBear 2.0 phishing service got past MFA on Microsoft 365 accounts by stealing session cookies |
| Recognize and report scams | Confirm any new or changed bank details by calling a number you already have, and make reporting suspicious email easy | In 2021, a Georgia agricultural business wired $158,000 after payment requests from an address nearly identical to its strawberry-seed supplier's |
| Update software | Patch mail servers and email software promptly | Microsoft reported on September 30 that attackers probed a Zimbra mail server flaw after a fix shipped but before it was disclosed, then exploited it to plant web shells |
MFA itself is now a lure. On September 9, Microsoft warned that attackers posing as IT support were calling and texting employees' personal phones, claiming a passkey, MFA or single sign-on setting had to be updated immediately. According to Microsoft, the passkey story is often just a pretext to walk victims through phishing or device-code sign-ins, and its advice includes enforcing phishing-resistant MFA through Conditional Access.
Lookalike domains need people, not DNS records. In the Georgia case, announced by the state's attorney general on September 16, the fake supplier address was nearly identical to the real one. Our breakdown of the strawberry-seed scam explains why DMARC can't block a near-miss domain.
What is the fifth behavior for business owners?
Lock your domain. Microsoft's documentation notes that internet email, by design, makes no effort to confirm that a sender is who they claim to be. Three DNS records change that for your domain:
- SPF lists the servers allowed to send mail for your domain.
- DKIM signs your messages so receivers can verify them against a public key in your DNS.
- DMARC tells receivers what to do with mail that claims your domain but fails those checks, and where to send you reports. A policy of p=none only monitors; p=quarantine and p=reject ask receivers to junk or refuse failing mail. Microsoft recommends a gradual rollout with p=reject as the goal.
Know the limits. DMARC protects your exact domain. It doesn't stop a lookalike domain, and it can't flag mail sent from a real mailbox that criminals have logged into, which is why the four habits above still matter.
Others are raising the bar too. Starting September 23, Zendesk is gradually moving eligible existing accounts to a default that suspends incoming email when SPF fails and DKIM is missing or fails (see our explainer on Zendesk's new SPF and DKIM default). And on September 24, the Federal Trade Commission asked for public comment on whether to update its rule against impersonating businesses and government to address platforms' ad tools that may help impersonation scams.
What should you do this month?
- Check your domain. Run our free email domain scanner to see your SPF and DMARC records and whether DKIM keys turn up at common selectors.
- List everything that sends as you, from your mailbox provider to invoicing and marketing tools. Keep one SPF record and turn on DKIM for each service.
- Publish DMARC and move it to enforcement. Start at p=none with reporting, fix what the reports show, then step up to quarantine and reject. Our DMARC setup guide walks through each stage.
- Move email, admin and finance accounts to phishing-resistant MFA.
- Write down a payment-change rule: new or changed bank details are confirmed by phone at a number you already have, never one from the email.
- Update your mail systems. If you self-host Zimbra, Microsoft advises upgrading to version 10.1.20 or later. Where patching must wait, it advises removing the zimbra-snmp package, disabling SNMP notifications and restricting SNMP and SMTP access to trusted hosts.
- Tell staff exactly how to report a suspicious email.
If you'd like help getting DMARC to enforcement without blocking your own mail, call us at (818) 574-8240.
Frequently asked questions
What is the theme of Cybersecurity Awareness Month 2026?
The National Cybersecurity Alliance's 2026 theme is "Don't Make It Easy for Them," built around four behaviors: strong passwords and a password manager, MFA, recognizing and reporting scams, and updating software. CISA, which co-leads the month, is framing its campaign as "Securing the Next 250," marking the nation's 250th anniversary.
Does DMARC stop business email compromise?
It stops one important kind. At quarantine or reject, DMARC tells receiving servers to junk or refuse mail that fails authentication for your exact domain, which makes impersonating that domain much harder. It doesn't stop lookalike domains or email sent from a real mailbox that criminals have taken over, so MFA and payment callbacks still matter.
Is MFA enough to protect Microsoft 365 mailboxes?
It's essential, but it can be bypassed. Researchers reported in September that the BigBear 2.0 phishing service stole session cookies to get past MFA, and Microsoft warned about fake IT-support calls and texts built around passkey updates. Microsoft recommends enforcing phishing-resistant MFA, such as passkeys or FIDO2 security keys, through Conditional Access.
Sources
- US Attorney's Office, Southern District of Iowa — Delaware men sentenced for cyber intrusion scheme targeting victims in the Southern District of Iowa (September 2026)
- National Cybersecurity Alliance — Cybersecurity Awareness Month (campaign page, 2026)
- National Cybersecurity Alliance — Cybersecurity Awareness Month 2026 Virtual Kick-off (event on October 1, 2026)
- CISA — Cybersecurity Awareness Month Toolkit (campaign page, 2026)
- Microsoft Security Blog — Passkey-themed social engineering leads to identity and cloud compromise (September 9, 2026)
- Microsoft Security Blog — Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 (September 30, 2026)
- Georgia Office of the Attorney General — Carr: Decatur Woman Sentenced for Involvement in $158k Business Email Compromise Scam (September 16, 2026)
- Federal Trade Commission — FTC Seeks Public Comment on Whether to Update Rule on Impersonation of Government and Businesses to Address Platforms' Role in Promoting Impersonation Scams (September 24, 2026)
- Zendesk — Announcing a new security standard for sender authentication (June 18, 2026)
- Microsoft Learn — Email authentication in cloud organizations (reference documentation, undated)
- Microsoft Learn — Set up DMARC to validate the From address domain for cloud senders (reference documentation, undated)
- CloudSEK — Tracking BigBear 2.0 Evilginx2 Phishing Campaign (September 7, 2026)
- The Register — BigBear phishing crew nets thousands of Microsoft 365 credentials (September 8, 2026)
- Help Net Security — Former US Air Force members behind million-dollar BEC scheme head to prison (September 30, 2026)
- KWQC — Former Air Force members sentenced after scamming Iowa victims in cyber fraud scheme (September 29, 2026)
- HIPAA Journal — Cybersecurity Awareness Month 2026: Critical Infrastructure Urged to Adopt Cybersecurity 3Rs (2026)
- UC Irvine — Cybersecurity Awareness Month 2026 (September 21, 2026)
Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.
Related Topics
Ready to Secure Your Email?
Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.