Cybersecurity Awareness Month: A Practical Four-Week Team Plan - Yenra

Run a four-week awareness program with short practical activities, named owners and evidence of completed improvements.

Four ivory planning panels display a key, update arrows, envelope and backup drive, with amber completion tokens.
A practical awareness program connects a short lesson to an action and a check.

Choose a few actions the team can complete

Use Cybersecurity Awareness Month to help people complete a few useful security tasks and practice asking for help. A short activity with a clear result is easier to sustain than a month of advice with no owner or follow-up.

The National Cybersecurity Alliance’s 2026 campaign page presents the theme “Don’t Make It Easy for Them” and offers a toolkit through its Champion registration. Use the current page for official campaign materials. The four-week plan below is an original Yenra planning example that can be adapted for October or another suitable month.

Before inviting participants, name a coordinator and a technical contact. Choose the people and systems in scope, check that the proposed actions are supported, and reserve short help sessions. Include remote staff, shift workers and people who need accessible formats or an alternative to a live session.

Agree what evidence is useful and proportionate. A completion count or a confirmed test result is usually more useful for program management than collecting screenshots containing passwords, recovery codes or personal messages. Keep individual problems in the appropriate private support process.

Use a four-week sequence

An adaptable four-week team plan
WeekActivityOwner and success check
1: Account accessHelp participants configure an approved password manager and supported MFA/passkey method for an in-scope account.Account owner and IT verify enrollment and a supported fallback route without collecting secrets.
2: Supported devicesCheck update status and identify unsupported or blocked devices.Device owner records completion; IT assigns unresolved exceptions an owner and next action.
3: ReportingWalk through a clearly labeled fictional suspicious-message example and the actual reporting route.Support confirms that a harmless practice report reaches the right queue and receives an understandable response.
4: RecoveryPractice a small approved restore or account-recovery dependency check.System owner records the tested scope, outcome and remaining gap; coordinator assigns follow-up.

Give each session a brief explanation, a demonstration and time to complete the action. Use a test account or harmless sample where a live demonstration could expose personal information or disrupt work. Tell participants how to stop and get assistance when the expected result does not appear.

NIST’s participation guidance offers additional ways to involve an organization or community. Choose activities that fit your audience. An experienced administrator and a first-time password-manager user need different starting points and help.

Make reporting easy to practice

Show the actual report button, help address or service-desk route that your organization supports. Explain what to include and how the support team will acknowledge the report. Give a backup route for a situation in which email or the normal login is unavailable.

Thank people for asking early. Keep exercise feedback specific: “Use the supplier number already in our records” gives a more usable next step than “be more careful.” If a participant discovers a real incident, move it into the incident process and keep it out of the public training discussion.

Measure completion and close the gaps

Record the number in scope, the number who completed the task and the unresolved reasons. Separate “attended a session” from “completed the security action.” Also separate a staff knowledge gap from a missing feature or an administrator’s pending work.

At the end, select a small number of improvements to keep: an easier reporting route, a device-exception review or a recurring recovery check owned by the team. Set a review date in the organization’s own planning system and confirm that someone has accepted responsibility.

Use the linked Security guides as task support. The vault recovery guide, spam and suspicious-email guide, phone preparation guide and small-team policy guide let participants return to detailed instructions when they need them.

For next year, retain the working plan and anonymized lessons, then refresh official campaign references and product-specific steps. A useful awareness program improves the organization’s ordinary support and security work throughout the year.

Related Security guides