Cybersecurity Awareness Month comes once a year. Attackers do not work on an annual calendar. October gives organizations an opportunity to pause, train, and recommit to good security habits, but awareness can no longer be treated as an annual exercise. For years, the underlying message was straightforward: recognize the warning signs, take the prescribed action, and stay ahead of attackers.
AI did not invent impersonation or social engineering, but it has made both easier to automate, personalize, and scale. Reconnaissance, targeting, and tailored pretexts that once took an attacker days now take minutes, lowering the barrier for anyone with intent. At the same time, AI is compressing the window between a vulnerability’s disclosure and its exploitation, and attackers increasingly arrive before the patch does. Both trends squeeze the same resource: organizations have less time to recognize, verify, and respond.
Awareness used to flow one way: from the cyber team to the rest of the organization. In the AI era, that is only half the job. Now it is a two-sided discipline. For IT and security teams, it demands passionate curiosity: connecting weak signals, questioning patterns, and pursuing root causes. For employees, it demands verification habits: judging the request, confirming it through a trusted channel, and reporting quickly.
For IT and Security Teams: Look Around Corners
AI can help correlate signals and accelerate analysis, but it should widen the investigation, not close the case.
The biggest awareness gap on IT teams is not a lack of tools. It is where the team stops looking. The immediate issue gets fixed, the ticket closes, and the root cause is left unexplored. But awareness requires passionate curiosity: treating every finding as the visible edge of something larger and staying with it until the pattern is understood. AI can help correlate signals and accelerate analysis, but it should widen the investigation, not close the case.
Beyond the perimeter. The activity that becomes your breach may begin long before the first alert appears. Search for employee credentials or company data on the dark web, lookalike domains registered last week, your company named on ransomware leak sites, or a related third-party breach. Attackers shop before they strike. Find out what they can buy before they do.
Inside your own AI. AI agents and autonomous systems are only as safe as the permissions they hold, the data they can access, and the actions they can take. A hidden prompt in an email, document, or web page can hijack the agent that reads it, turning your own AI against you with no malware, no stolen password, and no click. Treat anything an agent consumes as untrusted input. Use content-inspection controls before ingestion to detect instructions concealed in white text, zero-width characters, or other hidden content. Look for unapproved tools receiving sensitive information, AI features enabled by default, and service accounts with more privilege than the job requires.
Beyond the alert. Do not just fix it; find the pattern it belongs to. This is the skill that separates strong security analysts from ticket closers. Watch for the host that fails patching month after month, the user who appears in three phishing reports, repeated account lockouts, the service account that suddenly gets talkative, or the admin session from a city where nobody works. One event is noise. The same event three times is a lead. Attackers hide inside routine and alert fatigue, counting on the team to treat each alert as an isolated ticket. Curiosity asks what the team has stopped questioning.
At the help desk. The caller who knows the employee’s name, manager, and last ticket may be the attacker, not the employee. Be alert to password and multifactor authentication (MFA) resets requested by phone, urgency framed as executive pressure, and callers who resist callback verification. The help desk is now a perimeter. Treat identity verification there with the same rigor you demand of wire transfers.
One warning for leaders: curiosity is trainable, and it is killable. You get what you measure. Measure tickets closed and you will build a team that closes tickets while the event that becomes the breach sits right in front of them. The analyst who reopens the case because something felt wrong just did the most valuable work of the quarter. Support, encourage, and reward their curiosity. A clean dashboard is not a safe network.
For Employees: Judge the Ask, Not the Grammar
No employee can reliably out-analyze an AI-crafted attack. Typos and bad grammar were once useful warning signs. They are no longer reliable. Today’s lures arrive with polished language, familiar context, and the right names in the right places. Employee awareness now means recognizing abnormal behavior. Pause. Verify. Report.
Judge the ask, not the grammar.
Behavior is the new tell. The invoice that suddenly needs a new routing number. The familiar executive voice note asking you to bypass approval before a meeting. The “IT technician” who contacts you about a problem you never reported, asks for your password, requests an MFA code, or directs you to install remote-access software. AI can convincingly imitate the person. It cannot make skipping the process legitimate. When a request breaks pattern, report it. A false alarm costs minutes. A missed one costs millions. Judge the ask, not the grammar.
What you share becomes their script. A vacation post, public calendar entry, or detailed out-of-office message reveals when you are gone and who is covering. A promotion announcement identifies who now has wire authority. AI turns those details into a message or voice that feels personal and credible. Before posting, ask whether you are exposing an absence, approval authority, reporting line, or internal process. When a message feels personal, verify before you trust.
Guard AI in both directions. Never paste confidential company, customer, or employee data into an unapproved or non-enterprise tool. Treat AI output as a draft, not a decision, instruction, or approval. Code, analysis, and policy answers still require normal review. A polished answer is not an approved answer.
Trust channels, not voices. A familiar voice or convincing video is no longer proof of identity. Money, credentials, and sensitive data move only after verification through a known, independent channel. Use the company directory or a number already saved, not contact information supplied in the request. No exceptions for rank. A verification ritual that applies to the CEO protects the CEO.
Ask the Harder Questions This October
Training completion is not proof of awareness. Which alerts has your IT team learned to ignore? Would your verification process hold up against a cloned executive voice or changed payment request? How quickly do employees report something suspicious, and how quickly does security respond?
Before the month ends, do four things: investigate one recurring alert pattern; audit the permissions, data, and actions of one AI tool or agent; test one high-risk verification scenario; and measure two clocks. Clock one is employee time to report, clock two is security time to acknowledge.
Passionate curiosity is how your team finds the breach before the ransom note does. Fast reporting is how your people buy back the minutes AI took away. Attackers work in hours. Do not let your organization still run on months. ![]()
Sandy Jacolow
Leave a Comment