It’s Time to Rename Cybersecurity Awareness Month

Cybersecurity Awareness Month did its job. Twenty years later, people know security matters, and what's missing is action. It's time to rename it Cybersecurity Readiness Month.

October 2nd, 2026

Welcome to Cybersecurity Awareness Month. Every October, the security industry performs one of its oldest rituals. We remind everyone that passwords should be strong, multifactor authentication (MFA) is good, phishing is bad, software should be updated, and not to click sh*t.

In 2004 this made perfect sense, today, not so much. 

Cybersecurity Awareness Month started that year as a collaboration between the Department of Homeland Security and what is now the National Cybersecurity Alliance. The original campaign targeted home users, small businesses, schools, and other groups that were rapidly connecting to the Internet but often had little understanding of the risks involved.

At the time, Facebook had just launched. Gmail was brand new. Windows XP was everywhere. And the iPhone didn't exist. Most people had never heard the word ransomware. Getting people simply aware that cybersecurity mattered was a perfectly reasonable goal. More than two decades later, I think we can declare victory on the awareness front.

Awareness Isn't the Problem Anymore

People are aware. They may ignore the warnings. They may reuse passwords. They may approve an MFA request because they're tired and trying to get into a meeting. Companies may still expose databases to the Internet and developers may still accidentally commit credentials. But none of those things happen because people are somehow unaware that cybersecurity is an issue.

Cybersecurity is on the evening news. Ransomware shuts down hospitals. Data breaches generate congressional hearings. Parents worry about what happens to their kids online. CEOs discuss cyber risk with their boards. Insurance companies ask about security controls before writing policies. At this point, someone could probably explain phishing to you while actively clicking a phishing link. Awareness isn't the problem, behavior is.

This is why I think we should rename Cybersecurity Awareness Month. Awareness is passive, security isn't.

Knowing that software vulnerabilities exist doesn't protect an application. Fixing them does. Knowing that backups are important doesn't help when ransomware hits if nobody has tested whether those backups actually restore.

Even the organizations running Cybersecurity Awareness Month seem to recognize this. CISA's (Cybersecurity and Infrastructure Security Agency) messaging has increasingly emphasized taking action, while the National Cybersecurity Alliance has focused on building repeatable security habits. That's progress, but it also raises an obvious question: if the objective has changed, why hasn't the name?

We Need to Talk About the Acronym

Then there's the acronym problem. Cybersecurity Awareness Month inevitably shortens to CSAM, an acronym already widely used for child sexual abuse material by the FBI, DOJ, National Center for Missing & Exploited Children, technology companies, and trust and safety teams. This isn't some obscure collision buried in an acronym dictionary. It's a term used constantly by many of the same organizations we're asking to promote Cybersecurity Awareness Month. Of all the naming problems cybersecurity has created for itself, this might be the easiest one to fix.

Awareness Is a Terrible Finish Line

There's a third problem with the name that may actually be more important than the first two: names tell people what success looks like.

If you call something Awareness Month, success looks like people hearing about cybersecurity and being, you know, aware. We publish some graphics, employees watch another training video, someone sends a training phishing email. Everybody clicks through the annual slide deck while answering Slack messages. Somebody in marketing adds a padlock to a stock photo of a laptop. Congratulations, everyone is now aware. See you next October.

What we actually want is readiness. We want people to use MFA. We want organizations to patch systems. We want developers to fix exploitable vulnerabilities. We want companies to know what they'll do when credentials are stolen. We want backups that have actually been restored during a test. We want incident response plans that aren't Word documents last opened three CISOs ago.

That's a much higher bar than awareness, and it produces something we can actually measure. Did you enable the control? Did you patch the vulnerability? Did you test the backup? Did you exercise the response plan? Did you reduce the risk?

Security should be about outcomes, not whether everyone sat through the annual PowerPoint.

So What Should We Call It?

Call it Cybersecurity Readiness Month.

Yes, CSRM already has a few obscure uses, including Certified Security Risk Manager and Coastal Storm Risk Management. Fine. Acronyms collide. The important thing is that nobody is going to wonder why CISA is using the same acronym law enforcement uses for child sexual abuse material. CSRM is boring, uncontroversial, and usable. That's a substantial upgrade.

More importantly, readiness demands action. Awareness asks, "Do you know phishing is a problem?" Readiness asks, "What happens when somebody clicks?" Awareness tells you ransomware exists. Readiness asks whether your backups actually restore. Awareness tells employees to use MFA. Readiness asks why you haven't turned it on yet.

We don't need another October reminding people that attackers, vulnerabilities, phishing, and ransomware exist. Message received. We need to ask a harder question: Are you ready?

Awareness was the right mission for 2004. Readiness is the right mission now.

How Do We Rename Cybersecurity Awareness Month?

Cybersecurity Awareness Month isn't a federal law or anything. The observance is usually declared by a presidential proclamation every year, or an occasional congressional non-binding resolution, as well as the ongoing federal campaign led by CISA in partnership with the National Cybersecurity Alliance. That means officially changing the name is primarily a matter of getting the organizations responsible for the observance to agree that the campaign has outgrown its original branding.

The cleanest route would be for CISA and the National Cybersecurity Alliance to adopt new campaign branding, followed by the new name appearing in the annual presidential proclamation. Members of Congress could use the same terminology in supporting resolutions, and states, agencies, companies, nonprofits, and other participants would follow the new branding.

That's not trivial, but it's hardly impossible. We've renamed airports, military bases, federal agencies, government programs, sports teams, even large bodies of water. I have faith that the United States government can eventually figure out how to rename a month-long cybersecurity marketing campaign. Probably after forming a working group.

Or we could go the unofficial route. If we can all decide on a new name and just start using it we could drown out the official name and replace it with something that actually has some meaning behind it. I’m going with Cybersecurity Readiness Month unless someone comes up with something better.

Declare Victory and Move On

None of this means Cybersecurity Awareness Month was a failure. Quite the opposite. It has been around for more than 20 years because it served a legitimate purpose. It helped make cybersecurity something ordinary people talked about rather than something handled by a handful of people hiding in server rooms and communicating primarily through IRC. And you know what, it worked. We should declare victory.

Security has spent two decades telling people to become aware of the problem. They're aware. The next step is getting them prepared to do something about it. Awareness tells you something is flammable. Readiness means you know where the fire extinguisher is, you've checked that it works, and you aren't reading the instructions while the building burns.

Over the course of October, or Cybersecurity Readiness Month, I'll be publishing three additional parts to this series focused on what readiness actually looks like. We'll move past the posters, phishing quizzes, and annual training videos and get into the things that make a measurable difference: preparing individuals to protect themselves, helping organizations build security that works when something goes wrong, and making sure we can recover when prevention inevitably fails. Follow along on the Semgrep blog.

Let's retire Cybersecurity Awareness Month and replace it with something that reflects where we are today. I just know we can do better than "awareness." And we can definitely do better than CSAM.