Cybersecurity Awareness Month 2026: Why Cybersecurity Starts With People
October is Cybersecurity Awareness Month, and at Bastionpoint, we believe one of the most important parts of cybersecurity has nothing to do with hardware or software.
It starts with people.
Your employees answer the emails, approve the invoices, sign into the systems, and talk to the vendors. Below, we cover the three human risks we see most often with Richmond businesses, the warning signs to teach your team, and why that training pays off at home, too.
Why Does Cybersecurity Start With People?
Cybersecurity starts with people because technology can block most threats, but employees make the final call on the ones that get through. A firewall can’t tell whether a vendor really changed banks. A person who knows to pick up the phone can.
Of course, businesses need good firewalls, endpoint protection, email security, backups, monitoring, and all the other technology that goes into protecting an organization.
But at the end of the day, your employees are the ones:
- Answering emails
- Approving invoices
- Signing into systems
- Communicating with vendors
- Making hundreds of small decisions every day
Putting your people first means giving them the tools and training to make those decisions confidently. (For a deeper look at why the human side carries so much weight, read our guide to reducing employee cybersecurity risk.)
How Does Security Training at Work Protect Employees at Home?
The same habits that stop a fake invoice at work also stop a fake bank text at home. That is one of the most overlooked benefits of security awareness training for employees.
When you teach an employee how to recognize a cyber threat at work, you are also teaching them how to better protect themselves and their families at home.
That knowledge leaves the office with them:
| What they learn at work | How it protects them at home |
| Verify payment and banking changes by phone | They question a “your account is locked” banking text |
| Don’t scan unexpected QR codes | They skip the QR code on a parking meter sticker or a surprise package notice |
| Pause when someone demands immediate payment | They hang up on the “grandchild in trouble” or “IRS” call |
| Why multifactor authentication matters | They turn on MFA for their email, bank, and social accounts |
| Report anything that feels off | They tell a family member before sending money, not after |
3 Human Risks Richmond Businesses Should Watch This October
The three human risks we see most often with Richmond businesses are business email compromise, modern phishing, and attacks built on urgency. None of them need to break through a firewall. They work by getting a busy, well-meaning employee to click, pay, or approve something that looks routine.
Here’s what each one looks like and how to help your team catch it.
1. The Email That Looks Completely Normal
Business email compromise works because the request looks routine. It often comes from someone you already do business with, asking for something that feels completely normal.
In March 2026, a Richmond charitable organization wired more than $30,000 after receiving an email that appeared to come from a vendor it already knew. The message simply said the vendor no longer accepted checks and requested a wire transfer instead. The organization only discovered the fraud when it called the vendor to confirm the payment arrived. (12 On Your Side)
The good news: Richmond prosecutors and police were able to freeze the account and recover most of the money because they moved within 48 hours. That speed is the lesson. The sooner someone speaks up, the more there is to save.
Nationally, the FBI’s Internet Crime Complaint Center logged 24,768 business email compromise complaints and more than $3.04 billion in reported losses in 2025.
Train employees to stop and independently verify any change involving:
- Banking information or payment method (check to wire, new account number)
- Invoices that are new, unusual, or “past due”
- Passwords or login requests
- Payment instructions from executives, vendors, or board members
Verify using a phone number you already have on file, never the number in the email. If the email is fake, the phone number in it is too.
2. Phishing Is Getting Harder to Recognize
Today’s phishing looks polished, so “look for bad spelling” is no longer enough. People need to understand how modern phishing actually works and what to do when something feels off.
Messages can now include:
- Familiar logos and realistic login pages that copy Microsoft 365, banks, or shipping companies
- QR codes that send people to fake sites from their phones, a tactic called quishing (the FTC warns about this)
- Fake MFA requests, sometimes sent over and over until someone taps “Approve” just to make them stop (known as MFA fatigue)
- Convincing, urgent language, increasingly written with AI tools, so typos are rare
- Text messages instead of email, also called smishing. Here’s what a smish looks like.
An unexpected MFA prompt is a warning sign, not an annoyance. If you didn’t just try to log in, someone else may have your password. Deny it and tell IT right away.
Technology helps here too. Email filtering catches much of this before it reaches an inbox, and phishing-resistant MFA makes a stolen password far less useful.
3. Attackers Understand Human Behavior
One of the most effective tools cybercriminals have is not technical at all. It is urgency.
- “Pay this invoice today.”
- “I need these gift cards immediately.”
- “Your password expires in 30 minutes.”
- “The CEO needs this before the meeting.”
Attackers know that when people feel rushed, they are more likely to react before they think.
Good cybersecurity training teaches people one incredibly valuable skill: Slow down.
If a message is urgent, secret, and involves money or passwords, treat it as suspicious until it’s verified another way.
What Are the Warning Signs Employees Should Know?
Most social engineering attacks share a handful of red flags. Print this, post it near the accounts payable desk, or share it in your next team meeting.
| Red flag | What it sounds like | What to do |
| Payment change | “We no longer accept checks. Please wire the funds.” | Call the vendor at a known number before paying |
| Urgency | “This has to go out in the next hour.” | Pause. Real deadlines survive a 5-minute phone call |
| Secrecy | “Keep this between us for now.” | Loop in a manager or IT |
| Unusual payment method | “Buy gift cards and send me the codes.” | Stop. Legitimate businesses don’t pay this way |
| Unexpected login or MFA prompt | “Your account will be locked. Sign in here.” | Go to the site directly, deny unexpected MFA prompts |
| Unexpected QR code | “Scan to view your document.” | Don’t scan. Ask the sender through another channel |
Give Your People Permission to Question Things
At Bastionpoint, we believe cybersecurity should surround your employees, not simply depend on them.
That means combining security awareness training and phishing education with layers of technology:
| Layer | What it does for your people | Learn more |
| Email protection | Filters phishing before it reaches the inbox | Email Security |
| Endpoint security | Stops malicious files and activity on laptops and servers | Endpoint Protection Explained |
| Managed detection and response | Watches for threats around the clock and responds fast | How EDR Detects Attacks |
| Multifactor authentication | Makes a stolen password much less useful | Email Security |
| Backups | Lets you recover if something does get through | Disaster Prevention & Recovery |
| Security policies | Gives employees clear rules, like how to verify payments | Cybersecurity Policies & Procedures |
But there is also a cultural side to cybersecurity. Employees need to know that it is okay to question something:
- It is okay to call a vendor and verify banking information.
- It is okay to ask whether an email really came from an executive.
- It is okay to report something they clicked without worrying that they are going to get in trouble.
The sooner your IT or security team knows something happened, the faster they can respond. The Richmond charity story above proves it: acting within 48 hours is what got the money back.
Cybersecurity Awareness Month Tips You Can Use This Week
You don’t need a big program to make progress this October. These five cybersecurity tips for employees take less than an hour to put in place:
- Set a payment verification rule. Any change to banking details gets a phone call to a known number. No exceptions.
- Turn on MFA everywhere it’s offered, starting with email, banking, and remote access.
- Name a reporting contact. Make sure everyone knows exactly who to tell when something feels off, and that they won’t be in trouble for it.
- Run a 10-minute team huddle using the red flags table above.
- Share one at-home habit, like turning on MFA for personal email, so the lesson goes home with them.
These line up with the national Cybersecurity Awareness Month 2026 campaign. The National Cybersecurity Alliance theme this year is “Don’t Make It Easy for Them,” focused on strong passwords, MFA, software updates, and spotting phishing, and CISA’s theme is “Securing the Next 250.”
Want a bigger checklist? Our back-to-school security habits for Richmond companies covers MFA, backups, and access reviews in more detail.
Cybersecurity Awareness Month Is a Time to Invest in People
Cybersecurity Awareness Month is a great time to review your technology. But it is also a great time to invest in your people.
Because when you teach someone how to better protect your business, you may also be teaching them how to protect their bank account, their identity, their family, or someone they love.
To us, that is what putting people first looks like.
Defend Your Castle. Protect Your Business. Bastionpoint has helped Richmond businesses and nonprofits stay secure for more than 18 years. Let’s talk about training your team and putting the right protection around them. Call (804) 612-9876 or Schedule Your Free IT Assessment Today.
Watch Bastionpoint on CBS 6 This October
For more information on Cybersecurity Awareness Month and practical ways to protect your business, your employees, and your family, watch for Bastionpoint Technology’s cybersecurity segments during the CBS 6 Richmond (WTVR) newscasts throughout October.

Leave a Reply
Want to join the discussion?Feel free to contribute!