Cybersecurity Awareness Month 2023: A Call for Organizational Vigilance
As Cybersecurity Awareness Month unfolds, this year’s theme, “Don’t Make It Easy for Them,” resonates profoundly not just as advice for individuals but equally as a critical mandate for organizations. Cynthia Overby, the director of strategic security solutions at Rocket Software’s ZCOE, emphasizes this dual responsibility. According to her, the need for heightened cyber resilience has become paramount, especially as recent months have highlighted significant threats. She asserts, “The past few months have shown no shortage of evidence as to why building cyber resilience is more crucial than ever before, and we will no doubt see this evolve further over the coming year.”
Overby articulates a clear distinction in the evolving landscape of cybersecurity threats. She observes that attackers are not necessarily employing new techniques but are leveraging artificial intelligence (AI) to enhance the speed, scale, and sophistication of existing methods. This shift underscores the urgency for organizations to adapt and fortify their defenses.
Victoria Dimmick, the CEO of Titania, shares Overby’s sentiments regarding the origins of cyberattacks. Dimmick highlights that many breaches do not stem from sophisticated assaults but from vulnerabilities left exposed. She notes, “Cybersecurity Awareness Month’s theme is a useful reminder that many successful attacks don’t start with a highly sophisticated technique. They start with an opportunity we’ve left open.” Simple oversights, like unpatched vulnerabilities, unnecessary internet routes, and overly permissive access rules, can be the cracks through which attackers seep into secure networks. Dimmick stresses that the automation and intelligence of modern attacks are enabling adversaries to discover and exploit these weaknesses more swiftly.
The Urgency of Speed
Mark Kuhr, CTO and co-founder of Synack, reinforces the notion that speed is a defining characteristic of this year’s cybersecurity dialogue. He explains that while Cybersecurity Awareness Month traditionally calls attention to issues like weak passwords and phishing, the pressing narrative this year is about the rapid advancements made by attackers. His team’s 2026 State of Vulnerabilities Report revealed that remote code execution vulnerabilities surged by 39% in 2025, while brute force attempts jumped by 17%. These statistics illustrate a concerning trend: the gap between vulnerability discovery and exploitation is shrinking, putting organizations at greater risk.
Kuhr emphasizes that attackers are now capable of exploiting vulnerabilities even before they are made public. AI-powered adversaries can autonomously carry out reconnaissance and scanning across numerous assets, radically shifting the landscape of cybersecurity. Unfortunately, many organizations neglect significant portions of their attack surface; research indicates that the average enterprise only tests 32% of its exposed vulnerabilities, leaving the remaining 68% vulnerable and unmonitored.
The Perils of Assumptions
Overby warns that many organizations are dangerously complacent, falsely believing that their existing security measures are adequate. “One of the biggest mistakes organizations are making amidst the current threat climate is assuming that security controls are working just because they have been implemented,” she cautions. In an era dominated by AI-driven threats and complex infrastructure, security measures can quickly become obsolete.
Dimmick elaborates on this issue at the network level, noting, “Organizations often assume the controls they have put in place are still working as intended.” Networks evolve constantly, subject to changes in device configurations, firewall rules, and added permissions. The presumptions made months prior may no longer hold true, thereby amplifying vulnerabilities.
Andrew Costis, Engineering Manager of the Adversary Research Team at AttackIQ, articulates the critical need for rigorous validation of security controls. He argues that security strategies cannot rely on unchecked assumptions. Instead, organizations should actively test their defenses to ensure they are robust and capable of addressing real-world threats.
Transitioning from Compliance to Continuous Assurance
The current regulatory framework, while beneficial, may not suffice in keeping up with the fast-changing threat landscape. Overby points out that regulations such as the Cyber Resilience Act (CRA) advocate for secure-by-design development and software supply-chain transparency. However, these regulations cannot adapt to every shift in the cyber threat environment. Therefore, organizations must evolve from merely maintaining compliance to prioritizing continuous assurance.
She remarks, “This means a transition from asking ‘Do we have security controls?’ to ‘Can we prove they are working today?’” Overby insists that organizations positioned to navigate this evolving risk landscape will be those that incorporate continuous assurance as an operational cornerstone rather than as a sporadic exercise.
Costis advocates for continuous threat exposure management (CTEM) as a means to provide ongoing visibility into an organization’s vulnerabilities. This approach allows businesses to identify and prioritize their exposure dynamically and offers validation by testing defenses against real-world tactics employed by attackers.
The Path Forward
In conclusion, Cybersecurity Awareness Month serves as a vital reminder for organizations to not only acknowledge the existence of security controls but to actively validate their effectiveness. Dimmick encapsulates this sentiment by stating that successful cybersecurity hinges on disciplined practices and regular checks. “Good cybersecurity isn’t just about responding quickly when something goes wrong. It’s about making sure attackers have fewer places to go in the first place,” she argues.
Ultimately, vigilance and proactive measures are necessary to outpace threats in an increasingly complex landscape. As Costis aptly summarizes, awareness helps to understand potential attacks, but validation reveals how defenses can withstand those threats. In a world where attackers grow more sophisticated by the day, organizations must commit to verifying their defenses continuously rather than resting on outdated assumptions.

