Cybersecurity Awareness Month: 4 Basics That Stop Breaches
Updated August 1, 2026
In February 2024, the ransomware group ALPHV/BlackCat got into Change Healthcare – the company that processes a huge share of the country’s prescription and medical claims – through a single Citrix remote-access account. The account had a valid, stolen password. It didn’t have multi-factor authentication turned on. Attackers spent about ten days moving through the network before deploying ransomware. By the time it was over, UnitedHealth Group’s CEO told Congress the incident cost $872 million, disrupted pharmacies and medical claims across the country for weeks, and exposed protected health information in what may be the largest healthcare data breach in U.S. history.
None of that required a zero-day exploit or a nation-state budget. It required one login that should have had a second factor and didn’t. That’s what cyber hygiene actually means – not a single dramatic defense, but the unglamorous basics done consistently, on every account, every time.
Why the Basics Keep Failing
Verizon’s 2026 Data Breach Investigations Report – the industry’s largest annual study of confirmed breaches – found that 62% of breaches involved the human element in some way, with credential compromise showing up in 39% of them. And for the first time in the report’s 19-year history, exploited software vulnerabilities edged out stolen credentials as the single most common way attackers get in, accounting for 31% of breaches. “Keep it patched” now matters just as much as “guard your password.”
Attackers have also moved past email. The same report found mobile-based phishing – fake texts and voice calls – succeeding roughly 40% more often than the traditional email version, since fewer people think to be suspicious of a text message.
October marks the 22nd annual Cybersecurity Awareness Month, the National Cybersecurity Alliance and CISA’s yearly campaign built around the same four fundamentals: multi-factor authentication, strong (and managed) passwords, timely software updates, and phishing awareness. None of this is new advice. What’s changed is how expensive it’s gotten to skip it.
Essential Cyber Hygiene: The 4 Basics That Matter Most
We follow good hygiene to maintain physical health – brushing your teeth every day isn’t exciting, but skipping it has consequences. Cybersecurity works the same way. These four practices aren’t sophisticated, but they’re the foundation everything else gets built on.
Enabling Multi-Factor Authentication (MFA)
MFA means a second proof of identity beyond a password – a code from an app, a push notification, a hardware key – so a stolen password alone isn’t enough to get in. It’s not a nice-to-have anymore; it’s the single control missing from the Change Healthcare breach above.
The data backs that up. Microsoft’s own Azure-scale research found that MFA reduces account compromise risk by 99.22% overall, and 98.56% even on accounts where the password had already leaked. We enable MFA on every account we manage for a client, and we use Huntress ITDR to flag suspicious logins that make it through anyway – because a stolen session or an approved push notification can still slip past MFA, and having eyes on identity activity is what catches it.
MFA isn’t flawless, though, and it’s worth knowing where it can still be beaten. “Prompt bombing” – spamming an employee with login approval requests until one gets tapped by accident or out of frustration – accounted for roughly 14% of MFA-related incidents in last year’s DBIR research. That’s part of why we steer clients toward authenticator apps or hardware keys over SMS codes where we can, since those forms are harder to fatigue or intercept.
Strong Passwords & a Password Manager
Passwords remain a critical piece of account security, and reuse is still the quiet failure mode behind a lot of breaches. Verizon’s research on credential attacks found that among users infected with password-stealing malware, only 49% had used a distinct password for every service – meaning one leaked password often opens several doors, not just one. Credential stuffing attacks built on exactly that pattern made up a median 19% of all daily authentication attempts across the organizations Verizon studied – 25% at enterprise-sized companies.
We deploy and recommend Keeper Security across our client base so employees generate and store a unique, strong password for every account instead of reusing (or memorizing) a handful of them. Where we can set policy, we require passwords of at least 12 characters with a mix of upper and lower case letters, a number, and a symbol – long and random beats clever every time.
Keeping Software Updated
Outdated software is exactly the vulnerability category that’s now the single biggest way attackers get in, per the 31% figure above. Every unpatched operating system, application, or piece of firmware is a door someone else already knows how to open.
Waiting on individual employees to click “update later” is how that door stays open. We push security patches automatically across client endpoints through our RMM platform – RMM stands for remote monitoring and management, and it’s the software that lets us see and update every device on a network from one place, without needing someone at each individual computer. Patches go out on a set cadence rather than being left to chance, so the fix ships close to when it’s released, not whenever someone happens to restart their laptop.
Recognizing and Reporting Phishing
Phishing is still the most common way an attacker gets a foothold, and it’s no longer just email. Train your team to slow down on unsolicited messages, verify the sender before clicking a link or opening an attachment, and treat text messages and phone calls with the same suspicion as email – especially given how much better mobile-based attempts are performing right now.
We run ongoing phishing simulations and training through Huntress Managed SAT, and Proofpoint filters a large share of attempts before they ever reach an inbox. But the last line of defense is always a person who notices something’s off and says something. Make sure employees know exactly how to report a suspicious message, and treat every report as useful – even the false alarms – so the habit of speaking up sticks.
The Bottom Line
Cyber hygiene doesn’t require a big budget or a security team of your own. It requires MFA on every account, a password manager instead of reused passwords, updates that happen automatically instead of “when someone gets around to it,” and a team that knows what phishing looks like and feels safe reporting it. Change Healthcare had none of that on one account, and it cost their parent company the better part of a billion dollars. Most breaches don’t start with something exotic – they start with a basic that got skipped.
Book a Free Consultation
Not sure where your business actually stands on the basics? Let’s talk. Book a time on my calendar and we’ll walk through what’s already in place and what’s missing, as part of a broader cybersecurity program built for your business.
Frequently Asked Questions
It’s the National Cybersecurity Alliance and CISA’s annual campaign, held every October since 2004, to get individuals and businesses focused on the same core cybersecurity basics: multi-factor authentication, strong passwords, software updates, and phishing awareness. 2026 marks its 22nd year.
Enabling multi-factor authentication on every account, using strong and unique passwords managed through a password manager, keeping software and systems updated, and recognizing and reporting phishing attempts – across email, text, and phone.
Very. Microsoft’s research on Azure accounts found MFA cuts the risk of account compromise by 99.22% overall, and by 98.56% even on accounts where the password had already been leaked.
It’s the single biggest thing you can do, but it isn’t foolproof. Attackers have had some success with “prompt bombing” – spamming approval requests until someone taps one by mistake – which is why phishing-resistant MFA methods and ongoing monitoring for suspicious logins matter too.
Because the failure point usually isn’t one weak password – it’s reusing the same password across services. A password manager generates and stores a unique password for every account, so one leaked credential doesn’t open the door to everything else.
Don’t click any links or attachments, verify the sender through a separate channel if unsure, and report it right away using your company’s process. Reporting matters even when you’re not certain – it lets IT warn the rest of the team and take action before anyone else falls for it.