Welcome to the Cyber Readiness Institute weekly newsletter. By delivering short, no-jargon cybersecurity advice you can put to work immediately, we hope to help you build a resilient culture of cyber readiness—one tip at a time.
Welcome to Week 1 of Cybersecurity Awareness Month. As we discussed in September, we are moving beyond “check-the-box” compliance and focusing on building lasting, preventative habits. This week, we kick off our campaign by tackling one of the Core Four habits: Passwords and Multi-Factor Authentication (MFA).
Here’s a sobering truth: most cyberattacks are not sophisticated “break-ins.” Instead, attackers gain access through weak, stolen, or reused passwords. As we explored in our August series on “Resiliency by Design,” strengthening your passwords and enabling MFA is the digital equivalent of locking your front door.
To make this habit stick, you cannot just send an email telling people to update their passwords. Instead, guide your team through all three phases of behavioral change this week. Here is your leadership plan for this week:
1
Build Awareness (Reveal the Blind Spot)
The Problem: Your team likely thinks their passwords are “good enough” or that your business is too small to be targeted. They suffer from the “unconscious risk” we discussed last month.
Your Action (Monday or Tuesday): Send a quick, informal message in your team chat (Slack/Teams) or email. Keep it conversational:
Message
“Hey team—as we kick off Cybersecurity Awareness Month, did you know that over 80% of data breaches start with weak or reused passwords? Hackers often buy stolen credentials on the dark web or use AI-powered tools to test for compromised accounts at scale. We are going to lock our digital front door this week.”
2
Secure Collective Commitment (The Bridge)
The Problem: Just knowing about a threat doesn’t mean employees will change their behavior. You need collective buy-in to turn awareness into action.
Your Action (Wednesday): At the end of a scheduled meeting, ask for a collective agreement:
Message
“To protect our data and our customer data, I want us all to agree to a new standard. Can we make a pact that by this Friday, we will all be using 15+ character passwords or pass phrases on at least three critical accounts? Let me know if you are in.”
Why it works: Once the team openly agrees to a shared goal, social accountability replaces the friction of change.
3
Drive Action (The If/Then Rule)
The Problem: Overwhelming employees with a massive security checklist invites “Present Bias” (delaying action for immediate ease).
Your Action (Friday): Give them an ultra-simple, frictionless task. Provide them with this specific “If/Then” habit trigger to run on their top three critical work accounts (like email, financial tools, and customer databases):
Trigger
“IF I log into a critical work account, THEN I will take 30 seconds to confirm MFA is enabled.”
The Bottom Line
Building a culture of prevention starts with leadership. By guiding your team through Awareness, Commitment, and Action, you are helping them build habits that strengthen your organization’s security every day.
Up Next
Once our digital front door is locked, we need to make sure we aren’t leaving any windows open. For Week 2 of Cyber Awareness Month we tackle Software Updates, and how to turn applying patches from a delayed chore into an immediate team-wide reflex.
Free Resource
The Cyber Readiness Playbook & Guide
Download the Playbook, and get your copy of the Playbook Guide to start planning today.