October is Cybersecurity Awareness Month. CISA's theme this year is "Securing the Next 250", and the National Cybersecurity Alliance is running "Don't Make It Easy for Them". Both come with free toolkits, and behind them sits a large body of free guidance from government agencies and standards bodies.
We've grouped the material worth your time by topic. Every link goes to the original publisher, and every one was working when we checked it this month.
Start here
If you only do four things this month, do the four CISA has promoted for years under Secure Our World: recognize and report phishing, use strong passwords with a password manager, turn on MFA, and update software.
For the month itself, CISA has a 2026 toolkit, and the National Cybersecurity Alliance sends posters and social graphics to anyone who registers as a Champion.
Phishing and social engineering
- Phishing Guidance: Stopping the Attack Cycle at Phase One, from CISA, NSA, the FBI and MS-ISAC, for whoever runs your email and identity provider.
- Implementing Phishing-Resistant MFA, CISA's fact sheet on security keys and passkeys.
- How to Recognize and Avoid Phishing Scams from the FTC, plus its two-page small business phishing handout.
- The UK NCSC's phishing guidance and its free Top Tips for Staff e-learning, which needs no login.
- Google's phishing quiz, a good five-minute team exercise.
- NIST's Phish Scale, for rating how hard your own test emails are.
Our week one post goes further: free phishing awareness resources, and how to show an auditor you used them.
Hardening laptops, phones and servers
- CIS Benchmarks, free PDFs after registration.
- The NIST National Checklist Program, an index of checklists from many publishers.
- Microsoft's Security Compliance Toolkit for Windows, and NIST's macOS Security Compliance Project for Macs.
- DISA STIGs, strict but useful as a reference.
- For phones: NIST SP 800-124 Rev. 2, the NCSC's device security guidance, and NSA's Mobile Device Best Practices.
IoT and connected devices
- NIST IR 8425, the consumer IoT baseline, and NIST SP 800-213 written for federal agencies and usable by any organization adding IoT devices to its network.
- ETSI EN 303 645, the European consumer IoT standard, as a free PDF.
- The OWASP Internet of Things project. Its IoT Top 10 dates from 2018 and still reads as a sensible checklist.
- NSA's Best Practices for Securing Your Home Network, worth sending to anyone who works from home.
Physical security and insider risk
- CISA's physical security hub and its Insider Threat Mitigation Guide.
- CISA Tabletop Exercise Packages, ready to run, and the Cyber-Physical Convergence Scenarios.
- NIST SP 800-88 Rev. 2 on media sanitization, for the box of old laptops.
- Ready Business from Ready.gov, and the UK's National Protective Security Authority.
Running a small security program
- CISA's Cyber Guidance for Small Businesses and Cyber Essentials.
- CISA's catalog of no-cost cybersecurity services and tools.
- The FTC's Cybersecurity for Small Business and the FCC's Small Biz Cyber Planner.
- The NIST CSF 2.0 Small Business Quick-Start Guide and NIST's Small Business Cybersecurity Corner.
- The Global Cyber Alliance's Cybersecurity Toolkit for Small Business.
- When something goes wrong: NIST SP 800-61 Rev. 3 on incident response and CISA's #StopRansomware Guide.
Keeping a record of it
An auditor will ask for proof of awareness work. Whatever you pick from this list, assign it to named people, keep the completion dates, and tie it to a policy you already have.
Keel's policy templates and free tools need no signup. Security awareness training is on every Keel plan, including Free, and keeps each completion certificate as evidence.