October 2026 marks more than two decades of Cybersecurity Awareness Month, a time when the industry rallies to educate and engage end users. This year, we’re offering something different: insights tailored specifically for the vendor community.
In this exclusive Q&A, Melinda Marks, Senior Research Director of our Cybersecurity GTM Insights and Advisory practice, weighs in on security fundamentals, persistent misconceptions, and priorities heading into Cybersecurity Awareness Month and Q4.
Q: What’s one security habit every employee should adopt this Cybersecurity Awareness month, and why should security vendors model it internally?
Pause your work to update software whenever an update is available, including your operating system, browser, and any applications. While you may be in the middle of a task when the updates are available or you get a prompt about an update requirement, these updates are important as they often remediate vulnerabilities or software issues.
It may require some time to restart your system, but employees should make the updates as soon as possible. Security vendors especially need to follow this type of security hygiene and set the example because they’re often specifically targeted by attackers who want to show that everyone is susceptible.
Related Reading: Cybersecurity Buying Teams: Build Trust Now, to Build Pipeline Going Forward
Q: What’s the biggest cybersecurity misconception organizations still hold in 2026, and what’s perpetuating it?
The belief that most attacks are sophisticated and carried out by attackers with advanced skills. Especially in the cybersecurity industry, we like perpetuating this myth because it sounds more exciting to be battling the newest complex threats and adversaries. However, while some attacks are sophisticated, many successful attacks are caused by human errors or social engineering, or carelessness such as configuration issues or overprovisioned access.
For example, an organization can have every possible security control in place, but if an attacker can get a person’s password or device, they can gain access to sensitive information. Or if a user clicks on the wrong link and enters their personal info, an attacker is successful.
Q: Beyond AI-related risks, what’s one priority flying under the radar that should be on every security leader’s watchlist?
Employee training is more important than ever. Every employee, including executives and those on the security team, needs training on how to practice good security hygiene, use AI safely, spot threats or phishing attempts, update software and passwords regularly, use two-factor authentication, and more.
Q: What do people need to know about cybersecurity as they use AI?
Everyone needs to stay aware and vigilant about what they put into AI, and what comes out. Be careful about sharing personal or company information, usernames, and passwords. And review AI output closely: anything it produces should be checked and verified before it’s used.
Informa TechTarget’s award-winning editorial team has earned the trust of decision-makers worldwide. Learn how our network fuels the research journey for cybersecurity decision-makers when they are learning, evaluating, and preparing to buy.