October is back. The mornings are finally good for running, pumpkins are taking over everyone’s front porch, and everything apparently needs to taste like cinnamon. Including things that probably shouldn’t.
And, of course, it’s Cybersecurity Awareness Month!
Now, if you've been reading our articles for a while, you probably know the drill: strong passwords, multi-factor authentication, software updates, and phishing awareness. We've talked about these things before. A lot. And yet, here we are, talking about them again.
Why? Because knowing what to do and actually doing it are two very different things.
This year, the Cybersecurity and Infrastructure Security Agency (CISA), is celebrating Cybersecurity Awareness Month under the theme "Securing the Next 250," looking ahead to America's digital future. Meanwhile, the National Cybersecurity Alliance has chosen a slightly more straightforward message: "Don't Make It Easy for Them."
And we think that second one deserves some attention.
Because here's the thing: cybercriminals don't necessarily need us to be completely clueless about cybersecurity. Sometimes, they just need us to be busy, distracted, or a little too comfortable.
Think about a typical day at UMD: Between emails, meetings, research, classes, shared documents, and the occasional computer update that appears precisely when we have something important to finish, we're constantly making decisions involving technology.
And every now and then, one of those decisions involves security.
- Another MFA notification? Sure, approve. Wait, did I actually try to log in?
- An urgent email from someone in leadership? Better respond quickly! But is it really from them?
- A new AI tool that promises to summarize everything? Sounds amazing! But where exactly is all that information going?
- A software update? Remind me tomorrow. And tomorrow. And maybe next Tuesday.
- A shared document requesting access? Looks familiar enough. Click!
None of these situations is particularly unusual. In fact, that's precisely the problem; we're so accustomed to interacting with technology that it's easy to slip into autopilot. And when we're juggling a hundred other responsibilities, cybersecurity can feel like just another thing on our never-ending to-do list.
There's even a term for this: security fatigue. It's what happens when constant warnings, security requirements, and decisions become overwhelming, making people more likely to ignore them or take shortcuts. We already talked about this last year, you can check it out!
And in higher education, where collaboration, accessibility, and the free exchange of information are essential to what we do, finding the right balance can be especially challenging.
Our university relies on technology for just about everything: conducting research, teaching classes, processing financial transactions, managing student information, and keeping campus services running. A single compromised account or an improperly shared document can have consequences that extend well beyond one person's inbox.
But here's the good news: cybersecurity awareness isn't about becoming suspicious of everything or turning into a cybersecurity expert overnight. It's about developing a few habits that become second nature.
Before approving an unexpected MFA request, stop and check. Before sharing a document, take a second to confirm who can access it. Before entering university information into a new tool, consider whether it's appropriate to share. And when something seems unusual, don't be afraid to ask questions or report it.
None of this is particularly groundbreaking; and that's the whole point.
The Core 4 principles we discussed last year are still relevant, and probably will be for years to come. Technology changes, threats evolve, and AI keeps adding new complications, but the fundamentals remain remarkably consistent.
Perhaps the biggest cybersecurity challenge in 2026 isn't that we don't know enough; it's that we're expected to remember what we know while doing a thousand other things.
So, this October, instead of adding another complicated security resolution to your list, try something simpler: pick one cybersecurity habit you've been neglecting and actually stick with it.
Maybe it's finally setting up that password manager, reviewing your account security, or taking an extra five seconds before responding to an unexpected request.
Because cybersecurity isn't about being perfect. It's about making it just a little harder for someone to take advantage of us. And if we can do that while enjoying our pumpkin spice lattes, even better.
Happy Cybersecurity Awareness Month, everyone! Stay safe out there.