Deepfakes have spent much of their short history being treated as a curiosity. According to Anne Cutler, cybersecurity expert at Keeper Security, that complacency is now a risk in itself. “For many people, deepfakes still feel like an internet novelty – a fake celebrity video, an altered image or an amusing example of what AI can create. That perception needs to change,” she says. “Deepfakes are increasingly relevant to personal cybersecurity because the same technology used for entertainment can be weaponized by cybercriminals to impersonate other people, manipulate trust and steal sensitive information.”
Brian Long, CEO of Adaptive Security, believes this year’s Cybersecurity Awareness Month theme captures the problem neatly. “This year’s Cybersecurity Awareness Month theme, ‘Don’t make it easy for them,’ gets at something the old break room poster never did: attackers rarely need to be clever, they just need us to be predictable.”
“The advice hasn’t changed much in a decade: use a strong password, don’t click the weird link, report what looks off. But the threat has,” Long says. “A phishing email can now be generated in seconds, written for one employee by name, and sent at a scale no scammer could manage by hand. Phone calls can carry a cloned voice, and video calls a cloned face. Instinct alone isn’t enough anymore.”
Social engineering, supercharged
Cutler stresses that the underlying tactics are not new, but the quality and volume of attacks have changed. “Cybercriminals have always relied on social engineering, but what AI changes is how convincing and scalable those attacks can become,” she explains. “An attacker no longer has to rely solely on a suspicious email pretending to be an organization or individual you know. AI can help imitate a person’s voice, appearance or communication style, creating a much more persuasive request for money, account credentials or sensitive information.”
Olli Krebs, SVP EMEA at fraud prevention company Incode, argues that this shift demands a fundamental change in how organizations think about security. “Cyber security can no longer be treated as a feature or a compliance exercise. It has to be built into the architecture of everything we do online. AI has changed the stakes,” he says. “From AI-powered fraud to increasingly convincing deepfakes, the question for organizations is no longer simply, ‘are we compliant?’ it’s ‘can we spot and contain a threat before it does damage?’”
“That’s why this year’s Cyber Security Awareness Month theme, ‘Don’t Make It Easy for Them’, matters,” Krebs adds. “Security can’t live in a policy document or be the responsibility of one team.”
When familiarity becomes a vulnerability
For individuals, Cutler says, the biggest adjustment is psychological. “Our natural instinct to trust familiarity has become a vulnerability. Cybersecurity Awareness Month is an opportunity to update the way we think about personal security,” she says. “Recognizing phishing emails remains important, but awareness now also means questioning unexpected requests regardless of how authentic or personal they appear. A familiar face or voice should no longer be treated as proof of identity.”
Her practical advice centres on out-of-band verification. “If a family member, colleague or financial institution appears to contact you with an unusual or urgent request, verify it through another trusted channel. Call the person using a number you already have rather than one provided in the message,” she says. “Never provide passwords or Multi-Factor Authentication (MFA) codes in response to an unsolicited request, and always use strong, unique credentials backed up with MFA to make accounts harder to compromise.”
Building habits, week by week
Long argues that organisations should use October to build habits rather than simply repeat warnings. “That’s why the focus on everyday habits matters and why organizations should be building the month around four weekly themes and in a practical way,” he says.
The first week, he suggests, should tackle credentials: “Your passwords are easier to crack than you think, thanks to AI, so let’s fix those habits first.” The second turns to impersonation: “That voice on the phone or face on the call might not be who it seems, so how do we check?” In week three, the focus shifts to automated attacks: “Some attacks now run start to finish with no human involved, from researching you to writing the pitch.” And the final week addresses the data employees feed into AI: “Before pasting company data into an AI tool, ask whether it’s actually approved for that.”
Long says the delivery matters as much as the message. “By doing it through short videos, posters, plain-language newsletters, a content calendar and ready-to-send emails, security teams can run a full month without starting from scratch,” he says. “Training sticks when it feels like a habit worth keeping, not a rule to memorize. Small, repeated actions each week make us harder targets, and that is exactly what this theme asks of us.”
Assume every door is being tested
Krebs warns that organisations must plan on the basis that attackers are persistent. “In 2026, locking the front door isn’t enough. Organisations have to assume attackers are testing every door, window and loose brick, every day,” he says. “The winners will be those that can spot them early, shut down their access and stop an attempted attack becoming a crisis.”
Cutler concludes that understanding synthetic media is now a core part of staying safe online. “Deepfake awareness is personal cybersecurity awareness. Understanding how attackers can weaponize synthetic media is becoming an essential part of protecting our identities, accounts and financial lives.”
Or, as Long puts it: “This October, let’s swap the poster for a habit.”





