Sentrix

Analysis · Awareness

Cyber Security Awareness Month 2026: what the numbers say

59% of Canadians hit by an incident, 42% confident they can spot AI. The 2026 theme, the four weeks, and one measurable action per week for an organisation.

By Sentrix · Published 2026-10-05

On October 1, 2026, the Communications Security Establishment launched Cyber Security Awareness Month under the theme "Your best defence is you". The Get Cyber Safe campaign, which has carried it since 2011, published three figures from its 2026 tracking survey. The most telling one is not the highest.

What the release says

The theme and the four weeks. The month is split into four weeks: recognize cyber threats (phishing and scams), strengthen your defences (passwords, password managers and multi-factor authentication), protect your information (secure online banking and shopping), build your cyber security community (sharing knowledge and reporting fraud).

The three figures. According to the 2026 Get Cyber Safe Awareness Tracking Survey, 59% of Canadians reported experiencing at least one type of cyber incident in the last year. 73% are concerned about AI-related cybercrime. 42% feel confident they can recognize AI-generated content.

The two messages. Rajiv Gupta, Head of the Canadian Centre for Cyber Security, sums it up: "AI is making some online threats and scams more convincing than ever, but the fundamentals of cyber security have not changed." The Minister of National Defence, David J. McGuinty, reminds us that "Cyber security is a shared responsibility".

Why it matters

The gap between 73% and 42% is the real finding. A majority worries about AI-assisted fraud, but fewer than half believe they can recognize it. For an organisation, that means detection by eye cannot be the main control. A well-written email, a cloned voice or a polished fake invoice will get through. What holds is a process that does not depend on that judgement: verify through a second channel, report without fear, and use authentication that cannot be phished. A suspicious message reported within five minutes protects more people than a sharp eye that says nothing, which is why the reporting rate matters more than the click rate.

That is also what Rajiv Gupta says. Threats change shape, the fundamentals stay the same. So the month does not need a new programme. It needs one measure per week, dated, that proves the fundamentals are in place.

The survey figures are about individuals. For fraud reports and losses in Canada, and their limits, see Phishing and fraud: the Canadian numbers.

What we think at Sentrix

A poster leaves no evidence. A well-chosen week does. In the order of the official calendar:

  1. Week 1, recognize. Add a "Report phishing" button to the mail client, then run a simulation. Measure the reporting rate, not just the click rate: it is the reporting rate that tells you whether the alert reaches someone.
  2. Week 2, strengthen. Measure coverage of phishing-resistant authentication on privileged accounts, email and remote access. See phishing-resistant MFA and passkeys.
  3. Week 3, protect. Write the rule for verifying any change of banking details, by calling back a number you already know. Review, while you are at it, who can export personal information.
  4. Week 4, build. Publish a single incident reporting channel and hold a one-hour tabletop exercise on an AI-assisted fraud scenario.

Each of these pieces of evidence is mapped once and serves several frameworks. Annex A control 6.3 of ISO 27001 requires information security awareness, education and training. Law 25 and PIPEDA require reasonable security safeguards to protect personal information. A dated reporting rate and strong-authentication coverage are part of them.

For an MSP or MSSP, the month becomes a deliverable. You run the same week for every client, produce evidence per client, and compare quarter to quarter.

The next step

Pick the week 1 measure today and write down its starting value. On October 31, compare. If you want to prepare the four measures and their evidence with us, contact us.

Sources

Frequently asked questions

Q01
Where do the Cyber Security Awareness Month 2026 numbers come from?
From the 2026 Get Cyber Safe Awareness Tracking Survey, cited by the Communications Security Establishment in its October 1, 2026 release: 59% of Canadians reported experiencing at least one type of cyber incident in the last year, 73% are concerned about AI-related cybercrime and 42% feel confident they can recognize AI-generated content. These are answers from individuals, not incidents measured in organisations.
Q02
Is Cyber Security Awareness Month aimed at organisations?
The campaign speaks to individuals first, but its four weeks match controls an organisation already has to demonstrate: phishing reporting, strong authentication, protection of personal information, an incident reporting channel. In the minister's words, cyber security is a shared responsibility. The month is a good deadline to produce dated evidence for each one.
Q03
How can an MSP or MSSP use the month?
By running it once for every client, with the same measure each week and evidence per client: the reporting rate of the simulation, coverage of phishing-resistant authentication, the procedure for verifying payment changes, the date of the tabletop exercise. The client gets a result they can compare month to month, not a poster.

Let's talk about your compliance program.

Last updated: 2026-10-05