Cybersecurity Awareness Month 2026
You don't need to be an expert; you just gotta get better at the basics!

The NCDPI K-12 Cybersecurity Program proudly welcomes North Carolina’s PSUs to Cybersecurity Awareness Month 2026!
Cybersecurity Awareness Month is an international effort that is co-led by the National Cybersecurity Alliance (NCA) and Cybersecurity and Infrastructure Security Agency (CISA).
Cybersecurity Awareness Month is a great opportunity to spread awareness around cybersecurity best practices and build momentum for the cybersecurity efforts in your PSU! To help you accomplish these goals, we’ve aggregated a variety of free toolkits, resources, and events that you can then use in your community.
” Cybersecurity Awareness Month reminds everyone that there are simple, effective ways to keep themselves safe online, protect their personal data, and ultimately help secure our world.”
National Cyber Alliance
Basic Cybersecurity Best Practices
In K-12, Cybersecurity can be an intimidating concept to approach. With technology constantly changing, attacks getting more personal, and bad actors getting more sophisticated, it can seem impossible to keep up. Thankfully, your community can Stay Safe Online by just getting better at the basics! Most common threats can be mitigated by using stronger passwords, enabling MFA, updating software, and recognizing phishing & scams. This year, the NCA is referring to the concept as The Core 4 + more. Please look below for more information on those skills and how they can be applied through a K-12 lens.
Feel free to use the below language for your PSU’s Cybersecurity Awareness Month
Update Your Software
Updates fix known security holes in operating systems, browsers, and apps; skipping them leaves doors open in your systems. In schools, keeping browsers, testing apps, device OSs, and classroom tools current prevents instruction disruptions and helps mitigate potential ransomware incidents. Think of updates as routine maintenance that keeps learning and business operations running.
What you Can Do
- Restart devices weekly and accept updates when prompted.
- Force a browser update to grab the latest security patches.
- Update critical classroom/home apps (video tools, doc viewers, drivers).
- At home, update phones, tablets, computers, and smart devices tied to school accounts.
Example Scenarios
- A widespread browser 0-day exploit appears, and overnight auto-updates close the hole early that same morning. This prevents a potential PSU-wide service interruption.
- An outdated testing app locks up during exams. If the application was updated beforehand, the PSU could have avoided the resulting downtime and need for retests.
Recognize and Report Scams
Phishing and social engineering attacks prey on urgency, curiosity, or fear to make people click, share info, or move money. Recognizing and reporting suspicious messages quickly helps defenders isolate threats and protect everyone. In schools, scammers typically target front offices, principals, coaches, parents, and vendors with lures like gift-card requests, fake “shared documents,” FAFSA/fee scams, and “please update bank info” emails.
What you Can Do
- Pause before you click; check the sender, hover links, and distrust surprise “urgent” requests.
- Use your mail app’s Report button or forward suspicious messages to your PSU’s security address.
- If you clicked or entered info, report it right away! Speed limits damage.
- Verify money/data changes via a known phone number or in person, not just email.
Example Scenarios
- A registrar gets a “state audit” request for student records; reporting it prevents a privacy incident where PII was potentially disclosed.
- An athletics gift card email “from the principal” is flagged and blocked because staff members report it promptly. This saves numerous PSU members from potentially sending their money to the bad actors.
Turn on Multi-Factor Authentication
MFA adds a quick second check (Push Notification, passkey/security key, One-Time Password, yubi-key) so a stolen password alone can’t be used to log in to your account. It shuts down most account takeovers. In K-12, MFA is critical for email/SSO and especially for roles handling money or student data (finance, HR, registrars, front office, technology, etc).
What you Can Do
- Turn on MFA for your email and any other account that supports it.
- Store backup codes securely (in your password manager or printed and locked away).
- If you’re subbing or traveling, confirm your default MFA method works on the go.
Example Scenarios
- Someone tries to log in to your bank account using a stolen password, but your bank sends you an SMS one-time code to verify the login attempt. This tips you off to the compromise, and you’re able to alert your bank.
Use Stronger Passwords and a Password Manager
Unique, long passwords are a first line of defense; long, random, one-of-a-kind passwords dramatically reduce the chance of a breach. A password manager handles the “remembering,” so you don’t reuse passwords across accounts. In schools, one weak or reused password can cascade into access to gradebooks/SIS, HR/payroll, transportation, vendor portals, etc. Making strong/unique passwords “standard practice” protects students, staff, and families district-wide.
What you Can Do
- Make long passphrases (4–5 unrelated words) for important accounts.
- Don’t reuse passwords—keep personal and professional separate.
- Start using a password manager; save your top 5 logins today.
- Run your manager’s “password health” check and replace weak/reused items
Example Scenarios
- A reused personal password is exposed in a breach and unlocks a payroll portal; a unique passphrase in a manager would have stopped it.
- An afterschool club’s “shared” password leaks and circulates around campus to non-club members; switch to individual accounts or a shared vault entry with limited access.
For more information on free resources to use in your PSU’s Cybersecurity Awareness Month campaigns and a schedule of upcoming events during awareness month, check out the links below!