When Cybersecurity Awareness Month began in 2004, the technology landscape looked very different.
Cloud computing had yet to become an enterprise standard. Smartphones had not yet reshaped how we work. Generative AI was nowhere near the enterprise. And the digital ecosystems connecting businesses, infrastructure, employees and customers were far less complex than they are today.
More than two decades later, technology has transformed both how organizations operate and what they need to protect. The numbers reflect it. The global average cost of a data breach reached a record $4.99 million this year, up 12% over 2025, according to IBM's 2026 Cost of a Data Breach report. And for the first time in the 19-year history of Verizon's Data Breach Investigations Report, exploiting software vulnerabilities has overtaken stolen credentials as the most common way attackers get in.
That context gives this year's federal Cybersecurity Awareness Month theme, "Securing the Next 250," particular weight. As the United States marks its 250th anniversary, the theme looks past today's threats toward the secure digital foundation the country will need for its next era.
For technology leaders, that future starts with decisions being made right now.
This post opens TSG's Cybersecurity Awareness Month series. Over the coming weeks, we'll look at what securing the next 250 looks like in practice, from real client outcomes to practical guidance on the risks shaping 2026.
More than 20 years of building cybersecurity awareness
Cybersecurity Awareness Month launched in 2004 through a partnership between the National Cybersecurity Alliance and the U.S. Department of Homeland Security. What began as an effort to help Americans stay safer online has grown into a national initiative recognized across government, industry, academia and local communities.
Today, the National Cybersecurity Alliance (NCA) and the Cybersecurity and Infrastructure Security Agency (CISA) lead the campaign each October, publishing resources organizations can use with employees, customers and communities. The National Institute of Standards and Technology (NIST) partners with other federal agencies and private-sector organizations to support the month with events, tools and guidance. NIST's own cybersecurity program history and timeline is a useful look at how much the discipline has matured over the same period.
The public-private model has been central from the start. No single organization, industry or agency can secure an interconnected digital economy on its own. As technology has become more connected, so has the responsibility for protecting it.
The scope of that responsibility has expanded considerably. What began as a campaign about safer online habits now plays out across cloud platforms, AI systems, connected infrastructure, distributed workforces and complex digital supply chains.
The fundamental goal hasn't changed. The environment around it has.
What "Securing the Next 250" means
For 2026, NIST and CISA are both using the theme "Securing the Next 250," tying the observance to America's 250th anniversary. CISA frames it around strengthening the country's infrastructure against cyber threats and building resilience, with the message that resilience starts now and every action counts.
The theme is forward-looking by design. It invites leaders to consider not only today's risks, but the digital foundation they're building for whatever comes next.
Securing the next 250 doesn't mean predicting what cybersecurity will look like decades from now. Technology will keep changing, and so will the threats around it. It means building the resilience, governance and security practices that let an organization keep evolving safely.
As businesses invest in AI, move workloads to the cloud, modernize infrastructure and connect more systems, security decisions become business decisions. The question isn't only whether an organization is protected today. It's whether its approach to security can evolve as fast as the organization does.
Five priorities stand out for technology leaders.
1. Security has to evolve with modernization
Modernization continuously changes the technology environment. New platforms come online. Data moves between more systems. Cloud environments expand. Operational technology becomes more connected. Third-party platforms become embedded in core business processes.
Each change can create new value. Each can also change the attack surface, and attackers are moving faster to take advantage. The 2026 Verizon DBIR found that vulnerability exploitation was the starting point for 31% of breaches, and that AI is helping threat actors shrink the window between a flaw becoming known and being exploited from months to hours.
That speed is why security can't be bolted on after new technology is deployed. Requirements belong in architecture, implementation and adoption decisions from day one, and controls need to be reassessed as the environment changes. Many organizations still act late in the cycle: IBM found that while half of breached organizations use AI agents in threat hunting and response, only 18% apply them to vulnerability scanning and management, where problems can be caught earliest.
NIST's Cybersecurity Framework (CSF) 2.0, now in its third year, gives organizations a common structure for doing this continuously rather than as a one-time exercise.
The goal isn't to slow innovation. It's to build an environment where innovation can continue without security becoming an afterthought. (For more on why modernization works best as a continuous discipline, see Why one-time modernization programs are failing in 2026.)
2. AI is changing the security equation on both sides
AI is now the fastest-moving variable in enterprise risk. It's changing how attackers operate, how employees work and what organizations need to protect.
On the attack side, IBM's 2026 research found AI-driven attacks increased 56% year over year, with AI-enabled malicious breaches costing roughly $1 million more than the global breach average.
Inside the enterprise, adoption is outpacing governance:
- Shadow AI is growing fast. Verizon found frequent employee use of AI tools jumped from 15% to 45% in a single year, and unapproved AI use is now the third most common non-malicious data leakage activity.
- AI systems are becoming targets. Roughly one in five organizations IBM studied reported a breach involving AI models or applications. Of those, 92% lacked proper AI access controls.
- Machine identities are multiplying. As AI agents connect to applications, APIs and data, they create non-human identities that often hold elevated privileges. IBM found fewer than half of organizations are actively securing them. NIST makes a similar case in Why Agentic AI Needs a Strong Identity Foundation.
Notably, many AI-related breaches traced back to familiar weaknesses: compromised APIs, vulnerable applications and cloud misconfigurations. That makes AI security less a niche model problem and more an extension of strong architecture, access control and governance.
AI also helps defenders. Organizations using security AI and automation extensively saved an average of $1.93 million per breach, according to IBM. The lesson isn't to slow AI adoption. It's to govern it from the start. (TSG explores this further in Securing AI, cloud, and OT environments without slowing innovation.)
3. Resilience requires preparing for disruption
Strong security programs work to prevent incidents, but prevention alone isn't enough. Organizations also need to know how they'll respond when something goes wrong.
The cost of an incident is driven largely by what happens after it starts. IBM found that two categories, detection and escalation plus lost business, made up 63% of breach costs in 2026. In other words, how quickly an organization finds, contains and recovers from an incident matters as much as whether one occurs.
CISA's Cybersecurity Awareness Month guidance for organizations reflects the same priorities: use logging, back up and encrypt data, have an incident response plan and use it, and be prepared for system disruptions.
The distinction matters. A secure organization isn't simply one that keeps threats out. It's one that can see what's happening, respond effectively, keep critical operations running and recover.
As organizations depend more on digital systems, the ability to recover becomes inseparable from the ability to operate. In regulated sectors, it's increasingly a compliance expectation as well. (See Operational resilience and cyber regulation in financial markets.)
4. Interconnected technology creates interconnected risk
Few enterprise environments operate in isolation. Organizations depend on cloud providers, software platforms, vendors, partners and increasingly connected IT and operational technology (OT). A weakness outside the organization's own perimeter can still reach its operations, data and customers.
The data shows this risk is accelerating. Breaches involving a third party now account for 48% of all breaches, a 60% jump in a single year, according to the 2026 Verizon DBIR.
The stakes are highest in critical infrastructure. A recent NIST post, Securing Water and Wastewater Operational Technology Environments, points to recent attacks on the water sector as evidence of the growing threat to infrastructure the country depends on every day.
Technology leaders need visibility beyond individual tools and systems. That means understanding dependencies, third-party access, identity controls and how information moves across the environment. It also means moving from point-in-time vendor reviews toward continuous oversight.
Securing what's next requires looking at the whole ecosystem, not just the endpoint.
5. Cybersecurity is a business responsibility
One of the biggest changes since 2004 is where cybersecurity decisions get made.
Security teams remain essential, but many decisions that shape cyber risk happen elsewhere. Business leaders decide where technology investment goes. Technology teams design new environments. Procurement brings in third-party vendors. Employees choose which tools to use every day, sanctioned or not, as the rise of shadow AI shows.
NIST recognized this shift when it added a sixth function, Govern, to the Cybersecurity Framework in CSF 2.0. It places cybersecurity strategy, roles and risk oversight alongside the familiar work of identifying, protecting, detecting, responding and recovering.
Technology, security and business leaders need shared visibility into risk and a common understanding of how security supports broader priorities. That alignment helps organizations decide where to invest, which risks need attention now and how security should evolve as the business changes.
Seven questions to ask this October
Cybersecurity Awareness Month is a natural checkpoint. These questions can help technology leaders gauge whether their security approach is ready to evolve with the business:
- Is security involved in architecture decisions for current modernization programs, or reviewed only before go-live?
- How quickly are known exploited vulnerabilities patched across cloud, on-premises and OT environments?
- Do we have a sanctioned, governed path for employee AI use, and do we know where unapproved tools are in use?
- Are AI agents and other non-human identities inventoried, scoped to least privilege and monitored?
- When did we last test our incident response plan and restore from backups?
- Which third parties have access to our systems or data, and how often do we reassess that access?
- Do business leaders and the board have a clear, shared view of our top cyber risks?
From cybersecurity awareness to action
More than 20 years after Cybersecurity Awareness Month began, awareness still matters. But it's only the starting point.
The technology has changed. The threat landscape has changed. And cybersecurity's role within the business has changed with them.
"Securing the Next 250" is an invitation to look beyond the risks directly in front of us and consider the foundation we're building for what comes next. That starts with today's decisions: how organizations modernize, how they govern AI, how they manage third-party risk, how they prepare for disruption and how intentionally they build security into everything new.
At The Select Group, we help organizations build security into modernization across threat detection and response, governance, risk and compliance, and system hardening, so posture and progress move together. Explore TSG's cybersecurity capabilities.
Latest insights, in your inbox
Subscribe now to receive the latest news and insights from TSG.
%20(2).png?width=100&height=97&name=Inverted%20Logo%20(1)%20(2).png)