10/09/2026
Fully patching a vulnerability already known to be exploited took a median of 43 days, nearly two weeks longer than the year before. Shorten that window by starting with internet-facing systems and the CISA Known Exploited Vulnerabilities catalog. A useful question for the IT team or provider this week: ๐ฐ๐ก๐ข๐๐ก ๐ค๐ง๐จ๐ฐ๐ง ๐๐ฑ๐ฉ๐ฅ๐จ๐ข๐ญ๐๐ ๐ฏ๐ฎ๐ฅ๐ง๐๐ซ๐๐๐ข๐ฅ๐ข๐ญ๐ข๐๐ฌ ๐๐ซ๐ ๐ฌ๐ญ๐ข๐ฅ๐ฅ ๐จ๐ฉ๐๐ง ๐ญ๐จ๐๐๐ฒ?
October is ๐๐บ๐ฃ๐ฆ๐ณ๐ด๐ฆ๐ค๐ถ๐ณ๐ช๐ต๐บ ๐๐ธ๐ข๐ณ๐ฆ๐ฏ๐ฆ๐ด๐ด ๐๐ฐ๐ฏ๐ต๐ฉ. Four core steps anchor it every year, and the data keeps backing them up:
๐ Update software
๐ Use strong passwords and a password manager
๐ก๏ธ Turn on multifactor authentication (MFA)
๐ฃ Recognize and report phishing
๐งพ This month's newsletter, ๐๐ฒ๐๐๐ซ๐ฌ๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐ฐ๐๐ซ๐๐ง๐๐ฌ๐ฌ ๐๐จ๐ง๐ญ๐ก ๐๐๐๐, explains why each step still matters heading into 2027 and what to add next: https://www.linkedin.com/pulse/cybersecurity-awareness-month-2026-patrick-rost-cissp-ck2oc