חודש מודעות הוא התחלה. דיווח פשוט על פישינג, MFA עמיד לפישינג וטיפול בדיווחים צריכים לעבוד כל השנה.
ARTICLES / CYBERSECURITY AWARENESS
Cybersecurity awareness should work after October too
Awareness month is a start. Simple phishing reports, phishing-resistant MFA and responses to reports should work all year.
מאת בוריס פוסטילניק, מייסד Art of Cyberפורסם 1 באוקטובר 2026זמן קריאה: 2 דקות
אוקטובר הוא חודש המודעות לסייבר. במשרד תולים פוסטר, שולחים מצגת, ואולי גם עושים חידון.
נחמד. אבל מה קורה ב-2 בנובמבר?
אם עובד מקבל הודעה שנראית כאילו הגיעה מהמנכ"ל, ובה בקשה להעביר כסף בדחיפות - למי הוא מתקשר כדי לבדוק? ואם הוא כבר לחץ, האם הוא יודע שאפשר לדווח בלי לחטוף נזיפה?
מודעות היא לא מבחן זיכרון. היא הרגע שבו מישהו עוצר, בודק ומרים יד.
לכן, לפני עוד הדרכה, הייתי בודק שלושה דברים פשוטים:
האם לעובדים יש דרך קצרה וברורה לדווח על הודעה חשודה? האם חשבונות המייל והניהול מוגנים ב-MFA עמיד לפישינג? והאם מישהו באמת מטפל בדיווחים ומחזיר תשובה, או שהם נעלמים בתיבה?
CISA מדגישה השנה צעדים בסיסיים כמו זיהוי ודיווח על פישינג, סיסמאות חזקות, MFA ועדכוני תוכנה. אלה לא נושאים של חודש אחד. אלה הרגלים של כל השנה.
חודש מודעות טוב לא נגמר בפוסטר יפה. הוא משאיר אחריו דרך פעולה שעובדת גם ביום רגיל.
By Boris Pustilnik, founder of Art of CyberPublished October 1, 20262 min read
October is Cybersecurity Awareness Month. Offices put up a poster, send a presentation, and perhaps run a quiz.
Nice. But what happens on November 2?
If an employee gets a message that looks as though it came from the CEO, asking for an urgent money transfer, who do they call to check? And if they already clicked, do they know they can report it without being scolded?
Awareness is not a memory test. It is the moment someone stops, checks and raises a hand.
Before another training session, I would check three simple things:
Do employees have a short, clear way to report suspicious messages? Are email and administrator accounts protected by phishing-resistant MFA? Does someone actually handle reports and respond, or do they disappear into an inbox?
This year CISA stresses basic steps such as recognizing and reporting phishing, strong passwords, MFA and software updates. These are not topics for one month. They are year-round habits.
A good awareness month does not end with a nice poster. It leaves a way of working that holds up on an ordinary day.