Don't Make It Easy For Them: Why Lyon Tech Is a 2026 Cybersecurity Awareness Month Champion

October 1, 2026

We're proud to be a 2026 Cybersecurity Awareness Month Champion, joining organisations across the world in using October to make cybersecurity a little less abstract and a lot more actionable. But most of this year's official materials, understandably, are written for individuals: protect your own passwords, your own accounts, your own inbox.

That's good advice. It's also incomplete for the businesses we work with every day.

When a password gets reused or an MFA prompt gets ignored at work, the exposure isn't one inbox, it's every client file, every project drawing, every invoice and every account your business touches. So this October, we're taking the "Don't Make It Easy For Them" theme and pointing it squarely at business risk: what it actually means to make your organisation a harder target, and where the consumer advice needs a business-sized upgrade.

The habits still hold. The stakes are just bigger.

The Cybersecurity Awareness Month toolkit tells the story of four real cybercriminals and criminal operations, each one relying on the same thing: someone somewhere took the easy option.

Take Dariy Pankov, known as "dpxaker," who sold password-cracking software for as little as $250 a licence, no subscription required. His tools, and the AI-powered cracking that's followed since, don't need to guess a password one attempt at a time. They test thousands of combinations a second, and they love the same shortcuts businesses reach for under deadline pressure: a password reused across the CRM, the shared drive, and the finance system; a login built from a company name and the year.

An 8-character password can fall in seconds, no matter how many symbols you throw at it. A genuinely long, unique, randomly generated one (the kind a password manager creates without you having to think about it) takes billions of years to crack. That arithmetic doesn't change because the account belongs to a business instead of a person. It just gets more expensive when it goes wrong.

Then there's Zestix, a hacking operation that's compromised more than 50 multinational companies, not through some sophisticated zero-day exploit, but because someone, somewhere, never turned on multifactor authentication. Once a password is floating around the dark web from an unrelated breach, MFA is often the only thing standing between a stolen credential and a live company account. For a business, that's not just your inbox at risk. It's your VPN, your admin consoles, your finance platform, and every account an attacker could pivot through to reach a client.

And it's worth naming the version of "Giant Company" your business is actually likely to meet: not a scam text about a parcel, but a fake invoice from a "supplier," a spoofed email from "your MD" asking for an urgent payment, or a message impersonating a client's finance team. These attacks are built to create urgency and bypass judgement, and they're the mechanics behind business email compromise, a scam category that's grown alongside AI tools that make convincing fakes faster to produce.

Where the consumer checklist runs out

Long passwords, MFA, and phishing scepticism are the right foundation for anyone, and they belong on every device in your business. But a business has attack surfaces a personal account never will. If your October cybersecurity effort stops at the individual-habits checklist, here's what it's missing:

  • Offboarding and access reviews. Every former employee, every changed role, is a set of credentials that should have been switched off and often isn't. An account nobody remembers to close is one nobody's watching either: a quiet, low-effort door left open long after the person behind it has gone.
  • Vendor and third-party access. Contractors, freelancers, and suppliers with a login to your systems extend your attack surface to include their security habits, not just yours. It's worth knowing exactly who has access to what, and for how long, rather than assuming it's been tidied up.
  • Security awareness training as a habit, not a one-off. A single induction-day slide deck on phishing doesn't hold up against attacks that evolve constantly. Regular, current training, including realistic phishing simulations, is what actually changes behaviour under pressure, not just awareness of the topic in theory.
  • An incident response plan. Even well-defended businesses get targeted. The difference between a contained incident and a genuine crisis is usually whether anyone knew who to call, what to isolate, and what to say to clients in the first hour. Planning that in October is a lot cheaper than improvising it in a live incident.

Make it hard for them, we'll help

"Don't Make It Easy For Them" isn't a one-month campaign for us. It's the standard our cyber security services are built to meet year-round, across the exact gaps above:

  • Cyber awareness and training that goes beyond a slide deck: ongoing, current, and built around how your team actually works (find out more here)
  • Identity and access management, so access is granted deliberately, reviewed regularly, and switched off the moment it should be, covering employees and third parties alike. (find out more here)‍
  • Intrusion detection and prevention, watching for the moment someone tries the locked door, not just after they're through it. ‍(find out more here)‍
  • Threat detection and response, so if something does get through, it's caught and contained quickly rather than discovered weeks later. (Find out more here)

If you're not sure where your own business sits against any of this, that's exactly the conversation Cybersecurity Awareness Month is meant to start. We'd genuinely welcome it.

This October, make it difficult for them. Talk to Lyon Tech about your cyber security, and let's make this the month cybercriminals go home empty-handed.

‍

Write to us,
we will get back to you soon

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Don't Make It Easy For Them: Why Lyon Tech Is a 2026 Cybersecurity Awareness Month Champion

October 1, 2026

Most cybercriminals aren't geniuses. They're opportunists. They're not breaking down doors, they're checking which ones were left unlocked. That's the entire premise behind this year's Cybersecurity Awareness Month theme, set by the National Cybersecurity Alliance: Don't Make It Easy For Them.

We're proud to be a 2026 Cybersecurity Awareness Month Champion, joining organisations across the world in using October to make cybersecurity a little less abstract and a lot more actionable. But most of this year's official materials, understandably, are written for individuals: protect your own passwords, your own accounts, your own inbox.

That's good advice. It's also incomplete for the businesses we work with every day.

When a password gets reused or an MFA prompt gets ignored at work, the exposure isn't one inbox, it's every client file, every project drawing, every invoice and every account your business touches. So this October, we're taking the "Don't Make It Easy For Them" theme and pointing it squarely at business risk: what it actually means to make your organisation a harder target, and where the consumer advice needs a business-sized upgrade.

The habits still hold. The stakes are just bigger.

The Cybersecurity Awareness Month toolkit tells the story of four real cybercriminals and criminal operations, each one relying on the same thing: someone somewhere took the easy option.

Take Dariy Pankov, known as "dpxaker," who sold password-cracking software for as little as $250 a licence, no subscription required. His tools, and the AI-powered cracking that's followed since, don't need to guess a password one attempt at a time. They test thousands of combinations a second, and they love the same shortcuts businesses reach for under deadline pressure: a password reused across the CRM, the shared drive, and the finance system; a login built from a company name and the year.

An 8-character password can fall in seconds, no matter how many symbols you throw at it. A genuinely long, unique, randomly generated one (the kind a password manager creates without you having to think about it) takes billions of years to crack. That arithmetic doesn't change because the account belongs to a business instead of a person. It just gets more expensive when it goes wrong.

Then there's Zestix, a hacking operation that's compromised more than 50 multinational companies, not through some sophisticated zero-day exploit, but because someone, somewhere, never turned on multifactor authentication. Once a password is floating around the dark web from an unrelated breach, MFA is often the only thing standing between a stolen credential and a live company account. For a business, that's not just your inbox at risk. It's your VPN, your admin consoles, your finance platform, and every account an attacker could pivot through to reach a client.

And it's worth naming the version of "Giant Company" your business is actually likely to meet: not a scam text about a parcel, but a fake invoice from a "supplier," a spoofed email from "your MD" asking for an urgent payment, or a message impersonating a client's finance team. These attacks are built to create urgency and bypass judgement, and they're the mechanics behind business email compromise, a scam category that's grown alongside AI tools that make convincing fakes faster to produce.

Where the consumer checklist runs out

Long passwords, MFA, and phishing scepticism are the right foundation for anyone, and they belong on every device in your business. But a business has attack surfaces a personal account never will. If your October cybersecurity effort stops at the individual-habits checklist, here's what it's missing:

  • Offboarding and access reviews. Every former employee, every changed role, is a set of credentials that should have been switched off and often isn't. An account nobody remembers to close is one nobody's watching either: a quiet, low-effort door left open long after the person behind it has gone.
  • Vendor and third-party access. Contractors, freelancers, and suppliers with a login to your systems extend your attack surface to include their security habits, not just yours. It's worth knowing exactly who has access to what, and for how long, rather than assuming it's been tidied up.
  • Security awareness training as a habit, not a one-off. A single induction-day slide deck on phishing doesn't hold up against attacks that evolve constantly. Regular, current training, including realistic phishing simulations, is what actually changes behaviour under pressure, not just awareness of the topic in theory.
  • An incident response plan. Even well-defended businesses get targeted. The difference between a contained incident and a genuine crisis is usually whether anyone knew who to call, what to isolate, and what to say to clients in the first hour. Planning that in October is a lot cheaper than improvising it in a live incident.

Make it hard for them, we'll help

"Don't Make It Easy For Them" isn't a one-month campaign for us. It's the standard our cyber security services are built to meet year-round, across the exact gaps above:

  • Cyber awareness and training that goes beyond a slide deck: ongoing, current, and built around how your team actually works (find out more here)
  • Identity and access management, so access is granted deliberately, reviewed regularly, and switched off the moment it should be, covering employees and third parties alike. (find out more here)‍
  • Intrusion detection and prevention, watching for the moment someone tries the locked door, not just after they're through it. ‍(find out more here)‍
  • Threat detection and response, so if something does get through, it's caught and contained quickly rather than discovered weeks later. (Find out more here)

If you're not sure where your own business sits against any of this, that's exactly the conversation Cybersecurity Awareness Month is meant to start. We'd genuinely welcome it.

This October, make it difficult for them. Talk to Lyon Tech about your cyber security, and let's make this the month cybercriminals go home empty-handed.

‍

About Lyon Tech
Don't make it easy for cyber criminals. Discover our suite of cybersecurity services for London businesses, or get in touch with our team for a bespoke quote on ongoing support.
Explore more

Sign up for monthly updates

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Thin white curved line forming loops and waves on a black background.