Skip to main content

Every October, inboxes fill up with “It’s Cybersecurity Awareness Month: Top 5 Tips to Stay Safe Online.” (Cue the collective eye roll.)

The truth? Cybersecurity isn’t something you check off once a year, it’s a conversation that should never stop. This might elicit another eye roll, or even a “duh,” but it is always… worth… repeating.

To peel back the page a bit further, we tapped Ryan Davis, Chief Information Security Officer (CISO) at New Charter Technologies.

Cloud Computing

“Security should be something that we’re having a continuous conversation about,” says Davis. “As soon as it stops being the thing you’re thinking about, that’s when your defenses are down.”

To add to the fun, AI is only making cyber threats smarter and way harder to detect.

Attackers no longer need to be fluent in English, or even particularly clever, to fool you. Large language models can spin up eerily convincing emails in seconds, in any voice—from Bill Gates to your boss.

People Are Still the Weakest Link

Despite decades of training, phishing simulations, and “don’t click that link” emails, human error remains the biggest vulnerability.

And it’s not just because some people are careless, it’s because the attackers are evolving faster than awareness campaigns.

“The technology is enabling attackers to move faster than humans can react,” says Davis. “The things we’ve historically taught people to rely on—misspellings, odd links—those cues have all but evaporated.”

Even multi-factor authentication (MFA), one of the most effective defenses, isn’t foolproof. But skipping it because it’s “annoying”? That’s a rookie mistake.

“MFA really does make it more difficult for an attacker to be successful,” Davis notes. “Every time we respond to a compromise, it’s a similar story: that account didn’t have MFA turned on.”

Make Cybersecurity a Story, Not a Slogan

Davis argues for a culture of storytelling around security, something more human, relatable, and continuous.

“We see new threats every single day, and most of the time, we just go and respond to them,” he says. “But we so often miss the opportunity to talk about what just happened. That’s how people learn.”

Imagine if every MSP, IT team, and small business shared real, anonymized “in the trenches” stories. Quick, digestible, and honest. That kind of transparency could shift the whole industry from reactive to proactive.

“It’s not just about doing it better than the next guy,” Ryan adds. “It’s about all of us recognizing how important this is and keeping the conversation going.”

AI: The Double-Edged Sword

Is AI the future of cybersecurity, or its downfall? The answer, predictably, is “yes.”

“Anytime there’s a new technology, the bad guys almost always figure out how to weaponize it before the good guys can use it defensively,” Davis explains. “They only have to be successful once. We have to be successful every time.”

That’s the reality of security today. AI can help defenders detect and respond faster, but it also gives attackers new tools to deceive at scale.

Neither side has a monopoly on innovation.

From Zero Trust to Zero Buzzwords

Like AI, “Zero Trust” became another overhyped security buzzword, often stripped of its real meaning.

“At its core, Zero Trust is actually a great principle,” Ryan says. “Don’t trust anything; verify everything. But the marketing hype around it has created distrust in the concept itself.”

That skepticism is warranted. Everyone claims their solution is “AI-powered” or “Zero Trust-enabled.” But few actually live it.

“A lot of companies have been doing basic machine learning and just calling it AI,” Ryan says. “It doesn’t actually contribute to security, it dilutes it.”

Botton Line: Make It Continuous

If you take one thing from this Cybersecurity Awareness Month, let it be this: Security isn’t an event. It’s a mindset.

It’s not the once-a-year training video or the catchy awareness campaign. It’s the ongoing conversation—the Slack thread, the Teams chat, the quick debrief, the “hey, did anyone else see this?” moment.

Because the second you stop thinking about security, someone else is thinking about how to exploit that.

If you’re ready to make security more than an annual campaign, let’s have that conversation. 👉 Reach out to us today!