

Cybersecurity Awareness Month
- Home
- Academics
- Centers and Institutes
- Cyber Security Center of Academic Excellence
- Cybersecurity Awareness Month
October is Cybersecurity Awareness Month
Small, consistent online-safety habits can make a real difference. This October, the Center of Cybersecurity is sharing four practical ways to help protect your accounts, devices, and personal information—no technical background required.
St. John’s University is proud to support this national initiative alongside the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance (NCA)
Four ways to protect yourself.
Start with one habit today. Small, consistent choices add up.
Use Strong, Unique Passwords
Give every account its ownlong, hard-to-guess password.
Enable MFA Everywhere
Add a second layer of protection to your important accounts.
Keep Software Updated
Updates patch security weaknesses before criminals exploit them.
Scrutinize Every Message
Pause before you click, reply, or share information.
Week 1

Use Strong, Unique Passwords
Every online account deserves its own password. If one password is reused and compromised, it can put other accounts at risk. A password manager can create and securely store unique passwords so you do not have to memorize them all.
What to do
• Aim for 13 or more characters; longer is better.
• Use a random passphrase or a mix of letters, numbers, and symbols.
• Never reuse a password across accounts.
• Do not share your password with anyone.
• Consider a password manager to generate and store passwords securely.
Quick fact: 41% of respondents said they never use a password manager.
How to Create Strong Passwords (and Remember Them!)What is a password manager?Week 2

Enable MFA Everywhere
Multi-factor authentication (MFA) adds a second check to your sign-in. Even if someone gets your password, they still need that additional verification to access your account.
What to do
• Enable MFA on email, financial, social, shopping, and other important accounts.
• Use the University’s approved MFA methods for supported St. John’s systems.
• Never share an MFA code or approve a request you did not initiate.
• Where available, add a backup authentication method in case your primary method is unavailable.
Quick fact: MFA awareness reached 77% in 2025, but regular use was only 53%.
Turn on MFAMFA Best PracticesWeek 3

Keep Software Updated
Software updates often include fixes for security weaknesses that criminals can exploit. Keeping your operating system, browser, apps, and security tools current is one of the simplest protections you can put in place.
What to do
• Turn on automatic updates whenever possible.
• Install updates promptly instead of repeatedly postponing them.
• Keep your operating system, browser, applications, and security software current.
• Download software and updates only from official vendor websites or trusted app stores.
Quick fact: The share of people who said they always install updates fell from 44% in 2021 to 31% in 2025.
CISA Secure Our WorldCybersecurity Awareness Month ResourcesWeek 4

Scrutinize Every Message
Phishing attempts can arrive by email, text, social media, or messaging apps. They often impersonate trusted people or organizations and use urgency to get you to click, open, or share information before you think twice.
What to do
• Be cautious with unexpected messages and requests for account, financial, or personal information.
• Check the sender and inspect links before clicking.
• Do not open unexpected attachments or suspicious links.
• Verify a questionable request using contact information you already know—not the details in the message.
• Report suspected phishing through the University’s approved process or contact IT for help.
Quick fact: Phishing accounted for 40% of reported cyber incidents in 2025.
CISA Phishing Tip SheetCybersecurity Awareness Month Resources