Blog IDECSI

Cybersecurity Awareness Month: A CISO's M365 Action Plan

Written by Nathan Colombani | Sep 17, 2026, 6:30:00 AM

Every October, Cybersecurity Awareness Month gives security leaders a rare window of executive attention and budget flexibility. For a CISO, that window is worth more than another round of phishing simulations. Most awareness campaigns stop at training: e-learning modules, simulated phishing emails, posters on the breakroom wall. Without concrete correction of risky access on the Microsoft 365 tenant, the effect fades by November. This article lays out a CISO action plan that goes beyond training, turning Cybersecurity Awareness Month into measurable governance results.

Cybersecurity Awareness Month: an institutional lever most CISOs underuse

Cybersecurity Awareness Month has run every October in the United States since 2004, led by the Cybersecurity and Infrastructure Security Agency (CISA) in partnership with the National Cybersecurity Alliance. [adapté de FR] Each year, the campaign brings public and private organizations together around a shared awareness agenda, giving individual security initiatives a national platform to stand on.

For a CISO, this institutional backing translates into faster internal buy-in. A standalone access-remediation project competing against other roadmap items can stall for months. The same project, framed as part of Cybersecurity Awareness Month, benefits from executive attention that is already scheduled and already prioritized.

October is also when security teams get a natural audience for internal communication. Employee engagement with security messaging tends to run higher during Awareness Month than during a random week in March, which makes it fertile ground for launching a remediation campaign that requires broad employee participation.

Yet most CISOs stop short of using that attention for anything beyond communication. The budget and executive mindshare available in October rarely gets redirected toward an actual audit of the permissions and shares already sitting on the M365 tenant.

Cybersecurity Awareness Month gives CISOs a window of institutional legitimacy, but only a measurable remediation effort on the tenant turns that window into lasting results.

Why awareness training alone falls short

According to Verizon's 2026 Data Breach Investigations Report, the human element is involved in 62% of breaches, through error, manipulation, or misuse of access. That figure has stayed relatively stable year over year, which confirms that training alone does not structurally reduce risk.

Teaching employees to spot a phishing email does not fix an external share left open for two years, nor does it revoke access that should have been removed when an employee left the company. One risk is behavioral. The other is a governance gap. They call for different, complementary responses.

Training addresses the future: it lowers the odds that an employee makes a mistake tomorrow. It does nothing about the past: it fixes nothing that is already misconfigured, overshared, or forgotten on the tenant. An anonymous link that has been live for three years stays live no matter how good this year's training was.

An effective Cybersecurity Awareness Month program for a CISO combines both: standard security awareness training, which addresses future behavior, and a corrective audit of the tenant, which addresses data already exposed today. Without the second piece, the first stays incomplete and the tenant's actual risk indicators do not move year over year.

Training reduces future behavioral risk, but only a corrective audit of M365 access reduces the data exposure that already exists today.

The blind spots a standard awareness campaign misses

Most Cybersecurity Awareness Month campaigns overlook several risk categories tied directly to Microsoft 365 access governance. These blind spots map closely to categories in IDECSI's internal M365 risk-signal framework, particularly those covering sharing and access review.

Four blind spots come up most often in M365 tenants:

Anonymous sharing links left active on SharePoint or OneDrive, usually created for a one-off need and never disabled. This risk is covered in more depth in the external sharing best practices guide for Microsoft 365.

Accumulated oversharing on SharePoint libraries, where entire groups retain access to documents that no longer concern them, due to a lack of periodic review. This pattern and its fixes are detailed in the article on SharePoint oversharing.

Former employees' access that was never revoked after departure, due to the absence of an automated, systematic offboarding process between HR and IT.

Teams or SharePoint spaces with no identified owner, where nobody can say precisely who has access to what. Access governance on Microsoft Teams shows how these spaces multiply without a cleanup process.

These are not isolated incidents. They result from access rights accumulating gradually over time, rarely reviewed. Cybersecurity Awareness Month is a natural moment to launch that review, provided it moves beyond communication and into an operational action plan.

Active anonymous links, SharePoint oversharing, unrevoked access after departure, and ownerless spaces are the four most common blind spots of an awareness-only Cybersecurity Awareness Month campaign.

A 4-step CISO action plan for Cybersecurity Awareness Month

A structured action plan turns Cybersecurity Awareness Month into a measurable initiative without pulling IT resources away from other priorities. It relies on one principle: IT drives and oversees, users fix their own sharing.

 

Step

Content

Estimated duration

1. Tenant checkup

Full scan of M365 permissions and shares, risk identified per user

1 to 2 weeks

2. User-driven remediation

Users notified, given access to a dedicated interface to fix their own shares

2 to 3 weeks

3. Measuring the gains

Dashboard summarizing risks eliminated, by category and department

Ongoing

4. Sustaining the effort

A follow-up campaign scheduled 6 months out to lock in results

Outside October

 

This structure follows a DETOX-style format, typically running 4 to 6 weeks, which allows the checkup to start in early October and results to be measured before Cybersecurity Awareness Month ends.

Step 1 relies on an automated scan that identifies, per user, external shares, anonymous links, and legacy access. This initial map becomes the baseline for measuring progress at the end of the campaign, following the same logic as an access review across M365 collaboration tools.

Step 2 is what separates a standard awareness campaign from a results-driven one. Instead of centralizing remediation with the IT team, every user receives a notification listing their own risky shares and fixes what needs fixing in a few clicks. This avoids pulling significant IT resources while making each employee accountable for their own data.

Step 4 is the step most often skipped. A standalone October campaign produces a spike in remediation followed by gradual drift back toward risk if no follow-up campaign is scheduled. Building a durable security hygiene habit requires repeating the exercise, typically every six months.

An effective CISO action plan for Cybersecurity Awareness Month runs in 4 to 6 weeks, with users fixing their own access under IT oversight, without a heavy lift for technical teams.

A concrete example: what a structured campaign can deliver

According to IDECSI data, the Cergy-Pontoise metropolitan authority in France eliminated 50% of identified risks in its first DETOX campaign. In the second campaign, that rate climbed to 70%, illustrating the compounding effect of a repeated program rather than a one-time effort.

That result comes from the mechanics of the program itself: once equipped and made accountable, users each fix an average of several risky shares or access grants in the first campaign alone. Repeating the exercise, rather than running it once in October, compounds the gains over time and drives down the number of risky shares on the tenant.

A second example illustrates the same dynamic in a different industry: the Lactalis case study, in food and beverage manufacturing, shows how the same method for identifying and correcting non-compliant shares and access applies to an industrial environment, with a meaningful reduction in risk exposure.

For a CISO, this kind of result is a concrete metric to bring to the board or executive committee at the end of Cybersecurity Awareness Month, far more compelling than a training completion rate. A dashboard showing a precise number of risks eliminated, with a progression rate from one campaign to the next, turns Cybersecurity Awareness Month into a measurable initiative rather than a communications event.

According to IDECSI data, a first M365 access remediation campaign eliminates an average of 50% of identified risks, a rate that climbs to 70% in a second campaign.

Conclusion

Cybersecurity Awareness Month gives CISOs a valuable window of institutional attention, but that window only produces lasting results when paired with a corrective effort on M365 access and sharing. Awareness training alone leaves risk in place after October 31. A four-step action plan, from the initial checkup to sustaining the effort through a follow-up campaign, turns the month into results a CISO can bring to the board.

To convert this campaign into measurable results, Cybersecurity Awareness Month is the right moment to launch an M365 tenant audit before October ends.

FAQ

Q1: What is Cybersecurity Awareness Month and when does it happen? Cybersecurity Awareness Month runs every October in the United States, led by CISA in partnership with the National Cybersecurity Alliance since 2004. It is the US equivalent of the EU's European Cybersecurity Month, coordinated across member states by ENISA.

Q2: How should a CISO prepare an effective Cybersecurity Awareness Month program? A CISO benefits from pairing standard security awareness training with a corrective audit of M365 access. Launching the tenant checkup in early October allows measurable results to be ready before the month ends.

Q3: Awareness training or access remediation: which should a CISO prioritize in October? Both are complementary, but only access remediation reduces the data exposure that already exists. Verizon's 2026 DBIR shows the human element still involved in 62% of breaches, which does not remove the need to address accumulated technical risk.

Q4: How long does it take to fix risky permissions on an M365 tenant? A structured DETOX-style program typically runs 4 to 6 weeks, including the tenant checkup and the user-driven remediation phase.

Q5: Is Cybersecurity Awareness Month a good time to prepare for a Copilot rollout? Yes, because Copilot inherits existing tenant permissions. An access remediation campaign launched during Cybersecurity Awareness Month is a useful preparation step ahead of any Microsoft 365 Copilot deployment.