Cyber security incidents are becoming increasingly frequent, sophisticated and disruptive. In recent years, there has been a significant increase in the number of ransomware attacks, data breaches, phishing scams and other forms of cybercrime.
Human error remains a significant contributor to cyber security incidents and data breaches in Australia. Often, these errors arise from simple workplace mistakes rather than sophisticated external attacks. A rushed click, an overlooked warning sign or information shared in haste without appropriate verification can have serious consequences.
Cyber security is not just an IT issue. Every person has influence over an organisation’s cyber security through the choices they make online every day. Cyber security is everyone’s responsibility.
What is Cyber Security Action Month?
Cyber Security Action Month (CSAM) is an annual initiative led by the National Office of Cyber Security held each October. CSAM aims to educate individuals and businesses on how to stay safe online, improve cyber resilience and strengthen cyber response capabilities. CSAM provides a timely opportunity for organisations to reinforce the importance of cyber-safe behaviour. It is also a reminder that improving cyber security does not need to be complex or time-consuming.
The 2026 theme for CSAM is ‘Take a second. Stay secure.’
Why taking a second matters
Cyber criminals often rely on speed, distraction and pressure. The message behind this year’s theme is simple: pause, check and act carefully. It encourages Australians to take a moment before clicking a link, sharing information, creating a password or responding to an unexpected request.
That brief pause before acting can help people make safer choices and in turn, reduce the risk of scams, phishing attempts and avoidable data breaches from occurring.
The theme is not only about individual awareness and vigilance. It is also about governance and workplace culture. Building an environment where people feel confident to slow down, question unusual requests and report concerns early is equally important.
Practical steps to strengthen cyber resilience
Actioning the following simple and practical steps can make a meaningful difference:
Protect your accounts and devices
- Use strong and unique passphrases to help protect your account security.
- Enable multi-factor authentication to add an extra layer of security.
- Apply software updates promptly to protect against known security risks.
- Review privacy settings across your accounts, devices and platforms.
Stay alert online
- Be alert to suspicious emails or messages, particularly those creating urgency or requesting sensitive information.
- Think before sharing information online.
- Regularly review access permissions to sensitive information and consider whether they remain appropriate.
Prepare for the unexpected
- Back up data regularly to help minimise disruption if an incident occurs.
- Train staff regularly to recognise scams and respond appropriately.
- Test incident response arrangements regularly.
- Review and update your data breach response plan so your organisation can contain, assess and respond to a data and/or security breach quickly, helping to mitigate potential harm.
The disruption caused by a cyber security incident can be significant. It may involve operational downtime, financial loss, compliance challenges and reputational damage. A strong organisation-wide culture of vigilance and awareness can encourage people to stop, question and report anything that appears suspicious.
Taking a second to pause before clicking, sharing or responding to a request can help prevent an avoidable mistake from becoming a serious security incident. By creating a culture where people feel confident to stop, check and report concerns, your business can reduce the likelihood and impact of human-related cyber incidents.
This article was written by Special Counsel Hayley Bowman. Please contact Hayley if you have any questions or would like more information.
Disclaimer: This information is current as of September 2026. This article does not constitute legal advice and does not give rise to any solicitor/client relationship between Meridian Lawyers and the reader. Professional legal advice should be sought before acting or relying upon the content of this article.

Meet our Team
View our Insights