Introduction
Every October, organisations around the world mark Cybersecurity Awareness Month, a global reminder that security is not only a job for the IT department. Firewalls, antivirus tools and network monitoring matter, but most cyber incidents begin with something much simpler: a person clicking a link, sharing a password, plugging in an unknown USB drive, or approving a request they should have questioned.
For organisations that run operational technology (OT), such as power grids, water treatment plants, oil and gas facilities, manufacturing lines and building management systems, the stakes are even higher. In these environments, a cyber incident does not stop at lost data. It can stop production, damage equipment, disrupt essential services and put people’s safety at risk.
Below, we explain why awareness matters, how attackers target people, what to do when something goes wrong, and why everyone has a role in protecting IT and OT systems.
Why Cybersecurity Awareness Matters
Technology keeps getting better at blocking known threats, so attackers have adapted. Instead of breaking through the strongest wall, they look for the easiest door, and that door is very often a human decision made in a busy moment.
Year after year, major industry studies such as the Verizon Data Breach Investigations Report find that a large share of breaches involve a human element: stolen credentials, social engineering, simple mistakes or misuse of access. This does not mean people are the problem. It means people are the most important part of the solution.
Cybersecurity awareness turns employees from potential targets into an active line of defence. An aware workforce:
- Recognises threats early, before an attacker gains a foothold.
- Reports quickly, which shrinks the time an attacker has to move through the network.
- Follows secure habits by default, such as strong passwords, multi-factor authentication (MFA) and careful handling of removable media.
- Understands the business impact, so security feels like part of the job rather than an obstacle to it.
Awareness is also one of the most cost-effective investments an organisation can make. A single avoided incident can pay for years of training.
The Human Factor in Cybersecurity
Attackers study human behaviour as carefully as they study software vulnerabilities. They know that people want to be helpful, respond to authority, react to urgency, and trust familiar names and logos. Social engineering exploits exactly these instincts.
Common human-focused attack techniques:
- Pretexting: an attacker invents a believable story, such as a vendor needing remote access to “fix a fault” on a control system.
- Impersonation: messages or calls that appear to come from a senior manager, IT support or a trusted supplier.
- Baiting: infected USB drives left in car parks, reception areas or maintenance rooms, waiting for someone curious to plug them in.
- Credential harvesting: fake login pages designed to capture usernames and passwords, including for VPN and remote access portals.
- Tailgating: following an authorised person through a secure door into a plant, substation or data room.
Why OT environments face unique human risks
In industrial settings, the human factor looks different. Engineers and operators are focused on uptime and safety, often working in shifts under pressure. Laptops move between office and plant networks. Contractors and original equipment manufacturers (OEMs) regularly need access. Legacy systems may still use shared or default passwords because changing them is operationally difficult.
Each of these realities creates an opening. The good news is that a well-trained operator who asks “Should this laptop really be connected here?” or “Was this remote session scheduled?” can stop an attack that technology alone might miss.
Security is not about being suspicious of your colleagues. It is about verifying before you trust, especially when a request is urgent, unusual, or involves access, money or credentials.
Phishing: The Attack That Starts With You
Phishing remains one of the most common entry points for cyberattacks, including attacks on critical infrastructure. The 2015 attack on Ukraine’s power grid, which left hundreds of thousands of customers without electricity, began with spear-phishing emails that gave attackers a foothold in the utilities’ corporate networks. From there, they worked their way towards the systems that controlled the grid.
Modern phishing takes many forms:
- Spear-phishing: personalised messages that reference your role, projects or colleagues.
- Smishing and vishing: phishing by text message and by phone call.
- QR code phishing (quishing): codes that lead to malicious websites, often bypassing email filters.
- AI-assisted phishing: fluent, convincing messages and even voice or video impersonation that make old warning signs like poor grammar less reliable.
How to spot a phishing email
Most phishing messages still share a few tell-tale signs:
-
Urgency or pressure
"Act within one hour or your account will be suspended." Attackers want you to act before you think.
-
An unexpected request
Sharing credentials, approving a payment, changing bank details or enabling remote access when you were not expecting it.
-
A mismatched sender
The display name looks right, but the actual email address or domain is slightly different, such as an extra letter or a different ending.
-
Suspicious links
Hovering over the link reveals a web address that does not match the organization the message claims to come from.
-
Unusual attachments
Invoices, "updated shift schedules," or documents asking you to enable macros that you never requested.
What to do if you receive a suspicious message
- Stop. Do not click links, open attachments, scan QR codes or reply.
- Verify through a separate, trusted channel, such as calling the person on a known number.
- Report it using your organization's phishing report button or security contact.
- Delete it only after reporting, so the security team can analyze it.
Clicked by mistake? Report it immediately. Speed matters far more than embarrassment, and security teams would much rather hear from you in minutes than discover the problem weeks later.
Incident Reporting: When Something Goes Wrong
No awareness programme can stop every attack. That is why incident reporting is one of the most valuable security behaviours an organisation can build. The faster a potential incident is reported, the faster it can be contained, and the smaller the impact.
What should you report?
- Suspicious emails, messages or phone calls, even if you did not interact with them.
- Clicking a link or opening an attachment you are unsure about.
- Lost or stolen laptops, phones, access cards or USB drives.
- Unexpected pop-ups, slowdowns, or programs behaving strangely.
- In OT environments: unexplained setpoint changes, alarms you cannot account for, HMI screens acting on their own, unknown devices on the control network, or unscheduled remote sessions.
Building a no-blame reporting culture
People hesitate to report when they fear being blamed. A healthy security culture treats reporting as a positive act. Leaders should thank people who report, share (anonymised) lessons learned, and make the reporting process simple: one email address, one phone number, or one button.
If in doubt, report it out. A false alarm costs a few minutes. A missed incident can cost weeks of recovery.
From Awareness to Action
Awareness only makes a difference when it changes daily behavior. Here are practical habits every employee can adopt this Cybersecurity Awareness Month and beyond:
- Use strong, unique passphrases and a company-approved password manager.
- Turn on multi-factor authentication for email, VPN, remote access and cloud services. The 2021 Colonial Pipeline ransomware attack was reportedly traced to a single compromised VPN password on an account without MFA.
- Keep software and devices updated, and follow approved patching windows in OT environments.
- Never plug unknown USB drives or personal devices into control systems or engineering workstations. Use scanned, approved media only.
- Follow the principle of least privilege: only request and use the access you actually need.
What organizations should do
Individual habits need organizational support: role-based training, realistic phishing simulations, tabletop exercises that include OT scenarios, and leaders who model secure behavior. The NIST Cybersecurity Framework and the ISA/IEC 62443 series provide a strong foundation.
Cybersecurity Awareness in Critical Infrastructure
Critical infrastructure (electricity, water, energy, transport, healthcare) keeps society running, which makes it an attractive target for criminals and state-sponsored actors alike.
Why OT security is different from IT security
Many of the security principles are the same across IT and OT, but the priorities are very different, and awareness training should reflect that.
- Priorities: in IT, protecting the confidentiality of data usually comes first. In OT, the top priorities are the safety of people and the availability of physical processes.
- Impact: an IT incident typically means data loss, financial loss or reputational damage. An OT incident can mean power outages, contaminated water, damaged equipment, environmental harm or risk to human life.
- System lifespan: office IT is often replaced every three to five years, while industrial control systems commonly run for fifteen to thirty years.
- Patching: IT updates are frequent and often automated. OT patches must be planned around shutdowns, tested for safety, so human vigilance matters even more.
- People involved: OT security depends not only on IT staff but on operators, engineers, maintenance teams, contractors and OEMs, all of whom need awareness tailored to their roles.
As IT and OT networks become more connected for remote monitoring, analytics and efficiency, threats that begin in the office can reach the plant floor. The 2017 TRITON (also known as TRISIS) malware, which targeted safety instrumented systems at a petrochemical facility, showed that attackers are willing to go after the very systems designed to protect human life.
Awareness priorities for OT teams
- Secure remote access: all vendor and remote sessions should be approved, time-limited, monitored and protected with MFA.
- Removable media control: treat every USB drive and transient laptop as a potential threat until scanned.
- Know your normal: operators who understand normal process behaviour are often first to notice abnormal activity.
- Respect network segmentation: never bridge IT and OT networks with unauthorised connections, wireless hotspots or dual-homed devices.
- Physical security is cybersecurity: control rooms, cabinets and field sites must be protected from unauthorised access.
- Safety first in response: if you suspect a cyber incident affecting operations, follow your site’s incident and safety procedures and escalate immediately.
Conclusion: Everyone Has a Role in Cybersecurity
Cybersecurity is not a product you buy or a box you tick once a year. It is a shared responsibility that lives in everyday decisions: the email you pause to verify, the USB drive you refuse to plug in, the remote session you question, and the incident you report without hesitation.
From the boardroom to the control room, every person contributes to resilience. Technology provides the tools, but people provide the judgement.
This Cybersecurity Awareness Month, take one practical step: enable MFA on an account, complete your security training, review who has access to your systems, or simply talk with your team about how to report a suspicious event. Small actions, repeated by many people, create a strong security culture.
Stay alert. Verify. Report.
Together, we can make every connection safer, from the office inbox to the plant floor.
Ready to secure your OT systems?
Contact our cybersecurity specialists today to assess vulnerabilities, strengthen defenses, and protect your critical infrastructure from evolving cyber threats.