Resources
August 20, 2026 · Last updated on August 24, 2026

Free Cybersecurity Month toolkits, for when you can't build it all

Free Cybersecurity Month toolkits, for when you can't build it all
# Cybersecurity Awareness Month

Tailored content will always beat off-the-shelf. But these toolkits are genuinely helpful!

Maxime Cartier
Maxime Cartier
Free Cybersecurity Month toolkits, for when you can't build it all
I've organized ten Cybersecurity Awareness Months. Seven on the practitioner side, three now on the vendor side.
But every single year, October always came way too fast!
Pick a theme. Get it approved. Create the content. Ideally test it with a few employees before you commit. Translate it into the languages your colleagues actually work in. Then build the comms plan to broadcast it, department by department, country by country.
That's weeks of work, sometimes months.
And most security awareness practitioners are doing this with a small team. Or no team at all.
So here's the good news: you don't have to build all of it yourself. A few organizations put serious effort into free, ready-to-use October toolkits every year. Here's where I'd look.



Hoxhunt: "Cybersecurity is a team sport" 🏀

This is the toolkit my colleagues have built. I'm including it because I think it's genuinely good, and you can judge for yourself (it's free of course!).
This year's theme is cybersecurity as a team sport. Hoxhunt partnered with Caitlin Sarian ( Cybersecurity Girl)  and built the whole thing on threat intelligence, so the scenarios reflect what's plausibly hitting your organisation this year.
There's messaging, infographics, mini-games, and Ant Davis is also back for a third year of videos, and they're well worth a look!
  • Judgement Call: Ant compares racing to your inbox. Split-second decisions, just without the helmet.
  • Callback Phishing: a real callback scam walked through from start to finish.
  • Imposter: Ant hands over his own face and voice to show what an AI deepfake scam actually looks like.
New this year: two interactive mini-games. The spot-the-deepfake one is genuinely hard, which is the point, it lands the message that you often can't tell. And the inbox panic game is stressful in the best way. It shows how many instant, low-attention decisions we all make in our mailbox every single day.



The National Cybersecurity Alliance: "Don't make it easy for them"

The NCA toolkit takes a storytelling approach this year. It tells the tale of four real criminals and criminal organisations, alongside the actions you can take to avoid becoming their next victim. Real cases, real victims, everyday situations people recognize from their own lives.
What I admire most about the NCA, though, is their consistency. Year after year, they promote the same five core behaviours. No reinvention for the sake of novelty. Just repetition, which is exactly what behaviour change needs.

One caveat: the social media graphics and posters are great, but you'll likely still need to create the explanatory material that goes with them.



Don't forget your own country

Many countries run their own national cyber month campaign, with posters, videos and messaging already translated into the local language and adapted to the local threat landscape and regulatory context.
Whether you operate in the Netherlands, Canada, France, Australia or Germany go and look. Not only the content might be more culturally appropriate, it also gives your campaign a credible external anchor: "this is what our national cybersecurity agency is telling citizens this month" could land better than "this is what the security team wants you to do".



Bonus: videos worth borrowing

Not toolkits, but great content that other people made and published openly. Perfect to share of the internal social networks (like your Yammer or Teams channel), or include at the beginning or the end of a webinar.
  •  It Wasn't Me — #SecureYourAccount : my all-time favourite. But it sent me a reminder? Messaged me on WhatsApp? He even called in the shower! 🎶 Corporate communications tend to blend into each other. This one doesn't, and people still quote it back to me years later.
  •  Jessica Clark social-engineers a phone company : an oldie but a goodie, and still one of the clearest vishing demonstrations I know. Journalist Kevin Roose asked hackers at DEF CON to break into his life. Jessica Clark called his mobile provider posing as his wife, with a crying baby playing in the background. Show it to anyone who still thinks social engineering is only about email.



The caveat: off-the-shelf is rarely on-brand

Most of the resources in these toolkits are not customizable. You get a poster. You get an infographic. It looks good, but it might not feel like your organization, and it's hard to make it yours. Your colleagues will probably notice that it doesn't look like anything else in your internal channels, and it won't reference the tools, processes or reporting button that they actually use.
So my advice: don't just forward the file. Wrap it.

Check the licence (the two toolkits above are free to use and modify as you want), then re-use, remix, adapt. Put your own message next to the video. Add your logo to the infographic. Record a 30-second intro from your CISO (or, let's be ambitious, from the CEO) before the borrowed clip. Translate the poster copy into your internal tone of voice.
And the goal is not to produce the absolute most beautiful content. It's to change behaviour. In short-for-time teams, borrowed content that's been adapted to your reality beats original content that took half your year to create. Think also about the content that goes viral on TikTok: it's rarely the most polished!



Your turn

This list is what I know, but I'm sure I missed some.
If you've found a toolkit, a video, a game, a national campaign or a template that worked well for your October, drop it in the comments or share it in the Hub. That's what this community is for! Who knows, maybe someone out there is currently staring at a blank slide deck, three weeks from launch, hoping to find precisely what you have?
So what are you using this year?
Comments (0)
Popular
avatar

Dive in

Related

Content
Phish of the Week 24th of August
By Mette Luntama • Aug 24th, 2026 Views 5
Content
Phish of the Week 10th of August
By Mette Luntama • Aug 10th, 2026 Views 13
Content
Phish of the Week 17th of August
By Mette Luntama • Aug 17th, 2026 Views 16
Content
Callback Phishing
By Laura Lehtiö • Aug 17th, 2026 Views 91
Content
Phish of the Week 24th of August
By Mette Luntama • Aug 24th, 2026 Views 5
Content
Phish of the Week 17th of August
By Mette Luntama • Aug 17th, 2026 Views 16
Content
Callback Phishing
By Laura Lehtiö • Aug 17th, 2026 Views 91
Content
Phish of the Week 10th of August
By Mette Luntama • Aug 10th, 2026 Views 13