Skip to content
Navanta logo
  • 877-778-7774
  • Support
    • Our Story
    • Our People
    • Join Our Team
    • View All Solutions
    • Core Banking
    • Managed IT
      • Bankers Private Cloud
      • Bankers Essentials
      • Cyberthreats
      • M365 Management
    • CRM
    • Advisory
      • Risk Management
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
    • View All Resources
    • Articles
    • CEO Update
    • Client Spotlight
      • Core Banking
      • CRM
      • Cyberthreats
      • Exams & Audits
      • Information Security
      • Managed IT
    • IT Security Insights
    • Navanta in the News
    • Upcoming Events
    • Recorded Webinars
  • Brand FAQs
  • Contact Us
      • Our Story
      • Our People
      • Join Our Team
      • View All Solutions
      • Core Banking

        Keep community focus with a core that runs reliably.

      • Managed IT

        Simplify banking IT with one trusted partner.

      • CRM

        Know every customer. Grow every relationship

      • Advisory

        Navigate IT and risk with clarity and confidence.

      • Have something in mind?
        Bankers Private Cloud
      • Bankers Essentials
      • Cyberthreats
      • M365 Management
      • Risk Management
      • Virtual CIO
      • Virtual ISO
      • Security Awareness Training
      • View All Resources
      • Browse By Type
        Articles
      • CEO Update
      • Client Spotlight
      • IT Security Insights
      • Navanta in the News
      • Upcoming Events
      • Recorded Webinars
      • Browse by Topic
        Core Banking
      • CRM
      • Cyberthreats
      • Exams & Audits
      • Information Security
      • Managed IT
  • Brand FAQs
  • Contact Us
IT Security Insights

Cybersecurity Awareness Month: Small Habits, Stronger Protection

October 5, 2026

  • ARTIFICIAL INTELLIGENCE (AI)
  • CYBERTHREATS
  • INFORMATION SECURITY
  • RISK MANAGEMENT

Cybersecurity isn’t just IT’s job. The institutions with the strongest defenses treat this as a shared responsibility, from the teller line to the boardroom. The goal is for everyone to build a habit around good cyber hygiene, and you don’t need to be a security expert to do that.

Threats are moving faster

Many institutions are using AI to work smarter and faster, and so are attackers. CISA warns that AI is helping criminals find and exploit weaknesses more quickly than ever. Meanwhile, scammers are posing as banks by phone, text, email, and fake websites to steal passwords, MFA codes, and money. The FBI has logged more than 5,100 account-takeover complaints since January 2025, with losses topping $262 million.

Eight actions every employee can take

  1. Pause and verify. Be wary of anything unexpected or urgent. Attackers use urgency to rush you past your better judgment. Payment requests, account alerts, changed wiring instructions, and requests for sensitive information all deserve a second look. Before you act, confirm through a channel you already trust.
  2. Protect every account. Use long, unique passwords and an approved password manager. Never reuse passwords or share credentials.
  3. Don’t approve unexpected MFA prompts. Attackers will send prompt after prompt, hoping someone taps “approve” just to make them stop. Deny the prompt and report it.
  4. Think before you click or scan. Links, attachments, and QR codes can all hide something malicious. Confirm where it came from before you open, download, scan, or sign in.
  5. AI can make a scam convincing. Professional writing, a familiar name, a realistic voice, or a recognizable logo does not prove a request is legitimate. Follow your verification process every time, no matter how real it looks or who it seems to come from.
  6. Protect customer and institution information. Share sensitive information only with authorized people through approved channels. If something feels off, stop and verify first.
  7. Keep all devices and software current. Updates close the gaps attackers are looking for, so install approved ones promptly on all your devices, including phones and devices used at home.
  8. Report quickly and without hesitation. Report anything suspicious immediately, even if you already clicked, scanned, replied, downloaded, or shared information.

For institution leaders: back the habits with the right structure

Good individual habits only go so far on their own. They stick when leadership backs them with clear processes, tested controls, and focus. For 2026, CISA boils down organizational priorities to three things:

REDUCE

Prioritize known vulnerabilities, keep systems current, limit access by role, monitor activity, and strengthen controls around email, payments, remote access, and privileged accounts.

REPLACE

Identify unsupported hardware, software, and network devices, and build replacement decisions into planning and budgeting before aging technology becomes an avoidable risk.

RECOVER

Keep backups protected and out of attackers’ reach. Decide ahead of time who makes the calls and how you’ll communicate. Test incident-response and continuity plans.

A lesson beyond banking: the Hugging Face incident

What happened

In July 2026, Hugging Face, one of the largest platforms for sharing AI models and data, found an intruder inside its production systems. The attacker had uploaded what looked like an ordinary data file. Hidden inside was code that Hugging Face’s own systems ran automatically. When they processed it, the attacker gained a foothold. Over a single weekend, it worked its way to full system access, harvested cloud credentials, and moved into multiple internal clusters. The attacker turned out to be a swarm of autonomous AI agents running thousands of actions. Hugging Face says they reached some internal datasets and several service credentials, but found no evidence that public models, datasets, or published software were tampered with.

Why it got attention

No criminal group was behind it. OpenAI later said the agents were its own models, working through hacking challenges in an internal security test with some safeguards turned off. They were doing what they were told, just not the way the researchers expected. To get the job done, they broke out of the sandbox meant to contain them, got onto the internet, reached into parts of OpenAI’s own research systems, and even used an internal software tool as a makeshift message board to coordinate. OpenAI called it a “warning shot”: evidence that, without proper safeguards, highly capable AI agents are now able to work around technical controls.

The Navanta take

Everyone should care about this lesson. The biggest risks don’t always come from someone breaking through the firewall. Sometimes they start with a trusted system, vendor, or tool you rely on every day. Institutions should think beyond whether they are secure today and ask, “What happens if one of our trusted providers or AI-enabled tools behaves unexpectedly tomorrow?”

For community financial institutions, AI and new technology aren’t going away. The answer is to know where you use them, what they can reach, and who’s watching them. Limit their access, monitor for unusual activity, verify your vendors’ controls, and keep recovery and communication plans tested and ready.

Putting the lesson to work: AI and connected tools

Know what you’re running

Make a list of every AI tool, outside platform, plug-in, and automated agent in use, including the ones employees adopted on their own.

Map what each tool can reach

For every tool, know what data, credentials, systems, and outside services it can touch.

Give Tools Only The Access They Need

Apply least privilege to software the same way you do to people and keep risky processing away from production systems wherever you can.

Strengthen vendor reviews

Vendor reviews should now cover how they use AI, who can access their models, how they handle credentials, which subcontractors they rely on, and how fast they’ll tell you when something goes wrong.

Monitor connected platforms

Watch for unusual logins, credential use, data movement, or anything unexpected.

Prepare to contain an incident

When a provider reports a problem, you should be able to revoke tokens, rotate credentials, isolate the connection, and preserve logs quickly.

Test recovery and communications

Confirm that backups restore, recovery steps work, and backup communication channels are in place.

Exercise realistic failures

Add AI tool failures, a trusted platform going sideways, stolen credentials, and third-party outages to your tabletop exercises.

Questions leaders should be able to answer

  • What systems, services, AI tools, and third parties are most critical to serving customers?
  • Which unsupported or aging technologies create the greatest exposure?
  • How does the institution verify unusual payment, credential, and data requests?
  • Who makes decisions during an incident, and how will the institution communicate if normal channels are unavailable?
  • When did the institution last test recovery from protected backups and run a cyber exercise with business leaders?
  • How quickly can employees report something suspicious, and do they know exactly where to go?

Make October the start, not the finish

Repetition builds habits. The programs that work keep security in front of people all year with short reminders that fit their roles, realistic phishing, QRcode, and social-engineering tests, and reporting steps simple enough to remember under pressure. When someone slips, coach them right away.

Make reporting feel safe. The employee who says “I think I clicked something” within five minutes is doing exactly the right thing.

The takeaway

Cybersecurity helps keep the institution operating and supports its ability to serve customers and protect trust. Consistent habits, clear controls, and practiced recovery plans are what keep one bad email, one platform failure, or one missed update from turning into something bigger.

To learn about Navanta’s Security Awareness Training, visit:
navanta.com/find-a-solution/advisory-services/security-awareness-training

Resources

CISA Cybersecurity Awareness Month | FFIEC Cybersecurity Awareness | FDIC Cybersecurity Resources | FBI Business Email Compromise | Hugging Face incident disclosure | OpenAI incident summary | KnowBe4 QR code phishing guidance

Get a downloadable copy

Save or share this edition of IT Security Insights.

Download PDF

Join the Navanta Navigators Brief

Insights for community bankers navigating technology, security, and growth.

More in Artificial Intelligence (AI)

  • Stephen, Eric, and Patrick
    CEO UPDATE

    AI That Protects and Performs for Community Bankers 

    Read the Post
  • AI and Copilot in Banking Webinar Series hosted by Navanta
    RECORDED WEBINARS

    AI and Copilot in Banking: Making Strategic Decisions with Confidence – Two Part Webinar Series

    Watch the Recordings
  • Businesswoman hands covering glowing bank building icon, symbolizing financial institution protection, banking system stability, and regulatory compliance.
    RECORDED WEBINARS

    A Mid-year Look at the Regulatory Shifts Shaping Community Banking

    Watch the Recording
White Navanta logo
  • Linkedin
  • Get to Know Us
    • Our Story
    • Our People
    • Join Our Team
  • Find Your Solution
    • Core Banking
    • Managed IT
    • CRM
    • Advisory
  • Explore Resources
    • Articles
    • Client Spotlight
    • Events & Webinars
  • Contact Us
    • 877-778-7774
    • [email protected]

  • 877-778-7774
  • Support
  • Privacy Policy
© 2026 Navanta
Contact Us

Client Login

  • MyBPC

    Previously MyBankonIT. Log in here to access your client portal for Bankers Private Cloud.

    Sign In

  • theSafeTM

    Sign in here to access your account information and resources in theSafe as usual.

    Sign In

  • Navanta CRM

    Previously Quest Analytics IQCRM. Continue to use these existing CRM links:

    Product Updates Technical Requirements CRM Email Support