Network Security

SOCtoberfest Kickoff: The 7 Deadly Sins of Cybersecurity Meet CISA’s Core Steps

by Justin Carter

Part one of SonicWall’s SOCtoberfest series for Cybersecurity Awareness Month

Every October since 2004, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cybersecurity Alliance have used Cybersecurity Awareness Month to remind individuals, businesses and governments that staying safe online is a shared responsibility. This year, we’re celebrating our own way: welcome to SOCtoberfest, a month of content dedicated to the habits, gaps and quick wins that separate resilient organizations from breached ones.

We’re kicking things off with our newest research: the 2026 Cyber Protect Report: The 7 Deadly Sins of Cybersecurity. Unlike a typical threat report, we built a protect report based around a simple question: What keeps going wrong, over and over, in the breaches SonicWall investigates? The answer wasn’t exotic malware or nation-state tradecraft. It was seven predictable, preventable patterns.

That finding lines up almost perfectly with what CISA has been telling everyone for two decades: the basics matter more than the buzzwords. Below, we connect our seven sins to CISA’s Cybersecurity Awareness Month guidance, so you can see exactly where your organization’s habits need attention this October.

Why This Matters for Small and Mid-Sized Businesses

Small and mid-market businesses (SMBs) represent 99% of businesses in the United States and roughly 44% of Gross Domestic Product (GDP), yet they face the same threats as large enterprises with a fraction of the budget and staff. According to the Verizon 2025 Data Breach Investigations Report, ransomware appeared in 88% of breaches affecting small- to medium-sized businesses (SMBs), compared to just 39% of large enterprise breaches. Attackers are not overlooking small organizations. They target them because they are easier to breach and slower to detect intrusions.

The 7 Deadly Sins, At a Glance

Our 2026 Cyber Protect Report identifies seven recurring failures behind most of the breaches we investigate:

  1. Ignoring the Fundamentals — Weak or missing Multifactor Authentication (MFA), poor patch discipline and excessive admin privileges. Identity, cloud and credential compromise account for 85% of actionable security alerts.
  2. False Confidence — Believing “we’re too small to be a target,” overestimating readiness, and never stress-testing defenses. Attackers dwell inside environments for an average of 181 days, even though 80% of IT leaders believe they could contain a breach in under eight hours.
  3. Overexposed Access — Flat networks, “any/any” firewall rules, and implicit trust after login. Environments with any/any rules see attackers move laterally in as little as 12 minutes.
  4. Reactive Security Posture — Waiting for alerts instead of hunting for threats. Organizations face an average of 960 alerts a day, and 44% go uninvestigated.
  5. Cost-Driven Security Decisions — Choosing the cheapest option over the right one. A single SMB breach can exceed $4.91 million once you factor in downtime and recovery.
  6. Reliance on Legacy Access Models — VPNs that grant broad network access on a single credential check. 48% of breaches in our data trace back to compromised VPN credentials.
  7. Chasing Hype Over Execution — Buying the latest AI-powered tool while basic hygiene goes unmanaged. 90% of organizations currently lack the maturity to counter today’s AI-enabled threats.

Connecting the Sins to CISA’s Core Steps

CISA’s guidance for everyone, which includes avoiding and reporting phishing, using strong passwords, turning on multifactor authentication with a password manager and updating software, is not a coincidence. It directly counters Deadly Sin #1. Our data shows that 66% of SMBs globally have not implemented MFA, and 61% of exploits occur within 48 hours of a vulnerability’s public disclosure. Every one of CISA’s four core steps closes a door that our report shows attackers are actively walking through today.

CISA’s guidance for organizations maps just as cleanly to the remaining sins:

  • Using logging on your systems directly addresses Sin #4, Reactive Security Posture. Our investigations repeatedly found that signals were logged, however, nobody was reviewing them.
  • Back up data and encrypt data counter both Sin #2 (False Confidence) and Sin #6 (Legacy Access Models). Backups that have never been tested create the appearance of readiness without the substance.
  • An incident response plan, its use, and preparedness for system disruptions are the antidote to Sin #4 and Sin #5. Organizations with comprehensive incident response plans save an average of $1.23 million per breach.
  • If you experience a cyber incident, you should report it to CISA.

Resources for Your Organization

CISA also publishes guidance tailored to specific audiences, and it is worth bookmarking alongside our report:

What’s Next

A lack of technology does not cause the seven deadly sins. They stem from a lack of discipline, visibility and follow-through, and most are fixable without a major budget overhaul. Over the rest of SOCtoberfest, we will dig into each sin in more detail and pair it with concrete remediation steps your team can act on this month.

Read the full 2026 Cyber Protect Report for the complete data set, SOC and cyber-insurance perspectives, and a full remediation checklist for every sin. And follow along all October as we turn Cybersecurity Awareness Month into SOCtoberfest.

Share This Article

An Article By

Justin Carter

Social Media Manager

Justin Carter is the Social Media Manager at SonicWall, where he builds brand presence, drives digital engagement and translates complex cybersecurity topics into content that resonates with a broad audience. When he steps away from the screen, he’s usually weightlifting, following the latest developments in tech and space exploration and cheering on the Seattle Mariners—a pursuit that has taught him a great deal about patience and perseverance.

Related Articles

  • The SOC Van Pelt Report: You Know the Threat. You Know How It Operates. It Still Took You Down.
    Read More
  • While You Were Doomscrolling: Medusa Ransomware Hits 500+ Victims (And Your Spaghetti Sauce Might Be Listening to You)
    Read More