September has always felt like the “Monday” of the calendar year. Summer vacations are winding down, kids are back in school, football is back, and everyone suddenly realizes that the goals we confidently said we would accomplish “after Labor Day” are now staring us directly in the face. September is also National Preparedness Month—a timely reminder that effective security and resilience are not about predicting exactly what will happen; they are about being prepared to respond when something does. This is especially true as on September 11, 2026, we remember 25 years since the horrific attacks against our great nation that forever changed the way we approach security and preparedness. From the TSA to DHS, the Patriot Act, ODNI, and NCTC to name a few, we continue to remain proactive and ready. One of many takeaways is that as organizations settle into the fall routine, now is the time to review emergency plans, confirm contact lists, test notification systems, revisit business continuity procedures, and make sure employees know their roles before an incident occurs. A plan sitting in a binder—or worse, in someone’s inbox—is not really a plan until people understand it and can execute it. Like I always say, if you stay ready, you don’t have to get ready!
The return to school and normal fall business activity also brings a familiar mix of physical and cybersecurity concerns. Increased activity on campuses, more visitors, new employees and students, expanded events, and heavier use of technology create additional opportunities for security gaps to surface. On the cyber side, phishing, credential theft, ransomware, and increasingly convincing AI-assisted social engineering continue to challenge organizations. CISA continues to emphasize phishing awareness, strong authentication, timely software updates, and multifactor authentication as foundational protections. This month, consider conducting a quick “security reset”: review who has access to critical systems and facilities, remove unnecessary access, verify that MFA is enabled—preferably phishing-resistant MFA—test backups, and remind employees that an urgent email asking them to “just click this one link” is rarely as urgent as it claims to be. When in doubt, verify before you click.
Finally, September gives us plenty of reasons to pause and appreciate the season. It is the ninth month of the year, yet its name comes from septem, the Latin word for seven—a reminder that calendars, like security plans, sometimes have more history than logic. September also marks the beginning of meteorological fall, bringing cooler temperatures, changing weather, and the annual ritual of pretending we are excited about pumpkin spice everything. More importantly, it is a good time for leaders to look ahead: What risks have changed since the beginning of the year? What recommendations from the last assessment or exercise remain unfinished? And, perhaps most importantly, are we prepared to execute when the unexpected happens? The best security programs are not built around fear; they are built around preparation, accountability, and continuous improvement. As we head into the final months of the year, let’s make preparedness something we practice—not something we hope we never need.
Stay Safe!
Daniel R Pascale, CPP
Chief Executive Officer