by June Kaminski, RN MSN PhD(c)
Editor in Chief
CJNI was initiated by June Kaminski in 2006 when she was President-Elect of CNIA. In 2012, June was honoured to receive the CASN and Canada Health Infoway’s inaugural Nursing Faculty E-Health Award 2012 in Ottawa Canada. She offers the Nursing Informatics Learning Centre with accredited CEU informatics courses.
Citation: Kaminski, J. (2026). Editorial. Cyber security awareness month in the age of AI. Canadian Journal of Nursing Informatics, 21(3). https://cjni.net/journal/?p=17349

October is devoted to keeping people safe online and is recognized as Cyber Security Awareness month internationally. As the use of artificial intelligence (AI) becomes more common, sophisticated AI generated or supported attacks are escalating. It is important for all digital users (both in their private and professional lives) to raise their awareness and learn how to use technology consciously and defensively. Along this line, the theme for Cybersecurity Month 2026 is Your best defence is You!
One ready resource that is tailored to support Canadians to build their defences is the Cyber Safe campaign. “Get Cyber Safe is a national public awareness campaign created to inform Canadians about cyber security and the simple steps they can take to protect themselves online. The campaign is led by the Communications Security Establishment Canada (CSE), with advice and guidance from its Canadian Centre for Cyber Security (Cyber Centre), on behalf of the Government of Canada” (Government of Canada, 2026, p. 1). The campaign is organized into four weekly themes:
During this first week, Canadians are encouraged to learn more about common cyber threats that can impact their online safety. These include the classic phishing, spam, and malware tactics often used by cybercriminals to prey on unsuspecting victims. Now, it also includes tips for becoming more aware of AI powered cyber threats that can target people with realistic AI written phishing, malware and ransomware scams, images, agentic AI attacks where bots act autonomously on stolen credentials, voice simulations and deepfake voice and video scams, and messages that can increase the risks considerably (Pearlstein, 2026a).
AI can also enable cybercriminals to apply social engineering tactics to breach personal and organizational accounts and data. “Social engineering is a type of targeted phishing attack where a cyber criminal does research on search engines and social media to learn more about you or your company. Then, they send you a message that looks like it’s from a colleague, a supplier, a familiar company or another trusted source. They trick you into sharing sensitive information, like passwords, credit card numbers or financial data” (Government of Canada, 2024, p. 1).
The second week of the campaign guides people to develop habits that help them to set up barriers to prevent access to their private and work accounts by using strong passwords that are updated regularly, using reliable password managers, and activating multi-factor authentication (MFA). At first, these practices might seem time-consuming and unnecessary, but studies have shown that MFA alone reduces the risk of cyber attacks on personal and work accounts by 99.2% (Meyer et al., 2023).
Another strategy that all small and large businesses and organizations should embrace are “Turn on SPF, DKIM, and DMARC. These 3 DNS records make it materially harder for criminals to send email as your domain, protecting both your clients and your invoices” (Pearlstein, 2026b, p. 1).
During the third week, the campaign goes deeper to provide guidance on how to keep your personal information safe as you shop, bank, and access online services through the web or mobile apps. This can be extended into healthcare to expand the protection of personal health information when using online health services, labs, pharmacies, and so on. One great way to explore ways to improve your protection is to engage with Dell’s Interactive Cybersecurity Scenarios eBook to problem-solve cyberattack scenarios for real-time decision making in an interactive way. “Explore a wide range of attack types and industry-specific challenges across sectors like federal, state, and local government, financial services, and healthcare” (Dell Technologies, n.d., p. 2).
The final week encourages you to share what you have learned with others, whether your children, family members, elderly parents, friends, work colleagues, or patients (Government of Canada, 2026). At an organizational level, the Canadian Centre for Cyber Security offers expert advice, reports, latest alerts, and support for all levels of users from individuals, small businesses, large organizations, government and democratic institutions, and academic organizations. One example of an accessible resource is the centre’s Cross-Sector Cyber Security Readiness Goals Toolkit (Canadian Centre for Cyber Security, 2024), presented as a fillable pdf manual that can be used to guide cybersecurity development within organizations. At a national level, the centre’s report, National Cyber Threat Assessment 2025-2026 (Canadian Centre for Cyber Security, 2026a), offers a deep dive into the global cyber security threats that Canada is dealing with currently.
One way that these national threats are being dealt with is using AI to detect cybercriminal activity. “The Communications Security Establishment Canada is examining how artificial intelligence (AI) can support cyber defence and help cyber security practitioners detect, understand and respond to cyber threats. This work is being led through the Canadian Centre for Cyber Security (Cyber Centre) Frontier AI Lab, which evaluates emerging AI capabilities and their potential applications in cyber security. The Lab brings together expertise from government, academia, and industry to better understand how these technologies can be used effectively, securely, and responsibly” (Canadian Centre for Cyber Security, 2026b, p. 1).
Another way that the “Cyber Centre contributes to improving the cyber security ecosystem is by releasing some of its cyber defence tools to the open-source community” (Canadian Centre for Cyber Security, 2025, p. 1). Some examples are Assemblyline, a malware detection and analysis tool; Howler, a triage platform designed to assist teams in streamlining their workflow and enhancing their ability to handle alerts, and the National Cyber Threat Notification System, Canada’s early warning service for cyber security.
A noteworthy example of an expert community initiative that can help protect all users from AI and LLM related risks is the annual report from OWASP. The “OWASP Top 10 for LLM Applications 2026 is the latest community-driven guide to the most critical security risks facing applications powered by large language models. Developed by hundreds of AI security experts, this edition introduces updated rankings, expanded threat coverage, and new research grounded in thousands of real-world AI security incidents” (OWASP Foundation, 2026, p. 1). The top risks for 2026 are summarized in Figure 1. The Top 10 guide is an invaluable resource for all experts working with AI and LLM models within organizations of all sizes, but especially in complex healthcare organizations.
Figure 1
OWASP Top 10 GenAI/LLM Risks 2026

Following these four weeks of activities during the month of October can help every user protect themselves better when using cyber tools for work, play, entertainment, shopping, and so on. We all can become champions for cyber security awareness! Remember, Your best defence is You!
Canadian Centre for Cyber Security. (2026a). National cyber threat assessment 2025-2026. https://www.cyber.gc.ca/sites/default/files/national-cyber-threat-assessment-2025-2026-e.pdf
Canadian Centre for Cyber Security. (2026b). How the Canadian Centre for Cyber Security used frontier AI to accelerate detection engineering. https://www.cyber.gc.ca/en/guidance/canadian-centre-cyber-security-used-frontier-ai-accelerate-detection-engineering
Canadian Centre for Cyber Security. (2025). Tools and services. https://www.cyber.gc.ca/en/tools-services
Canadian Centre for Cyber Security. (2024). Cross-sector cyber security readiness goals toolkit. https://www.cyber.gc.ca/sites/default/files/cyber-readiness-goals-toolkit-e.pdf
Dell Technologies. (n.d.). Interactive cybersecurity scenarios eBook. https://www.delltechnologies.com/assetlink/doc/en-ca/interactive-cyber-scenarios-ebook-en-dl1knab-original.pdf
Government of Canada. (2026). October is Cyber Security Awareness Month in Canada. https://www.getcybersafe.gc.ca/en
Government of Canada. (2024). Get cyber safe guide for small businesses. https://www.getcybersafe.gc.ca/en/resources/get-cyber-safe-guide-small-businesses
Government of Canada. (n.d.). Canadian Centre for Cyber Security. https://www.cyber.gc.ca/en
Meyer, L. A., Romero, S., Bertoli, G., Burt, T., Weinert, A., & Ferres, J. L. (2023). How effective is multifactor authentication at deterring cyberattacks? Microsoft White Paper. https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/MFA-Microsoft-Research-Paper-update.pdf
OWASP Foundation. (2026). OWASP GenAI LLM Top 10 2026. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/
Pearlstein, M. (2026a). AI-Powered cyber threats: What Toronto businesses need to prepare for in 2026. Fusion Computing. https://fusioncomputing.ca/ai-powered-cyber-threats-2026/
Pearlstein, M. (2026b). Top 18 cybersecurity tips for Canadian small businesses, ranked by impact (2026). Fusion Computing. https://fusioncomputing.ca/cybersecurity-tips-small-business-canada/