← Back to insights

The Cybersecurity Story Desk: Five stories brands could own in November 2026

Five timely cybersecurity campaign opportunities spanning regulation, human risk, AI-enabled attacks, Black Friday and supply-chain resilience.

Hardware security keys on a laptop

November’s strongest opportunities sit at the intersection of new regulation, board accountability, AI-enabled threats and the holiday shopping season.

Below are five media narratives we expect journalists to pursue, along with the evidence companies will need if they want to contribute something more valuable than generic commentary.

Story 01

The Cyber Resilience Act has moved from preparation to incident response

Why this story matters now

The EU Cyber Resilience Act’s incident-reporting requirements came into force on September 11, 2026.

Manufacturers of products with digital elements must now provide:

  • An initial warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident
  • A more complete notification within 72 hours
  • A subsequent final report within the applicable reporting period

Notifications are made through ENISA’s new Single Reporting Platform. At launch, the platform does not provide an API, meaning organizations can automate their internal workflows but must submit notifications through the platform interface.

November gives journalists the first meaningful opportunity to ask how implementation is working in practice.

The questions journalists are likely to ask

  • Are technology manufacturers actually prepared to meet the 24-hour deadline?
  • Who is responsible for deciding whether an incident is reportable?
  • Are security, legal and product teams working from the same process?
  • How are manufacturers handling vulnerabilities found in third-party components?
  • Will the reporting burden expose weaknesses in software supply-chain governance?
  • Are smaller manufacturers disproportionately affected?

The opportunity for cybersecurity companies

This is a strong moment for companies working in vulnerability management, product security, incident response, DevSecOps and software supply-chain security.

The weakest pitch would be a general explanation of the legislation.

The strongest pitch would provide evidence of operational readiness.

A campaign we would consider

Proposed headline:

Three in four technology manufacturers cannot determine whether a cyber incident is reportable within 24 hours

Survey 200 to 300 security, product and compliance leaders at companies selling digital products into the EU.

Ask:

  • Whether they have tested the reporting process
  • Who owns the decision
  • How quickly relevant teams can assemble the required information
  • Whether third-party component visibility is sufficient
  • Whether an incident-response simulation has been completed
  • Whether the board understands the new obligation

The resulting story would provide journalists with the first independent indication of whether the market is genuinely ready.

Best suited to: Product-security platforms, vulnerability-management companies, incident-response specialists and software supply-chain vendors.

Ideal activation window: Late October through the first half of November.

Could your company credibly own this story?

Get in touch and we can discuss how we can approach it.

Story 02

Cybersecurity Awareness Month is over. Did employee behavior actually change?

Why this story matters now

Organizations have just completed another October filled with phishing tests, training modules, posters and internal awareness campaigns.

On November 11, ENISA will hold its European Cybersecurity Awareness Raising Conference under the theme “From Awareness to Impact.”

That wording captures a growing challenge: companies can document participation in training, but many cannot demonstrate that awareness activity changed behavior or reduced risk.

The questions journalists are likely to ask

  • Does annual security training produce lasting behavioral change?
  • Are phishing simulations measuring learning or simply catching employees out?
  • Which employees remain most vulnerable after completing training?
  • Does awareness training address AI-generated voice, video and message impersonation?
  • Are boards measuring participation when they should be measuring resilience?
  • How quickly do employees report a suspicious interaction?

The opportunity for cybersecurity companies

This gives human-risk, identity, email-security and security-awareness businesses a chance to challenge a stale industry practice.

Avoid telling journalists that “employees are the weakest link.” That framing is overused and places responsibility on individuals without examining the systems around them.

A stronger position would be:

The security industry has spent years measuring whether employees completed training. It should be measuring whether the organization recognized and contained a realistic attack.

A campaign we would consider

Proposed headline:

Cybersecurity training completion is rising, but employees are getting slower to report sophisticated attacks

Analyze anonymized customer data or run a controlled study comparing:

  • Conventional phishing emails
  • AI-personalized emails
  • Voice-note impersonation
  • Fake collaboration invitations
  • Multi-channel attacks that move from email to messaging platforms

Measure reporting speed, escalation rates and the percentage of employees who engage with each approach.

Best suited to: Email-security companies, identity providers, human-risk platforms and managed security providers.

Ideal activation window: November 2 to November 13.

Could your company credibly own this story?

Get in touch and we can discuss how we can approach it.

Story 03

AI-enabled attacks are becoming ordinary, not exceptional

Why this story matters now

ENISA’s 2026 threat assessment says emerging AI models are expected to be used increasingly in malicious operations. The important story is no longer whether criminals use AI. It is how AI changes the economics and scale of familiar attacks.

AI can help attackers produce more convincing messages, research targets, imitate executives and adapt campaigns across languages. But inflated claims about fully autonomous cyberattacks will face growing skepticism from technical journalists.

The questions journalists are likely to ask

  • Where is AI materially improving attacker success?
  • Which AI-enabled threats are real, and which are vendor marketing?
  • Has the quality of phishing improved measurably?
  • Are voice and video impersonation changing business-payment fraud?
  • Can security teams identify AI-generated content reliably?
  • Is AI creating new attacks or making existing attacks cheaper?

The opportunity for cybersecurity companies

The company that brings credible evidence can cut through the hype.

That could include:

  • Changes in phishing grammar and personalization
  • The time required to prepare a targeted campaign
  • Translation quality across multiple languages
  • Differences between AI-generated and conventional attacks
  • Detection rates for synthetic voice or video
  • Real incident patterns observed by response teams

A campaign we would consider

Proposed headline:

AI has cut the time needed to prepare a targeted impersonation attack from hours to minutes

Run a controlled red-team experiment using a fixed amount of public information about a fictional or consenting executive.

Compare the time, quality and cost of producing:

  • A conventional spear-phishing message
  • An AI-assisted message
  • A translated version
  • A cloned voice message
  • A multi-stage attack sequence

The story should focus on the operational difference, not simply declare that AI makes attacks more dangerous.

Best suited to: Threat-intelligence providers, email-security companies, identity platforms, fraud-prevention vendors and red-team specialists.

Ideal activation window: Throughout November, with additional opportunities around the major cybersecurity conferences taking place during the month.

Could your company credibly own this story?

Get in touch and we can discuss how we can approach it.

Story 04

Black Friday will test whether retailers can distinguish customers from automated attackers

Why this story matters now

Black Friday falls on November 27, 2026, followed by Cyber Monday on November 30.

The FBI says non-payment and non-delivery scams generated more than $503 million in reported losses during 2025, while credit-card fraud accounted for another $282 million.

The seasonal story is normally framed as consumer advice. A more valuable business angle is how retailers and platforms distinguish legitimate high-volume shopping behavior from credential stuffing, automated account creation, payment fraud and malicious bots.

The questions journalists are likely to ask

  • Are AI-generated fake stores becoming harder for consumers to identify?
  • How quickly can criminals clone a legitimate retailer’s website and creative?
  • Are retailers prepared for simultaneous traffic growth and attack activity?
  • How much promotional abuse is driven by automated accounts?
  • Are security checks increasing checkout abandonment?
  • What happens when fraud systems wrongly reject legitimate seasonal purchases?

The opportunity for cybersecurity companies

Companies with access to fraud, bot, identity, payment or ecommerce data should begin collecting a clean pre-Black Friday baseline now.

The most valuable data will show change over time:

  • Automated traffic as a percentage of total traffic
  • Credential-stuffing attempts
  • Newly registered fraudulent domains
  • Account-takeover attempts
  • Promotion abuse
  • Payment rejection rates
  • Time required to remove fake storefronts

A campaign we would consider

Proposed headline:

One in every X Black Friday login attempts comes from an automated attacker

Publish a live or rapidly updated Black Friday threat index using aggregated customer data.

Break the findings down by:

  • Country
  • Retail category
  • Attack type
  • Device
  • Time of day
  • Change from an ordinary trading week

Prepare spokespeople and visuals in advance so findings can be released while journalists are actively covering the shopping period.

Best suited to: Ecommerce-security platforms, bot-management companies, payment and fraud providers, identity vendors and digital-risk protection companies.

Ideal activation window: Teaser findings from November 16, followed by live data from November 25 to December 1.

Could your company credibly own this story?

Get in touch and we can discuss how we can approach it.

Story 05

Ransomware resilience is becoming a supply-chain question

Why this story matters now

ENISA’s latest threat landscape continues to identify ransomware as the most consequential cyber threat in the short term. It also emphasizes the expanding attack surface created by digital dependencies.

The media conversation is therefore shifting from:

Can this organization stop a ransomware attack?

to:

Can this organization continue operating when a critical supplier is compromised?

This creates a stronger board-level and operational story than another prediction about ransomware volumes.

The questions journalists are likely to ask

  • Do organizations know which supplier failures would stop operations?
  • Are ransomware exercises testing third-party outages?
  • How quickly can a company replace a critical software provider?
  • Do contracts provide enough information and support during an incident?
  • Which dependencies are invisible to the board?
  • Does cyber insurance cover losses caused by a supplier’s outage?

The opportunity for cybersecurity companies

This topic suits vendors that can speak credibly about:

  • Third-party risk
  • Software supply chains
  • Business continuity
  • Backup and recovery
  • Incident response
  • Critical infrastructure
  • Board governance

A campaign we would consider

Proposed headline:

Most boards know their largest cyber risks, but not the suppliers most likely to stop the business

Survey CISOs, risk leaders and board members on whether they can identify:

  • Their five most operationally critical technology suppliers
  • The recovery time associated with each dependency
  • Contractual notification requirements
  • Alternative providers or manual processes
  • When the dependency was last tested in a simulation

The campaign could be supported by an anonymized map showing how one supplier incident spreads across sectors.

Best suited to: Third-party-risk platforms, resilience providers, backup companies, incident-response specialists and cybersecurity consultancies.

Ideal activation window: Mid to late November.

Could your company credibly own this story?

Get in touch and we can discuss how we can approach it.

Dates worth having on the radar

  • November 3-5: Barcelona Cybersecurity Congress
  • November 4-5: European Cybersecurity Skills Conference
  • November 9-11: UK National Information Security Conference
  • November 10-11: API Cybersecurity Conference for the oil and gas industry
  • November 11: ENISA Cybersecurity Awareness Raising Conference
  • November 17-18: CODE BLUE 2026
  • November 18: Government Security Virtual Summit
  • November 24-25: Jisc Security Conference
  • November 27: Black Friday
  • November 30: Cyber Monday

What we would prioritize

For most cybersecurity companies, we would not try to contribute to all five conversations.

The best choice depends on the evidence the company can credibly provide:

  • Customer or product data: Build a data-led media campaign.
  • Senior technical experts: Run a rapid-response commentary program.
  • Access to security leaders: Commission a focused market survey.
  • Incident-response experience: Create anonymized case-pattern analysis.
  • A product connected to new regulation: Lead with practical implementation evidence.
  • Limited original data: Develop a strong contrarian viewpoint supported by public evidence.

The objective is not to comment on cybersecurity news. It is to contribute the evidence that makes the news worth covering.

Your next campaign

Get your November story opportunity

We’ll identify the strongest timely campaign for your company, the evidence it needs and the publications likely to care.

Get in touch