Let Your People Know – It’s ok to go slow
With limited time, resources, and a list of things to worry about, small businesses are on the menu for today’s criminal looking for an easy mark. Attackers know that owners are busy, stretched thin, and often operating without the same security structure larger companies take for granted.
Is it possible for a small business to stay safe without breaking the budget?
Along with using modern equipment (machines withen five or six years old, on Windows 11 or up-to-date MacOS) and maintaining business grade licensing, most security analysts would agree that User Education is of critical importance, delivers biggest bang for the buck, and is easily the one where most business fail.
After all, users are proven to be the one most exploited! Our people are a major weakness, and for the purposes of this blog we’re going to focus on that, adjust for it, and make it a strength.
In cybersecurity, one of the best ways to become “faster” is to slow down. Cybercriminals bet on our speed. They create urgency and apply pressure. It’s why the most important things a business owner can do is give their permission to slow down.
Permission to pause when something involves money, passwords, client information, payroll, banking, access to business systems, or when something just doesn’t seem right. And that permission shouldn’t just be implied. It should be in the handbook, stated during onboarding, repeated in weekly meetings, and effectively made part business operations.
It should be ingrained into the culture: “When money, passwords, banking information, client data, payroll, or access to our systems is involved, slow down, verify, and ask if your uncertain.”
That one sentence can change the culture. It tells people that asking questions is not a problem. It tells them that confirming a request is not an inconvenience. It tells them that security is part of the job, not something separate from the job.
If we recognize that “we the people” are often the biggest risk, we can address that risk. We can talk about it. We can train around it. We can build better habits. And over time, we can turn the culture of the organization into one of its greatest strengths.
Being secure online is a choice. It’s not always complicated, but it does require attention. You can protect your data, avoid common cyberattacks, and operate in a more secure environment by getting the basics right and treat cybersecurity as a people issue, not just a technical one.
Yes, tools matter. Security software matters. Multi-factor authentication matters. Proper Microsoft 365 licensing matters. Updated computers matter. But none of that replaces a team that knows how to slow down, think twice, and ask the right question before clicking, sending, approving, or sharing.
So here are 5 things we suggest
1. Your attitude and work habits send a message
If the always rushing, always demanding immediate action, and always making people feel like speed matters and accuracy is expected, employees will move fast and mistakes will be made.
That's not to say you need to change your workstyle. We're not business coaches. But the message needs to be clear: “When something involves money, client information, passwords, banking, payroll, or access to our systems, I want you to slow down. Slow down and verify.”
That should be repeated often. Put it in your employee handbook. Say it during onboarding. Bring it up during staff meetings. Remind people before busy seasons, tax deadlines, billing cycles, payroll runs, travel periods, or any time the business is moving fast. Send them educational information like our blog on how passwords are compromised so they understand the issue is real.
Criminals are no longer attacking your technology. They’re attacking your process and your people.
2. Verify before sending money or information
This is one of the simplest and most important habits a small business can build. We wrote about it in our blog on how security should follow you just like work does. Before sending money, changing banking information, sharing client data, approving a wire, or responding to an unusual request, verify it through another channel.
Not by replying to the same email. By picking up the phone, sending a new text, or even calling the number you already have on file.
-
If a vendor emails new payment instructions, verify.
-
If a client asks you to send sensitive documents to a new email address, verify.
-
If someone inside the company asks for gift cards, banking changes, payroll updates, passwords, or urgent payments, verify.
3. Talk about the risks with your team
Most people don’t make security mistakes because they’re reckless. They make mistakes because they don’t know what to look for.
So talk about it. Talk about fake Microsoft login pages. Talk about invoice scams. Talk about wire fraud. Talk about text messages that look like they came from the owner. Talk about emails that create urgency, fear, or pressure.
Make cybersecurity part of normal business conversation. You don’t need to scare people. You need to make them aware.
4. Be skeptical of urgency
Cybercriminals love pressure. They want your people moving fast. They want them nervous. They want them worried about missing a deadline, upsetting the boss, losing a deal, or creating a problem.
That’s why so many scams sound urgent:
“Please handle this right away.”
“I need this before the end of the day.”
“Your password is expiring.”
The more urgent something feels, the more important it is to slow down. Healthy skepticism is not paranoia. It’s good business.
Teach your team that it’s okay to pause. It’s okay to ask questions. It’s okay to confirm. It’s okay to say, “This doesn’t feel right.” That one sentence can save your business a lot of pain.
That’s a fair question for your IT provider. And if you don’t have an IT provider, it’s a fair reason to get a review.
5. Make security part of the culture
The goal is not perfection. The goal is awareness.
A secure culture is one where people pay attention. They verify before acting. They use strong passwords. They report suspicious emails. They don’t hide mistakes. They know that protecting the business is part of everyone’s job.
That doesn't require a cybersecurity degree. It requires leadership. A small business owner can set the tone by saying: “We take this seriously”, or “If something feels wrong, say something.”
That’s training. That’s culture. That matters.
It's about being constant and consistent
Of course, this list is not comprehensive. There are many other ways to increase your speed, reduce your risk, and make your business a harder target.
Security tools and software are important, and in many cases, highly recommended. But the most basic and powerful place to start is with your people.
Talk to them constantly and consistently and let the know that they have permission to slow down.
Know your risk. Protect what you've built. We find employees learn best when they’re told by someone other than you. If we can help in that regard, complete the form below and let’s setup a quick training.
Reach out if we can help.
