Cybersecurity for Small Business: Would Your Employees Spot a Scam?

Cybersecurity for Small Business: Would Your Employees Spot a Scam?

Imagine one of your employees receives an email that appears to come from you. You need a payment made to a vendor, and you need it done right away. The message looks legitimate, the request does not seem completely out of the ordinary, and the employee wants to be responsive.

Would your employee stop and verify the request before sending the money?

That is the kind of question small business owners need to be asking. Cybercriminals do not always need to break through sophisticated computer defenses. Sometimes, they simply need to convince one person that an email, text message, phone call, or request is legitimate.

October is Cybersecurity Awareness Month, but cybersecurity for small business is something owners need to think about throughout the year. While technology is obviously an important part of protecting a company, I believe there is another part that deserves just as much attention: the people using that technology every day.

Your employees can play an important role in protecting your business, but we cannot expect them to recognize every threat on their own. As business owners and managers, we need to give them clear procedures, reasonable safeguards, and the confidence to stop and ask questions when something does not seem right.

Cybercriminals Do Not Always Attack the Technology

When people picture a cyberattack, they may imagine a skilled hacker breaking through a company’s computer defenses. That certainly can happen, but criminals also use a much simpler approach: they try to convince a person to give them access.

An employee might receive an email that appears to come from you, a coworker, a customer, a bank, or a familiar vendor. The message might ask the employee to click a link, open an attachment, provide login information, change payment instructions, or take some other seemingly legitimate action.

The Federal Trade Commission (FTC) warns small businesses about phishing and other scams designed to trick employees into revealing passwords, financial information, or other sensitive data. Criminals can also impersonate company executives or vendors and try to persuade employees to send money or disclose information.

This is one reason I do not like the common phrase that employees are a company’s “weakest link.” An employee cannot reasonably be expected to recognize every threat without guidance. If we want employees to help protect the business, management has to establish expectations and procedures first.

Cybersecurity Starts with Clear Procedures

One of the principles I have discussed throughout my years working with businesses is that employees generally perform better when they understand what is expected of them.

Cybersecurity should be no different.

I know of a company where an HR manager received an email that appeared to come from an employee. The employee had supposedly changed banks and wanted future paychecks deposited into a new account. The HR manager made the requested change without independently verifying it with the employee.

The email was not from the employee.

The problem was not discovered until payday, when the employee reported that his paycheck had not been deposited into his bank account. An investigation determined that the original email was a phishing scam and the direct deposit information had been changed to an account controlled by the scammer.

There is an important management lesson in this example. Telling employees to “watch out for phishing emails” is not enough. A clear company procedure could require that any request to change direct deposit information be independently verified with the employee before the change is made.

The same principle can apply to requests to change a vendor’s payment information, provide confidential records, reset passwords, or disclose customer information.

Employees should not have to decide on their own whether an email “looks real.” For requests involving money, account access, or sensitive information, give them a procedure to follow.

Teach Employees to Stop, Think, and Verify

Two coworkers having a conversation at a desk with a laptop.

Many scams depend on urgency.

A message might claim that an account is about to be closed, a payment is overdue, the owner needs money transferred immediately, or an employee must log in right away to correct a problem.

That urgency is intentional. The criminal wants the employee to act before thinking.

Employees should know that it is acceptable to stop and verify an unusual request, even when the message appears to come from someone in authority.

That requires management support.

If I tell employees to question suspicious requests but become irritated every time someone verifies something with me, I am sending two different messages. Eventually, employees may decide it is easier to comply than to ask.

A good cybersecurity culture gives employees permission to stop, verify, and ask questions.

Make It Easy to Report a Mistake

Imagine that an employee clicks a suspicious link and realizes a few minutes later that something was wrong. What happens next?

If that employee is afraid of being embarrassed, reprimanded, or fired, the natural reaction may be to say nothing and hope everything is fine.

That delay can make the situation worse.

Employees need to know exactly whom to contact when they think they have clicked a suspicious link, opened a questionable attachment, provided information they should not have, or noticed something unusual on a computer.

I would much rather have an employee report ten things that turn out to be harmless than keep quiet about the one incident that requires immediate attention.

That does not mean mistakes should be ignored. It means the first priority should be protecting the business and addressing the problem.

Pay Attention to Who Has Access

Cybersecurity for small business also involves something far less dramatic than phishing attacks: access.

As businesses grow, employees accumulate access to different systems. Someone may have credentials for email, accounting software, customer databases, cloud storage, social media accounts, website administration, or other business tools.

Business owners should know who has access to important systems and why.

This becomes particularly important when an employee changes responsibilities or leaves the company. Access that is no longer necessary should be removed promptly.

It is easy for this task to fall through the cracks when a departure is busy or unexpected. A simple employee offboarding checklist can help ensure that accounts, passwords, devices, keys, and system permissions are addressed consistently.

Basic Security Practices Still Matter

Management also needs to establish basic expectations for how employees use company technology.

The FTC recommends practices such as protecting passwords, using multifactor authentication, keeping software updated, backing up important data, and training employees to recognize common scams.

Multifactor authentication, often called MFA, is important because a stolen password alone may not be enough for someone to gain access to an account.

These measures can sound technical, but the management question is straightforward: Have we established clear security practices, and do staff understand what they are expected to do?

For example, requiring multifactor authentication or setting rules for handling passwords only helps protect the business when those practices are consistently followed.

Good Organization Is Part of Good Security

Four coworkers having a discussion around a laptop in an office.

Cybersecurity is often discussed as though it begins and ends with technology. I do not see it that way.

Think back to the payroll example. The HR manager did not need to be a cybersecurity expert to prevent that particular scam from succeeding. What was needed was a clear policy: a request to change an employee’s direct deposit information must be independently verified before anyone makes the change.

That is an organizational issue.

At IET, we help businesses develop clear, practical policies and procedures where they are missing, unclear, or no longer working effectively. This work extends throughout an organization, including areas that can affect cybersecurity.

We also look closely at a company’s flow lines. Who communicates with whom? Who has the authority to approve something? Where does information go next? What happens when an employee encounters something unusual?

If those lines are unclear, important information can be missed, responsibilities can overlap, and employees can make decisions without realizing that someone else should have been involved.

Communication is another important part of that structure. IET works with employees not simply to help them perform the mechanics of their jobs, but to develop a higher level of communication within the organization. Employees need to know when to ask a question, when to verify information, whom to contact, and how to communicate a potential problem quickly.

Those skills have value throughout a business. They can also make a difference when a suspicious email or unusual request arrives.

Learn more about IET’s business consulting services.

Technology Still Has an Important Role

Good management practices do not replace appropriate technical safeguards.

Businesses still need to think about passwords, multifactor authentication, software updates, backups, access controls, and the security of the systems they depend on. Those areas can require technical expertise that falls outside the work IET provides.

At IET, we use Solutions by BG, Inc. for our own managed IT and cybersecurity needs, and it is a company I recommend to other small businesses that need help protecting and managing their technology.

I see the two sides as complementary. Technology can provide important safeguards, while good policies, clear flow lines, and well-trained employees help determine what happens when a real person encounters a situation the technology cannot resolve for them.

Cybersecurity Is Part of Managing a Business

Technology will continue to change, and so will the methods criminals use to target businesses. Small-business owners cannot realistically keep up with every new threat themselves, nor should every employee be expected to recognize every sophisticated scam.

What management can do is create an organization in which employees know what is expected of them, important procedures are clearly defined, communication flows where it needs to go, and employees know when to stop and ask questions.

That is not just good cybersecurity. It is good management.

I have spent much of my career helping businesses put those pieces in place. Sometimes that means developing policy or procedures where none exists. Sometimes it means identifying a breakdown in communication or clarifying who is responsible for what. And sometimes it means training employees to communicate and work together at a higher level.

Cybersecurity gives us one more reason why those fundamentals matter.

Rohn Walker
CEO, International Executive Technology

Skip to content