Every October, organizations observe Cybersecurity Awareness Month. Employees are reminded not to click suspicious links, use strong passwords, and complete their annual security training. While those messages remain important, they often come with the underlying assumption that cybersecurity incidents happen because someone wasn’t paying attention.
One of the biggest misconceptions in cybersecurity is that awareness training exists because employees are the problem. The truth is that awareness programs should help employees recognize when someone is attempting to take advantage of their strengths.
Many successful cyberattacks are not careless employees ignoring training. They begin with a well-intentioned employee trying to help someone else. After all, many work in healthcare to help others. The qualities that healthcare organizations look for in their people include responsiveness, collaboration, customer-focus, and willingness to assist others. Organizations reward those who solve problems, move quickly, and help teammates overcome obstacles.
Those qualities are valuable. They are also exactly the qualities attackers seek to, and often do, exploit.
Consider a few common scenarios.
- A help desk technician receives a call from someone claiming to be locked out of their account before an important meeting. The technician wants to help.
- A finance employee receives an urgent request that appears to come from a senior leader. They want to be responsive.
- A department manager is asked to quickly share information needed to support a project. They want to keep work moving.
- A clinician receives a request involving a patient issue that appears time-sensitive. They want to provide care as efficiently as possible.
In each case, the employee is trying to do the right thing. The challenge is that attackers understand this. For years, people have imagined cybercriminals focusing primarily on technical vulnerabilities such as software exploits, malware, and sophisticated hacking tools. While those threats certainly exist, many attacks begin by targeting people’s far more predictable human behavior.
Attackers understand that most people want to be helpful. They understand that employees feel pressure to respond quickly. They know that urgency can sometimes override caution. They know that authority influences decisions. They know that many people would rather solve a problem immediately than slow down and ask additional questions.
That doesn’t make employees careless. It makes them human. Attackers seek to use this humanity and kindness against people so they can harm organizations.
In fact, the employee who falls victim to a social engineering attack is not always the least engaged employee. In many cases, it is the employee most invested in helping others and getting work done.
When viewed through that lens, cybersecurity awareness takes on a different meaning.
- The goal is not to make people suspicious of everyone around them.
- The goal is not to make employees less collaborative.
- The goal is not to create a culture where nobody helps anyone.
- The goal is to create a culture where verification becomes part of helping.
That distinction matters. It matters to the organization, and the patient needs to know why it matters to them.
When an employee pauses to verify a request, they are not being difficult. They are being professional. When someone asks for identity confirmation before resetting an account, they are protecting both the organization and the individual making the request. When a finance employee calls back to confirm a payment request, they are not displaying distrust. They are following good security practices. When a manager asks a few additional questions before sharing information, they are demonstrating responsible stewardship.
Verification should not be viewed as an obstacle to productivity. It should be viewed as a component of trust.
After all, trust without verification is exactly what attackers depend on. This is why some of the most effective security cultures teach a simple principle.
Slow down long enough to be certain.
Attackers frequently create urgency because urgency discourages verification. They want employees to feel rushed. They want people to believe there is no time to double-check. They want emotions to drive decisions.
Many successful attacks would fail if the intended target simply paused for sixty seconds to verify a request through a trusted channel. That may not sound as exciting as discussions about nation-state actors or advanced malware, but it is often where the most meaningful risk reduction occurs.
This Cybersecurity Awareness Month, it’s worth remembering that security is often a battle between good intentions and careful verification, not a battle between smart people and careless people. Most employees come to work wanting to help their colleagues, their customers, and their organizations succeed. That is a strength worth protecting, not criticizing.
The next cybersecurity incident is far more likely to begin with someone trying to help than with someone trying to cause harm. The solution is not to become less helpful. The solution is to create a culture where everyone’s first response to a request is, “I’d be happy to help. Let me verify first.” Because in cybersecurity, some of the strongest defenses are not technical controls at all. Sometimes they are a simple pause, a thoughtful question, and a helpful employee who knows that verification is part of helping.