Brockton has been calling itself the City of Champions
for a long time. It's a fitting nickname for a city associated with fighters
like Rocky Marciano and Marvin Hagler, but there's one piece of boxing advice
we probably shouldn't carry over into cybersecurity:
Don't try to tough it out.
An employee clicks a link in an email. A Microsoft login
page appears, they type in their password, and only afterward does something
feel wrong. Maybe the page disappears strangely. Maybe the email suddenly looks
less convincing on a second read. Maybe an unexpected MFA notification pops up
a few minutes later.
There's an uncomfortable moment when the employee realizes, I
may have just made a mistake.
What happens next matters enormously.
Good cybersecurity awareness isn't about creating employees
who never click the wrong thing, never lose a device, and never make a mistake.
It's about creating employees who recognize when something may have happened
and tell someone quickly enough for the business to respond.
For Brockton businesses, that makes reporting suspicious
activity one of the most important—and most overlooked—parts of the human side
of cybersecurity.
A Mistake and an Incident Aren't Always the Same Thing
One reason employees hesitate to report cybersecurity
problems is embarrassment.
They know they've been told not to click suspicious links.
They remember the training. They may even have rolled their eyes at the
phishing simulation last month and confidently announced that they would never
fall for something like that.
And then they fall for something like that.
The natural impulse can be to close the window and hope
nothing happened.
That is exactly the wrong instinct.
Clicking a malicious link does not automatically mean the
company has suffered a major breach. Entering a password into the wrong page
does not guarantee that an attacker has taken over the account. Losing a phone
does not mean someone has accessed company data.
Those events create risk.
What happens next depends in part on how quickly the company
knows about them.
If an employee immediately reports that they entered
credentials into a suspicious site, IT may be able to reset the password,
revoke active sessions, review login activity, and check whether anything
unusual occurred.
If nobody learns about it until two days later, the same
investigation becomes considerably more complicated.
That's why one of the simplest rules we can teach employees
is:
If something happens, tell someone. If you made a
mistake, tell them faster.
The goal isn't to assign blame. The goal is to give the
people responsible for security time to do something useful.
Your Employees May See the First Warning Sign
Cybersecurity software can see a lot.
It can detect malicious files, unusual network traffic,
suspicious logins, known threats, and all kinds of activity that would be
completely invisible to the average employee.
But technology doesn't know everything.
An employee may know that the email supposedly sent by their
boss doesn't sound like their boss.
Accounting may know that a vendor has never changed payment
instructions this way before.
A receptionist may notice that someone claiming to be from
IT is unusually determined to get an employee on the phone.
An employee may see an MFA notification appear when they
haven't tried to sign in.
Someone may notice that messages are suddenly disappearing
from their mailbox or coworkers are receiving strange emails from their
account.
Those observations have context that a security product may
not have.
That makes employees more than potential victims. They can
also become an early-warning system.
The important part is making sure they know what to do with
that information.
If the company's incident-reporting procedure is buried on
page 42 of an employee handbook last updated in 2019, we probably shouldn't be
surprised when nobody follows it.
Employees should be able to answer a much simpler question:
Something weird just happened. Who do I tell?
What Should Employees Report?
The answer should be broader than "phishing emails."
Employees should report anything that suggests someone may
be attempting to misuse their identity, access company information, or
manipulate a normal business process.
That can include an unexpected MFA request, a suspicious
email or text message, a phone call asking for credentials, an unusual payment
request, a lost company device, strange computer behavior, or sensitive
information accidentally sent to the wrong recipient.
And, yes, employees should report things they already
clicked.
That last part deserves emphasis because security training
can accidentally send the wrong message. If every phishing simulation ends with
a giant red screen announcing YOU FAILED, we shouldn't be shocked when
an employee's first thought after a real mistake is to keep quiet.
We want a different reaction:
That was suspicious. I should tell someone.
A company benefits far more from knowing about a problem in
five minutes than from discovering a perfectly documented mistake five days
later.
The Near Miss Matters Too
Suppose an employee at a Brockton company receives a very
convincing email asking them to review a shared document.
They don't click it.
Good.
They delete the message and continue working.
Also understandable.
But reporting the message may be much more valuable.
If one employee received it, twenty others may have received
the same thing. IT might be able to block the sender, remove similar messages,
investigate where it came from, or warn the rest of the company before someone
else takes the bait.
One employee's suspicion can therefore protect coworkers
they may never even know were targeted.
That's why we should teach employees to report near
misses, not just successful attacks.
The report doesn't need to become a federal case. Most
suspicious messages will turn out to be routine spam, harmless mistakes, or
something easily handled.
That's okay.
A fire alarm isn't considered a failure because most
buildings don't burn down.
We'd rather know.
Make Reporting Easier Than Ignoring It
If we want employees to report cybersecurity concerns, the
process has to be easy.
A "Report Phishing" button inside Outlook is useful because
the employee doesn't need to remember an email address.
A familiar help-desk number is useful because someone who
has just realized they entered their password into a fake website probably
doesn't want to hunt through the company intranet for an incident-response
flowchart.
Employees should also know what to do outside normal
business hours. A suspicious login at 8:30 on Tuesday morning is easy to
report. A lost laptop at 8:30 on Saturday night can be less obvious.
The business side of "See Something, Say Something"
therefore has a few practical requirements:
Employees need to know what to report, where
to report it, and what to do immediately afterward.
They also need to believe that reporting quickly is
preferable to hiding a mistake.
That culture matters.
People will make mistakes. The company can either learn
about them quickly or learn about them eventually.
Quickly is better.
So You Clicked the Link. Now What?
Let's return to our employee.
They clicked.
They entered a password.
Then they realized the page didn't look right.
The first step isn't to panic. It also isn't to start
Googling "how to remove hackers from computer" and downloading whatever appears
first.
Stop interacting with the suspicious page and report what
happened through the company's established IT or cybersecurity process.
Be specific.
Tell them what you clicked, approximately when it happened,
whether you entered credentials, whether you downloaded or opened anything, and
what happened afterward.
Then follow the instructions you're given.
Depending on what occurred, IT may ask you to reset a
password, reauthenticate, disconnect a device, preserve a message, or take some
other action.
The important part is speed and accuracy.
Nobody needs the employee to solve the crime.
We just need them to raise their hand.
In Cybersecurity, Getting Back Up Quickly Matters More
Than Never Falling Down
That brings us back to Brockton.
The City of Champions has produced enough fighters to
understand that getting hit and losing the fight are not the same thing.
Cybersecurity works similarly.
An employee receiving a phishing message isn't a breach.
Clicking a link isn't automatically a disaster. Even making a mistake doesn't
necessarily determine the outcome.
What matters is whether the organization has layers of
protection—and whether people recognize when one of those layers may have
failed.
So whether an employee is working downtown, heading home
toward Easton, meeting a customer in West Bridgewater, or finishing something
later from the kitchen table, the rule stays the same:
See something unusual? Say something.
Clicked something you shouldn't have? Say something
faster.
Your employees aren't expected to stop every cyberattack
themselves. They're expected to give the people who can respond a chance to
respond.
During Cyber
Smart September, that may be one of the most important lessons of all.
A sitting duck stays still.
Your employees should know when to raise the alarm.
In Short
Brockton businesses can reduce cybersecurity risk by
teaching employees to report suspicious emails, unexpected MFA prompts, lost
devices, unusual payment requests, and accidental clicks as quickly as
possible. Fast cybersecurity incident reporting gives IT teams more time to
reset compromised credentials, investigate suspicious activity, protect other
employees, and contain a potential threat before it becomes a larger business
problem.
For companies in Brockton and nearby communities such as
Easton and West Bridgewater, effective employee cybersecurity awareness should
emphasize that reporting a possible mistake quickly is more valuable than
trying to hide it or investigate it alone.
Frequently Asked Questions
What should I do if I clicked a phishing link?
Stop interacting with the suspicious website or message and
report the incident to your company's IT or cybersecurity contact as quickly as
possible. Tell them whether you entered a password, downloaded a file, approved
an MFA request, or provided any other information.
Do not assume that closing the browser means the problem is
over. The appropriate next steps depend on what happened, and IT may need to
reset credentials or investigate account and device activity.
What should I do if I entered my password on a phishing
website?
Report it immediately through your company's established IT
or cybersecurity process. The password may need to be changed, existing login
sessions may need to be revoked, and the account may need to be reviewed for
suspicious activity.
If that password was reused on another account, tell IT that
as well. Reusing passwords can allow one stolen credential to create problems
across multiple services.
Should employees report suspicious emails even if they
didn't click anything?
Yes. Reporting a suspicious email can help IT determine
whether other employees received the same message and take steps to block,
remove, or warn people about the threat.
A phishing report is useful even when the employee
successfully avoided the attack. In many cases, the employee who spots the scam
first can help protect everyone else.
