Fall in Massachusetts has a way of announcing itself before
the calendar really does. The mornings get cooler, the light changes, and the
first leaves begin collecting along the edges of parking lots. Summer traffic
on the South Shore starts to thin out, only to be replaced by the familiar
experience of discovering, five minutes late for work, that you are now behind
a school bus making what appears to be every possible stop between Marshfield
and wherever you were hoping to be.
Backpacks return to front steps. Calendars fill up. Offices
that ran at half-speed through August begin settling back into their normal
rhythms. There is something appealing about the back-to-school idea even when
you have been out of school for decades. September still carries a faint
suggestion that this might be a good time to sharpen a pencil, open a fresh
notebook, and understand something a little better than you did before.
Technology is probably one of those things.
There is an odd bargain we have made with it over the past
twenty years. The more essential technology has become to running a business,
the less many business owners feel they are supposed to understand it. That
makes a certain amount of sense. A dental practice in Plymouth does not exist
to administer Microsoft 365. An engineering firm in Quincy should be spending
its time on engineering, not studying identity management. The owner of a
construction company with projects scattered across Southeastern Massachusetts
has more pressing things to think about than whether a particular
authentication protocol is configured correctly.
Specialization is one of the reasons businesses work at all.
We hire accountants because we do not want to become accountants, attorneys
because we do not want to become attorneys, and technology professionals
because running and protecting modern business systems has become a profession
in its own right. But specialization has never meant complete ignorance.
A business owner may never prepare a corporate tax return,
but they generally understand the difference between revenue and profit. They
may never draft an employment agreement, but they know when a conversation
belongs with counsel. They probably cannot repair the electrical system in
their building, but if the lights dim every afternoon at three o'clock, they
know enough to recognize that something deserves attention.
Technology deserves the same kind of fluency. Not expertise
for its own sake, and certainly not another vocabulary test filled with
acronyms, but enough understanding to recognize when something ordinary has
become slightly unusual.
A request arrives from a longtime vendor asking that future
payments go to a new bank account. An employee receives an unexpected approval
request on their phone while sitting at their desk. Someone pastes part of a
client document into an AI tool because it can save twenty minutes of tedious
work. An outside contractor gets access to a shared folder for a project and,
six months after the project ends, nobody remembers that the access is still
there.
None of these situations feels particularly dramatic, which
is part of what makes them important. Most security incidents do not announce
themselves with alarms and flashing screens. They begin in the middle of an
otherwise ordinary workday, when somebody has to make a small decision with
incomplete information.
Knowing Enough to Notice
We tend to think of expertise as the thing that keeps us
safe. Often, what matters first is simply knowing enough to recognize when a
question should be asked.
You do not need to understand business email compromise in
technical detail to know that a change in payment instructions deserves a phone
call to a number you already trust. You do not need to know how an attacker
steals login credentials to understand that an authentication request you did
not initiate is worth reporting. You do not need to understand the architecture
of a large language model to wonder where company information goes after
someone pastes it into an AI service.
These are modest pieces of knowledge, but their value comes
from the fact that they change behavior at precisely the moment when behavior
matters. That is what we mean this month when we talk about becoming Cyber
Smart.
The goal is not to turn a business owner into an IT
professional or an office manager into a security analyst. That would be
unreasonable and, for most people, a poor use of time. The goal is to develop
enough fluency to participate intelligently in the technology that now
surrounds almost every part of the business.
That might mean knowing enough to ask when backups were last
tested rather than assuming that having backup software means recovery will
work. It might mean understanding that MFA is important without knowing how to
configure it, or recognizing that employee access should change when someone
leaves the company. It might mean asking a few questions about the AI tool
someone discovered last week before client information starts flowing through
it.
The value lies less in having every answer than in knowing
which questions are worth asking.
Cybersecurity Is Increasingly a Management Question
For years, cybersecurity was treated primarily as a
technical discipline. The servers lived in a closet, the IT company handled the
firewall, and everyone else was largely expected not to touch anything. That
boundary has become much harder to maintain.
A typical business may now have information spread across
Microsoft 365, cloud accounting software, industry-specific applications,
employees' phones, laptops at home, vendor portals, CRM systems, file-sharing
platforms, and an expanding collection of AI tools. Some of those systems are
tightly controlled by IT. Others can be adopted by an employee with an email
address and a credit card.
As a result, many important security decisions are now made
by people who would never describe themselves as making security decisions. A
manager decides who should have access to a folder. An employee decides whether
an email looks legitimate. An executive decides whether a new AI service seems
useful. An office administrator decides whether an unusual payment request is
strange enough to slow things down.
Good technology can put guardrails around those decisions,
and it should. But there is no product capable of removing judgment from a
business entirely. That is why we tend to think about security as the
intersection of three things: technology, training, and culture.
Technology should make dangerous actions harder and obvious
attacks less likely to reach people in the first place. Training gives
employees enough context to recognize the situations that technology cannot
resolve for them. Culture determines what happens after somebody notices
something unusual.
That last piece is easy to underestimate. An employee who
reports a suspicious click five minutes after it happens has given the business
options. An employee who stays quiet for two days because they are embarrassed
has made the same initial mistake but created a very different problem. A
healthy security culture is not one where everyone is terrified of getting
something wrong. It is one where asking questions early is considered part of
doing the job well.
"I'm Not Sure" Can Be a Useful Answer
One of the peculiarities of cybersecurity is that businesses
tend to accumulate protections gradually. Someone enabled MFA a few years ago.
A backup system was added. A new security product replaced an old one.
Employees began taking an annual training course. An insurance questionnaire
prompted another round of changes. Microsoft added features. A vendor added
something else.
Eventually, a business can have a fairly impressive
collection of protections without necessarily having a clear picture of how
they all fit together. The useful question is no longer simply, "Do we have
cybersecurity?" It is, "What do we actually know about the protections we
have?"
Do we know that MFA is being used consistently? Do we know
that former employees no longer have access? Do we know that backups can
actually be restored rather than simply that the backup software reports
success? Do we know what employees are doing with AI? Do people know whom to
contact if something seems wrong? Do we know which outside vendors can still
access company systems?
These are not deeply technical questions. They are business
questions about technology, and "I'm not sure" is often a perfectly good answer
because uncertainty gives you somewhere useful to look next.
A September Refresher
That is the idea behind the Cyber Smart resources we are
sharing this month. We have built a short assessment around the kinds of
situations people encounter during an ordinary workday: suspicious messages,
payment requests, unexpected logins, AI use, data sharing, and what happens
after somebody believes they may have made a mistake.
There is no prize for getting everything right. The point is
to establish a baseline, identify a few blind spots, and perhaps come away with
two or three better questions for your IT provider. If one of the questions
makes you stop and think, "I actually don't know how we handle that," the
assessment has probably done its job.
Because the real test does not happen while you are taking a
quiz. It happens later, when a vendor says their banking information has
changed, when your phone asks you to approve a login you did not initiate, when
a new employee needs access to sensitive information, or when somebody finds a
new piece of software that promises to make an annoying part of their job
disappear.
The technical work of cybersecurity can be outsourced, and
in most businesses it should be. Monitoring, configuration, patching, backups,
identity controls, endpoint protection, and the hundreds of other things
happening behind the scenes belong with people who spend their careers doing
them well.
What cannot be outsourced completely is judgment.
Fortunately, good judgment does not require mastery. It
requires enough understanding to notice when the ordinary becomes slightly
unusual, enough confidence to ask a question, and a workplace where asking that
question is encouraged. That will not make anyone a cybersecurity expert, but
it can make a business more thoughtful, more resilient, and considerably harder
to fool.
For September, that seems like a pretty worthwhile thing to
learn.
Take the Cyber Smart assessment and explore this month's
resources at systemsupport.com/cyber-smart.
