Large pencil-shaped sign on white wall with message Love to Learn in black text outdoors

System+Signal: Knowing Enough to Ask Better Questions

Fall in Massachusetts has a way of announcing itself before the calendar really does. The mornings get cooler, the light changes, and the first leaves begin collecting along the edges of parking lots. Summer traffic on the South Shore starts to thin out, only to be replaced by the familiar experience of discovering, five minutes late for work, that you are now behind a school bus making what appears to be every possible stop between Marshfield and wherever you were hoping to be.

Backpacks return to front steps. Calendars fill up. Offices that ran at half-speed through August begin settling back into their normal rhythms. There is something appealing about the back-to-school idea even when you have been out of school for decades. September still carries a faint suggestion that this might be a good time to sharpen a pencil, open a fresh notebook, and understand something a little better than you did before.

Technology is probably one of those things.

There is an odd bargain we have made with it over the past twenty years. The more essential technology has become to running a business, the less many business owners feel they are supposed to understand it. That makes a certain amount of sense. A dental practice in Plymouth does not exist to administer Microsoft 365. An engineering firm in Quincy should be spending its time on engineering, not studying identity management. The owner of a construction company with projects scattered across Southeastern Massachusetts has more pressing things to think about than whether a particular authentication protocol is configured correctly.

Specialization is one of the reasons businesses work at all. We hire accountants because we do not want to become accountants, attorneys because we do not want to become attorneys, and technology professionals because running and protecting modern business systems has become a profession in its own right. But specialization has never meant complete ignorance.

A business owner may never prepare a corporate tax return, but they generally understand the difference between revenue and profit. They may never draft an employment agreement, but they know when a conversation belongs with counsel. They probably cannot repair the electrical system in their building, but if the lights dim every afternoon at three o'clock, they know enough to recognize that something deserves attention.

Technology deserves the same kind of fluency. Not expertise for its own sake, and certainly not another vocabulary test filled with acronyms, but enough understanding to recognize when something ordinary has become slightly unusual.

A request arrives from a longtime vendor asking that future payments go to a new bank account. An employee receives an unexpected approval request on their phone while sitting at their desk. Someone pastes part of a client document into an AI tool because it can save twenty minutes of tedious work. An outside contractor gets access to a shared folder for a project and, six months after the project ends, nobody remembers that the access is still there.

None of these situations feels particularly dramatic, which is part of what makes them important. Most security incidents do not announce themselves with alarms and flashing screens. They begin in the middle of an otherwise ordinary workday, when somebody has to make a small decision with incomplete information.

Knowing Enough to Notice

We tend to think of expertise as the thing that keeps us safe. Often, what matters first is simply knowing enough to recognize when a question should be asked.

You do not need to understand business email compromise in technical detail to know that a change in payment instructions deserves a phone call to a number you already trust. You do not need to know how an attacker steals login credentials to understand that an authentication request you did not initiate is worth reporting. You do not need to understand the architecture of a large language model to wonder where company information goes after someone pastes it into an AI service.

These are modest pieces of knowledge, but their value comes from the fact that they change behavior at precisely the moment when behavior matters. That is what we mean this month when we talk about becoming Cyber Smart.

The goal is not to turn a business owner into an IT professional or an office manager into a security analyst. That would be unreasonable and, for most people, a poor use of time. The goal is to develop enough fluency to participate intelligently in the technology that now surrounds almost every part of the business.

That might mean knowing enough to ask when backups were last tested rather than assuming that having backup software means recovery will work. It might mean understanding that MFA is important without knowing how to configure it, or recognizing that employee access should change when someone leaves the company. It might mean asking a few questions about the AI tool someone discovered last week before client information starts flowing through it.

The value lies less in having every answer than in knowing which questions are worth asking.

Cybersecurity Is Increasingly a Management Question

For years, cybersecurity was treated primarily as a technical discipline. The servers lived in a closet, the IT company handled the firewall, and everyone else was largely expected not to touch anything. That boundary has become much harder to maintain.

A typical business may now have information spread across Microsoft 365, cloud accounting software, industry-specific applications, employees' phones, laptops at home, vendor portals, CRM systems, file-sharing platforms, and an expanding collection of AI tools. Some of those systems are tightly controlled by IT. Others can be adopted by an employee with an email address and a credit card.

As a result, many important security decisions are now made by people who would never describe themselves as making security decisions. A manager decides who should have access to a folder. An employee decides whether an email looks legitimate. An executive decides whether a new AI service seems useful. An office administrator decides whether an unusual payment request is strange enough to slow things down.

Good technology can put guardrails around those decisions, and it should. But there is no product capable of removing judgment from a business entirely. That is why we tend to think about security as the intersection of three things: technology, training, and culture.

Technology should make dangerous actions harder and obvious attacks less likely to reach people in the first place. Training gives employees enough context to recognize the situations that technology cannot resolve for them. Culture determines what happens after somebody notices something unusual.

That last piece is easy to underestimate. An employee who reports a suspicious click five minutes after it happens has given the business options. An employee who stays quiet for two days because they are embarrassed has made the same initial mistake but created a very different problem. A healthy security culture is not one where everyone is terrified of getting something wrong. It is one where asking questions early is considered part of doing the job well.

"I'm Not Sure" Can Be a Useful Answer

One of the peculiarities of cybersecurity is that businesses tend to accumulate protections gradually. Someone enabled MFA a few years ago. A backup system was added. A new security product replaced an old one. Employees began taking an annual training course. An insurance questionnaire prompted another round of changes. Microsoft added features. A vendor added something else.

Eventually, a business can have a fairly impressive collection of protections without necessarily having a clear picture of how they all fit together. The useful question is no longer simply, "Do we have cybersecurity?" It is, "What do we actually know about the protections we have?"

Do we know that MFA is being used consistently? Do we know that former employees no longer have access? Do we know that backups can actually be restored rather than simply that the backup software reports success? Do we know what employees are doing with AI? Do people know whom to contact if something seems wrong? Do we know which outside vendors can still access company systems?

These are not deeply technical questions. They are business questions about technology, and "I'm not sure" is often a perfectly good answer because uncertainty gives you somewhere useful to look next.

A September Refresher

That is the idea behind the Cyber Smart resources we are sharing this month. We have built a short assessment around the kinds of situations people encounter during an ordinary workday: suspicious messages, payment requests, unexpected logins, AI use, data sharing, and what happens after somebody believes they may have made a mistake.

There is no prize for getting everything right. The point is to establish a baseline, identify a few blind spots, and perhaps come away with two or three better questions for your IT provider. If one of the questions makes you stop and think, "I actually don't know how we handle that," the assessment has probably done its job.

Because the real test does not happen while you are taking a quiz. It happens later, when a vendor says their banking information has changed, when your phone asks you to approve a login you did not initiate, when a new employee needs access to sensitive information, or when somebody finds a new piece of software that promises to make an annoying part of their job disappear.

The technical work of cybersecurity can be outsourced, and in most businesses it should be. Monitoring, configuration, patching, backups, identity controls, endpoint protection, and the hundreds of other things happening behind the scenes belong with people who spend their careers doing them well.

What cannot be outsourced completely is judgment.

Fortunately, good judgment does not require mastery. It requires enough understanding to notice when the ordinary becomes slightly unusual, enough confidence to ask a question, and a workplace where asking that question is encouraged. That will not make anyone a cybersecurity expert, but it can make a business more thoughtful, more resilient, and considerably harder to fool.

For September, that seems like a pretty worthwhile thing to learn.

Take the Cyber Smart assessment and explore this month's resources at systemsupport.com/cyber-smart.