In almost every company that has suffered a serious incident, someone had noticed something beforehand. A strange message, an unusual window, a file that would not open properly. The person said nothing, or waited.
They did not wait out of negligence. They waited because they were not sure, did not want to bother anyone over nothing, and feared the reaction. Meanwhile, an attack that could have been stopped within twenty minutes had two days to unfold.
That is the whole point of a security culture. It is not about turning people into experts. It is about making sure they speak up quickly.
The reporting delay decides everything
An IT incident is not an event, it is a duration.
When credentials are stolen, the attacker does not empty the accounts immediately. They watch, they read the messages, they learn how the company works, who approves payments and in what tone people write to each other. This quiet phase can last for weeks. That is exactly what we describe in our article on e-mail account compromise.
Every hour saved on this duration reduces the scale of the damage. Reporting within the hour often makes it possible to cut off access before any money moves. Reporting the next morning is sometimes already too late.
Yet this delay does not depend on any tool. It depends on what the person anticipates as a reaction. A company can install the best filters on the market: if its team dreads announcing bad news, it will lose the hours that matter every single time.
What kills a security culture?
Three practices are enough, and none of them is ill-intentioned.
Looking for someone to blame. After an incident, the question “who clicked” comes up naturally. It seems legitimate, it even looks methodical. Yet it serves no operational purpose: knowing who clicked changes nothing about what needs to be done within the hour. On the other hand, the whole team registers the question, and draws the obvious conclusion for next time.
Publishing named results from a simulation. A phishing simulation is a fake trapped message deliberately sent to employees to measure their reflexes. The tool can be useful, and our article on phishing simulations describes the conditions needed for it to remain so. Publishing the list of those who clicked turns it into public humiliation. The people concerned do not become more vigilant, they become distrustful of their employer, and they stop reporting genuinely suspicious messages for fear it might be another test.
Mocking a naive question. “How do I know if a website is secure?” A sigh, a knowing look, and the person will never ask a question again. They will still keep using the tool, simply without asking. Every question left unasked is a risk that stays inside the company.
Many managers find it reassuring to never have anything to deal with. In reality, this is the most worrying sign of all. Fraudulent messages land in every inbox, without exception. If no one ever reports anything, it is not that nothing happens: it is that nothing gets reported. The day a serious incident occurs, it will be discovered late, through its consequences.
What builds one?
The effective moves are few, and they cost little.
Publicly thank whoever reports something, including a false alarm. This is the single most rewarding move in the whole approach. When someone forwards a suspicious message that turns out to be perfectly legitimate, the temptation is to reply that it was nothing. Do the opposite: say in a meeting that it was a good instinct, and that this is exactly what should be done. You have just set the acceptable level of vigilance for everyone, without needing any training session.
Explain the reasons behind the rules. An instruction without justification is experienced as an arbitrary constraint, and an arbitrary constraint gets bypassed as soon as it gets in the way. “Change your password” achieves nothing. “If this password is also the one for your favourite online shop, and that shop gets hacked, someone will be able to read your work e-mail” produces a change in behaviour. Our article on phishing provides this kind of concrete explanation, ready to reuse internally as it stands.
Accept that an unworkable rule will be bypassed, and fix it as a result. This is the hardest part for management, because it means admitting a mistake was made.
Security that gets in the way of work gets bypassed
This is not a hypothesis, it is a constant.
If sending a document to a client requires three approvals, people will use their personal e-mail. If the official file-sharing system is slow, they will use a USB stick instead. If the password must change every thirty days and meet eight requirements, it will end up written on a piece of paper under the keyboard, with a digit incremented each time.
Bring the team together and ask: "What makes your life harder in our IT rules?" Listen without correcting, without justifying, and take notes. Every answer points to a workaround that already exists, or will soon exist. Fixing an unworkable rule protects more than repeating it does.
A realistic rule is worth more than an ideal rule that gets bypassed. A slightly less locked-down file-sharing system that everyone actually uses is better than a perfect setup that nobody opens. The measures described in the Best practices pillar are only worth something if they are applied day to day.
What role does management’s example play?
A security culture is judged by what management does, not by what it says.
A manager who requests an exception for themselves, who refuses two-factor authentication because it is annoying, or who demands permanent access to everything, clearly announces that these rules are for other people. No amount of awareness training will make up for that message.
The stakes here are also very concrete. Managers and financial officers are the most sought-after targets, because they hold the authority to approve a payment. That is exactly the mechanism behind CEO fraud, which was the subject of 605 reports from Swiss companies in the first half of 2025 and 366 in the second half.
There is one last move, free and remarkably effective: telling your own story of hesitation. A manager who admits they nearly replied to a fake supplier message gives their whole team permission to admit the same thing.
This exemplary behaviour requires management to have trained first, ahead of their teams, and for real reasons rather than as a matter of principle. We cover this in training management first.
The first sentence matters more than anything else
Someone comes to see you. They clicked, they entered their password on a fake page, they sent a file to the wrong person. They feel uneasy, and they have been hesitating outside your door for twenty minutes.
What you say in the five seconds that follow will have more impact than all your awareness activities for the whole year. The entire team will know about it before the end of the day.
| Situation | What closes the door | What opens it |
|---|---|---|
| An employee reports a click | ”How could you fall for that?" | "Thanks for telling me right away, we’ll take care of it.” |
| A false alarm | ”It was nothing, don’t bother me with that." | "Good instinct, that’s exactly what you should do.” |
| A basic question | ”You should know that by now." | "Good question, no one had asked that before.” |
| A bypassed rule | ”But the instruction is clear." | "Why isn’t it working? Let’s review it.” |
Only afterwards come the technical steps: isolating the machine, changing the affected passwords, checking what may have been reached. Our article on the first hours after an attack details this process.
What does an outside perspective add here?
A company’s culture cannot be outsourced. No one can build in your place the trust that leads an employee to come and talk to you on a Friday evening. It plays out through dozens of small interactions, over years, and it belongs entirely to you.
An outside perspective serves a different purpose: seeing what habit has made invisible. A company no longer perceives its own blind spots. The shared access that everyone has used for six years, the generic mailbox whose password nobody remembers anymore, the payment procedure that everyone assumes someone else checks. These blind spots are not acts of negligence, they are arrangements that have become normal.
These principles form a genuine foundation, but they do not replace an examination of how your organisation actually works. To identify your starting point, the cyber check-up includes several questions on reporting and internal habits. The other awareness articles, including onboarding a new employee, are grouped in the Training pillar, and our online training for Swiss French-speaking SMEs will offer these principles in a ready-to-follow format.