Building a Culture of Cyber Awareness: 10 Steps for Small Businesses
Updated July 27, 2026
At Portolan Networks, most of the compromises we’ve seen didn’t start with a firewall failure or an outdated server. They started with a person. In one case, an employee at a client’s company clicked what looked like a routine invoice. The business had basic antivirus, but nothing more current or comprehensive, and that one click quietly installed remote access tools, giving an attacker a foothold on their network. Nobody caught it internally. It came to light only after the client’s own customers started reporting phishing emails, all pointing to the same malicious link, being sent from that company’s email accounts.
That’s the outcome we work to prevent. And even when the first line of defense doesn’t catch something, there’s usually another one behind it. We’ve seen it play out both ways for other clients: a poisoned Google search result trying to silently run malicious code on someone’s machine, stopped before anything loaded. And a fake Microsoft login page that wasn’t caught in time. An employee clicked it and entered their credentials before anyone realized what it was. But the moment those credentials were used, our identity threat detection tools flagged the activity as suspicious, automatically disabled the account, and alerted us before the attacker could do anything with the access.
None of this is a knock on employees. It’s just reality. According to Verizon’s 2026 Data Breach Investigations Report, 62% of breaches involve the human element. The good news is that this is also the most preventable category of risk in cybersecurity. The right technology stops a lot of it before it starts, but culture is what catches the rest.
Why Culture Matters
Good security tools catch a lot, but they can’t catch everything, and they can’t catch it forever. The remote-access case we just described started with a click that no antivirus flagged as dangerous. It was legitimate software. What eventually stopped it from getting worse wasn’t a piece of software. It was people noticing something was wrong and saying something.
That’s the real value of a culture of cyber awareness: it’s the layer that keeps working even when the technology can’t keep up. Every employee, from the front desk to the executive team, either helps close that gap or leaves it open. When your team knows what a scam looks like, feels safe reporting a mistake without fear of blame, and understands what’s actually at risk (client confidentiality, financial accounts, the trust your business has built), they become part of your defense instead of your biggest liability.
That shift doesn’t happen by accident. It has to be built deliberately, the same way you’d build any other operational habit. Here’s how.
Easy Steps, Big Impact
1. Start with Leadership Buy-in
Security awareness training only works if it’s treated as a business requirement, not an optional extra. The single biggest factor we’ve seen determine whether a rollout actually sticks: leadership makes it mandatory, not opt-in. When training is optional, it quietly slides down everyone’s priority list, not out of carelessness, just because it’s competing with actual client work. In larger organizations, this usually means looping in HR early, since they typically own onboarding and policy enforcement.
The good news is that the ask on leadership is small. With a platform like Huntress Managed SAT (formerly Curricula), most training modules take under 15 minutes a month, a modest time investment for a meaningful drop in risk. What matters just as much as making it mandatory is explaining why. Telling employees “we’re doing this because…,” rather than just handing down a policy, turns compliance into real buy-in.
2. Make Security Awareness Fun, Not Fearful
Once training is mandatory, how it’s delivered determines whether people actually absorb it or just click through to finish. We use Huntress Managed SAT with clients because its modules are short and scenario-based, closer to a story than a lecture. Think a simulated decision point inside a phishing attempt, rather than a slideshow of dos and don’ts. That format matters: people remember a scenario they had to think through far more than a rule they were told to memorize.
Fear-based messaging (“click the wrong link and you’ll get the company hacked”) tends to make employees defensive or anxious rather than careful. Framing training around real, relatable scenarios (and explaining why a particular threat matters to your business specifically) builds the kind of instinctive caution you actually want, without making cybersecurity feel like a minefield.
3. Speak Their Language
Cybersecurity terms can be confusing, and confusion is the enemy of good habits. Employees can’t follow advice they don’t understand. Communicate in plain language, and focus on what someone actually needs to do, not the jargon behind it.
Take multi-factor authentication (MFA). The old explanation was simple: “an extra layer of security when you log in, like needing a code from your phone on top of your password.” That’s still true, but the recommendation itself needs an update. Microsoft has announced it’s retiring SMS- and voice-based MFA entirely by February 2027, shifting instead to passkeys by default starting in September 2026. In plain terms: if your team still logs in using text-message codes, that method is going away, and it was never the strongest option to begin with, since a code sent by text can be tricked out of someone far more easily than a passkey can be bypassed. Passkeys use something tied to your device itself (a fingerprint, a face scan, or a security key) instead of a code that can be phished. If your business hasn’t started that shift yet, now’s the time.
Two other terms that come up often with our clients (especially now that cyber insurance applications ask about them directly) are EDR and MDR:
- EDR (Endpoint Detection and Response) is software that watches your computers and servers for suspicious activity, similar to a security camera watching a building, and can respond automatically if it spots something dangerous.
- MDR (Managed Detection and Response) means real security analysts are watching those alerts around the clock, so a threat gets a human response, not just an automated one.
Insurers ask about these because they matter, but your employees don’t need to memorize acronyms. They need to know the business has eyes on its systems at all times, and that reporting anything unusual is part of what makes that system work.
4. Keep it Short and Sweet
We already touched on this: Huntress Managed SAT’s modules run under 15 minutes a month, and that’s by design. Long, infrequent training (the classic once-a-year, hour-long seminar) tends to fade from memory within weeks. Short sessions delivered consistently, month after month, work better: they keep security top of mind without asking much of anyone’s day. If you’re evaluating whether your current training approach is actually working, frequency matters as much as content. A few minutes every month beats an hour once a year.
5. Conduct Phishing Drills
Regular phishing drills test employee awareness in a low-stakes setting, before a real attempt lands. We run monthly simulated phishing campaigns for clients through Huntress Managed SAT: realistic but harmless phishing attempts, with tracking on who clicks, who reports, and who does neither.
The pattern is consistent: when someone clicks, it’s almost always someone who either hasn’t gone through training yet or wasn’t enrolled in it at all. Employees who complete monthly training reliably spot the same tactics that catch untrained employees off guard. That alone is one of the clearest arguments for keeping training mandatory and current for every employee, not just the ones who happen to opt in.
After each drill, don’t just record who clicked. Walk through the email with employees and point out what gave it away: an urgent subject line, a slightly-off sender address, a link that doesn’t quite go where it claims. That habit of dissecting a fake is what turns a one-time test into a skill people carry into their actual inbox.
6. Make Reporting Easy and Encouraged
Employees need to feel comfortable reporting something suspicious without worrying they’ll be blamed for almost falling for it. In practice, this doesn’t need to be complicated: for many of our clients, reporting has simply meant forwarding a suspicious email along for review, and even that simple habit works. It’s common to hear from staff, in passing, about phishing emails they spotted and deleted on their own, a good sign the training is sinking in.
If you want to make reporting even easier, Outlook’s built-in “Report Phishing” button is worth enabling. It lets employees flag a suspicious email in one click, routes it for review automatically, and removes any friction that might make someone hesitate to report. Whatever method you choose, the goal is the same: make it as easy as possible to raise a hand, and treat every report as a win, not an inconvenience.
7. Have a Go-To Person for Security Questions
In larger organizations, this might look like a formal “security champion” program. For most of the small businesses we work with, it’s simpler than that: one person (usually whoever’s most comfortable with technology) becomes the one coworkers ask first when something looks off. That doesn’t need a title or a program to be effective. What matters is that employees have someone approachable to check with before they click, rather than just a policy document to reference after the fact.
If that person doesn’t already exist informally in your office, it’s worth naming one. Having a designated first point of contact removes the hesitation that keeps people from asking a “dumb question,” which is usually the first sign of a legitimate one.
8. Beyond Work: Security Spills Over
Cybersecurity habits don’t stay contained to office hours. Employees who reuse weak passwords, connect to unsecured Wi-Fi, or leave devices logged in at home bring those same habits back to work, and increasingly, work follows them home in the other direction, too. With remote and hybrid work now common, many employees access client files, email, and business systems from personal devices and home networks that your business doesn’t control and can’t fully secure.
That makes basic home security guidance more than a nice-to-have: strong, unique passwords, a secured home Wi-Fi network, caution on public hotspots, and, if remote access is part of someone’s routine, the same caution toward a personal laptop or phone touching business data as you’d expect toward an office computer. Good habits at home reinforce good habits at work, and the reverse is just as true.
9. Celebrate Success
Recognition doesn’t have to be complicated to be effective. Publicly acknowledging when someone reports a suspicious email, or when a team improves its results on a phishing drill, reinforces that security is a shared win, not just a compliance obligation. It’s a small habit worth building in deliberately. Most businesses focus entirely on catching mistakes and never pause to recognize when the system worked exactly as intended.
10. Leverage Technology
Culture and technology aren’t competing priorities. The best results come from combining both. A few tools worth having in place, and why:
- Security awareness training and phishing simulation (we use Huntress Managed SAT): automated monthly training and simulated phishing campaigns, with no manual tracking required.
- A dedicated password manager (we recommend and deploy Keeper Security): more secure than the password manager built into your browser, with secure password sharing between employees and protections a browser extension simply doesn’t offer.
- Email filtering (we use Proofpoint): filters out the bulk of phishing and malicious email before it ever reaches an inbox, reducing how often an employee has to be the one making the right call in the first place.
- Identity threat detection (we use Huntress ITDR): this is what actually caught the fake Microsoft login page mentioned earlier. An employee did click it and enter their credentials, but the moment those credentials were used, Huntress ITDR flagged the suspicious activity, automatically disabled the account, and alerted us before the attacker could do anything with the access.
- DNS filtering (we use DNS Filter): this is what stopped the malicious Google search result we described earlier. The moment an employee clicked through to the compromised site, the connection was blocked before any malicious script could run.
- Data classification tools, like Microsoft’s Sensitivity Labels in Microsoft Purview, which let you automatically tag and restrict sensitive files (client records, financial data) based on what they contain. This matters more the further your business moves into cloud storage and collaboration tools, and it’s worth raising with your IT provider even if it isn’t in place yet.
None of these tools replace the need for a security-aware team. As the remote-access-tool story earlier showed, technology missed that one. But paired with the culture-building steps above, good tools close a lot of the gaps that training alone can’t catch, and catch a lot that training was never going to prevent in the first place.
The Bottom Line: Everyone Plays a Role
Building a culture of cyber awareness isn’t a one-time project. It’s an ongoing habit, the same way locking the door behind you becomes automatic. Revisit these steps regularly, keep the conversation going, and treat security awareness as part of how your business normally operates, not a once-a-year obligation.
Think back to the story we opened with: a business with no ongoing training that found out about its compromise only when its own customers reported it. That’s the outcome a culture of cyber awareness is built to prevent, not by making your team paranoid, but by making them prepared. Cybersecurity is a shared responsibility, and when your whole team understands what’s at stake and knows what to do about it, they become your strongest line of defense, not your biggest risk.
Book a Free Consultation
If you’re not sure where your business stands, whether your current training is actually working, whether your email and DNS filtering would catch what we described above, or whether it’s time to put a real cybersecurity program in place, let’s talk. Book a time on my calendar and we’ll walk through where the gaps are and what closing them would actually look like for your business.
Frequently Asked Questions
Monthly is ideal. Short, frequent training (under 15 minutes at a time) sticks better than a single long annual session, and keeps pace with how quickly new scams evolve.
EDR (Endpoint Detection and Response) is software that monitors your computers and servers for suspicious activity. MDR (Managed Detection and Response) adds a team of human analysts actively watching and responding to what that software detects. Cyber insurance applications increasingly ask about both.
No. SMS-based codes have been considered a weak form of MFA for years. NIST has classified SMS one-time codes as a “restricted” authenticator since 2017 due to risks like SIM-swapping and message interception. Microsoft’s decision to retire SMS and voice MFA entirely (fully phased out by February 2027, with passkeys becoming the default starting September 2026) is catching up to that long-standing guidance, not setting a new one. If your business still relies on text-message codes, it’s worth moving to passkeys now rather than waiting for the deadline.
Report it immediately rather than trying to fix it themselves. The faster it’s reported, the faster any exposure can be contained, and no one should hesitate out of fear of getting in trouble. Early reporting is the win, not the mistake.
Yes, training and technology catch different things. A well-trained employee can catch something no filter flagged; good email and DNS filtering can catch something that gets past even a well-trained employee. You want both layers, not one instead of the other.