Skip to content
Annuaire
Sections
Soft Skills

Cybersecurity: raising the alarm without fear of judgment

Cybersecurity: raising the alarm without fear of judgment
L’essentiel

Faced with phishing and AI-powered fraud, silence can make a simple mistake worse. For businesses, enabling people to raise the alarm without humiliation is becoming an essential complement to technical safeguards.

À retenir

Faced with phishing and AI-powered fraud, silence can make a simple mistake worse. For businesses, enabling people to raise the alarm without humiliation is becoming an essential complement to technical safeguards.

The click is done. A second later, a detail catches the eye: that unfamiliar address, that urgent request, that form asking for a password yet again. What now? Report it immediately, or wait and hope nothing has been triggered? Part of cybersecurity hinges on the choice between these two reactions. Looking ahead to September 2026, as artificial intelligence can make impersonation more convincing, knowing how to report a concern without fear of judgment is a collective skill as valuable as it is understated.

The trap no longer necessarily contains a spelling mistake

Phishing does not rely solely on a technical vulnerability. It exploits a busy day, a reporting relationship, a routine. An expected invoice arrives at just the right moment; a supposed technician offers to fix a problem; an executive asks for an exception. The attacker is less interested in making a lengthy case than in prompting an action before any checks begin.

Generative AI can make it easier to write fluent messages, translate them and tailor them to a professional context. Voice synthesis and manipulated video create further opportunities for impersonation. That does not mean every fraud involves sophisticated technology: an ordinary email sent from a compromised account can still be far more effective than an elaborate fake.

A case made public in Hong Kong in 2024 nevertheless illustrates the potential scale of such deception. According to local police, an employee made transfers after a video conference in which participants presented as colleagues were digital imitations. The lesson is not to stop trusting everyone. It is to stop basing sensitive decisions solely on the appearance of authenticity.

After a mistake, silence opens a second breach

Email filters, multifactor authentication and access restrictions remain essential. But no safeguard eliminates every attack scenario. An employee may approve an unexpected request, share a document or enter their credentials on a fake page. At that moment, their ability to raise the alarm becomes a security measure in its own right.

A prompt report can make it possible to revoke sessions, block an account, search for similar messages or contact a bank before recovering the funds becomes more difficult. It does not guarantee a positive outcome. It does, however, give teams a chance to act sooner, while waiting may allow the attacker to advance.

Yet shame slows people down. If training repeatedly insists that scams are obvious and only careless people fall for them, admitting a mistake amounts to declaring oneself incompetent. If the last incident earned someone a public reprimand, that punishment is what colleagues remember most. Official messaging may encourage reporting; everyday reactions determine whether it happens.

Psychological safety in practice

In management, psychological safety means being able to take an interpersonal risk — ask a question, express disagreement, admit a mistake — without facing humiliation. Applied to cybersecurity, it means neither excusing everything nor abandoning the rules. It allows the danger to be addressed first, before responsibility is assessed with care.

The distinction is essential: an honest mistake reported promptly is not the same as repeated, deliberate circumvention of the rules, let alone a malicious act. Promising absolute immunity would lack credibility. An organization can, however, make a clear commitment to receive reports without ridicule, restrict their circulation to those who need to know and avoid treating a request for help as an admission of wrongdoing.

The first response matters twice over

Imagine an accountant calling after sending a bank statement to a fake supplier. Starting by asking how she could have fallen for the scam yields no useful information. Thanking her for reporting it, then establishing the facts, instead helps produce an actionable account. That reaction also shapes what she will later tell her colleagues.

The line manager plays a decisive role here. They must be willing to interrupt a meeting so an alert can be sent, accept that an instruction apparently issued in their name may be checked and acknowledge their own uncertainties. An independent confirmation procedure loses all value if the boss later criticizes the team for wasting their time.

Raising the alarm must be easier than staying silent

A reporting policy cannot amount to an intranet page alone. When doubt arises, there must be a visible route: a button in the email application, a familiar phone number, a clearly identified channel. If the usual account may be compromised, an alternative must be available. And employees must be able to report a suspicion without first having to prove that an attack has occurred.

  • Describe the action: a message opened, a link followed, a file downloaded, information shared or an authentication request approved.
  • Provide the context: the approximate time, the tool used, the identity displayed and the nature of the request.
  • Preserve useful evidence: keep the message and follow the internal procedure, without forwarding a suspicious attachment to colleagues.
  • Wait for appropriate instructions: do not improvise a cleanup or erase evidence to make the embarrassment disappear.

The team receiving the alert must then confirm that it is being handled and explain the next step. Without feedback, reporting feels like sending a message in a bottle. A brief follow-up, even when it was a false alarm, shows that speaking up served a purpose and helps people recognize similar situations in the future.

Train employees without setting them up

Phishing simulations can help people recognize threats and test a reporting process. Poorly designed, they become an exercise in assigning blame. Publishing the names of those who were caught out or using a particularly distressing personal subject risks undermining trust. The exercise should lead to a practical explanation, not a ranking of supposedly gullible colleagues.

The metrics must change too. The click rate does not tell the whole story. The time taken to report, the ease of reaching a team and the quality of its response also deserve to be tracked. An increase in alerts may reflect a growing threat, but it can also signal restored trust: the figures need context.

Finally, scenarios must teach people to verify, not simply to spot fakes. When a familiar voice requests an urgent transfer, calling back on a known number and requiring dual approval is better than listening for an audio flaw. That discipline remains useful even when the imitation is convincing.

What next? For September 2026 and beyond, a priority is emerging: design technical safeguards, verification procedures and management practices together. If AI-assisted fraud becomes more convincing, relying solely on individual vigilance will make even less sense. The resilient company will not be the one where nobody makes mistakes, but the one where concerns can be voiced immediately — and where speaking up brings help rather than judgment.

Sur votre appareil

Comprendre cet article

L’analyse utilise l’intelligence locale du navigateur lorsqu’elle existe, sinon un résumé extractif. Le texte n’est envoyé à aucun service extérieur.

Facebook X LinkedIn

Ensuite A lire aussi