October is Cybersecurity Awareness Month, and you’ll probably hear a lot about passwords, multi-factor authentication, firewalls, ransomware, and security software.
All of those things matter.
But there’s another part of cybersecurity we can’t afford to overlook.
People.
I was talking with an organization once after an employee received an email that looked completely normal.
It appeared to come from someone the employee knew.
The request wasn’t outrageous.
There wasn’t a giant flashing warning that said:
THIS IS A CYBERATTACK.
There was simply a message asking the employee to do something.
And that’s what makes modern cyberattacks so effective.
Attackers don’t always need to break through your firewall.
Sometimes they just need to convince one good employee to open the door.
For credit unions, Cybersecurity Awareness Month is a good opportunity to ask an important question:
Are we building security technology—or are we building a security culture?
You need both.
Your Employees Aren’t the Problem
Let’s get something straight before we go any further.
I don’t like calling employees the “weakest link.”
Your employees come to work to serve members.
They aren’t cybersecurity analysts.
And attackers are very good at creating situations designed to make normal people react quickly.
An email appears to come from the CEO.
A vendor suddenly changes payment instructions.
Microsoft says your password is about to expire.
Someone from “IT” calls and needs to verify your account.
A member appears to need urgent help.
The attacker uses something powerful:
Trust.
So instead of treating employees like the cybersecurity problem, let’s turn them into part of the cybersecurity solution.
1. Teach People to Slow Down
Urgency is one of the attacker’s favorite tools.
“Do this immediately.”
“Your account will be disabled.”
“I need this before my meeting.”
“Don’t call me—I’m traveling.”
That sense of urgency is designed to bypass the little voice in someone’s head saying:
“This seems strange.”
Teach employees that it’s okay to slow down.
Before clicking a link, opening an unexpected attachment, changing payment information, sharing sensitive information, or approving an unusual request, stop and verify.
Thirty seconds of skepticism can prevent days or weeks of recovery work.
2. Make Verification Normal
Imagine an employee receives an email that appears to come from the CEO:
“I’m in a meeting. I need you to take care of this immediately.”
What happens next?
Does the employee feel comfortable calling the CEO?
Or are they worried they’ll look foolish?
That’s a culture question.
Employees should know that verifying an unusual request is a good thing.
Call the person using a known number.
Start a new email instead of replying to the suspicious message.
Follow established procedures for financial transactions and sensitive requests.
I would much rather have an employee spend two minutes verifying something legitimate than spend the next two weeks recovering from something that wasn’t.
3. Give Employees a Simple Framework
Cybersecurity training gets complicated when we give people 47 things to remember.
I prefer something simpler.
Teach employees to PAUSE.
P — Pay Attention
Does anything about the message seem unusual?
Look at the sender, wording, request, links, and attachments.
A — Ask Why
Why is this person asking me to do this?
Is it normal?
U — Urgency Is a Warning
Is somebody trying to make me act before I have time to think?
S — Stop and Verify
Use another trusted method to confirm unusual requests.
E — Escalate
If something doesn’t feel right, report it.
That’s the behavior we’re trying to create.
Not fear.
Awareness.
4. Make Reporting Easy
Here’s something leadership needs to think about.
What happens when an employee clicks something suspicious?
Do they immediately tell somebody?
Or do they sit quietly for 30 minutes hoping nothing happens because they’re embarrassed?
Those 30 minutes could matter.
Your culture should make this message crystal clear:
If you think you made a mistake, tell us immediately.
Don’t hide it.
Don’t try to fix it yourself.
Don’t worry about being embarrassed.
Call the appropriate person.
The faster your technology or security team knows about a potential incident, the faster they can investigate it.
A healthy cybersecurity culture rewards quick reporting.
5. Train More Than Once a Year
Once-a-year cybersecurity training is better than nothing.
But think about how quickly people forget things they don’t regularly use.
Security awareness works better when it’s reinforced throughout the year.
That doesn’t mean employees need hours of training every month.
Keep it practical.
A short phishing reminder.
A five-minute discussion during a staff meeting.
A simulated phishing exercise.
A warning about a current scam.
A reminder about handling sensitive information.
Cybersecurity Awareness Month can create momentum.
The other 11 months are where you build the habit.
6. Don’t Forget Executives and the Board
Cybersecurity training isn’t just for frontline employees.
In fact, leadership can be an especially attractive target.
Executives may have access to sensitive information.
They may have authority to approve transactions.
Their names are publicly available.
Attackers can research leadership teams and create convincing messages.
Board members can also have access to sensitive communications and documents.
Cybersecurity awareness should include everyone.
If someone has access to your information, systems, or decisions, they’re part of the security conversation.
7. Prepare Employees for AI-Powered Scams
Artificial intelligence is making this conversation even more important.
Fraudulent messages can become more polished.
Impersonation can become more convincing.
Voice and video technologies can create situations that feel very real.
That’s why employees can’t rely only on:
“The email had bad grammar, so I knew it was fake.”
The better defense is process.
If someone asks for something unusual involving money, credentials, confidential information, or access, verify the request through a trusted method.
The more convincing attacks become, the more valuable good procedures become.
8. Test the Culture
You don’t really know how prepared people are until you test them.
Phishing simulations can help identify where more education is needed.
But don’t turn them into a game of:
“Gotcha! You failed.”
That’s the wrong message.
Use results to improve.
Which attacks are employees struggling to recognize?
Which departments need additional education?
Are people reporting suspicious messages?
Is reporting getting faster?
The goal isn’t a perfect score.
The goal is improvement.
What Should Leadership Measure?
You don’t need a 30-page cybersecurity awareness report.
Start with a few useful questions:
- Are employees completing training?
- How are employees performing during phishing exercises?
- Are suspicious messages being reported?
- How quickly are they reported?
- Are certain types of attacks repeatedly causing problems?
- Are executives and other high-risk users receiving appropriate training?
Then review those trends during your quarterly technology and cybersecurity meetings.
Training should create measurable improvement.
A Question for Your Next Staff Meeting
During Cybersecurity Awareness Month, ask your employees this:
“If you received a suspicious email right now, would you know exactly what to do?”
Don’t assume the answer.
Ask them.
Where should they report it?
Who should they call?
What should they do if they already clicked?
What happens if they entered their password?
If different employees give different answers, you’ve just identified an opportunity to improve.
Final Thoughts
You can spend a lot of money on cybersecurity.
And sometimes you should.
But one of your most valuable security investments is creating employees who are comfortable stopping and saying:
“Something about this doesn’t look right.”
Teach people to slow down.
Make verification normal.
Give them a simple process.
Make reporting easy.
Train throughout the year.
Include executives and the board.
Test what you’ve taught.
And when somebody reports something suspicious, thank them for speaking up.
That’s how you build what people sometimes call a human firewall.
I prefer another term.
A security-minded team.
Because your employees aren’t your weakest link.
With the right education, processes, and culture, they can become one of your strongest layers of protection.
Cybersecurity Awareness Month gives us a reason to talk about it.
The goal is to make those habits last long after October ends.
Is Your Credit Union Building a Stronger Cybersecurity Culture?
Technology is only one part of cybersecurity.
At CTG, we help credit unions look at the bigger picture—including cybersecurity strategy, employee awareness, Microsoft 365 security, identity protection, incident response, ransomware recovery, business continuity, vendor risk, and long-term technology planning.
For more than 26 years, CTG has helped organizations make better technology decisions, backed by a team with more than 200 years of combined experience.
Our vendor-agnostic approach starts with your risks, your people, and your goals—not a product we’re trying to sell.
This Cybersecurity Awareness Month, ask your team one simple question:
Would our employees know what to do if something didn’t look right?
If you’re not completely confident in the answer, let’s start the conversation.
Talk with CTG
Phone: 330-655-8144
Email: brett.harney@ctgusa.net
Website: ctgusa.net
Let’s build cybersecurity awareness that lasts longer than October—and turn your employees into one of your strongest lines of defense.
Recent Blog Posts...
Could One Employee Put Your Credit Union at Risk? How to Build a Human Firewall
Why Do Quarterly Technology Reviews Matter More Than Annual IT Planning for Credit Unions?
7 Ways to Protect Your TruLinx Environment from Cyberattacks
10 Questions Every Mid-Sized Organization Should Ask About Its Cybersecurity Program
Cybersecurity Awareness Month: 10 Questions Every Credit Union Should Ask About Its Cybersecurity Program
- AI6
- Application Integration6
- Application Performance16
- Artificial Intelligence1
- Asset Management2
- Bandwidth Management8
- Business Continuity / Disaster Recovery41
- BYOD7
- Cloud58
- Collaboration18
- Communication20
- Compliance4
- Contact Center1
- Credit Unions19
- Cyber Liability Insurance2
- Cybersecurity44
- Dark Web1
- Hosted Phone47
- Hybrid Working2
- Internet7
- Internet of Things6
- IT Infrastructure26
- Managed Network Services20
- Managed Services19
- Microsoft Teams2
- Network Performance29
- Network Security34
- News11
- Phishing1
- Press Release2
- Ransomware1
- Risk Assessment3
- security2
- SIP Trunking3
- surveillance1
- Technology Audit3
- Telehealth3
- TruLinx9
- Uncategorized38
- Unified Communications51
- VoIP36
- Work From Home3

