One click undoes everything else
You can have a firewall, antivirus and backups in place, and one employee can still hand a criminal the keys by clicking a link in a fake invoice. Phishing is one of the most common ways attackers get into small businesses, and it doesn't care how good your equipment is.
Your employees aren't careless. They're busy. A convincing email that lands at 4:45 on a Friday gets clicked. Training fixes that, but only if your team actually sits through it.
Why 15 minutes
Hour-long security videos get played in a background tab. A short, specific conversation at a staff meeting sticks.
Here's the plan. Run the quiz below out loud at your next team huddle. Talk through the answers. Finish with the one rule that matters most. Then spend 15 minutes on your own checklist.
The 5-question phishing quiz for your team
- Your boss emails asking you to buy 5 gift cards for a client and send the codes. They say they're in a meeting and can't talk. What do you do?
- Don't buy anything. Call your boss on a number you already have, not one in the email. Urgent gift-card requests are one of the most common scams out there. A real boss can wait 2 minutes for you to confirm.
- A vendor emails to say their bank account changed and asks you to update it before paying this month's invoice. The email address looks right. Is it safe?
- No. Call the vendor at the number on file and confirm before changing any payment details. Attackers break into or copy real vendor email accounts specifically to redirect payments. Once money is wired, it's usually gone.
- You get a text saying your package can't be delivered, with a link to reschedule. You did order something this week. Do you click it?
- No. Open the shipping company's website or app yourself and track it there. Fake delivery texts spike from October through December because almost everyone is expecting a package.
- You click a link about a shared document and a Microsoft sign-in page appears. It looks exactly like the real thing. Do you sign in?
- Close it. Check the address bar: fake sign-in pages often use a web address that's close but not quite right. If you weren't expecting a shared file, ask the sender through a separate message. Typing your password into a fake page gives an attacker your email, your files and often more.
- You already clicked a link and now think it was fake. What do you do?
- Tell someone right away: your manager or your IT provider. Don't wait and don't be embarrassed. The first 10 minutes matter most. A quick password change and account check can stop a small mistake from becoming a breach. The person who reports fast is doing the job right.
The one rule to leave them with
If an email or text asks for money, passwords or speed, verify it a different way. Pick up the phone. Walk down the hall.
Every scam in the quiz above falls apart with one phone call.
4 red flags to post in the break room
Print these. Tape them up. They cover most of what your team will see this year.
Pressure to act now
"Today," "right now," "before end of day." Urgency is the attacker's main tool.
A sender that doesn't match
The display name says your bank. The actual email address says something else.
Payment changes
New bank details, gift cards or wire transfers always get a phone call first.
Links you didn't expect
Hover before you click. If the web address looks off, it is.
Your 15-minute owner checklist
Your team guards the front door. You make sure the locks work.
Go through these 6 items this month. Any item you can't answer "yes" to is where you start.
| Check | Why it matters |
|---|---|
| Multi-factor authentication is on for email and banking | A stolen password alone can't get anyone in. |
| Backups ran in the last 24 hours, and someone has tested a restore | A backup you've never restored is a guess, not a plan. |
| Every computer still gets security updates | Windows 10 security updates end October 13. Unpatched machines are easy targets. |
| Former employees' accounts are shut off | Old logins are open doors nobody is watching. |
| Your team knows exactly who to call if they click something | A name and a phone number, posted where everyone can see it. |
| You have a written rule for payment changes | One rule, call to confirm, stops most invoice fraud. |
Can't check all 6? You're not alone.
Most owners can't answer half these questions on the spot. That's not a failure. It's a sign you need someone whose job is to know.
IDN has served SE Wisconsin businesses since 2004 and helped 1,000+ clients answer exactly these questions. And when someone does click the wrong link, our clients get a response in 10 minutes. Not a ticket number. A person in Racine who already knows your setup.
Want to go further? Our 12-point cybersecurity checklist for SE Wisconsin businesses covers the rest.
