Nearly every serious incident we see at a small business starts with a person, not a system. Not an unpatched server, not a clever exploit. Somebody was helpful to the wrong person.
Three patterns account for most of it.
The fake support call
Somebody phones or produces an alert claiming your computer has a problem. They talk the person through opening a legitimate remote support tool, which they then control. Security research published in September 2026 documented exactly this: attackers walking victims into installing remote access software, then using it to spread further. The tool is real, the session is real, and nothing on the machine looks obviously wrong.
The version that catches businesses is the one that arrives as a phone call during a busy morning.
The invoice or bank detail change
An email arrives, apparently from a supplier or a client, asking to update payment details. The formatting is right. Sometimes the thread is real, because the other party mailbox was compromised first and the attacker is replying inside a genuine conversation.
This is the one that costs the most money. A business in Queen Creek lost three hundred thousand dollars to exactly this pattern.
The urgent request from the boss
A message that appears to come from an owner or partner, asking someone junior to do something quickly and quietly. Buy gift cards, send a wire, forward a document. It works because it targets the social dynamic rather than the technology.
What actually stops these
A callback rule, on a number you already had. Any request to change payment details, or any unexpected request for money or data, gets verified by phoning a number from your own records. Not the number in the email. This single habit stops most of the second and third patterns and it costs nothing.
Multi factor authentication everywhere. It does not stop the phone call, but it substantially limits what a stolen password achieves.
Permission to be slow. Most of these attacks work because someone did not want to seem obstructive. Staff need to know explicitly that verifying a request is never going to get them in trouble, even if the request turns out to be genuine and even if it is from the owner.
That last one is a management decision, not a technical control, and it is the cheapest thing on this list.
