Cybersecurity
Our Bookkeeper Almost Wired $38,000 to a Supplier That Does Not Exist.
The accounts payable clerk at a manufacturer outside Meadville had been paying that supplier's invoices for eleven years. So when the email came through saying the company had changed banks and the remittance details were updated going forward, it did not feel like anything. It arrived inside the existing email thread, under the same subject line they had been using for months. It referenced the correct open purchase order. It was signed by the same contact she had spoken to on the phone that spring. The invoice was for a little over thirty-eight thousand dollars, which was ordinary for that account, and she had it queued for payment before lunch.
What stopped it was luck wearing the costume of habit. She wanted to confirm a delivery date, picked up the phone, and called the supplier at the number in her own records. The supplier had not changed banks. The supplier had not sent that email. Somebody had been sitting inside that mailbox reading the correspondence for several weeks, waiting for exactly the right moment to reply.
Notice what did not fail here. The firewall was fine. The antivirus was fine. Nothing was infected, nothing was encrypted, and no alarm went off anywhere, because from a technical standpoint nothing wrong happened at all. An email arrived and a person read it. That is the shape of the attack that is actually hitting small and mid-sized businesses across Western Pennsylvania right now, and it is why a cybersecurity awareness program has quietly become one of the highest-return things a 20 to 50 person company can put in place. Your employees are already making security decisions every day, dozens of them, whether anyone has prepared them or not. The only real question is whether those decisions are guesses.
How does a fake invoice get past a careful bookkeeper?
Because it is not fake in the way people picture. The mental image most owners carry is the old phishing email: bad grammar, a foreign prince, a suspicious attachment. That version still exists, and your spam filter eats most of it before anyone sees it. The version that costs money looks nothing like that.
The common pattern is called business email compromise, and it usually runs like this. An attacker gets into one email account somewhere in the supply chain (your vendor's, your customer's, or one of yours) by stealing a password, often from an unrelated breach where the person reused it. Then they do nothing. They read. They learn who approves payments, how invoices are worded, when the monthly billing cycle lands, whether the owner signs off personally or the office manager handles it, and even the way people close their emails. Weeks later, they reply inside a genuine thread with new banking details.
Nothing in that email is technically malicious. There is no attachment to scan, no link to block, and the message frequently comes from a real, legitimate mail server belonging to a real business. Security software has very little to grab onto. The only reliable control left is a person who has been taught to notice the pattern (payment details changing by email) and who has been given a rule to follow when they see it.
The same logic covers the other requests your staff are getting. The urgent text that appears to come from the owner asking someone to pick up gift cards. The email from an employee asking to update their direct deposit account before Friday's payroll. The perfect replica of a Microsoft 365 login page that harvests a password. The multi-factor authentication prompt that keeps buzzing someone's phone at eleven at night until they tap approve just to make it stop. Every one of those is aimed at a human being, not at your equipment.
Why doesn't the once-a-year security video work?
Almost every business that has done anything at all has done the annual version: a forty minute video, everyone clicks through it in October, a certificate goes in a file, done for the year. It is not useless, but as protection it fails for three reasons that have nothing to do with effort.
The first is simply how memory works. Whatever anyone retained in October is gone by February, and the attack does not schedule itself around your training calendar.
The second is turnover. The person you hired in March sits untrained until the next annual cycle, and new employees are the most targeted people in your company precisely because they do not yet know what is normal, who has authority to ask for what, or that the owner would never request a wire transfer by text while traveling.
The third is that the attacks have moved. The advice to watch for typos and awkward English is now actively misleading, because messages are being written with AI tools that produce clean, fluent, on-brand copy at scale. Staff trained on last decade's warning signs are looking for tells that no longer appear. Phishing security awareness training that is not refreshed teaches people to trust exactly the emails they should question.
An annual video satisfies a checkbox. It does not change behavior, and behavior is the entire point.
What does a real cybersecurity awareness program actually include?
Something ongoing, short, and measured. The rhythm matters more than the volume, and a good program is deliberately small enough that nobody dreads it.
In practice, an effective employee cyber security training program contains most of the following:
- A baseline simulated phishing test before any training happens, so you know where you honestly stand rather than where you hope you stand. Most first-time baselines land somewhere between a fifth and a third of staff clicking, and owners are usually surprised by who does.
- Short monthly lessons, five to ten minutes, on one topic at a time. Not an annual marathon.
- Simulated phishing on a rotating, unpredictable schedule, with coaching for anyone who clicks instead of punishment. The moment people fear being embarrassed, they stop reporting, and reporting is the thing you are actually building.
- Role-based emphasis. Anyone who touches money (accounts payable, payroll, the owner) gets specific training on payment fraud. Front desk staff get training on the caller claiming to be from your IT company. Executives get training on the fact that they are the most impersonated people in the building.
- A one-click report button in email and a standing rule that reporting something harmless is always the right call and never a mistake.
- A written verification procedure for money. Any change to banking details, any new payee, and any unusual payment request is confirmed by voice, at a phone number already on file, never a number supplied in the message itself. This single rule would have stopped the Meadville invoice on the first day rather than by accident.
- Training within the first week for new hires, and prompt account and device removal for departures.
- Plain-English reporting to the owner showing click rates, report rates, and who still needs attention.
Awareness training is not a substitute for the technical side, and any provider selling it that way is overselling. It sits on top of email security filtering that removes the obvious volume, endpoint protection that catches what gets through and gets clicked, and multi-factor authentication on every account that will accept it. The training exists to handle the residue, which is the small number of well-crafted messages that no filter can distinguish from real correspondence. That residue is where the losses live.
Is employee cyber security training something our insurance or regulators require?
Increasingly, yes, and this is the part that moves the conversation from good idea to line item.
Cyber liability insurers now ask about it directly. Recent renewal questionnaires ask whether you conduct security awareness training, how often, and whether you run simulated phishing. Answering yes on that form when you do not really have a program is a serious exposure of its own, because the answers are representations, and a carrier that discovers at claim time that a stated control did not exist has grounds to reduce or deny the payout. The questionnaire is the same reason we keep telling owners that outsourcing cyber security has become a coverage question and not only a risk question.
For regulated businesses it is more explicit. Medical and dental practices operating under HIPAA are required to have a security awareness and training program for the workforce, and it is one of the items that comes up quickly after a reportable incident. Any business that takes card payments falls under PCI requirements that call for awareness training at hire and at least annually for everyone who handles cardholder data, which sweeps in a lot of retail shops and restaurants that do not think of themselves as regulated at all. Accounting firms, attorneys, and financial advisors carry client-confidentiality duties that a single successful phishing email can breach in an afternoon, and Pennsylvania's breach notification law then determines who has to be told and how fast.
None of that is a reason to buy compliance theater. It is a reason to run something real, because the same program that satisfies the auditor is the one that keeps the wire from going out.
How do we know whether the training is actually working?
You measure it, which is the honest advantage a running program has over a video nobody remembers.
Watch the click rate on simulated phishing over time, but do not stop there, because the more useful number is the report rate. A company where thirty percent of staff forward a suspicious email to the right place within ten minutes is in far better shape than one where nobody clicks but nobody speaks up either, since silence means the real attack lands with no warning. Track how long it takes from delivery to the first report. Watch for repeat clickers and give them attention rather than a reprimand. And test the procedures, not only the people, by confirming that a banking-change request genuinely triggers the callback rule instead of being waved through by someone who is busy.
One caution worth stating plainly. If simulated phishing becomes a way to embarrass staff, the program will backfire, quietly and completely. People hide mistakes from employers who punish them. The goal is a workplace where an employee who clicked something at 4:55 on a Friday tells you immediately, because that one phone call is the difference between a password reset and a month of recovery.
Who runs all of this if we do not have an IT department?
Nobody inside a 25-person business has a spare hour a month to build phishing simulations, write lessons, chase the people who did not finish, and produce reporting. That is exactly why awareness programs get bought with good intentions and then die in the second month.
Handing it to a provider solves the maintenance problem. We run the baseline test, set the monthly cadence, rotate the simulations so they stay realistic, coach the people who need it, handle new hires as they start, and give you a short report you can hand to your insurer without inventing anything. It pairs naturally with a cybersecurity assessment at the start, so the training is aimed at your actual gaps, and with the device oversight that determines what happens when the phone with company email on it goes missing. For what a program costs at your size, request an IT assessment and we will price it against what you actually have rather than a generic package.
If you are not sure how your team would handle a convincing fake invoice, there is a straightforward way to find out that costs nothing but a conversation. We work with small and mid-sized businesses throughout Mercer, Crawford, Lawrence, Butler, and Erie counties (Meadville, Sharon, Hermitage, Grove City, New Castle) along with bordering eastern Ohio, and we will show you where you stand in plain English. Call 833-859-9021 or Request an IT assessment through our contact page.