Weak password habits
The everyday password failures are familiar: reuse across accounts and shared logins on small teams where one credential floats between people. These habits persist because good password behavior feels like friction. Every unique, complex password is one more thing standing between someone and the task they're trying to finish.
The consequence arrives later, from somewhere else. When a breach at another company leaks credentials, attackers replay those username and password pairs against your accounts, a technique called credential stuffing. Akamai counted 26 billion credential stuffing attempts every month in its 2024 report, and credential abuse was the initial access vector in 22% of breaches per the Verizon 2026 DBIR. One reused password becomes an account takeover. The practical fixes, password managers and multi-factor authentication, come later in this article.
Ignoring malware warnings
Malware gets in through ordinary actions. Someone downloads an attachment they didn't vet or clicks straight through a security warning to get a task done. The prompt feels like an obstacle because habituation plus workload means it barely registers before the mouse moves to "proceed."
The stakes for a small organization are existential. Ransomware appeared in 44% of breaches in the Verizon 2026 DBIR, and average recovery costs for small businesses could run up to millions. Add extended downtime and lost customers, and a single incident can end the business. Prevention is a mix of trained caution and technical guardrails that take the risky option off the table before anyone has to decide.
Not reporting incidents
The most damaging behavior is silence. After an employee clicks something and senses it was wrong, fear or uncertainty keeps them silent. That delay is the whole problem. The Verizon 2025 DBIR found the median time from phishing delivery to a click is 21 seconds, while the median time to report it is 28 minutes. Attackers get a head start measured in real damage.
A blame-heavy culture guarantees under-reporting, because nobody volunteers for punishment. As Hoxhunt's human risk team put it: "A click isn't a failure, but following it up with silence is." That silence turns a small mistake into a major breach, which makes reporting a behavior your program has to design for on purpose. The next section is about exactly that.
Building a reporting culture
Under-reporting traces back to fear and a lack of psychological safety. Amy Edmondson, the Harvard professor who defined the term, describes psychological safety as the belief that you won't be punished or humiliated for speaking up about a mistake. Without it, people hide clicks. With it, they raise their hand fast enough for you to act.
Building that culture is concrete work, and it comes down to a few moves:
-
Give people one obvious reporting channel, such as a report button in email or a single address everyone knows.
-
Acknowledge every report quickly, so the person hears back with a clear response.
-
Treat a reported click as a success worth thanking someone for.
Punitive approaches stay popular because they feel decisive, and 81% of security professionals in SoSafe's Human Risk Review still believed reprimanding users changes behavior. The behavioral science disagrees. Positive reinforcement strengthens habits faster and holds longer than punishment, which mostly teaches people to go quiet. The payoff justifies the effort: a workforce that reports turns every employee into an early-warning sensor. The Verizon 2026 DBIR found that recently trained employees report phishing at 21%, four times the 5% rate of untrained staff, which is the difference between catching a campaign early and finding out after the damage is done.