top of page

Mindfulness and Cybersecurity: Why Slowing Down Matters for Small Businesses

Oct 19, 2023
16 min read

Updated: Aug 27

Mindfulness and cybersecurity for small businesses, encouraging employees to pause, think and verify before responding to suspicious requests.

Updated August 2026: I originally published this article in 2023 from a much more personal perspective about mindfulness and staying safe online. A lot has changed since then, both in cybersecurity and in the work I do with small businesses. Authentication has changed, current password guidance looks different from what many of us were taught years ago, AI has become part of everyday business operations, and I have spent considerably more time working directly with Microsoft 365 security, compromised accounts, phishing, device management and incident response. I wanted to come back to this article because the original idea still matters, but I look at it differently now. Attackers often benefit when someone is rushed, distracted or reacting automatically, and I have come to think that good cybersecurity needs to account for the people who actually have to work with all of these security controls every day.


When I talk about mindfulness and cybersecurity, I am not suggesting that mindfulness is a cybersecurity control or that an employee can somehow think their way around a technical attack. Businesses still need the appropriate technical protections for their environment, including identity security, endpoint protection, email security, backups, device management, patching and properly configured networks. What interests me is what happens when those technical protections meet the person sitting in front of the computer.


An employee may receive an unexpected MFA prompt while answering emails and talking on the phone, someone in accounting may receive an urgent message saying a vendor changed its banking information, or an employee may click a Microsoft 365 sign in link because they are trying to get through an overflowing inbox before a meeting. Those are normal work situations, and attackers know how useful urgency, distraction and routine can be.


Sometimes the safer response is simply to slow down long enough to ask whether what is happening makes sense. If you were not trying to sign in, why are you receiving an MFA request? If a vendor has used the same banking information for years, why did it suddenly change by email? If Microsoft is supposedly warning you about your account, why are you being asked to sign in through a link in an unexpected message? That pause does not replace the security technology around the employee, but it can give the employee enough time to recognize that something is unusual and allow the controls and procedures already in place to do their jobs.


What Does Mindfulness Have to Do With Cybersecurity?

When I originally wrote this article, the connection between mindfulness and cybersecurity was largely something I was thinking about from personal experience. There is now research looking more directly at that relationship. A 2025 peer reviewed study published in Information & Management examined mindfulness, information processing and phishing identification, including how people process information when deciding whether something is legitimate. I would not take that research and turn it into a claim that mindfulness prevents phishing, because that is not what it establishes. What I do think it reinforces is something very practical for a small business: attention and decision making matter when employees are interacting with suspicious messages, authentication requests and other situations where an attacker is trying to get them to act.


Employees are also making those decisions while doing their actual jobs. They are not sitting in a quiet security training room carefully analyzing every email. They may be processing payroll, answering a customer, trying to finish a proposal, working from a phone between appointments or dealing with several problems at once. That is one reason I think security awareness needs to go beyond teaching people to look for spelling mistakes or suspicious attachments. Employees need to understand which situations deserve an intentional pause, especially when a request involves credentials, money, sensitive information or access to company systems. The business also needs procedures that make it easy for an employee to verify something without feeling like they are creating a problem by slowing down.


Phishing Often Depends on Getting Someone to React

Phishing and Business Email Compromise can take many forms, and the convincing attacks do not always look like the stereotypical scam email. A message may appear to come from Microsoft, a vendor, a customer, an executive or another employee. In some cases, an attacker may be using an actual compromised account, which means the message can come from an address the employee already knows and may even fit into an existing conversation. That is why I do not want an employee's entire phishing defense to depend on whether an email “looks fake.”


Urgency is often what makes these attacks effective. A message says a password is about to expire, a document needs to be reviewed immediately, an MFA request needs to be approved, a payment needs to go out before the end of the day or a vendor has changed banking information and the next payment needs to use the new account. When the request is presented as urgent, the employee may feel that stopping to verify it will delay someone else's work. I would rather build verification into the business process so that the employee does not have to make that judgment alone. If banking instructions change, independently verifying that change should simply be part of the process. If an unexpected MFA prompt appears when the employee is not signing in, the employee should know not to approve it and should know exactly who to contact.


That approach is also consistent with current Federal Trade Commission guidance for small businesses, which emphasizes pausing and independently verifying suspicious requests. The point is not to make employees distrust every email they receive. It is to make verification normal when the potential consequence of getting the decision wrong is significant.


Security Fatigue Can Work Against What We Are Trying to Protect

There is another side of this that I think deserves more attention. Businesses can create so much security friction that employees begin treating security as an obstacle they need to work around. If someone is constantly being asked to change passwords, approve authentication prompts, dismiss warnings, remember complicated rules and navigate security processes nobody has clearly explained, some of those actions eventually become routine. Once that happens, the employee may stop thinking about what the prompt or warning actually means.


I do not want an MFA prompt to become something an employee automatically approves because they see them all the time. I want an unexpected MFA prompt to get their attention. I do not want employees ignoring every security warning because they have been conditioned to click through dozens that never seemed important. I also do not want someone hiding the fact that they clicked a suspicious link because the company's security culture has made them more afraid of being blamed than concerned about reporting the incident quickly. The goal is not to remove meaningful security controls in the name of convenience. My goal is to make the important controls strong and understandable while eliminating unnecessary security habits that create friction without providing enough benefit to justify it.


Password policy is a particularly good example because current guidance has changed in a way that reflects some of these human behavior problems.


Password Advice Has Changed

For years, many businesses were told that good password security meant forcing employees to create a new password every 60 or 90 days while requiring an uppercase letter, lowercase letter, number and special character. Current NIST guidance has moved away from those arbitrary periodic password changes and traditional composition rules. NIST SP 800 63B 4 says passwords should not be changed periodically unless there is evidence of compromise or another reason the credential needs to be changed, and it places much more emphasis on password length and screening passwords against commonly used or compromised values.


There is a very practical reason that makes sense to me. If someone has to invent a new password every few months, eventually they need a system for remembering all of those changes. A password based on a season and year may simply become the next season and year when the expiration message appears. The password technically changed, but the rule encouraged the employee to develop a predictable pattern rather than meaningfully improving the credential. NIST discusses this problem directly, which is why I think it is important for businesses to distinguish between a security practice that feels stricter and one that current guidance actually supports.

Older password approach

Current direction

Force password changes every 60 or 90 days

Do not require arbitrary periodic changes. Change passwords when there is evidence of compromise or another legitimate reason.

Require uppercase letters, lowercase letters, numbers and special characters

NIST has moved away from mandatory composition rules and puts greater emphasis on password length.

Expect employees to memorize many complex passwords

Allow and support password managers so employees can use unique credentials without memorizing every password.

Accept a password simply because it meets complexity rules

Screen new passwords against commonly used, expected and compromised passwords.

Rely heavily on passwords to protect important accounts

Use MFA and consider phishing resistant authentication methods such as passkeys where appropriate.

The table above summarizes the direction of current NIST password guidance along with my broader security recommendations. It does not mean every small business has exactly the same password or authentication requirements. Regulatory obligations, contractual requirements, cyber insurance requirements, application limitations and other factors may affect what a particular business needs to implement.


For passwords that employees need to remember, my preference is to encourage longer, unique passwords or passphrases rather than complicated password puzzles. A password manager can also help employees use unique credentials without having to memorize a different complex password for every business application. Passwords still need to be protected appropriately, and a long password does not eliminate the need for MFA on important business systems, but the larger lesson is useful: good security does not have to make the employee's job unnecessarily difficult to be effective.


Passkeys Are Changing the Authentication Conversation

Passwords are also no longer the only way we should be thinking about authentication. Microsoft and other major platforms are moving toward phishing resistant authentication methods, including passkeys. Unlike a traditional password that an employee types into a website and that can potentially be captured through phishing, passkeys use cryptographic credentials tied to the legitimate service. That changes the attack problem because there is no reusable password for an employee to accidentally hand over to a fake login page in the same way.


This is becoming particularly relevant for businesses using Microsoft 365 because Microsoft is actively changing the authentication experience in Microsoft Entra ID. I have already been implementing passkeys for clients where they make sense, and I go into the current Microsoft changes and what they mean for small businesses in Goodbye Passwords, Hello Passkeys: A Friendlier and Safer Way to Sign In.


What I like about the direction of passkeys is how well it fits the larger point of this article. Stronger security does not always have to mean adding another complicated step for the employee. Sometimes we can improve security by changing the authentication method itself so the unsafe action becomes harder to perform while the legitimate sign in experience becomes easier. That is the kind of security design I would rather work toward.


MFA Fatigue Is a Good Example of Why Attention Still Matters

Multi factor authentication remains an important security control, but employees also need to understand what an authentication request means. Attackers have used repeated push notifications in an attempt to get someone to eventually approve one of them, a technique commonly described as MFA fatigue or push bombing. Someone who is busy, distracted or simply tired of seeing notifications may approve a request without stopping to think about whether they actually initiated the sign in.


Microsoft has made changes to Microsoft Authenticator that help address this problem, including number matching for push notifications. Instead of receiving a simple approval request that can be accepted with a tap, the user matches the number displayed during the sign in process. That makes accidental approval more difficult, but the employee still needs to understand the most important part of the process. If you are not trying to sign in, you should not approve the authentication request.


I also want employees to report unexpected authentication activity rather than simply dismissing it and going back to work. An unexpected MFA request does not automatically prove that an account has been compromised, but it may be useful information for whoever manages the environment. The same principle applies to password reset notifications and other account activity the employee did not initiate. Security tools can generate valuable signals, but somebody has to recognize that the signal matters and know what to do with it.


Cybersecurity Awareness for Small Businesses Should Teach Employees When to Stop and Ask

I do not expect employees to become cybersecurity analysts, and I do not think good security awareness training should make them feel like that is their responsibility. What I want employees to understand is when something is unusual enough that they should stop and ask for help. Some of the situations I want employees to recognize include:

  • An MFA request appears when they are not trying to sign in.

  • A vendor suddenly sends new banking or payment information.

  • An unexpected Microsoft 365 login page asks for credentials.

  • Someone asks for a password or authentication code.

  • A message from management contains an unusual request involving money or sensitive information.

  • A computer begins behaving strangely.

  • A password reset notification arrives that the employee did not request.

  • An email, text message or phone call creates unusual urgency around money, credentials or confidential information.

The employee does not need to determine whether the event is malicious before reporting it. In fact, I would rather have someone report something that turns out to be harmless than decide on their own that it probably does not matter. That is where security awareness and incident response begin to overlap. Employees need to know what suspicious behavior can look like, but the business also needs to give them a clear reporting path.


My Small Business Incident Response Checklist is designed to help businesses work through those questions before something happens. Who should employees contact? Who is the backup contact? Who is authorized to make technical decisions? Where is the cyber insurance information? How will the company communicate if its normal systems are unavailable? Those answers should not have to be invented while an employee is already worried that something has gone wrong.


Employees Should Be Comfortable Reporting a Mistake Quickly

One of the human factors I care about most is what happens after an employee thinks they may have made a mistake. If someone clicked a suspicious link, entered a password, approved an authentication request they did not recognize or opened something they should not have, I want to know about it as quickly as possible.


Embarrassment can become a security problem when it delays reporting. If employees believe they are going to be blamed or punished simply for saying that something happened, they may wait to see whether anything bad occurs before telling anyone. That delay can make the technical response more difficult because account activity, malicious sessions or other access may continue while everyone assumes the environment is fine.


The immediate goal when an employee reports a possible incident should be to understand what happened and determine what needs to be protected. That does not mean businesses can never hold employees accountable for deliberately ignoring policies or repeatedly engaging in unsafe behavior. It means the initial incident response should focus on facts and containment rather than blame.


I also encourage employees to describe what they actually observed instead of trying to diagnose the technical problem themselves. “I clicked the link and entered my Microsoft 365 password” gives me useful information. “My mouse started moving by itself around 2:15” gives me something specific to investigate. “I think somebody hacked us” is much less useful because I still need to determine what actually occurred.


If something may already be happening, I go into the immediate response much more deeply in My Small Business Was Hacked. What Should I Do Right Now?.


Payment Changes Are a Good Place to Intentionally Slow Things Down

Some business processes are worth slowing down on purpose, and changes involving money are near the top of that list. If a vendor emails new banking instructions, taking a few additional minutes to independently verify the change is worth the inconvenience. The same is true when someone claiming to be an owner, executive, client or vendor sends an unusual request involving money, payroll information or other sensitive information.


I do not want the accounting employee to have to decide whether an email “looks legitimate enough” to send a significant payment. I would rather the business establish a verification procedure before that situation happens. That might mean contacting the vendor through a known phone number or another trusted communication method rather than using the contact information provided in the message requesting the change. The exact procedure should fit the business, but the important part is that verification becomes normal rather than something an employee has to justify.


This is another place where mindfulness and cybersecurity meet in a practical way. The safest employee is not necessarily the person who can identify every technical characteristic of a sophisticated Business Email Compromise attempt. It may simply be the person who recognizes that a request is unusual enough to stop the normal workflow and follow the company's verification process.


AI Has Added Another Place Where Employees Need Clear Guidance

AI is one of the biggest differences between the business environment when I originally wrote this article in 2023 and the environment I am working in today. Employees may now be using ChatGPT, Claude, Microsoft Copilot, Gemini or AI features built directly into applications the company already uses. They may use AI to draft emails, summarize documents, research questions, analyze information or help with everyday work.

From a security and governance perspective, telling employees to “be careful with AI” is not enough. I want the business to know which AI platforms employees are using, whether they are using personal or company managed accounts, what company information is appropriate to enter, what information should not be entered, whether the AI platform is connected to business systems and who is responsible for approving new tools or integrations. I also do not generalize how every AI platform handles business information because the product, plan, configuration and terms matter.


This connects directly to security fatigue because vague rules create uncertainty. If the only AI policy is “don't put sensitive information into AI,” employees are still left to decide what the company means by sensitive information and which tools the rule applies to. Clear governance gives employees a better chance of making the right decision without having to guess every time they use a new feature.


Good AI governance should help employees understand how to use approved technology correctly rather than relying entirely on restrictions after the technology is already being used.


Better Security Is Not Always More Security Prompts

One of the things I understand differently now than when I first wrote this article is that adding another security control is not automatically the same thing as improving the security of the business. A control needs to address a real risk, it needs to be configured properly and the people using it need to understand what it is asking them to do.


I do not want to force arbitrary password changes simply because that is what businesses did for years. I do not want to generate so many low value warnings that employees learn to ignore every security alert. I do not want to tell accounting to “watch for scams” when we could establish a clear verification procedure for payment changes. I do not want employees receiving MFA prompts without understanding that an unexpected request may be something they need to report. I also do not want employees trying to remember a complicated incident response procedure that has never been documented or discussed.


None of that means reducing security standards. In many cases, the better approach is actually stronger. Passkeys can provide better phishing resistance than passwords while potentially making sign in easier. Centralized device management can give the business better control over company devices instead of placing responsibility entirely on the employee. A defined payment verification procedure can be stronger than repeatedly reminding employees to look for suspicious emails. A documented incident response process can be far more useful than expecting everyone to remember what they heard during annual security training.


The goal is to put the right friction in the right places.


What Should a Small Business Do About Security Fatigue?

I would start by looking at the security experience from the perspective of the people who actually have to use it. Where are employees being asked to make security decisions? Which warnings actually require action? Are they receiving authentication prompts they do not understand? Are password requirements based on current guidance or simply policies that have been carried forward for years? Does the business provide a password manager? Are stronger authentication methods such as passkeys appropriate for the systems being used?


I would also look beyond authentication. Do employees know how to verify an unusual payment request? Do they know what to do if an unexpected MFA prompt appears? Do they know which AI tools are approved and what company information can be used with them? Do they know exactly who to contact if a computer begins behaving strangely or if they think they clicked something suspicious? Most importantly, when someone does report something, does the business have a process for responding?


Those questions fit into the broader security environment I discuss in Small Business Cybersecurity: What Should You Actually Have in Place?. The technology still matters. MFA, endpoint protection, backups, email security, encryption, device management, network security and incident response all matter. The human side should reinforce those protections rather than being expected to compensate for technical controls that were never properly implemented.


Mindfulness Is Not a Security Product

Because of the title of this article, I want to make one distinction particularly clear. Mindfulness will not replace MFA, patch a computer, configure Microsoft Defender, encrypt a stolen laptop, create a backup, secure a firewall or investigate a compromised Microsoft 365 account. Those are technical responsibilities that still require appropriate tools, configuration, management and expertise.


What slowing down can do is give someone enough time to notice that something does not make sense. Why am I receiving this MFA request when I am not signing in? Why did this vendor suddenly change banks? Why is Microsoft supposedly asking me to log in through an unexpected email? Why is someone asking me for my authentication code? Why does this payment have to happen in the next five minutes? Why am I about to upload a client document into an AI platform I have never used before?


Those questions create an opportunity for the security controls and business procedures already in place to work. The employee can decline the authentication request, call the vendor, report the email, contact IT or check the company's AI policy rather than automatically continuing with whatever the message or application asked them to do.

That is the role I see mindfulness playing in cybersecurity. It is not the defense itself. It can be the moment that gives the defenses around the employee a chance to work.


Cybersecurity Is About People Too

The technology side of cybersecurity has become considerably more sophisticated since I first published this article in 2023. We have stronger identity controls, better authentication methods, centrally managed endpoint security and device management, more capable email protections and much better visibility into what is happening inside many business environments. We can monitor sign ins, manage devices remotely, encrypt information, segment networks, protect cloud identities and build more resilient backup and recovery strategies.


But employees still have to work inside that environment every day. That is why I do not think good cybersecurity means adding every possible security control and hoping employees tolerate it. The controls need to address real risks. The processes need to make sense. Employees need to understand the decisions that actually matter, and when something unusual happens, they need to feel comfortable stopping, asking questions and reporting it.


Sometimes, a few extra seconds of attention are worth far more than another rule nobody understands. That was the idea behind the article I originally wrote in 2023. After revisiting it in 2026, I think the idea still holds up. What has changed is how much more clearly I now see the relationship between the technology, the business processes and the people who have to use both.


ADDITIONAL RESOURCES

National Institute of Standards and Technology: NIST SP 800 63B 4, Digital Identity Guidelines: Authentication and Authenticator Management

Current NIST authentication guidance covering password length, compromised password screening, password managers, password changes and authentication requirements.https://csrc.nist.gov/pubs/sp/800/63/b/4/final


NIST: SP 800 63B 4 Password Requirements and Usability Considerations

Current NIST guidance covering password length, password composition rules, periodic password changes, compromised password screening and support for password managers.https://pages.nist.gov/800-63-4/sp800-63b.html


NIST: How Do I Create a Good Password?

Plain language NIST guidance on longer passwords, passphrases, password managers and MFA.https://www.nist.gov/cybersecurity-and-privacy/how-do-i-create-good-password

Microsoft Learn: Microsoft Entra Authentication Overview

Microsoft guidance on authentication methods, including phishing resistant authentication options such as passkeys, Windows Hello for Business and FIDO2 security keys.https://learn.microsoft.com/en-us/entra/identity/authentication/overview-authentication


Microsoft Learn: Passkeys by Default and Retirement of Microsoft Provided SMS and Voice Authentication

Microsoft's current guidance and timeline for changes to passkeys, SMS and voice authentication in Microsoft Entra ID.https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement


Microsoft Learn: Number Matching in Microsoft Authenticator

Microsoft documentation explaining number matching for Authenticator push notifications.https://learn.microsoft.com/en-us/entra/identity/authentication/how-to-mfa-number-match


Federal Trade Commission: Cybersecurity for Small Business

FTC cybersecurity guidance covering phishing, employee awareness, authentication, data protection and other security practices for small businesses.https://www.ftc.gov/business-guidance/small-businesses/cybersecurity


Federal Trade Commission: Cybersecurity for Small Business, Phishing

FTC guidance on recognizing phishing attempts, verifying suspicious requests and helping employees respond appropriately.https://www.ftc.gov/business-guidance/blog/2018/11/cybersecurity-small-business-phishing


Bera, D. and Kim, D.J.: The Nexus of Mindfulness, Affect, and Information Processing in Phishing Identification

A 2025 peer reviewed study published in Information & Management examining relationships among mindfulness, information processing and phishing identification.https://www.sciencedirect.com/science/article/pii/S0378720625000138

Comments


bottom of page