It’s 4:17 on a Friday afternoon.
An employee receives an email that appears to be from the firm’s principal: “Can you send me the updated wire instructions before you leave?”
The name is right. The tone sounds familiar. And with everyone trying to wrap up the week, the easiest thing to do is simply respond. There’s only one problem: the principal never sent it.
Your IT partner can put strong protections in place, but they can’t stop every bad click, rushed reply, or split-second call. Some decisions still come down to whether an employee knows what to do when something feels off.
The assumption that leaves firms exposed
Most advisors believe cybersecurity lives somewhere behind the scenes — the IT team has tools, the computers have protection, someone schedules the updates, cybersecurity is “handled.”
In reality, your defenses are tested every time an employee decides whether to trust an email, link, or request involving client data or firm assets. Those decisions happen every day, across every part of the firm. To truly strengthen your security, your team needs to know what to do when something doesn’t look right.
Technology can’t make every call
Good security tools block a lot of attack attempts before your team ever sees them, but no technology can eliminate every questionable request or make every decision on an employee’s behalf.
Today’s phishing attacks aren’t obvious. They’re built to mimic familiar writing styles, reference custodians and vendors you actually work with, and mirror the rhythm of normal firm communication. When an unusual wire request comes from a “client,” a custodian appears to change instructions mid-transfer, or a team member needs access to a file they’ve never opened before, someone has to decide what happens next — often in an instant.
“Be careful” isn’t a cybersecurity plan
Most firms tell employees to watch out for suspicious emails. But what happens when they find one? Every employee should know:
- Who to contact
- How to verify a request is legitimate
- Not to click links or download attachments
- What to do if they already have
- How to report the issue
Telling everyone to simply “be careful,” without a clear next step, puts the full weight of a high-stakes decision on the person least equipped to handle it in the moment. An employee unsure whether they’re bothering someone may stay quiet. Someone worried about blame for clicking the wrong thing may hesitate to report it. That hesitation is costly — the time lost while someone decides whether to speak up can turn a manageable incident into a much bigger one, with client money or data on the line.
Leadership sets the tone
Responsibility starts at the top, because employees take their cues from leadership. If a principal routinely skips verification steps because they’re in a hurry, the team learns that speed matters more than process. If managers make it uncomfortable to flag suspicious activity, employees stay quiet. If someone gets publicly reprimanded for clicking the wrong thing, everyone learns to hide their mistakes instead of reporting them.
The opposite is also true. When leadership normalizes verification, the team takes it seriously. When someone who flags an unusual request is backed up rather than brushed off, the whole firm operates more carefully.
Cybersecurity works better when everyone knows their role
Back to that employee at 4:17 on a Friday afternoon.
The goal isn’t to make your team paranoid about every email. It’s to make sure that when something feels off, they know exactly what to do, who to ask, and how to verify — before client money or data is at risk. Your team doesn’t need to become cybersecurity experts to help protect the firm. They need clear expectations, good habits, and the confidence to speak up.
Building that kind of security culture takes more than an annual training session. It takes the right safeguards, practical processes, and ongoing guidance — and it’s exactly the kind of documentation the SEC expects to see during an examination.
That’s where the right partner comes in. We help RIAs take the guesswork out of cybersecurity by identifying gaps, strengthening protections, and helping every employee understand the role they play in keeping the firm — and its clients — secure.
Cybersecurity is everyone’s responsibility, but you don’t have to manage it alone. Schedule a 60-minute discovery call with our team to find the gaps in your current approach and how to address them.
Call us at 865-622-9304 or visit our page to schedule yours.

