All articles
Employee Fear Gives Attackers Their Biggest Head Start. Psychological Safety Takes It Back.
Cybersecurity strategists Jothi Dugar and Ty Hughes explain how a leader's first reaction to a reported mistake sets the length of the attacker's head start.

Make The Security Digest one of your go-to sources on Google
An organization that humiliates people for honest mistakes is actively helping the attackers. It becomes a vulnerability when people fear judgment when they make a mistake.
Security awareness programs are designed to lower the number of employees who fall for a phishing message. Generative AI now supports 15 distinct attack techniques that make those messages hard to distinguish from the real thing. The time between an accidental click and the report is a number a security team can still move. Few programs measure it, and an attacker spends every minute of that delay working deeper into the environment. Employees often set the length of the delay based on the reaction they expect when they walk into a manager's office.
Cybersecurity strategists Jothi Dugar and Ty Hughes have spent several years pressing security leaders to count culture among their operational controls. Dugar, known professionally as JoJo D., 'The Chaos Guru,' is a cybersecurity executive, strategist, and international bestselling author with more than 25 years of experience leading and advising across cybersecurity, technology, and organizational transformation. Hughes, known in the field as "The AI Alchemist," is a transformational technologist and a President's Management Council Interagency Rotation Fellow who has spent close to two decades guiding organizations through technical and human complexity. Both treat the delay between a mistake and its disclosure as a security measurement. Their work is part of a broader approach they describe as Cyber Wellness, which treats human and organizational conditions as part of cybersecurity resilience rather than separate from it.
"An organization that humiliates people for honest mistakes is actively helping the attackers. It becomes a vulnerability when people fear judgment when they make a mistake, and that causes them to either hesitate, not bring things to the surface, try to conceal their mistakes, or feel like they're alone and try to fix it by themselves, which inadvertently gives an attacker more time to do more damage," says Dugar. Shame never appears in a vulnerability scan, and the work of closing it belongs to the leaders who decide how a disclosure gets received.
The room is watching
A staff member who walks into an office to admit a click has already made a hard decision under pressure, and the response they get teaches everyone else what that walk will cost them. Hughes counts the exchange as part of the incident response itself. "In those precious few moments, it could be something as simple as resetting an account or segmenting something off," he says. "If your staff are hesitant to bring you bad news, does that turn from minutes to hours, from hours to days, at which time the adversaries advance across your infrastructure?" No detection tool has anything to work with until someone says the words out loud, which means the opening hour of the response belongs to whoever is deciding whether to speak.
Hughes has watched leaders answer a disclosure by escalating their own reaction first. The reaction looks like urgency at the time, and the cost lands on the next incident. "That shame in the very beginning is something that can be very impactful, advancing the adversary without the adversary even doing anything additional from a technology perspective, other than letting human nature take its course," Hughes notes. The pattern holds even when the staff involved are competent, motivated, and fully briefed on the policy.
Organizations asking why an alert went unread usually land on a queue, a competing priority, and whatever the analyst carried in from home that morning. Dugar puts that workload next to the attacker's day, where one person works a single target and nothing competes for their attention. "Our adversaries out there, they don't necessarily defeat intelligence," she explains. "They exploit what's already there." People reviewing a missed alert already know it turned into an incident, and that makes the warning signs look obvious. "We want to try to take the context away from hindsight masquerading as expertise to a topic of how can we set our employees up for success," Dugar adds.
The naughty list
Most phishing programs are commissioned as training, and Hughes has seen plenty run with results circulated internally and names attached. The exercise still produces a click rate, and that number still reaches leadership as a security result. "Simulations can help teach recognition and reporting, but they can become really harmful when they surprise, embarrass, or rank or publish who clicked on something," Hughes explains. "A simulation that destroys trust might be a successful phishing campaign, but it's a failed exercise."
Hughes looks at the same result sheet differently from the people who commissioned it.
Click rates are easy to count, but reporting behavior is more valuable.
- Ty Hughes, "The AI Alchemist," Cybersecurity Strategist
"I'd rather know when someone clicks on something and why they clicked on it and be able to ascertain, is there something particular about this construct of an email or this construct of a document that really inspired staff to click on it. And if that's the case, then we need to look at it and educate the rest of the staff, educate the broader enterprise," he adds. Time to report, the quality of the first information a team receives, and whether anyone reports at all sit outside the summary most programs hand to leadership.
A clean sheet carries its own ambiguity. "There are times where you have phishing campaigns in place and you get back, oh, no one clicked on it," Hughes adds. "Does that mean the organization is getting smarter, or are they just so used to getting up on the phishing naughty list that if this doesn't come from the person I directly report to, we're just not clicking on it?"
Dugar has watched the same programs arrive at security teams from several levels above them, already designed and carrying a remediation list. The team enforcing the program had no hand in building it, and employees aim their frustration at whoever delivers the news. "The cyber teams get a report like, 'Oh, here are your repeat clickers, and you now must mandate that they take the training again,'" Dugar notes. "They're more worried about the training non-compliance than people actually learning what to do, what not to do, and what to look out for."
Thank you for telling me
Hughes has a specific opening line in mind for the manager who receives bad news, and he treats the wording as part of the response procedure. "Imagine the manager who says, 'Thank you for letting me know. Thank you for bringing this to my attention. Now let's take some actions,'" he says. "Immediately we go into, 'All right, what do we know and how do we lessen the impact?'" From there Hughes follows a sequence he has run many times, informing the people who need to know and keeping the escalation proportionate to the size of the event.
A second conversation follows once the incident closes, and Hughes uses it to settle the employee back into the team. He keeps a story ready for the occasion. "Let me tell you about the time early in my career where I did something really similar, and let them know that you're not perfect either and that you got through it then, you're going to get through it now," Hughes adds. "But hey, this is what I really appreciated. It was brought to my attention early. It allowed us to go through and take the necessary cyber security related steps." The prevention discussion comes last, once the person across the desk has stopped bracing for it.
Dugar identifies a gap in most response plans at exactly this point. Teams drill the technical sequence until it runs without conscious thought, and nobody drills what happens to the employee who triggered the call. She brings a human-centered incident response technique into those first minutes, and it holds the conversation to what can be verified. A misconfiguration exists or it doesn't, and the question of who created it can wait until the environment is stable. "The managers that just jump to blaming someone or a team or anyone or the situation are choosing their own personal emotional satisfaction over the actual containment of the incident," says Dugar. "If we just focus on the raw facts of the matter and being calm and neutral about it, and really focusing on stabilizing the incident but also stabilizing the people involved in the incident, then you're able to get much faster performance."
Consequences worth publishing
Security leaders hear the psychological safety argument and reach for the obvious objection, which is that a workforce facing no consequences learns nothing. Hughes takes the objection seriously enough to answer it head on. "Psychological safety does not remove consequences for reckless or intentional conduct," Hughes says. "What it really does and what it really means is your staff feel safe enough to bring you the bad news." What changes is the reception an employee gets for arriving early with incomplete information.
Most organizations run awareness training once or twice a year and never publish what happens to the person who fails it. Employees end up guessing at their own exposure in the moment they have to decide whether to speak. "If you know the consequences and they're predictable and they're proportionate and they're fair, people know what to expect," explains Dugar. "We're not trying to say don't hold anyone accountable, but we do need to make sure people know ahead of time what the accountability looks like." She also holds that no program can promise a workforce will catch everything, given how convincing the current generation of phishing messages has become.
Waiting for a complete picture is the most defensible-sounding way to lose a containment window. A leader who already knows something is developing can absorb bad news an hour later, and a leader who hears it first from another department cannot. "People tend to wait until the last second to confirm all the facts of the matter before they report it to leadership," Dugar says. "Tell your staff that it's okay if you don't know all the facts. Just tell me what you know so far. I'd rather know sooner than later."
An organization where employees can report honest mistakes without fear of humiliation or disproportionate punishment hears about problems from the people closest to them, and early information from that person is the most reliable way to shorten a breach. "Leaders who equate psychological safety with weakness, they misunderstand what leadership is and they misunderstand what security is," Hughes concludes.






