Digital defence in 30 minutes: a crash course for non-technical managers
Most digital fraud does not start with a brilliant hack. It starts with a rushed click, a shared password in a group chat, or a polite email that asks finance to “just update the bank details.”
You do not need an IT degree to stop most of it. You need a short set of habits your whole team can follow — and a culture where pausing is allowed.
This guide is for owners, finance leads, and managers who want practical defence, not buzzwords.
Why “I’m not technical” is not a free pass
Attackers aim at people who approve money, reset access, or help a colleague with a login. One bad moment can cost more than a year of software licences.
Good defence is rarely exotic. It is slowing down the moments that matter: payments, password changes, and unexpected urgency.
Run this in one 30-minute meeting
Print the five rules below. Walk through them once. Assign an owner for each. That is enough to start.
1. Turn on two-step login where money and mail live
After the password, require a second check — usually a phone prompt or authenticator app.
Turn it on for work email, banking, accounting tools, and shared drives. Prefer an authenticator app over SMS codes when you can; SMS can be intercepted more easily.
If someone says two-step login is “annoying,” remind them that reconstructing a stolen payment is worse.
2. Give every person their own login
A single “company password” shared on chat is a gift to scammers. When one person leaves, or one phone is lost, everyone is exposed.
Use a password manager so long, unique passwords are easy. Never reuse the email password on banking or payroll. If a tool only offers one shared account, limit who knows it and change it when someone leaves.
3. Never change bank details from email alone
If a supplier, “CEO,” or staff member asks to change banking details by email, stop.
Call a number you already trust — from your supplier file or HR record, not the number in the message. Have a second person approve before anyone updates records or pays.
Urgency is part of the scam. “Pay today or interest applies” is a reason to slow down, not speed up.
4. Teach a simple phishing “pause check”
Before anyone clicks a link or opens an attachment that asks for login, money, or secrets, they ask three questions:
- Does the sender’s address look slightly wrong?
- Are they rushing me (“do this in ten minutes”)?
- Would this normally arrive another way — a known portal, a standing process, a familiar phone call?
If anything feels off, verify with a known contact first. Being wrong about a false alarm is cheap. Being wrong about a real scam is not.
5. Keep a one-page “first hour” card
When something goes wrong, people freeze. Write the phone numbers down in advance:
- Your bank’s fraud line
- Who resets email and system access inside the company
- Glial or your IT partner
- Your lawyer, if you have one
Speed and proof beat panic. Knowing who to call removes half the chaos.
Ten minutes a week keeps this alive
- After someone leaves, remove their email and admin access the same day.
- Glance at mailbox forwarding rules — scammers love a hidden redirect.
- Confirm two-step login is still on for finance and leadership accounts.
If something already feels wrong
Do not tidy the mailbox first. Keep the emails and screenshots. Change passwords from a device you trust. If money moved, call your bank the same day and get a reference number.
When the trail is messy — several mailboxes, odd logins, conflicting stories — a structured review helps. Glial’s Digital Fraud Investigations service turns scattered messages into a clear timeline and next steps. We do not promise fund recovery, and we do not replace your bank, lawyer, or the police.
Need help now?
Request a confidential assessment. Typical first response within one business day for urgent cases.
Start enquiry