Thomas Barnett

All issues

The Everyday Habits Putting Businesses Most at Risk

The Everyday Habits Putting Businesses Most at Risk

When people think of cyber attacks, they picture hooded hackers, flashing red warning lights, and complex code scrolling across a screen.

In reality, most breaches don’t start with some sophisticated exploit, they start with us.

The Human Element Behind 80% of Breaches

Research shows that around 80% of data breaches are down to human error.

That might sound like a big, vague number, but the truth is it’s the everyday habits: the quick clicks, reused passwords, and “just this once” moments that open the door.

If there’s one thing I’ve learned from working with small businesses and startups, it’s that people don’t mean to be careless. They’re busy and juggling ten things at once. Security feels like something that’ll “get done later”.

But attackers know that. They rely on it.

Let’s talk about the biggest everyday habits that quietly put companies at risk.


1. Weak Passwords: The Simplest Way In

It sounds obvious, but weak or reused passwords are still the number one cause of breaches.

People underestimate how easy it is for attackers to crack them or how often the same password is used across work and personal accounts.

If your business doesn’t have some kind of password manager or policy, you’re relying on everyone’s memory. And that means the same old “Welcome123” or “CompanyName2024” logins floating around your systems.

It only takes one leaked password to unlock the lot.

A few small changes make a huge difference:


You don’t need to overcomplicate it, just stop making it easy.


2. Phishing Emails: The Number-One Entry Point

If I could hammer home one thing, it’s that phishing emails are the biggest threat to small businesses, hands down.

About nine out of ten cyberattacks start with a phishing email, an email that looks genuine but is designed to trick you into clicking a malicious link, downloading an infected attachment, or giving away information.

The scary part is they look so convincing these days.

Attackers will copy your supplier’s logo, spoof a colleague’s email address, or send a message that looks exactly like an invoice or delivery note.

I’ve seen people who are brilliant at their jobs fall for one because they were in a rush or distracted. It’s not about intelligence; it’s about timing and awareness.

If you take nothing else from this blog: never click a link or open an attachment unless you’re sure where it came from.

When in doubt, pick up the phone or message the sender through another channel. That ten-second check could save you a world of pain.


3. Being Too Relaxed in Public Spaces

A few weeks ago, I was chatting in a coffee shop with Tony Sales, a former fraudster who now works with police and cybersecurity firms to help people understand how criminals think.

As we sat there, he pointed out how easy it would be to steal information from the people around us.

Bags left open, laptops unattended, phones on the table with no eyes on them and devices connected to public Wi-Fi.

Most people simply aren’t paying attention.

We’re not talking about elaborate heists here, just everyday carelessness.

If someone wanted to, they could run a small scanning device near your bag and pick up card or phone signals. Or plug a tiny USB stick into an unlocked laptop.

The opportunities are endless when nobody’s looking.

I’m not saying we all need to live in paranoia. Just be a bit more vigilant. Keep your belongings close. Lock your devices when you step away. Simple things make a difference.


4. Public Wi-Fi: The Hacker’s Playground

Here’s another one that surprises people: connecting to public Wi-Fi without thinking twice.

It’s shockingly easy for someone to set up a fake Wi-Fi hotspot in a café or hotel lobby. They give it a familiar name like “FreeCoffeeShopWiFi”, and once you connect, they can see everything you do.

Logins. Bank details. Even national insurance numbers if you’re filling in forms or using shared tools.

If you’re logging into anything sensitive like emails, cloud dashboards, client data on public Wi-Fi, you’re basically handing that information over to whoever’s watching.


The fix is simple again:


A few extra seconds to connect properly is worth it compared to the damage a leak could cause.


5. Training and Vigilance

If I’m being completely honest, most breaches could be stopped if people just slowed down for five seconds and thought, “Does this feel right?”

Security awareness isn’t about fear; it’s about mindfulness.

Teaching your team how to spot phishing attempts, manage passwords, and stay alert in public spaces gives you the biggest security return for the least cost.

You don’t need fancy tech or million-pound budgets to reduce risk.

You just need people who know what to look for and care enough to pause before they click.

The basics save you 80% of the time.


Cutting Through the Noise

The cybersecurity world can feel like noise: endless tools, buzzwords, and expensive promises.

But at its core, it’s about people.

How we think, how we behave, and how often we let convenience win over caution.

For startups and SMEs, where everyone wears five hats and time is tight, the human element is both the biggest risk and the biggest opportunity.

If you can build a culture of vigilance, one where security isn’t a tick-box but a shared habit, you’ll already be ahead of most businesses.

Cybersecurity doesn’t need to be hard or expensive.

It just needs to be human.


Share
Get the next issue in your inbox
Free, and you can unsubscribe any time.

0 comments

More issues

All 3 →
#2 Oct 20, 2025

Compliance Isn’t the Same as Security

Read issue →
#1 Oct 14, 2025

The Biggest Security Mistake Founders Make (and How to Avoid It)

Read issue →