A manager posts a quick question in a team chat.
They want to share a set of internal project documents with an external partner. Nothing about the request is unusual. The partner is real, the project is active, and several people in the channel already know why the documents are needed.
The manager keeps the decision simple: react with a thumbs-up if you are happy for the documents to be shared.
A few reactions appear almost immediately. Someone else reads the message between two other pieces of work. They recognise the names, understand the project and can see that colleagues have already agreed. They add their own thumbs-up and move on.
There is no obvious warning sign. Nobody has impersonated the manager. There is no suspicious link, strange attachment or urgent demand from an unknown sender. The person has not ignored a rule they know they should follow. They have simply used a familiar action in the way their team normally uses it.
Except the action has quietly changed meaning.
A thumbs-up that usually means seen, fine by me or sounds good has just become part of a decision about who should receive internal information. The physical action is identical. The effort is almost identical. The interface certainly is.
The consequence is not.
That distinction matters because a surprising amount of cybersecurity judgement sits inside actions that are too small to feel consequential. A button takes a second to press. An access request can be accepted while someone is listening to a meeting. A permission can be changed from a dropdown menu, and a document can be forwarded with almost no interruption to the task already under way.
It is easy for the familiarity and size of the action to shape how we interpret the decision. When something takes two seconds and has been done countless times before, there is little to make this particular occasion feel as though it deserves more thought.
Digital systems do not share that sense of proportion. A tiny action can change who has access to information, what somebody is authorised to do, where data can travel or who becomes responsible for what happens next.
The useful distinction, then, is not how difficult the action is. It is what changes after you take it.
The click is small. The change may not be.
Imagine a slightly different situation.
A colleague sends you a link to the project brief in chat. You are already involved in the work, you recognise the colleague, and the document title is exactly what you would expect.
You click it and discover that you do not currently have permission to view the document. The system presents a large, convenient Request access button.
Clicking it feels almost administrative. You were sent the document, so presumably you were supposed to see it. Going back to the colleague can feel unnecessary when the platform has already given you a way to solve the problem yourself.
Requesting access therefore makes perfect sense.
Yet the access boundary may exist for a reason. You might have been sent the wrong version. The document could contain material relevant to only part of the team. Your colleague may simply have assumed you already had access without knowing whether you should.
Being included in the conversation is not necessarily the same as being entitled to everything linked from it.
That difference is easy to see once the situation has been slowed down. It is harder to notice while the work is moving, because the interface has already translated the problem into a simple task: you do not have access; would you like to request it?
The system is helping you complete the action. It is not necessarily helping you decide whether the change should happen at all.
This is where routine becomes important.
People have to use familiarity to work efficiently. We could not sensibly reconsider the full implications of every click, message, document and system prompt we encounter. Most familiar actions are familiar precisely because we have completed them successfully many times before, and that experience allows us to keep work moving without exhausting our attention on every minor step.
The difficulty is that the meaning of an action can change while the action itself remains familiar.
The thumbs-up still looks like a thumbs-up when it becomes an approval. The access button still looks like a normal platform control when it changes who can reach information. A familiar name remains familiar even when the request attached to it carries a different level of authority or consequence.
This is why telling people simply to “pay more attention” does not get us very far. Attention is finite, and ordinary work constantly competes for it. More importantly, the person may have no obvious reason to allocate extra attention to that moment in the first place.
Nothing has yet told them that this particular two-second action deserves ten seconds.
A better question than “does this look suspicious?”
A lot of conventional security advice depends on recognising that something looks wrong.
That remains useful when there is something unusual to notice. It is much less useful when the request is legitimate, the person is trusted and the task itself is perfectly normal.
The manager may genuinely want the documents shared. Your colleague may genuinely want you involved in the project. The access request may be entirely appropriate. A decision can deserve more attention without anything about it being suspicious.
That gives us another way to identify these moments. Rather than asking people to treat every small action as a cybersecurity exercise, we can become more interested in the ordinary actions that change something meaningful.
Does the action change who can see or use information? Does it create a new permission or remove an existing boundary? Does it turn an informal conversation into an approval? Does it move information somewhere new, commit the organisation to something or make an action harder to reverse?
Those questions focus attention on the consequence of the decision rather than requiring someone to detect a threat first.
Consider the thumbs-up again. The problem is not that emoji reactions are inherently insecure. In a busy team, they can be a perfectly sensible way to acknowledge information, test agreement or keep a conversation moving without filling the channel with repeated replies.
The difficulty appears when the same convention starts carrying decisions that require more clarity than the convention can provide.
If a thumbs-up sometimes means I have seen this and sometimes means I authorise this information to be shared externally, the person has to infer which meaning applies from the surrounding conversation. The significant part of the decision is less visible than the mechanism used to record it.
The same principle applies to access. A Request access button is useful because it removes friction, but low friction is not automatically the right design for every decision involving information. If the person granting access cannot easily see why it is needed, what the requester is working on or which version of a document they require, they may be making a meaningful decision with very little meaningful information.
At that point, the question becomes bigger than whether an individual remembers to pause. It becomes a question about how the work itself has been organised.
Make consequential decisions visible
There is a temptation in cybersecurity to solve problems like these by adding another instruction: check before sharing, verify access, think before you click, be cautious when approving requests.
None of those instructions is inherently wrong. They simply leave the hardest part unresolved. The person still has to recognise when the ordinary action in front of them deserves a different level of judgement.
That responsibility cannot sit entirely with the individual.
If an organisation uses an informal reaction to authorise consequential actions, it can decide which decisions need a clearer form of approval. If staff routinely make access decisions without enough context, the access process can make the owner, purpose and scope clearer. If verification adds so much friction that people reasonably avoid it during busy work, the verification route itself deserves attention.
Management signals matter as well. Someone who pauses before granting access may add a minute to a task that another person wants completed now. If the clearest measure of good work is responsiveness, that pause can feel like poor performance even when policy says that checking is important.
People notice what work rewards. An organisation cannot reasonably ask employees to make careful judgements while repeatedly arranging work so that careful judgement looks like unnecessary delay.
Training has a role here, but it needs to operate at the same level as the decision.
Knowing that permissions matter is useful. Recognising the moment when an apparently ordinary permission deserves closer attention is different. Teams need opportunities to examine why the quick response felt reasonable, what changed because of it and where a proportionate check could fit without turning collaboration into bureaucracy.
For one person, that might mean noticing that being sent a document does not automatically establish a need for access. In another situation, it might mean distinguishing acknowledgement from authorisation, or confirming the person and document before changing a permission while a meeting is competing for attention.
The practical change can be very small. What matters is attaching the pause to the significance of the change rather than to a vague sense that something might be dangerous.
That keeps the response proportionate too. Nobody needs to investigate every thumbs-up, scrutinise every shared document or treat familiar colleagues as potential threats. Most routine work should remain routine.
What deserves more deliberate attention are the points where an ordinary action alters access, authority, information or control.
Once those points are visible, the organisation can decide what level of checking makes sense. A low-impact change may need little more than a moment of deliberate thought. Something involving sensitive information, financial authority, external access or an action that is difficult to reverse may justify clearer confirmation through an appropriate route.
The check should fit the consequence. Where the correct route is awkward, slow or unclear, that is useful information about the system rather than evidence that somebody simply needs another reminder to be careful.
There is a wider reason this matters.
When we look back at a decision after something has gone wrong, its significance is obvious. We already know which permission mattered, which approval should have been clearer and which piece of information travelled further than intended.
The person making the original decision did not have that advantage.
They saw a thumbs-up. They saw a Request access button. They saw a few seconds of admin sitting inside work that was already moving.
Better cybersecurity judgement means making the significance of those moments easier to recognise before hindsight makes it obvious.
So when an apparently tiny task appears, the most useful question may not be, “Does this look suspicious?”
It may simply be:
What changes if I do this?
If somebody gains access, authority shifts, information moves, a boundary disappears or another person will rely on the decision afterwards, the action may deserve more attention than its size suggests.
The click can stay small. The judgement should not disappear with it.
Director of Training and Development, Cyber Rebels.
Andy Longhurst is the founder of Cyber Rebels and a cybersecurity practitioner and educator focused on how risk actually shows up in real organisations. His work sits at the intersection of digital safety, education, and practical risk management — helping teams understand not just what policies say, but what happens in the moments where decisions are made under pressure.
With a background spanning adult education, web development, and technical consultancy, Andy specialises in translating complex security concepts into clear, usable understanding. Rather than focusing solely on tools or compliance frameworks, his approach centres on human behaviour, judgement, and the systems that shape everyday choices.
He delivers live, interactive cyber awareness training for organisations of all sizes, from small businesses and education providers to public-sector teams and larger organisations operating in complex risk environments.
Outside of delivery, Andy spends his time analysing emerging attack patterns, refining training design, and exploring how organisations can build resilience that holds up in the real world — usually with a strategically sized cup of tea close to hand.
