Training · 4 September 2026 · 10 min read
What would you do? 5 security decisions, played with a room of entrepreneurs
On Thursday we put five real situations to a room of business owners, voting on their phones. Same game here: you choose, the right answer is marked, you learn why the others cost.
ClearSecurity Vision
Thursday, 3 September, a room of about twenty business owners. No slides, no scare tactics. Five situations on the screen, phones out, anonymous vote, then the right answer and why.
Below is exactly the same game. For each question you pick an option, then you see the right answer marked, what is wrong with the others, and what the room chose. Nothing is recorded, there is no score. There are just five decisions you will make, sooner or later, in your own company.
1. The invoice with a new IBAN
A supplier you have worked with for years writes: we changed our bank account, the new IBAN is on the invoice. The invoice looks perfectly normal. What do you do?
A. I pay. It is my supplier, I know them.
Wrong. That trust is exactly what the fraudster is betting on. The email can come from an address that imitates the supplier's, or from the supplier's real account after it was hacked. The money goes to a stranger's account and rarely comes back. Nobody in the room picked this one, which is good news.
B. I reply to the email and ask them to confirm.
Wrong. If you reply to the email, the fraudster is the one who confirms. The fake address is theirs, and if the supplier's account is hacked, they read the reply too. A confirmation over the same channel confirms nothing. Someone in the room picked this one.
C. I call them on the number I already had from before.
Correct. You verify over a channel the email did not give you: the number from the contract, the one you had before. A two-minute call, on every bank account change, no exceptions. And it is not theory: someone in that room had lived through it for real.
2. Passwords
Which is the safest password practice?
A. A complex password (like X7k#Rp2!m), changed every 3 months without exception.
Wrong. That is the rule from fifteen years ago. Forced rotation produces Password1, Password2, Password3 and a sticky note under the keyboard. Complexity does not help if the same password ends up in five places. Current guidance has dropped periodic changes without cause: you change a password when there is a sign it leaked. Someone in the room picked this one.
B. A different password for every account, kept in a password manager, plus two-step verification.
Correct. Three things, together: a different password for each account, kept in a password manager so you do not have to remember them, and a second step at login (a code, an app or a hardware key). Even if one password leaks, the account holds. For Microsoft 365 the steps are in our two-step verification guide.
C. One very strong password, the same everywhere, so you can remember it.
Wrong. A reused password is a single key for every door. Websites get breached every week, and leaked passwords are tried automatically on email, banking, accounting. The first leak opens all of them, however strong the password. In the room, this was the most chosen wrong answer.
3. Your key person leaves
Your key person has resigned. They leave on good terms and work another two weeks. Their accounts?
A. I close them on the last working day, all of them, from a list.
Correct. The important word is "list". You write it on the day notice is given, not on the last day: which accounts they have, which shared passwords they know, which devices carry company email, which forwarding rules sit in their mailbox. On the last day you tick everything off. Without the list you cannot close what you do not know exists. What happens without it is in "The employee who left with the keys".
B. I leave them open for a while after they go, so they can hand things over.
Wrong. "So they can hand over" means a former employee holding the company's keys, and a live account nobody watches anymore. Handover happens while the person is still employed, during those two weeks, from their own account. After the last day the account closes, and whatever is left gets handed over person to person, not through a login. In the room, this option tied with the correct answer.
C. Nothing to close. Several of our passwords are shared anyway.
Wrong, and the most dangerous of the three. A shared password can never be fired: everyone who ever passed through the team knows it. If you have shared passwords, the day someone leaves is the day you change every one they knew. Nobody in the room picked this one. In practice, shared passwords exist in most small companies; people just do not recognise them on a voting screen.
4. The disk dies
The company's files live in one place: on a workstation or on the file server. One morning the disk dies, or everything is encrypted. What saves you?
A. Nothing needed. The equipment is new and good quality, nothing will happen to it.
Wrong. Disks die regardless of what they cost, and ransomware does not ask how old the server is. One place means one point of failure. Nobody in the room picked this one.
B. A separate, automatic, tested backup.
Correct. All three words matter. Separate: not on the same equipment and not permanently on the same network, so it does not get encrypted along with the original. Automatic: whatever depends on a person gets forgotten. Tested: you restore one file at least once and see that it works. An untested backup is still just hope. Almost the whole room got this right. The full rule is in "The 3-2-1 backup rule".
C. Syncing to Google Drive or OneDrive. Everything goes up there anyway.
Wrong, but it is the most common confusion. Sync is a mirror: what gets encrypted below arrives encrypted above, within seconds. Deletions sync too. Version history in Drive or OneDrive sometimes helps, but it was not built for this and it has limits. Sync is for working from several devices; backup is something else. Someone in the room picked this one.
5. Monday morning, everything encrypted
Monday morning: everything is encrypted. On the screen, a message: 5,000 euros in crypto and you get your data back. Without the data, the company stops. What do you do?
A. I pay. 5,000 is less than a week with the company stopped.
Wrong. You pay a criminal who now knows you pay. Often you do not get everything back: the decryptor is slow, broken, or never arrives. And the cause is still there: the door they came through is still open, and the next day they can hit you again, at a different price.
B. I do not pay, on principle, and I reinstall everything.
Wrong, even if it sounds heroic. By reinstalling you wipe both the chance of recovery (free decryptors exist for some ransomware families) and the evidence. Without evidence you do not know how they got in, so you do not know what to close. And if personal data of your clients is among the files, you have notification duties that "we reinstalled" does not cover.
C. I disconnect it from the network so it does not spread to the rest of the company, delete nothing, do not shut it down, and call an incident specialist.
Correct. You can no longer stop the encryption on that machine. Disconnecting saves the rest of the company: the server, the other computers, the backup. You do not shut it down: keys and useful traces may still be in memory. You delete nothing. And you bring in someone who has been through this before, in the first hour, not on day three. It is the verdict that matters most when it actually happens.
What came out of the room
Nothing exotic. The wrong answers were the usual ones: the same password everywhere, the former employee’s accounts left open “for handover”, a confirmation requested on the fraudster’s own email, sync mistaken for backup. These are not signs of carelessness. They are habits that have not cost anything yet, which is why they feel fine.
The good part: on backup, almost the whole room answered correctly. That lesson has been learned, probably on someone’s own skin.
Five things to do tomorrow morning
- The IBAN rule. Any bank account change from a supplier is verified by phone, on the old number, before the first payment. Write it into the payment procedure, one sentence.
- A password manager plus a second step. Start with email and the bank. The other accounts follow as you open them.
- The leaver’s list. One page: accounts, shared passwords, devices, email forwarding rules. Filled in on the day notice is given, ticked off on the last day.
- One restore test. Pick a file, restore it from backup, open it. If it does not work, you found out now, not on a Monday morning.
- One phone number. Of someone who has been through an incident, written somewhere you can find it with the computers locked.
When to call us
There are three moments when a conversation with us saves you the most:
- An email or an invoice arrived that does not smell right.
- A large client, your bank or your insurer asks you to prove your data is safe.
- The person who knew all the passwords has left, or you woke up to locked computers.
And there is a quieter one: nothing is wrong, but on one or two of the five questions above you were not sure what you would pick. That is the cheapest moment of all. The conversation starts from the list above, the five things for tomorrow morning, and ends with it ticked off, before any of the other three moments arrives on its own.
We take it from there. Write to us, or forward this article to someone who is in one of those moments right now.
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.