Across this series we've covered voice cloning, synthetic video, and AI-crafted phishing, three ways attackers are getting better at looking legitimate. But there's a quieter problem that does just as much damage: people notice something's wrong, and don't say anything.
Not because they don't care, but because reporting feels like an admission of failure, they're not sure it's "serious enough," or they assume someone else has already flagged it. Every minute between "something felt off" and "someone in IT knows about it" is a minute an attacker gets to spread further through your systems.
We've drawn on our earlier guidance on cyber attacks, transparency, and building a no-blame culture. The myths below are worth repeating, because they're exactly what keeps people quiet.
The myths that keep people silent
- "Staying quiet makes the problem go away." It doesn't, it just stops anyone else learning from it, which is how the same attack succeeds again elsewhere in the organisation.
- "Reporting to the authorities makes it more likely to go public." The opposite is usually true: the NCSC and ICO don't publicly disclose incidents without permission.
- "No confirmed data theft means no need to tell the ICO." Organisations should assume compromise and act accordingly, rather than waiting for certainty that may never come.
- "If there's no data leak, there's no breach to report." A breach covers far more than data loss alone.
If staff are quietly carrying any of these assumptions, they'll talk themselves out of reporting exactly the kind of "small" thing: a clicked link, a strange call, an odd login prompt, that this series has spent the last few days asking them to flag.
Why reporting gets delayed, the behavioural side
- Fear of blame. Staff worry that reporting a clicked link or a suspicious call means admitting they nearly fell for it, so they quietly hope it was nothing, rather than flag it.
- Uncertainty about the threshold. Without a clear "when in doubt, report it" culture, people assume minor things aren't worth raising, and minor things are often exactly how major incidents start.
- Not knowing who to tell, or how. If reporting means hunting for the right contact, busy staff deprioritise it.
- Diffusion of responsibility. In a larger organisation, it's easy to assume "someone else has probably already said something."
What normalising immediate reporting actually looks like
- Make "report it" the default message, not the exception. Every piece of cyber awareness training, including this series, should end with the same instruction: if something feels wrong, report it immediately, even if you're not sure.
- Remove the friction and know your escalation chain in advance. Staff shouldn't have to look this up mid-incident. Make sure your internal reporting route is clear, and that whoever holds the SLT Digital Lead role knows the wider chain:
- Report Fraud: 0300 123 2040
- DfE sector cyber team
- NCSC: for closures or serious financial damage
- ICO: within 72 hours for high-risk breaches. DPE customers should contact us to report on their behalf by raising a ticket from the data breach log on our Knowledge Bank Platform.
- Your cyber insurance provider
- Jisc: for further education institutions
- Forward suspicious emails internally for review, and report scam text messages by forwarding to 7726
- Reward the behaviour, not the outcome. Thank people who report things that turn out to be nothing. A genuine "no-blame" culture has to be lived, not just stated in a policy.
- Make the first response blame-free, every time. "You did the right thing" before any investigation happens protects everyone else's willingness to do the same.
- Preserve evidence rather than delete it. The instinct to tidy up (deleting a suspicious email, clearing a call log) destroys exactly what an investigation needs.
Why "small" incidents matter more than they seem
A single strange login attempt, a phishing email that didn't quite land, or a call that felt slightly off rarely looks worth reporting on its own. But attackers often test an organisation before committing to a full attack, probing which emails get through, which staff respond to a suspicious call, or whether a login attempt triggers any response at all. Taken individually, these look like noise. Reported and looked at together, they can reveal a pattern: the same attacker, working out where your weak points are before they strike properly. The incident that seems too small to mention might be the one piece of information that lets IT spot the build-up before it becomes a breach.
💡Your Daily Cyber Tip: the 60-second rule
If something feels off: an email, a call, a video, a login prompt, give yourself a 60-second rule: report it within 60 seconds of noticing, before talking yourself out of it.
Where this sits in the DfE Digital & Technology Standards
This sits under Cyber Security, cyber awareness and incident response, and reinforces Digital Leadership & Governance, which expects clear, well-understood escalation routes. A standard is only as good as how quickly people actually use it.
It connects everything this week
Spotting a cloned voice, a synthetic video, or an AI-crafted phishing email only matters if the person who spots it then tells someone, fast. Catch up on AI-crafted phishing bait →
