THE SHORT ANSWER

A verification culture makes safe checking routine: unusual payment or access changes use known-channel confirmation, higher consequences require another approver, employees may pause urgent requests, and suspicious communication can be reported without blame.

Make verification an expected part of the process

  • Define which changes always require a callback or second approver.
  • Keep trusted contact records outside incoming requests.
  • Give people permission to pause authority and urgency signals.
  • Provide one clear route for reporting suspicious communication.
  • Review near misses without punishing reasonable verification.

Evidence & context: Federal Bureau of Investigation

Add friction where consequence is high

Action
ActionExample consequenceProportionate practice
Routine low-value interactionSmall, reversible inconvenienceBasic channel and context check
Payment-detail changeMoney sent to the wrong destinationKnown-channel confirmation and recorded approval
Sensitive-data requestPrivacy or identity harmConfirm identity, authority and minimum data needed
Privileged accessWide system or customer impactStrong authentication, authorization and second review

Evidence & context: National Institute of Standards and Technology

Leaders determine whether people will pause

If a leader reacts badly when questioned, staff learn to obey convincing urgency. Psychological-safety research concerns a climate for interpersonal risk; it does not make verification automatic. Leaders must respond constructively and follow the same controls themselves.

Connect this practice to Questions for Managers and How to Build Trust & Psychological Safety.

Evidence & context: Administrative Science Quarterly

Practise the response without creating reusable deception

Walk through a neutral scenario: an expected supplier asks to change payment details. Rehearse who pauses, which known contact is used, who approves, what is recorded and how a concern is reported. Test the control, not the realism of a scam.

Sources & further reading

  1. Business Email Compromise

    Federal Bureau of Investigation. Official defensive guidance explaining BEC and recommending independent verification when account numbers or payment procedures change. Reporting routes are United States-specific.

  2. NIST SP 800-63-4: Digital Identity Guidelines

    National Institute of Standards and Technology. The 2025 guideline distinguishes identity proofing, authentication and federation and selects assurance according to risk. It is written for United States federal systems but offers a useful conceptual reference beyond them.

  3. Psychological Safety and Learning Behavior in Work Teams

    Administrative Science Quarterly. A foundational 1999 multimethod field study of 51 manufacturing teams linking psychological safety with learning behavior. Its sample and observational relationships do not prove that one intervention or score guarantees team performance.

Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.

A correction, a counterexample or an experience worth sharing?

Join the conversation ↗