THE SHORT ANSWER
A verification culture makes safe checking routine: unusual payment or access changes use known-channel confirmation, higher consequences require another approver, employees may pause urgent requests, and suspicious communication can be reported without blame.
Make verification an expected part of the process
- Define which changes always require a callback or second approver.
- Keep trusted contact records outside incoming requests.
- Give people permission to pause authority and urgency signals.
- Provide one clear route for reporting suspicious communication.
- Review near misses without punishing reasonable verification.
Evidence & context: Federal Bureau of Investigation
Add friction where consequence is high
| Action | Example consequence | Proportionate practice |
|---|---|---|
| Routine low-value interaction | Small, reversible inconvenience | Basic channel and context check |
| Payment-detail change | Money sent to the wrong destination | Known-channel confirmation and recorded approval |
| Sensitive-data request | Privacy or identity harm | Confirm identity, authority and minimum data needed |
| Privileged access | Wide system or customer impact | Strong authentication, authorization and second review |
Evidence & context: National Institute of Standards and Technology
Leaders determine whether people will pause
If a leader reacts badly when questioned, staff learn to obey convincing urgency. Psychological-safety research concerns a climate for interpersonal risk; it does not make verification automatic. Leaders must respond constructively and follow the same controls themselves.
Connect this practice to Questions for Managers and How to Build Trust & Psychological Safety.
Evidence & context: Administrative Science Quarterly
Practise the response without creating reusable deception
Walk through a neutral scenario: an expected supplier asks to change payment details. Rehearse who pauses, which known contact is used, who approves, what is recorded and how a concern is reported. Test the control, not the realism of a scam.
Sources & further reading
- Business Email Compromise
Federal Bureau of Investigation. Official defensive guidance explaining BEC and recommending independent verification when account numbers or payment procedures change. Reporting routes are United States-specific.
- NIST SP 800-63-4: Digital Identity Guidelines
National Institute of Standards and Technology. The 2025 guideline distinguishes identity proofing, authentication and federation and selects assurance according to risk. It is written for United States federal systems but offers a useful conceptual reference beyond them.
- Psychological Safety and Learning Behavior in Work Teams
Administrative Science Quarterly. A foundational 1999 multimethod field study of 51 manufacturing teams linking psychological safety with learning behavior. Its sample and observational relationships do not prove that one intervention or score guarantees team performance.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗