AI and Cybersecurity Foundations
Most breaches do not start with sophisticated hacking. They start with one click on a busy Tuesday. Get the basics right.
Presented by
Sean Hiebert
Founder and CEO, StillWater IT Solutions
Hosted by Lyndon Smith & Joshua Leyenhorst
Key takeaways
- People are the weakest point, not the technology. Around 90% of breaches start with one click on the wrong link.
- Three doors get left open: phishing emails, weak passwords, and unpatched devices.
- Urgency is the tell. If a message pressures you to act right now, treat the pressure itself as the warning sign.
- Never log in through a link in an email, and have a verification policy for money and account changes. A quick phone call catches these.
- Govern AI like any other business system: inventory the tools, require approval, use paid business-grade accounts, and never paste proprietary information into a free tool.
Most owners assume cybersecurity is a technology problem, something you solve by buying the right software and locking everything down. Sean Hiebert, Founder and CEO of StillWater IT Solutions, opened this session by taking that idea apart. The businesses that get breached are rarely the ones with the wrong firewall. They are the ones where somebody clicked the wrong link on a busy Tuesday.
It is not about locking everything down or chasing every new tool. It is about getting the basics right and protecting your people from the most common mistakes.
People are the weakest point, not the technology
Around 90% of breaches start with a single click. Not a zero-day exploit, not somebody defeating your firewall. One person, moving fast, clicking something that looked legitimate. That reframes the whole problem. The highest-return security work in a small business is not buying more software, it is building habits in your team.
Sean named the three doors most small businesses leave open:
- Phishing emails, the entry point for most incidents.
- Weak passwords, reused across accounts and stored somewhere convenient.
- Unpatched devices, quietly running known vulnerabilities.
Urgency is the tell
This is the single most useful pattern to teach a team. Almost every social-engineering attack manufactures time pressure: a payment that must go out now, a login about to expire, an account about to be cut off. Legitimate business rarely needs you to act within the next four minutes. When the pressure shows up, that is the signal to slow down rather than speed up.
Two rules that follow from it
- Never log in through a link in an email. Go to the account directly, or call IT to verify.
- Have a verification policy for money and account changes. A quick phone call to a known number catches these.
What it costs when the basics are missing
Sean walked through incidents his team has handled directly. Names withheld, numbers not.
- $157KA construction payment redirected after an email account was compromised and the banking details on an invoice were quietly changed.
- $50KMoved in three transactions by an attacker impersonating a CFO from a lookalike domain, one letter off, using a lowercase L that reads exactly like a capital i. It surfaced only because a staff member mentioned to the real CFO that payroll would not clear.
- $1MA framing company closed its doors after an administrator was talked into transferring a million dollars out of the account.
None of these involved sophisticated hacking. Each one turned on a person, under time pressure, doing something that looked entirely reasonable at the time. That is why the verification phone call is the control that matters.
Five things you can start doing differently
None of these require a budget approval or a project plan. They are habits, and they close most of the doors that attacks actually use.
- 1Turn on two-step authentication for Microsoft 365.
- 2Start using a real password manager, encrypted, not a spreadsheet named “summer recipes”.
- 3Pause and phone to verify any money or login request.
- 4Lock your screen every time you stand up. Windows key plus L.
- 5Never put proprietary information into a free AI tool.
Where AI fits in
AI is already on every desk, usually well before there is any policy about it. Sean’s position was not to slow it down, it was to govern it like any other business system. The risk is not that your team uses AI. The risk is that nobody knows which tools are in play, what is being pasted into them, or whether the output was ever checked.
- Keep an inventory of the AI tools your team uses.
- Treat a new AI tool like any other software purchase that needs approval.
- Stick to paid, business-grade accounts rather than free ones.
- Verify any number, law, or citation against the primary source before it goes out.
The most interesting idea came at the end. AI can be shaped, through personalization, into a useful “ruthless mentor” that challenges your thinking, rather than a yes-machine that reinforces bad habits. A tool that only ever agrees with you is not an advisor.
From the discussion
What the questions surfaced
The session ran close to two hours because the questions kept coming. Several of the answers are worth having on the record.
Is “change your password every 90 days” still good advice?
No, and Microsoft has abandoned the recommendation. Forced rotation pushes people into predictable patterns: ABC123 becomes ABC124, then ABC125, which is trivial to guess. Length and a password manager beat rotation. Aim for at least 12 characters with numbers and symbols.
Why is a password manager safer than what I do now?
Because it encrypts. The alternative Sean’s team keeps finding is a spreadsheet with an innocuous name. They once ran a tool that scanned client machines for spreadsheets containing the word “password” and were getting alerts five times a week. The password managers built into Google and Microsoft do genuinely encrypt, so they are a real step up from a list.
If I black out text in a PDF, is that information actually gone?
Not necessarily. Editors like Adobe work in layers, and a layer that was added can be removed, which takes the redaction with it. Export the redacted file to a flat file or an image so the black bars are baked into the pixels and there is no text or metadata underneath.
Do I need a business plan to secure an AI tool, or is my paid personal account enough?
A paid personal subscription is usually enough. The privacy controls exist on paid plans, they are simply off by default, whereas business plans switch them on for you. Free tiers do not offer the controls at all. The settings live in different places on each tool, but they do broadly the same job and take about five minutes to set.
Are Macs safer than Windows PCs?
Not in the way people assume. Almost everything now arrives through phishing and account compromise rather than the device itself, and that does not care which machine you use. Device-level infections are a small fraction of what Sean’s team sees compared to account phishing.
What about a computer several people share?
Use a guest profile. If everyone signs into the same browser profile, everyone inherits the saved passwords. Sean described a business where every staff member and visitor used one signed-in account, which handed the whole password list to anyone who sat down.
Should we install updates the moment they are released?
StillWater deliberately runs about two weeks behind. That gives the vendor time to fix its own bad patches after the industry reports them, and Sean says it results in far fewer update-related breakages. The point is that patching should be on a schedule someone owns, not left to chance.
Here are the keys to your Maserati. I understand you don’t know how to drive. That’s AI right now. It gets you wherever you think you want to go, lightning fast, in the wrong direction a lot of the time.
The takeaway
Security and AI are both people problems before they are technology problems. Teach the tells, set the verification habits, govern the tools, and you close the doors that most attacks actually walk through.
About the guest
Sean Hiebert
Founder and CEO of StillWater IT Solutions, a managed IT and cybersecurity firm supporting small and mid-sized businesses across Canada. He also runs StillWater Academy, practical AI and security training built around the tools teams already use.
40% off StillWater Academy
Sean has extended a 40% discount to everyone who joined this session. StillWater Academy is practical AI and security training built around the tools your team already uses, with a company AI policy, risk register, and rollout plan generated as you work through it. Ten modules per learner, and a verified certificate valid for 12 months.
Claim the 40% discountWant the full session?
The full recording, Q&A included, is in the community.
Sean stayed on well past the hour to answer questions. Members of The Business Growth Factor get every Community Connect session on demand, plus the resources and worksheets we work through together, and access to peers asking the same questions you are.
Join the CommunityKeep going
Related post
Using AI to Codify Your Business Operations
Once the guardrails are in place, this is how you put AI to work turning what you know into documented process.
Related post
Workplace Safety, COR and SECOR
The same principle in a different domain: the systems that protect your people are habits before they are paperwork.