Ann Westerheim is blunt about the disconnect she sees every day. As founder of Ekaru, a cybersecurity-focused MSP in Boston, she spends much of her time trying—and sometimes failing—to convince small business owners that they’re at risk.
“People only see headlines for what’s happening with big business and they’re not seeing the headlines for what’s happening with small business,” she said.
That perception gap runs deep. When a Fortune 500 company gets breached, it makes national news. But when a ten-person accounting firm loses its client data in a phishing scam, no one outside the victims and their clients will ever hear about it. For the business owner, though, the damage is existential.%20(1).jpg?width=258&height=387&name=ChannelCon2025_3070-lowres%20(1)%20(1).jpg)
Small businesses are hardly a niche: They account for roughly half of the U.S. economy, 40% of private payroll and a quarter of government contract work. Yet their cyber defenses can be shockingly weak, and their owners may also shockingly believe they are “under the radar.”
That illusion is costly. In Massachusetts alone, Westerheim points to half-million-dollar losses at Arlington schools and the town of Franklin due to simple business email compromise scams.
Why Cyber Advice Falls Flat
The scale of cybercrime is staggering—so much so that if it were counted as an economy, its $10.5 trillion “price tag” would rank it third in the world, just behind the United States and China. And yet, Westerheim said, the lessons never seem to stick.
“Why does it keep happening over and over and over again? Why aren’t we learning? Why isn’t it getting any better?” she asked.
For her, one culprit is the “curse of knowledge.” Cyber professionals understand frameworks like NIST and CIS, pore over breach reports and install layer upon layer of defense tools. But that expertise becomes a liability when they try to communicate with Main Street business owners.
“We go out to our community and say, ‘hey, we have 300 tools that can help you. Just buy some of these things and everything’s going to be okay,’” she said. “This is completely overwhelming to a local small business.”
Even when simple, low-cost solutions are available, adoption stalls.
“99.99% of Microsoft 365 security incidents happen with accounts that don’t have MFA,” Westerheim noted.
But in many small firms, just a third of users bother to turn on multifactor authentication. Some executives even refuse because it feels inconvenient.
That paradox frustrates Westerheim: Clients erupt over a 15-minute network outage but balk at enabling MFA—the single easiest safeguard against an email takeover.
Communication, Not Technology
To Westerheim, the breakthrough won’t come from more products.
“We really need to view this as it’s not a technology problem we’re solving, it’s a communication problem,” she said.
That means ditching acronyms and instead translating risk into terms owners understand. If a client doesn’t know what DMARC is, don’t lecture them on email authentication standards. Ask instead: “Do you want your emails to get delivered? Is it important that somebody else doesn’t send fake invoices in your name?”
Cyber frameworks are free and public. The NIST Cybersecurity Framework, CIS Controls—none are hidden. Yet small firms rarely implement them. Why? Because no one has made the message relevant to their daily concerns.
Westerheim recalls recommending a basic security measure that cost the equivalent of “one latte a month.” The client refused. “Folks won’t go ahead to do it,” she said, shaking her head.
Lessons From Public Awareness
If cybersecurity professionals want change, Westerheim argues, they should look outside their industry.
“You’re not just telling somebody, ‘here’s a fact, I’m going to tell you once and we’re going to change behavior.’ It doesn’t work like that,” she said.
Instead, she points to decades-long public awareness campaigns that reshaped cultural norms:
- Smoking went from doctor-endorsed to deadly through relentless messaging starting in the 1960s.
- Seatbelt use climbed from 10% in the 1980s to over 90% today thanks to laws and “Click It or Ticket” messaging.
- Smokey Bear’s “Only you can prevent forest fires” quip made individual responsibility unforgettable.
- Don’t Mess with Texas transformed from an anti-littering slogan into an enduring cultural marker.
Cybersecurity, Westerheim says, needs the same kind of approach: Simple, repeatable, emotionally resonant messages that stick.
Shared Responsibility, Even Civic Duty
Part of the challenge is breaking small businesses of the “insurance mindset”—the belief that a cyber policy means the risk is handled. Westerheim calls that a dangerous illusion. Claims often get denied if applications are inaccurate or controls are missing. She pushes instead for personal responsibility.
“If you lose a bunch of money in a business email compromise scam, it’s your money. You lost it, and you can’t do anything about it and nobody else is rescuing you,” she said.
Abroad, some governments have codified that responsibility. In Finland, cybersecurity training is treated as a civic duty. Westerheim sees a lesson for the United States: Culture change requires not just technology, but education and expectation.
“Cybersecurity is no longer the sole responsibility of professionals, and cyber citizen skills can’t be stressed enough,” she said.
A Culture of Security
That culture shift, Westerheim argues, can be fueled by more engaging, less punitive awareness efforts. She applauds gamified incident-response exercises and simple awareness stunts like “Lock It Up,” which teaches employees to hit Windows-L before leaving their desks.
Industry initiatives also matter. The GTIA Cybersecurity Trustmark, for example, requires MSPs to document their own policies and safeguards—a way of proving they practice what they preach.
And while regulations are tightening (new SEC rules, HIPAA requirements, CMMC standards) Westerheim warns against assuming Washington or big tech will save the day.
“Government’s not going to fix it for us. There’s not going to be some product, some piece of technology that we can buy that’s going to make the problem go away,” she said.
Instead, professionals must make security a shared journey with clients: Continuous reinforcement, practical steps and plain-spoken conversations about risk.
Closing the Gap
Westerheim insists the stakes aren’t abstract. Cybercrime doesn’t just drain balance sheets—it threatens jobs, livelihoods and entire companies. Even nations. She’s seen employees wonder if their firm will survive after a breach, scrambling for resumes while leadership tries to save its biggest accounts. Changing that trajectory means meeting Main Street where it is, not where security pros wish it were.
“Make it easy to do the right thing,” she said. “And it’s not okay to fail. We can do something to eliminate a lot of the risk.”
GTIA Members: Download Cybersecurity Guidebook for MSPs: Best Practices for Protecting Clients on the Member Portal.

