An owner we know rolled out endpoint security software on a Monday. By Wednesday, three people had asked a coworker whether the boss could read their text messages. By Friday, someone asked whether it could turn on the webcam. None of it was true. All of it was believable, because nobody had said anything.
Security monitoring is a normal part of running a business. It is also the easiest thing to communicate badly. Say nothing and you get rumors, which are worse than reality. Say it clumsily and you sound like you are watching people rather than protecting the company. The fix is a short, honest explanation given before the tools go in.
What Security Monitoring Actually Sees
Understand it yourself first, so you can explain it without hedging. NIST’s Cybersecurity Framework 2.0 Small Business Quick-Start Guide, published in 2024, describes the Detect function as providing outcomes that help you find and analyze possible cybersecurity attacks and compromises, and suggests engaging a service provider to monitor computers and networks for suspicious activity. The Federal Trade Commission’s Start with Security guide frames the goal as answering one question: what is happening on your network. In practice, a small business stack sees this.
- Programs running on company devices. The endpoint tool flags anything behaving like malicious software. It cares about behavior, not what document you have open.
- Sign in events. Who signed in, when, from what device and roughly where. This is how you catch a stolen password used from a place you have never worked.
- Email flow and filtering. What was blocked, and whether a mailbox started forwarding to an outside address, a classic sign of compromise.
- Destinations devices connect to. Web filtering sees the sites a device reaches so it can block malicious ones. On a company device, that is real.
- Administrative changes. New accounts, permission changes, new mail rules. What an intruder does next.
- Device health. Whether the machine is encrypted, patched, and protected. Mostly this is how you learn a laptop skipped updates.
What It Does Not See, and Why Saying So Matters
This is the part owners skip, and the part that buys trust. People are not worried about log files. They are worried about specific personal scenarios, and if you do not address those they will assume the worst. Confirm your configuration first, since details vary by tool. For a standard setup, the honest answers sound like this.
- It is not a video feed. Standard tooling does not stream anyone’s screen or access the camera or microphone.
- Nobody is reading along. No person watches activity as it happens. Alerts fire on suspicious patterns, and a human looks then.
- Personal phones are outside the boundary. Unless a personal device was deliberately enrolled in management, it is not in scope.
- Personal accounts are not visible. Company tools cover company systems. A personal account used in a browser on a company laptop is a gray area, which is why the policy should say to keep personal business on personal devices.
- Nobody is counting keystrokes. The fear underneath all the others. If you are not doing productivity tracking, say so without qualification.
One more, said out loud: on a company owned device, browsing is generally visible at the level of sites reached. Do not fudge that. Tell people plainly, and give them the implication: personal browsing belongs on a personal device. A clear boundary lands better than a reassurance that turns out to be incomplete.
Security Monitoring Versus Productivity Surveillance
These are two categories of tool with two purposes, and conflating them destroys trust in both. Security monitoring asks whether something dangerous is happening to the company. Is an unfamiliar program executing, is someone signing in from an impossible location, did a mailbox start forwarding outside. The subject is the threat.
Productivity surveillance asks how hard a specific person is working. Active hours, idle time, application rankings, screenshots, keystroke counts. The subject is the employee. You can have opinions about that category. Ours is that it measures the wrong things and costs more in morale than it returns. But the point applies regardless: do not let people confuse the two, and do not deploy them under one explanation.
When staff believe a security tool is secretly a performance tool, two things happen. They stop reporting problems, because reporting draws attention to their own screen. And they route work around the monitored systems, using personal email and cloud storage to avoid feeling watched. That moves company data out of your sight. We covered where that leads in our post on shadow IT and the risk inside your own organization. The irony is direct: an unclear monitoring message makes your business less secure, not more.
Tell People in Advance, and Put It in Writing
Timing does most of the work. Announced beforehand, monitoring is infrastructure. Discovered afterward, it is a betrayal, and you will not get that trust back cheaply. Employment law here varies by state, and we are not attorneys, so have counsel review your policy language. The case for telling people first is overwhelming.
- Say it in person before anything is installed. Five minutes in a team meeting, not a handbook footnote.
- Put a short written version in the handbook. One page: what is monitored, on what devices, why, who sees it, and for how long.
- Name who has access. Vagueness breeds rumor. If it is you and the IT provider, say so.
- State what it will not be used for. If it is not part of performance reviews, write that down. Written beats verbal.
- Repeat it at onboarding. New hires should hear it in week one.
A Short Script You Can Use
Adjust the specifics to your setup and use your own words.
“I want to tell you about security software going onto company computers next week, and I want you to hear it from me rather than notice it later. It watches for malicious programs, sign ins from places we do not do business, and someone getting into an email account they should not be in. Nobody is watching your screen. It does not turn on cameras or microphones, it does not read your texts, and it is not on your personal phone. It is not a productivity tool either. I am not counting keystrokes or measuring idle time, and none of it shows up in a performance review. One honest note: on a company laptop, the websites the machine reaches are visible to the security tools, so keep personal browsing on your own devices. The only people who can see this are me and our IT provider, and we look when something gets flagged. Most important: if you click something you should not have, tell us immediately. Nobody gets in trouble. The first five minutes is the difference between a small problem and an expensive week. Ask me anything.”
The Bottom Line
Monitoring is not what damages trust. Surprise does. Vagueness does. Being caught in an inaccurate statement damages it permanently. The tools are ordinary, they are how you find out a password was stolen before it becomes a wire transfer, and most people accept that when you explain it plainly.
Learn what your tools do. Tell people before you turn them on. Be specific about what is visible, including the uncomfortable parts. Keep security monitoring separate from productivity measurement. Put a page in the handbook. That is the job.
If you are not sure what your tools can and cannot see, resolve that before someone asks in a meeting. We will walk through your setup and give you a plain language inventory of what is collected, who sees it, and how long it is kept, so the answer you give your team is one you can stand behind. Contact us today.
Sources:

Comments are closed