The Only Week They Are Actually Listening
Key Intel / TL;DR
  • A new hire's first week is the only period where they are paying full attention and have no habits to override.
  • Most organizations spend that window on a compliance video, a policy acknowledgment, and a badge photograph.
  • What actually transmits in week one is the informal rule set, learned by watching whoever sits nearest.
  • Badge, accounts, and norms are issued by three teams that rarely speak to each other, so the new person reconciles them alone.
  • Run the security conversation in week two with a named person, not a module, and ask what they have already been told.

My first week working in corrections, somebody walked me past a door and told me which one it was, what the policy said about it, and then what everybody actually did about it. Those last two were different. I learned the real rule from a person in a hallway inside my first few hours, and I never once went back and checked the manual, because the hallway version came with a face attached and the manual did not.

That is how every organization transmits its actual operating rules, and almost nobody plans for it. We put enormous effort into the written version and none at all into the hallway.

The Window Is Real and It Closes

There is a specific neurological reason the first week matters more than any week that follows, and it has nothing to do with enthusiasm or company spirit. It is about what a nervous system does when it lands somewhere it has never been.

A new environment produces genuine physiological arousal. Elevated attention, heightened encoding, and a nervous system that has not yet decided what in this building is safe to ignore. Your new hire is running in a state where everything is signal because they have no basis yet for sorting signal from noise. They are watching where people put their badges, whether the side door gets propped, how somebody talks to the person at the front desk, and what happens when a colleague makes a mistake in front of a manager.

That state costs energy, so the brain resolves it as fast as it can. Within a couple of weeks the novelty drops away and the habits set, and from that point forward you are no longer teaching anybody anything. You are asking them to overwrite something, which is a categorically harder request and the reason annual awareness training performs the way it does.

So you get one window per employee, it lasts a matter of days, and it is the highest-attention audience your security function will ever have. Look at what most organizations put in it.

What Actually Goes in the Window

A twenty-minute video with a quiz. An acknowledgment form for a policy document nobody reads on the day they are asked to sign it. A badge photograph. Account credentials delivered by whatever mechanism IT uses, frequently over email to a personal address before the corporate one exists.

None of that is malicious or lazy, and every piece of it exists because somebody needed evidence that the step occurred. The video is there so the compliance file is complete. The acknowledgment is there so the employment lawyer is comfortable. These are artifacts produced for an auditor, and the new hire correctly reads them as such within about ninety seconds.

Meanwhile the actual curriculum runs in parallel and nobody is teaching it. On day two somebody says do not bother with the ticket system for that, just message me. On day three somebody shares a login because provisioning is slow. On day four a person props the back door during a delivery, and your new hire watches nobody react.

Every one of those is a lesson, and every one of them lands harder than the video, because it arrives from a human being who is demonstrating it instead of asserting it. This is Shadow Risk forming in real time: the gap between the documented control environment and the one people actually operate, transmitted person to person, never written down anywhere you could audit it.

Three Teams, One Confused Person

Now add the converged dimension, because the first week is also where physical, cyber, and cognitive security visibly fail to be one thing. A new hire experiences all three in the same forty-eight hours and gets them from three separate sources.

Facilities issues the badge and explains the doors, while IT provisions the accounts and covers the password rules. Whoever runs the onboarding session handles the culture portion, usually HR. Those three groups rarely speak to each other, they schedule independently, and they each assume one of the others covered the part they skipped.

The result is a person holding a physical credential from one team, a digital credential from another, and a set of behavioral expectations from a third, with no explanation anywhere of how the three relate. So they build their own model, and their model is usually that the badge is for getting in, the password is for logging in, and security is a department that sends emails.

I have walked a lot of buildings where the tailgating problem, the shared-credential problem, and the unreported-incident problem were all treated as three separate findings with three separate remediation owners. They are the same finding. Somebody’s first week taught them that the badge is a door key rather than an identity claim, and everything downstream follows from that one idea.

The Question Nobody Asks

If you want to know what your organization actually teaches, there is a very cheap instrument available and it works for about three weeks after a start date.

Ask a new hire what they have already been told to ignore. That one question has produced more useful findings for me than most of the instruments built for the purpose.

Not in a survey, and not through their manager. A five-minute conversation in week three, from somebody with no authority over them, asking what surprised them and what they were told the real process is. People at that stage will tell you, because they have not yet been socialized into protecting the group and the informal rules still strike them as interesting instead of ordinary.

What comes back is an unfiltered picture of your control environment as operated. I have never run that conversation and learned nothing. I have frequently run it and learned about an access path, a workaround, or a standing exception that appeared in no assessment we had commissioned and in none of the security culture metrics we were tracking at the time.

That window closes too. By month three they have stopped noticing, because it has become simply how things are done, which is the definition of culture and the reason culture is so hard to audit from the inside.

What to Do With the First Two Weeks

None of this requires a platform purchase, and all of it requires somebody senior enough to be worth listening to. The cost is calendar time from people who are already employed.

Move the security conversation to week two

Week one is saturated with logistics, paperwork, and remembering names, and nothing lands. Week two has room in it, and the person is still in the high-attention state. Schedule it deliberately instead of bundling it into day-one orientation where it competes with the parking instructions.

Send a person, not a module

The change that matters most is that a named human being with a real job holds this conversation, because the informal curriculum travels person to person and only a person can compete with it. A security lead, an operations manager, somebody who was actually there when something went wrong. Fifteen minutes from a person beats forty from a platform.

Explain the badge as an identity claim

Say out loud that the credential asserts who they are and that lending it transfers their identity rather than opening a door for a colleague. That framing takes one sentence and it is the difference between a person who holds a door for a stranger and one who does not. Cover the digital equivalent in the same conversation, since it is the same idea in a different medium.

Name the workarounds before somebody else does

Tell them which shortcuts exist, that you know about them, and which ones are genuinely fine. An organization that admits its own gaps gets told about new ones. An organization that pretends the documented process is the real process teaches every new hire that the first honest thing they hear will come from a colleague rather than from you.

Tell them what happens when they report something

Most people’s model of reporting comes from a previous employer and is usually bad. Say specifically what happens, who sees it, and what does not happen to them, which is the practical application of blameless reporting at the individual level. Then make the first report they file easy, and respond to it fast enough that they notice.

Ask the question in week three

Put it on somebody’s calendar as an actual recurring task with a name against it. The findings go into the same place your assessment findings go, because that is what they are.

The Part That Does Not Fit on a Dashboard

The uncomfortable thing about all of this is that it produces almost no metrics. You cannot show a board a completion percentage for a hallway conversation, and the Human Zero-Day does not resolve into a number that trends down quarter over quarter.

What you can show is the second-order effect. Reports go up before incidents go down, which looks wrong on a dashboard and is exactly what improvement looks like from the inside. More people telling you about things is the leading indicator, and it arrives before anything you can put in a chart.

Most organizations will keep spending the window on the video, because the video generates the artifact and the artifact is what the audit asks for. The people who fix this will be the ones who worked out that their new hire already learned the real rules on day two, from somebody in a hallway, and decided to be in that hallway first.

If you want an outside read on what your organization is actually teaching in its first two weeks, contact Grab The Axe. You can also take our free Human Attack Surface Score, and our guide to behavioral security training covers what replaces the phishing-click metric.

Jeff Welch is CEO of Grab The Axe.

Distribute Intel
Jeff Welch
Chief Executive Officer
Jeff Welch
Architect of the 'Cognitive Firewall.'

A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.

View Author Page →