### Purpose

Use this checklist when a new employee joins the company to ensure cybersecurity requirements are completed before or shortly after access is granted.

The objective is to give new employees only the access they need, configure their accounts securely, provide approved devices and tools, and make sure they understand basic cybersecurity responsibilities from the beginning.

### Employee Information

Employee name: ____________________

Department: ____________________

Role: ____________________

Manager: ____________________

Start date: ____________________

Onboarding owner: ____________________

### Accounts and Access

- [ ]  Required systems and applications identified.
- [ ]  Access approved by the appropriate manager or system owner.
- [ ]  Individual user accounts created.
- [ ]  Access limited to what the role requires.
- [ ]  Administrator access avoided unless specifically approved.
- [ ]  Finance, payroll, HR, customer data, or other sensitive access separately approved where applicable.
- [ ]  Shared accounts avoided where practical.
- [ ]  Temporary project access given an expiry date where appropriate.
- [ ]  Vendor or external platform access documented where applicable.

### Authentication

- [ ]  MFA enabled on required accounts.
- [ ]  Employee shown how to use MFA correctly.
- [ ]  Employee instructed never to approve unexpected MFA prompts.
- [ ]  Password manager account created or approved.
- [ ]  Employee instructed to use unique work passwords.
- [ ]  Account recovery information configured securely.

### Device Setup

- [ ]  Approved device issued or approved personal device reviewed.
- [ ]  Operating system supported and updated.
- [ ]  Endpoint protection enabled.
- [ ]  Disk encryption enabled where required.
- [ ]  Screen lock configured.
- [ ]  Automatic security updates enabled where practical.
- [ ]  Unnecessary local administrator rights removed.
- [ ]  Approved remote access configured if needed.
- [ ]  Device recorded in the Asset Inventory.

### Data and Tool Use

- [ ]  Employee told where company data should be stored.
- [ ]  Approved file-sharing tools explained.
- [ ]  Personal email and personal cloud storage restrictions explained.
- [ ]  Software and SaaS approval requirements explained.
- [ ]  AI tool rules explained where applicable.
- [ ]  Sensitive data handling requirements explained.

### Cybersecurity Training

- [ ]  Core cybersecurity training assigned.
- [ ]  Phishing and suspicious message guidance provided.
- [ ]  Password and MFA rules explained.
- [ ]  Payment fraud and impersonation risks explained where relevant.
- [ ]  Lost-device reporting explained.
- [ ]  Security incident reporting process explained.
- [ ]  Role-based training assigned where required.

### Reporting Information

**Employee knows how to report:**

- [ ]  Suspicious email or message.
- [ ]  Unexpected MFA prompt.
- [ ]  Fake login page.
- [ ]  Lost or stolen device.
- [ ]  Data sent to the wrong person.
- [ ]  Payment fraud attempt.
- [ ]  Malware or unusual device behavior.
- [ ]  A cybersecurity mistake they have made.

Reporting channel: ____________________

Emergency contact: ____________________

### Completion

Completed by: ____________________

Manager confirmation: ____________________

Employee acknowledgement: ____________________

Completion date: ____________________

Evidence location: ____________________

### Practical Rule

A new employee should not receive broad access first and security controls later.

Secure the account, device, access, and training as part of onboarding.
