Employee Cybersecurity Onboarding Checklist
Purpose
Use this checklist when a new employee joins the company to ensure cybersecurity requirements are completed before or shortly after access is granted.
The objective is to give new employees only the access they need, configure their accounts securely, provide approved devices and tools, and make sure they understand basic cybersecurity responsibilities from the beginning.
Employee Information
Employee name: ____________________
Department: ____________________
Role: ____________________
Manager: ____________________
Start date: ____________________
Onboarding owner: ____________________
Accounts and Access
- Required systems and applications identified.
- Access approved by the appropriate manager or system owner.
- Individual user accounts created.
- Access limited to what the role requires.
- Administrator access avoided unless specifically approved.
- Finance, payroll, HR, customer data, or other sensitive access separately approved where applicable.
- Shared accounts avoided where practical.
- Temporary project access given an expiry date where appropriate.
- Vendor or external platform access documented where applicable.
Authentication
- MFA enabled on required accounts.
- Employee shown how to use MFA correctly.
- Employee instructed never to approve unexpected MFA prompts.
- Password manager account created or approved.
- Employee instructed to use unique work passwords.
- Account recovery information configured securely.
Device Setup
- Approved device issued or approved personal device reviewed.
- Operating system supported and updated.
- Endpoint protection enabled.
- Disk encryption enabled where required.
- Screen lock configured.
- Automatic security updates enabled where practical.
- Unnecessary local administrator rights removed.
- Approved remote access configured if needed.
- Device recorded in the Asset Inventory.
Data and Tool Use
- Employee told where company data should be stored.
- Approved file-sharing tools explained.
- Personal email and personal cloud storage restrictions explained.
- Software and SaaS approval requirements explained.
- AI tool rules explained where applicable.
- Sensitive data handling requirements explained.
Cybersecurity Training
- Core cybersecurity training assigned.
- Phishing and suspicious message guidance provided.
- Password and MFA rules explained.
- Payment fraud and impersonation risks explained where relevant.
- Lost-device reporting explained.
- Security incident reporting process explained.
- Role-based training assigned where required.
Reporting Information
Employee knows how to report:
- Suspicious email or message.
- Unexpected MFA prompt.
- Fake login page.
- Lost or stolen device.
- Data sent to the wrong person.
- Payment fraud attempt.
- Malware or unusual device behavior.
- A cybersecurity mistake they have made.
Reporting channel: ____________________
Emergency contact: ____________________
Completion
Completed by: ____________________
Manager confirmation: ____________________
Employee acknowledgement: ____________________
Completion date: ____________________
Evidence location: ____________________
Practical Rule
A new employee should not receive broad access first and security controls later.
Secure the account, device, access, and training as part of onboarding.