## Purpose

This is a short cybersecurity reference employees can keep available for everyday use.

## The 10 Rules

### 1. Protect Your Passwords

Use unique passwords and the approved password manager.

Never reuse your company password on personal services.

### 2. Use MFA

Use MFA wherever required.

Never approve an unexpected MFA request.

Report unexpected prompts.

### 3. Question Unexpected Messages

Be cautious with unexpected:

- Links
- Attachments
- QR codes
- Login requests
- Payment instructions
- Password resets
- Urgent messages

### 4. Verify Financial Changes

Never change bank or payment details based only on an email or message.

Follow the company’s independent verification procedure.

### 5. Use Approved Tools

**Do not put company information into unapproved:**

- Cloud services
- AI tools
- Personal email
- Personal file storage
- Messaging applications
- Online converters

### 6. Protect Company Data

Check recipients before sending information.

Avoid unnecessary public sharing.

Only give people access to information they need.

### 7. Protect Your Device

- Lock it when unattended
- Install updates
- Do not disable security controls
- Report loss or theft immediately

### 8. Watch for Impersonation

**Attackers may pretend to be:**

- Your manager
- An executive
- IT support
- A supplier
- A customer
- A bank
- A trusted technology provider

Verify unusual requests independently.

### 9. Report Mistakes

If you clicked, sent, entered, approved, or uploaded something you should not have, report it immediately.

Do not try to hide the problem.

### 10. Ask When Unsure

You are not expected to investigate cyber threats yourself.

Reporting channel: ____________________

Emergency contact: ____________________

## Practical Rule

Stop, verify, and report when something does not look right.
