Employee Cybersecurity Quick Rules
Purpose
This is a short cybersecurity reference employees can keep available for everyday use.
The 10 Rules
1. Protect Your Passwords
Use unique passwords and the approved password manager.
Never reuse your company password on personal services.
2. Use MFA
Use MFA wherever required.
Never approve an unexpected MFA request.
Report unexpected prompts.
3. Question Unexpected Messages
Be cautious with unexpected:
- Links
- Attachments
- QR codes
- Login requests
- Payment instructions
- Password resets
- Urgent messages
4. Verify Financial Changes
Never change bank or payment details based only on an email or message.
Follow the company’s independent verification procedure.
5. Use Approved Tools
Do not put company information into unapproved:
- Cloud services
- AI tools
- Personal email
- Personal file storage
- Messaging applications
- Online converters
6. Protect Company Data
Check recipients before sending information.
Avoid unnecessary public sharing.
Only give people access to information they need.
7. Protect Your Device
- Lock it when unattended
- Install updates
- Do not disable security controls
- Report loss or theft immediately
8. Watch for Impersonation
Attackers may pretend to be:
- Your manager
- An executive
- IT support
- A supplier
- A customer
- A bank
- A trusted technology provider
Verify unusual requests independently.
9. Report Mistakes
If you clicked, sent, entered, approved, or uploaded something you should not have, report it immediately.
Do not try to hide the problem.
10. Ask When Unsure
You are not expected to investigate cyber threats yourself.
Reporting channel: ____________________
Emergency contact: ____________________
Practical Rule
Stop, verify, and report when something does not look right.