## Purpose

Use this briefing to provide every new employee or contractor with the minimum cybersecurity information they should understand when joining the company.

It can be delivered during onboarding alongside the Employee Cybersecurity Onboarding Checklist.

## Protect Your Account

- Use only your assigned account.

- Use unique passwords.

- Use the company-approved password manager where provided.

- Enable MFA where required.

- Never approve an MFA request you did not initiate.

- Never give passwords or MFA codes to someone requesting them by email, chat, or telephone.

- IT support should not need your password.

## Be Careful With Messages

**Attackers may impersonate:**

- Executives
- Colleagues
- IT support
- Customers
- Suppliers
- Banks
- Courier companies
- Microsoft, Google, or other technology providers

**Be particularly cautious when a message asks you to:**

- Log in
- Open an attachment
- Scan a QR code
- Approve MFA
- Send sensitive information
- Change payment details
- Buy gift cards
- Make an urgent payment
- Keep the request secret

If something feels unusual, verify it independently.

## Protect Company Information

Store company information in approved systems.

**Do not move company information to:**

- Personal email
- Personal cloud storage
- Unapproved messaging services
- Unapproved SaaS applications
- Unapproved AI services

Check recipients before sending sensitive information.

Avoid public sharing unless specifically required and approved.

## Use Approved Technology

**Use company-approved:**

- Devices
- Software
- Cloud services
- File-sharing tools
- Remote access
- AI services
- Browser extensions

Do not install or connect new technology to company systems without approval where required.

## Protect Your Device

- Lock your device when leaving it unattended.

- Do not disable security software.

- Install required updates.

- Protect devices during travel.

- Do not allow unauthorized people to use company devices.

- Report lost or stolen equipment immediately.

## Be Careful With Remote Work

- Use approved remote access.

- Protect company devices from other household or public users.

- Avoid exposing sensitive information in public areas.

- Use trusted internet connections where practical.

## Watch for Fraud

Treat unusual financial requests carefully.

**Be particularly suspicious of:**

- Changed supplier bank details.
- Urgent executive payment requests.
- Payroll bank-detail changes.
- Unusual refunds.
- Requests to bypass approval procedures.
- Requests for secrecy.

Follow company verification procedures even if the request appears to come from someone senior.

## Report Suspicious Activity

**Report immediately if:**

- You clicked a suspicious link
- You entered your password somewhere suspicious
- You approved an unexpected MFA request
- You received a suspicious email
- You sent information to the wrong person
- Your device was lost or stolen
- You see an unexpected login
- You suspect malware
- You receive a suspicious payment request

Reporting method: ____________________

Emergency contact: ____________________

## If You Make a Mistake

Report it quickly.

**Do not:**

- Hide it
- Delete evidence
- Try to investigate the attacker yourself
- Wait to see whether something bad happens

Early reporting gives the company more options to contain the problem.

## Employee Confirmation

Employee: ____________________

Briefing provided by: ____________________

Date: ____________________

Questions or additional training required: ____________________

Employee acknowledgement: ____________________

## Practical Rule

Protect your account, protect company information, question unusual requests, and report suspicious activity quickly.
