New Employee Cybersecurity Briefing
Purpose
Use this briefing to provide every new employee or contractor with the minimum cybersecurity information they should understand when joining the company.
It can be delivered during onboarding alongside the Employee Cybersecurity Onboarding Checklist.
Protect Your Account
-
Use only your assigned account.
-
Use unique passwords.
-
Use the company-approved password manager where provided.
-
Enable MFA where required.
-
Never approve an MFA request you did not initiate.
-
Never give passwords or MFA codes to someone requesting them by email, chat, or telephone.
-
IT support should not need your password.
Be Careful With Messages
Attackers may impersonate:
- Executives
- Colleagues
- IT support
- Customers
- Suppliers
- Banks
- Courier companies
- Microsoft, Google, or other technology providers
Be particularly cautious when a message asks you to:
- Log in
- Open an attachment
- Scan a QR code
- Approve MFA
- Send sensitive information
- Change payment details
- Buy gift cards
- Make an urgent payment
- Keep the request secret
If something feels unusual, verify it independently.
Protect Company Information
Store company information in approved systems.
Do not move company information to:
- Personal email
- Personal cloud storage
- Unapproved messaging services
- Unapproved SaaS applications
- Unapproved AI services
Check recipients before sending sensitive information.
Avoid public sharing unless specifically required and approved.
Use Approved Technology
Use company-approved:
- Devices
- Software
- Cloud services
- File-sharing tools
- Remote access
- AI services
- Browser extensions
Do not install or connect new technology to company systems without approval where required.
Protect Your Device
-
Lock your device when leaving it unattended.
-
Do not disable security software.
-
Install required updates.
-
Protect devices during travel.
-
Do not allow unauthorized people to use company devices.
-
Report lost or stolen equipment immediately.
Be Careful With Remote Work
-
Use approved remote access.
-
Protect company devices from other household or public users.
-
Avoid exposing sensitive information in public areas.
-
Use trusted internet connections where practical.
Watch for Fraud
Treat unusual financial requests carefully.
Be particularly suspicious of:
- Changed supplier bank details.
- Urgent executive payment requests.
- Payroll bank-detail changes.
- Unusual refunds.
- Requests to bypass approval procedures.
- Requests for secrecy.
Follow company verification procedures even if the request appears to come from someone senior.
Report Suspicious Activity
Report immediately if:
- You clicked a suspicious link
- You entered your password somewhere suspicious
- You approved an unexpected MFA request
- You received a suspicious email
- You sent information to the wrong person
- Your device was lost or stolen
- You see an unexpected login
- You suspect malware
- You receive a suspicious payment request
Reporting method: ____________________
Emergency contact: ____________________
If You Make a Mistake
Report it quickly.
Do not:
- Hide it
- Delete evidence
- Try to investigate the attacker yourself
- Wait to see whether something bad happens
Early reporting gives the company more options to contain the problem.
Employee Confirmation
Employee: ____________________
Briefing provided by: ____________________
Date: ____________________
Questions or additional training required: ____________________
Employee acknowledgement: ____________________
Practical Rule
Protect your account, protect company information, question unusual requests, and report suspicious activity quickly.