Start with accounts and access
Use unique passwords, multi-factor authentication where available and individual accounts rather than shared credentials. Grant access needed for the role and remove it promptly when responsibilities change.
Password managers and central access processes can reduce insecure workarounds. Privileged access deserves additional control and monitoring appropriate to the organisation.
Protect devices and connections
Keep supported software updated, enable device encryption and screen locking, and separate work from other household use where possible. Treat unexpected downloads, links and authentication prompts cautiously.
Public networks may require additional safeguards under the employer’s policy. A virtual private network is not a universal solution, and specialist advice may be needed for sensitive systems.
Handle data deliberately
Store files in approved systems, limit local copies and avoid moving confidential information into personal email, unapproved cloud services or public AI tools. Use secure sharing and confirm recipients before sending.
Classify sensitive information in a way workers can understand. Privacy, contractual and regulatory duties vary, so high-risk handling should follow organisation-specific guidance.
Make reporting safe and quick
People need a clear route to report a suspicious message, lost device, mistaken disclosure or unusual account behaviour. Early reporting can limit harm; a blame-first culture encourages delay.
Practise incident contacts and recovery steps. This article provides general basics, not a security assessment, legal opinion or guarantee against attack.
Turn general rules into a usable routine
At the start of an engagement, workers should know which device and account to use, where approved files belong, how access is requested and who receives a security report. Employers should provide instructions in language people can apply during ordinary work, not only a long policy document.
Before sharing information, verify the recipient, permission and channel. Pause on unexpected urgency, changed bank details, unfamiliar sign-in pages and requests for one-time codes. Confirm suspicious instructions through a separate trusted route rather than replying to the same message.
Prepare for loss as well as prevention. Important work should use approved backup and recovery processes, devices should be capable of remote protection where appropriate, and people should know what to do after a lost device or mistaken disclosure. Early reporting can materially change the outcome.
Security controls must reflect the organisation’s data, systems and threats. Teams handling health, financial, identity or privileged infrastructure information need specialist assessment beyond these basics. This overview supports awareness; it is not a substitute for a tailored security programme.