Cybersecurity is not just an IT department responsibility. Every employee with access to a work computer, email account, or business application is part of the security perimeter. Attackers know this — the majority of successful breaches start with a targeted employee, not a technical exploit.
The good news: you do not need technical expertise to be a strong link in your organisation's security chain. You need to understand a small number of concepts, recognise the most common attack patterns, and know what to do when something seems wrong.
Why Employees Are Targeted
Attackers target employees because people are often easier to deceive than systems are to break. A well-configured firewall is very difficult to bypass. A well-crafted phishing email sent to the right person can achieve the same result in seconds.
Your access — to email, to files, to financial systems, to client data — is valuable. An attacker who tricks you into handing over your login credentials, or who gets you to run malware, inherits your access. They do not need to hack the system if they can log in as you.
Fundamental 1: Your Password Is the Key to Your Work Life
Your password protects everything accessible to your work account. If it is compromised, everything behind it is accessible to the attacker. Three things make passwords a weak link:
Reuse. Using the same password for your work email as you use for a shopping site means that a breach at the shopping site potentially exposes your work account. Use unique passwords for every account.
Weakness. Short passwords or passwords based on predictable information (your name, your birthday, common words) can be cracked. Use long, random passwords — a password manager generates these automatically.
Sharing. Passwords shared with colleagues, written on sticky notes, or entered on someone else's computer are no longer private. Keep passwords to yourself and store them in a password manager.
Ask your employer whether a password manager is provided. If not, personal options (Bitwarden is free) work for business use.
Fundamental 2: Multi-Factor Authentication Is Your Safety Net
Even with a strong, unique password, account compromise is possible if that password is stolen through a phishing attack or a data breach at another site. MFA is the safety net.
When MFA is enabled, logging in requires your password plus a second step — usually a code from an authenticator app on your phone. Even if an attacker has your password, they cannot log in without the second factor.
Use MFA on every account that supports it. If your employer has not enabled it on your work accounts, ask IT to do so. Enable it on your personal accounts too — bank, email, social media.
One important rule: never share or read out a verification code that arrives on your phone to anyone who calls you. That is someone attempting to complete a login using your credentials. Hang up.
Fundamental 3: Phishing Is the Most Common Attack and It Targets You
Phishing is an attempt to trick you into clicking a malicious link, opening a harmful attachment, or entering your credentials on a fake website. It arrives by email most commonly, but also by text, phone, and messaging platforms.
The most important warning signs to recognise:
- Unexpected urgency — any message demanding immediate action on an account, payment, or credential is suspicious
- Sender address mismatch — the display name looks right but the actual email address is wrong
- Links that go somewhere unexpected — hover before clicking to see the destination URL
- Requests for passwords or verification codes — legitimate services never ask for these via email or phone
- Unexpected attachments from known contacts — malware is often delivered via email that appears to come from someone you know
When in doubt: do not click, do not open, and report to IT.
Fundamental 4: Physical Security Matters Too
Cybersecurity is not just about digital attacks. Physical security of your devices and workspace is part of the picture.
- Lock your screen when you step away from your computer (Windows key + L on Windows, Ctrl + Command + Q on Mac). An unlocked computer is an open door.
- Do not leave work devices unattended in public places.
- Do not plug unknown USB drives or charging cables into work devices. Malicious USB devices can install malware on connection.
- Be aware of shoulder surfing in public spaces — people can observe passwords and sensitive information on your screen.
- Work documents and printouts containing sensitive information should be shredded, not binned.
Fundamental 5: Know What to Report and How
The value of employee security awareness is only realised if suspicious activity gets reported. An employee who spots a phishing email and deletes it without reporting it has protected themselves but not their colleagues.
Know the answers to these questions:
- How do I report a suspicious email at my organisation? (A button in email? A specific address? A message to IT?)
- Who do I contact if I think I clicked something I should not have?
- Who do I contact if I notice something unusual on my computer?
Reporting quickly after a security incident is the most important factor in limiting damage. A clicked phishing link reported within the hour can be contained. The same incident discovered a week later, after the attacker has established persistence and accessed more systems, cannot.
Fundamental 6: Your Personal Devices and Accounts Affect Your Employer
The boundary between personal and professional security is not as clear as it used to be. If you use personal devices for work, access work email on your phone, or work from home on a shared computer:
- Your personal device's security posture affects your employer's data
- Malware on a personal device can capture work credentials entered on that device
- A compromise of your personal email can enable account recovery attacks against work accounts that use it as a backup
Keep personal devices updated, use MFA on personal accounts, and be aware that work and personal security are not fully separate.
The Daily Habits That Make the Biggest Difference
- Check sender addresses before acting on email requests
- Hover before clicking links in email
- Lock your screen when stepping away
- Keep software updated
- Report suspicious emails rather than just deleting them
- Verify unexpected financial or access requests through a separate channel
None of these habits require technical expertise. They require awareness and consistency. An organisation where every employee practises these habits is significantly harder to attack than one where security is assumed to be IT's problem alone.
Your employer can run security awareness training and phishing simulations through SecureAZ