Cyber Security
Cyber security basics for employees: a 12-point checklist for UK staff
A practical cyber security checklist for employees in UK small businesses: phishing, passwords, MFA, devices, data handling and how to report an incident.
By Dig IT SolutionsUpdated 8 September 20266 min read
Short answer
Every employee should know how to spot a phishing message, use a unique password with multi-factor authentication, lock and update their devices, handle company data only through approved systems and report anything suspicious straight away. Those five habits stop most of the attacks that reach UK small businesses, because most breaches start with a person, not a firewall.
Most cyber incidents in small businesses start with a person doing something ordinary: opening an attachment, approving a login prompt, reusing a password. That is not a criticism of staff, it is a description of how attackers work. The Cyber Security Breaches Survey from the UK government has found year after year that phishing is the most common attack reported by businesses, and phishing is aimed squarely at people.
This article is written for the people, not the IT department. It is a checklist you can print, put on the intranet or use as the basis of an induction. Managers: if you want it delivered as a short session with a phishing test afterwards, that is what our security awareness training does.
The 12-point staff checklist
- Pause before you click. Urgency, secrecy and unexpected attachments are the three signs of a phishing message. If an email pressures you to act now, treat that pressure as the warning.
- Check the sender, not the name. Display names are free to fake. Look at the actual address, and look at where a link really goes before you follow it.
- Verify payment and bank-detail changes by phone. Use a number you already hold, never one in the email. This one habit defeats most invoice fraud.
- Use a different password for every work account. Three random words make a strong, memorable password, as the NCSC recommends. Never reuse your work password anywhere else.
- Use the password manager. If your business provides one, put everything in it. If it does not, ask why not.
- Turn on multi-factor authentication (MFA) and never approve a prompt you did not trigger. If your phone asks you to approve a sign-in while you are making a cup of tea, that is someone else trying to get in. Deny it and report it.
- Lock your screen when you step away. Windows key + L. It takes half a second and it matters in shared offices, client sites and cafés.
- Install updates when asked. Restart when your laptop wants to restart. Attackers exploit known, already-patched flaws far more often than unknown ones.
- Keep company data in company systems. Do not forward work documents to personal email, personal cloud storage or WhatsApp, and do not plug in unknown USB sticks.
- Only access what your job needs. If you find you can open something you should not be able to, tell IT rather than browsing it.
- Be careful with public Wi-Fi. Use your phone's hotspot or the company VPN in preference to hotel and café networks.
- Report anything odd, immediately, without embarrassment. A clicked link, a lost phone, an unusual login alert, a strange pop-up. Reporting early is the difference between a quiet fix and a bad week.
The rest of this article explains the reasoning behind each group of points, because people follow rules they understand.
Phishing: the attack that reaches you personally
Phishing is any message designed to get you to hand over credentials, approve a payment or run something malicious. It arrives by email most often, but also by text ("smishing"), phone ("vishing"), QR code and Microsoft Teams message. The modern versions are well written and often use a real supplier's name, so spelling mistakes are no longer a reliable tell.
The reliable tells are behavioural. Is the message trying to make you act quickly? Is it asking for something unusual, such as a change of bank details, a gift-card purchase or your password? Does the link lead somewhere that does not match the sender? If any of those are true, stop and check through a different channel.
Forward suspicious emails to the NCSC's Suspicious Email Reporting Service at report@phishing.gov.uk, and forward scam texts to 7726 free of charge. Both are official UK reporting routes and they help take down the sites behind the messages. Our companion article on how phishing attacks work and how to spot them has worked examples.
Passwords and MFA: the two habits that block account takeover
Stolen and reused passwords are how most accounts are broken into. Attackers buy lists of leaked credentials from other breaches and simply try them against Microsoft 365. If your work password is the same as an old shopping account password, that is the route in.
The NCSC's guidance is practical: use a long password built from three random words, use a different one for every account, store them in a password manager and do not change them on a schedule. Forced 90-day changes lead to "Summer2026!" style passwords that attackers guess first.
MFA (a code, app prompt or security key on top of the password) closes most of the remaining gap. The one thing to remember is that attackers now try to exploit MFA by sending you repeated prompts hoping you approve one to make them stop. Never approve a prompt you did not trigger. We cover the options, including phishing-resistant methods, in what MFA is and why your business needs it.
Devices: updates, locks and where you connect
An unpatched laptop is an open door. Windows 10 reached end of support in October 2025, so if you are still using one without extended support, tell your manager. Otherwise, the rule is simple: install updates when prompted and restart when asked. In businesses we manage, updates are pushed centrally, but the restart still needs you.
Lock your screen every time you leave your desk, keep laptops out of sight in cars, and use your phone's hotspot rather than public Wi-Fi when you can. If you use a personal phone for email, expect it to need a PIN, encryption and a managed app. Our guide to BYOD security risks explains why.
Data: keep it where the business can protect it
Under UK GDPR your employer is responsible for personal data wherever it ends up, and the ICO expects businesses to be able to show where that data is. Forwarding a customer list to your Gmail to work on at the weekend breaks that, however good the intention. Use SharePoint, OneDrive or Teams, share links rather than attachments, and ask before installing new apps that handle company information.
If you leave the business, your access will be removed and any work data on personal devices wiped through management tools. That is normal, and it is why keeping personal and work data separate protects you too.
Reporting: the habit that matters most
Every point above can fail. Someone will eventually click a convincing link. What decides the outcome is how quickly IT hears about it. A compromised Microsoft 365 account reported within minutes gets its password reset and sessions revoked before any damage is done. The same account discovered weeks later may have been used to send fraudulent invoices to every customer in your address book.
Good businesses make reporting easy and blame-free. If yours punishes people for reporting mistakes, people will stop reporting them, and that is the real risk.
For managers: turning the checklist into a programme
A checklist on the wall helps, but the businesses that see phishing click rates fall do three further things. They run short, regular awareness sessions rather than one annual slog. They test with simulated phishing and share the results openly. And they back the training with technology so the secure option is the easy one: a password manager, MFA everywhere, email filtering that removes the obvious lures, and endpoint protection that catches what gets through.
If you want a framework to build around, the five controls of Cyber Essentials cover the technical side and map neatly onto the habits above. Our Cyber Essentials guide explains what is involved.
What to do next
Share this checklist with your team, then find out how they would actually respond to a phishing email. We run security awareness training with simulated phishing for businesses across Hertfordshire, Essex and London. To talk it through with an engineer, contact us.

