New Starters and Cyber Security (Devices, Access and Training)
Scammers are often on the lookout for new starters.
New employees are keen to help, do not yet know who is who and are setting up accounts and logins for the first time. That makes them an easy target for a convincing email that looks like it comes from a manager or a supplier. A simple, repeatable onboarding checklist lowers that risk and makes the first week smoother for everyone. Here is one that works for small businesses.
1. Devices: get the basics locked down before day one
Have the new starter’s device ready before they arrive, so they are not tempted to use a personal laptop or phone while they wait.
- Issue a company-managed laptop and phone wherever possible.
- Install all updates to the operating system, browser and key apps before handing it over.
- Turn on disk encryption and an automatic screen lock.
- Install and check your endpoint protection, such as antivirus.
- Make sure the right folders are backed up automatically.
For details on Cyber Security Services, visit www.majestecltd.co.uk/
2. Access: give only what is needed
The principle here is least privilege: people get access to the systems and data they need for their job, and nothing more. It limits the damage if an account is ever compromised.
- Create an individual user account. Never share logins between staff.
- Turn on multi-factor authentication for email, finance and admin tools.
- Give access only to the systems and folders the role requires.
- Add the person to the right groups so permissions are managed in one place.
- Book a review after 30 days and remove anything they do not use.
3. Training: head off the common first-week mistakes
A short session in the first week covers the situations new starters are most likely to meet.
- How to spot phishing: urgent requests, unfamiliar links and sudden changes to payment details.
- Your process for invoice requests and supplier bank detail changes, including checking by phone on a known number.
- How to handle customer data safely, and what can and cannot be emailed or downloaded.
- How to report something suspicious. The simple rule is: if you are not sure, stop and ask.
Make it clear that reporting a mistake quickly is always the right thing to do. A new starter who clicked a bad link and says so straight away is far less of a risk than one who stays quiet because they are worried about getting into trouble.
4. Plan for leavers now
Record everything you set up for each person as you go: accounts, devices, group memberships and any shared passwords they were given. When they leave, you can then remove access cleanly and on the same day, rather than discovering months later that a former employee could still log in.
The checklist at a glance
| When | Task | Owner |
|---|---|---|
| Before day one | Device set up, updated, encrypted and backed up | IT or manager |
| Day one | Individual account, MFA, least-privilege access | IT or manager |
| First week | Phishing, payments and data handling training | Manager |
| Day 30 | Access review | IT or manager |
| On leaving | Remove access, recover devices | IT or manager |
Frequently asked questions
Why do scammers target new employees?
New starters do not yet know how the business normally works, who their colleagues are or how payments are approved. A message that appears to come from a director asking for an urgent favour, or from IT asking them to confirm their new password, is much harder to question in the first few weeks.
Is multi-factor authentication really necessary for a small business?
Yes. It is one of the most effective protections available, because a stolen password alone is no longer enough to get into the account. Most email and cloud services include it at no extra cost, and it takes a few minutes per person to set up.
Where to go next
For the wider picture, read our guide to preventing network attacks.
A secure onboarding process is one of the simplest ways to prevent breaches.
