Guide to Cybersecurity for Staff

lady on a laptop graphic

Organizational staff want to keep their information and the information they handle safe. This guide provides staff with achievable security controls to help them protect organizational information. Each control area has suggestions for ways staff can level-up their security habits.

Account Security

Minimum: Use longer, stronger passwords or passphrases that are different for each website or app you use. Then, if your password for one system is stolen, the other systems remain safe. To generate and keep track of long, strong passwords, use a secure password manager.

Better: Use multi-factor authentication via Microsoft Authenticator or Google Authenticator to add another layer of security to your accounts.

Best: Use passkeys instead of passwords to authenticate. These are the most difficult to hack or steal. Passkeys can be generated with a secure password manager, a passkey device that plugs into your computer, using computers that accept biometric data (finger print/facial ID) or using a cell phone.

If circumstance require sharing of an account, use a secure password manager to share passkey or multi-factor authentication security for the account.

Phishing Prevention

Practice “Stop. Think. Verify”:

  • Stop: Email scams often try to create urgency. Pausing to calmly evaluate the email allows careful thought before any reaction.
  • Think: Does it make sense that this person is sending me this email? Is it written with wording/tone they would use?
  • Verify: If a link or an attachement to an email leads to something asking you to login, install software or click a second link, first call or talk with the sender, to make sure the email is valid.

Report suspicious emails to your technical support.

Data Loss Prevention

Check to make sure digital files containing sensitive information are restricted to “view only” for people who only need to see but not edit the data

File sharing:

  • Limit the scope of who can view files to only those idivduals or groups who need it.
  • Avoid public/”anyone with the link” sharing, unless the data is truly public.
  • Limit those who need to see the data to “view only”, unless they specifically need edit rights.

Data minimization:

  • Review and understand organizational policies for how long information must be retained as well as what type of information must be retained.
  • Schedule a periodic Data Delete Day to clean out unneeded electronic files and data.
  • If exporting data from a system, delete the exported file when no longer needed.
  • Consider the value vs. the increased data exposure of utilizing websites and apps that collect organizational data.

Many organizational data compromises can be prevented or reduced in impact by utilizing these security practices. Staff play an important part in strengthening and protecting the organization.