10 security habits every employee should build

Cybersecurity isn’t just the responsibility of IT teams. Every day, employees make decisions that can either reduce risk or create opportunities for attackers. Opening an email, approving a login request, sharing a document, or connecting to a public Wi-Fi network may seem routine, but these everyday actions often become the starting point of a security incident.

The encouraging part is that staying secure doesn’t require deep technical knowledge. Building a few simple habits can make a meaningful difference and help prevent many of the attacks organizations face every day.

Here are ten security habits every employee should build.

1. Think before you click

Cybercriminals are good at making malicious emails look legitimate. They often imitate trusted brands, colleagues, suppliers, or even senior executives to encourage people to click a link or open an attachment without thinking twice.

Before interacting with an email or message, take a moment to look a little closer. Does the sender look genuine? Were you expecting this message? Is it creating unnecessary urgency or asking you to act immediately?

Taking a few extra seconds to verify an email is often enough to spot something that doesn’t feel right.

2. Verify unexpected requests

Not every request is as genuine as it appears. An email from a colleague, a message from your manager, or a supplier asking you to update payment details can all look perfectly legitimate at first glance. Attackers rely on that trust to persuade people to share information, approve payments, or reveal credentials.

Whenever something feels unusual, pause before responding. A quick phone call or message through another trusted communication channel can confirm whether the request is genuine and help prevent an expensive mistake.

3. Use strong, unique passwords

Reusing the same password across multiple accounts is one of the easiest ways for attackers to gain access to more than one system. If credentials are exposed through a third-party breach, attackers often try the same username and password combination on email accounts, cloud services, and business applications.

Using a password manager makes it much easier to create long, unique passwords without having to remember them all yourself. It’s one of the simplest changes you can make to improve your personal and professional security.

4. Enable multi-factor authentication (MFA)

Even strong passwords can be stolen. Multi-factor authentication adds an extra layer of protection by requiring a second form of verification before someone can access your account.

Wherever possible, enable MFA on work email, business applications, cloud platforms, and any account that contains sensitive information. It’s a small step that significantly reduces the chances of unauthorized access.

 

Build stronger security habits across your organization

Our Security Awareness training helps organizations build practical, lasting security habits through realistic scenarios, hands-on exercises, and engaging learning experiences.

Request an evaluation →

 

5. Keep your devices up to date

Software updates do much more than introduce new features. They often fix vulnerabilities that attackers actively exploit, sometimes within days of those vulnerabilities becoming public.

Keeping your operating system, browser, and applications updated is one of the easiest ways to reduce your exposure to known threats. If updates are available, don’t leave them for “later.”

6. Lock your screen whenever you step away

Not every security incident happens online. Leaving your laptop unlocked in a meeting room, shared office, or public space gives anyone nearby the opportunity to access sensitive information.

Making it a habit to lock your screen whenever you leave your desk only takes a second, but it protects your work and the people you work with.

7. Be mindful of what you share online

Social media has become an invaluable source of information for attackers. Details about your role, colleagues, projects, business travel, or even your daily routine can be combined to create convincing phishing emails and social engineering attacks.

Before sharing something publicly, ask yourself whether the information could help someone impersonate you or your organization.

8. Handle sensitive information carefully when using AI tools

AI assistants have quickly become part of the modern workplace, helping employees write, summarize, analyze, and automate everyday tasks.

However, it’s important to remember that not every AI platform is intended to process confidential business information.

Before uploading documents, customer information, internal reports, or source code, make sure you’re using an approved tool and understand how your organization expects AI to be used.

Treat AI platforms with the same level of care you would any external service.

9. Report suspicious activity early

Many people avoid reporting something because they worry they’ll be mistaken. In practice, security teams would much rather investigate a false alarm than discover an incident after it has already spread.

If an email looks suspicious, a login notification seems unusual, or something simply doesn’t feel right, report it. Early reporting gives security teams the opportunity to respond before a small issue becomes a larger one.

10. Make security part of your daily routine

Security isn’t built through a single annual training session. It’s built through the small decisions people make every day.

Checking a sender before clicking a link, confirming an unexpected request, locking your laptop before leaving your desk, or reporting something unusual may seem like minor actions on their own. Together, they create a stronger security culture and help reduce risk across the entire organization.

Good habits become automatic over time, and that’s exactly what effective security awareness is designed to achieve.

 

Looking to improve security awareness across your organization?

Our Security Awareness training combines realistic attack simulations, practical exercises, and role-based learning to help employees recognize threats, make better decisions, and build secure habits that last.

Request an evaluation →

 

Building a stronger security culture

Cybersecurity is constantly evolving, but many successful attacks still rely on the same thing: people making quick decisions under pressure.

Building stronger security habits won’t eliminate every threat, but it will make it much harder for attackers to succeed.

Whether you’re working in HR, Finance, Sales, Marketing, or IT, these habits can help you make safer decisions, protect sensitive information, and contribute to a stronger security culture across your organization.

The goal of security awareness isn’t simply to teach people about cyber threats. It’s to help them recognize risky situations, respond with confidence, and make secure behaviour part of everyday work. That shift in behavior is what creates lasting resilience.

Design your training strategy

Transform your team’s capabilities. Book a strategy call to discuss your training and hiring needs.

Latest updates & insights

Your source for new partnerships, cybersecurity insights, expert content, and upcoming events.

Syllabus:

Intro to GCP

  • GCP Hierarchy
  • Google Workspace
  • gcloud config
  • Basic Hacking Techniques

Exploitation of GCP Services

  • IAM
  • KMS
  • Secrets 
  • Storage
  • Compute Instances & VPC
  • Cloud Functions
  • CloudSQL
  • Pub/Sub
  • App Engine
  • Google APIs
  • Cloud Shell

Methodologies

  • White box

Security Services

  • GCP Logging & Monitoring

Syllabus:

Intro to AWS

  • AWS Organization
  • AWS Principals
  • Basic Hacking Techniques

Exploitation of AWS Services

  • IAM
  • STS
  • KMS
  • Secrets Manager
  • S3
  • EC2 & VPC
  • Lambda
  • RDS
  • SQS
  • SNS

Methologies

  • White box

Common Detection Mechanisms

  • CloudTrail

Syllabus:

Azure Basics

  • Azure Organization
  • Entra ID
  • Azure Tokens & APIs
  • Basic Enumeration Tools

 

Exploitation of Azure Services

  • Entra ID IAM
  • Azure IAM
  • Azure Applications
  • Azure Key Vault
  • Azure Virtual Machine & Networking
  • Storage Accounts
  • Azure File Share
  • Azure Table Storage
  • Azure SQL Database
  • Azure MySQL & PostgreSQL
  • Azure CosmosDB
  • Azure App Service
  • Basic Azure Research Technique
  • Azure Function Apps
  • Static Web Apps
  • Azure Container Registry
  • Azure Container
  • Instances, Apps & Jobs
  • Azure Queue
  • Azure Service Bus
  • Azure Automation Account
  • Azure Logic Apps
  • Azure Cloud Shell
  • Azure Virtual Desktop

 

Methologies

  • White box
  • Black box
  • Pivoting between Entra ID & AD

 

Common Detection Mechanisms

  • Azure & Entra ID Logging & Monitoring
  • Microsoft Sentinel
  • Microsoft Defender for Cloud & Microsoft Defender EASM

Fundamentals and Setup

  1. Overview of Android’s architecture and ecosystem dynamics.
  2. Exploration of security features native to Android using Java, Kotlin, C++, and Rust.
  3. Mobile Application Threat Model
    a) Differences between mobile and web application threat models.
    b) Applying threat modeling techniques specifically to mobile applications.
    c) Case studies highlighting potential threats and vulnerabilities.
    d) How do we secure and test cross platform apps (e.g. ReactNative, Xamarin, etc).
  4. Introduction to industry mobile security standards
    a) OWASP Mobile Application Security (MAS) project
    b) Effective usage of the Mobile Application Security Verification Standard (MASVS).
    c) Effective usage of the Mobile Security Testing Guide (MSTG).
    d) Overview of the OWASP top 10 for mobile.
  5. Setting up and preparing a mobile security testing lab
    a) Configuration of industry-standard tools and guidance on their appropriate use.
    b) Setup of virtual mobile devices using Corellium, including its advantages.
    c) Introductory exercises to familiarize with the tools.
  6. Secure Coding Overview
    a) Exercises to identify vulnerabilities in code examples
    b) Discussion of the appropriate mechanisms for remediation
    c) Practical session on remediation and re-testing the app
  7. Secure storage
    a) Overview of application storage mechanisms.
    b) Introduction to cryptographic storage solutions on Android.

Advanced Techniques and Practical Application

  • Mobile penetration testing methodology
    a) Methodologies used in real-world scenarios with practical tips and tricks.
  • Identifying issues with backend APIs
    a) Examination of client-side trust issues.
    b) Analysis of insecure communications including certificate validation and pinning.
  • Cryptography in Android apps
    a) Utilization of Android’s Crypto APIs.
    b) Implementation of native cryptography using libraries like libnacl and OpenSSL.
    c) Management of cryptographic keys.
  • Authentication and Authorization
    a) Testing client-side authentication mechanisms, including secure usage of biometrics.
    b) Strategies to detect and bypass authentication flaws.
    c) Security measures for API authentication.
  • Android IPC
    a) Detailed exploration of Intents, deep links, Binders/services, and broadcast receivers.
  • Webviews
    a) Identifying and resolving common security issues in Android Webview configurations.
  • Software Composition Analysis (SBOM)
    a) Techniques to determine the components of an Android app.
    b) Identifying known vulnerabilities within these components.
  • Mobile Device Management (MDM)
    a) Introduction to Mobile Device Management: definition, core features, and its role in enhancing organizational security.
    b) Discussion on the benefits and practical applications of MDM in controlling and securing mobile devices across an enterprise.
  • Mobile Application Management (MAM)
    a) Overview of Mobile Application Management: what it entails and its significance in enterprise environments.
    b) Exploration of how MAM contributes to managing and securing applications specifically, detailing its utility for enterprise security strategies.

Advanced Techniques and Practical Application

  • Mobile penetration testing methodology
    a) Methodologies used in real-world scenarios with practical tips and tricks.
  • Identifying issues with backend APIs
    a) Examination of client-side trust issues.
    b) Analysis of insecure communications including App Transport Security issues & certificate pinning.
  • Cryptography in IOS apps
    a) Utilization of iOS’s CryptoKit & CommonCrypto APIs.
    b) Implementation of native cryptography using libraries like libnacl and OpenSSL.
    c) Management of cryptographic keys and leveraging the secure enclave.
  • Authentication and Authorization
    a) Testing client-side authentication mechanisms, including secure usage of Local Authentication (biometrics).
    b) Strategies to detect and bypass authentication flaws.
    c) Security measures for API authentication.
    d) Using Device Check and App Attest
  • iOS IPC
    a) Detailed exploration of URL schemes, deep (universal) links, and extensions.
  • Webviews
    a) Identifying and resolving common security issues in iOS Webview configurations.
  • Software Composition Analysis (SBOM)
    a) Techniques to determine the components of an iOS app.
    b) Identifying known vulnerabilities within these components.
  • Implementing App Integrity
    a) What to look for
    b) How to implement
  • Mobile Device Management (MDM)
    a) Introduction to Mobile Device Management: definition, core features, and its role in enhancing organizational security.
    b) Discussion on the benefits and practical applications of MDM in controlling and securing mobile devices across an enterprise.
  • Mobile Application Management (MAM)
    a) Overview of Mobile Application Management: what it entails and its significance in enterprise environments.
    b) Exploration of how MAM contributes to managing and securing applications specifically, detailing its utility for enterprise security strategies.

Fundamentals & Setup

  1. Overview of iOS’s architecture and ecosystem dynamics.
  2. Exploration of security features native to to iOS using Objective-C, Swift, and C(++).
  3. Mobile Application Threat Model
    a) Differences between mobile and web application threat models.
    b) Applying threat modeling techniques specifically to mobile applications.
    c) Case studies highlighting potential threats and vulnerabilities.
    d) How do we secure and test cross platform apps (e.g. ReactNative, Xamarin, etc).
  4. Introduction to industry mobile security standards
    a) OWASP Mobile Application Security (MAS) project
    b) Effective usage of the Mobile Application Security Verification Standard (MASVS).
    c) Effective usage of the Mobile Security Testing Guide (MSTG).
    d) Overview of the OWASP top 10 for mobile.
  5. Setting up and preparing a mobile security testing lab
    a) Configuration of industry-standard tools and guidance on their appropriate use.
    b) Setup of virtual mobile devices using Corellium, including its advantages.
    c) Introductory exercises to familiarize with the tools.
  6. Secure Coding Overview
    a) Exercises to identify vulnerabilities in iOS code examples
    b) Discussion of the appropriate mechanisms for remediation
    c) Practical session on remediation and re-testing the app
  7. Secure storage
    a) Overview of application storage mechanisms.
    b) Introduction to cryptographic storage solutions on iOS.