IT security checklist for employees

IT security checklist for employees



Eight Spoked Asterisk One-off checks

Devices:

Check if your  operating system  is (still) supportedOnly devices from reputable brands running an actively supported OS receive security patches. Outdated systems have known vulnerabilities that attackers can exploit.
Set your OS and apps to  automatically update  Most cyberattacks exploit known vulnerabilities that updates have already fixed. Enable automatic updates so this happens without thinking about it.
Lock all your devices with a  password, PIN, or biometrics  The first line of defence against unauthorised access if a device is lost or stolen. Without it, anyone can pick it up and open it.
Set  automatic screen lock  (5 minutes) Prevents others from accessing your device when you step away and forget to lock it manually. Also lock it yourself any time you take a break.
Check what  security software  is already installed, and activate/install if needed Protects against viruses, malware, ransomware, and dangerous websites. Windows includes Microsoft Defender built in; Mac users should add Malwarebytes or Bitdefender.
Enable  disk encryption  (FileVault / BitLocker / Device Encryption) A screen lock alone doesn't protect locally stored files if someone removes the drive or boots from USB. Encryption makes the data unreadable without your credentials — and a lost unencrypted device containing personal data is mostly a reportable incident under the AVG.
Set your device's recycle bin to  delete files automatically after 30 days Files in the recycle bin are still on your device and recoverable. Auto-deletion ensures they're gone for good — reducing the risk of sensitive data sitting around unnoticed.

Passwords:

 Store  all your passwords in the password manager A password manager is the only reliable way to use strong, unique passwords across all accounts without having to remember them. Easiest: use the  import/export  function to migrate existing passwords in one go.
 Delete  all saved passwords from your browser(s) / former password manager / stored elsewhere Passwords saved in browsers, documents, emails, or on paper are easy to steal and hard to update consistently. The password manager is the single place they should live.
Replace weak passwords with  strong passwords  generated by the password manager Human-chosen passwords are predictable. Generated passwords (minimum 14 characters, random) are not — and the manager remembers them for you, so there's no trade-off.
Enable  SSO  (preferred option) or MFA/2FA (alternative option) on all your business accounts (  list per tool  ) If a password is stolen or guessed, SSO/MFA is what stops an attacker from actually getting in. Enable it on every business account you have.

Policy:

Sign the  Information Security Policy for employees  By signing, you confirm you've read and understood what's expected of you. This also gives the organisation a clear record of who has been informed.


Counterclockwise Arrows Button Recurring checks

Monthly:

Only needed if you couldn't set this automatically on your device (as suggested above):
Delete (or move) all items from your (1) downloads folder, (2) desktop, and (3) recycle binBusiness files that accumulate locally — especially in Downloads — are outside your secure cloud environment. Move them to the right business application or delete them.
Check that all  security updates  are installed on your device Most successful attacks exploit known vulnerabilities that already have a patch available. Keeping your OS, browser, and software up to date closes those gaps.

Quarterly:

Check that the devices you use for business software still meet the requirements of the  Information Security Policy for employees  Devices change — new phone, different laptop, updated OS. A quarterly check ensures everything you use for work still complies.
Check that  SSO  (preferred option) or  MFA/2FA  (alternative option) is still active on all business accounts Access settings can inadvertently change after updates, account migrations, or when adding new tools. A quarterly check ensures nothing has slipped through.
Check your password manager's security report for weak passwords, missing MFA, or other vulnerabilities (e.g.  Proton Pass monitor  ) The report flags things that are easy to miss individually — reused passwords, accounts without MFA, compromised credentials. Fix any issues flagged.

Yearly:

(Re-)read the  Information Security Policy for employees  Policies evolve. An annual read ensures you're up to date with any changes and keeps good habits front of mind.
Take  Google's phishing quiz  (8 questions - takes ± 5 minutes) Phishing is the most common way attackers gain access. Eight quick questions that sharpen your ability to spot it.
For organisations that use Google: Ensure that your  Google Security Checkup  results in 'No issues found'A quick scan of your Google account's security settings — connected apps, recent sign-in activity, recovery options. Aim for 'No issues found'.