top of page

What is Cyber Security? What Every Employee Must Know

Cybercrime is a growing concern for every organisation. In the UK, there were 239,600 cyber-enabled crime reports in 2025, resulting in £1.63 billion in reported financial losses. Around 40% of businesses and 30% of charities have experienced cyber attacks in the past year, including 91% of universities.


Educating staff about cyber crime is, therefore, critical to preventing losses. It’s not the sole responsibility of the IT department. A single unsafe click, shared password, or unreported incident can expose an entire organisation.


Below, we explain the cyber security dos and don’ts every employee should understand, including:



Retro illustrative red robot with orange eyes

Who Is Targeting Us, and What Are They Looking For?


Crime has moved online. With large parts of an organisation’s operations taking place online, criminals have more opportunities to target its systems, data, and employees.


The main threat actors include:


  • Opportunistic cybercriminals

  • Organised ransomware groups

  • Fraudsters and credential thieves

  • Malicious insiders

  • Hacktivists

  • State-sponsored groups


Many attacks are financially motivated, using fraud, extortion, or stolen data to make money. Others aim to conduct espionage, disrupt services, damage reputations, or advance political or ideological goals.


Groups may be after passwords, customer data, payment information, intellectual property, or system access.


The Core Principles of Information Security


Information security has three objectives:


  1. Confidentiality means ensuring that information is only accessible to authorised people. Passwords, encryption, access controls, and secure handling procedures help protect it.

  2. Integrity means keeping information accurate, complete, and protected from unauthorised alteration or deletion.

  3. Availability means ensuring that authorised users can access information and systems when needed. Backups, updates, and continuity planning support this principle.


This doesn’t have to be extremely complicated. For example, consider a customer database.

Confidentiality means restricting access to authorised employees, integrity means ensuring records cannot be improperly changed, and availability means keeping the database accessible through reliable systems and backups.


Retro grey robot with brightly coloured buttons

The Dos and Don’ts of Cyber Security


To help you and your colleagues stay safe while working online we're sharing our top tips:


1. Do Inspect Links, But Don’t Click Blindly


Cybersecurity 101 is never to click links blindly. Check the sender’s full address and hover over links before opening them.


If the email address is unusual, the domain is misspelled, there’s a sense of urgency, or the email has unexpected attachments, it’s best not to click.


2. Do Use a Password Manager


Password managers can help create and store strong, unique passwords. Use an approved option and protect it with multi-factor authentication.


3. Don’t Share Logins


Shared credentials remove accountability and make compromised access harder to trace. Use an authorised shared-access system or request a separate account instead.


4. Do Lock Your Screen


Leaving your screen unattended creates an opportunity for a cybercriminal, even for a few minutes. Someone could enter the building under false pretenses and access your account. It’s always best to lock the screen and set devices to lock automatically after a short period of inactivity.


5. Don’t Leave Laptops Unattended


Just as your screen should be locked, devices themselves should not be left unattended. Keep devices physically secure in offices, cafés, vehicles, hotels, and public spaces. Store laptops out of sight and follow company transport and storage policies.


6. Do Use the Corporate VPN


An approved VPN offers great protection when working away from the office. It can protect the connection; however, it does not make suspicious websites or downloads safe.


7. Don’t Use Public Wi-Fi Without Protection


Working from home is now common. But that can mean working from a café, hotel, or airport. The problem is these Wi-Fi networks are often insecure. Using a home network or mobile hotspot is preferable.


If public Wi-Fi is unavoidable, follow company policy and use an approved VPN.


8. Do Report Incidents Immediately, and Don’t Fix Them Yourself


Immediately report suspicious emails, accidental clicks, lost devices, unusual login alerts, and exposed information. Do not delete evidence, investigate the attack, or make unapproved changes yourself. The faster you report the problem, the easier it is to mitigate the damage.


Secure Remote Work and Device Safety Policies


Companies can support their staff with a clear remote work and device safety policy. It can explain why there’s a risk and the best practices to minimise damage.


It should cover:


  • Use approved and properly configured devices.

  • Install security updates promptly.

  • Keep antivirus or endpoint protection active.

  • Encrypt devices and maintain approved backups.

  • Secure home routers with strong passwords and current firmware.

  • Avoid unapproved USB drives, software, and cloud-storage services.

  • Prevent family members or housemates from using work devices.

  • Protect confidential conversations and screens in shared spaces.


Are Your Passwords Actually Protecting Company Data?


Using a password alone does not provide the strongest protection. Password length and uniqueness matter more than minor, predictable substitutions. Use an approved password manager and multi-factor authentication. Where supported, passkeys provide a secure alternative to passwords.


Reusing passwords across multiple platforms or storing passwords in obvious locations should be avoided. It makes it easy for cybercriminals to access the system.


Common Cyber Security Threats: Phishing, Malware, and Social Engineering


Cyber criminals are becoming increasingly sophisticated. Phishing is described as fraudulent communication designed to make someone reveal information, open a file, send money, or visit a malicious website.


Malware, on the other hand, is a piece of software that steals information, monitors activity, encrypts files, or provides attackers with remote access.


Perhaps most sophisticated of all is social engineering. To circumvent protections, criminals will manipulate people rather than directly defeating technical security. Tactics include fake password-reset emails, invoice and payment fraud, impersonation of senior employees, or repeated multi-factor authentication requests.


Can You Spot a Phishing Email in Under Five Seconds?


Some phishing emails contain obvious warning signs, but sophisticated attacks can be difficult to spot. All it takes is one click without thinking.


  • That’s why it’s crucial to train staff to ask the right questions.

  • Is the sender or domain unfamiliar?

  • Is the message unexpected?

  • Does it create urgency or fear?

  • Does it request passwords, payments, or sensitive information?

  • Does the link lead somewhere different from its displayed text?

  • Is there an unusual attachment or QR code?


These questions cannot confirm that an email is safe, but they can reveal obvious warning signs.


Retro grey robot shooting fire out of body

How to Respond and Report an Incident


Just as company policies should be clear about how to avoid a cyber incident, they should also detail what should happen if one occurs.


Employees should immediately stop interacting with the message, website, or file. The employee should write a report detailing what happened, when it happened, which device was involved, and whether any information was entered. Any affected devices should be disconnected.

Even near misses must be documented, as they can expose potential weak spots and help improve overall security.


How to Implement Daily Compliance


Cyber security should be built into small, repeatable workplace habits rather than treated as an annual exercise. Provide clear induction training, regular refreshers, realistic phishing simulations, and a simple, blame-free reporting process. Organisations should also require multi-factor authentication, approved password managers, regular updates, and appropriate access controls.


Effective security depends on employees understanding both the rules and why they matter. flick Learning’s Cyber Security Training provides a concise introduction in approximately 13 minutes. The CPD-certified Level 2 course includes an assessment and downloadable certificate.


Keep up to date with all things flick, including our latest news and features, by signing up to our monthly newsletter and by making sure you are following us on LinkedIn, Facebook, and Instagram.

Comments


bottom of page