Modern Australian
Men's Weekly

.

How to encourage cyber-safe behaviour at work without becoming the office grouch

  • Written by Nathalie Collins, Academic Director (National Programs), Edith Cowan University

Business etiquette has one golden rule: treat others with respect and care. The same is true for encouraging cyber safety at work, on everything from password security to keeping valuable information like tax file numbers safe.

But how can you encourage cyber-safe behaviour at work without becoming the office grouch?

The trick, as it often is in life, is to encourage the right behaviours tactfully and by offering helpful solutions. Vilifying or mocking those who “do the wrong thing” is unlikely to help.

In short, offer alternatives and not reproach.

Hey, what’s your password?

Many organisations have policies to prevent password sharing (and most, by now, would hopefully actively discourage people from keeping passwords on a Post-it note stuck to a computer). However, asking others for a password is not yet necessarily considered taboo.

Perhaps your colleague wants to use your computer and asks for your login. Or they may need access to a shared repository such as Dropbox but have forgotten the password.

Two women chat while looking at a computer. If you’re reluctant to share your personal password, your instincts are correct. Shutterstock

If you’re reluctant to share your personal password, or broadcast a team password in Slack or on a group chat, your instincts are correct. Passwords are deeply valuable pieces of information, and many catastrophic security breaches can be traced back to poor password management at work.

But if your colleague asks for a password, rather than responding with a short, sharp “no”, soften the blow by asking why they want it. If there is a legitimate reason, work with them to resolve the issue — without giving anything away.

For example, instead of posting a Dropbox password on Slack, can you direct them to your organisation’s password manager and help them learn how to retrieve passwords from it? If it’s access to a computer they need, can you help them restart a computer and log in as a guest instead of as you?

Never send usernames and passwords by email.

Read more: A computer can guess more than 100,000,000,000 passwords per second. Still think yours is secure?

If systems are not in place at work to help people who need access to a shared password or a computer terminal, talk to your IT team about finding long-term solutions. That might include investing in a password manager such as 1Password, Dashlane or LastPass.

Files can be shared within teams through OneDrive, Dropbox or other organisational repository to reduce the need for a colleague to access your computer to “just get a file off it”.

‘Please fill in this confidential form and email it to me’

It’s not uncommon for IT, HR, finance or well-meaning admin support staff to ask you to fill in a form with sensitive information and just “email it back”.

Even doctors and lawyers have been known to mishandle documents with signatures, tax file numbers or other identifying information such as birthdays.

Don’t feel under pressure to do it. The fact is, such information is invaluable to hackers and identity thieves. Should your workplace email suffer a data breach, bad actors may be able to retrieve these scanned forms from inboxes they’ve invaded.

Read more: Everyone falls for fake emails: lessons from cybersecurity summer school

Most organisations have secure ways of transferring files, varying from a secure cloud storage solution to secure file sharing sites. Use them, and never your personal email or cloud solutions.

If your organisation doesn’t have a secure way to save the files you can use one and send your colleague the link in a work email.

Alternatively, you can send an encrypted PDF in an email, which means much tighter control of who can access the file.

Sometimes the safest solutions are the simplest. Go old-school: walk the documents over to the person instead of scanning and emailing them.

If you’re asked to send personal information in an insecure way, hide your Pikachu face. Instead, say: “We’re supposed to be transferring files this way. If you want, I can show you how for next time?”

Offering a solution, rather than shaming, is much more likely to lead to change.

A person scans forms at work. Sometimes the safest solutions are the simplest; if you can, just walk the documents over to the person instead of scanning and emailing them. Shutterstock

Can you pass on my resume?

Job-hunters may try to get their foot in the door by leveraging a friend or ex-colleague. Many of us would be keen to help a friend by passing on their CV to the boss.

Unfortunately, malicious actors of all kinds also know this. As outlined in this article, fake CVs can be sent by email with a Microsoft Excel attachment. When opened, the attached file can launch malware that:

…then attempts to hijack private information, credentials from users of targeted financial institutions, and passwords and cookies stored in web browsers. Attackers can then exploit these acquisitions to make financial transactions.

Malware is not just embedded in links and attachments - even LinkedIn messages can contain malware. The consequences of opening such links or attachments can be extreme, and may even include ransomware (where hackers refuse access to files or online systems until the victim pays up).

A computer displays the homepage of LinkedIn. Even LinkedIn messages can contain malware. Shutterstock

Don’t pass on CVs, especially if the person is a friend of a friend. Instead, pass on the person’s name to the boss, so she or he can look them up on LinkedIn. Don’t follow links sent to you, even by trusted contacts. Links can often be difficult to check without clicking on them and you may be redirected to a malicious site.

And if you are the jobseeker, demonstrate your own cyber-security awareness by not circulating CVs or other documents with personal information that may be valuable to identity thieves. No birthdays, addresses, just email, mobile number and LinkedIn.

The same rule applies to QR codes - don’t blindly open the webpage pointed to on a business card QR code. You may get more than you bargained for.

Resist the urge to do something unsafe when on deadline

Unfortunately, many workplaces still see cyber-unsafe behaviour as broadly acceptable and the pressure to do something unsafe, especially when on deadline, can be profound.

But by treading respectfully, and helpfully, you can improve your office reputation as a cybersafe staff member and help reduce the risk to your organisation.

Authors: Nathalie Collins, Academic Director (National Programs), Edith Cowan University

Read more https://theconversation.com/how-to-encourage-cyber-safe-behaviour-at-work-without-becoming-the-office-grouch-152319

Keeping Lone and Remote Workers Safe: Employer Duties and Practical Solutions

In Australia, thousands of employees work alone, in remote locations, or in direct contact with the public every day. While these roles are critical...

How Your General Dentist Supports Your Smile Over a Lifetime

A healthy grin is more than just a desirable feature; it reflects overall health, well-being, and self-esteem. Our oral health needs evolve from chi...

A Brighter Smile in Sydney: Expert Cosmetic Dentists and Veneers Solutions

A confident smile can open doors, boost your self-esteem, and leave a lasting impression. In Sydney, more people than ever are turning to cosmetic den...

How To Keep Vase Flowers Fresh Through Australia’s Coldest Months

Winter flowers develop slowly, which gives them stronger structure and longer vase life Heat from indoor environments is the biggest threat to th...

Artificial Intelligence is Powering the Growth of Australian Telehealth Services

Many Australians have traditionally experienced difficulties in accessing timely and quality healthcare, especially those who live in rural or remot...

VR Training in Australia – Customer Service Risk Management

In today’s rapidly evolving workplaces, Australian organisations are turning to immersive learning tools like VR to handle specialised needs such ...

Powering Shepparton’s Businesses: Expert Commercial Electrical Services You Can Count On

When it comes to running a successful business, having reliable, compliant, and efficient electrical systems is non-negotiable. From small retail ou...

Maximise Efficiency: Cleaner Solar Panels for Optimal Performance

Solar panels are a smart investment in energy efficiency, sustainability, and long-term savings—especially here in Cairns, where the tropical sun ...

7 Common Air Conditioner Issues in Melbourne – And How to Fix Them

Image by freepik Living in Melbourne, we all know how unpredictable the weather can be. One moment it’s cold and windy, the next it’s a scorchin...

Powering Palm QLD with Reliable Electrical Solutions

Image by pvproductions on Freepik When it comes to finding a trustworthy electrician Palm QLD locals can count on, the team at East Coast Sparkies s...

The Smart Way to Grow Online: SEO Management Sydney Businesses Can Rely On

If you’re a Sydney-based business owner, you already know the digital space is crowded. But with the right strategy, you don’t need to shout the...

What Your Car Says About You: The Personality Behind the Vehicle

You can tell a lot about someone by the car they drive—or at least, that’s what people think. True Blue Mobile Mechanics reckon the car says a l...

The Confidence Curve: Why Boudoir Photography Is the Empowerment Trend You Didn’t Know You Needed

Boudoir photography has been quietly taking over social feeds, Pinterest boards, and personal milestones—and for good reason. It’s not just abou...

Understanding Level 2 Electricians: Why Sydney Residents Need Licenced Experts for Complex Electrical Work

When it comes to electrical work around the home or business, not all electricians are created equal. In Sydney, particularly when you're dealing wi...

Retirement Anchored in Model Boat Building for Waterford’s Doug Unsold

WATERFORD — When Doug Unsold sees his ship come in, it’s usually one he’s crafted with his own hands. The 67-year-old retiree from Waterford ...

The Science Behind Alarm Clocks and Your Circadian Rhythm

Waking up on time isn’t just about setting an alarm—it’s about working with your body, not against it. At the heart of every restful night and...

How to Use Plants to Create a Calming Atmosphere in Your Home

In today’s fast-paced world, cultivating a calm, soothing environment at home has never been more important. Whether you live in a busy urban apar...

How Maths Tutoring Can Help Students Master Maths

Mathematics can be a daunting subject for many students, often causing stress and frustration. However, maths tutoring has proven to be an effective...