1. Treat unexpected requests as unverified
Attackers create urgency: an overdue invoice, a password expiry, a senior manager demanding a payment or a delivery requiring immediate action. Pause and verify the request through a trusted channel, particularly when money, credentials or confidential information are involved.
2. Use strong, unique authentication
Passwords should not be reused across services. A password manager can generate and store unique credentials. Multi-factor authentication adds another control, although users must still reject unexpected approval prompts.
3. Keep devices and software updated
Updates often correct known vulnerabilities. Delaying them gives attackers more time to exploit weaknesses. Organisation-managed devices should follow an agreed update process rather than relying entirely on individual memory.
4. Handle information according to its sensitivity
Before sharing, downloading or uploading information, consider whether the recipient, location and service are authorised. Public AI tools and personal cloud accounts should never receive organisational information unless policy explicitly permits it.
5. Report quickly—even after a mistake
Someone who clicks a suspicious link should report it immediately rather than hide it. Early reporting gives the security team time to reset credentials, isolate devices and investigate. A blame culture delays action and increases damage.