Landing your first office job is a major milestone. You’ve mastered the commute, worked out what everyone means by “let’s take this offline” and “EOP” – as well as, hopefully figured out where the free coffee is. But there’s another part of office life that rarely makes it into the graduate handbook: staying safe online.
Aaron Engel, Chief Information Security Officer at ExpressVPN, shares his top tips for maintaining good digital hygiene when starting a new job. From convincing phishing emails to fake requests from your boss, scammers know that new employees may be unfamiliar with company processes and that makes them an easy target. Here are seven simple habits to adopt from day one.
1. Don’t assume an email is genuine because it looks professional
Phishing emails have come a long way. A message can appear to come from your manager, a colleague or a familiar company and still be malicious, whether it’s asking you to click a suspicious link or making an unusual financial request. Before responding, check the sender’s email address carefully and look out for anything that feels out of character, creates urgency or asks you to bypass normal processes.
This is also where “out-of-band” validation comes in. If you receive an unusual request from your boss or another colleague, don’t validate it by replying to the same email, contact them through company-approved messaging channels. The same principle applies to less dramatic requests, such as being asked to buy gift cards or share sensitive information. If the request is unexpected, verify it independently before taking action. A legitimate request can survive a quick phone call.
2. Hover before you click
One simple habit can help you spot suspicious links: hover before you click. On a computer, hovering over a link should show you the destination URL. Look for misspelled domains, unusual addresses or links that don’t match what the email claims to be about.
If your boss emails asking you to “quickly log in here”, take a second to check where that link leads.
3. Your AI assistant doesn’t need to know everything
AI tools are quickly becoming part of everyday working life, from writing emails to summarising documents. But that doesn’t mean every work document belongs in an AI chatbot.
Avoid entering confidential company information or sensitive internal documents unless your employer has explicitly approved the tool for that purpose. Don’t be afraid to ask what the company’s policy is on AI if you haven’t been told already.
A great rule of thumb is, if you wouldn’t paste it into a public forum, don’t automatically paste it into an AI tool.
4. Make friends with your password manager
If your company provides a password manager, use it. Password managers make it easier to create and store strong, unique passwords without having to remember dozens of different combinations.
It’s also a habit worth taking into your personal life if you aren’t already using one. And whatever you do, try not to become that new starter with passwords scribbled on sticky notes around their monitor. Your first week is probably too early to become an office cybersecurity cautionary tale.
5. Protect your connection when working remotely
Working from a coffee shop or remotely can be one of the perks of office life, but public Wi-Fi isn’t always the safest place to access work accounts. Using a reputable VPN can help protect your internet connection, particularly when you’re working outside the office.
Think of it as adding another protective layer between your work and the rest of the internet.\
6. Lock your screen. Every. Single. Time.
Heading to grab a coffee? Going to a meeting? Stepping away from your desk for two minutes? Lock your screen. It’s a simple habit that can prevent someone from accessing your accounts or sensitive company information while you’re away and, at the very least, can save you from an unfortunate office prank.
It becomes even more important if you’re working somewhere public. Leaving an unlocked laptop unattended in a café or co-working space can give a stranger direct access to your work and sensitive information.
7. Actually read your cybersecurity training and know how to report something suspicious
It’s tempting to click through mandatory cybersecurity training as quickly as possible just to get the box ticked. But when you’re new to a company, the training and employee handbook can be one of your best guides to understanding how that organisation expects you to work securely.
Pay attention to the basics: how to report a suspicious email, who to contact if you think you’ve clicked something you shouldn’t have, what information you’re allowed to share with AI tools and whether your company offers security features such as multi-factor authentication (MFA).
And remember, when it comes to cybersecurity, reporting something suspicious is always better than saying nothing. If an email, link or request looks shady, don’t worry about making a fuss; flagging it quickly can help protect both you and your company. Knowing exactly how and where to report something means you can act quickly if something does go wrong.
8. When in doubt, ask
Being new to a company can make you reluctant to question something that appears to come from a senior colleague. But asking a quick question is a strength, not a weakness.
If an email seems unusual, a link looks strange or someone is asking you to break from the normal process, check with your manager or IT team. No one expects you to know every company procedure on day one.
Starting your first job post uni is about more than learning the ropes of office life; it’s also about building good digital habits that will stay with you throughout your career. A little caution can go a long way, and if something does go wrong, don’t panic or try to hide it: report it quickly and let your company’s IT or security team help. After all, cybersecurity is everyone’s responsibility and it’s never too early to start taking it seriously.
