Read The Times Australia

Daily Bulletin

How to encourage cyber-safe behaviour at work without becoming the office grouch

  • Written by: Nathalie Collins, Academic Director (National Programs), Edith Cowan University

Business etiquette has one golden rule: treat others with respect and care. The same is true for encouraging cyber safety at work, on everything from password security to keeping valuable information like tax file numbers safe.

But how can you encourage cyber-safe behaviour at work without becoming the office grouch?

The trick, as it often is in life, is to encourage the right behaviours tactfully and by offering helpful solutions. Vilifying or mocking those who “do the wrong thing” is unlikely to help.

In short, offer alternatives and not reproach.

Hey, what’s your password?

Many organisations have policies to prevent password sharing (and most, by now, would hopefully actively discourage people from keeping passwords on a Post-it note stuck to a computer). However, asking others for a password is not yet necessarily considered taboo.

Perhaps your colleague wants to use your computer and asks for your login. Or they may need access to a shared repository such as Dropbox but have forgotten the password.

Two women chat while looking at a computer. If you’re reluctant to share your personal password, your instincts are correct. Shutterstock

If you’re reluctant to share your personal password, or broadcast a team password in Slack or on a group chat, your instincts are correct. Passwords are deeply valuable pieces of information, and many catastrophic security breaches can be traced back to poor password management at work.

But if your colleague asks for a password, rather than responding with a short, sharp “no”, soften the blow by asking why they want it. If there is a legitimate reason, work with them to resolve the issue — without giving anything away.

For example, instead of posting a Dropbox password on Slack, can you direct them to your organisation’s password manager and help them learn how to retrieve passwords from it? If it’s access to a computer they need, can you help them restart a computer and log in as a guest instead of as you?

Never send usernames and passwords by email.

Read more: A computer can guess more than 100,000,000,000 passwords per second. Still think yours is secure?

If systems are not in place at work to help people who need access to a shared password or a computer terminal, talk to your IT team about finding long-term solutions. That might include investing in a password manager such as 1Password, Dashlane or LastPass.

Files can be shared within teams through OneDrive, Dropbox or other organisational repository to reduce the need for a colleague to access your computer to “just get a file off it”.

‘Please fill in this confidential form and email it to me’

It’s not uncommon for IT, HR, finance or well-meaning admin support staff to ask you to fill in a form with sensitive information and just “email it back”.

Even doctors and lawyers have been known to mishandle documents with signatures, tax file numbers or other identifying information such as birthdays.

Don’t feel under pressure to do it. The fact is, such information is invaluable to hackers and identity thieves. Should your workplace email suffer a data breach, bad actors may be able to retrieve these scanned forms from inboxes they’ve invaded.

Read more: Everyone falls for fake emails: lessons from cybersecurity summer school

Most organisations have secure ways of transferring files, varying from a secure cloud storage solution to secure file sharing sites. Use them, and never your personal email or cloud solutions.

If your organisation doesn’t have a secure way to save the files you can use one and send your colleague the link in a work email.

Alternatively, you can send an encrypted PDF in an email, which means much tighter control of who can access the file.

Sometimes the safest solutions are the simplest. Go old-school: walk the documents over to the person instead of scanning and emailing them.

If you’re asked to send personal information in an insecure way, hide your Pikachu face. Instead, say: “We’re supposed to be transferring files this way. If you want, I can show you how for next time?”

Offering a solution, rather than shaming, is much more likely to lead to change.

A person scans forms at work. Sometimes the safest solutions are the simplest; if you can, just walk the documents over to the person instead of scanning and emailing them. Shutterstock

Can you pass on my resume?

Job-hunters may try to get their foot in the door by leveraging a friend or ex-colleague. Many of us would be keen to help a friend by passing on their CV to the boss.

Unfortunately, malicious actors of all kinds also know this. As outlined in this article, fake CVs can be sent by email with a Microsoft Excel attachment. When opened, the attached file can launch malware that:

…then attempts to hijack private information, credentials from users of targeted financial institutions, and passwords and cookies stored in web browsers. Attackers can then exploit these acquisitions to make financial transactions.

Malware is not just embedded in links and attachments - even LinkedIn messages can contain malware. The consequences of opening such links or attachments can be extreme, and may even include ransomware (where hackers refuse access to files or online systems until the victim pays up).

A computer displays the homepage of LinkedIn. Even LinkedIn messages can contain malware. Shutterstock

Don’t pass on CVs, especially if the person is a friend of a friend. Instead, pass on the person’s name to the boss, so she or he can look them up on LinkedIn. Don’t follow links sent to you, even by trusted contacts. Links can often be difficult to check without clicking on them and you may be redirected to a malicious site.

And if you are the jobseeker, demonstrate your own cyber-security awareness by not circulating CVs or other documents with personal information that may be valuable to identity thieves. No birthdays, addresses, just email, mobile number and LinkedIn.

The same rule applies to QR codes - don’t blindly open the webpage pointed to on a business card QR code. You may get more than you bargained for.

Resist the urge to do something unsafe when on deadline

Unfortunately, many workplaces still see cyber-unsafe behaviour as broadly acceptable and the pressure to do something unsafe, especially when on deadline, can be profound.

But by treading respectfully, and helpfully, you can improve your office reputation as a cybersafe staff member and help reduce the risk to your organisation.

Authors: Nathalie Collins, Academic Director (National Programs), Edith Cowan University

Read more https://theconversation.com/how-to-encourage-cyber-safe-behaviour-at-work-without-becoming-the-office-grouch-152319

Business News

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...