Cyber Security at Work FAQs

Cyber security at work FAQs cover best practice to help organisations protect data, people, and systems.

What is cyber security?

Cyber security is the practice of protecting systems, networks, devices, and data from digital threats such as unauthorised access, cyber-attacks, data breaches, and disruption, ensuring information remains confidential, accurate, and available when needed.

Why is cyber security important?

Cyber security is important because it protects sensitive data, prevents financial loss and operational disruption, reduces the risk of cybercrime, and helps organisations meet legal and regulatory obligations while maintaining trust with customers and employees.

What is cyber security awareness training?

Cyber security awareness training teaches people how to recognise, prevent, and respond to cyber threats, helping them use technology safely and protect organisations from risks such as phishing, malware, and data breaches.

What is the purpose of cyber security awareness training?

The purpose of cyber security awareness training is to help people understand cyber risks, recognise common threats such as phishing and malware, and adopt safe behaviours that protect systems, data, and organisations from cyber-attacks and breaches.

Why is cyber security training so important?

Cyber security training is important because it reduces human error, helps prevent cyber attacks and data breaches, protects sensitive information, and supports legal and regulatory compliance by ensuring people understand their role in keeping systems and data secure.

Why train employees on cyber security?

Employees are often the first line of defence against cyber threats, so cyber security training helps them recognise risks, avoid common mistakes, and respond appropriately to incidents, reducing the likelihood of data breaches, financial loss, and operational disruption.

Is cyber security training mandatory?

Cyber security training is not explicitly mandated by a single law, but it is effectively required under several UK laws and regulations, including the UK GDPR and the Data Protection Act 2018, which require organisations to take ‘appropriate technical and organisational measures’ to protect personal data.

Providing cyber security awareness training helps demonstrate compliance with these duties. It is also relevant to the Network and Information Systems (NIS) Regulations 2018 for organisations operating essential or digital services, where staff competence and security awareness form part of expected risk management measures.

How long does cyber security training take?

Cyber security training duration can vary, but our online Cyber Security Awareness Training is designed to be completed in around 25 to 30 minutes, enabling employees to gain essential knowledge without significant disruption to their working day.

How much does cyber security awareness training cost?

Cyber security awareness training costs can vary, but our Cyber Security Awareness Training is priced at £30, offering a cost-effective way for organisations to improve cyber security awareness and reduce the risk of cyber incidents.

What is social engineering and how does it differ from a technical hack?

Social engineering is a cyber-attack that manipulates people into revealing information or taking actions, such as clicking malicious links or sharing passwords.

Unlike a technical hack, which exploits system or software vulnerabilities, social engineering exploits human behaviour and trust rather than technology.

What is phishing in cyber security?

Phishing is a cyber-attack where criminals use fake emails, messages, or websites to trick people into revealing sensitive information, such as passwords or bank details, or into downloading malicious software.

What is smishing and how does it target employees via text message?

Smishing is a type of phishing carried out via SMS text messages. It targets employees by sending messages that appear urgent or legitimate (for example, delivery issues or account warnings) to trick them into clicking malicious links, downloading malware, or sharing sensitive information such as passwords or verification codes.

What is vishing in cyber security?

Vishing (voice phishing) is a cyber-attack where criminals use phone calls or voice messages to trick people into revealing sensitive information or taking actions such as making payments or sharing login details, often by impersonating a trusted organisation.

What is baiting in cyber security?

Baiting is a cyber-attack where criminals lure people with something enticing, such as free downloads or infected USB drives, to trick them into installing malware or giving attackers access to systems and data.

What is pharming in cyber security?

Pharming is a cyber-attack that redirects users from a legitimate website to a fake one without their knowledge, with the aim of stealing sensitive information such as login details or financial data.

How is artificial intelligence being used by cybercriminals for deepfakes?

Cybercriminals use artificial intelligence to create realistic deepfake audio, video, or images that impersonate real people. These are used to scam organisations through fake phone calls or videos (for example, posing as senior leaders), bypass identity checks, spread misinformation, or make fraud and social engineering attacks more convincing and harder to detect.

What is ransomware and how does it affect businesses?

Ransomware is a type of malicious software that encrypts an organisation’s data or systems and demands payment to restore access. It can disrupt operations, cause financial loss, lead to data breaches, damage reputation, and result in legal or regulatory consequences if sensitive data is affected.

What is the difference between a strong password and a passphrase?

A strong password is usually a short string of mixed characters, using upper and lower case letters, numbers, and symbols. It relies on complexity but can be hard to remember.

A passphrase is a longer sequence of words, often with spaces or symbols. It relies on length rather than complexity, making it easier to remember and much harder for attackers to crack.

Passphrases are generally more secure and more user-friendly than traditional complex passwords, especially when combined with multi-factor authentication.

How does a password manager improve security?

A password manager improves security by creating, storing, and autofilling strong, unique passwords for each account.

It removes the need to reuse passwords or remember them, reducing the risk of breaches spreading between accounts. Password managers also protect credentials with strong encryption and can warn you about weak, reused, or compromised passwords.

What is MFA in cyber security?

MFA (multi-factor authentication) is a security measure that requires users to verify their identity using two or more factors, such as a password, a one-time code sent to a phone, or a biometric check, making unauthorised access much harder.

What is multi factor authentication in cyber security?

Multi-factor authentication (MFA) is a cyber security measure that requires users to confirm their identity using two or more verification methods, such as something they know (a password), something they have (a security code or device), or something they are (biometric data), to reduce the risk of unauthorised access.

What is the principle of least privilege in a workplace?

The principle of least privilege means employees are given only the minimum level of access needed to perform their job. This reduces the risk of accidental damage, data breaches, or misuse of systems by limiting what users can see or change if an account is compromised.

Why are software updates and patching critical for cyber security?

Software updates and patching are critical for cyber security because they fix known vulnerabilities that attackers actively exploit.

Without updates, systems remain exposed to malware, ransomware, and unauthorised access.

Patching also improves system stability, protects sensitive data, and helps organisations meet security and compliance requirements by reducing the attack surface.

What is shadow IT and why is it a security risk?

Shadow IT refers to software, apps, or online services used by employees without approval from the organisation’s IT or security teams. It is a security risk because these tools may lack proper security controls, data protection, or monitoring, increasing the chance of data breaches, compliance failures, and unauthorised access to company information.

What is the difference between an IT department and a cyber security team?

An IT department focuses on keeping systems running day to day, such as managing hardware, software, networks, and user support.

A cyber security team focuses on protecting those systems and data from threats by managing risks, monitoring for attacks, setting security controls, and responding to incidents.

How do I stay cyber secure when working from home or in a public place?

To stay cyber secure when working from home or in public, use secure Wi-Fi (or a trusted mobile hotspot) and avoid public networks where possible. Keep your devices updated, use strong, unique passwords, and enable multi-factor authentication.

Always connect through a VPN if your organisation provides one, lock your screen when away, and be alert to phishing emails or messages. Avoid accessing sensitive information in public view and only use approved work devices and software.

What are the risks of using public Wi-Fi for work tasks?

Using public Wi-Fi for work tasks increases the risk of data interception, account compromise, and malware infection.

Public networks are often unsecured, making it easier for attackers to intercept data, steal login details, or carry out “man-in-the-middle” attacks. Fake or spoofed Wi-Fi hotspots can also trick users into connecting and handing over information without realising it.

If sensitive work is carried out on public Wi-Fi without strong protections such as a VPN, confidential data and systems can be exposed to unauthorised access.

What is a VPN and why should I use one when working remotely?

A VPN (Virtual Private Network) creates a secure, encrypted connection between your device and your organisation’s network or the internet.

When working remotely, a VPN protects your data from being intercepted on unsecured or public Wi-Fi. It helps keep login details, emails, and files private, reduces the risk of cyber-attacks such as eavesdropping, and allows you to access work systems securely as if you were on the office network.

How should I handle work data on personal devices or mobile phones?

Work data on personal devices or mobile phones should be handled carefully and in line with your organisation’s policies.

Only access work systems using approved apps and secure connections, such as a VPN. Keep devices updated, protected with strong passwords or biometrics, and enable encryption where possible. Separate work and personal data, avoid storing sensitive information locally, and never share work devices or accounts with others.

If a device is lost, stolen, or compromised, report it immediately so access can be blocked or data wiped.

What is the clean desk policy and how does it relate to cyber security?

A clean desk policy requires employees to clear desks of sensitive information and lock away documents and devices when not in use. It supports cyber security by reducing the risk of unauthorised access to data, preventing information being viewed, stolen, or misused, and helping protect against data breaches caused by poor physical security.

How can I tell if my work computer has been compromised by malware?

Signs your work computer may be compromised by malware include:

  • Unusual slowness, crashes, or freezing
  • Unexpected pop-ups, warnings, or fake security alerts
  • Programs opening, closing, or running without your input
  • Unrecognised software or browser extensions
  • Changes to settings you didn’t make (homepage, security settings, passwords)
  • High network activity when you’re not doing much
  • Blocked access to files or a ransom message

If you notice any of these, disconnect from the network immediately and report it to IT or your security team. Don’t try to fix it yourself, as that can make things worse.

What should I do if I think I have clicked on a phishing link?

If you think you have clicked on a phishing link, act quickly:

  • Disconnect from the network (turn off Wi-Fi or unplug the cable) to limit potential damage.
  • Do not enter any information or download anything further.
  • Report it immediately to your IT or security team, following your organisation’s procedure.
  • Change any passwords you may have entered, starting with work accounts.
  • Run a security scan if advised by IT.

Prompt reporting helps reduce the risk to you and the wider organisation.

What is a data breach and when does it need to be reported to the ICO?

A data breach is a security incident where personal data is accessed, disclosed, lost, altered, or destroyed without authorisation.

In the UK, a breach must be reported to the Information Commissioner’s Office (ICO) within 72 hours if it is likely to result in a risk to individuals’ rights and freedoms (for example, risk of identity theft, financial loss, or distress).
If the risk is high, affected individuals must also be informed without undue delay.

How often should a cyber security risk assessment be conducted?

A cyber security risk assessment should be conducted at least annually, and whenever there is a significant change, such as new systems, software, suppliers, threats, or a security incident.

Regular reviews help ensure risks remain identified, controlled, and aligned with the organisation’s current technology and threat landscape.