Skip to main content

General Security Best Practices

Ensuring the security of an organization’s IT infrastructure requires the active participation of all employees. Here are some essential best practices that employees should follow to maintain cybersecurity:

1. Password Management & MFA

  • Use Strong Passwords: Create complex passwords using a mix of upper and lower case letters, numbers, and special characters. Avoid using easily guessable information such as birthdays or common words. Use this Password Generator

  • Change Passwords Regularly: Update passwords periodically and avoid reusing old passwords.

  • Enable Multi-Factor Authentication (MFA): Whenever possible, use MFA to add an extra layer of security to your accounts.

2. Email Security

  • Be Cautious with Attachments and Links: Do not open attachments or click on links in emails from unknown senders. Verify the source if something looks suspicious.

  • Beware of Phishing: Be on the lookout for phishing emails that try to trick you into providing personal information or clicking on malicious links. Look for signs such as misspellings, urgent requests, or unfamiliar sender addresses.

3. Data Protection

  • Encrypt Sensitive Data: Use encryption tools to protect sensitive information stored on your devices or transmitted over the internet.

  • Regular Backups: Ensure that important data is backed up regularly to a secure location. This helps in recovery in case of a ransomware attack or data loss.

  • Limit Access: Only access and share data necessary for your role. Avoid sharing sensitive information through unsecured channels.

4. Device Security

  • Keep Software Updated: Regularly update your operating system, antivirus software, and all applications to protect against the latest threats.

  • Use Antivirus Software: Ensure that your device is protected by Sentinel One antivirus software.

  • Secure Mobile Devices: Use password protection, encryption, and remote wipe capabilities for smartphones and tablets used for work.

5. Safe Browsing Practices

  • Use Secure Connections: Access websites using HTTPS to ensure the data transmitted is encrypted.

  • Avoid Unsecured Wi-Fi Networks: Do not use public Wi-Fi for accessing sensitive company information. Use a VPN if remote access is required.

  • Be Wary of Downloading Files: Only download software or files from trusted sources.

6. Physical Security

  • Lock Your Devices: Always lock your computer or mobile device when not in use, especially in public or shared spaces.

  • Secure Workstations: Ensure that your work area is secure and that sensitive documents are stored in locked cabinets or drawers.

7. Social Engineering Awareness

  • Recognize Social Engineering Tactics: Be aware of common tactics such as impersonation, pretexting, or baiting used to manipulate employees into divulging confidential information.

  • Verify Identities: Always verify the identity of individuals requesting sensitive information, whether over the phone, in person, or via email.

8. Incident Reporting

  • Report Suspicious Activity: Immediately report any suspicious activity, potential security breaches, or lost/stolen devices to your IT department or security team.

  • Follow Incident Response & Breach Notification Procedures-: Familiarize yourself with the company’s Incident Response & Breach Notification Procedures and follow them diligently in the event of a security incident.

9. Training and Awareness

  • Participate in Training: Attend regular cybersecurity training sessions provided by Flink to stay informed about the latest threats and best practices. Find the training here.

  • Stay Informed: Keep up-to-date with the latest cybersecurity trends and threats by following reputable sources and security bulletins.

Did this answer your question?