Starter Guide Cyber Security

New User Cyber Safety Pack

Published August 2026 · v1.0 - August 2026 · 10 pages

A simple cyber security induction for new starters and employees, covering phishing, social engineering, passwords, MFA, device security and incident reporting, with free NCSC training and a downloadable quick-reference guide.

What's inside

  • The five essential cyber safety rules for new starters
  • STOP, CHECK, VERIFY, REPORT: a simple habit for spotting scams
  • How modern phishing and social engineering actually work in 2026
  • Protecting passwords, MFA and your devices
  • What to do if something goes wrong, with no blame
  • A direct link to the free official NCSC staff training

Starting a new job means new systems, new passwords, new people and lots of unfamiliar emails. That also makes the first few weeks an ideal opportunity for cyber criminals.

This free cyber safety pack gives employees the practical basics they need to work safely online, recognise phishing and social engineering, protect their accounts and know what to do when something does not look right. No technical knowledge is required.

NEW USER CYBER SAFETY PACK

Phishing. Passwords. MFA. Devices. Social engineering. Reporting.

Free official NCSC training. No account required. Takes less than 30 minutes. Includes a short quiz. The NCSC training opens on the National Cyber Security Centre website in a new tab.

Under 30 minutes

Complete the NCSC core training in one short session.

No technical knowledge needed

Written for ordinary employees, not IT specialists.

Practical advice

Learn what to do when an email, call, login or request does not feel right.

Free to use

No registration and no email address required.

Five things every new starter should know

01  Stop before you click

Unexpected does not automatically mean malicious, but unexpected messages deserve a second look. Be cautious when an email, Teams message, text or other communication:

  • asks you to sign in
  • asks for a password or MFA code
  • contains an unexpected attachment
  • asks you to change bank details
  • asks you to make an urgent payment
  • claims your account will be disabled
  • pressures you to act immediately
  • asks you to bypass a normal procedure

Do not rely on bad spelling as a warning sign. Modern phishing messages can be perfectly written. Learn how phishing has changed.

02  Verify unusual requests another way

If someone asks you to do something unusual, sensitive or financially important, verify it using a contact method you already trust. Do not simply reply to the message that caused the concern. For example, call the person on their normal known number, speak to them in person, use an existing company directory, ask your manager or IT team, or follow your organisation’s payment or identity verification procedure.

A familiar name, email address, phone number or even a voice is no longer enough on its own. Urgency is not a reason to skip security procedures. See how social engineering attacks work in the real world.

03  Protect your accounts

Your work account is part of your organisation’s security perimeter. Employees should:

  • use a strong, unique work password or passphrase
  • never reuse a work password on personal websites
  • use the approved company password manager where provided
  • use multi-factor authentication (MFA)
  • never approve an MFA request they did not initiate
  • never tell anyone an MFA code
  • never share passwords with colleagues
  • contact IT about unexpected authentication prompts

A genuine IT team should not need to know your password to help you.

04  Keep devices safe

A secure account is only part of the picture. The device you use matters too. Employees should lock their screen whenever they leave a device, only install approved software, avoid unknown USB devices, take care with screens in public, keep laptops, phones and tablets physically secure, and immediately report a lost or stolen work device.

If your organisation manages updates centrally, allow the update or restart when your IT team asks you to.

05  Report it quickly

Cyber incidents become harder to deal with when nobody knows they have happened. If you clicked a suspicious link, opened an unexpected attachment, entered your password into a page you now distrust, approved an unexpected MFA request, sent information to the wrong person, responded to a suspected scam, lost a work device, or noticed anything else unusual, report it immediately.

Clicked something? Tell someone.

Reporting a mistake quickly gives your IT team the best chance of protecting you and the organisation. Do not wait to see what happens, and do not try to hide it.

Remember four words

STOP
Do not let urgency make the decision for you.
CHECK
Look at what is actually being requested.
VERIFY
Use a separate, trusted contact method when necessary.
REPORT
Tell your organisation quickly if something looks wrong.

Complete the official NCSC staff training

The UK’s National Cyber Security Centre provides a free cyber security awareness course designed for non-technical staff. It covers four core areas:

  • strong passwords
  • securing devices
  • defending against phishing
  • reporting incidents

It takes less than 30 minutes and includes a short quiz.

Start NCSC Top Tips for Staff ↗

The NCSC training opens on the National Cyber Security Centre website. System Force IT does not operate or control the NCSC training platform.

Download the NCSC staff security infographic ↗
External resource from the National Cyber Security Centre.

More free System Force resources

Safer Internet for Business

An eight-page guide to phishing, social engineering, MFA, password hygiene and reducing human error.

Read the guide →

AI Scams: Deepfakes, Voice Clones and Smarter Phishing

Why modern scams are harder to recognise and why good spelling is no longer proof that a message is genuine.

Read the article →

The M&S Cyber Attack Started With a Phone Call

A real-world example of social engineering and why identity verification procedures matter.

Read the article →

Phishing Defence Playbook for UK SMEs

A deeper guide for business owners and IT teams covering phishing controls, awareness and incident response.

Read the playbook →

Using this pack for employee onboarding

You can use this page as part of your new-starter induction process. A simple approach is:

  1. Ask the employee to read the New User Cyber Safety Pack.
  2. Ask them to complete the NCSC Top Tips for Staff training.
  3. Make sure they know your organisation’s own incident reporting procedure.
  4. Explain who they should contact if they make a mistake or see something suspicious.
  5. Repeat security awareness periodically rather than treating it as a once-only exercise.

Every organisation should add its own reporting process, acceptable-use policies and role-specific requirements. This public guide does not replace an employer’s policies.

There is also a simple printable onboarding record (PDF) that managers and HR can use to note completion. It is a record, not a certificate.

If your organisation is supported by System Force IT, use your normal System Force support route. Otherwise, follow your organisation’s own incident reporting process.

Frequently Asked Questions

Is the cyber security training free?

Yes. The System Force New User Cyber Safety Pack is free to download and the NCSC Top Tips for Staff training is also provided free of charge by the National Cyber Security Centre.

How long does the training take?

The NCSC states that its Top Tips for Staff training takes less than 30 minutes. The System Force Cyber Safety Pack is designed to be read in around 10 to 15 minutes.

Is this suitable for people without technical knowledge?

Yes. It is specifically intended for ordinary employees and new starters. No technical or cyber security background is required.

Does this replace our company’s cyber security policies?

No. Every employer should provide its own policies, reporting procedures and role-specific requirements. This pack provides general cyber safety awareness to complement those policies.

What should an employee do if they click a phishing link?

They should report it to their organisation’s IT team or designated contact immediately. Fast reporting gives the organisation the best opportunity to investigate, reset credentials where necessary and limit any impact.

Should staff be punished for reporting a mistake?

Security incidents should be reported as quickly as possible. Organisations should encourage prompt reporting rather than creating a culture where employees hide mistakes because they fear blame.

Need help building a safer workforce?

Technology is only part of cyber security. Good procedures, sensible controls and confident staff make attacks much harder to succeed. System Force IT helps UK SMEs protect Microsoft 365, endpoints, networks, data and users, backed by practical cyber security guidance and ongoing support.

This guide provides general cyber security awareness information. Organisations should supplement it with their own policies, procedures, reporting routes and role-specific training. Explore more free downloads in our resources library.